top of page

FCA Safeguarding Audits CASS 15: What PIs and EMIs Must Prepare in 2026

  • Jul 15
  • 15 min read
Safeguarding Audits Under CASS 15: What PIs and EMIs Must Prepare in 2026

Safeguarding Audits Under CASS 15: What PIs and EMIs Must Prepare in 2026

The FCA’s strengthened safeguarding regime has changed the annual safeguarding audit from an inconsistently applied expectation into a formal regulatory requirement for most payment and electronic money institutions that hold material amounts of customer funds.


Since 7 May 2026, Authorised Payment Institutions and Electronic Money Institutions within scope of SUP 3A must arrange an annual safeguarding audit where they do not qualify for the £100,000 relevant-funds exemption. The audit is a reasonable assurance engagement addressed to the FCA and examines both whether the firm maintained systems capable of complying with the safeguarding regime throughout the audit period and whether it was actually compliant at the period end.


This makes safeguarding audit readiness considerably broader than preparing a policy and producing several bank statements for the auditor. Firms need to demonstrate that CASS 15 works operationally across the complete safeguarding lifecycle, including identification of relevant funds, segregation, daily reconciliations, third-party due diligence, acknowledgement arrangements, record keeping, resolution packs, monthly REP027 reporting and governance.


For many firms, the first audit under the new regime will be the first time these arrangements are tested systematically against detailed FCA Handbook rules. Boards and senior management should therefore treat audit preparation as an ongoing control process rather than an exercise that begins shortly before the auditor arrives.


CASS 15 safeguarding audit requirements at a glance

Requirement

Position from 7 May 2026

Main firms in scope

APIs providing payment services other than solely PIS/AIS, and electronic money institutions

Audit exemption

Available where the institution has not been required to safeguard more than £100,000 of relevant funds at any time for a period of at least 53 weeks

Assurance level

Reasonable assurance

Auditor

Independent external auditor meeting FCA qualification, independence, skill and experience requirements

Audit frequency

Annual, with the period covered ending no more than 53 weeks after the relevant preceding date

First audit submission

Transitional timing allows the first report to be delivered within 6 months of the audit period end

Subsequent audits

Generally submitted to the FCA within 4 months of the audit period end

Report recipient

Addressed and delivered directly to the FCA by the auditor, with the final report also provided to the institution

Core opinion

Whether adequate systems were maintained throughout the period and whether the institution complied at the period end

Breaches

Individual breaches identified during the audit must be recorded in the prescribed breaches schedule

The audit rules sit within SUP 3A, while the underlying safeguarding requirements are spread across the Payment Services Regulations 2017, Electronic Money Regulations 2011, CASS 15, CASS 10A and associated FCA rules and guidance. Firms should therefore prepare against the complete safeguarding framework rather than treating CASS 15 as the only source of audit criteria.


Which PIs and EMIs need a safeguarding audit?

The mandatory SUP 3A audit regime applies principally to Authorised Payment Institutions that provide payment services other than solely payment initiation or account information services, together with Electronic Money Institutions. This includes institutions using the segregation method and those using an insurance or guarantee method, because the audit requirement is concerned with compliance with the relevant funds regime rather than one particular method of safeguarding.


An exemption applies where the institution has not been required to safeguard more than £100,000 of relevant funds at any time for a period of at least 53 weeks. This is not simply a year-end balance test. Senior management must determine on a continuing basis whether the firm qualifies for the exemption and must arrange an auditor once the conditions for exemption are no longer met.


A firm that ordinarily safeguards £50,000 but temporarily holds £150,000 may therefore need to reconsider its audit status. The threshold focuses on whether the institution was required to safeguard more than £100,000 at any point during the relevant period, not merely its average or typical safeguarding balance.


Safeguarding institutions outside the mandatory SUP 3A audit population still need adequate safeguarding arrangements. The FCA expressly recognises that voluntarily arranging an audit may help a firm demonstrate that those arrangements are effective, particularly where the operating model is complex or senior management wants independent assurance before regulatory scrutiny.


What does the safeguarding auditor actually give an opinion on?

The safeguarding report is not merely a review of whether money was present in the safeguarding bank account on one selected date.


Under SUP 3A, the auditor provides a reasonable assurance opinion on two fundamental questions. First, whether the institution maintained systems adequate to enable it to comply with the relevant funds regime throughout the audit period. Second, whether the institution was compliant with that regime at the end of the period covered by the report.


