REP027 is the monthly safeguarding return required from safeguarding institutions under SUP 16.14A of the Financial Conduct Authority Handbook. It is generally due within 15 business days after each calendar month end and should be produced from the same controlled records used for the firm's CASS 15 safeguarding reconciliations.
REP027 is not an administrative form that can safely be assembled from a separate month-end spreadsheet. It gives the regulator recurring information about the firm's safeguarding arrangements and control outcomes. An inconsistency between the return, daily reconciliation records and board reporting can therefore expose a wider records or governance weakness.
## What REP027 is
SUP 16.14A was introduced with the strengthened safeguarding regime that took effect on 7 May 2026. Its purpose is to provide the Financial Conduct Authority with regular and comprehensive information about how a safeguarding institution protects relevant funds.
The return sits alongside CASS 15 rather than replacing it. CASS 15 governs the records, calculations, reconciliations and controls. REP027 reports prescribed information produced by that framework.
Under SUP 16.14A.3R, a safeguarding institution must submit its safeguarding return within 15 business days after the end of each calendar month. A firm is not required to submit a return for a month in which it first becomes a safeguarding institution, but it should check the precise application provision against its circumstances.
REP027 is not FSA056
REP027 is frequently confused with FSA056, also known as the Client Money and Assets Return or CMAR. They are different returns for different populations.
| Return | Principal population | Rule location | General frequency |
|---|---|---|---|
| REP027 | Payment and e-money safeguarding institutions | SUP 16.14A | Monthly |
| FSA056 or CMAR | CASS medium and large investment firms | SUP 16.14 | Monthly |
A group containing both a payment institution and an investment firm may need both returns. It should maintain separate obligation records, legal-entity ownership and submission evidence.
Build the return from the reconciled position
The month-end safeguarding position should come from the same governed data and methodology used for daily internal and external reconciliation. Re-extracting the ledger and rebuilding the calculation for REP027 creates an avoidable second version of the truth.
The reporting record should preserve:
- the month-end source-data snapshot;
- the relevant CASS 15 reconciliation runs;
- the calculation and mapping version;
- open exceptions and their treatment;
- reporting-specific adjustments;
- validation results;
- preparer and reviewer approval;
- the submitted return and submission receipt; and
- any rejected submission, correction or resubmission.
A reviewer should be able to select a material return figure and trace it directly to the underlying approved record.
Data ownership
REP027 data typically crosses finance, operations, compliance and treasury. The firm should assign an owner to each field or data family before the reporting window begins.
Finance may own ledger balances and own-funds information. Operations may own accounts, processors and exception data. Compliance may own breach, notification and governance responses. The accountable senior manager should receive one controlled version for approval.
Shared ownership must not become ambiguous ownership. The reporting procedure should identify who supplies, validates, challenges and approves each input.
Validation
A controlled REP027 process should apply at least four forms of validation.
First, technical validation confirms the correct format, mandatory fields and permitted values. Second, arithmetic validation checks totals and relationships within the return. Third, reconciliation validation compares the return with daily records, bank evidence and related regulatory submissions. Fourth, reasonableness validation identifies unexpected movements against previous periods.
Warnings should require a recorded explanation or resolution. A user should not be able to dismiss a failed validation without attribution.
Treatment of open exceptions and shortfalls
Month end does not make an unresolved safeguarding issue disappear. The reporting process should display open breaks, shortfalls and control failures so the preparer can apply the required reporting treatment and consider any separate notification obligation.
REP027 does not replace notification without delay where CASS 15 or Principle 11 requires it. Firms should avoid waiting for the monthly return where the rules require earlier engagement with the regulator.
The return, breach record and board information should describe the same underlying event consistently. Different case counts or closing balances indicate a data-governance problem even if each document was prepared conscientiously.
Review and attestation
Approval should attach to the exact version submitted. An email saying “looks fine” is weak evidence if the figures changed afterwards.
The reviewer should see the full return, material movements, unresolved exceptions, validation overrides and comparison with the underlying safeguarding position. The workflow should record the person's identity, role, time and decision.
Submission access should be limited to authorised users. The submitted file, regulator receipt and any validation response should be retained with the approved version.
Corrections and resubmissions
A corrected return should not overwrite the original. The evidence record should show what changed, why it changed, the regulatory impact, who approved the correction and when it was resubmitted.
The firm should also decide whether the correction reveals a defect in the underlying reconciliation, reporting mapping or review process. Correcting the form without repairing the cause leaves the next return exposed to the same failure.
Recurring corrections, late submissions and repeated validation overrides should be visible in senior-management information.
Board reporting
The board pack and REP027 serve different purposes but should draw from the same controlled data. The return supplies prescribed regulatory information. The board pack should explain trends, significant exceptions, shortfalls, repeated causes, remediation and matters requiring oversight.
Building the board pack independently creates a risk that directors see figures that do not agree with the regulator's return. The better model generates both outputs from the approved safeguarding record and then adds board-level explanation.
Technology and Safeheld
Technology can assemble governed source data, map it to reporting fields, expose unresolved exceptions, enforce maker-checker approval and preserve the filed evidence.
Safeheld is a specialist regulatory technology platform for safeguarding reconciliation, regulatory reporting and compliance evidence. It is relevant where REP027 is assembled manually or cannot be traced directly to the reconciliations that produced its figures.
Regulatory Counsel can review scope, interpretation, governance and remediation. Safeheld supports the operational workflow. A firm should still apply accountable review and control the final submission.
Monthly REP027 checklist
- Confirm the reporting entity, period and deadline.
- Lock the approved month-end source snapshot.
- Confirm required reconciliations completed.
- Review open shortfalls, discrepancies and breaches.
- Populate fields from governed sources.
- Apply technical, arithmetic and reasonableness validation.
- Reconcile the draft with safeguarding records and board data.
- Obtain named approval of the exact submission version.
- Submit through the authorised FCA channel.
- Retain the return, receipt, validation and subsequent correspondence.
Get help with REP027
Regulatory Counsel's regulatory reporting practice can review the firm's REP027 interpretation, data ownership, controls and remediation. Safeheld can demonstrate the connected reconciliation and reporting evidence workflow.
Frequently Asked Questions
REP027 is the identifier used for the monthly safeguarding return required under SUP 16.14A for safeguarding institutions in scope.
It is generally due within 15 business days after the end of each calendar month, subject to the detailed application rule.
No. CMAR or FSA056 is a separate return for certain investment firms. REP027 relates to payment and e-money safeguarding institutions.
Yes. Reporting figures should be derived from and traceable to the governed safeguarding records. Any reporting-specific adjustment should be explicit and approved.
Data assembly, validation, workflow and evidence can be automated. The firm should retain accountable review, regulatory judgement and control of submission.
Official sources
This article provides general guidance. The requirements applicable to a firm depend on its permissions, products and arrangements.
Definitive guides on this topic
The permanent reference pages this article relates to.
Safeguarding and CASS 15
Safeguarding arrangements, reconciliations and the CASS 15 regime.
UK Electronic Money Institution licence
FCA EMI requirements, EUR 350,000 capital, safeguarding, cost and timeline.
UK Authorised Payment Institution licence
FCA API requirements, own funds methods, safeguarding, cost and timeline.