CASS 15 Explained: The FCA's Safeguarding Regime for Payment and E-Money Firms
- Aug 6
- 11 min read

Buckingham Capital Consulting has advised payment and e-money firms on FCA authorisation, safeguarding and regulator engagement since 2013.
CASS 15 is the chapter of the FCA Handbook that sets out how payment institutions and electronic money institutions must safeguard relevant funds. It came into force on 7 May 2026 and introduced daily reconciliations, a monthly regulatory return, an annual safeguarding audit and a resolution pack, alongside detailed requirements covering governance, record keeping, segregation and third-party oversight.
For firms that have never been subject to a CASS regime, this is a significant change. Safeguarding moved from a principle applied periodically to a set of operating controls performed and evidenced every reconciliation day.
This article sets out what CASS 15 requires, who it applies to, and what each obligation involves in practice.
What is CASS 15?
CASS 15 is the FCA's Supplementary Regime for safeguarding, introduced by Policy Statement PS25/12 and inserted into the Client Assets sourcebook of the FCA Handbook. The FCA published the final rules on 7 August 2025 and allowed a nine-month implementation period, with the rules taking effect on 7 May 2026.
CASS 15 supplements the existing safeguarding requirements in the Payment Services Regulations 2017 and the Electronic Money Regulations 2011. It does not replace them. Firms remain subject to both the regulations and the new Handbook chapter, and the FCA's amended Approach Document sets out its expectations across the combined framework.
The regime is described as supplementary because it is an interim step. The FCA has stated its intention to move to a Post-Repeal Regime in which the safeguarding provisions of the PSRs and EMRs are replaced entirely with a full CASS-style regime.
Which firms does CASS 15 apply to?
CASS 15 applies to:
Authorised payment institutions
Authorised electronic money institutions
Small electronic money institutions
Credit unions that issue electronic money
Small payment institutions are not required to safeguard, but may opt in voluntarily. Firms may also opt in for unrelated payment services.
Scope questions arise most often where a firm operates a mixed business model, provides services through agents or distributors, or receives funds that may or may not constitute relevant funds. Where the boundary is unclear, the firm's determination should be documented, because an auditor will ask how it was drawn and a supervisor may ask the same.
Why the FCA introduced CASS 15
The FCA's concern was the consistency and quality of safeguarding across the payments sector. Insolvencies of payment and e-money firms have repeatedly revealed shortfalls between the funds that should have been safeguarded and the funds actually available to return to customers. Where the previous regime relied largely on high-level obligations in the regulations, the FCA concluded that firms required detailed, testable rules.
The direction of travel is toward parity with the standards applied to investment firms under CASS 6 and CASS 7. Payment and e-money firms are now subject to reconciliation, reporting and audit obligations of a broadly comparable character.
The core requirements of CASS 15
Identifying relevant funds
Relevant funds are sums received in exchange for electronic money that has been issued, sums received from or for a payment service user for the execution of a payment transaction, and sums received from another payment service provider for the execution of a payment transaction.
The definition is straightforward. Its application is not. Firms must determine, and document, when the safeguarding obligation begins and ends, how fees once due are treated, how foreign exchange is handled where it is linked to a payment service and where it is not, how funds held through agents and distributors are treated, and how long unclaimed funds must continue to be safeguarded.
These determinations should be set out in the firm's safeguarding policy, and the reconciliation performed must be consistent with the position taken. Inconsistency between the two is among the more common audit findings.
Daily internal safeguarding reconciliation
On each reconciliation day, a firm must perform an internal safeguarding reconciliation. This compares the relevant funds that should be safeguarded against the firm's own internal records.
The reconciliation is intended to check the accuracy of the firm's books and records. It is not the means by which those records are maintained. A firm whose reconciliation is the only point at which customer entitlements are established has misunderstood the obligation.
Daily external safeguarding reconciliation
On each reconciliation day, a firm must also perform an external safeguarding reconciliation. This compares the firm's internal records against third-party records: statements from the institutions holding safeguarding accounts, and records from custodians holding relevant assets.
Where the same reconciliation point cannot be used for both the internal and external reconciliation, the firm must document in its policies why not, and how the external reconciliation nonetheless achieves its purpose.
In practice, firms frequently perform the internal reconciliation well and treat the external reconciliation as a periodic check against bank statements. Both are required daily, and the difference in rigour between the two is visible to an auditor.
The D+1 segregation requirement and resource
CASS 15 replaced the previous deposit requirement and resource comparison with a higher-level test.
The D+1 segregation requirement is the amount of relevant funds that should be held in relevant funds bank accounts, or as relevant assets in relevant assets accounts.
The D+1 segregation resource is the balance of those accounts.
