Safeguarding Audit Software: Preparing Evidence for the Annual Audit
- Aug 4
- 7 min read

Buckingham Capital Consulting has advised payment and e-money firms on FCA authorisation, safeguarding and regulator engagement since 2013.
Safeguarding audit software maintains the evidence a firm requires for the annual safeguarding audit under SUP 3A, capturing each reconciliation, break, correction and approval as it occurs rather than assembling records after the audit period has closed.
The audit applies to authorised payment institutions and authorised electronic money institutions that safeguarded £100,000 or more during the relevant period. The first report is due within six months of the end of the audit period and subsequent reports within four months. For most firms in scope it is the first audit of any part of their business conducted against a CASS regime.
This article sets out what the auditor examines, what will be requested, where firms most often have difficulty, and what a firm should expect software to provide.
Safeguarding Audit Software: What the audit examines
The audit addresses two questions.
Whether the firm's books and records correctly reflect and substantiate the relevant funds held for customers, and whether those records reconcile to the funds actually held. The auditor tests whether customer entitlements are properly recorded, whether the segregation requirement was calculated correctly, whether the resource was correctly identified, and whether the two reconciled.
Whether the firm had systems and controls sufficient to safeguard relevant funds throughout the period. This is a test of operation over time rather than of condition at a point. The auditor examines whether reconciliations were performed on each reconciliation day, whether breaks and shortfalls were identified and remedied, whether breaches were recorded and notified, whether the resolution pack was maintained, whether third-party due diligence was performed, and whether governance operated.
The distinction between the two matters. A firm whose safeguarding arrangements are entirely sound at the date of the audit, but which cannot evidence their operation across the period, has a difficulty the auditor cannot resolve in the firm's favour.
Two points on audit scope
Breach reporting at zero materiality. Following guidance issued by the Financial Reporting Council, safeguarding auditors report all breaches to the FCA rather than only material ones. Under the previous approach a firm could reasonably expect immaterial matters to be noted internally and remediated. Firms should now assume that anything identified during fieldwork appears in the report submitted to the regulator.
The practical consequence is that a firm with sound safeguarding arrangements but weak evidence discipline may accumulate a report containing a number of findings, none individually serious, which collectively invite supervisory attention.
IT general controls. Controls covering change management, user access and IT operations form part of the audit, and significant deficiencies are likely to be recorded as breaches.
This is relevant to firms operating the safeguarding process in spreadsheets. A workbook has limited access control, no change management, and no record distinguishing the version presented to the auditor from a version amended subsequently. The absence of those controls is itself capable of generating findings, independently of whether the reconciliations were performed correctly.
Firms should confirm the current position with their auditor when scoping the engagement, as guidance in this area has continued to develop since the regime took effect.
What the auditor will request
The requests follow the obligations. Firms should expect to provide:
Reconciliation records for every reconciliation day in the period, showing the segregation requirement, the segregation resource, the comparison, the outcome and any action taken. The reconciliation calendar and the basis on which it was determined. Records of breaks, their investigation and resolution, and who approved each. The breach register. Notifications made to the FCA and any correspondence arising. The resolution pack.
Acknowledgement letters for each safeguarding account. Third-party due diligence records and review dates. Safeguarding policies and procedures with version history. Evidence of governance and senior management oversight. The monthly safeguarding returns submitted during the period and the records supporting each. Where insurance or a comparable guarantee is used, the policy and related notifications.
Each of these should be retrievable by date. Where retrieval requires assembly from multiple sources, the assembly itself consumes engagement time and is capable of producing observations.
Where firms most often have difficulty
Evidence assembled rather than retained. The firm performed the reconciliation, and the record demonstrating that it did so to the standard the audit applies was not created at the time. This is the most common source of findings and it is an evidence failure rather than a control failure.
External reconciliation treated less rigorously than internal. Both are required on each reconciliation day. Firms frequently perform the internal reconciliation to a high standard and treat the external reconciliation as a periodic check against bank statements. The difference in rigour is visible in the records.
The relevant funds boundary undocumented. Where the firm's treatment of fees once due, foreign exchange linked to payment services, funds held through agents and distributors, or unclaimed balances involves judgement, that judgement should be documented in the safeguarding policy and applied consistently in the reconciliation. Inconsistency between the two is a frequent finding.
Corrections without recorded approval. A shortfall identified and remedied, where the decision to fund it and the confirmation that it was funded exist in correspondence rather than in the record.
