Safeguarding sounds like one obligation. In practice it is six or more, each with its own definition of which funds are protected, its own timing, its own reporting cycle and its own audit requirement.
For a firm holding a single licence, that is manageable. For a firm holding permissions in the UK, the EU, Canada, Singapore, Hong Kong and Australia, it becomes an operational problem: six regulators, six sets of records, six reporting calendars, and no single process that satisfies all of them.
This article sets out how the regimes differ, and where a group holding multiple licences has to run parallel arrangements rather than one.
What does safeguarding actually mean?
Safeguarding is the requirement that customer funds held by a payment or e-money firm are kept separate from the firm's own money, so those funds can be returned if the firm fails.
It exists because these firms are not banks. Customer funds held by a payment institution or an electronic money institution are not covered by a deposit guarantee scheme. Where the firm fails, the customer's protection is the safeguarding arrangement and nothing else.
The FCA's guidance sets out the UK position. Recent UK firm failures made the consequences concrete: customers in several cases recovered a fraction of what they were owed, with shortfalls driven by inadequate records rather than missing money.
Every jurisdiction in this article shares that objective. What differs is how far each regulator goes in specifying how it must be achieved.
How do the six regimes compare?
| UK | EU | Canada | Singapore | Hong Kong | Australia | |
|---|---|---|---|---|---|---|
| Principal instrument | PSRs 2017 reg 23, EMRs 2011 reg 20, CASS 15, CASS 10A, SUP 3A, SUP 16.14A | PSD2 Art 10, EMD2 Art 7 | Retail Payment Activities Act and Retail Payment Activities Regulations | Payment Services Act 2019 | Payment Systems and Stored Value Facilities Ordinance | Currently non-cash payment facility authorisation and the purchased payment facility regime. Reform in train |
| Regulator | FCA | National competent authority per member state | Bank of Canada | MAS | HKMA | ASIC, with APRA for major stored value facilities under the proposed regime |
| Who is in scope | Authorised PIs holding relevant funds, authorised EMIs, small EMIs, credit unions issuing e-money. Small PIs may opt in | Payment institutions and electronic money institutions | PSPs performing a retail payment function and holding end-user funds at rest, including PSPs outside Canada directing activities at Canadian end users | Major Payment Institutions. Standard Payment Institutions below the thresholds are not subject to safeguarding | SVF licensees. No de minimis float threshold for licensing | To be determined by the reform. Proposed: SVF providers under AFSL |
| Thresholds | £100,000 safeguarding audit exemption | Set nationally | None for the safeguarding obligation itself | MPI status at S$3m monthly transactions for one service, S$6m for two or more, or S$5m average daily outstanding e-money | Minimum paid-up capital HKD 25 million | Proposed A$200m aggregate stored value for APRA registration, subject to regulations |
| Permitted methods | Segregation, secure liquid assets with an authorised custodian, or insurance or comparable guarantee | Segregation in a credit institution, secure low-risk liquid assets, or insurance or comparable guarantee | Trust account, or segregated account with insurance or a guarantee | Undertaking or guarantee from a safeguarding institution, or a trust account with one | Segregated trust account with a licensed Hong Kong bank, bank guarantee, or equivalent high-quality liquid assets. Float protected at least 100 per cent | Proposed: segregated trust accounts with Australian ADIs, with permitted insurance or alternatives set by regulations |
| Segregation deadline | Promptly, and at the latest by close of the business day following receipt | Set nationally | On receipt, or no later than the end of the business day after the day of receipt | Per MAS requirements | Float kept separate at all times | To be set by regulations |
| Reconciliation frequency | Internal and external reconciliation at least once on each reconciliation day | Not centrally prescribed | No fixed frequency prescribed. PSPs must track the total held for end users, the total that must be safeguarded, and the total actually safeguarded | Not prescribed in the same terms | Not prescribed in the same terms | To be determined |
| Regular regulatory return | Monthly, SUP 16.14A, via RegData | Varies by member state | Annual report to the Bank of Canada. First report due no later than 31 March 2026 | Periodic reporting per licence class | Periodic reporting to the HKMA | To be determined |
| Dedicated audit | Annual safeguarding audit under SUP 3A, subject to the £100,000 exemption | Varies by member state | Annual review of the safeguarding framework | Annual audit | Annual audit | To be determined |
| Insolvency resolution pack | Yes, CASS 10A, retrievable within 48 hours | Not centrally prescribed | Not prescribed in this form | Not prescribed in this form | Trust arrangement supported by a legal opinion expected | Not prescribed in this form |
| Status | In force 7 May 2026 | PSD3 in draft | Safeguarding requirements in force 8 September 2025 | In force since 28 January 2020 | In force | Tranche 1 exposure draft released March 2026. Not yet in force |
The pattern is that the UK has moved furthest toward prescription and the rest sit at various points behind it. That has a practical consequence set out at the end of this article.
