Reconciliation is the operational core of the interim safeguarding regime. Firms can hold funds in a compliant account and still fail the requirements if they cannot demonstrate, day by day, that the amount held matched the amount that should have been held, and that any difference was identified and corrected.
This article sets out how the reconciliation requirements work in practice and what a firm needs from its systems to evidence them.
Internal and external reconciliation
Internal reconciliation compares the firm's safeguarding records, the customer-level record of relevant funds, against the firm's own accounting records. It answers the question: does our own view of what we owe customers hold together internally?
External reconciliation compares the safeguarding records against statements and confirmations from third parties: the credit institution holding the safeguarding account, any custodian, the insurer or guarantor where that method is used, and any intermediary holding relevant funds.
Both must be performed. A firm that reconciles only to the bank statement has not tested the integrity of its own customer-level records; a firm that reconciles only internally has not tested whether the money is actually there.
Frequency and timing
The requirement is to reconcile as often as necessary, and as soon as reasonably practicable after the reconciliation date, to ensure accuracy. In practice, for firms processing daily customer flows, this means a daily reconciliation cycle, completed early enough that any shortfall can be funded from the firm's own resources on the same business day and any excess withdrawn.
Two timing points cause most difficulty:
Cut-off consistency. The ledger extract, the customer record and the bank statement must relate to the same point in time. Mismatched cut-offs create phantom discrepancies that consume investigation time.
Funds in transit. Amounts received but not yet credited, and payments instructed but not yet settled, must be treated consistently and identifiably, not netted into a residual balancing figure.
Discrepancy management
A reconciliation that produces a difference is not a failure. A reconciliation that produces a difference the firm cannot explain, or explains late, is.
The process should establish:
- The materiality and ageing thresholds that trigger escalation.
- Who investigates, who approves the resolution and how those roles are kept separate.
- The immediate funding action, so that customers are not exposed while the investigation runs.
- Root cause analysis where discrepancies recur, feeding back into the underlying process.
- The record: what the difference was, why it arose, what was done, when, and by whom.
Recurring discrepancies from the same source are treated far more seriously than isolated exceptions, because they indicate a control weakness rather than an operational error.
Records and reconstruction
The evidential test most firms fail is reconstruction. An auditor or a case officer will select a date, often not a month end, and ask the firm to produce the safeguarding position as at that date: the customer-level record, the reconciliation performed, the discrepancies identified, and the actions taken.
Meeting that test requires records to be immutable and time-stamped, not overwritten. Where reconciliation is performed in a workbook that is saved over, the position as at a past date usually cannot be reproduced with confidence, and the finding is not "the reconciliation was wrong" but "the firm cannot demonstrate that it was right".
What reconciliation tooling must deliver
| Requirement | What the system must do |
|---|---|
| Customer-level record | Maintain relevant funds by customer, with the timing rules applied to receipt and cessation |
| Internal reconciliation | Compare safeguarding records to the general ledger on the same cut-off |
| External reconciliation | Ingest bank, custodian and insurer records automatically and match against the firm record |
| Shortfall and excess | Calculate the required top-up or withdrawal for the day and evidence the action taken |
| Exception workflow | Investigate, escalate, approve and close with segregation of duties enforced by the system |
| Audit trail | Immutable log of every entry, adjustment and approval with user, timestamp and reason |
| Reconstruction | Reproduce the full position and reconciliation as at any historic date |
| Reporting | Board-level metrics on discrepancy volume, ageing, funding events and root cause |
Our safeguarding reconciliation best practice guide covers the process design in more detail, and the PS25/12 buyer's guide covers evaluation and vendor due diligence.
Software partner
For firms implementing purpose-built tooling, SafeHeld provides safeguarding and reconciliation software designed around the UK CASS 15 requirements, including daily internal and external reconciliation, exception workflow with segregation of duties, and audit-ready evidence packs.
Regulatory Counsel is independent of any software provider. Our role sits on the regulatory side: settling the relevant funds analysis, defining the reconciliation methodology the system implements, drafting the safeguarding policy and procedures, and preparing the firm for its safeguarding audit.
Common findings to avoid
Reconciling to the bank only. Internal reconciliation omitted, so customer-level record integrity is untested.
Balancing figures. A residual line used to force agreement, with no investigation.
Month-end only. Daily flows reconciled monthly, leaving customers exposed between cycles.
No segregation. The same individual prepares, reviews and approves.
Unresolved ageing. Old discrepancies carried forward without escalation.
Policy and practice divergence. A safeguarding policy describing a frequency or method the firm does not actually operate.
About Regulatory Counsel
Regulatory Counsel advises UK and international payment institutions and e-money institutions on safeguarding, authorisation, prudential requirements, financial crime and regulator engagement.
Our safeguarding work covers relevant funds analysis, reconciliation methodology design, safeguarding policy and procedures, audit readiness and remediation of audit findings, and independent advice on reconciliation technology selection.
Contact our regulatory team at info@regulatorycounsel.co.uk.
This article is provided for general information and does not constitute legal or regulatory advice. Firms should confirm the current position against FCA publications and take advice on their specific circumstances.
Frequently Asked Questions
Internal reconciliation compares the customer-level safeguarding record to the firm's own accounting records. External reconciliation compares the safeguarding record to third-party records such as bank, custodian or insurer statements. Both are required.
As often as necessary to ensure accuracy and to identify discrepancies promptly. For firms with daily customer flows this means a daily cycle, completed in time to fund any shortfall or withdraw any excess on the same business day.
The firm must pay its own funds into the safeguarding arrangement to cover the shortfall without delay, then investigate the cause, record the resolution and address the underlying control weakness.
Yes. Auditors and the FCA commonly select a historic date and ask for the position as at that date, including the record, the reconciliation and the discrepancy actions. Inability to reconstruct is a common finding.
The interim safeguarding regime introduced through PS25/12 applies to payment institutions and e-money institutions safeguarding relevant funds, with the detailed requirements set out in the CASS 15 sourcebook.
The activity can be supported by a provider, but the obligation and senior manager accountability remain with the firm. The arrangement should be governed under the firm's SYSC 8 outsourcing framework, with oversight and exit planning.
