Monthly Safeguarding Return Software for Payment and E-Money Firms
- Aug 6
- 6 min read

Buckingham Capital Consulting has advised payment and e-money firms on FCA authorisation, safeguarding and regulator engagement since 2013.
Monthly safeguarding return software prepares the return required under SUP 16.14A from a firm's operational safeguarding records, rather than from data assembled separately at month end. The return covers relevant funds held, reconciliation performance across the reporting period, shortfalls identified and remedied, safeguarding accounts and assets, the safeguarding method in use, and breaches and notifications.
The return became a monthly obligation on 7 May 2026 and is submitted through RegData. For most payment institutions and electronic money institutions it is the most frequent safeguarding deliverable, and the first point at which weaknesses in the underlying records become visible to the FCA.
This article sets out what the return contains, where each figure originates, the inconsistencies that most commonly arise, and what a firm should expect software to do.
What the return covers
The return is structured around the firm's safeguarding position across the reporting period rather than at a single date.
Relevant funds held. The total safeguarded at the reporting date, reported separately for electronic money and for unrelated payment services where the firm holds both. These are distinct asset pools under CASS 15 and are reconciled and reported separately.
The segregation position. The D+1 segregation requirement and the D+1 segregation resource across the period. The return is concerned with the pattern over the month rather than only the position on the final day.
Reconciliation performance. The number of reconciliation days in the period, and confirmation that internal and external safeguarding reconciliations were performed on each of them.
Shortfalls. Shortfalls identified during the period, their value, and how each was remedied.
Safeguarding accounts. The accounts held, the institutions holding them, and the balances. Jurisdiction is relevant where accounts are held outside the United Kingdom.
Relevant assets. Where the firm holds relevant assets rather than or in addition to cash, the custodians, asset types and values.
Safeguarding method. Segregation, insurance, comparable guarantee, or a combination. Where insurance or a guarantee is used, the provider and cover details.
Breaches and notifications. Breaches occurring during the period and notifications made to the FCA.
Where the data originates
Every figure in the return has its origin in the daily records the firm maintains through the month.
The segregation requirement and resource come from the internal and external reconciliations performed on each reconciliation day. The count of reconciliation days comes from the firm's reconciliation calendar. Shortfalls and their remediation come from the break and correction records. Account balances come from the external reconciliation. Breaches and notifications come from the breach register.
This has a direct bearing on how difficult the return is to prepare. A firm holding those records in a controlled system reviews a return populated from data that already exists and has already been approved. A firm working from workbooks, statement folders and correspondence reconstructs the month's position at month end, and the reconstruction is where inconsistency enters.
The difficulty compounds across a reporting year. Each month's return is assembled from a slightly different combination of sources, sometimes by a different individual, applying judgements that are not themselves recorded. Over an audit period of up to fifty-three weeks, the returns and the underlying records drift apart, and the annual safeguarding audit examines both.
Inconsistencies that commonly arise
Four recur often enough to be worth anticipating.
Reconciliation day count. Where the reconciliation calendar has not been fixed in advance, the number of reconciliation days reported in the return may not match the number of reconciliations the firm actually performed. Either a required reconciliation was missed or the count is wrong, and each requires explanation.
Shortfalls omitted following prompt correction. A variance identified and corrected within the same day is sometimes treated operationally as a non-event. It remains a shortfall that occurred during the period and is reportable. Prompt remediation is a positive fact about the firm's controls and is reported alongside it.
Asset pools combined. Firms holding funds in respect of both electronic money and unrelated payment services must report the pools separately. A combined figure misstates both, and the misstatement is visible where the firm's account structure shows separate designations.
Balance timing. Account balances taken from a different point in time than the reconciliation used, producing figures in the return that do not agree with the reconciliation evidence an auditor will sample.
None of these are difficult to avoid where the return is drawn from the operational record. All become likely where it is compiled independently of it.
What software should do
Assemble the return from reconciliation records rather than from a separate data collection. The figures reported should be the figures approved during the month. Where the return is compiled from a different source, the two will diverge, and the divergence is what an auditor and a supervisor examine.
Apply the reconciliation calendar automatically. The calendar determines the day count reported. Where it is applied by the system in advance, the count reflects the calendar as defined rather than as recalled at month end, and any excluded day carries a recorded reason.
