Safeguarding

CASS 15 Reporting Requirements 2026: FCA Returns, Records and Management Information

Regulatory Counsel · Published August 2026 · Last reviewed August 2026 · 8 min read

CASS 15 reporting is not one reporting requirement.

For payment institutions and electronic money institutions, the strengthened safeguarding regime creates several connected information obligations.

Safeguarding institutions generally need to submit a monthly safeguarding return to the FCA. Their underlying CASS 15 records and reconciliations need to support that information. Specified failures can create immediate FCA notification obligations. Firms within SUP 3A also have independent safeguarding audit reporting, while senior management and governing bodies need sufficient internal information to oversee safeguarding properly.

The practical challenge is ensuring all of these outputs come from a consistent safeguarding record.

What is the CASS 15 monthly safeguarding return?

The monthly safeguarding return is established under SUP 16.14A.

It applies to safeguarding institutions and is intended to give the FCA regular and comprehensive information concerning their safeguarding of relevant funds.

The return is commonly referred to as REP027.

A safeguarding institution must generally submit the return within 15 business days after the end of each calendar month.

There is an exception for a month during which the firm first becomes a safeguarding institution.

The return is submitted electronically through the means made available by the FCA.

When is REP027 due?

The reporting period is a calendar month.

The safeguarding return must generally reach the FCA within 15 business days after that month ends.

This is a relatively short cycle.

A firm cannot wait until the reporting deadline to discover whether safeguarding information for the previous month is complete.

The underlying data, reconciliations and review process should already be operating as part of the firm's normal safeguarding control environment.

The reporting process should therefore be treated as a downstream output of daily safeguarding operations rather than an independent monthly compliance exercise.

Why did the FCA introduce monthly safeguarding reporting?

The FCA wants more regular information about the safeguarding position of payment and e-money firms.

Historically, weaknesses in safeguarding could persist without the regulator receiving sufficiently frequent structured information to identify the risk quickly.

Monthly reporting allows the FCA to receive recurring data about firms' safeguarding arrangements and potentially identify trends, inconsistencies or weaknesses earlier.

For firms, this increases the importance of consistency.

A number reported month after month can create a regulatory record against which later submissions, audit findings and supervisory information may be compared.

What information should support the safeguarding return?

The return should be prepared from reliable underlying safeguarding records.

Those records include the information through which the firm determines relevant funds, calculates its safeguarding requirement and resource and performs the applicable reconciliation processes.

The reporting team should be able to trace reported information back to controlled source records.

This is particularly important where the firm has multiple payment products, safeguarding banks, accounts, currencies, agents or e-money arrangements.

A manual reporting process can become difficult if information has to be collected from several teams every month and adjusted independently of the firm's reconciliation system.

How does CASS 15 reconciliation connect to reporting?

Reconciliation and reporting should tell the same story.

CASS 15 requires internal safeguarding reconciliation to test the firm's records concerning its safeguarding requirement and safeguarding resource.

External reconciliation compares relevant internal records with information from banks, custodians and other relevant parties.

Those controls provide critical evidence concerning the firm's safeguarding position.

If the monthly FCA return is prepared from a different dataset, discrepancies can arise between what the firm reported to the FCA and what its daily safeguarding records showed.

A strong reporting architecture therefore creates a clear connection between source data, reconciliation, adjustments, approvals and the final regulatory return.

CASS 15 reporting is more than REP027

The monthly return is important, but it is only one part of the reporting framework.

CASS 15 requires adequate operational oversight and reporting to the governing body.

CASS 10A also requires the governing body to receive a report concerning compliance with the resolution-pack requirements at least annually.

SUP 3A creates a separate safeguarding auditor report for relevant institutions within the audit regime.

CASS 15 also includes direct FCA notification requirements where specified material safeguarding failures occur.

A firm therefore needs to distinguish between:

  1. scheduled regulatory reporting
  2. immediate or event-driven FCA notifications
  3. independent auditor reporting
  4. internal senior-management information
  5. board reporting
  6. resolution-pack governance reporting

Treating all of these as one generic "reporting" process risks important obligations being missed.

When must a firm notify the FCA about CASS 15 problems?

CASS 15 contains specific circumstances requiring written notification to the FCA without delay.

These include specified situations where records and accounts become materially out of date, inaccurate or invalid, where the institution will be unable to or materially fails to conduct required internal safeguarding reconciliation and where it cannot appropriately address certain shortfalls or excess amounts.

Firms should review the complete notification rules against their circumstances rather than relying on these examples alone.

The operational implication is important.

A potential reporting trigger may first appear in the reconciliation process.

If reconciliation exceptions remain within an operations queue without regulatory escalation criteria, the compliance team may not learn about an issue quickly enough.

Exception management and regulatory notification therefore need to connect.

What management information should the safeguarding senior manager receive?

The individual responsible for operational safeguarding oversight needs information capable of demonstrating whether the framework is working.

