top of page

FCA Safeguarding Reconciliations 2026: Internal and External Reconciliation Requirements Explained

  • 6 days ago
  • 13 min read

FCA Safeguarding Reconciliations 2026: Internal and External Reconciliation Requirements Explained

FCA Safeguarding Reconciliations 2026: Internal and External Reconciliation Requirements Explained

Daily safeguarding reconciliations are now one of the most important operational requirements for UK Payment Institutions and Electronic Money Institutions.


Since 7 May 2026, firms within scope of CASS 15 have been required to perform internal and external safeguarding reconciliations at least once each reconciliation day. The purpose is to establish whether the amount a firm is required to safeguard is properly reflected in its records and whether the relevant funds or assets are actually held where the firm expects them to be.


The rules are more demanding than simply checking a safeguarding bank balance against a customer ledger. Firms must maintain accurate records, calculate their safeguarding requirement correctly, reconcile internal and third-party information, investigate discrepancies and correct shortfalls promptly. For firms with high transaction volumes, multiple currencies, agents, acquiring flows or several banking partners, the quality of the reconciliation process is likely to become one of the clearest indicators of whether the wider safeguarding framework is working properly.


What is a safeguarding reconciliation?

A safeguarding reconciliation is the process by which a payment or e-money firm checks that the customer funds it is required to protect are accurately recorded and appropriately safeguarded.


CASS 15 requires two distinct processes: an internal safeguarding reconciliation and an external safeguarding reconciliation. They serve different purposes and should not be treated as interchangeable.


The internal reconciliation tests the firm’s own records and calculations. It asks whether the firm’s safeguarding resource corresponds with its safeguarding requirement and whether the correct amount has been placed into safeguarding accounts or relevant assets where required.


The external reconciliation then tests the accuracy of those internal records against information from the banks, custodians or other third parties actually holding the safeguarded funds or relevant assets.


Together, the two processes are intended to identify shortfalls, excesses, record-keeping errors and differences between what the firm believes it holds and what is actually held externally.


Internal and external safeguarding reconciliations at a glance

Reconciliation

What it checks

Main source of information

Internal safeguarding reconciliation

Whether the firm’s safeguarding resource matches its safeguarding requirement

Internal books, ledgers, payment accounts and accounting records

External safeguarding reconciliation

Whether internal records agree with balances held by banks, custodians and other third parties

Bank statements, custodian records and other independent confirmations

Frequency

At least once each reconciliation day, and more frequently where necessary

Determined by CASS 15 and the firm’s operating model

Discrepancies

Must be identified, investigated and resolved promptly

Reconciliation records and supporting evidence

Shortfalls

Generally must be corrected as soon as possible and by the end of the reconciliation day

Firm funds or relevant funds as permitted by the rules

The distinction matters because a firm cannot establish that its safeguarding arrangements are correct simply by looking at the balance in its safeguarding bank account. It must first determine independently how much it should be safeguarding and then verify that amount against external evidence.


What is an internal safeguarding reconciliation?

An internal safeguarding reconciliation is designed to test whether the firm’s own records show that the correct amount of customer money is being protected.


The firm must calculate its safeguarding requirement, which represents the amount of relevant funds it should be safeguarding for customers, and compare this with its safeguarding resource. The calculation must be based on the firm’s internal records and ledgers rather than simply using the balance shown on a bank statement.

This distinction is fundamental. If a firm uses the same external bank balance both to calculate what it should be safeguarding and to confirm what is actually safeguarded, the reconciliation loses its independence and may fail to identify an underlying record-keeping error.


The firm therefore needs reliable internal records capable of identifying how much is owed to each customer and how those individual balances aggregate into the overall safeguarding requirement. Transaction records, payment accounts, internal ledgers and accounting systems must be sufficiently accurate to support the calculation at the selected reconciliation point.


The detailed rules governing these processes are set out in CASS 15.8 of the FCA Handbook.


What is an external safeguarding reconciliation?

The external safeguarding reconciliation compares the firm’s internal records with information obtained independently from the institutions actually holding the relevant funds or relevant assets. For funds held in safeguarding bank accounts, the firm compares its recorded balance for each account with the balance confirmed by the bank. The comparison is performed currency by currency. Where relevant assets are used, the firm must compare its records with the quantities confirmed by the relevant custodian or other third party.


The purpose is to identify whether the external position matches what the firm believes should be held. A difference may arise because of transaction timing, incorrect booking, missing transactions, fees, bank errors or weaknesses in the firm’s own records.