What does the UK require?
The UK regime is the most detailed of the six and is the reference point for the others.
Safeguarding obligations sit in regulation 23 of the Payment Services Regulations 2017 and regulation 20 of the Electronic Money Regulations 2011, supplemented since 7 May 2026 by a dedicated FCA Handbook chapter, CASS 15, introduced by Policy Statement PS25/12.
Who is in scope. Authorised payment institutions holding relevant funds, authorised electronic money institutions, small electronic money institutions, and credit unions issuing electronic money. Small payment institutions may opt in.
Reconciliation. Firms must perform an internal safeguarding reconciliation and an external safeguarding reconciliation at least once on each reconciliation day. A reconciliation day excludes Saturdays, Sundays, UK bank holidays, and days on which a relevant foreign market is closed.
The comparison is between the D+1 segregation requirement, being the relevant funds that should be held, and the D+1 segregation resource, being the balance of those accounts. Where the resource falls short the firm must remedy it, using its own funds if necessary. Where it exceeds the requirement the excess must be withdrawn.
Separate asset pools. Funds held in respect of electronic money and funds held for unrelated payment services are separate pools, reconciled and reported separately. A combined reconciliation misstates both.
Reporting. A monthly safeguarding return under SUP 16.14A, submitted through RegData.
Audit. An annual safeguarding audit under SUP 3A, unless the firm safeguarded less than £100,000 throughout a relevant period of at least 53 weeks.
Resolution pack. A pack maintained under CASS 10A, retrievable within 48 hours, containing the records an insolvency practitioner would need to return customer funds.
Our guide to UK CASS 15 safeguarding requirements sets this out in full.
What does the EU require?
The EU regime is principles-based where the UK's is prescriptive.
Article 10 of the second Payment Services Directive and Article 7 of the second Electronic Money Directive require that funds received from payment service users are either held in a segregated account with a credit institution, invested in secure low-risk liquid assets as defined by the national competent authority, or covered by an insurance policy or comparable guarantee.
Three differences from the UK matter operationally.
Detail sits with the national regulator. The directives set the objective; each member state's competent authority determines how it is supervised. A firm operating across several member states may face different supervisory expectations in each.
Reconciliation frequency is not centrally prescribed. There is no EU equivalent of the reconciliation day and no directly applicable daily requirement.
No central reporting equivalent. There is no EU counterpart to the monthly SUP 16.14A return.
PSD3 and the accompanying Payment Services Regulation are in draft. The direction of travel is toward greater prescription. Firms with EU permissions should track the proposals rather than assume the current position holds.
Our guide to EU safeguarding under PSD2 Article 10 covers the detail.
What does Canada require?
Canada's Retail Payment Activities Act introduced a statutory safeguarding obligation for payment service providers holding end-user funds, supervised by the Bank of Canada. The safeguarding requirements took effect on 8 September 2025.
