top of page
Blue Light Gradient

CASS 15 Safeguarding Software

Safeheld is the safeguarding platform from our group company Safeheld, built for FCA-regulated payment and e-money firms. Daily internal and external reconciliation, the D+1 segregation position, break management, the monthly SUP 16.14A return, the CASS 10A resolution pack and audit-ready evidence.

Speak with Our Safeguarding Experts

Speak with Our Experts

Complete the form, and our experts will contact you within 24 hours. Alternatively, call us directly at 0207 866 2512.

The platform. One record. Every output.

The daily reconciliation you sign off is the same record that produces your monthly return, your board reporting and your audit evidence.

sh2.png

Daily safeguarding position

Internal and external reconciliation on each reconciliation day. The segregation requirement and resource calculated and compared, shortfalls and excess identified, the day signed off with a recorded approval.

Audit evidence

Every reconciliation, break, approval and sign-off held in an immutable record. The evidence pack assembles for any period, and auditors receive read-only access scoped to the period under review.

Resolution pack

The CASS 10A pack draws from live data and stays current. Completeness monitored, gaps flagged, available on demand within the 48-hour requirement.

Breach register and FCA notifications

Breaches recorded with cause, value, remediation and notification status. Notification triggers identified and drafts prepared for senior approval.

Monthly safeguarding return

The SUP 16.14A return assembles from the reconciliation records already held. Reviewed, approved and exported ready for RegData submission.

Built by safeguarding practitioners

wired-gradient-457-shield-security (2).gif

Regulatory depth

The rules are built into the platform: how relevant funds are identified, how the segregation position is calculated, which days require reconciliation, what the resolution pack must contain and what triggers a notification to the FCA. Specified by practitioners advising payment and e-money firms since 2013.

wired-gradient-204-chat-message-heart.gif

One record, every output

Reconciliation, approval and sign-off are captured as they happen, so the monthly return, the board pack and the audit evidence all draw from the same approved record rather than being assembled separately.

wired-gradient-1103-confetti (3).gif

Kept current

The Supplementary Regime is an interim step toward a full CASS-style regime. Safeheld is maintained by the same team advising firms through that transition, so the platform develops with the FCA's expectations.

Delivering CASS advisory services since 2013

download (6).png
download.png
download (4).png
download (5).png
kpmg-logo.webp
download (2).png
download_edited.jpg
download (8).png
download (3).png
hryze pics6.jpg
unnamed.jpg
favicon2.png
pay-construct-logo_edited.jpg
mxxg7axrzaxavyb17cgh.webp
download (1).png
download (7).png
download.jpg
bai logo.png

Why firms use Safeheld

Daily operation

CASS 15 has been in force since 7 May 2026. Internal and external reconciliations on every reconciliation day, a monthly return and an annual audit are now routine operating requirements.

Audit readiness

Most authorised firms must arrange an annual safeguarding audit, with the first report due within six months of the audit period end. Evidence is strongest where it accumulates through the year rather than being assembled for the audit.

Controls the auditor can test

IT general controls covering change management, user access and IT operations form part of the safeguarding audit. A platform with role-based access, approval workflow and an immutable record supports that testing directly.

Continuity

Where the reconciliation, the return and the evidence sit in one system with defined ownership and approval, the process continues through absence, growth and change of personnel.

Neon Lights_edited.jpg

Our People

Our safeguarding team combines payments regulation, client money and financial services compliance experience. The same practitioners who advise firms through FCA authorisation and supervision specify and maintain the regulatory logic within Safeheld.

When you work with us, you gain direct access to senior professionals rather than an account manager. Implementation is supported by people who understand what an auditor will ask for and what a supervisor will read.

Key CASS 15 information

What CASS 15 requires

CASS 15 came into force on 7 May 2026 as part of the FCA's Supplementary Regime, introduced by Policy Statement PS25/12. It supplements the safeguarding requirements in the Payment Services Regulations 2017 and the Electronic Money Regulations 2011, and applies to authorised payment institutions, authorised electronic money institutions, small electronic money institutions and credit unions issuing e-money. Small payment institutions may opt in.

  • Daily internal safeguarding reconciliation. On each reconciliation day, the firm compares the relevant funds that should be safeguarded against its internal records.

  • Daily external safeguarding reconciliation. On each reconciliation day, the firm compares its internal records against third-party records: statements from institutions holding safeguarding accounts and records from custodians holding relevant assets.

  • D+1 segregation. The segregation requirement, being the relevant funds that should be held, is compared against the segregation resource, being the amount actually held. Shortfalls are remedied, using the firm's own funds where relevant funds are unavailable. Excess is withdrawn.

  • Separate asset pools. Funds held in respect of e-money and funds held for unrelated payment services are reconciled and reported separately.

  • Reconciliation days. All days except Saturdays, Sundays, UK bank holidays and days on which relevant foreign markets are closed. The firm determines which foreign markets are relevant to its business and applies that determination consistently.

  • Monthly safeguarding return. A return under SUP 16.14A submitted through RegData covering funds held, reconciliation performance, shortfalls, accounts, assets, safeguarding method and breaches.