Where possible, the external information should relate to the same point in time used for the internal safeguarding reconciliation. If the timing cannot be aligned exactly, the firm’s documented methodology should explain how it deals with that difference so that the reconciliation still achieves its purpose.


This is particularly important for firms operating across multiple time zones or using banking and payment partners whose statements update at different times. Timing differences may be legitimate, but they need to be understood, documented and consistently treated rather than becoming a permanent explanation for unexplained reconciliation breaks.


How often must safeguarding reconciliations be performed?

Internal and external safeguarding reconciliations must generally be performed as frequently as necessary and at least once each reconciliation day.


A reconciliation day excludes weekends, bank holidays and certain days when relevant foreign markets are not open. However, the minimum frequency should not automatically be treated as sufficient for every business.

A firm processing large transaction volumes, operating continuously across several markets or experiencing rapid movements in relevant funds may need more frequent controls to maintain accurate records and protect customers effectively. The reconciliation methodology should reflect the nature, scale and complexity of the business rather than being designed solely around the minimum wording of the rule.


The firm must also establish consistent reconciliation points. Internal reconciliations should use the firm’s records as at those defined points, allowing the methodology to be repeated and independently reviewed.


For compliance and audit purposes, consistency is important. Changing cut-off times, data sources or calculation methods without clear justification can create unexplained movements and make it difficult to demonstrate that the process is operating reliably.


Calculating the safeguarding requirement correctly

The quality of a safeguarding reconciliation depends heavily on whether the safeguarding requirement itself is accurate.


For a relatively simple remittance business, the calculation may be straightforward. For a larger EMI or payment institution, it can involve thousands or millions of transactions across payment accounts, card programmes, acquiring arrangements, refunds, chargebacks, agents, different currencies and multiple settlement cycles.


The firm must be able to determine promptly how much it should be safeguarding for each client and maintain records that explain the transactions and commitments underlying those balances. This requires a clear methodology for deciding when funds enter and leave the safeguarding calculation and how different transaction states are treated.


Problems often arise where the operational systems and the safeguarding methodology have developed separately. For example, the transaction platform may classify a payment as completed while the safeguarding methodology continues to treat the funds as relevant, or the reverse. Fees, refunds and unsettled transactions can also create differences where their treatment is not defined consistently.


A robust methodology should therefore explain how each material type of transaction affects the safeguarding requirement. The calculation should be capable of being reproduced from the underlying data and independently reviewed by someone who was not responsible for preparing it.


AEMIs may need separate reconciliations for different asset pools

Authorised Electronic Money Institutions can create additional complexity where they provide both electronic money services and payment services unrelated to the issuance of electronic money.


CASS 15 requires relevant funds relating to those activities to be distinguished appropriately. Where an AEMI provides unrelated payment services alongside e-money issuance, the relevant provisions apply separately to the electronic money asset pool and the unrelated payment services asset pool.


In practical terms, this means the firm must be able to identify which customer funds belong to which activity and reconcile them accordingly. Combining the balances into one undifferentiated calculation can obscure shortfalls and make it difficult to establish which customers have claims against which asset pool if the firm fails.


This is an area where firms with several product lines should review their transaction mapping carefully. The legal classification of the product, the contractual relationship with the customer and the purpose for which funds are received all influence how the safeguarding obligation should be applied.


What happens when a reconciliation identifies a shortfall?

A safeguarding shortfall requires prompt action.


Where the internal reconciliation identifies that the safeguarding resource is lower than the safeguarding requirement, the firm must determine the reason for the discrepancy and correct the shortfall as soon as possible. Under CASS 15, the shortfall generally needs to be addressed by the end of the day on which the reconciliation is performed.


The firm should not treat topping up the account as the end of the matter. The immediate financial correction protects customers, but management must also understand why the shortfall arose.


A one-off timing issue can require a different response from a recurring systems error or an incorrectly designed calculation. Where the same category of shortfall repeatedly appears, simply adding the firm’s own money each day does not resolve the underlying control weakness.


Recurring shortfalls should therefore be analysed for root cause, documented and escalated appropriately. Where the underlying issue affects the accuracy of records or indicates a material safeguarding failure, the firm should also consider whether FCA notification requirements are triggered.


How should reconciliation discrepancies be handled?

Not every reconciliation difference represents a safeguarding breach, but every material difference needs to be understood.


A discrepancy may arise because a payment was recorded internally before appearing on an external bank statement, because of a foreign-exchange timing difference, an unallocated receipt, an incorrect ledger entry or a genuine shortfall. The purpose of the reconciliation process is to distinguish legitimate timing items from errors that require correction.


