Safeguarding

FCA Safeguarding Software: A PS25/12 Buyer's Guide

Regulatory Counsel · Published August 2026 · Last reviewed August 2026 · 11 min read

Key Takeaways

  • The interim safeguarding regime set out in PS25/12 and the CASS 15 sourcebook raises the evidential standard on records, reconciliation and resolution of discrepancies.
  • Spreadsheet-based reconciliation is not prohibited, but it is increasingly difficult to evidence to the standard an auditor and the FCA now expect.
  • The core software requirements are a complete relevant funds record, daily internal and external reconciliation, exception management with an audit trail, and reporting that can be reproduced for any historic date.
  • Software supports compliance. It does not discharge it. Governance, senior manager accountability and the safeguarding audit remain the firm's responsibility.
  • Selection should be tested against the firm's own flows, including agent, distributor and multi-currency arrangements, not against a generic demonstration.
Data centre aisle in cool blue light representing safeguarding and reconciliation systems infrastructure for payment firms

The FCA's policy statement PS25/12 introduced an interim safeguarding regime for payment institutions and e-money institutions, delivered through a new CASS 15 sourcebook. It does not change the underlying statutory obligation to safeguard relevant funds. It changes the standard of evidence required to show that the obligation is being met, and it makes weak record keeping and reconciliation visible far more quickly.

That has driven a wave of firms reassessing whether spreadsheet-based safeguarding processes remain defensible, and what a purpose-built safeguarding or reconciliation platform actually needs to do.

What changed, and why tooling is now in scope

The interim regime tightens three things in particular.

Records and accounts. Firms are expected to maintain records sufficient to identify, at any point in time, the relevant funds held for each customer and the assets held to cover them, and to enable an insolvency practitioner to distribute funds promptly.

Reconciliation. Internal reconciliation of the safeguarding records against the firm's own books, and external reconciliation against third-party statements, on a defined and frequent basis, with any shortfall funded and any excess withdrawn on the same day where required.

Evidence and reporting. Discrepancies must be identified, investigated, escalated and resolved, with a record of each step, and the firm must be able to reproduce the position as at a historic date.

None of that mandates software. All of it is materially harder to evidence without it. Our PS25/12 safeguarding compliance checklist and our guide to safeguarding reconciliation and reporting under the new FCA rules cover the underlying obligations in detail.

Where spreadsheet processes break down

Version control. A reconciliation performed in a workbook that has since been edited cannot be reproduced reliably.

Manual matching. High transaction volumes across multiple currencies and multiple safeguarding accounts create matching error rates that scale with volume.

Timing. Same-day identification and funding of a shortfall is difficult where the reconciliation is completed manually on a lag.

Segregation of duties. Preparer and reviewer controls in a shared workbook are assertions rather than system-enforced controls.

Audit evidence. The safeguarding audit requires evidence of what was done, by whom and when. Email trails and file naming conventions are a weak substitute for an immutable log.

The functional requirements checklist

When evaluating safeguarding or reconciliation software, test it against the following.

Records and data model

  • A relevant funds record at customer level, not only at aggregate level.
  • Correct treatment of funds received, funds becoming relevant funds, and funds ceasing to be relevant funds, with the timing rules applied.
  • Multi-currency support with a defined revaluation approach.
  • Handling of funds held through agents, distributors and partner arrangements.
  • Ability to reproduce the complete position as at any historic date.

Reconciliation engine

  • Internal reconciliation against the firm's ledger and external reconciliation against bank, custodian and insurer records.
  • Automated ingestion of statements and transaction files, with tolerance for format variation.
  • Configurable matching rules, with unmatched items surfaced rather than absorbed.
  • Same-day calculation of shortfall or excess, with the required funding action clearly identified.

Exception management and controls

  • Workflow for investigation, escalation and sign-off, with system-enforced segregation between preparer and approver.
  • Ageing of unresolved discrepancies with escalation thresholds.
  • Immutable audit trail covering every change, with user, timestamp and reason.
  • Role-based access control and least-privilege administration.