  • Resolution pack. A CASS 10A pack retrievable within 48 hours containing the records needed to return relevant funds to customers in an insolvency procedure.

  • Annual safeguarding audit. Required for firms that safeguarded £100,000 or more during the relevant period, with the report submitted to the FCA. The first report is due within six months of the audit period end and within four months thereafter. The audit period must not exceed 53 weeks.

  • Third-party oversight. Documented due diligence on banks, custodians, insurers and guarantors, with periodic review and consideration of whether to diversify.

  • Named responsibility. A director or senior manager of sufficient skill and authority is responsible for safeguarding compliance.

Other important information

CASS 15 and the Post-Repeal Regime. The Supplementary Regime is an interim step. The FCA intends to replace the safeguarding provisions of the PSRs and EMRs with a full CASS-style regime, so control frameworks built now should anticipate that end state.

Small payment institutions. SPIs are not required to safeguard but may opt in, and become subject to the regime on doing so.

The audit exemption. Firms that safeguarded less than £100,000 throughout the relevant period may be exempt from the audit requirement. Senior management determines this on an ongoing basis and the assessment should be documented.

Platform and framework. Safeheld operates the reconciliation, assembles the return, maintains the resolution pack and produces the evidence. Determining what constitutes relevant funds for a particular business model, designing the control framework and holding the accountability remain with the firm. Buckingham Capital Consulting supports that work directly where required.

How Safeheld meets CASS 15 & PS25/12 requirements

  • Reconciliation. Daily internal and external reconciliation across entities, accounts and currencies, with the segregation requirement and resource calculated automatically and the reconciliation calendar applied without manual assessment.

  • Separate pools. E-money and unrelated payment services reconciled and reported as distinct asset pools throughout.

  • Break and breach management. Unmatched items tracked to resolution with ownership, ageing, root cause and maker-checker approval. Breaches recorded against CASS 15 requirements, with notification triggers identified and drafts prepared for senior approval.

  • Monthly return. The SUP 16.14A return assembled from operational records, validated, reviewed and approved before export for RegData submission.

  • Resolution pack. The CASS 10A pack maintained from live data with completeness monitored and gaps flagged, available on demand.

  • Audit. Evidence packs assembled for any period, with scoped read-only auditor access and a full record of every action, approval and sign-off.

  • Third-party oversight. Banks, custodians, insurers and guarantors held in a register with due diligence records, review cycles and diversification assessment.

  • Governance. Acknowledgement letter status per account, policy versions and review dates, wind-down plan testing evidence, monthly attestation and board reporting.

What Safeheld provides

  • Reconciliation and segregation. Daily internal and external reconciliation with the D+1 position calculated across entities, accounts, currencies and asset pools.

  • Break and breach workflow. Ownership, ageing, root cause, remediation and maker-checker approval, with breaches classified and notification drafts prepared.

  • Regulatory reporting. The monthly SUP 16.14A return and board reporting drawn from the same operational record.

  • Resolution pack and audit evidence. CASS 10A maintained from live data, evidence packs for any period, and scoped auditor access.

  • Governance records. Third-party due diligence, acknowledgement letters, policies, wind-down testing and monthly attestation.

Key information and requirements

  • The regime is live. CASS 15 and the amended Approach Document came into force on 7 May 2026, supplementing the safeguarding requirements in the PSRs 2017 and EMRs 2011.

  • Reconciliation is daily. Internal and external safeguarding reconciliations are performed at least once each reconciliation day.

  • Responsibility sits with a named individual. A director or senior manager of sufficient skill and authority is responsible for safeguarding compliance.

  • Audit reporting is at zero materiality. Following FRC guidance, safeguarding auditors report all breaches to the FCA rather than only material ones.

  • The resolution pack must be current. It is retrievable within 48 hours, which assumes an existing pack rather than one assembled on request.

Our CASS 15 safeguarding publications

Frequently Asked Questions about Cass 15 safeguarding

Which firms does CASS 15 apply to?

CASS 15 applies to authorised payment institutions, authorised electronic money institutions, small electronic money institutions and credit unions that issue e-money in the United Kingdom. Small payment institutions are not required to safeguard but may opt in voluntarily, and firms may also opt in for unrelated payment services. The regime supplements rather than replaces the safeguarding obligations already contained in the Payment Services Regulations 2017 and the Electronic Money Regulations 2011, so firms remain subject to both. Scope questions most often arise where a firm operates a mixed business model, provides services through agents or distributors, or holds funds that may or may not constitute relevant funds. These determinations should be documented, because an auditor will ask how the boundary was drawn.

What are relevant funds?

Relevant funds are sums received in exchange for electronic money that has been issued, sums received from or for a payment service user for the execution of a payment transaction, and sums received from another payment service provider for the execution of a payment transaction. The practical difficulty is rarely the definition but its application: when the obligation begins, when it ends, how fees once due are treated, how foreign exchange is handled where it is linked to a payment service, how funds held by agents and distributors are treated, and how long unclaimed funds must continue to be safeguarded. Each requires a documented position, and consistency between that position and the reconciliation performed is what an auditor looks for.

