
The FCA’s Supplementary Regime for safeguarding took effect on 7 May 2026. It does not replace the safeguarding duties in the Payment Services Regulations 2017 or the Electronic Money Regulations 2011. It makes them much more prescriptive.
The practical change is simple: firms now need to prove, every day, what relevant funds they hold, where those funds are, whether they have been placed correctly, and what they did when something broke.
CASS 15 is the core chapter, but the regime is wider. It also brings in CASS 10A resolution pack, SUP 3A safeguarding audits and SUP 16.14A monthly safeguarding returns.
The new regime turns safeguarding from a policy obligation into a daily evidence obligation.
As of July 2026, under the FCA's PS25/12 and CASS 15.
The legal duty to safeguard relevant funds already existed under the EMRs and PSRs. What changed is the operating standard. The FCA has turned safeguarding into a more detailed daily control regime, with clearer requirements for records, reconciliations, reporting, audit and resolution planning. What was previously often treated as a supervisory expectation, a good practice or guidance is now much more prescriptive and easier for the FCA, auditors and insolvency practitioners to test.
PS25/12 introduces the regime in stages. The current stage is the Supplementary Regime. A later Post Repeal Regime is expected to move the regime closer to a fuller CASS 6 & 7 style end state, but it is not yet live and remains subject to further consultation and legislative timing. The practical point is that firms should build flexible safeguarding frameworks that can adapt to further change, rather than hard coding a narrow interim solution.
The change matters because the FCA is responding to real weaknesses. In 2023 the FCA opened supervisory cases relating to around 15% of firms that safeguard. In PS25/12, the FCA said electronic money institutions safeguarded approximately £26 billion of relevant funds in 2024, while payment institutions safeguarded around £6 billion on any given day in 2024. It also reported that payment and e-money firms that became insolvent between 2018 and 2023 had an average shortfall of 65% between funds owed to clients and funds safeguarded. Considering that funds of customers of failed firms are not protected by the Financial Services Compensation Scheme, the regime is therefore a response to practical failures in identifying, protecting and returning customer funds.
The Supplementary Regime came into force on 7 May 2026. The implementation window has closed. In scope firms should now be operating under the new rules that they will be held accountable against.
Here is the timeline that matters:
The practical reading is simple – there is no grace period left – the firms are either compliant or non-compliant with the new FCA handbook safeguarding rules.
The main timing nuance is audit submission: the first safeguarding audit report is due within 6 months of the audit period end, while later reports are due within 4 months. Firms using insurance or a guarantee also need contingency planning at least 3 months before expiry where no replacement is in place.
CASS 15 applies to firms that receive or hold relevant funds, including authorised payment institutions, electronic money institutions, credit unions issuing e-money and small payment institutions that opt in to voluntary safeguarding. For most market participants, the key point is that authorised payment institutions and electronic money institutions are in scope, while small payment institutions are not caught unless they opt in.
If your firm receives funds for payment execution, or receives funds in exchange for e-money issuance, it needs to identify whether those funds are relevant funds and whether CASS 15 applies. Scope is not only a question of licence type. It depends on the activity, the funds flow and whether the firm receives or holds relevant funds in the relevant funds regime.
The audit exemption also needs care. A firm is exempt from the SUP 3A safeguarding audit requirement only if it has not been required to safeguard more than £100,000 of relevant funds at any time over at least 53 weeks. That is not a casual point in time test. Senior management needs to keep it under review.
Now that the regime is live, firms should start with reviewing their business operating models, not spreadsheets:
Once that is clear, the core outputs can feed into daily reconciliations, breach and exception handling, a live resolution pack, audit and monthly reporting. Each is a control you must be able to evidence on request, not a process you can simply assert.