The first question makes the audit inherently operational. An institution could have the correct amount of money in its safeguarding account at year end but still have serious weaknesses if its daily processes regularly misidentified relevant funds, reconciliations were unreliable, shortfalls were not corrected promptly or records could not demonstrate individual customer entitlements.


The second question tests the actual position at the reporting date. The auditor needs sufficient evidence to determine whether the institution was complying with the applicable safeguarding requirements, rather than merely having policies that described how compliance was supposed to work.


This distinction is why firms should prepare evidence across the entire audit period. A clean balance on the final day cannot retrospectively cure months of control failures.


Reasonable assurance means the audit is substantive

The FCA requires the safeguarding report to be prepared as a reasonable assurance engagement. That is a higher level of assurance than the limited-assurance approach contemplated for some firms during earlier policy development.


In practical terms, the auditor needs sufficient appropriate evidence to support a positive opinion on the institution’s systems and compliance. This is likely to involve testing processes, records, reconciliations, transactions, third-party arrangements and governance rather than relying primarily on management representations.


The FCA also expects auditors to identify individual regulatory breaches encountered during the audit and include them in the prescribed breaches schedule. A breach does not automatically mean the auditor must issue an adverse opinion, because the auditor will consider its significance, duration, context and recurrence, but firms should not assume that minor breaches disappear simply because they fall below a financial materiality threshold.


This creates an important distinction between audit preparation and cosmetic remediation. A firm should not focus solely on ensuring the final month looks clean. The auditor may test historical evidence across the period, and weaknesses identified earlier may still need to be disclosed and explained even where they have subsequently been corrected.


Daily reconciliations will be central to audit readiness

CASS 15 requires internal and external safeguarding reconciliations at least once each reconciliation day. These processes are likely to form one of the most important areas of evidence during a safeguarding audit because they demonstrate whether the firm knows what it owes customers, what safeguarding resources it holds and whether discrepancies are identified and corrected promptly.


The internal reconciliation should establish the firm’s safeguarding requirement from its own books and records and compare that requirement with the safeguarding resource calculated under the applicable methodology. The external reconciliation then verifies relevant internal records against records held by banks, custodians or other third parties.


Auditors are likely to examine more than whether a reconciliation spreadsheet exists. The methodology, data inputs, timing, treatment of cut-offs, pending transactions, unallocated funds, foreign exchange, fees and exceptions all affect whether the reconciliation is reliable.


Evidence of review is equally important. Where discrepancies occur, the firm should be able to show what caused them, how quickly they were investigated, whether a shortfall arose, what corrective action was taken and whether recurring issues were escalated.


Our detailed guide to FCA safeguarding reconciliations explains the internal and external reconciliation requirements in more detail.


The audit will test how the firm identifies relevant funds

One of the most common underlying safeguarding risks is incorrect classification of customer money.

A firm must determine when money becomes relevant funds, how long the safeguarding obligation continues and which amounts fall outside the regime. This can become complicated where the business handles card settlement flows, merchant acquiring, cross-border transfers, fees, refunds, chargebacks, prefunding or funds received through agents and distributors.


The audit trail should allow the firm to explain how each material category of funds is treated and why. The methodology should be reflected consistently across customer terms, operational systems, accounting records, safeguarding calculations and regulatory reporting.


Unallocated customer funds require particular care. The fact that a firm cannot immediately identify the individual customer does not necessarily mean the money is outside safeguarding. Where the firm can identify that the money was received for a payment transaction or in exchange for e-money, it may still constitute relevant funds and should be treated accordingly while the firm seeks to resolve the allocation.


A safeguarding policy that uses high-level regulatory wording without mapping these rules to the firm’s actual transaction flows will provide limited audit comfort. The auditor needs to see how the rule operates in practice.


Safeguarding bank accounts and acknowledgement arrangements

Where the segregation method is used, auditors will examine whether relevant funds are placed into appropriate safeguarding accounts and whether the institution has documented the legal and operational protections around those accounts correctly.


Account names should clearly indicate their safeguarding purpose wherever possible, and the firm should maintain the required acknowledgement documentation with the relevant credit institution. The wording, execution and continued validity of those arrangements matter because they help demonstrate that the account is not treated as an ordinary corporate account available to satisfy the firm’s own liabilities.