Reporting and audit

  • Reporting aligned to the reconciliation and record keeping requirements, exportable for the safeguarding audit.
  • Board and senior manager reporting: discrepancy volumes, ageing, funding events and resolution times.
  • Read-only auditor access with evidence packs that can be produced without manual reconstruction.

Operational resilience and vendor risk

  • Documented recovery time and recovery point objectives, and evidence of testing.
  • Data location, encryption, retention and deletion terms.
  • Exit provisions, including a full data export in a usable format.
  • Where the provider is material to an important business service, treatment within the firm's outsourcing and operational resilience framework under SYSC 8.

What software cannot do

Three points are worth stating plainly, because they are where firms get into difficulty.

It does not create the legal analysis. Whether particular funds are relevant funds, when they become so, and how a specific commercial arrangement is characterised are legal and regulatory questions. A platform applies the configuration it is given.

It does not discharge senior manager accountability. The relevant senior manager must be able to evidence reasonable steps, including oversight of how the tool is configured, what its exception reports show, and what was done in response.

It does not replace the audit. Firms within scope must obtain a safeguarding audit. Good tooling shortens the audit and reduces findings; it does not remove the requirement. See our guide to safeguarding audits and PS25/12 EMI requirements.

Software partner

Firms looking specifically at purpose-built safeguarding and reconciliation tooling for the UK regime should look at SafeHeld, a safeguarding and reconciliation software provider whose product is built around the UK CASS 15 and PS25/12 requirements, including daily internal and external reconciliation, exception workflow and audit-ready evidence packs.

Regulatory Counsel works alongside software providers on the regulatory side of implementation: confirming the relevant funds analysis, defining the reconciliation methodology, drafting the safeguarding policy and procedures the system operates under, and preparing the firm for the safeguarding audit. We are independent of any provider and advise on selection against the firm's own flows.

A practical selection process

  1. Document the firm's actual money flows, including agents, partners, currencies and settlement timings, before speaking to any provider.
  2. Define the reconciliation methodology and the relevant funds analysis first, so that the tool is configured to a decided position rather than deciding it.
  3. Test candidate platforms against a sample of the firm's own historic data, including a period containing a known discrepancy.
  4. Require the provider to demonstrate reproduction of a historic reconciliation, not only a live dashboard.
  5. Involve the safeguarding auditor early on evidence format.
  6. Complete outsourcing due diligence under SYSC 8, including exit planning.
  7. Run parallel operation before decommissioning the existing process, and retain the historic records.

About Regulatory Counsel

Regulatory Counsel advises UK and international payment institutions, e-money institutions and cryptoasset firms on safeguarding, authorisation, financial crime and regulator engagement.

Our safeguarding work covers relevant funds analysis, safeguarding policy and procedure design, reconciliation methodology, readiness for the safeguarding audit, remediation of audit findings, and independent advice on safeguarding technology selection and implementation.

Contact our regulatory team at info@regulatorycounsel.co.uk.

This article is provided for general information and does not constitute legal or regulatory advice. Firms should confirm the current position against FCA publications and take advice on their specific circumstances.

Frequently Asked Questions

No. The rules require outcomes: accurate records, frequent internal and external reconciliation, prompt resolution of discrepancies and evidence of all of it. Software is not mandated, but meeting the evidential standard manually at volume is difficult.

CASS 15 is the client assets sourcebook chapter introduced through PS25/12 for the interim safeguarding regime applying to payment institutions and e-money institutions, covering records and accounts, reconciliation, resolution of discrepancies and related requirements.

It is not prohibited, but spreadsheets struggle with version control, system-enforced segregation of duties, same-day discrepancy identification at volume, and reproducing a historic reconciliation for audit.

A customer-level relevant funds record, daily internal and external reconciliation, calculation of shortfall or excess, an exception workflow with approvals, an immutable audit trail, and reproduction of the position as at any historic date.

Well-configured tooling generally shortens the audit and reduces evidential findings, but it does not remove the audit requirement or cure an incorrect relevant funds analysis.

Where the provider supports a function relevant to regulatory obligations, the firm should apply its outsourcing framework under SYSC 8, including due diligence, a written agreement, oversight, resilience assessment and exit planning.

Need Expert Advice?

Free initial consultation. No obligation.

Speak to an Expert