On 7 May 2026 the FCA’s supplementary safeguarding regime came into force as CASS 15 of the FCA Handbook. If you are an authorised payment institution or e-money institution, the practical effect is that safeguarding is no longer something you can evidence with a well-drafted policy and a segregated account. It is now something an auditor tests, opines on, and reports to your regulator every year.

The rules were finalised in PS25/12 on 7 August 2025, following consultation CP24/20. They originate in HM Treasury’s 2023 review of the Payment Services Regulations, prompted by a run of firm failures in which customer money proved considerably harder to return than anyone had assumed.

Supplementary now, statutory trust later

There are two stages, and conflating them causes confusion.

The supplementary regime is what is in force. CASS 15 sits on top of the existing safeguarding requirements in the Payment Services Regulations 2017 and the Electronic Money Regulations 2011. It does not replace them. Both operate in parallel, which is why firms are finding their compliance mapping more complex than expected.

The post-repeal regime would replace PSR and EMR safeguarding altogether with a CASS-style statutory trust over relevant funds. Those rules have not been made, and no commencement date exists. The FCA has indicated it will not revisit them until a full audit cycle under the supplementary regime has completed. Plan for the regime you have, not the one that may arrive.

Who is in scope

  • Authorised payment institutions, except those providing only payment initiation services or account information services
  • Authorised e-money institutions
  • Small e-money institutions
  • Credit unions issuing e-money in the UK

Small payment institutions are not caught but may opt in voluntarily.

There is a de minimis exemption from the audit requirement: a firm that has not been required to safeguard more than £100,000 of relevant funds at any time over a period of at least 53 weeks does not need one. Note the construction carefully. It is a high-water mark test across the whole period, not an average and not a year-end balance.

What the audit is, and why “reasonable assurance” matters

The safeguarding audit is a reasonable assurance engagement. Opinions are expressed directly against CASS 15, the PSRs 2017 and the EMRs 2011, using a standardised report template with three possible outcomes: unmodified, qualified or adverse.

Reasonable assurance is the same level as a statutory audit opinion. It is not a review, not an agreed-upon procedures exercise and not a health check. Your auditor is required to gather sufficient appropriate evidence to form a positive opinion, which means testing, not enquiry.

Practically, expect scrutiny of:

  • Daily reconciliations, now codified rather than left to firm judgement
  • Books and records, with prescriptive requirements about what must be maintained and in what form
  • A CASS resolution pack under CASS 10A, capable of enabling an insolvency practitioner to return funds quickly
  • Third-party and counterparty due diligence on where relevant funds are held
  • The monthly safeguarding regulatory return

The reconciliation requirement is where most firms discover a gap. Performing a reconciliation daily is one thing; evidencing that you performed it daily, that breaks were identified and investigated, and that someone with authority reviewed it, is another. Auditors test the evidence, not the intention.

Timing

The audit period must not exceed 53 weeks from the end of the previous report period, or from the date the firm became subject to the rules. For a firm that came into scope on 7 May 2026, the first period therefore ends by roughly early May 2027 at the latest.

The FCA extended the first report deadline to six months after period end, up from the four months consulted on. Subsequent reports are due within four months. That first-year extension is a one-off concession and it is worth using deliberately rather than absorbing it as slack.

The standards position is unusual

There is currently no dedicated FRC assurance standard for safeguarding audits. The FRC published interim guidance on 17 March 2026, which is explicitly non-mandatory and is not a performance standard. A formal standard is expected to follow public consultation and will be issued as an appendix to the existing CASS Assurance Standard, anticipated in 2027.

This matters when you appoint an auditor. In the absence of a mandatory standard, the rigour of your engagement depends heavily on the methodology of the firm you choose. Two auditors can approach the same firm very differently right now, and the FCA will be reading the reports.

What to do before your first audit

Do a dry run. Pick a month, pull the reconciliations, and ask whether an auditor could evidence completeness and timeliness from what you hold. Test whether your resolution pack would actually let a third party return funds. Check that your counterparty due diligence is documented rather than assumed.

Firms that treat the first safeguarding audit as a live exercise starting six months before period end tend to receive unmodified opinions. Firms that treat it as a year-end event tend not to.

If you want a view on where your safeguarding arrangements sit against CASS 15 before an auditor forms one, that is a conversation worth having early.