The Annual Safeguarding Audit: What Payment and E-Money Firms Should Expect
- Aug 5
- 5 min read

Buckingham Capital Consulting has advised payment and e-money firms on FCA authorisation, safeguarding and regulator engagement since 2013.
The annual safeguarding audit is an independent examination of a firm's safeguarding arrangements, required under SUP 3A of the FCA Handbook and reported to the FCA. It applies to authorised payment institutions and authorised electronic money institutions that safeguarded £100,000 or more during the relevant period.
For most firms in scope, it is the first audit of any part of their business conducted against a CASS regime. This article sets out who must obtain one, when it is due, what the auditor examines and how firms can prepare.
Which firms need a safeguarding audit?
Authorised payment institutions and authorised electronic money institutions must arrange an annual safeguarding audit.
Firms that safeguarded less than £100,000 throughout a relevant period of at least 53 weeks are exempt. Senior management must determine on an ongoing basis whether the exemption applies, and the assessment should be documented rather than assumed. The FCA has indicated that exempt firms may nonetheless wish to obtain a voluntary audit.
The audit must be performed by a qualified, regulated auditor.
Timing
The audit period must not exceed 53 weeks. Firms may align it with their financial year or select a different period.
The first audit report is due within six months of the end of the audit period. Subsequent reports are due within four months.
The longer window for the first report reflects the fact that most firms are undertaking this for the first time. It should not be read as slack in the timetable: the work of assembling evidence for a first audit is substantially greater than for subsequent ones, and firms that begin at the end of the period find the exercise considerably harder than those who prepared during it.
What the auditor examines
The audit addresses two questions.
Do the firm's books and records correctly reflect and substantiate the funds held for customers, and do those records reconcile to the funds actually held?
The auditor tests whether customer entitlements are properly recorded, whether the safeguarding requirement was calculated correctly, whether the resource was correctly identified and whether the two reconciled throughout the period.
Did the firm have systems and controls sufficient to safeguard relevant funds throughout the period?
This is a test of operation over time, not condition at a point. The auditor examines whether reconciliations were performed on each reconciliation day, whether breaks and shortfalls were identified and remedied, whether breaches were recorded and notified, whether the resolution pack was maintained, whether due diligence was performed and whether governance operated.
The distinction matters. A firm whose arrangements are sound today but which cannot evidence their operation across the period has a problem the auditor cannot resolve in its favour.
Two points on scope
Breach reporting. Following guidance issued by the Financial Reporting Council, safeguarding auditors report all breaches to the FCA rather than only material ones. Firms should assume that anything identified appears in the report.
IT general controls. Controls covering change management, user access and IT operations form part of the audit, with significant deficiencies likely to be recorded as breaches. This is relevant to firms operating the safeguarding process in spreadsheets, where access control, change management and an immutable record are difficult to evidence.
Firms should confirm the current position with their auditor when scoping the engagement, as guidance in this area has developed since the regime took effect.
What the auditor will request
The requests follow the obligations. Firms should expect to provide:
Reconciliation records for every reconciliation day in the period, showing the segregation requirement, the segregation resource, the comparison, the outcome and any action taken. The reconciliation calendar and the basis for it. Records of breaks, their investigation and resolution, and who approved each. The breach register.
Notifications made to the FCA and any correspondence. The resolution pack. Acknowledgement letters for each safeguarding account. Third-party due diligence records and review dates. Safeguarding policies and procedures, with version history. Evidence of governance and oversight. Monthly safeguarding returns submitted during the period and the records supporting them. Where insurance or a guarantee is used, the policy and related notifications.
Preparing for the audit
Determine the audit period and appoint the auditor early. Auditors with CASS experience have limited capacity and the population of firms requiring this work grew substantially in 2026.
Assess evidence against each obligation before fieldwork. Take each requirement in turn and identify the record that demonstrates compliance. Where no record exists, that is a finding waiting to happen, and it is better identified in advance than during fieldwork.
Check consistency across outputs. The monthly returns, the reconciliation records, the breach register and the resolution pack should tell the same story. Where they were compiled separately, they frequently do not.
Confirm the reconciliation count. The number of reconciliations performed should equal the number of reconciliation days in the period. Any gap requires explanation.
Review the IT control position. Where the process runs in spreadsheets, consider how access control, change management and record integrity will be evidenced.
Brief the people the auditor will interview. Those operating the controls should be able to explain what they do and why, consistent with the documented procedures.
Common findings
Reconciliations performed but not evidenced to the standard the audit requires. External reconciliation treated less rigorously than internal. The relevant funds boundary undocumented or applied inconsistently with the policy. Resolution pack out of date. Breaks resolved without recorded approval. Breaches identified but not recorded in a register. Third-party due diligence performed at appointment but not reviewed since. Monthly returns inconsistent with the underlying records.
Most of these are evidence failures rather than control failures. The firm was doing the right thing and cannot demonstrate it. That distinction does not help at audit.
Frequently asked questions
Which firms must have a safeguarding audit?
Authorised payment institutions and authorised electronic money institutions, unless they safeguarded less than £100,000 throughout a relevant period of at least 53 weeks.
When is the first safeguarding audit report due?
Within six months of the end of the first audit period. Subsequent reports are due within four months. The audit period must not exceed 53 weeks.
Who can perform the audit?
A qualified, regulated auditor. The FCA confirmed this requirement in PS25/12 to ensure consistent audit quality.
Does the auditor report only material breaches?
No. Following FRC guidance, safeguarding auditors report all breaches to the FCA rather than only material ones.
Are IT controls part of the audit?
Yes. IT general controls covering change management, user access and IT operations form part of the audit, and significant deficiencies are likely to be recorded as breaches.
What if we are exempt?
Firms below the £100,000 threshold across the relevant period are exempt, but should document the assessment. The FCA has indicated that exempt firms may wish to obtain a voluntary audit.
Evidence assembled as it is created
The difficulty in a first safeguarding audit is rarely the arrangements themselves. It is producing evidence that those arrangements operated on every day of the period.
Safeheld records every reconciliation, break, remediation, approval and sign-off as it happens, in a record that cannot be altered afterwards. The audit evidence pack assembles for any period, and auditors can be given read-only access scoped to the period under review.
About Safeheld
Safeheld is the safeguarding platform for FCA-regulated payment and e-money firms, covering daily reconciliation, breach management, regulatory reporting, resolution pack maintenance and audit evidence. Safeheld is a Buckingham Capital Consulting company. safeheld.com
About Buckingham Capital Consulting
Buckingham Capital Consulting is a leading UK and European financial services regulatory consultancy. Since 2013 we have advised payment institutions, electronic money institutions, investment firms and cryptoasset businesses on authorisation, prudential and conduct requirements, safeguarding, governance and regulator engagement across the UK and EU. Contact our safeguarding team
The Annual Safeguarding Audit: What Payment and E-Money Firms Should Expect