The firm should also evidence due diligence on the bank or other institution holding relevant funds. CASS 15 requires safeguarding institutions to exercise due skill, care and diligence in selecting, appointing and periodically reviewing third parties, taking into account factors such as financial strength, market reputation, concentration risk and the legal protections available to customers.


An old due diligence file completed when the bank account was first opened will not necessarily be sufficient. Reviews should be refreshed at least annually and when material circumstances change, with the rationale for continuing to use the institution documented clearly.


Third-party due diligence needs evidence, not assumptions

Many payment and e-money firms rely on a network of banks, custodians, processors, agents and other service providers. The safeguarding audit will therefore extend beyond controls performed entirely within the regulated firm.


The FCA expects institutions to demonstrate that they have assessed the suitability of third parties holding or managing relevant funds. This should include the institution’s financial standing, regulatory status where relevant, operational capability, concentration exposure and the legal framework governing customer protection.


For overseas safeguarding arrangements, the legal analysis can be particularly important. The firm should understand whether local insolvency law recognises the priority and protection intended under the UK safeguarding regime and whether any contractual or legal issues could interfere with the return of customer funds.


The audit evidence should show not only that due diligence was performed but how the decision was reached. Where significant amounts of customer money are concentrated with one institution, senior management should understand and document why that concentration remains appropriate.


This is an area where firms often have strong commercial onboarding files but weak regulatory evidence. Credit limits, pricing negotiations and service-level agreements do not replace safeguarding-specific due diligence.


Resolution packs will form part of the evidence trail

CASS 10A requires firms within scope to maintain a resolution pack that can help an insolvency practitioner, administrator or other relevant person identify and return safeguarded funds promptly if the institution fails.


The resolution pack should be maintained as a live operational resource rather than assembled retrospectively for audit. It needs to contain or provide rapid access to key information about safeguarding accounts, relevant third parties, reconciliations, customer entitlements, systems, records, key contacts and other information needed to understand the safeguarding arrangements.


Auditors may examine whether the pack is complete, current and capable of being retrieved within the required timeframe. A document index containing expired contracts, old bank details or links to inaccessible systems will not achieve the regulatory purpose.


Firms should therefore test the resolution pack periodically. A useful test is whether an informed external person with no previous knowledge of the business could use the material to understand where customer funds are held, how much should be safeguarded and how customer entitlements can be reconstructed.


The quality of the resolution pack often reveals the quality of the underlying safeguarding framework. Where records, responsibilities and processes are fragmented, the pack usually exposes those weaknesses quickly.


REP027 should reconcile with the underlying safeguarding records

Since 7 May 2026, firms within scope must submit monthly safeguarding information to the FCA through REP027. The return gives the regulator regular visibility over relevant funds, safeguarding arrangements and compliance with key obligations.


The audit and REP027 should not operate as separate regulatory processes. Figures and declarations in monthly returns should be supported by the same books, reconciliation data and safeguarding methodology used by the firm operationally.


Inconsistencies between REP027, daily reconciliation records, bank statements and management information can create difficult audit questions. Even where each number can eventually be explained, repeated differences may indicate weak data governance or insufficient review before regulatory submissions.


Firms should therefore build a documented reconciliation between regulatory reporting and the underlying safeguarding records. Significant adjustments, unusual movements and changes in methodology should be understood and approved rather than discovered for the first time during the audit.


Our guide to FCA regulatory reporting for Payment Institutions and EMIs covers the wider reporting obligations that sit alongside REP027.


Governance and board oversight are part of safeguarding compliance

Safeguarding should have clear ownership within the institution.

The FCA expects an appropriate individual to have oversight of the safeguarding framework, but effective governance requires more than naming someone in a policy. Responsibility should be reflected in actual decision-making, management information, escalation procedures and board oversight.


Senior management should receive information that allows it to understand safeguarding balances, reconciliation breaks, shortfalls, unresolved exceptions, third-party concentrations, audit findings and regulatory reporting issues. Where recurring problems arise, the board should be able to see whether root causes are being addressed rather than simply receiving confirmation that each individual break was closed.


The auditor may also consider how identified breaches were handled. Evidence should show when management became aware of the issue, how materiality was assessed, whether regulatory notification was considered and what remedial action followed.


A mature framework creates an evidence trail from operational exception through investigation, escalation, decision and closure. Where governance exists mainly through informal conversations, proving effective oversight becomes much harder.


Every breach identified during the audit matters

The new safeguarding report includes a specific breaches schedule.


