Safeguarding

CASS 15 Compliance 2026: Complete FCA Guide for Payment Institutions and EMIs

Regulatory Counsel · Published August 2026 · Last reviewed August 2026 · 9 min read

CASS 15 has changed safeguarding for UK payment and electronic money firms from a relatively principles-based obligation into a much more structured operational compliance regime.

The FCA's strengthened safeguarding rules took effect on 7 May 2026. Firms within scope now face detailed requirements around governance, relevant funds, records, internal and external safeguarding reconciliations, third-party arrangements and notification of material failures. Separate but connected requirements cover monthly FCA safeguarding returns, independent safeguarding audits for firms within the audit regime and a CASS resolution pack.

For boards and senior management, CASS 15 compliance is therefore not simply about having an updated safeguarding policy. The firm needs to be able to demonstrate, through its actual records and controls, that relevant funds are identified, protected, reconciled and monitored correctly every day.

This guide explains the principal requirements and what firms should be doing now.

What is CASS 15?

CASS 15 is the chapter of the FCA Client Assets sourcebook governing relevant funds held by safeguarding institutions in the payment services and electronic money sectors.

It supplements the safeguarding requirements contained in the Payment Services Regulations 2017 and Electronic Money Regulations 2011.

The current CASS 15 framework forms part of the FCA's Supplementary Regime introduced through PS25/12. It is important not to confuse this with the proposed Post-Repeal Regime. The FCA did not proceed with that second stage at the same time, meaning firms should base their current compliance arrangements on the rules that are actually in force.

CASS 15 nevertheless represents a significant increase in prescription, oversight and evidence compared with the previous safeguarding framework.

Who needs to comply with CASS 15?

CASS 15 applies to safeguarding institutions that receive or hold relevant funds within its scope.

This includes authorised payment institutions that hold relevant funds and electronic money institutions, together with other institutions brought within the chapter by the FCA rules.

Small payment institutions that voluntarily safeguard can also enter relevant parts of the regime.

The precise application should be checked against the firm's permissions and business model. A payment firm that never receives or holds customer funds may be in a materially different position from one that routinely controls substantial customer balances.

Firms with mixed activities also need clear records identifying the capacity in which money is being held.

What does CASS 15 require?

The operational framework can be understood through several connected obligations.

A safeguarding institution must maintain adequate arrangements to protect clients' rights and prevent relevant funds being used for the firm's own account.

It must establish, implement and maintain adequate safeguarding policies and procedures.

It must maintain records and accounts sufficient to identify relevant funds and explain its transactions and commitments.

It must undertake internal and external safeguarding reconciliations.

It must address discrepancies and shortfalls in accordance with the FCA rules.

It must operate appropriate arrangements with banks, custodians and other relevant third parties.

It must maintain governance and oversight capable of identifying failures and escalating material issues.

It must also comply with associated FCA requirements for regulatory reporting, resolution planning and, where applicable, safeguarding audit.

The important point is that these are not separate compliance exercises. The information generated by one control frequently becomes the evidence for another.

CASS 15 governance and senior management responsibility

CASS 15 requires a safeguarding institution to allocate responsibility for operational compliance with the relevant funds regime to a single director or senior manager with sufficient skill and authority.

That person must also report to the firm's governing body in respect of their safeguarding oversight.

This changes the practical governance expectation.

Safeguarding should have a clearly identifiable owner rather than being divided informally between finance, operations and compliance. That owner needs reliable information from those functions to determine whether the controls are actually working.

Boards should expect regular management information covering safeguarding positions, reconciliation completion, discrepancies, unresolved exceptions, significant third-party issues, regulatory reporting and audit findings.

A board report that simply states that safeguarding remains compliant without supporting evidence is unlikely to provide meaningful oversight.

CASS 15 daily reconciliation requirements

Reconciliation is one of the most operationally significant parts of the regime.

