The FCA’s New CASS 15 Safeguarding Regime: What Changes for EMIs and PIs

The FCA's new safeguarding regime (PS25/12) takes effect 7 May 2026. Advapay on the CASS 15 rules, daily reconciliation, the resolution pack, the annual audit, and what to do now.

Jul 9

The FCA’s Supplementary Regime for safeguarding took effect on 7 May 2026. It does not replace the safeguarding duties in the Payment Services Regulations 2017 or the Electronic Money Regulations 2011. It makes them much more prescriptive.

The practical change is simple: firms now need to prove, every day, what relevant funds they hold, where those funds are, whether they have been placed correctly, and what they did when something broke.

CASS 15 is the core chapter, but the regime is wider. It also brings in CASS 10A resolution pack, SUP 3A safeguarding audits and SUP 16.14A monthly safeguarding returns.

The new regime turns safeguarding from a policy obligation into a daily evidence obligation.

As of July 2026, under the FCA's PS25/12 and CASS 15.

01 - What is actually changing under the FCA's new safeguarding regime?

The legal duty to safeguard relevant funds already existed under the EMRs and PSRs. What changed is the operating standard. The FCA has turned safeguarding into a more detailed daily control regime, with clearer requirements for records, reconciliations, reporting, audit and resolution planning. What was previously often treated as a supervisory expectation, a good practice or guidance is now much more prescriptive and easier for the FCA, auditors and insolvency practitioners to test. 

PS25/12 introduces the regime in stages. The current stage is the Supplementary Regime. A later Post Repeal Regime is expected to move the regime closer to a fuller CASS 6 & 7 style end state, but it is not yet live and remains subject to further consultation and legislative timing. The practical point is that firms should build flexible safeguarding frameworks that can adapt to further change, rather than hard coding a narrow interim solution.

The change matters because the FCA is responding to real weaknesses. In 2023 the FCA opened supervisory cases relating to around 15% of firms that safeguard. In PS25/12, the FCA said electronic money institutions safeguarded approximately £26 billion of relevant funds in 2024, while payment institutions safeguarded around £6 billion on any given day in 2024. It also reported that payment and e-money firms that became insolvent between 2018 and 2023 had an average shortfall of 65% between funds owed to clients and funds safeguarded. Considering that funds of customers of failed firms are not protected by the Financial Services Compensation Scheme, the regime is therefore a response to practical failures in identifying, protecting and returning customer funds.

02 - When do the new safeguarding rules take effect?

The Supplementary Regime came into force on 7 May 2026. The implementation window has closed. In scope firms should now be operating under the new rules that they will be held accountable against. 

Here is the timeline that matters:

  • September 2024 — the FCA published CP24/20, proposing the changes.
  • 7 August 2025 — PS25/12, the final policy statement, confirmed the rules and the legal instrument (FCA 2025/38).
  • 7 May 2026 — the Supplementary Regime (CASS 15, CASS 10A, SUP 3A, SUP 16.14A) came into force.
  • Post-Repeal Regime — the later end state remains subject to further consultation and legislative timing, with no in force date set.

The practical reading is simple – there is no grace period left – the firms are either compliant or non-compliant with the new FCA handbook safeguarding rules. 

The main timing nuance is audit submission: the first safeguarding audit report is due within 6 months of the audit period end, while later reports are due within 4 months. Firms using insurance or a guarantee also need contingency planning at least 3 months before expiry where no replacement is in place.

03 - Who do the new CASS safeguarding rules apply to?

CASS 15 applies to firms that receive or hold relevant funds, including authorised payment institutions, electronic money institutions, credit unions issuing e-money and small payment institutions that opt in to voluntary safeguarding. For most market participants, the key point is that authorised payment institutions and electronic money institutions are in scope, while small payment institutions are not caught unless they opt in.

If your firm receives funds for payment execution, or receives funds in exchange for e-money issuance, it needs to identify whether those funds are relevant funds and whether CASS 15 applies. Scope is not only a question of licence type. It depends on the activity, the funds flow and whether the firm receives or holds relevant funds in the relevant funds regime.

The audit exemption also needs care. A firm is exempt from the SUP 3A safeguarding audit requirement only if it has not been required to safeguard more than £100,000 of relevant funds at any time over at least 53 weeks. That is not a casual point in time test. Senior management needs to keep it under review.

04 - What must your firm do now to comply?

Now that the regime is live, firms should start with reviewing their business operating models, not spreadsheets: 

  • What are the flows?
  • What money is relevant funds in those flows?
  • Where is it held?
  • Can we prove the position every reconciliation day?

Once that is clear, the core outputs can feed into  daily reconciliations, breach and exception handling, a live resolution pack, audit and monthly reporting. Each is a control you must be able to evidence on request, not a process you can simply assert.