"The firms that handle this regime well do not treat safeguarding as multiple separate obligations. They treat it as one daily control environment. The firm needs to know what money is relevant, where it is held, what the records show and what happened when something broke. If funds classification or account mapping is wrong, the reconciliation will simply compound mistakes." — Oliver Roberts, Compliance Officer, Advapay UK
The main mistake is treating the Supplementary Regime as a policy refresh.The rules are now specific enough that a tidy policy and a messy process is exactly the gap an auditor and the FCA look for. Firms need to test whether their funds flow, account structure, reconciliation logic, evidence trail, breach process and Board reporting actually work. The regime effectively forces firms to perform a health check of their safeguarding arrangements.
The common gaps are familiar: manual reconciliations, weak D+1 logic, scattered evidence, no structured breach log, weak IT controls and poor Board MI. The problem is rarely one spreadsheet. It is the chain behind it: classification, ledger mapping, cut offs, account movements, approvals and exception handling.
The supervisory risk is now also sharper. The FCA has more ways to see weak safeguarding through daily records, monthly returns, audit findings, resolution pack readiness and breach notification triggers. A firm that cannot explain what it holds, where it is and how breaks were fixed is exposed. Recent FCA intervention activity also shows that safeguarding weaknesses can form part of wider serious regulatory concerns, especially where they sit alongside other issues.
Advapay helps firms turn CASS 15 into an effective and compliant safeguarding process via three layers: conducting initial health check, improving operating model and providing a RegTech solution.
The safeguarding health check looks at the operating model, how funds move through the business, whether relevant funds are identified correctly, and whether the firm can prove its position each reconciliation day.
Where gaps are found, we help rebuild and improve the operating model so the firm has clear ownership, repeatable reconciliations, controlled exceptions and required levels of oversight.
Where technology is needed, Macrobank's accounting and reconciliation tooling further supports the operating process by tracking client balances against safeguarded funds and producing tracked reconciliation records that the rules require.
If you want a straight read on where your safeguarding process stands against CASS 15, speak to our team.
Advapay runs UK licensing and consulting across 100+ clients, 5 offices, and a team of around 50 people, so the safeguarding setup is built as part of the authorisation file or the operating model, not bolted on after the rules bite. For the general safeguarding primer that sits underneath this UK-specific regime, contact our team directly.
Is the FCA's new safeguarding regime the same as "CASS 15"? Not exactly. CASS 15 is the main new Handbook chapter, but the Supplementary Regime is wider. It also includes the CASS 10A resolution pack, SUP 3A safeguarding audits and SUP 16.14A monthly returns.
Did the new rules replace the EMRs and PSRs safeguarding requirements? No. The Supplementary Regime supplements the EMR and PSR safeguarding duties. The later Post Repeal Regime is still subject to further consultation and is not yet in force.
How often do we have to reconcile under the new regime? At least once each reconciliation day. Firms need internal and external safeguarding reconciliations. In practice, that means checking the firm’s records, D+1 placement where relevant, and external records from banks or other relevant third parties.
Does every firm need an annual safeguarding audit? No. There is an exemption where the firm has not had to safeguard more than £100,000 of relevant funds at any time over at least 53 weeks. Senior management must keep that position under review.
What is the resolution pack and how fast must we produce it? It is the live pack of records needed to identify and return relevant funds if the firm fails. It must be maintained according to CASS10 requirements in advance and retrievable quickly, in any event within 48 hours where required. It should not be assembled after the event.
Most firms understand the safeguarding principle. The gap is usually in the operating detail. The Supplementary Regime does not create safeguarding from scratch – it raises the operating standard and makes weak safeguarding processes easier to test, easier to challenge and harder to defend.
The firms most exposed are the ones that cannot prove the basics: what money is relevant, where it is held, whether D+1 placement was met, what is their reconciliation logic and what happened when something broke. The practical lesson is to get the foundations right at the outset. Get that wrong, and daily reconciliation does not fix the problem. It compounds it.
Good safeguarding is now a daily control environment.
If you want help mapping your safeguarding process to CASS 15, speak to our team. Advapay can support the health check, operating model and technology layer as one connected safeguarding project.
Oliver Roberts, Compliance Officer, Advapay UK