Who is in scope. A payment service provider performing a retail payment function and holding end-user funds at rest. The Bank of Canada's guidance draws a specific distinction: a PSP holds funds where it keeps end-user funds at rest and available for future withdrawal or transfer. It does not hold funds where it pre-funds a transaction, reserves funds to mitigate credit risk, or receives funds concurrently with an instruction to transfer them immediately.
The regime reaches PSPs without a place of business in Canada where they perform retail payment activities for end users in Canada and direct activities at persons in Canada. For those PSPs, only funds held for Canadian end users are in scope.
Method. End-user funds must be held in trust in a trust account, or held in a segregated account with insurance or a guarantee in respect of the funds. Under either option, funds must be segregated from the PSP's own funds and all other funds it holds, in a separate safeguarding account. Client funds relating to services outside the Act's scope cannot be held in that account.
Timing. Funds must be placed in the safeguarding account on receipt, or no later than the end of the business day after the day of receipt.
What must be tracked. Three figures: the total funds held on behalf of end users, the total that must be placed in a safeguarding account, and the total actually held in one. The regime does not prescribe a fixed reconciliation frequency in the way CASS 15 does, but a PSP cannot track those three figures without a regular reconciliation.
Framework and reporting. PSPs must establish and maintain a safeguarding-of-funds framework and review it. An annual report is submitted to the Bank of Canada; the first was due no later than 31 March 2026.
Two features distinguish the regime from the UK. The supervisor is the central bank rather than a conduct regulator. And scope turns on the payment function performed rather than the licence held, which brings firms in that would not hold a UK payment institution authorisation.
Our guide to Canada RPAA end-user funds safeguarding sets out the requirements.
What does Singapore require?
Singapore's Payment Services Act 2019 imposes safeguarding obligations on Major Payment Institutions, supervised by the Monetary Authority of Singapore.
The threshold determines the obligation. A firm is a Major Payment Institution where it exceeds any of: S$3 million in monthly transactions for any one payment service, S$6 million in monthly transactions across two or more, or S$5 million in average daily outstanding e-money. Below those thresholds a firm is a Standard Payment Institution and is not subject to the safeguarding requirement.
That structure has a practical consequence. Growth across a threshold is a compliance event as much as a commercial one, and a firm approaching one should have the safeguarding arrangement in place before it crosses rather than after.
Method. A Major Payment Institution issuing e-money must safeguard customer money through an undertaking or guarantee from a safeguarding institution, or a trust account maintained with one. MAS specifies the institutions with which funds may be held.
Restrictions. The Act prohibits licensees from lending customer money, and from using customer money or interest earned on it to finance the business. That is a structural separation not present in the same form in every other regime.
Capital. Base capital of S$250,000 for most Major Payment Institution services. Standard Payment Institutions require S$100,000.
What does Hong Kong require?
Hong Kong regulates stored value facilities under the Payment Systems and Stored Value Facilities Ordinance, supervised by the Hong Kong Monetary Authority.
No de minimis threshold. Unlike Singapore, Hong Kong has no general float threshold below which licensing is not required. A firm carrying on multi-purpose stored value facility business needs a licence or an exemption, which makes the regime demanding for smaller entrants.
Float protection. The float must be kept separate from the licensee's other funds and protected at least 100 per cent. Accepted methods are a segregated trust account with a licensed bank in Hong Kong, a guarantee from a licensed Hong Kong bank, or equivalent high-quality liquid asset arrangements. The HKMA expects a trust arrangement supported by a legal opinion, so that facility users have priority over other creditors on insolvency.
What the HKMA looks for. Licensees must have an effective and robust system ensuring float is used only in accordance with users' instructions, protected against claims by other creditors of the issuer in all circumstances, and protected against misappropriation. Float protection is the most closely supervised aspect of the regime.
Capital. Minimum paid-up capital of HKD 25 million, with the HKMA able to impose more through licence conditions depending on projected float and business complexity.