Firms should establish clear procedures for investigating reconciliation breaks, including ownership, ageing and escalation thresholds. An unexplained item should not remain indefinitely on the reconciliation simply because its value is small or because similar items have occurred before.


The FCA rules require firms to record the time and date of each reconciliation, the actions taken, the outcome of the safeguarding calculation and other relevant results. The supporting audit trail should therefore show not only that the process was completed but also how discrepancies were investigated and resolved.


This evidence becomes particularly important during a safeguarding audit or FCA review. A reconciliation file containing repeated manual adjustments with little explanation can indicate that the control is being used to force the numbers to agree rather than to identify genuine differences.


Timing differences need proper control

Timing differences are unavoidable in many payment businesses, but they are also one of the easiest areas in which weak reconciliation practices can become normalised.


A payment may be recorded in the firm’s systems at one time and appear in a bank or scheme settlement account later. Cross-border transactions may span different banking days, and card acquiring arrangements can involve settlement delays that do not align neatly with the firm’s internal cut-off.


These differences should be predictable and supported by evidence. The reconciliation methodology should explain the expected timing, how the item is recorded while outstanding and when it should clear.


Ageing is particularly important. A genuine timing difference should normally reverse or settle within an expected period. Where an item remains unresolved beyond that period, it should be investigated rather than continuing to be described as timing indefinitely.


Management information should also distinguish normal timing items from unexplained breaks. Without that distinction, a reconciliation can appear operationally stable while significant unresolved issues accumulate beneath the headline balance.


Manual reconciliations create additional risk

CASS 15 does not require every safeguarding reconciliation to be fully automated, and many smaller firms will continue to use spreadsheets or other manual processes. Manual reconciliation is not inherently non-compliant, but it creates greater exposure to human error, inconsistent treatment and weak audit trails.


The risk increases as transaction volumes and business complexity grow. A process that worked adequately for a firm processing a few thousand transactions may become unreliable once the business operates multiple products, currencies and banking relationships.


Manual adjustments should be controlled carefully. The reason for each material adjustment should be documented, evidence retained and an appropriate reviewer should be able to understand why the adjustment was necessary.


Firms should also consider key-person dependency. If only one employee understands the reconciliation workbook, the methodology or the adjustments required each morning, the safeguarding framework has an operational resilience weakness even where the reconciliation is technically completed on time.


Automation should therefore be considered where it reduces genuine risk, but technology alone is not the answer. An automated reconciliation built on incorrect regulatory logic will produce incorrect results more efficiently. The methodology must be right before the process is automated.


Reconciliations should connect to REP027 and wider safeguarding governance

Daily reconciliations should not operate in isolation from the firm’s wider safeguarding framework.

The data used to calculate and reconcile relevant funds should be consistent with the information used for monthly safeguarding reporting, management information, safeguarding audits and the firm’s resolution pack. Significant differences between these sources may indicate inconsistent definitions or data sets.


Under the new regime, firms within scope submit monthly safeguarding information to the FCA through REP027. This gives the regulator greater visibility over safeguarding balances and arrangements and makes consistency between daily controls and regulatory reporting increasingly important.


Senior management should receive information that allows it to understand the quality of the reconciliation process rather than simply whether it was completed. This should include material shortfalls, recurring breaks, aged discrepancies, manual adjustments, systems issues and overdue remediation actions.


Our Safeguarding and CASS services support payment and e-money firms with reconciliation methodology, safeguarding reviews, audit readiness and remediation.


Common reconciliation weaknesses to review

The most significant weaknesses are often not obvious failures to perform a daily reconciliation. They are weaknesses within a process that appears to be operating.


A firm may complete its reconciliations every morning but use incomplete transaction data, treat unresolved differences inconsistently or rely on recurring manual adjustments. Another may reconcile the safeguarding bank account accurately but calculate the underlying safeguarding requirement incorrectly, meaning that the entire exercise starts with the wrong number.


Other weaknesses can include poor treatment of fees, refunds and chargebacks, failure to distinguish separate asset pools, inconsistent cut-off times, inadequate evidence supporting adjustments and excessive reliance on one individual who understands the process.


The key question is therefore not simply whether reconciliations are being completed. It is whether the methodology can demonstrate, consistently and independently, that the right amount of customer money is being safeguarded.


What should firms test now?

Firms should review a representative sample of reconciliations from beginning to end rather than limiting assurance work to the final spreadsheet or report.


The review should trace the safeguarding requirement back to underlying customer and transaction records, confirm that internal and external reconciliations use the correct data sources and assess how differences were investigated. It should also check whether shortfalls were corrected within the required timeframe and whether recurring issues were escalated for remediation.


