CASS 15 came into force on 7 May 2026. It is the FCA's Supplementary Regime for safeguarding, introduced by Policy Statement PS25/12 (Changes to the safeguarding regime for payments and e-money firms) following Consultation Paper CP24/20. This article sets out what the regime requires of firms now that it is operational: the scope of application, the reconciliation and records obligations, the audit cycle, the monthly return, and the governance the rules actually mandate.
What CASS 15 Does - and Does Not - Do
CASS 15 supplements, rather than replaces, the existing statutory safeguarding obligations. Relevant funds continue to be safeguarded under the Payment Services Regulations 2017 and the Electronic Money Regulations 2011. CASS 15 adds detailed rules on records and accounts, reconciliations, resolution of discrepancies, the safeguarding audit and regulatory reporting.
It is important to be precise about what the Supplementary Regime does not do. CASS 15 does not create a statutory trust. The statutory trust was proposed as part of the FCA's Post-Repeal Regime, under which relevant funds would be held on trust for customers from receipt. The FCA has stated its intention to move to that Post-Repeal Regime, but has deferred it for further consultation. Firms should not describe their current safeguarding arrangements as operating under a statutory trust, and safeguarding account documentation should reflect the position as it stands under the PSRs, the EMRs and CASS 15.
Who Is In Scope
The regime is broader than authorised payment institutions and authorised electronic money institutions alone. CASS 15 applies to:
- Authorised payment institutions
- Authorised electronic money institutions
- Small electronic money institutions
- Credit unions that issue electronic money
Small payment institutions are not required to safeguard, but may opt in - and where they do, the CASS 15 obligations follow. Firms that have grown towards the small payment institution threshold should assess the operational implications of the regime before authorisation rather than after.
Reconciliations: The Reconciliation Day Standard
CASS 15 requires firms to carry out internal safeguarding reconciliations and external safeguarding reconciliations on each reconciliation day.
A reconciliation day is any day other than a Saturday or Sunday, a UK bank holiday, or a day on which a relevant foreign market is closed. This was a deliberate change from the consultation proposal in CP24/20, which required reconciliation on every business day. Firms that built implementation plans against the consultation text should confirm that their operating procedures reflect the final rule rather than the proposal.
The internal reconciliation compares the firm's own records of relevant funds owed to customers against its records of the funds it holds or has secured. The external reconciliation compares the firm's internal records against statements or confirmations obtained from the third parties holding or securing those funds - the safeguarding credit institution, custodian, insurer or guarantor.
Where a discrepancy is identified, the firm must investigate it and correct it as soon as practicable. Any shortfall must be made good from the firm's own funds. Firms must keep records of each reconciliation, the methodology applied, the results, discrepancies identified and the corrective action taken.
For firms processing material transaction volumes across multiple corridors or accounts, automated reconciliation is realistically the only way to meet the standard consistently and produce the audit trail the regime expects.
The Safeguarding Audit Cycle
CASS 15 introduces a mandatory safeguarding audit conducted by an independent auditor, who provides an opinion on the firm's compliance with the safeguarding requirements throughout the audit period.
The timing is defined by reference to the firm's audit period, not by reference to the commencement date of the regime:
- The first safeguarding audit report is due within six months of the end of the firm's audit period.
- Subsequent reports are due within four months of the end of each audit period.
- The audit period must not exceed 53 weeks.
Firms may align the audit period with their financial year or select a different period. Aligning with the financial year is administratively simpler where the finance function is already preparing year-end information; selecting a different period may be preferable where the year-end is already a pressure point.
The audit examines the adequacy of the firm's safeguarding arrangements, the accuracy and frequency of reconciliations, the segregation of relevant funds from the firm's own funds, the governance and oversight arrangements, and compliance with the records and accounts requirements. A qualified or adverse opinion will attract supervisory attention.
The Monthly Safeguarding Return
Firms are subject to a monthly safeguarding return made under SUP 16.14A and submitted through RegData. The return captures data on safeguarded fund balances, the firm's safeguarding method, reconciliation outcomes and discrepancies, and safeguarding-related incidents in the reporting period.
The return is a supervisory dataset, not merely an administrative filing. Month-on-month patterns - recurring discrepancies, volatile balances, repeated late resolution - are visible to the FCA across the population of firms and are capable of triggering targeted supervisory engagement. Firms should treat the return as management information in its own right and review it before submission rather than after.
