The Annual Safeguarding Audit: What the FCA Actually Expects

The annual safeguarding audit is a reasonable-assurance review under SUP 3A. Advapay on who needs one, what the auditor actually tests, the deadlines, and how UK EMIs and PIs prepare.

Aug 7

The annual safeguarding audit is a reasonable-assurance engagement under SUP 3A in which an external auditor reports to the FCA on whether the firm maintained systems adequate to comply with the relevant funds regime throughout the period and complied at period end. Most in-scope EMIs and authorised PIs need one. Until 14 May 2027, the exemption applies where the firm has not been required to safeguard more than £100,000 of relevant funds at any time since 7 May 2026. After that, eligibility is assessed over a period of at least 53 weeks.

The audit tests evidence, not intentions.

As of August 2026, under the FCA's PS25/12 and SUP 3A.

01 - "Does our firm actually need a safeguarding audit?"

Most in-scope EMIs and authorised PIs do. The exemption is not a point-in-time balance test, and senior management must keep the firm’s eligibility under review on an ongoing basis. Even where the audit exemption applies, the underlying safeguarding obligations remain.

This is a significant formalisation of the previous position. FCA guidance previously expected firms subject to a statutory accounts audit to arrange a specific annual safeguarding audit by an independent external provider. SUP 3A now makes the requirement binding for all relevant institutions, prescribes the report and requires the external auditor to submit it to the FCA.

If you are unsure which side of the line you are on, assume you are in scope and build for the audit.

02 - "Show me your reconciliation for this date"

A core area of audit work is reconciliation continuity: they will pick dates across the period and ask you to produce the internal and external reconciliation records for each. Because the opinion covers systems throughout the period, firms should expect sampling and evidence requests across the year rather than only at period end.

What they are checking is that the internal reconciliation covered the comparison of safeguarding resource with safeguarding requirement and, where applicable, the separate D+1 comparison. They will also check that the external reconciliation compared the firm’s records with relevant third-party evidence, that discrepancies were handled within the applicable timeframe and that the records are complete and dated.

This is why the cadence rule — at least once each reconciliation day, excluding weekends, bank holidays, and foreign-market closures — is a core audit area. The auditor does not need to identify a shortfall. A failure to operate or evidence the required daily control can be enough to support a finding.

03 - "Where is the bank's acknowledgement letter?"

On segregation, the auditor tests whether the account is properly designated and documented. The bank’s acknowledgement letter is key evidence because it identifies the account and restricts the bank’s rights of recourse and set-off. No current and accurate letter, no clean evidence of the acknowledgement-letter control. 

They will check that relevant funds sit in correctly designated accounts, that each safeguarding account has an executed acknowledgement letter where required, and that each letter remains accurate and has been reviewed at least annually and whenever the arrangements change. A safeguarding account operating without an up-to-date acknowledgement letter can create an audit finding, because the balance may be intact while the account arrangements do not meet CASS 15.

The auditor will also test the insurance or guarantee route if you use it, including whether the cover complies with the relevant safeguarding requirements. Where less than three months remains before expiry and no replacement or renewal is in place, the firm must prepare and provide the FCA with a plan for moving to the segregation method. 

04 - "Produce your resolution pack"

The CASS 10A resolution pack is a separate safeguarding obligation rather than part of the formal SUP 3A opinion, although it may still be considered as part of wider safeguarding readiness. It must be complete, current and retrievable within 48 hours in the specified circumstances. The pack helps an insolvency practitioner return relevant funds quickly if the firm fails.

The pack should include, among other things, the master document index, the list of  institutions holding relevant funds or relevant assets, the executed acknowledgement letters, the insurance or guarantee policies, the agent and distributor lists, and the relevant third-party providers. Material inaccuracies must be corrected promptly and no later than five business days after the relevant change. A pack built once and never updated, where the bank list or a letter is stale, fails the currency test even if everything was correct on the day it was assembled.

The 48-hour retrieval standard is the practical test here. If producing the pack takes a week of digging, it would take the same week in an actual insolvency, which is precisely the outcome the FCA designed the pack to prevent.

05 - "When and how do you report to the FCA?"

On reporting, timing matters: the safeguarding report must normally be submitted within four months of the period end, and the audit period must not exceed 53 weeks. Late or inaccurate reporting is itself a compliance issue.

The six-month deadline is transitional, not a standing rule for every first audit. It applies where the period covered ends within 53 weeks of 7 May 2026. After that, four months is the rule, and the audit period cannot stretch beyond 53 weeks from the previous report or from when you became subject to the rules.

Alongside the audit, the monthly safeguarding return under SUP 16.14A gives the FCA an ongoing view between audits. The return should be supported by the same underlying safeguarding records, but it is a separate obligation and is not itself part of the annual SUP 3A report.

06 - How Advapay helps you prepare for the safeguarding audit

Advapay prepares firms for the audit by getting the evidence right before the auditor arrives — helping fintechs open bank accounts for client funds with proper acknowledgement letters, and running the daily reconciliation and maintaining records inside the Macrobank platform that support the audit evidence. Preparation is a process, not a pre-audit scramble.

Macrobank produces the dated reconciliation records and supports the resolution pack and governance evidence. Because Advapay runs UK licensing and consulting across 100+ clients with a team of around 70, firms can go into the audit with the evidence already in place.

To prepare for your safeguarding audit with the evidence already in order, speak to our team.

"An auditor's questions are predictable — show me a reconciliation, where is the acknowledgement letter, what caused this break and how was it fixed? What is not predictable is whether the firm can answer them on the spot. The whole job of preparing for the audit is making sure every one of those answers is a document you can hand over in minutes, not a thing you have to go and assemble." — Oliver Roberts, Compliance Officer, Advapay UK

Questions teams actually ask (FAQ)

Who has to have an annual safeguarding audit? Most in-scope EMIs and authorised PIs. Until 14 May 2027, the exemption applies where the firm has not been required to safeguard more than £100,000 of relevant funds at any time since 7 May 2026. After that, eligibility is assessed over a period of at least 53 weeks. The underlying safeguarding obligations remain even where the audit exemption applies.

What kind of assurance does the audit give? Reasonable assurance — the auditor opines on whether the firm maintained systems adequate to comply with the relevant funds regime throughout the period and complied at period end. It is a detailed control-testing engagement, not a light-touch review.

When is the safeguarding audit due? The standard deadline is four months after the audit period ends. A transitional six-month deadline applies where that period ends within 53 weeks of 7 May 2026. The audit period must not exceed 53 weeks from the previous report or from when the firm became subject to the rules.

What evidence is likely to receive close attention? Reconciliation records, acknowledgement letters and evidence showing how breaches were investigated and remediated. The audit covers the relevant funds regime as a whole, so there is no fixed shortlist.

Do we still report between audits? Yes. The monthly safeguarding return under SUP 16.14A gives the FCA an ongoing view. The returns should be supported by the firm’s underlying safeguarding records, but they remain separate from the annual SUP 3A report.

Final thought

The annual safeguarding audit is not only a test of whether customer funds were protected. It also tests whether the firm maintained adequate systems throughout the period and complied at period end. The auditor’s questions are knowable in advance: show me the reconciliation records, the account documentation and how identified breaches were handled. Prepare so that each answer is a document you can produce on the spot, and the audit becomes a confirmation rather than an examination.

To go into your audit with the evidence already in order, speak to our team.

Oliver Roberts, Compliance Officer, Advapay UK

Schedule a 30 min call with us