The methodology should then be compared with the actual business model. New products, banking partners, currencies, agents or settlement processes can make an originally sound methodology incomplete if it has not been updated as the business changes.


Finally, firms should consider whether another competent person could reproduce and explain the reconciliation without relying on undocumented knowledge. A well-controlled process should be repeatable, reviewable and understandable to compliance, senior management and the safeguarding auditor.


For firms reviewing the wider regime, our PS25/12 and CASS 15 safeguarding guide explains the broader requirements introduced on 7 May 2026.


Why safeguarding reconciliations now matter more to the FCA

The FCA introduced the strengthened safeguarding regime because it identified weaknesses in how some payment and e-money firms protected customer funds. The objective is to reduce shortfalls and improve the speed with which money can be returned to customers if a firm fails.


Daily reconciliations are central to that objective because they provide an early warning mechanism. A well-designed process should identify when the amount being safeguarded is insufficient, when records are inaccurate or when external balances do not correspond with the firm’s expectations.


The introduction of monthly reporting and formal safeguarding audits also means reconciliation weaknesses are more likely to become visible. Firms should expect auditors and the FCA to look beyond whether a reconciliation file exists and consider whether the methodology, data, governance and resolution of discrepancies demonstrate effective safeguarding in practice.


For boards and senior management, this makes reconciliation quality an important indicator of wider safeguarding risk. Persistent breaks, unexplained adjustments or frequent shortfalls should not be viewed as routine finance issues; they can point to weaknesses in systems, product design, data quality or governance that require broader remediation.


How Buckingham Capital Consulting can help

Buckingham Capital Consulting has specialised in payment and electronic money regulation since 2013, supporting Payment Institutions and Electronic Money Institutions with safeguarding, FCA compliance and regulatory remediation.


We review safeguarding reconciliation frameworks from both a regulatory and operational perspective, including the calculation of the safeguarding requirement, internal and external reconciliation methodology, treatment of discrepancies, governance, records and alignment with REP027 reporting. The objective is to determine whether the process actually demonstrates that customer funds are protected rather than simply whether a reconciliation procedure exists.


Our work can include safeguarding gap assessments, review or redesign of reconciliation methodologies, testing of daily reconciliations, CASS 15 compliance reviews, safeguarding audit readiness and remediation of findings raised by auditors or the FCA.


Where weaknesses are identified, the focus should be on correcting the underlying process rather than adding further layers of manual checking around an unreliable methodology. Effective safeguarding depends on accurate data, clear regulatory treatment of transactions and controls that remain reliable as the business grows.


To discuss a safeguarding reconciliation review, CASS 15 compliance assessment or preparation for a safeguarding audit, contact Buckingham Capital Consulting.


Frequently asked questions

How often must payment and e-money firms perform safeguarding reconciliations?

Firms within scope of CASS 15 must generally perform internal and external safeguarding reconciliations as frequently as necessary and at least once each reconciliation day. The appropriate frequency should reflect the scale and complexity of the business, so firms with high transaction volumes or more complex operating models may need additional controls beyond the minimum frequency.


What is the difference between an internal and external safeguarding reconciliation?

The internal safeguarding reconciliation uses the firm’s own books and records to determine whether its safeguarding resource corresponds with its safeguarding requirement. The external rec

onciliation compares the firm’s internal records with independent information from banks, custodians or other third parties holding relevant funds or assets. Using both processes helps identify errors within the firm’s own records as well as differences between internal and external balances.


What happens if a safeguarding reconciliation identifies a shortfall?

The firm must determine why the shortfall arose and take action to correct it promptly. Under CASS 15, a shortfall identified through the relevant reconciliation process generally needs to be corrected as soon as possible and by the end of the day on which the reconciliation is performed. The firm should also investigate the root cause, particularly where similar shortfalls recur.


Can safeguarding reconciliations be performed using spreadsheets?

Yes, the rules do not require every firm to use an automated reconciliation platform. However, a spreadsheet-based process must still be accurate, controlled, independently reviewable and capable of producing a reliable audit trail. As transaction volumes and complexity increase, firms should assess whether manual processes continue to provide an appropriate level of control.


What should firms do if they are unsure whether their reconciliation methodology complies with CASS 15?

The firm should test the complete methodology rather than reviewing the written procedure alone. This should include tracing the safeguarding requirement to underlying customer records, testing internal and external reconciliation inputs, reviewing how timing differences and discrepancies are handled and confirming that shortfalls are corrected appropriately. An independent safeguarding review before the first full audit cycle can identify weaknesses while there is still time to remediate them.

 
 
bottom of page