Returns inconsistent with the underlying records. The monthly safeguarding returns submitted during the period examined against the reconciliations supporting them.
Resolution pack out of date. A pack assembled once and not maintained, describing arrangements that have since changed.
What software should do
Capture evidence as controls operate. Every reconciliation, break, investigation, correction, approval and sign-off recorded at the moment it occurs, with named attribution and a timestamp, rather than documented afterwards.
Hold records in a form that cannot be amended without detection. The auditor's second question, after establishing that a record exists, is whether it could have been created or altered after the date it describes. Records held in a form where alteration is detectable answer that question directly.
Make evidence retrievable by date. The auditor samples dates. Where the complete control cycle for any specified date can be retrieved in a single action, fieldwork proceeds efficiently. Where it must be assembled, engagement time and cost increase.
Assemble the evidence pack for any period. Selection of the audit period should produce a structured pack covering reconciliations, breaks, corrections, breaches, notifications, resolution pack status, acknowledgement letters, third-party due diligence, policies and governance records, indexed so that the auditor can map to the obligations being tested.
Provide scoped auditor access. Read-only access limited to the audit period, with every action the auditor takes recorded, allows the auditor to work directly in the system rather than through document requests.
Ensure the artefacts agree. Where the monthly returns, the resolution pack, the board reporting and the audit evidence all derive from the same underlying records, they cannot diverge. Where each is compiled separately, divergence is likely and is what the audit examines.
Preparing for the audit
Determine the audit period and appoint the auditor early. Auditors with CASS experience have limited capacity, and the population of firms requiring safeguarding audits increased substantially in 2026.
Assess evidence against each obligation before fieldwork. Take each requirement in turn and identify the record that demonstrates compliance. Where no record exists, it is better identified in advance than during fieldwork.
Confirm the reconciliation count. The number of reconciliations performed should equal the number of reconciliation days in the period, and any difference requires explanation.
Check consistency across artefacts. The monthly returns, the reconciliation records, the breach register and the resolution pack should describe the same position.
Review the IT control position. Where the process runs in spreadsheets, consider how access control, change management and record integrity will be evidenced.
Brief those the auditor will interview. Individuals operating the controls should be able to explain what they do and why, consistent with the documented procedures.
Frequently asked questions
Which firms need a safeguarding audit?
Authorised payment institutions and authorised electronic money institutions, unless they safeguarded less than £100,000 throughout a relevant period of at least fifty-three weeks. Senior management must determine on an ongoing basis whether the exemption applies, and the assessment should be documented.
When is the first audit report due?
Within six months of the end of the first audit period. Subsequent reports are due within four months. The audit period must not exceed fifty-three weeks.
Who can perform the audit?
A qualified, regulated auditor. The FCA confirmed this requirement in PS25/12 to support consistency of audit quality across the sector.
Does the auditor report only material breaches?
No. Following FRC guidance, safeguarding auditors report all breaches to the FCA rather than only material ones.
Are IT controls within the scope of the audit?
Yes. IT general controls covering change management, user access and IT operations form part of the audit, and significant deficiencies are likely to be recorded as breaches. Firms should confirm current scope with their auditor.
What produces most audit findings?
Evidence rather than control. In most cases the firm performed the reconciliation and cannot demonstrate that the record produced for the auditor is the record relied upon at the time.
Can we obtain a voluntary audit if we are exempt?
Yes. The FCA has indicated that firms below the threshold may wish to obtain a voluntary safeguarding audit.
Evidence retained as it is created
The difficulty in a first safeguarding audit is rarely the arrangements themselves. It is demonstrating that those arrangements operated on every reconciliation day of the period.
The above is why we built Safeheld. Safeheld records every reconciliation, break, correction, approval and sign-off as it occurs, with named attribution, in a form that cannot be amended afterwards without detection. The audit evidence pack assembles for any period, structured to the obligations being tested, and auditors receive read-only access scoped to the audit period with every action logged.
About Safeheld
Safeheld is the safeguarding platform for FCA-regulated payment and e-money firms, covering daily reconciliation, breach management, regulatory reporting, resolution pack maintenance and audit evidence. Safeheld is a Buckingham Capital Consulting company. safeheld.com
About Buckingham Capital Consulting
Buckingham Capital Consulting is a leading UK and European financial services regulatory consultancy. Since 2013 we have advised payment institutions, electronic money institutions, investment firms and cryptoasset businesses on authorisation, prudential and conduct requirements, safeguarding, governance and regulator engagement across the UK and EU. Contact our safeguarding team