  • Daily reconciliation (CASS 15). This is not one balance check. Stage 1 checks whether the firm’s records show enough safeguarding resource for the safeguarding requirement. Stage 2 checks D+1 placement where it applies. Stage 3 compares the firm’s internal records to external records from the bank, account provider, custodian or other relevant third party. The D+1 check may not work the same way where all relevant funds already go directly into a relevant funds bank account or relevant assets.
  • Remediation, breach logging and FCA notification. Breaks need a controlled response. Stage 1 and Stage 2 shortfalls generally need same day remediation. External discrepancies need investigation without undue delay. Material issues should be assessed for FCA notification, not buried in emails or an informal issue log.
  • The resolution pack (CASS 10A). The resolution pack must be live, accurate and retrievable quickly, in any event within 48 hours where the rule requires it. It should identify the accounts, institutions, agreements, acknowledgement letters, insurance or guarantee documents, agents, distributors, operational third parties, key people, procedures and reconciliation records needed to return relevant funds if the firm fails. The pack should not be built after the event.
  • The annual safeguarding audit (SUP 3A). Where the audit requirement applies, this is not a light review. The auditor is looking at whether the firm had adequate systems to comply with the relevant funds regime and whether it complied with the safeguarding requirements. Firms below the £100,000 over 53 weeks threshold may be exempt, but they still need a working safeguarding process.
  • The monthly safeguarding return (SUP 16.14A). The return should come from the same control process as the reconciliation, exception log and Board MI. It should not be rebuilt manually every month.

"The firms that handle this regime well do not treat safeguarding as multiple separate obligations. They treat it as one daily control environment. The firm needs to know what money is relevant, where it is held, what the records show and what happened when something broke. If funds classification or account mapping is wrong, the reconciliation will simply compound mistakes." — Oliver Roberts, Compliance Officer, Advapay UK

05 - Where firms are getting the transition wrong

The main mistake is treating the Supplementary Regime as a policy refresh.The rules are now specific enough that a tidy policy and a messy process is exactly the gap an auditor and the FCA look for. Firms need to test whether their funds flow, account structure, reconciliation logic, evidence trail, breach process and Board reporting actually work. The regime effectively forces firms to perform a health check of their safeguarding arrangements. 

The common gaps are familiar: manual reconciliations, weak D+1 logic, scattered evidence, no structured breach log, weak IT controls and poor Board MI. The problem is rarely one spreadsheet. It is the chain behind it: classification, ledger mapping, cut offs, account movements, approvals and exception handling.

The supervisory risk is now also sharper. The FCA has more ways to see weak safeguarding through daily records, monthly returns, audit findings, resolution pack readiness and breach notification triggers. A firm that cannot explain what it holds, where it is and how breaks were fixed is exposed. Recent FCA intervention activity also shows that safeguarding weaknesses can form part of wider serious regulatory concerns, especially where they sit alongside other issues.

06 - How Advapay helps you meet the new safeguarding regime

Advapay helps firms turn CASS 15 into an effective and compliant safeguarding process via three layers: conducting initial health check, improving operating model and providing a RegTech solution. 

The safeguarding health check looks at the operating model, how funds move through the business, whether relevant funds are identified correctly, and whether the firm can prove its position each reconciliation day.

Where gaps are found, we help rebuild and improve the operating model so the firm has clear ownership, repeatable reconciliations, controlled exceptions and required levels of oversight. 

Where technology is needed, Macrobank's accounting and reconciliation tooling further supports the operating process by tracking client balances against safeguarded funds and producing tracked reconciliation records that the rules require. 

If you want a straight read on where your safeguarding process stands against CASS 15, speak to our team. 

Advapay runs UK licensing and consulting across 100+ clients, 5 offices, and a team of around 50 people, so the safeguarding setup is built as part of the authorisation file or the operating model, not bolted on after the rules bite. For the general safeguarding primer that sits underneath this UK-specific regime, contact our team directly.

Questions teams actually ask (FAQ)

Is the FCA's new safeguarding regime the same as "CASS 15"? Not exactly. CASS 15 is the main new Handbook chapter, but the Supplementary Regime is wider. It also includes the CASS 10A resolution pack, SUP 3A safeguarding audits and SUP 16.14A monthly returns.

Did the new rules replace the EMRs and PSRs safeguarding requirements? No. The Supplementary Regime supplements the EMR and PSR safeguarding duties. The later Post Repeal Regime is still subject to further consultation and is not yet in force.

How often do we have to reconcile under the new regime? At least once each reconciliation day. Firms need internal and external safeguarding reconciliations. In practice, that means checking the firm’s records, D+1 placement where relevant, and external records from banks or other relevant third parties.

Does every firm need an annual safeguarding audit? No. There is an exemption where the firm has not had to safeguard more than £100,000 of relevant funds at any time over at least 53 weeks. Senior management must keep that position under review.

What is the resolution pack and how fast must we produce it? It is the live pack of records needed to identify and return relevant funds if the firm fails. It must be maintained according to CASS10 requirements  in advance and retrievable quickly, in any event within 48 hours where required. It should not be assembled after the event. 

Final thought

Most firms understand the safeguarding principle. The gap is usually in the operating detail. The Supplementary Regime does not create safeguarding from scratch – it raises the operating standard and makes weak safeguarding processes easier to test, easier to challenge and harder to defend.

The firms most exposed are the ones that cannot prove the basics: what money is relevant, where it is held, whether D+1 placement was met, what is their reconciliation logic and what happened when something broke. The practical lesson is to get the foundations right at the outset. Get that wrong, and daily reconciliation does not fix the problem. It compounds it.

Good safeguarding is now a daily control environment.

If you want help mapping your safeguarding process to CASS 15, speak to our team. Advapay can support the health check, operating model and technology layer as one connected safeguarding project.

Oliver Roberts, Compliance Officer, Advapay UK

Schedule a 30 min call with us