CASS 15 After Implementation: What Payment and E-Money Firms Must Be Doing Now in 2026
- 3 days ago
- 11 min read

CASS 15 After Implementation: What Payment and E-Money Firms Must Be Doing Now in 2026
The FCA’s strengthened safeguarding regime for payment and electronic money firms came into force on 7 May 2026. For Authorised Payment Institutions, Authorised Electronic Money Institutions and other firms within scope, the implementation phase is now over. The focus has shifted from preparing policies and updating procedures to demonstrating that the new safeguarding framework is working effectively in practice.
CASS 15 introduces more prescriptive requirements around safeguarding governance, reconciliations, third-party due diligence, records, acknowledgement arrangements and the protection of relevant funds. It sits alongside new requirements for safeguarding audits, resolution packs and monthly regulatory reporting, creating a substantially more formal client-assets style regime for the payments and e-money sector.
For firms that implemented the changes shortly before the deadline, the main risk is now operational. The FCA will expect the controls described in policies to be reflected in daily processes, accurate reconciliations, complete records, effective oversight and evidence that breaches are identified and corrected promptly. A firm that updated its safeguarding policy in May but cannot evidence how the framework operates day to day remains exposed.
What is CASS 15?
CASS 15 is the new chapter of the FCA Client Assets Sourcebook governing the safeguarding of relevant funds by payment institutions and electronic money institutions. It forms part of the Supplementary Regime introduced through PS25/12 and came into force on 7 May 2026.
The underlying statutory obligation to safeguard customer funds still comes from the Payment Services Regulations 2017 and Electronic Money Regulations 2011. CASS 15 adds more detailed FCA rules around how firms should organise, operate, document and monitor those safeguarding arrangements.
For Authorised Payment Institutions and Authorised Electronic Money Institutions, safeguarding remains mandatory. Small Electronic Money Institutions must also safeguard funds received in exchange for electronic money, while Small Payment Institutions and certain SEMI activities can elect to safeguard under the relevant regime. Where firms are within scope of CASS 15, they must now comply with a much more structured framework than existed previously.
The objective remains straightforward: if a payment or e-money firm fails, customer funds should be identifiable, properly protected and capable of being returned as quickly as possible.
What changed on 7 May 2026?
The most significant change is that safeguarding is no longer governed primarily through high-level statutory requirements and FCA guidance. Firms now have detailed Handbook rules covering the operation of their safeguarding framework.
The strengthened regime includes daily internal and external safeguarding reconciliations, clearer requirements for records and accounts, more formal due diligence when selecting banks and other safeguarding institutions, resolution packs, safeguarding audits and monthly reporting to the FCA.
The FCA has also clarified when safeguarding obligations begin. Firms need to identify precisely when funds become relevant funds and ensure they are protected from that point. This is particularly important for firms using complex payment chains, collection accounts, acquiring models, agents, distributors or multiple banking partners.
For firms operating at scale, the practical challenge is ensuring that all of these requirements work together. Safeguarding cannot be treated as an isolated finance reconciliation exercise. Operations, finance, compliance, treasury, technology and senior management all have responsibilities within the control framework.
Daily safeguarding reconciliations are now a core requirement
One of the most important operational changes is the requirement to perform internal and external safeguarding reconciliations at least once each reconciliation day.
The internal safeguarding reconciliation compares the amount the firm is required to safeguard against the amount its internal records show as being protected. The purpose is to identify whether the firm has segregated enough money or assets to meet its obligations to customers.
The external safeguarding reconciliation compares the firm’s internal records with information obtained from the third parties actually holding the safeguarded funds, such as bank statements or other independent records. This provides an external check that what the firm believes it holds corresponds with what is actually held.
The key point is that reconciliation should not become a mechanical daily exercise that merely produces a spreadsheet. Firms must understand and investigate differences, determine whether any shortfall exists, correct discrepancies appropriately and retain a clear audit trail showing what happened.
