CASS 15 has created a fundamentally more data-intensive safeguarding environment for payment institutions and electronic money institutions.
Firms need to perform regular internal and external safeguarding reconciliations, identify and resolve discrepancies, maintain detailed records, prepare monthly regulatory information, support independent safeguarding audits and keep a continuously accurate CASS resolution pack.
For firms operating significant payment volumes across multiple accounts, currencies, entities or safeguarding partners, managing these obligations through spreadsheets and disconnected files can become both expensive and fragile.
CASS 15 software can automate much of the operational work. The more important question is what the software actually needs to do.
What is CASS 15 software?
CASS 15 software is technology used by payment and electronic money firms to operate, monitor and evidence safeguarding controls under the FCA's strengthened relevant funds regime.
At its simplest, the software should help a firm determine what it owes to clients, compare that position with the resources that have been safeguarded and identify any difference.
A more complete system should connect that reconciliation process to exception management, evidence, governance, regulatory reporting, audit and resolution planning.
This matters because CASS 15 compliance is not achieved by producing a single correct number.
The regulated firm needs evidence showing how that number was produced, what information was used, when controls were performed, what discrepancies arose, who investigated them and how problems were resolved.
Why spreadsheets become difficult under CASS 15
Spreadsheets are not prohibited by CASS 15.
For a very small and simple business, carefully controlled spreadsheets may remain workable.
The problem is operational scale.
A firm may need to combine customer ledger information, payment transaction data, safeguarding bank balances, asset information, data from agents or distributors and information from multiple currencies and accounts.
It then needs to perform the required reconciliations, investigate unmatched positions, document actions, retain evidence, produce management information and use the same underlying data for regulatory reporting and audit.
If each stage operates through a different spreadsheet or manual process, the firm can end up with several versions of its safeguarding position.
The risk is not simply human error. It is the absence of a reliable single evidential chain between the transaction, reconciliation, exception, resolution and regulatory output.
What should good CASS 15 software do?
A strong CASS 15 system should support the complete operational control cycle rather than merely matching two balances.
That should include:
- ingestion of reliable source data
- identification and calculation of the relevant safeguarding population
- internal safeguarding reconciliation
- external safeguarding reconciliation
- exception identification
- investigation workflow
- evidence and audit trail
- escalation of potentially material issues
- regulatory reporting support
- resolution-pack maintenance
- management and board information
- retention of the underlying record
The precise architecture will depend on the firm's business model.
An EMI processing high transaction volumes across multiple currencies will have different operational needs from a smaller payment institution with a limited number of safeguarding accounts.
The regulatory objective, however, is the same: the firm should be able to demonstrate that its relevant funds are properly protected and that its controls work consistently.
CASS 15 software and internal safeguarding reconciliation
Internal safeguarding reconciliation is more than a comparison between the customer ledger and a bank balance.
The firm's internal records need to support calculation of its safeguarding requirement and safeguarding resource in accordance with the applicable methodology.
The system therefore needs reliable information about the underlying client position.
It should also preserve the reconciliation point and record when the process was performed, what actions were taken and what the outcome was.
Automating the calculation without preserving the evidence can solve an operational problem while leaving a compliance problem behind.
The strongest systems treat the reconciliation as a controlled regulatory process, not simply an accounting calculation.
CASS 15 software and external reconciliation
External safeguarding reconciliation checks the firm's internal records against information obtained from the institutions holding relevant funds or relevant assets.
That may involve multiple banks, accounts, currencies, custodians or other parties.
Automation can substantially reduce the manual matching burden, particularly where transaction volumes are high.
The technology should nevertheless make source provenance clear.
A user, auditor or regulator should be able to understand which external record was used, the period to which it related, which internal position it was compared against and what happened to any resulting difference.
A system that automatically forces transactions to match without a transparent reasoning trail may reduce visible exceptions without improving the underlying safeguarding control.
Exception management is as important as matching
Most reconciliation systems can identify transactions that match.
The more important question is what happens when they do not.
An unexplained difference may result from timing, missing data, an incorrect ledger entry, an unexpected bank movement, a payment-processing problem or a genuine safeguarding shortfall.
CASS 15 software should therefore provide a controlled exception workflow.
The firm should be able to identify the break, assign or investigate it, attach relevant evidence, record the explanation, track remediation and escalate an issue where required.
This produces something far more useful than a spreadsheet cell marked "resolved".
It creates evidence showing why the firm concluded that the issue was resolved.
Can CASS 15 software help with FCA breach detection?
Technology can help identify conditions that may require escalation.
The FCA rules include circumstances in which a safeguarding institution must notify the FCA in writing without delay, including specified material failures involving records, reconciliations or correction of relevant shortfalls and excesses.
A compliance platform can help by identifying missed reconciliations, unresolved discrepancies, safeguarding deficits or other predetermined indicators.
The final regulatory decision should not necessarily be delegated to software.
Materiality, context and the precise FCA notification requirement may require senior compliance or legal judgement.
A useful system therefore combines automated detection with a controlled human escalation process.
CASS 15 software and REP027 reporting
Safeguarding institutions are generally required to submit their FCA safeguarding return within 15 business days of each month end.