What does Australia require?
Australia is the jurisdiction in this article where the framework is changing most, and any firm with Australian permissions should treat the current position as transitional.
The current regime. Obligations arise through non-cash payment facility authorisation under the Australian Financial Services Licence framework, and through the purchased payment facility regime under the Banking Act 1959, administered principally by APRA and the Reserve Bank of Australia. There is no single safeguarding chapter equivalent to CASS 15.
The reform. Treasury released Tranche 1 exposure draft legislation in March 2026 for consultation. The proposals would:
- Repeal the purchased payment facility regime and replace it with a stored value facility authorisation under the AFSL framework
- Require major stored value facility providers to register with APRA and comply with APRA-made prudential standards while remaining outside the authorised deposit-taking institution framework, under the proposed Payment Entities (Prudential Regulation) Bill 2026
- Set the major provider threshold at an indicated A$200 million aggregate stored value, subject to regulations
- Introduce a payment-related money framework across stored value facilities, payment instruments and payment services, modelled on existing client money rules but adapted for payment flows, with customer funds generally held in segregated trust accounts with Australian authorised deposit-taking institutions and permitted insurance or alternative mechanisms set out in regulations
- Expand ASIC's information-gathering powers over suspected unlicensed payment activity
- Make a revised ePayments Code mandatory
What this means practically. A firm planning Australian operations should design to the proposed framework rather than the current one, because the current one is being replaced. A firm already operating should track the consultation, since the proposed definition of a stored value facility is broad enough to capture prepaid cards, consumer wallets and account-based products that may not previously have been in scope.
Why can one process not satisfy all six?
Four differences make a single global safeguarding process impossible, and they are the differences most often underestimated.
The definition of protected funds is not the same. The UK's relevant funds, the EU's funds received from payment service users, Canada's end-user funds held at rest, Singapore's e-money and Hong Kong's float are overlapping but distinct concepts. The same customer payment may be protected in one jurisdiction and outside scope in another.
Scope itself is defined differently. The UK and Singapore define scope by licence category. Canada defines it by payment function performed. Hong Kong defines it by facility type with no size threshold. A group cannot assume that an entity in scope in one jurisdiction is in scope in another, or the reverse.
The cadence differs. The UK requires reconciliation on each reconciliation day. Canada requires three fund figures to be tracked without prescribing a frequency. Others do not prescribe one in the same terms. A firm running a monthly process satisfies some regimes and breaches others.
The evidential standard differs, and this is the one that causes most trouble. The UK requires a resolution pack retrievable within 48 hours and an annual audit against a dedicated auditing standard. Hong Kong expects a trust arrangement supported by a legal opinion. Producing that standard of evidence in one jurisdiction while operating to a lighter standard elsewhere creates an inconsistency a supervisor will ask about.
What does this mean for a firm holding multiple licences?
Firms in this position generally take one of two approaches.
Run to the highest standard everywhere. Apply the most demanding regime's requirements across the group, so controls, evidence and governance are consistent. Several multi-licence groups have taken this approach with CASS 15, on the basis that satisfying the UK positions them well elsewhere.
It is defensible and it is expensive. It also does not remove the jurisdiction-specific outputs: a Canadian annual report is still a Canadian annual report, whatever standard produced the underlying figures.
Run jurisdiction-specific processes from one record. Maintain a single record of customer funds, accounts and movements, and generate each regulator's reconciliation, return and evidence from it according to that regime's rules.
This is harder to build and cheaper to operate, and it is the only approach that scales past three or four licences. It also produces something the first approach does not: a single position the group can state confidently, rather than several processes that have to be reconciled to each other before anyone can answer a question.
Our guide to multi-jurisdiction safeguarding compliance addresses how firms structure this, and our guide to regulatory reporting for multi-licence payment firms covers the reporting calendar.
