Safeguarding

Multi-Jurisdiction Safeguarding Compliance for Payment Firms

Published September 2026 · Last reviewed September 2026 · 12 min read

Key Takeaways

  • A group holding several payment or e-money licences must satisfy each regulator separately. There is no mutual recognition of safeguarding compliance between jurisdictions.
  • Three approaches exist in practice: separate processes per entity, one global process built to the strictest standard, or one record generating each jurisdiction's outputs.
  • Separate processes per entity is the most common and the least defensible at scale, because nobody can state the group's position without reconciling several sets of records first.
  • Building to the strictest standard is defensible but does not remove the jurisdiction-specific outputs each regulator requires.
  • Scope is defined differently by different regulators. The UK and Singapore define it by licence category, Canada by payment function performed, Hong Kong by facility type with no size threshold.
  • Supervisors increasingly ask group-level questions of entity-level arrangements. A firm that cannot answer at group level has a governance problem, not just a reporting one.
  • General information, not legal advice.

A firm holding one payment licence has one safeguarding process. A firm holding five has a choice to make, and most make it by accident.

The default is that each entity builds its own arrangement to satisfy its own regulator, using whatever systems that team already had. It works, entity by entity. What it does not produce is a group position anyone can state without a week of reconciliation, and that is what boards, auditors and increasingly supervisors ask for.

This article sets out the three approaches, what each costs, and where each breaks.

Why is there no mutual recognition?

Safeguarding is a domestic protection. Each regulator is protecting the customers of the entity it authorises, using the mechanism its own law provides.

That has three consequences.

Compliance in one jurisdiction confers nothing in another. A UK entity's CASS 15 compliance is not evidence to the Bank of Canada, MAS or the HKMA. Each requires its own arrangement, its own records and its own reporting.

Scope is not consistent. The UK and Singapore define scope by licence category. Canada defines it by payment function performed, which can bring an entity into scope that holds no equivalent licence elsewhere. Hong Kong applies its regime to stored value facility business with no de minimis threshold. A group cannot assume that an entity in scope in one jurisdiction is in scope in another.

The insolvency analysis is entity-level. Safeguarding exists for the failure case, and failure is resolved entity by entity under the insolvency law of that jurisdiction. Group-level arrangements do not change what happens to a single entity's customers.

This is why a group cannot consolidate safeguarding the way it consolidates accounts. Our guide to safeguarding requirements by jurisdiction sets out how far the regimes diverge.

What are the three approaches?

Separate processesOne global standardOne record, many outputs
How it worksEach entity runs its own process to its own regulator's rulesGroup applies the strictest regime's requirements everywhereOne record of funds, accounts and movements; each jurisdiction's outputs generated from it
Cost to buildLow, usually already doneHighHigh
Cost to operateHigh and rising with each licenceHighLow
Group positionRequires reconciliation to stateConsistent standard, separate outputsAvailable on demand
Scales past four licencesPoorlyWith costYes
Typical adopterGroups that grew by acquisitionLarge groups with strong central complianceGroups building deliberately

Approach one: separate processes per entity

Each regulated entity maintains its own safeguarding arrangement, its own reconciliation, its own records and its own reporting, designed against its own regulator's requirements.

Where it works. Every entity is compliant on its own terms. Local teams understand their own regulator. Nothing depends on a central function that may not understand a local rule.

Where it breaks. Four places, and they compound.

Nobody can state the group position. Asked how much customer money the group safeguards, the answer requires collecting figures from several systems on different cycles with different definitions, and it arrives days later.

Definitions drift. Each entity interprets its own regulator's definition of protected funds. Over time the group has several inconsistent treatments of the same commercial arrangement, and nobody notices until an auditor compares them.

Cost grows linearly with licences. Every new jurisdiction is a new process, a new system and new headcount.

Evidence standards diverge. One entity produces resolution-pack-grade records because its regulator demands it; another produces a spreadsheet because its regulator does not. The inconsistency is visible to any auditor looking across the group.

Approach two: one global standard

The group identifies the most demanding regime it is subject to and applies those requirements everywhere.

In practice this usually means building to UK CASS 15: reconciliation on each reconciliation day, evidence produced as controls operate, records retrievable at insolvency-pack standard, and annual independent audit.

Where it works. Controls, evidence and governance are consistent. Local teams operate one process. A new licence is a configuration rather than a build. And where a regulator raises a question, the answer is that the group operates to a higher standard than that regulator requires, which is a good position to be in.

Where it breaks. Two places.

It does not remove the jurisdiction-specific outputs. Each regulator still requires its own return, in its own format, on its own cycle. Building to the highest standard produces better underlying figures; it does not produce a Canadian annual report.

It is expensive where it is unnecessary. A small entity in a light-touch jurisdiction carries UK-grade cost for protection its own regulator does not require. That is a commercial judgement rather than a compliance failure, but it is a real cost.

Approach three: one record, many outputs

The group maintains a single record of customer funds, safeguarding accounts and movements across every entity, and generates each jurisdiction's reconciliation, return and evidence from that record according to that regime's rules.