Maintain asset pools separately throughout. Separation should hold through reconciliation, reporting and evidence, not be applied at the point of reporting.
Record shortfalls against the reconciliation that identified them. Where a shortfall, its cause, its correction and the approver are held against the run that produced it, the return's shortfall reporting reflects the operational record without curation.
Validate before submission. Internal consistency checks — day count against reconciliations performed, account balances against the external reconciliation, breach count against the register — identify errors before submission rather than after.
Retain the return with its supporting records. The auditor will examine the returns submitted during the audit period and the records supporting each. Consistency between the two is directly relevant to the audit opinion, and the supporting record should remain retrievable by period.
Support review and approval with named attribution. The return is a regulatory submission and its accuracy is the firm's responsibility. Approval by the individual responsible for safeguarding compliance should be recorded.
Preparing the return in practice
Through the month. Perform and record the internal and external reconciliations on each reconciliation day, with the segregation requirement, the resource, the comparison and any action taken recorded as each is completed. Record breaks and their resolution as they arise. Maintain the breach register.
At month end. Verify that the number of reconciliations recorded matches the number of reconciliation days in the period. Confirm the asset pool split. Confirm shortfalls and remediation are complete. Confirm accounts and balances agree to the external reconciliation.
Before submission. Review the return against the underlying records and obtain approval from the individual responsible for safeguarding compliance.
After submission. Retain the return and the supporting records together, indexed by period.
Monthly Safeguarding Return Software for Payment and E-Money Firms - Frequently asked questions
What is the monthly safeguarding return?
A regulatory return required under SUP 16.14A and submitted through RegData, covering a firm's safeguarding position for the reporting month including relevant funds held, reconciliation performance, shortfalls, safeguarding accounts and assets, the safeguarding method in use, and breaches and notifications.
Which firms must submit it?
Firms subject to the Supplementary Regime: authorised payment institutions, authorised electronic money institutions, small electronic money institutions and credit unions issuing e-money. Small payment institutions that have opted in to safeguarding are also within scope.
When is the return due?
The submission window follows the FCA's reporting calendar for the firm's permission and reporting period. Firms should confirm their own due date in RegData rather than relying on a general rule, since timing varies with permission type.
Do shortfalls remedied on the same day need to be reported?
Yes. The shortfall occurred during the period and is reportable. The remediation is recorded alongside it.
How are e-money and unrelated payment services funds reported?
Separately. They are distinct asset pools under CASS 15 and are reconciled and reported as such. A combined figure misstates both.
What if a reconciliation was not performed on a reconciliation day?
Where a firm knew in advance that it would be unable to perform a reconciliation, notification to the FCA was required at that point. The failure is a breach, is recorded in the breach register, and is reflected in the return.
Does the auditor examine the monthly returns?
Yes. The annual safeguarding audit examines the returns submitted during the audit period alongside the records supporting them. Consistency between the two is relevant to the audit opinion.
Preparing the return from operational records
The return is straightforward where the underlying records are complete and difficult where they are not. The determining factor is whether the firm's daily reconciliation position is held in a form that can be reported from directly.
Safeheld assembles the SUP 16.14A return from the reconciliation records already held, applies the reconciliation calendar automatically, maintains e-money and unrelated payment services as separate asset pools throughout, and records shortfalls and corrections against the reconciliation that identified them. The return is validated, reviewed and approved in the platform before export for RegData submission, and is retained with its supporting evidence.
About Safeheld
Safeheld is the safeguarding platform for FCA-regulated payment and e-money firms, covering daily reconciliation, breach management, regulatory reporting, resolution pack maintenance and audit evidence. Safeheld is a Buckingham Capital Consulting company. safeheld.com
About Buckingham Capital Consulting
Buckingham Capital Consulting is a leading UK and European financial services regulatory consultancy. Since 2013 we have advised payment institutions, electronic money institutions, investment firms and cryptoasset businesses on authorisation, prudential and conduct requirements, safeguarding, governance and regulator engagement across the UK and EU. Contact our safeguarding team
Monthly Safeguarding Return Software for Payment and E-Money Firms