Subject to the detailed rules and exceptions, a safeguarding institution must perform an internal safeguarding reconciliation as frequently as necessary and no less than once each reconciliation day.

The internal reconciliation tests the firm's own records and accounts to determine whether its safeguarding resource matches its safeguarding requirement and whether the relevant amounts are held in the required accounts or assets.

External safeguarding reconciliation compares the firm's internal records with records or confirmations from banks, custodians and other relevant third parties.

This is not simply a finance ledger exercise.

A compliant process needs reliable source data, defined reconciliation points, clear ownership, records of when the reconciliation was performed, evidence of the steps taken, documented outcomes and a process for investigating and resolving discrepancies.

This is one reason firms are increasingly considering CASS 15 compliance software rather than relying entirely on spreadsheets and manually assembled evidence.

What records must a firm retain?

CASS 15 places substantial emphasis on records and evidence.

A firm must be able to distinguish relevant funds from other money and maintain records sufficient to show and explain its relevant transactions and commitments.

The rules also require specific information to be recorded for safeguarding reconciliations, including when the process was carried out, the actions taken and the outcome.

Unless a different requirement applies, records made under the chapter generally need to be retained for five years from the later of their creation or latest modification.

For management, the practical question is therefore not only whether a reconciliation was completed. The firm should also be able to demonstrate how it was completed and what happened when something did not reconcile.

How quickly must reconciliation discrepancies be addressed?

A discrepancy should trigger investigation rather than simply be carried forward to the next reporting cycle.

The FCA rules contain specific requirements dealing with reconciliation discrepancies, shortfalls and excess amounts.

Material failures can also create direct notification obligations to the FCA.

For example, CASS 15 requires notification without delay in specified circumstances where records become materially out of date or inaccurate, where the firm materially fails to conduct required internal reconciliation or where it cannot appropriately address a shortfall or excess.

Firms therefore need an escalation framework that distinguishes routine operational breaks from issues that may have regulatory significance.

CASS 15 and third-party safeguarding arrangements

Payment and e-money firms frequently rely on banks, custodians, processors, agents and other providers as part of their safeguarding architecture.

CASS 15 contains more structured expectations around those relationships.

Firms should know precisely where relevant funds are located, which counterparties perform safeguarding-related functions, which agreements govern those arrangements and what evidence supports the firm's assessment of each third party.

Bank acknowledgement arrangements are particularly important where required.

Third-party dependency is also relevant to reconciliation. An automated process cannot compensate for source information that is incomplete, delayed or structurally incapable of supporting the firm's reconciliation methodology.

What is the CASS 15 resolution pack requirement?

The resolution-pack obligation is contained principally in CASS 10A and applies to safeguarding institutions when they receive or hold relevant funds in accordance with CASS 15.

The purpose is straightforward: if the institution fails, the information needed to identify and return safeguarded funds should be available quickly.

The pack includes a master document, information concerning safeguarding institutions and relevant accounts, executed agreements, acknowledgement letters, information about agents and relevant third parties, safeguarding procedures, key individuals and specified CASS 15 records.

The pack is not intended to be assembled after a firm enters difficulty.

It must be maintained on an ongoing basis and the required documents must generally be retrievable as soon as practicable and in any event within 48 hours in the circumstances specified by the rules.

This makes resolution-pack readiness an ongoing operational control rather than an annual documentation exercise.

What are the CASS 15 audit requirements?

The safeguarding audit regime sits in SUP 3A rather than CASS 15 itself.

Subject to the FCA's exemption, relevant authorised payment institutions and electronic money institutions must appoint an external auditor.

An institution is exempt where it has not been required to safeguard more than £100,000 of relevant funds at any time for a period of at least 53 weeks.

For firms within scope, the auditor prepares a safeguarding report addressed to the FCA as a reasonable assurance engagement.

The report must address whether the institution maintained adequate systems to comply with the relevant funds regime throughout the period and whether it was compliant at the end of the period.