The record is one. The outputs are many, and each is correct for its own regulator.

What it requires. Three things that are harder than they sound.

The record must hold the jurisdiction-specific concepts, not a lowest common denominator. A single field called "protected funds" is not sufficient where the UK protects relevant funds, Canada protects end-user funds held at rest and Hong Kong protects float. The record has to carry the facts from which each definition can be derived.

The reconciliation logic must be per-regime. The UK's reconciliation day calendar and Canada's requirement to track three fund figures are different rules applied to the same underlying data.

Evidence must be produced as controls operate rather than assembled per jurisdiction. A record that satisfies the UK's 48-hour resolution pack requirement satisfies every lighter requirement automatically, provided the evidence is captured once, at the time.

Where it works. The group position is available on demand. Adding a licence adds a rule set, not a process. Definitions cannot drift because there is one record. And the evidential standard is uniform, so no entity is the weak one.

Where it breaks. It requires building or buying infrastructure that does this, and most general reconciliation software does not. A configurable engine can be made to reconcile anything; it does not know what a reconciliation day is, or that Canadian end-user funds held at rest are a different population from UK relevant funds.

What do supervisors expect of a group?

Supervisory practice is moving toward group-level questions asked of entity-level arrangements.

Three questions recur, and a group should be able to answer each without a project.

How much customer money does the group hold, and where? Asked in supervisory meetings and by safeguarding auditors. A group that needs a week to answer has told the supervisor something about its control environment.

Is the treatment of the same arrangement consistent across entities? Where one entity treats a commercial arrangement as protected funds and another does not, the supervisor will ask why, and the answer needs to be a regulatory difference rather than an inconsistency nobody spotted.

Where is the weakest arrangement in the group? A supervisor in a strict jurisdiction may ask about a group entity in a lighter one, on the basis that group failure is a risk to their own market. The answer should not be that nobody has looked.

Which approach should a group take?

The honest answer depends on licence count and growth intention.

Up to two licences. Separate processes are workable. The reconciliation burden at group level is small enough to absorb.

Three or four licences. Build to one standard, or build one record. Separate processes start costing more than the alternative, and the group-position problem becomes visible at board level.

Five or more, or growing. One record generating many outputs is the only approach that scales. Every additional licence is otherwise a linear increase in cost and a further divergence in definitions.

Growing by acquisition. Assume separate processes and plan the consolidation, because acquired entities arrive with their own systems and nobody consolidates safeguarding in the first year of integration.

Our guide to regulatory reporting for multi-licence payment firms covers the reporting calendar a group has to run once it holds several licences.

Frequently Asked Questions

No. There is no mutual recognition of safeguarding compliance. CASS 15 compliance positions a firm well against the substance of most other regimes, but each regulator requires its own arrangement, records and reporting from the entity it authorises.

Generally no. Each regime has requirements about how safeguarding accounts are titled, which institutions may hold them and what acknowledgement the institution must give. Canada goes further, prohibiting client funds relating to out-of-scope services from being held in the safeguarding account at all. Commingling funds belonging to customers of different regulated entities creates an insolvency problem even where it is operationally convenient.

That depends on the approach taken. Where each entity runs its own process, the position has to be assembled from several systems and reconciled for differing definitions. Where the group operates from one record, the position is available directly. The difficulty of answering this question is a reasonable test of which approach a group is really running.

Failure is resolved entity by entity, under the insolvency law of that jurisdiction, using that entity's safeguarding arrangement. Group-level arrangements do not change the outcome for that entity's customers, which is why entity-level compliance cannot be substituted with a group policy.

Yes, because the rules differ. The reconciliation cadence, the definition of protected funds and the treatment of items in transit are not the same across regimes. One reconciliation cannot be correct under several rule sets simultaneously, though several reconciliations can be generated from one underlying record.

Several local processes are cheaper to start and more expensive to run, and the crossover comes at around three or four licences. Beyond that, the cost of maintaining separate processes and reconciling them at group level exceeds the cost of running one record with jurisdiction-specific outputs.

Yes, and this is a common source of error. The UK and Singapore define scope by licence category, Canada by the payment function performed, and Hong Kong by facility type with no size threshold. An entity outside scope in one jurisdiction may be squarely within it in another.

References

About Regulatory Counsel

Regulatory Counsel advises UK and international payment, e-money and cryptoasset firms on authorisation, safeguarding, prudential and conduct requirements, regulatory reporting and regulator engagement across multiple jurisdictions.

Our work with multi-licence groups covers safeguarding structure review, jurisdiction-by-jurisdiction gap analysis, reconciliation methodology design, group-level governance and reporting frameworks, and audit readiness across several regulators.

Where a group needs one record producing each regulator's reconciliation, return and evidence, Safeheld is the platform built for it.

Contact our regulatory team at info@regulatorycounsel.co.uk.

This article is provided for general information and does not constitute legal or regulatory advice. Confirm the current position with the relevant regulators and take advice on your specific circumstances.

Need Expert Advice?

Free initial consultation. No obligation.

Speak to an Expert