Frequently Asked Questions
No. Every major payments jurisdiction requires customer funds to be held separately from the firm's own money, but the definition of which funds are protected, how scope is determined, the reconciliation cadence, the reporting cycle and the audit requirement all differ.
The UK, following the introduction of CASS 15 on 7 May 2026. It is the only regime covered here that combines a prescribed reconciliation frequency, a monthly regulatory return, an annual audit under a dedicated auditing standard, and an insolvency resolution pack retrievable within 48 hours. Hong Kong is the most demanding on float protection specifically, requiring at least 100 per cent protection and a trust arrangement supported by a legal opinion, with no de minimis threshold.
The UK requires internal and external safeguarding reconciliation at least once on each reconciliation day, which excludes Saturdays, Sundays, UK bank holidays and days when a relevant foreign market is closed. It is the only regime covered here that prescribes a reconciliation frequency in those terms. Canada requires payment service providers to track the total held for end users, the total that must be safeguarded and the total actually safeguarded, which in practice requires regular reconciliation without prescribing a frequency.
No. CASS 15 compliance positions a firm well against the substance of most other regimes, but each jurisdiction has its own reporting obligations, its own definition of protected funds and its own audit requirements. A UK-compliant firm still has to produce a Canadian annual report, a Singaporean audit and member-state-specific EU evidence.
That depends on the facility. Australia currently regulates through non-cash payment facility authorisation and the purchased payment facility regime. Both are being replaced: Treasury released Tranche 1 exposure draft legislation in March 2026 proposing stored value facility authorisation under the AFSL framework, APRA registration for major providers, and a new payment-related money framework. Firms should design to the proposed regime and confirm the current position directly.
Yes, in part. The Retail Payment Activities Act reaches payment service providers without a place of business in Canada where they perform retail payment activities for end users in Canada and direct activities at persons in Canada. For those providers, only funds held for Canadian end users are within scope.
On becoming a Major Payment Institution, which occurs on exceeding S$3 million in monthly transactions for any one payment service, S$6 million across two or more, or S$5 million in average daily outstanding e-money. Standard Payment Institutions below those thresholds are not subject to the safeguarding requirement.
Generally no. Each regime has requirements about the institutions with which funds may be held, how accounts must be titled and what acknowledgement the institution must give. Canada goes further and prohibits holding client funds relating to out-of-scope services in the safeguarding account at all.
Frequently. The UK introduced CASS 15 in May 2026. Canada's requirements took effect in September 2025. PSD3 is in draft in the EU. Australia's framework is in consultation. Any firm relying on a summary should confirm the current position with the relevant regulator.
References
- FCA - Safeguarding requirements for payment institutions and e-money institutions
- Payment Services Regulations 2017
- Electronic Money Regulations 2011
- FCA Handbook - CASS 15
- Bank of Canada - Retail payments supervision
- Bank of Canada - Safeguarding end-user funds supervisory guideline
- MAS - Guide to the Payment Services Act 2019
- HKMA - Guideline on Supervision of Stored Value Facility Licensees
- Australian Treasury - Regulation of Payment Service Providers, Tranche 1 exposure draft legislation, March 2026
About Regulatory Counsel
Regulatory Counsel advises UK and international payment, e-money and cryptoasset firms on authorisation, safeguarding, prudential and conduct requirements, regulatory reporting and regulator engagement across multiple jurisdictions.
Our work with multi-licence groups covers jurisdiction-by-jurisdiction safeguarding analysis, reconciliation methodology design, regulatory reporting frameworks, audit readiness and remediation.
Where a group needs one record producing each regulator's reconciliation, return and evidence, Safeheld is the platform built for it.
Contact our regulatory team at info@regulatorycounsel.co.uk.
This article is provided for general information and does not constitute legal or regulatory advice. Safeguarding regimes change and supervisory expectations vary. Confirm the current position with the relevant regulator and take advice on your specific circumstances.
Definitive guides on this topic
The permanent reference pages this article relates to.