Persistent unexplained reconciliation differences, manual adjustments without adequate evidence or repeated timing mismatches can indicate weaknesses in the underlying safeguarding framework. Where discrepancies recur, the correct response is not simply to adjust the reconciliation each day but to identify the root cause.
Firms need accurate records of the safeguarding requirement
A reliable reconciliation depends on the firm being able to calculate its safeguarding requirement accurately.
This can become difficult where a firm has high transaction volumes, multiple currencies, refunds, chargebacks, unsettled transactions, fees, agents, acquiring flows or funds moving across several accounts and payment partners.
The safeguarding requirement must reflect the firm’s actual obligation to customers. If the underlying transaction data is incomplete or incorrectly classified, even a technically completed reconciliation can produce the wrong answer.
Firms should therefore be able to trace the calculation from underlying customer and transaction records through to the final safeguarding requirement. They should also be able to explain clearly which balances are included or excluded and why.
This is one of the areas where compliance teams should work closely with finance and operations. A safeguarding policy may describe the methodology correctly, but the real regulatory risk sits in whether systems and operational processes produce an accurate number every day.
Safeguarding bank accounts require more than the correct account name
CASS 15 strengthens expectations around how firms select, appoint and monitor third parties that hold or manage relevant funds.
Firms should conduct appropriate due diligence before placing safeguarded funds with a bank or other eligible safeguarding institution and should continue to review that relationship. The assessment should consider the institution’s financial strength, expertise, market reputation and the risks created by concentrating large amounts of customer funds with a single provider.
This is particularly important for payment and e-money firms that depend heavily on one banking partner. A safeguarding arrangement may satisfy the technical rules while still creating concentration or operational risk if the firm has no realistic contingency should that provider withdraw services or experience difficulties.
Firms must also ensure that safeguarding accounts are correctly designated and that required acknowledgement arrangements are in place. The purpose is to make clear that the money is held for safeguarding purposes and should not be treated as the firm’s own money if the firm becomes insolvent.
Banks and other safeguarding providers should therefore be treated as part of the firm’s regulatory control environment, not merely as commercial suppliers.
Monthly safeguarding reporting gives the FCA much greater visibility
Payment and e-money firms within scope must now submit monthly information about their safeguarding arrangements and relevant funds to the FCA.
The safeguarding return, REP027, is generally due within 15 business days of the end of each calendar month. It gives the FCA substantially more regular visibility into how firms safeguard customer money, including balances, reconciliation activity, safeguarding methods and potential breaches.
This is a major supervisory change.
Historically, weaknesses in safeguarding could remain largely invisible to the regulator until an audit, supervisory review or firm failure exposed them. Monthly reporting allows the FCA to identify unusual movements, repeated problems or inconsistencies much earlier.
Firms should therefore treat the return as a regulatory control rather than an administrative reporting task. The data submitted should reconcile with the firm’s underlying safeguarding records and management information, and there should be clear ownership and review before submission.
Where a monthly return identifies a breach or inconsistency, firms should consider whether a separate FCA notification obligation is triggered rather than assuming that disclosure through the return alone is sufficient.
Safeguarding audits are now more formalised
The new regime also introduces clearer requirements around independent safeguarding audits. The purpose of the audit is not simply to confirm that customer money existed in the correct account on a particular date. The auditor will consider whether the firm maintained adequate systems and controls and complied with the relevant safeguarding requirements across the period being reviewed.
This means firms should expect scrutiny of areas such as reconciliation methodology, segregation, bank account arrangements, acknowledgement letters, third-party due diligence, record keeping, breach handling, governance and the safeguarding resolution pack.
For the first audit periods under the new regime, transitional timing provisions apply. The FCA states that the first safeguarding audit falling within the transitional arrangements may be submitted within six months of the end of the relevant period, while subsequent reports are generally subject to a four-month submission deadline.