Governance: What the Rules Require
CASS 15 requires that responsibility for the firm's compliance with the safeguarding requirements sits with a director or senior manager of sufficient skill and authority.
The rules do not create a defined "safeguarding officer" role, do not require the appointment to be at board level, and do not prescribe quarterly board reporting. Statements to the contrary have circulated widely and should not be relied upon when designing a governance framework or evidencing compliance.
That said, arrangements beyond the minimum are commonly appropriate - and should be described as good practice rather than as regulatory requirements. In our experience the following are worth considering, and are readily defensible in supervisory engagement:
- A clearly documented allocation of safeguarding responsibility to a named individual, mapped to the relevant Senior Management Function where SM&CR applies
- Periodic reporting on safeguarding to the board or an appropriate committee, with immediate escalation of material discrepancies or incidents
- Independent challenge of the reconciliation methodology, whether by internal audit, compliance or a second-line function
- Documented escalation procedures with defined thresholds and timeframes
The distinction matters. A firm that presents good practice as a rule requirement tends also to misdescribe what the rules require elsewhere, and supervisors notice.
Operating the Regime: Where Attention Should Sit Now
With the regime live, the practical questions have shifted from implementation to operation.
The monthly return cycle. Firms should confirm that the data feeding the SUP 16.14A return is generated from source systems rather than reassembled manually each month, that the submission calendar is owned by a named individual, and that discrepancies reported in the return reconcile to the firm's internal records.
The first safeguarding audit. Firms should have fixed their audit period, appointed an auditor with genuine payment services and e-money expertise, and completed an internal readiness review against CASS 15 before fieldwork begins. Gaps identified by the firm and remediated are materially better than gaps identified by the auditor.
Reconciliation discipline. Records for every reconciliation day must be complete and retrievable for the whole audit period. Gaps in the record - including days incorrectly treated as non-reconciliation days - are among the more common findings.
Supervisory engagement. The FCA has access to a monthly dataset it did not previously have. Firms should expect questions to be specific and data-led, and should be able to explain any anomaly in their own returns without reconstructing the position from scratch.
Documentation accuracy. Safeguarding policies, account documentation and customer-facing disclosures should describe the regime accurately. References to a statutory trust, to a mandatory board-level safeguarding officer, or to a "REP020" return are incorrect under the current rules and should be removed.
Regulatory Counsel advises payment institutions and electronic money institutions on CASS 15 compliance, including reconciliation methodology, safeguarding audit readiness, SUP 16.14A reporting, governance design and gap analysis against the Supplementary Regime. Contact us for a free initial consultation. See our PS25 safeguarding service for details.
Frequently Asked Questions
CASS 15 came into force on 7 May 2026. It was introduced by PS25/12 as the FCA's Supplementary Regime and supplements the safeguarding obligations under the Payment Services Regulations 2017 and the Electronic Money Regulations 2011.
No. The statutory trust was proposed as part of the Post-Repeal Regime, which the FCA has deferred for further consultation. Under the Supplementary Regime, relevant funds continue to be safeguarded under the PSRs and EMRs as supplemented by CASS 15.
Authorised payment institutions, authorised electronic money institutions, small electronic money institutions, and credit unions that issue electronic money. Small payment institutions are not required to safeguard but may opt in, in which case the CASS 15 obligations follow.
Internal and external safeguarding reconciliations must be carried out on each reconciliation day. A reconciliation day is any day other than a Saturday or Sunday, a UK bank holiday, or a day on which a relevant foreign market is closed.
The first safeguarding audit report is due within six months of the end of the firm's audit period, and subsequent reports within four months. The audit period must not exceed 53 weeks and may be aligned with the firm's financial year or set to a different period.
It is a monthly return made under SUP 16.14A and submitted through RegData, covering safeguarded fund balances, the safeguarding method used, reconciliation outcomes and discrepancies, and safeguarding incidents in the reporting period. There is no return designated REP020.
No. CASS 15 requires that responsibility for safeguarding compliance sits with a director or senior manager of sufficient skill and authority. It does not create a defined safeguarding officer role, does not mandate a board-level appointment, and does not prescribe quarterly board reporting. Additional governance may be adopted as good practice.