CASS 15 requires safeguarding institutions to perform internal and external safeguarding reconciliations as frequently as necessary and at least once on each reconciliation day. The control is not complete when two totals are compared. Firms must use reliable records, apply a consistent reconciliation point, correct shortfalls and discrepancies, investigate causes and retain evidence of review.
This guide explains the operational sequence and the distinction between internal reconciliation, external reconciliation and the allocation of relevant funds by the end of the following business day.
## The three controls firms often confuse
Daily safeguarding involves related but distinct controls. Treating them as one “bank reconciliation” leaves important questions unanswered.
| Control | Question answered | Principal evidence |
|---|---|---|
| Relevant-funds allocation | Which client and liability does a receipt relate to? | Client ledger and unallocated-funds record |
| Internal safeguarding reconciliation | Is the safeguarding resource sufficient for the safeguarding requirement? | Requirement and resource calculation |
| External safeguarding reconciliation | Do internal records agree with the balances confirmed by third parties? | Bank, custodian or other external statement comparison |
A firm can pass one and fail another. It may hold enough money overall while its bank statement does not agree with its records. It may also match its bank balance while excluding relevant funds from the client requirement.
What is a reconciliation day?
CASS 15 uses the defined concept of a reconciliation day. The regime does not simply say “every calendar day”. PS25/12 explains that reconciliations are not required on weekends, public holidays and days when relevant foreign markets are not open, subject to the detailed rule and the firm's circumstances.
The firm must still decide whether more frequent or additional reconciliations are necessary because of its business. High transaction volume, intraday exposure, multiple settlement cycles or significant time-zone differences may justify controls beyond the minimum.
The approved policy should state the reconciliation calendar, point in time and treatment of bank holidays and foreign-market closures. Operators should not decide the calendar informally each morning.
Step 1: establish the reconciliation point
The firm must select reconciliation points for every day on which it performs internal safeguarding reconciliations. The points should be consistent and the calculation should use records at the corresponding time.
This sounds straightforward until systems close at different times. A client ledger may use Coordinated Universal Time, a bank may issue a local-midnight statement, and a processor may settle on a scheme day. The methodology needs controlled adjustments that bring those sources to the approved point.
Every adjustment should have a defined type, source, owner and reversal treatment. A manual “timing difference” without those attributes can conceal stale or unsupported balances.
Step 2: calculate the safeguarding requirement
The safeguarding requirement is the amount the firm should safeguard for clients. Under the standard method in CASS 15.8, it includes individual safeguarding balances, ignoring negative balances, and unallocated relevant funds.
The calculation should start from a complete client population. Common risks include omitted product ledgers, customers mapped to the wrong legal entity, transactions posted after cut-off and netting positive and negative client positions incorrectly.
The control should reconcile the population back to an independently understood ledger total. Otherwise, a perfectly executed formula can operate on incomplete data.
Step 3: calculate the safeguarding resource
The safeguarding resource represents the qualifying funds and assets used to meet the requirement. Under the standard method it can include balances in relevant-funds bank accounts, segregated relevant funds not yet placed in such an account, qualifying relevant assets and amounts covered through an eligible insurance or guarantee method.
Firms must exclude non-relevant funds where required and apply the correct valuation treatment. The calculation should show each component by account, currency and legal entity rather than presenting one unexplained total.
Evidence for a resource item must be appropriate to the time of the reconciliation. A balance copied from a dashboard without its account identity, date and source is weak evidence.
Step 4: compare and correct the internal position
The firm compares the resource with the requirement. A resource below the requirement is a shortfall and requires the firm to take the prescribed corrective action, including paying in the necessary amount from its own funds.
A surplus is not automatically harmless. It may indicate unidentified own funds, duplicated records, delayed release or an error in the requirement. Persistent surpluses should be understood and corrected rather than accepted as a sign of prudence.
The completed record should show the initial result, action taken, corrected position and review. Overwriting the initial shortfall with the post-funding balance removes evidence that the shortfall occurred.
Step 5: perform the external reconciliation
The external reconciliation compares internal account records with statements or other confirmations from safeguarding banks, custodians and relevant third parties. It must be performed as soon as reasonably practicable after the date to which it relates.
Where external records cannot be aligned precisely with the internal reconciliation point, the policy should explain how the process still achieves its purpose. That normally requires separately identified timing items supported by transaction-level evidence.
The operator should not net unrelated differences merely because the total reaches zero. A missing £50,000 receipt and an unexplained £50,000 debit are two control failures, not a match.
D+1 allocation of relevant funds
CASS 15.2.5 requires a safeguarding institution to allocate relevant-funds receipts to an individual client promptly and, in any event, no later than the end of the business day following receipt or later identification in the circumstances specified by the rule.
This allocation requirement is sometimes described as D+1. It should not be confused with permission to delay safeguarding generally until the next day. The Payment Services Regulations and Electronic Money Regulations continue to govern when relevant funds must be safeguarded, and some client-crediting obligations require faster action.
The daily control should identify receipts approaching the allocation deadline and retain them as unallocated relevant funds in the records until correctly assigned.
How to manage reconciliation exceptions
An exception workflow should make the unresolved population visible to finance, operations and compliance. Each case should contain enough information for a person unfamiliar with the event to understand what happened.
