How to Build an Audit-Ready Safeguarding Framework Under CASS 15

An audit-ready safeguarding framework is one where every CASS 15 control has a record that proves it. Advapay's control-by-control checklist for UK EMIs and PIs facing the annual safeguarding audit.

Jul 16

An audit-ready safeguarding framework is one where each key safeguarding control has proof behind it. Segregation has account and acknowledgement evidence. Reconciliation has dated daily records. The resolution pack is live, current and retrievable. Build it control by control, keep the evidence as the process runs, and the annual safeguarding audit should become confirmation rather than discovery.

As of July 2026, under the FCA's PS25/12 and CASS 15.

01 - What does "audit-ready" actually mean for safeguarding?

Audit ready does not mean having a policy that says the control should operate. It means being able to prove that it did operate.

Pick a date. Can the firm produce the reconciliation record? Can it show where relevant funds were held? Can it explain any break and evidence the fix? That is the practical test.

SUP 3A makes that standard harder to avoid. The safeguarding report is a reasonable assurance engagement. The auditor’s opinion covers whether the firm maintained adequate systems throughout the period and whether it complied at period end. That is not a period end screenshot exercise. Firms should expect sampling, evidence requests and control testing across the audit period.

The audit exemption is narrow. A firm is exempt only if it has not been required to safeguard more than £100,000 of relevant funds at any time over at least 53 weeks. Senior management should not treat that as a casual threshold check.

02 - The safeguarding control-by-control checklist

The framework breaks into seven major control areas. For each, there is the control you operate, the record that evidences it, and what the audit checks. If you can fill every row of this table for any given date, you are audit-ready. Treat the evidence column as the deliverable. A control without a record is not audit ready.

Control area The record that evidences it What the audit checks
Segregation of relevant funds Account records, account statements and signed safeguarding account acknowledgement letters Relevant funds are identified, kept separate from firm money and placed correctly
Daily internal reconciliation Dated daily record showing safeguarding resource against safeguarding requirement, with D+1 placement checked where relevant A reconciliation ran each reconciliation day and differences were explained and remediated
Daily external reconciliation Dated record comparing internal records against bank, account provider or custodian records Internal records agree to external evidence, and breaks were investigated without undue delay
Resolution pack (CASS 10A) Master document index, bank lists, acknowledgement letters, insurance or guarantee policies and key operational records The pack is current, usable and retrievable within 48 hours where required
Insurance or guarantee method Policy or guarantee documents and expiry monitoring Cover is valid, sufficient and monitored. Where no replacement or renewal is in place, contingency planning starts at least 3 months before expiry.
Third party due diligence Due diligence and periodic review records for relevant banks, account providers and operational providers Third parties were assessed before use and kept under review
Governance, records and monthly return Oversight minutes, Board MI, safeguarding policy, issue log and submitted monthly return Safeguarding has clear ownership and reporting is supported by evidence

Each row is one control. The rest of this section walks through the areas where firms most often get thin on evidence.

Segregation and acknowledgement letters. Segregation is only as strong as the records behind it. The account needs to be identifiable as a safeguarding account, supported by account records and a current acknowledgement letter where required. A missing, stale or incorrectly signed acknowledgement letter is an easy audit finding.

Reconciliation records. Reconciliation is only audit ready if the record exists for each reconciliation day. A missing day, an unexplained break or a late fix turns a working process into an audit issue.

The resolution pack. The resolution pack is not a once a year folder. It has to stay current. If a bank, account, letter, policy or operational provider changes, the pack needs to move with it. CASS 10A also makes clear that the retrieval period is not time to start building the pack.

03 - What separates a framework that passes from one that doesn't?

The frameworks that pass are the ones where evidence is produced by the process, not assembled before the audit. The ones that struggle treat safeguarding as a policy plus a scramble. The difference shows up in three controls more than any other.

The first pressure point is reconciliation continuity. The rules require internal and external reconciliation each reconciliation day. The audit can sample any date in the period. A process that produces a clean dated record each day is defensible. A spreadsheet someone updates “most days” is not.

The second pressure point is the resolution pack. 48 hour retrieval sounds simple until an acknowledgement letter changes mid-year and the pack is not updated. The pack is not an annual filing exercise. It has to stay usable.

The third pressure point is governance. The auditor will expect evidence that safeguarding is owned, reviewed and escalated. A policy nobody uses is not governance.

The FCA built the monthly return and the audit to surface these weaknesses earlier. The point is to find poor evidence, weak ownership and broken processes before customer funds are exposed.

04 - How Advapay helps you build an audit-ready framework

Advapay helps firms build the safeguarding framework where it has to operate: in the funds flow, the banking set-up, the reconciliation process and the platform evidence. That means helping firms structure safeguarding accounts properly, obtain the right acknowledgement letters, and produce the records an auditor will expect to see.

The work starts with the operating model. What money comes in? What becomes relevant funds? Where is it held? Can the firm evidence the position each reconciliation day?

Where gaps are found, Advapay helps rebuild the process. That may include account mapping, reconciliation methodology, exception handling, breach escalation, Board MI and RegData outputs.

Macrobank’s accounting and reconciliation tooling can support the daily evidence trail. It helps produce dated reconciliation records, client balance tracking, exception records and audit outputs.

Advapay’s licensing and consulting experience means the safeguarding framework can be built into the authorisation file or operating model from the start, rather than bolted on before an audit. For what the new regime changed in the first place, see our explainer on the FCA’s new safeguarding rules.

To pressure test your framework before an auditor does, speak to our team.

"An auditor does not grade your intentions. They sample a date and ask you to show the control was operated. Pick a random Tuesday from six months ago. Can you produce the reconciliation record, the account acknowledgement and the current resolution pack? If you can, you are ready. If you have to build any of it after the question is asked, you are not." — Oliver Roberts, Compliance Officer, Advapay UK

Questions teams actually ask (FAQ)

Who has to have an annual safeguarding audit? Most in scope EMIs and authorised PIs that hold relevant funds. The main exemption is where the firm has not been required to safeguard more than £100,000 of relevant funds at any time over at least 53 weeks. Even where the exemption applies, the firm still needs to operate the safeguarding records, reconciliation and resolution-pack controls.

What standard does the safeguarding audit apply? It is a reasonable assurance engagement. The auditor gives an opinion on whether the firm’s safeguarding systems were adequate through the period and whether the firm complied at period end. This is detailed control testing, not a light review.

What issues are most likely to create audit findings? Missing acknowledgement letters, gaps in daily reconciliation records, unexplained breaks and an out-of-date resolution pack. These are often proof failures before they are fund failures.

How current does the resolution pack have to be? Current enough to be used. It must be retrievable within 48 hours where required, but that does not mean the firm has 48 hours to build it. If a bank, account, acknowledgement letter, agent or insurance arrangement changes, the pack needs to be updated.

When is the first audit due? Firms have six months after the end of the first audit period to submit the first safeguarding audit report. Later reports are due within four months. The audit period must not exceed 53 weeks.

Final thought

An audit-ready safeguarding framework is not a binder you produce for the auditor. It is a set of controls that generate evidence as they run.

Build it control by control. Keep the record alongside each control. Then the annual audit should confirm what you already know, rather than discover what is missing.

The firms that struggle are not always the ones with no controls. They are the ones with no proof. The regime rewards evidence.

If you want to test your framework against the CASS 15 controls before an auditor does, speak to our team.

Oliver Roberts, Compliance Officer, Advapay UK

Schedule a 30 min call with us