Under SUP 3A, the auditor must identify each individual regulation or rule within scope where a breach has been identified during the audit. This includes breaches identified by the auditor, disclosed by the institution or identified through other relevant sources during the review.


The existence of a breach does not necessarily mean the overall audit opinion will be qualified or adverse. The auditor applies professional judgement to its significance, considering factors such as duration, context and recurrence. Nevertheless, the FCA receives direct visibility of the breaches reported.


Firms should therefore maintain their own safeguarding breach register throughout the year. Waiting for the auditor to identify issues first can indicate that internal compliance monitoring is not operating effectively.


The register should distinguish isolated operational errors from systemic weaknesses, record remediation and identify repeated themes. Where the same reconciliation, segregation or record-keeping issue occurs repeatedly, the underlying control design should be reviewed rather than treating each occurrence as an unrelated exception.


Choosing the safeguarding auditor

A firm does not have to use the same auditor for its safeguarding audit and its statutory financial statements.

The appointed safeguarding auditor must meet the applicable qualification and independence requirements, and the institution must take reasonable steps to ensure that the auditor has the skill, resources and experience necessary to perform the work. The FCA specifically expects firms to consider whether the auditor understands the relevant safeguarding requirements and has access to appropriate specialist expertise.


This means price should not be the only selection criterion. CASS 15 is a specialist operational regime, and an auditor unfamiliar with payment flows, e-money liabilities, safeguarding reconciliations or the distinction between relevant and non-relevant funds may require significantly more time to understand the business.


Firms should engage the auditor early enough to agree the audit period, evidence requirements, data format and practical timetable. Waiting until after the audit period has ended can create unnecessary pressure, particularly where historic evidence needs to be reconstructed.


Auditor independence should also be considered where advisers have helped design or operate the safeguarding framework. The firm needs to distinguish between regulatory advisory support, internal assurance and the independent external audit required under SUP 3A.


When is the first safeguarding audit due?

The audit period does not have to align with the firm’s financial year, although firms may choose to align the two where this is operationally convenient.


Under SUP 3A, the period covered by a safeguarding report must end no more than 53 weeks after the institution first becomes subject to the audit chapter, becomes subject again after losing an exemption, or after the end of the previous audit period. The FCA introduced transitional timing for the first audit following implementation of the new regime, allowing the first safeguarding report to be delivered within six months after the relevant period end.


For subsequent audits, the standard requirement is for the auditor to deliver the report to the FCA within four months of the end of the period covered. The final report is also provided to the institution at the same time.

The important practical point is that firms should establish their audit timetable now rather than waiting for the reporting deadline. The auditor needs evidence spanning the audit period, and weaknesses in historic records cannot always be repaired retrospectively.


The FCA’s current safeguarding guidance for payment and e-money institutions summarises the new audit timetable and the wider requirements introduced from 7 May 2026.


A practical safeguarding audit-readiness review

A strong pre-audit review should test the safeguarding framework in the same way an informed external reviewer would approach it. It should begin with the complete flow of customer money, identifying when safeguarding starts, which legal entity receives the funds, where the money moves and when the safeguarding obligation ends.


The review should then test whether the written methodology matches operational reality. Daily internal and external reconciliations should be independently recalculated for selected dates, unusual transactions traced through the process and discrepancies examined to determine whether escalation and correction were timely.


Third-party files, safeguarding account documentation, resolution packs, REP027 returns and board reporting should be reviewed as one connected framework. Inconsistencies between these records often reveal weaknesses that are not obvious when each document is examined separately.


Finally, the firm should identify known breaches and remediation before the external audit begins. The objective should not be to conceal historic issues but to demonstrate that management understands them, has assessed their significance and has implemented sustainable corrective action.


Our Safeguarding Readiness Checker can also help firms identify initial PS25/12 and CASS 15 gaps before an audit or supervisory review.


Common safeguarding audit weaknesses

The most serious audit findings are not always dramatic shortfalls in customer money. More commonly, weaknesses arise because the firm cannot demonstrate consistently that its safeguarding calculation and control framework are reliable.


Typical issues include incorrectly identifying when funds become relevant, using reconciliation methodologies that do not capture all liabilities, relying on unexplained manual adjustments, failing to investigate recurring reconciliation differences and maintaining incomplete evidence of management review.


Other weaknesses include outdated safeguarding bank due diligence, incomplete acknowledgement arrangements, resolution packs that do not reflect the current business, inconsistent REP027 reporting and poor documentation of breaches or shortfalls.