Minimum fields include the amount, currency, source, detection time, account, entity, owner, age, cause, proposed correction and evidence. The workflow should distinguish a temporary timing item from an error requiring a ledger correction or own-funds payment.
Ageing thresholds should trigger escalation. An item that remains open for several cycles is no longer an ordinary timing difference. Its continued presence can affect the reliability of subsequent reconciliations and monthly reporting.
From exception to breach assessment
Not every exception is a breach, and not every breach is notifiable. The assessment should nevertheless be explicit.
| Factor | Question |
|---|---|
| Amount | What was the absolute and relative size? |
| Duration | How long did the issue exist before correction? |
| Customers | Were customer entitlements or access affected? |
| Records | Could the firm still identify relevant funds and clients? |
| Recurrence | Has the same cause appeared before? |
| Control failure | Did a required reconciliation fail or become unreliable? |
| Remediation | Was the cause corrected or only the individual item? |
The decision and rationale should be reviewed by the appropriate compliance or senior owner. Where CASS 15 or Principle 11 requires notification, the firm should notify the Financial Conduct Authority without delay rather than waiting for the next REP027 submission.
Root cause and recurring differences
Closing an item after posting an adjustment treats the symptom. Root-cause analysis asks why the issue entered the process and why the preventive or detective control did not stop it.
Useful categories include source-data failure, incorrect mapping, cut-off mismatch, bank or processor delay, manual error, unauthorised rule change and product-design weakness. Trends should be reported across cases, not hidden in free-text notes.
Repeat causes matter because ten corrected £1,000 errors can indicate more risk than one unusual £20,000 event. Management information should therefore show frequency and recurrence alongside value.
Maker-checker review and segregation of duties
The person preparing or changing a reconciliation should not be the only person approving it. The reviewer should examine the source completeness, material adjustments, unmatched items and any funding action, not simply click “approved”.
Access should reflect roles. Users who administer mapping or calculation rules should not be able to conceal the resulting exceptions by editing completed evidence. Emergency access and overrides need monitoring and retrospective review.
Where the same small team performs several functions, the firm should design proportionate compensating controls and document why they are effective.
Evidence to retain
For every reconciliation, retain:
- original source files or confirmations;
- data-quality and completeness results;
- the approved rule or methodology version;
- requirement and resource components;
- external comparison and matching output;
- adjustments with supporting evidence;
- exceptions, investigations and corrective actions;
- preparer and reviewer timestamps; and
- final approved result.
This evidence supports REP027, audit testing, regulatory review and the CASS 10A resolution pack. It also allows the firm to reproduce a historical position after staff or systems change.
Automating the process with Safeheld
Daily reconciliation is a strong candidate for technology because it combines repeated data preparation, deterministic calculations, exception routing and evidence retention.
Safeheld is a specialist regulatory technology platform. It supports the operational reconciliation, investigation, evidence and reporting workflow. Regulatory Counsel can advise on the methodology and notification framework, while the firm retains responsibility for decisions and submissions.
The practical test is whether the system helps the firm identify a real shortfall earlier, explain it faster and produce complete evidence without rebuilding the day from spreadsheets and emails.
Daily operating checklist
- Confirm all expected source data arrived and passed validation.
- Lock the approved reconciliation point and rule version.
- Calculate the safeguarding requirement.
- Calculate the safeguarding resource.
- Correct and evidence any internal shortfall.
- Complete the external reconciliation using independent records.
- Assign, age and investigate all exceptions.
- Assess breaches, materiality and notification.
- Obtain maker-checker approval.
- Preserve the complete record and update management information.
Get the control reviewed
Regulatory Counsel can review the relevant-funds methodology, reconciliation design, breach framework and governance. Safeheld can demonstrate how the daily workflow and its evidence can be controlled in technology.
Firms should request a review where reconciliations are late, depend on one individual, contain persistent unidentified differences or cannot be reproduced from the retained evidence.
Frequently Asked Questions
They must be performed as frequently as necessary and at least once on each reconciliation day, subject to the detailed rules and circumstances.
The internal reconciliation compares what the firm should safeguard with its safeguarding resource. The external reconciliation compares internal records with independent third-party balances.
No. D+1 in CASS 15.2.5 concerns the outside limit for allocating certain receipts to individual clients. The underlying safeguarding and payment or e-money obligations must still be applied.
No. The firm must assess the applicable notification rules, materiality and circumstances. Certain failures require notification without delay, and REP027 separately captures prescribed monthly information.
Artificial intelligence can assist investigation and suggest causes, but accountable staff should approve material adjustments, breach decisions and regulatory notifications using explainable evidence.
Official sources
This article provides general information, not legal advice. The correct methodology and notification decision depend on the firm's permissions, products, records and circumstances.
Definitive guides on this topic
The permanent reference pages this article relates to.
Safeguarding and CASS 15
Safeguarding arrangements, reconciliations and the CASS 15 regime.
UK Electronic Money Institution licence
FCA EMI requirements, EUR 350,000 capital, safeguarding, cost and timeline.
UK Authorised Payment Institution licence
FCA API requirements, own funds methods, safeguarding, cost and timeline.