What is a reconciliation day?

A reconciliation day is any day other than a Saturday or Sunday, a UK bank holiday, or a day on which a relevant foreign market is closed. This was a change from the original proposal, which required reconciliation on every business day. Firms determine which foreign markets are relevant to their business, document that determination and apply it consistently. The reconciliation calendar is best defined in advance rather than assessed each morning, so that any excluded day is supported by a recorded reason.

What is the D+1 segregation requirement?

The D+1 segregation requirement is the amount of relevant funds that should be held in safeguarding accounts or as relevant assets. It is compared against the segregation resource, being the amount actually held. Where the resource is less than the requirement, the firm has a shortfall and must remedy it, using its own funds if relevant funds are not available. Where the resource exceeds the requirement, the firm may withdraw the excess. The comparison is performed on each reconciliation day using a consistent reconciliation point, and the calculation, the comparison and the action taken are all recorded.

What is the difference between internal and external safeguarding reconciliation?

Internal reconciliation compares the firm's own records: what customers are owed against what the firm's books show is held. External reconciliation compares those internal records against third-party records, principally statements from the institutions holding the safeguarding accounts and records from custodians holding relevant assets. Both are performed on each reconciliation day. Where the same reconciliation point cannot be used for both, the firm documents in its policies why not and how the external reconciliation nonetheless achieves its purpose.

What must the resolution pack contain and how quickly must it be produced?

The CASS 10A resolution pack must be retrievable within 48 hours. It contains the documents and records needed to enable relevant funds to be returned to customers if the firm enters an insolvency procedure: the safeguarding accounts held and the institutions holding them, relevant assets and custodians, agents and distributors, the firm's procedures for the management, recording and transfer of relevant funds, the calculation methodology used, acknowledgement letters, key contacts and the records establishing customer entitlements. The most effective packs are living records drawn from current data, so that the 48-hour requirement is met by retrieval rather than reconstruction.

When must a safeguarding breach be notified to the FCA?

Notification is required without delay where the firm's internal records are materially out of date, inaccurate or invalid; where the firm will be unable to perform an internal or external reconciliation; where the firm will be unable to remedy a discrepancy identified in a reconciliation; and where there has been a material difference between the amount safeguarded and the amount that should have been safeguarded at any time during the preceding year. A breach register recording each breach, its cause, its value, the remediation undertaken and whether notification was made supports both the audit and any supervisory enquiry.

Which firms need a safeguarding audit and when is the first report due?

Authorised payment institutions and authorised e-money institutions must arrange an annual safeguarding audit unless they safeguarded less than £100,000 throughout the relevant period of at least 53 weeks. The first audit report is submitted within six months of the end of the audit period, and subsequent reports within four months. The audit period must not exceed 53 weeks. Scoping the audit early is worthwhile: FRC guidance introduced a zero materiality threshold, meaning auditors report all breaches to the FCA rather than only material ones, and IT general controls covering change management, user access and IT operations form part of the audit.

What is in the monthly safeguarding return and when is it due?

The return is made under SUP 16.14A and submitted through RegData. It covers relevant funds held, split between e-money and unrelated payment services; the segregation requirement and resource across the period; confirmation that reconciliations were performed on each reconciliation day; shortfalls identified and remedied; safeguarding accounts and the institutions holding them; relevant assets and custodians; the safeguarding method used; and breaches and notifications during the period. The submission window follows the FCA's reporting calendar for your permission, so firms should confirm their own due date in RegData.

What happens if there is a shortfall?

A shortfall means the segregation resource is less than the segregation requirement, so less is held than should be held. The firm remedies it, using its own funds where relevant funds are not available. The shortfall, its cause, the action taken and the date of resolution are recorded. Where the shortfall indicates internal records were materially inaccurate, or where the firm cannot remedy it, notification to the FCA is required. Root cause analysis matters alongside the correction, because a pattern of shortfalls is what an auditor and a supervisor will examine.

Do we still need to comply with the PSRs and EMRs?

Yes. The Supplementary Regime supplements the existing safeguarding requirements in the Payment Services Regulations 2017 and the Electronic Money Regulations 2011 rather than replacing them. Firms are subject to both, and the amended Approach Document sets out the FCA's expectations across the combined framework. The FCA has stated its intention to move to a Post-Repeal Regime in which those provisions are replaced with a full CASS-style regime, so control frameworks designed now should anticipate that end state.

Will software make us CASS 15 compliant?

A purpose-built platform automates the daily reconciliation, calculates the segregation requirement and resource, manages breaks with maker-checker approval, maintains the resolution pack from live data, assembles the monthly return and produces the audit evidence pack. Determining what constitutes relevant funds for a particular business model, designing a control framework that fits how the firm operates and holding the accountability remain with the firm. The Safeheld platform handles the operation. The control framework and the accountability remain with the firm, and Buckingham Capital Consulting supports both where required.

bottom of page