Fast-growing firms face an additional risk. Safeguarding processes that worked at lower transaction volumes can become unreliable when new products, currencies, agents, banks or settlement models are introduced without redesigning the underlying controls.


The best audit preparation therefore focuses on whether the framework still reflects the business that exists today. A policy written for the firm’s original authorisation model may no longer describe how money actually moves through the organisation.


What should boards and compliance teams do before the audit?

The first step is to determine formally whether the institution is within the mandatory SUP 3A audit requirement and establish the relevant audit period and submission timetable. Where the firm relies on the £100,000 exemption, senior management should retain evidence supporting that conclusion and continue monitoring eligibility.


The firm should then complete an independent audit-readiness assessment covering the entire safeguarding lifecycle. Any material weaknesses should be prioritised according to customer risk, regulatory significance and the time needed to produce a reliable evidence trail before the external audit.


Known breaches should be recorded transparently and remediation should be documented. Where controls have changed, the firm should retain evidence of the previous issue, the reason for the change, implementation testing and subsequent monitoring.


Finally, boards should treat the audit as an annual assurance mechanism rather than a compliance deadline. The strongest firms operate continuously as though their safeguarding arrangements may need to be evidenced tomorrow, because the same records that support the annual audit also support FCA supervision, monthly reporting and an orderly return of customer funds if the firm fails.


How Buckingham Capital Consulting can help

Buckingham Capital Consulting supports Payment Institutions and Electronic Money Institutions with safeguarding, CASS 15 and PS25/12 compliance, including preparation for the new safeguarding audit regime.


We can conduct a pre-audit safeguarding gap assessment before the external auditor begins fieldwork, reviewing the firm’s relevant-funds methodology, transaction flows, safeguarding accounts, internal and external reconciliations, third-party due diligence, resolution pack, REP027 reporting, governance and breach management.


Where weaknesses are identified, we provide a prioritised remediation plan and work with management to strengthen the underlying framework. This can include redesigning safeguarding methodologies and procedures, reviewing reconciliation approaches, strengthening governance and management information, improving regulatory evidence and preparing the firm to respond efficiently to auditor findings.


We can also support boards and compliance teams where an audit identifies breaches or control weaknesses, including regulatory impact assessment, remediation planning and preparation for FCA engagement where necessary.


The independent safeguarding audit itself must be performed by an appropriately qualified and independent external auditor. Our role is to help the firm ensure that the regulatory framework being audited is properly designed, operationally effective and supported by the evidence the auditor and FCA will expect.


To discuss safeguarding audit readiness, a CASS 15 gap assessment or remediation following an audit finding, contact Buckingham Capital Consulting.


Frequently asked questions

Do all Payment Institutions and EMIs need an annual safeguarding audit?

Not every firm does. SUP 3A principally applies to Authorised Payment Institutions providing payment services other than solely PIS or AIS and to Electronic Money Institutions, subject to the audit exemption. An institution is exempt where it has not been required to safeguard more than £100,000 of relevant funds at any time for a period of at least 53 weeks. Senior management is responsible for monitoring whether the exemption continues to apply.


What type of assurance is required for a CASS 15 safeguarding audit?

The safeguarding report must be prepared as a reasonable assurance engagement. The auditor provides an opinion on whether the firm maintained systems adequate to enable compliance with the relevant funds regime throughout the period and whether it was compliant at the end of the period.


When is the first safeguarding audit due under the 2026 rules?

The new safeguarding regime took effect on 7 May 2026. The audit period must comply with the SUP 3A timing rules, and transitional provisions allow the first safeguarding report to be delivered within six months of the end of the relevant audit period. Subsequent reports are generally required within four months of the period end.


Does the safeguarding auditor need to be the same firm as the statutory auditor?

No. The FCA expressly allows the safeguarding auditor and statutory financial statements auditor to be different firms. The safeguarding auditor must nevertheless satisfy the applicable qualification and independence requirements and have the necessary skill, resources and experience to perform the specialist safeguarding work.


What should a PI or EMI prepare before a safeguarding audit?

The firm should prepare evidence covering the complete safeguarding lifecycle, including its relevant-funds methodology, transaction flows, safeguarding account arrangements, daily internal and external reconciliations, third-party due diligence, resolution pack, REP027 returns, breach records and governance. A pre-audit gap assessment can identify weaknesses early enough for sustainable remediation before the external audit is completed.

 
 
bottom of page