The practical point is that firms should not wait for the auditor to identify weaknesses. A pre-audit review should test whether the evidence supporting the safeguarding framework is complete and whether operational practice matches documented procedures.
An audit qualification arising from a control that management already knew was weak is considerably harder to explain than a weakness identified and remediated proactively.
The safeguarding resolution pack must work in a real failure scenario
CASS 10A requires firms to maintain a safeguarding resolution pack containing information that would help an administrator, insolvency practitioner or other relevant person identify and return safeguarded customer funds if the firm failed.
The resolution pack should not be treated as a static folder created for compliance purposes and reviewed once a year. It needs to remain accurate as bank accounts, safeguarding institutions, key personnel, systems and operational arrangements change.
A useful test is whether someone unfamiliar with the firm could use the pack to understand quickly where customer funds are held, how the safeguarding requirement is calculated, who the relevant banking and operational contacts are and what information would be needed to return money to customers. If that cannot be done without relying heavily on undocumented knowledge held by a few employees, the resolution pack is unlikely to achieve its intended purpose.
This is particularly important for firms using multiple banks, agents, outsourced technology providers or complex cross-border structures. The more complicated the operating model, the more valuable a clear and current resolution pack becomes.
Safeguarding governance needs clear senior management ownership
CASS 15 should not be treated as a compliance-team responsibility alone. Safeguarding sits at the centre of a payment or e-money firm’s customer protection obligations, and senior management should understand whether the framework is operating effectively. This means receiving meaningful management information rather than simply being told that reconciliations have been completed.
Boards and senior managers should have visibility over material reconciliation differences, breaches, aged unresolved items, safeguarding shortfalls, banking concentration, audit findings and overdue remediation actions. They should also understand where the firm depends on manual controls and whether transaction growth is creating pressure on existing systems.
The strongest governance frameworks distinguish clearly between the people performing daily safeguarding processes, those reviewing or challenging the outputs and the senior managers accountable for ensuring weaknesses are addressed.
A firm may have technically compliant procedures but still have weak governance if significant issues are repeatedly corrected operationally without being escalated or analysed.
Common CASS 15 weaknesses firms should look for now
Several months after implementation, the key question is no longer whether a firm has written the required policies. It is whether its controls consistently produce the correct result.
Common areas that should be tested include reconciliation differences that remain unexplained for too long, incorrect treatment of fees or unsettled transactions, weak evidence supporting manual adjustments, incomplete third-party due diligence and safeguarding account documentation that has not been reviewed following changes to banking arrangements.
Firms should also check whether their monthly regulatory returns are produced from the same underlying data used in daily safeguarding controls. Differences between regulatory reporting, finance records and safeguarding calculations can indicate that different parts of the business are using inconsistent data or methodologies.
Another common weakness is excessive dependence on key individuals. If only one member of the finance or operations team understands how the safeguarding calculation works, the control framework has a resilience problem even if the daily reconciliations are technically being completed.
The objective should be a safeguarding framework that is repeatable, independently reviewable and capable of continuing to operate during staff absence, system disruption or firm stress.
What should PIs and EMIs be doing now?
Firms that completed a CASS 15 implementation project before 7 May 2026 should now move into an assurance phase.
The first priority is to test whether the framework implemented on paper is functioning correctly in live operations. A sample of daily reconciliations should be traced from underlying transaction data through to the safeguarding requirement, segregated balances, external bank information and any resulting adjustments.
The firm should also review its first months of REP027 submissions for consistency, confirm that safeguarding bank and acknowledgement arrangements remain current, test the resolution pack and assess whether third-party due diligence is complete and properly evidenced.
Any recurring reconciliation differences or control exceptions should be analysed by root cause. A discrepancy that is corrected every morning but reappears the following day is not necessarily a resolved issue.
Finally, firms approaching their first safeguarding audit should carry out a readiness review before the auditor begins substantive testing. This gives management an opportunity to remediate weaknesses rather than discovering them through a qualified or adverse audit finding.
