top of page

Safeguarding Reconciliation Software for EMIs and Payment Institutions

  • Aug 6
  • 5 min read
Safeguarding Reconciliation Software for EMIs and Payment Institutions

Buckingham Capital Consulting has advised payment and e-money firms on FCA authorisation, safeguarding and regulator engagement since 2013.


Safeguarding reconciliation software automates the internal and external reconciliations that CASS 15 requires on each reconciliation day, calculates the D+1 segregation position, tracks breaks through to approved resolution and produces the evidence an auditor will test.


Since 7 May 2026, payment institutions and electronic money institutions have been required to reconcile daily and evidence that they did. This article sets out what the reconciliation actually involves and what software needs to do to support it properly.


What the reconciliation requires

CASS 15 requires two distinct reconciliations, each performed at least once on every reconciliation day.


The internal safeguarding reconciliation compares the relevant funds that should be safeguarded against the firm's own internal records. Its purpose is to check that the firm's books and records are accurate.


The external safeguarding reconciliation compares those internal records against third-party records: statements from the institutions holding safeguarding accounts and records from custodians holding relevant assets.


Both feed the central comparison. The D+1 segregation requirement, being the relevant funds that should be held in relevant funds bank accounts or as relevant assets, is compared against the D+1 segregation resource, being the balances of those accounts. Where the resource is short, the firm must remedy it, using its own funds if necessary. Where there is excess, it may be withdrawn.


Every element of that - the calculation, the comparison, the outcome, the action taken - must be recorded.


What makes safeguarding reconciliation different

A general reconciliation engine matches transactions between two data sets. Safeguarding reconciliation does that, but the matching is the smaller part of the obligation.


The requirement must be calculated correctly. Determining what should be safeguarded involves the firm's documented position on when the obligation begins and ends, the treatment of fees, foreign exchange linked to payment services, funds through agents and distributors, and unclaimed funds. The calculation encodes regulatory judgement, not only arithmetic.


Asset pools are separate. Funds held in respect of electronic money and funds held for unrelated payment services must be reconciled and reported separately throughout. A single combined reconciliation misstates both.


The calendar is defined by rule. Reconciliation is required on each reconciliation day: all days except weekends, UK bank holidays and days on which a relevant foreign market is closed. The calendar should be fixed in advance, with any excluded day supported by a recorded reason.


Breaks require approval, not just resolution. A break resolved without recorded investigation, root cause and second-person approval leaves the firm with a corrected figure and no evidence of control.


The output is regulatory. The reconciliation feeds the monthly SUP 16.14A return, the resolution pack, board reporting and the audit evidence. Where each is compiled separately, they diverge.


What to look for

Correct calculation of the segregation requirement and resource for the firm's specific model, with the treatment of relevant funds configurable to the position set out in its safeguarding policy.

Separate asset pools for e-money and unrelated payment services, maintained through reconciliation, reporting and evidence.

A reconciliation calendar applied automatically, covering weekends, UK bank holidays and the foreign markets relevant to the firm.

Internal and external reconciliation as distinct processes, with the ability to record the reconciliation point used for each and, where they differ, the rationale.

Break management with ownership, ageing, root cause and maker-checker approval, so that resolution is evidenced rather than assumed.

Multi-entity, multi-currency and multi-account handling for firms operating across several safeguarding accounts or legal entities.

Data ingestion that fits the firm's sources, whether bank statements, ledger extracts or custodian reports, without requiring months of integration work.

An immutable record of every calculation, comparison, break, remediation, approval and sign-off, since IT general controls covering change management, user access and record integrity form part of the safeguarding audit.

Regulatory outputs drawn from the same record — the monthly return, the resolution pack, board reporting and the audit evidence pack — so that all four describe the same position.


Why spreadsheets become difficult

Spreadsheets can perform the calculation. What they cannot easily do is evidence that the control operated.

There is no access control, so the auditor cannot establish who could change what. There is no change management, so the auditor cannot establish what was altered after approval. There is no immutable record, so the reconciliation as it stands today is not demonstrably the reconciliation as it stood on the day. And IT general controls now form part of the safeguarding audit, with significant deficiencies likely to be recorded as breaches.

There is also a continuity issue. Where the daily reconciliation, the monthly return and the audit evidence sit with one person and their workbook, absence becomes a compliance event and departure becomes a remediation project.


Frequently asked questions

What is safeguarding reconciliation?

The comparison, required on each reconciliation day under CASS 15, between the relevant funds a firm should be safeguarding and the funds it actually holds. It comprises an internal reconciliation against the firm's own records and an external reconciliation against third-party records.

How often must safeguarding reconciliation be performed?

At least once on every reconciliation day, for both the internal and external reconciliation. A reconciliation day is any day other than a Saturday or Sunday, a UK bank holiday, or a day on which a relevant foreign market is closed.

Can we use a general reconciliation tool?

A general tool can match transactions. It will not calculate the segregation requirement according to the firm's documented treatment of relevant funds, maintain separate asset pools, apply the reconciliation calendar or produce the regulatory outputs CASS 15 requires.

Do e-money and payment services funds need separate reconciliations?

Yes. They are separate asset pools and must be reconciled and reported separately.

Does reconciliation software make us compliant?

It operates the control and produces the evidence. Determining what constitutes relevant funds for a particular business model, designing the control framework and holding accountability for safeguarding remain with the firm.


Safeguarding reconciliation in Safeheld

Safeheld performs the internal and external reconciliation on each reconciliation day, calculates the D+1 segregation requirement and resource across separate asset pools, applies the reconciliation calendar automatically and tracks every break through to approved resolution. The monthly SUP 16.14A return, the CASS 10A resolution pack, board reporting and the audit evidence pack all draw from the same record.

The regulatory logic is specified by practitioners who advise payment and e-money firms on FCA authorisation and supervision.



About Safeheld

Safeheld is the safeguarding platform for FCA-regulated payment and e-money firms, covering daily reconciliation, breach management, regulatory reporting, resolution pack maintenance and audit evidence. Safeheld is a Buckingham Capital Consulting company. safeheld.com


About Buckingham Capital Consulting

Buckingham Capital Consulting is a leading UK and European financial services regulatory consultancy. Since 2013 we have advised payment institutions, electronic money institutions, investment firms and cryptoasset businesses on authorisation, prudential and conduct requirements, safeguarding, governance and regulator engagement across the UK and EU. Contact our safeguarding team

 
 
bottom of page