Fintech AdvisoryPartners
All insights

Safeguarding

Safeguarding for Payment Firms: What Good Looks Like Under the New Regime

The supplementary safeguarding regime has applied since 7 May 2026. Good implementation connects legal analysis, transaction-level data, daily operations, governance and evidence—rather than treating safeguarding as a finance-only calculation.

10 min read

Key takeaways

  • The first control is identifying relevant funds accurately and knowing when the safeguarding obligation begins and ends.
  • Segregation must be maintained across the complete money flow, including receipts, transfers, fees, returns and exceptions.
  • Daily reconciliation needs reliable data, timely completion, clear discrepancy ownership and evidence of resolution.
  • CASS 15 strengthens expectations for oversight, records, third parties, reporting and—where applicable—safeguarding audit.

The FCA’s supplementary safeguarding regime took effect on 7 May 2026 through CASS 15 and related reporting and audit provisions. It supplements the safeguarding requirements in the Payment Services Regulations 2017 and Electronic Money Regulations 2011.

The operational implication is significant: safeguarding should be treated as a controlled system with defined inputs, daily processes, senior ownership and evidence—not as a month-end balance comparison or a policy owned by one function.

Start with the relevant-funds analysis

A firm cannot safeguard accurately unless it can identify which receipts are relevant funds, at what point they become relevant and when they cease to be. That analysis needs to follow each product and payment flow, including failed, reversed, refunded, disputed or partially executed transactions.

Product, finance, compliance and engineering teams should use the same definitions. Ledger codes and transaction statuses need to implement the documented analysis consistently. Where a firm provides more than one service, it should be clear which asset pool and rules apply rather than assuming all customer-facing balances have identical treatment.

Maintain the safeguarding chain

Segregation is not only the final transfer into a designated safeguarding account. Management should understand where relevant funds can sit from receipt through to execution, including collection accounts, acquirers, payment processors, correspondent routes and accounts operated by third parties.

For each stage, the firm should be able to explain:

  • how relevant funds are identified and allocated to individual clients;
  • which account holds them and how that account is designated;
  • how quickly funds move to the safeguarding arrangement;
  • whether fees or the firm’s own money can be present and how these are removed;
  • what evidence supports acknowledgement letters and account restrictions; and
  • how delays, outages, returns and manual interventions are detected and resolved.

CASS 15 also requires due skill, care and diligence in selecting, appointing and periodically reviewing relevant third parties. Due diligence should focus on the specific legal entity and arrangement, not only a provider’s group reputation.

Reconciliation is a daily operating discipline

The regime requires daily checks. In practice, the internal safeguarding reconciliation should compare the firm’s relevant-funds requirement with the resources protected for clients using complete and accurate records. Any external reconciliation should independently test the firm’s records against third-party statements or other external sources as the rules require.

“D+1” or “T+1” should not become shorthand that obscures ownership. The firm should define the data cut-off, completion deadline, approver, tolerance, escalation threshold and correction process. Weekends, bank holidays, late files and unavailable systems need explicit treatment.

Good reconciliation evidence normally shows who prepared and reviewed the calculation, the source files used, changes or manual adjustments, the reason for each discrepancy, how any shortfall or excess was addressed and when the issue was closed. A spreadsheet total without lineage or review is difficult to defend.

Governance, records and third-party evidence

CASS 15 requires responsibility for operational compliance with the relevant-funds regime to be allocated to a single director or senior manager with sufficient skill and authority, including reporting to the governing body. That named ownership should be supported by operational responsibilities across finance, operations, compliance, technology and treasury.

Management information should reveal more than the safeguarded balance. Useful measures may include late reconciliations, unresolved differences, shortfalls and excesses, manual adjustments, aged unallocated receipts, acknowledgement-letter status, third-party review findings, system incidents and recurring root causes.

Records must allow the firm, at any time and without delay, to distinguish relevant funds from other funds. Retention, access and retrieval should therefore be tested. An insolvency practitioner or reviewer should not need individual staff knowledge to reconstruct the position.

Audit and reporting expectations

The supplementary regime introduced monthly safeguarding reporting and annual safeguarding audits for firms within scope, subject to the detailed application and available exemptions in the FCA rules. For example, the FCA has described proportionality for smaller firms, including an audit exemption where a firm holds less than £100,000 in customer funds, but firms should assess the precise rule against their own status and circumstances.

Reporting and audit readiness should be an output of the operating model, not a separate annual exercise. Returns should reconcile to governance information and underlying records. Audit findings should have accountable owners, realistic deadlines and evidence of closure.

Common implementation weaknesses

  • Relevant-funds logic is documented but not reflected consistently in product or ledger configuration.
  • Reconciliations depend on one person, late provider files or unexplained manual adjustments.
  • Safeguarding account names, acknowledgement letters or third-party terms are incomplete or out of date.
  • Shortfalls and discrepancies are corrected without root-cause analysis or senior visibility.
  • Board reporting presents balances but not control failures, timeliness or unresolved exceptions.
  • New products, corridors or providers go live before the safeguarding analysis and data mapping are updated.
  • Wind-down and insolvency records cannot produce a reliable client entitlement position promptly.

A practical operating checklist

  1. Confirm scope and relevant-funds treatment for every product and transaction state.
  2. Map the complete safeguarding chain, including all banks, processors, agents and distributors.
  3. Validate account designations, acknowledgement letters and third-party due diligence.
  4. Document daily internal and external reconciliation methods, inputs, timing and approvals.
  5. Test exceptions: delayed files, weekends, outages, refunds, chargebacks, unallocated funds and shortfalls.
  6. Assign one sufficiently senior owner and define supporting responsibilities across functions.
  7. Build management information around timeliness, discrepancies, ageing, incidents and remediation.
  8. Confirm monthly reporting and safeguarding-audit obligations for the firm’s specific status.
  9. Test whether records can reconstruct client entitlements promptly without relying on one individual.
  10. Embed safeguarding review into product, partner and system change governance.

Sources and further reading

Important: This article is general information only and does not constitute legal advice. Regulatory requirements depend on a firm’s specific model and circumstances.

Start a conversation

Turn the issue into a workable plan.

Discuss a project