Monthly reporting creates a direct connection between operational data quality and regulatory reporting.
If the reconciliation system and reporting process use different datasets, finance and compliance may spend substantial time explaining why the numbers differ.
A better architecture allows the reporting output to be generated from, or demonstrably reconciled to, the same controlled source data used to operate safeguarding.
This can reduce manual preparation and the risk of inconsistencies between internal records and the information submitted to the FCA.
Technology should support the return, validation and evidence process while leaving the firm with appropriate review and approval controls before submission.
CASS 15 software and resolution packs
CASS 10A requires a safeguarding institution to maintain a CASS resolution pack while it receives or holds relevant funds in accordance with CASS 15.
The pack contains both relatively static documents and information that changes as the business operates.
That creates a maintenance problem.
If the pack exists as a folder that compliance updates periodically, changes to safeguarding accounts, third parties, responsibilities, policies or reconciliation records can cause it to become stale.
CASS 10A specifically requires ongoing review and prompt correction of material inaccuracies.
Technology can help by connecting live safeguarding records with the documents and information required for resolution purposes.
The objective should be resolution-pack readiness rather than periodic resolution-pack creation.
CASS 15 software and safeguarding audits
For firms within SUP 3A, the external auditor must prepare a reasonable-assurance safeguarding report addressed to the FCA.
The auditor is concerned not only with the firm's position on a single date but with whether adequate systems were maintained throughout the reporting period.
That makes continuous evidence valuable.
A platform that preserves reconciliation runs, source data, exceptions, investigation records, remediation and approvals can materially simplify the process of producing audit evidence.
It cannot guarantee a clean audit opinion.
It can, however, reduce the need to reconstruct a year's worth of operational evidence after the year has ended.
What does Safeheld provide for CASS 15?
Safeheld is a specialist client-funds assurance platform designed to connect reconciliation, breach detection, regulatory reporting, resolution packs and audit evidence within a common control environment.
For payment and e-money firms, Safeheld can ingest source information, perform and evidence safeguarding reconciliation, surface exceptions, preserve investigation history and support downstream regulatory outputs.
The commercial value is not simply automation.
It is the ability to reduce the number of disconnected records through which a firm tries to prove the same safeguarding position.
A firm evaluating Safeheld or any CASS 15 software should test the product against its own actual money flows, ledger architecture, safeguarding accounts, currencies, exception types and reporting process before implementation.
What CASS 15 software cannot replace
Technology should not be treated as a substitute for a compliant safeguarding framework.
The firm still needs to determine what constitutes relevant funds, choose the correct safeguarding method, establish appropriate policies, appoint and oversee relevant third parties, define governance and escalation arrangements and satisfy itself that the reconciliation methodology is appropriate.
These can require regulatory judgement.
Where the underlying framework needs to be designed, reviewed or remediated, firms can obtain specialist CASS 15 advisory support from Buckingham Capital Consulting.
The strongest model is therefore not software instead of compliance expertise.
It is sound regulatory design combined with reliable operational infrastructure.
Questions to ask when choosing CASS 15 software
Before selecting a platform, a firm should ask:
- Can it model our actual relevant funds population?
- Can it perform and separately evidence internal and external safeguarding reconciliations?
- Can we see exactly which source records produced each result?
- How are unmatched items investigated and approved?
- Is there a complete history of changes and decisions?
- Can potential breaches and shortfalls be escalated?
- Can monthly reporting be generated from the same controlled data?
- Can the system support our CASS resolution pack?
- Can auditors retrieve clear evidence covering the full reporting period?
- Can the system handle our transaction volumes, currencies and safeguarding partners?
- What happens when source data is late or incomplete?
- Can the firm export its records independently of the supplier?
The last point is particularly important.
Regulatory evidence belongs to the regulated institution. A compliance system should make that evidence more accessible, not create a new dependency that makes it harder to retrieve.
The objective is continuous evidence
The strongest reason to adopt CASS 15 software is not that the FCA requires firms to buy software. It does not.
The reason is that the regime requires a level of recurring operational control and evidence that becomes progressively harder to manage through disconnected manual processes as complexity grows.
A good system should allow management to move from asking, "Did we complete the spreadsheet?" to asking, "Can we prove our safeguarding position and the operation of our controls?"
That is the standard firms should use when assessing CASS 15 technology.
Frequently Asked Questions
CASS 15 software is technology used to support payment and electronic money firms with safeguarding controls such as reconciliation, exception management, evidence, regulatory reporting, audit support and resolution-pack maintenance.
No. The FCA rules specify the safeguarding outcomes, controls, records and processes that firms must maintain. They do not require firms to purchase a particular technology product.
Yes. Internal and external reconciliation can be substantially automated where reliable source data is available. The firm remains responsible for the methodology, oversight, investigation of discrepancies and regulatory compliance.
Safeheld is a specialist client-funds assurance platform covering reconciliation, breach detection, regulatory reporting, resolution packs and audit evidence, including support for firms operating under the FCA safeguarding regime.
No. Software can operate and evidence controls, but regulatory judgement may still be required when defining the safeguarding perimeter, designing the methodology, reviewing policies, addressing audit findings or conducting remediation.