A CASS 10A resolution pack is the controlled set of documents and records needed to understand a safeguarding institution's relevant-funds arrangements if it fails or the regulator requests the information.
The pack must be maintained before a crisis. CASS 10A requires arrangements allowing the relevant office holder and the firm to retrieve each required document as soon as practicable and, in any event, within 48 hours in the specified circumstances. Important core documents should be immediately retrievable.
## Purpose of the resolution pack
The pack is designed to reduce delay and uncertainty after failure. An insolvency practitioner should not need to reconstruct the firm's safeguarding model from emails, staff knowledge and disconnected systems before identifying relevant funds and customers.
CASS 10A therefore requires a master document and supporting records that explain where relevant funds are held, which counterparties are involved, how the records operate and who can provide assistance.
The pack is a resolution control, not an ordinary compliance archive. Its quality is tested by whether an unfamiliar authorised person can retrieve and use the documents under pressure.
Who must maintain one?
CASS 10A applies to safeguarding institutions receiving or holding relevant funds in accordance with CASS 15, subject to the detailed application provisions.
Groups should identify the obligation by legal entity. A group member may hold a document in its own pack where the conditions in CASS 10A are met, but the safeguarding institution must still be able to deliver it within the required timeframe.
The firm should not assume that a group drive, outsourced provider or parent-company system satisfies the rule without testing post-insolvency access.
Core contents
The exact list should be checked against the current Handbook. Principal categories include:
| Category | Typical content |
|---|---|
| Master document | Index, location, access method and pack structure |
| Institutions and accounts | Safeguarding banks, custodians, account identifiers and details |
| Acknowledgement evidence | Required executed acknowledgement letters |
| Agreements | Relevant account, custody, insurance or guarantee documents |
| Third parties | Agents, distributors, processors and other material holders or managers |
| Procedures | Safeguarding methodology, records and reconciliation procedures |
| Key people | Individuals able to explain and operate the arrangements |
| Reconciliation evidence | Most recent internal and external reconciliation records |
| Systems | Information needed to access and interpret relevant records |
The pack should use legal names and account identifiers consistently with bank records and reconciliations. Ambiguous trading names or expired contact details slow resolution.
Immediate and 48-hour retrieval
CASS 10A.1.7R establishes the 48-hour outside limit for retrieving each document in the relevant circumstances. CASS 10A.1.9E identifies documents and records that should be immediately retrievable, including key institution information, acknowledgement letters, insurance or guarantee documentation where applicable, key individuals and the most recent reconciliation records.
“Immediately” and “within 48 hours” are not interchangeable targets. A firm should design its test around the faster expectation for core material and use 48 hours as the outside rule for the wider pack.
The test should also consider evenings, weekends, absence of key staff and loss of normal system access.
The five-business-day update rule
The pack must be reviewed on an ongoing basis. Where a change of circumstances makes prescribed content materially inaccurate, the firm must correct the inaccuracy promptly and no later than five business days after the change arose.
That makes event-driven ownership essential. Relevant triggers include a new safeguarding account, closed account, new custodian, changed acknowledgement letter, revised methodology, personnel change, new agent or changed system access.
A quarterly review can supplement this process but cannot reliably satisfy a five-business-day rule on its own.
The master document
The master document should make the pack usable. It should identify each required item, where it is stored, its owner, access instructions and the date or event that last validated it.
Avoid references that depend on one person's memory, such as “ask Finance for the latest version”. The pack should identify a role and an alternative contact, with access arrangements that survive absence or organisational change.
The master document should also explain relationships between entities, accounts and asset pools so the user does not confuse one licensed firm's funds with another's.
Acknowledgement letters and agreements
Executed acknowledgement letters and relevant account agreements are critical because they help establish the purpose and status of accounts. The pack should contain the final executed version, not an unsigned template or email requesting the bank's approval.
The account name, number, institution and legal entity should agree with the firm's live account inventory and reconciliation sources. Disagreement may indicate that the wrong account is being reconciled or that the pack is stale.
Insurance or guarantee documents should include the operative policy, coverage and relevant supporting information where that safeguarding method is used.
Reconciliation records
The most recent internal and external reconciliation records should be immediately retrievable. They need enough supporting information to show the safeguarding requirement, resource, third-party balances, open differences and review.
A summary total without source and exception context may not allow an office holder to understand the true position.
The pack should link to a stable export or record that remains available if the main application, identity provider or supplier access becomes unavailable.
Systems and post-insolvency access
CASS 10A guidance recognises that some component documents depend on systems continuing to operate. Firms should plan for access after insolvency rather than assume normal credentials, employees and supplier contracts remain available.
The plan should cover:
- system and data owners;
- privileged and emergency access;
- exports and backup locations;
- encryption keys or authentication dependencies;
- supplier contacts and contractual continuity;
- data formats and instructions; and
- tested recovery of the relevant evidence.
A cloud folder is not resilient if access depends on a disabled corporate identity account.
How to perform a retrieval test
A meaningful test should begin without pre-assembling the pack.
- Record the start time and triggering scenario.
- Ask an independent participant to use the master document.
- Retrieve immediate documents first.
- Retrieve every remaining prescribed item.
- Confirm versions against live accounts and records.
- Test access without the usual key operator.
- Record completion time and missing or stale items.
- Assign remediation with owners and deadlines.
- Retest failed components.
- report the outcome to the responsible senior manager.
The objective is not merely to beat 48 hours. It is to establish that the material is accurate, complete and understandable.
How Safeheld supports resolution readiness
Safeheld is a specialist regulatory technology platform for safeguarding reconciliation, regulatory reporting and compliance evidence. It can connect current reconciliation evidence, account information, owners and pack documents so that resolution material is maintained from the underlying control record.
Regulatory Counsel can review legal scope, contents, governance and remediation. Technology supports retrieval and evidence but does not remove the firm's responsibility to maintain accurate information.
Request a resolution-pack review
Regulatory Counsel's safeguarding practice can assess pack contents, update triggers, access and retrieval testing. Safeheld can demonstrate the linked operational evidence and pack workflow.
Frequently Asked Questions
It is the prescribed collection of documents and records intended to help an office holder, the firm or a regulator understand and retrieve safeguarding information promptly.
CASS 10A requires each document to be retrievable as soon as practicable and within 48 hours in the relevant circumstances. Specified core documents should be immediately retrievable.
A material inaccuracy caused by changed circumstances must be corrected promptly and no later than five business days after the change arose.
Potentially, where the detailed CASS 10A conditions are satisfied and the safeguarding institution can still meet the retrieval requirement.
No. The content must be reviewed on an ongoing basis and material inaccuracies are subject to a five-business-day correction limit.
Official sources
This article provides general guidance. The requirements applicable to a firm depend on its permissions, products and arrangements.
Definitive guides on this topic
The permanent reference pages this article relates to.
Safeguarding and CASS 15
Safeguarding arrangements, reconciliations and the CASS 15 regime.
UK Electronic Money Institution licence
FCA EMI requirements, EUR 350,000 capital, safeguarding, cost and timeline.
UK Authorised Payment Institution licence
FCA API requirements, own funds methods, safeguarding, cost and timeline.