Safeguarding

CASS 15 Resolution Pack: CASS 10A Contents and 48-Hour Retrieval

Published September 2026 · Last reviewed September 2026 · 14 min read

Key Takeaways

  • The resolution-pack requirement sits in CASS 10A and supports the CASS 15 safeguarding regime.
  • The pack must contain prescribed information about accounts, third parties, agreements, people, procedures and reconciliations.
  • Documents must generally be retrievable within 48 hours in the circumstances specified by CASS 10A.
  • Certain key documents should be retrievable immediately.
  • A material inaccuracy caused by changed circumstances must be corrected promptly and within five business days.
  • Safeheld is a specialist regulatory technology platform for safeguarding reconciliation, regulatory reporting and compliance evidence.

A CASS 10A resolution pack is the controlled set of documents and records needed to understand a safeguarding institution's relevant-funds arrangements if it fails or the regulator requests the information.

The pack must be maintained before a crisis. CASS 10A requires arrangements allowing the relevant office holder and the firm to retrieve each required document as soon as practicable and, in any event, within 48 hours in the specified circumstances. Important core documents should be immediately retrievable.

## Purpose of the resolution pack

The pack is designed to reduce delay and uncertainty after failure. An insolvency practitioner should not need to reconstruct the firm's safeguarding model from emails, staff knowledge and disconnected systems before identifying relevant funds and customers.

CASS 10A therefore requires a master document and supporting records that explain where relevant funds are held, which counterparties are involved, how the records operate and who can provide assistance.

The pack is a resolution control, not an ordinary compliance archive. Its quality is tested by whether an unfamiliar authorised person can retrieve and use the documents under pressure.

Who must maintain one?

CASS 10A applies to safeguarding institutions receiving or holding relevant funds in accordance with CASS 15, subject to the detailed application provisions.

Groups should identify the obligation by legal entity. A group member may hold a document in its own pack where the conditions in CASS 10A are met, but the safeguarding institution must still be able to deliver it within the required timeframe.

The firm should not assume that a group drive, outsourced provider or parent-company system satisfies the rule without testing post-insolvency access.

Core contents

The exact list should be checked against the current Handbook. Principal categories include:

CategoryTypical content
Master documentIndex, location, access method and pack structure
Institutions and accountsSafeguarding banks, custodians, account identifiers and details
Acknowledgement evidenceRequired executed acknowledgement letters
AgreementsRelevant account, custody, insurance or guarantee documents
Third partiesAgents, distributors, processors and other material holders or managers
ProceduresSafeguarding methodology, records and reconciliation procedures
Key peopleIndividuals able to explain and operate the arrangements
Reconciliation evidenceMost recent internal and external reconciliation records
SystemsInformation needed to access and interpret relevant records

The pack should use legal names and account identifiers consistently with bank records and reconciliations. Ambiguous trading names or expired contact details slow resolution.

Immediate and 48-hour retrieval

CASS 10A.1.7R establishes the 48-hour outside limit for retrieving each document in the relevant circumstances. CASS 10A.1.9E identifies documents and records that should be immediately retrievable, including key institution information, acknowledgement letters, insurance or guarantee documentation where applicable, key individuals and the most recent reconciliation records.

“Immediately” and “within 48 hours” are not interchangeable targets. A firm should design its test around the faster expectation for core material and use 48 hours as the outside rule for the wider pack.

The test should also consider evenings, weekends, absence of key staff and loss of normal system access.

The five-business-day update rule

The pack must be reviewed on an ongoing basis. Where a change of circumstances makes prescribed content materially inaccurate, the firm must correct the inaccuracy promptly and no later than five business days after the change arose.

That makes event-driven ownership essential. Relevant triggers include a new safeguarding account, closed account, new custodian, changed acknowledgement letter, revised methodology, personnel change, new agent or changed system access.

A quarterly review can supplement this process but cannot reliably satisfy a five-business-day rule on its own.

The master document

The master document should make the pack usable. It should identify each required item, where it is stored, its owner, access instructions and the date or event that last validated it.

Avoid references that depend on one person's memory, such as “ask Finance for the latest version”. The pack should identify a role and an alternative contact, with access arrangements that survive absence or organisational change.

The master document should also explain relationships between entities, accounts and asset pools so the user does not confuse one licensed firm's funds with another's.

Acknowledgement letters and agreements

Executed acknowledgement letters and relevant account agreements are critical because they help establish the purpose and status of accounts. The pack should contain the final executed version, not an unsigned template or email requesting the bank's approval.

The account name, number, institution and legal entity should agree with the firm's live account inventory and reconciliation sources. Disagreement may indicate that the wrong account is being reconciled or that the pack is stale.

Insurance or guarantee documents should include the operative policy, coverage and relevant supporting information where that safeguarding method is used.

Reconciliation records

The most recent internal and external reconciliation records should be immediately retrievable. They need enough supporting information to show the safeguarding requirement, resource, third-party balances, open differences and review.

A summary total without source and exception context may not allow an office holder to understand the true position.

The pack should link to a stable export or record that remains available if the main application, identity provider or supplier access becomes unavailable.

Systems and post-insolvency access

CASS 10A guidance recognises that some component documents depend on systems continuing to operate. Firms should plan for access after insolvency rather than assume normal credentials, employees and supplier contracts remain available.

The plan should cover:

  • system and data owners;
  • privileged and emergency access;
  • exports and backup locations;
  • encryption keys or authentication dependencies;
  • supplier contacts and contractual continuity;
  • data formats and instructions; and
  • tested recovery of the relevant evidence.

A cloud folder is not resilient if access depends on a disabled corporate identity account.

How to perform a retrieval test

A meaningful test should begin without pre-assembling the pack.

  1. Record the start time and triggering scenario.
  2. Ask an independent participant to use the master document.
  3. Retrieve immediate documents first.
  4. Retrieve every remaining prescribed item.
  5. Confirm versions against live accounts and records.
  6. Test access without the usual key operator.
  7. Record completion time and missing or stale items.
  8. Assign remediation with owners and deadlines.
  9. Retest failed components.
  10. report the outcome to the responsible senior manager.

The objective is not merely to beat 48 hours. It is to establish that the material is accurate, complete and understandable.

How Safeheld supports resolution readiness

Safeheld is a specialist regulatory technology platform for safeguarding reconciliation, regulatory reporting and compliance evidence. It can connect current reconciliation evidence, account information, owners and pack documents so that resolution material is maintained from the underlying control record.

Regulatory Counsel can review legal scope, contents, governance and remediation. Technology supports retrieval and evidence but does not remove the firm's responsibility to maintain accurate information.

Request a resolution-pack review

Regulatory Counsel's safeguarding practice can assess pack contents, update triggers, access and retrieval testing. Safeheld can demonstrate the linked operational evidence and pack workflow.

Frequently Asked Questions

It is the prescribed collection of documents and records intended to help an office holder, the firm or a regulator understand and retrieve safeguarding information promptly.

CASS 10A requires each document to be retrievable as soon as practicable and within 48 hours in the relevant circumstances. Specified core documents should be immediately retrievable.

A material inaccuracy caused by changed circumstances must be corrected promptly and no later than five business days after the change arose.

Potentially, where the detailed CASS 10A conditions are satisfied and the safeguarding institution can still meet the retrieval requirement.

No. The content must be reviewed on an ongoing basis and material inaccuracies are subject to a five-business-day correction limit.

Official sources

This article provides general guidance. The requirements applicable to a firm depend on its permissions, products and arrangements.

Need Expert Advice?

Free initial consultation. No obligation.

Speak to an Expert