This makes the quality of the firm's daily evidence particularly important. Audit readiness should be built into the safeguarding process throughout the year rather than reconstructed immediately before the auditor arrives.

What are the CASS 15 FCA reporting requirements?

The FCA has also introduced a dedicated safeguarding return.

Under SUP 16.14A, safeguarding institutions must generally submit a safeguarding return within 15 business days after the end of each calendar month.

The purpose is to give the FCA regular and comprehensive information concerning how firms safeguard relevant funds.

Monthly reporting means data quality problems can become regulatory reporting problems quickly.

Firms need controls around preparation, review, approval and submission of the return, together with clear reconciliation between the information reported to the FCA and the firm's underlying safeguarding records.

Can firms automate CASS 15 compliance?

Technology can automate significant parts of the operational framework, but responsibility remains with the regulated firm.

Safeheld is a specialist client-funds assurance platform covering reconciliation, breach detection, regulatory reporting, resolution packs and audit evidence.

For CASS 15 firms, the value of a system such as Safeheld is not merely that it can calculate a reconciliation. It is that reconciliation results, exceptions, investigation evidence, reporting and resolution-pack information can be connected to a common underlying record.

This can reduce the operational fragmentation created when finance performs reconciliations in spreadsheets, compliance maintains separate breach logs, reporting is prepared manually and the resolution pack is updated independently.

Technology does not remove the requirement for judgement, governance or regulatory accountability. It can, however, make the control environment easier to operate, monitor and evidence.

When is specialist CASS 15 advice required?

Software cannot determine every regulatory question.

A firm may need specialist advice where it is unclear whether funds fall within the safeguarding perimeter, where the reconciliation methodology needs to be redesigned, where policies do not reflect actual money flows, where audit findings indicate structural weaknesses or where the FCA has raised concerns.

Buckingham Capital Consulting provides specialist safeguarding and CASS 15 advisory support to payment and electronic money firms, including gap analysis, policies and procedures, reconciliation reviews, resolution-pack support, audit readiness and remediation.

The distinction is important.

Regulatory advice helps determine what the firm's arrangements should be. Operational technology helps the firm execute, monitor and evidence those arrangements consistently.

What should firms do now?

For firms already subject to CASS 15, the implementation deadline has passed. The question is now whether the framework works in practice.

Management should be able to answer five basic questions confidently:

  1. Can we identify our relevant funds position accurately?
  2. Are required internal and external reconciliations completed and evidenced on time?
  3. Are discrepancies identified, investigated and escalated appropriately?
  4. Can we produce our safeguarding reporting, audit evidence and resolution pack from reliable underlying records?
  5. Can our senior manager and board demonstrate effective oversight?

If any answer depends heavily on manual reconstruction, knowledge held by one individual or documents spread across multiple uncontrolled locations, the firm should consider whether its CASS 15 framework is sufficiently resilient.

CASS 15 compliance is now an ongoing operating requirement, not an implementation project.

Frequently Asked Questions

CASS 15 is the FCA Client Assets sourcebook chapter dealing with relevant funds held by payment and electronic money safeguarding institutions. It supplements safeguarding requirements under the Payment Services Regulations 2017 and Electronic Money Regulations 2011.

The strengthened safeguarding regime, including CASS 15, came into force on 7 May 2026.

Subject to the detailed rules and applicable exceptions, internal safeguarding reconciliation must be performed as frequently as necessary and no less than once each reconciliation day. External safeguarding reconciliation is also subject to a minimum reconciliation-day frequency.

No. SUP 3A contains an exemption where the institution has not been required to safeguard more than £100,000 of relevant funds at any time for a period of at least 53 weeks. Firms should assess their status on a continuing basis.

A significant part of reconciliation, evidence capture, exception management, reporting and resolution-pack maintenance can be supported by specialist technology such as Safeheld. Regulatory accountability and judgement remain with the regulated institution.

Need Expert Advice?

Free initial consultation. No obligation.

Speak to an Expert