The two are compared on each reconciliation day. Where the resource is less than the requirement, the firm has a shortfall and must remedy it, using its own funds where relevant funds are not available. Where the resource exceeds the requirement, the firm may withdraw the excess.
The calculation, the comparison, the outcome and any action taken must all be recorded.
Separate asset pools
Where a firm holds funds in respect of both electronic money and unrelated payment services, those funds form separate asset pools. They must be reconciled and reported separately throughout.
This is a point firms operating mixed models sometimes overlook, and it affects the structure of the reconciliation rather than only its presentation.
Reconciliation days
CASS 15 requires reconciliation on each reconciliation day rather than each business day. A reconciliation day is any day other than a Saturday or Sunday, a UK bank holiday, or a day on which a relevant foreign market is closed.
This was a change from the original proposal in the consultation, which required reconciliation on every business day, and it was made to reduce the burden on firms operating across markets with differing calendars.
Firms must determine which foreign markets are relevant to their business, document that determination and apply it consistently. Nothing prevents a firm from reconciling on a day that is not a reconciliation day where the nature, volume or complexity of its business makes that appropriate.
The practical point is that the calendar should be defined in advance. A firm assessing each morning whether today is a reconciliation day cannot readily evidence why any particular day was excluded.
The resolution pack
CASS 15 requires firms to maintain a resolution pack under CASS 10A, retrievable within 48 hours.
The pack contains the documents and records needed to enable relevant funds to be returned to customers if the firm enters an insolvency procedure. That includes the safeguarding accounts held and the institutions holding them, relevant assets and custodians, the firm's agents and distributors, the procedures for the management, recording and transfer of relevant funds, the calculation methodology used, acknowledgement letters, key contacts and the records establishing customer entitlements.
The 48-hour requirement assumes an existing pack. A resolution pack assembled once a year is out of date for most of the year, and the requirement is not met by the ability to reconstruct one on request.
The monthly safeguarding return
Firms must submit a monthly safeguarding return under SUP 16.14A, filed through RegData.
The return covers relevant funds held, split between electronic money and unrelated payment services; the segregation requirement and resource across the reporting period; confirmation that internal and external reconciliations were performed on each reconciliation day; shortfalls identified and how they were remedied; safeguarding accounts and the institutions holding them; relevant assets and custodians; the safeguarding method used; and breaches and notifications during the period.
The return draws on records the firm maintains throughout the month. Firms holding those records in a controlled system assemble the return from data that already exists. Firms working from spreadsheets rebuild it each month, which is where inconsistency between the return, the underlying reconciliation records and the audit evidence tends to arise.
The annual safeguarding audit
Authorised payment institutions and authorised electronic money institutions must arrange an annual safeguarding audit, with the report submitted to the FCA.
Firms that safeguarded less than £100,000 throughout a relevant period of at least 53 weeks are exempt. Senior management must determine whether the exemption applies on an ongoing basis, and the assessment should be documented. The FCA has indicated that exempt firms may wish to obtain a voluntary audit.
The audit period must not exceed 53 weeks. The first report is due within six months of the end of the audit period, and subsequent reports within four months.
For firms that have never been subject to a CASS audit, this is the single largest operational change. The auditor examines whether the firm's books and records correctly reflect and substantiate the customers for whom funds are held, whether those records reconcile to the funds actually held, and whether the firm has systems and controls sufficient to safeguard those funds throughout the period.
Two points are worth noting on scope. Following guidance from the Financial Reporting Council, safeguarding auditors report all breaches to the FCA rather than only material ones. And IT general controls covering change management, user access and IT operations form part of the audit, with significant deficiencies likely to be recorded as breaches. Firms should confirm the current position with their auditor when scoping the engagement.
Breach notification
A firm must notify the FCA without delay where:
Its internal records are materially out of date, inaccurate or invalid
It will be unable to perform an internal or external safeguarding reconciliation
It will be unable to remedy a discrepancy identified in a reconciliation
There has been a material difference between the amount safeguarded and the amount that should have been safeguarded at any time during the preceding year
A breach register recording each breach, its cause, its value, the remediation undertaken and whether notification was made supports both the audit and any supervisory enquiry.
Third-party due diligence
Firms must carry out and document due diligence on the third parties involved in their safeguarding arrangements: the banks holding safeguarding accounts, custodians holding relevant assets, and any insurer or guarantor.
Due diligence is not a one-off exercise at appointment. It requires periodic review, and firms are expected to consider whether diversification across multiple providers is appropriate to their circumstances.
Acknowledgement letters
Firms must obtain acknowledgement letters from the institutions holding safeguarding accounts. The letter records that the institution acknowledges the funds are held for safeguarding purposes, that it has no right of set-off or counterclaim against them, and that it will not combine the account with any other account.
Letters obtained under the previous regime may continue in their existing form subject to the transitional provisions, but new letters should follow the CASS 15 template.