CASS 15 compliance is now an ongoing supervisory issue
The most important shift under the new regime is that safeguarding has become more visible to the FCA.
Daily reconciliation requirements create a stronger operational evidence base. Monthly REP027 reporting gives the regulator regular information about safeguarding arrangements. Independent audits provide further assurance, while resolution packs and formal third-party controls make it easier to test whether firms could protect customers in a failure scenario.
The result is that safeguarding weaknesses are now more likely to become visible earlier.
For well-run firms, this should not be viewed negatively. A strong safeguarding framework protects customers, reduces the risk of regulatory intervention and gives management better visibility over one of the most important financial risks in a payment or e-money business.
For firms whose safeguarding processes remain highly manual, fragmented or dependent on informal practices, however, CASS 15 significantly raises the standard they are expected to meet.
How Buckingham Capital Consulting can help
Buckingham Capital Consulting has specialised in payment and electronic money regulation since 2013 and supports Payment Institutions and Electronic Money Institutions with safeguarding, FCA compliance and regulatory remediation.
We help firms assess whether their CASS 15 framework is operating effectively in practice, including safeguarding reconciliations, governance, policies and procedures, third-party arrangements, resolution packs, regulatory reporting and audit readiness. Where weaknesses are identified, we support firms in designing and implementing proportionate remediation rather than simply rewriting policies around controls that remain ineffective.
Our work can include a focused CASS 15 compliance review, safeguarding gap analysis, review of reconciliation methodology, REP027 reporting, resolution pack testing, safeguarding audit preparation and remediation of FCA or auditor findings.
For firms still reviewing the wider changes introduced by the FCA’s safeguarding reforms, our PS25/12 and CASS 15 safeguarding guide provides an overview of the regime, while our Safeguarding and CASS services support firms with implementation, assurance and remediation.
To discuss a CASS 15 review, safeguarding audit preparation or concerns about your current safeguarding framework, contact Buckingham Capital Consulting.
Frequently asked questions
What is CASS 15?
CASS 15 is the FCA Handbook chapter containing detailed safeguarding rules for payment and electronic money institutions. It came into force on 7 May 2026 as part of the PS25/12 Supplementary Regime and supplements the underlying safeguarding obligations in the Payment Services Regulations 2017 and Electronic Money Regulations 2011. It covers areas including organisational arrangements, records, reconciliations, safeguarding institutions and the protection of relevant funds.
Do payment institutions have to perform safeguarding reconciliations every day?
Firms within scope must perform internal and external safeguarding reconciliations at least once each reconciliation day, subject to the detailed CASS 15 requirements. The purpose is to ensure that the amount the firm is required to safeguard corresponds with the money or assets actually being protected. Differences should be investigated and corrected promptly rather than simply carried forward or adjusted without explanation.
What is the REP027 safeguarding return?
REP027 is the FCA’s monthly safeguarding regulatory return for payment and e-money firms within scope. It provides the FCA with information about relevant funds, safeguarding arrangements, reconciliations and compliance. The return is generally due within 15 business days of the end of each calendar month, giving the FCA much more frequent visibility over firms’ safeguarding positions than under the previous regime.
What is a CASS 15 safeguarding resolution pack?
The safeguarding resolution pack is required under CASS 10A and contains information needed to identify, protect and return customer funds efficiently if the firm fails. It should include current information about safeguarding accounts, relevant institutions, records, systems, key contacts and other material needed in an insolvency scenario. Firms should maintain it as a live operational document rather than a static compliance file.
What should firms do if they implemented CASS 15 but are unsure whether they are fully compliant?
The most effective next step is an operational compliance review rather than another policy review. The firm should test actual reconciliations, safeguarding calculations, bank arrangements, monthly reporting, breach handling, third-party due diligence and the resolution pack against the current rules. Any recurring differences or manual workarounds should be investigated before the first safeguarding audit or FCA supervisory review exposes them.