Useful management information is likely to include:

safeguarding requirement and resource completion status of required reconciliations unresolved reconciliation breaks identified shortfalls and excesses ageing of exceptions material data-quality issues safeguarding bank and third-party issues regulatory returns and submission status potential FCA notifications audit findings remediation actions resolution-pack status

The exact dashboard should reflect the institution's scale and complexity.

The purpose is not to create the largest possible report.

It is to ensure that the responsible senior person can identify a safeguarding problem early enough to act.

What should the board see?

Board information should be concise enough to support decision-making while sufficiently detailed to expose meaningful risk.

A board should not need to review every reconciliation break.

It should, however, understand whether required reconciliations are being completed, whether significant exceptions remain unresolved, whether relevant funds are protected, whether returns have been submitted correctly and whether audit or supervisory issues require action.

Trends are particularly useful.

A growing number of manual adjustments or ageing exceptions can signal deterioration even if the headline safeguarding position remains balanced at each reporting date.

Good CASS 15 reporting therefore focuses on the quality of the control environment as well as the final numbers.

Why manual REP027 preparation creates risk

Manual regulatory reporting is not automatically non-compliant.

The risk arises when information is repeatedly re-keyed, transformed or adjusted outside the controlled safeguarding record.

Every manual step can create a difference between the firm's operational position and its regulatory submission.

This also makes review harder.

A reviewer needs to determine not only whether the final return looks reasonable but also whether it can be traced back to the underlying books and records.

As transaction volumes and complexity increase, automation can materially reduce this burden.

How Safeheld supports CASS 15 reporting

Safeheld connects safeguarding reconciliation, exception handling, regulatory reporting, resolution packs and audit evidence within a common client-funds assurance environment.

For CASS 15 reporting, the principal advantage is the ability to derive regulatory information from the same underlying control record used to reconcile and monitor safeguarded funds.

This can reduce repeated data assembly and create a clearer trail between the reported number and the underlying evidence.

Safeheld can also support monitoring and escalation around safeguarding exceptions before those issues become reporting problems.

The regulated firm should still retain appropriate review, approval and submission governance.

Automation can prepare and evidence information. It does not transfer regulatory accountability away from the institution.

When does regulatory advisory support become useful?

Some reporting problems are actually symptoms of a deeper safeguarding issue.

For example, a firm may be unable to complete its monthly return confidently because its definition of relevant funds is unclear, its reconciliation methodology is inconsistent with its actual payment flows or historical records contain unexplained adjustments.

In those circumstances, automating the report alone will not solve the problem.

Buckingham Capital Consulting provides specialist CASS 15 and safeguarding advisory support, including regulatory reporting reviews, reconciliation methodology, policies, audit readiness, gap analysis and remediation.

The appropriate sequence is usually to establish the correct regulatory treatment, fix the underlying control where necessary and then automate the recurring process.

CASS 15 reporting controls firms should implement

A practical reporting framework should answer the following questions:

  1. Who owns preparation of the monthly safeguarding return?
  2. Which systems and records provide each reported field?
  3. How is reported information reconciled to the safeguarding records?
  4. Who reviews the return?
  5. Who approves submission?
  6. How is evidence of review retained?
  7. How are late or incomplete source records escalated?
  8. How are potential CASS 15 notification events identified?
  9. How are differences between reporting periods explained?
  10. How are corrections handled?
  11. Do audit records and regulatory returns use consistent information?
  12. Can the senior safeguarding owner see the reporting status at any time?

These controls should operate each month rather than being reconstructed shortly before the deadline.

Reporting should emerge from the safeguarding system

The most resilient CASS 15 reporting model is one in which the regulatory return is the output of a controlled safeguarding process.

The firm identifies relevant funds correctly.

It performs and evidences reconciliation.

It investigates discrepancies.

It records adjustments and remediation.

It escalates issues where required.

The resulting information then flows into regulatory reporting and management oversight.

When firms reverse that process and build the regulatory return first, significant manual work is usually required to make the underlying evidence support it afterwards.

For the FCA, auditors and boards, the underlying evidence matters just as much as the final submitted form.

Frequently Asked Questions

REP027 is the FCA safeguarding return used under the strengthened payment and e-money safeguarding reporting regime.

A safeguarding institution must generally submit a safeguarding return for each calendar month.

Under SUP 16.14A, the return must generally be submitted within 15 business days after the end of the relevant calendar month.

Yes. CASS 15 contains specific circumstances in which a safeguarding institution must notify the FCA in writing without delay, including certain material failures concerning records, reconciliation and correction of safeguarding discrepancies.

Yes. Specialist technology such as Safeheld can support generation and evidence of safeguarding regulatory information from the same underlying data used for reconciliation and exception management. The regulated institution remains responsible for review, accuracy and regulatory submission.

Need Expert Advice?

Free initial consultation. No obligation.

Speak to an Expert