Governance and named responsibility
Responsibility for safeguarding compliance must sit with a director or senior manager of sufficient skill and authority.
This is a substantive requirement rather than an administrative one. The individual is expected to have genuine oversight of the safeguarding arrangements, which means access to the reconciliation position, visibility of breaks and breaches, and the standing to require remediation. Firms should be able to evidence how that oversight is exercised, not only who holds the title.
Insurance and comparable guarantees
Where a firm safeguards through insurance or a comparable guarantee rather than segregation, the policy must not contain conditions or restrictions beyond certification of an insolvency event.
The notification requirements are specific. A firm must notify the FCA at least two months before first using the method, and on any change of cover or change of provider. At least three months before expiry, the firm must decide whether to continue with the method, and where it will not, it must be able to demonstrate how funds will be safeguarded by segregation instead.
What CASS 15 means in practice
The obligations above describe a control environment operating continuously, evidenced as it operates. That is a different discipline from the periodic compliance exercise many firms were running previously, and three consequences follow.
The evidence is the deliverable. A firm that performs its reconciliations correctly but cannot demonstrate that it did so has not met the standard the audit will apply. Every reconciliation, comparison, break, remediation and approval needs a record showing what was done, by whom and when.
The outputs should share a source. The monthly return, the board reporting, the resolution pack and the audit evidence all describe the same underlying position. Where each is compiled separately, they diverge, and the divergence is what auditors and supervisors notice. Where all four draw from the same signed record, they cannot.
Key-person dependency becomes a control weakness. Where the daily reconciliation, the monthly return and the audit evidence sit with one person and their workbook, absence becomes a compliance event. The requirement for daily operation and continuous evidence assumes a process that survives its operator.
What comes next: the Post-Repeal Regime
CASS 15 is explicitly an interim regime. The FCA intends to repeal the safeguarding provisions of the PSRs and EMRs and replace them with a full CASS-style regime, under which relevant funds would be held on statutory trust.
Firms designing control frameworks now should anticipate that end state rather than building only for the current position. The operational requirements - daily reconciliation, evidenced controls, audit readiness - are unlikely to reduce.
Frequently asked questions
When did CASS 15 come into force?
CASS 15 came into force on 7 May 2026. The FCA published the final rules in Policy Statement PS25/12 on 7 August 2025, allowing a nine-month implementation period.
Does CASS 15 replace the safeguarding requirements in the PSRs and EMRs?
No. CASS 15 supplements the safeguarding requirements in the Payment Services Regulations 2017 and the Electronic Money Regulations 2011. Firms remain subject to both. The FCA has stated its intention to replace those provisions with a full CASS-style regime at a later stage.
How often must safeguarding reconciliations be performed?
Internal and external safeguarding reconciliations must each be performed at least once on every reconciliation day. A reconciliation day is any day other than a Saturday or Sunday, a UK bank holiday, or a day on which a relevant foreign market is closed.
Which firms are exempt from the safeguarding audit?
Firms that safeguarded less than £100,000 throughout a relevant period of at least 53 weeks are exempt from the annual safeguarding audit requirement. Senior management must determine on an ongoing basis whether the exemption applies, and the FCA has indicated that exempt firms may wish to obtain a voluntary audit.
What is the difference between the segregation requirement and the segregation resource?
The D+1 segregation requirement is the amount of relevant funds that should be held in safeguarding accounts or as relevant assets. The D+1 segregation resource is the balance of those accounts. Where the resource is less than the requirement, the firm has a shortfall and must remedy it. Where the resource exceeds the requirement, the firm may withdraw the excess.
How quickly must a resolution pack be produced?
Within 48 hours. The requirement assumes a pack that already exists and is current, rather than one assembled in response to a request.
Operating CASS 15
Meeting CASS 15 means running a set of controls every reconciliation day and holding the evidence that they operated.
Safeheld runs the daily internal and external reconciliations, calculates the D+1 segregation position, manages breaks through to approved resolution, assembles the monthly SUP 16.14A return, maintains the CASS 10A resolution pack from live data and produces audit-ready evidence — all from a single record.
About Safeheld
Safeheld is the safeguarding platform for FCA-regulated payment and e-money firms, covering daily reconciliation, breach management, regulatory reporting, resolution pack maintenance and audit evidence. Safeheld is a Buckingham Capital Consulting company. safeheld.com
About Buckingham Capital Consulting
Buckingham Capital Consulting is a leading UK and European financial services regulatory consultancy. Since 2013 we have advised payment institutions, electronic money institutions, investment firms and cryptoasset businesses on authorisation, prudential and conduct requirements, safeguarding, governance and regulator engagement across the UK and EU. Contact our safeguarding team
CASS 15 Explained: The FCA's Safeguarding Regime for Payment and E-Money Firms



