Safeguarding 2026: What E-Money and Payments Firms Need to Prepare Now
The FCA’s new CASS 15 framework comes into force on 7 May 2026. For most payment and e-money firms, it represents the biggest operational…
Safeguarding 2026: What E-Money and Payments Firms Need to Prepare Now

The FCA’s new CASS 15 framework comes into force on 7 May 2026. For most payment and e-money firms, it represents the biggest operational shift since authorisation. Here’s what’s changing, what it means in practice, and where firms are most likely to fall short.
On 7 August 2025, the FCA published Policy Statement PS25/12, finalising the new Supplementary Regime for safeguarding customer funds held by payment institutions and e-money institutions. The rules take effect on 7 May 2026 — less than three months from now.
This is not a minor update. It is a structural overhaul of how firms are expected to protect, reconcile, report on and document customer funds. For many firms in the payments and e-money space, particularly those that have operated under lighter-touch safeguarding expectations, this represents a step-change in what the FCA expects — not just operationally, but in terms of documentation, governance and audit readiness.
And yet, a significant number of firms are still underestimating what compliance actually requires.
What Is Actually Changing?
The new framework, built around CASS 15, CASS 10A, SUP 3A and SUP 16.14A, introduces four core requirements that bring payment and e-money firms closer to the standards already expected of investment firms under the Client Assets Sourcebook:
1. Daily Reconciliation
Safeguarded funds must be reconciled on every business day — comparing what should be held against what is actually held, and remediating any shortfall promptly using the firm’s own funds if necessary. This is not a weekly check or a month-end exercise. It is a daily operational discipline that most payment firms have never had to maintain at this level.
2. Monthly FCA Reporting
Firms must now submit a monthly regulatory return within 15 business days of each calendar month end. The return covers safeguarding methods, the number of clients for whom funds are safeguarded, reconciliation outcomes, balances, accounts, and any breaches. This is a new reporting obligation — and it requires firms to have their data structured, accurate and submission-ready on an ongoing basis.
3. Annual Safeguarding Audit
All payment and e-money institutions that have safeguarded £100,000 or more at any point over a rolling 53-week period must undergo an annual safeguarding audit by a qualified auditor. Before these changes, unqualified consultants could perform these reviews. That is no longer the case. The first audit report must be submitted within six months of the period end, and within four months in subsequent years.
4. Resolution Pack
Firms must maintain a comprehensive, living resolution pack — retrievable within 48 hours — that details where safeguarded funds are held, the firm’s agents and distributors, flow-of-funds descriptions, and procedures for returning client money in the event of insolvency. This is not a static document. The FCA expects it to be a continuously updated set of records that links directly to the latest reconciliations, contracts and account information.
Why This Matters More Than Firms Think
The tendency among many firms is to treat safeguarding reform as a compliance checklist: update a few policies, run some reconciliations, submit the return. But the FCA’s intent is more fundamental than that.
The regulator has been explicit about the reason for these changes: previous safeguarding failures resulted in customers recovering, on average, only 35% of the funds they were owed when firms failed. That is not a number regulators accept quietly.
What this means in practice is that the FCA is not just looking for box-ticking compliance. It is looking for evidence that firms have genuinely embedded safeguarding into their operational governance — that boards understand the requirements, that reconciliations are real and not performative, and that resolution packs would actually work in an insolvency scenario.
Firms that approach this as a paperwork exercise are likely to find themselves under increased supervisory scrutiny, particularly if their documentation does not reflect how safeguarding actually operates within the business.
Where Firms Are Most Likely to Fall Short
Having spent over six years working across crypto, payments and e-money environments, I have seen how documentation and operational readiness consistently lag behind regulatory expectations. Based on that experience, here is where I expect the biggest gaps to emerge:
Documentation is still treated as a one-off exercise. Most firms produce safeguarding policies and procedures at the point of authorisation and rarely update them. Under CASS 15, documentation must be living, version-controlled and reflective of actual operational practice. Static policies will not survive audit scrutiny.
Resolution packs do not exist in a usable form. Many firms either do not have a resolution pack at all, or have one that was created for the authorisation application and never updated. The FCA expects these packs to be retrievable within 48 hours and to contain current, accurate information. Building this from scratch in the final weeks before May 2026 is not realistic.
Reconciliation infrastructure is manual and fragmented. Daily reconciliation requires systems that can compare safeguarded balances against obligations in near real-time. Many smaller EMIs and payment institutions still rely on spreadsheets or manual processes that cannot support this frequency or accuracy at scale.
Audit readiness is low. Firms that have never been subject to a CASS-style audit may not understand the depth of evidence expected. Auditors will want to see not just that reconciliations happened, but that discrepancies were identified, escalated, and resolved — with a documented trail.
Governance narratives are weak. The FCA expects a named senior manager to be responsible for safeguarding, with board-level approval of safeguarding policies. Many firms have not yet formalised this governance structure or documented how safeguarding oversight sits within their broader risk and control framework.
The Cross-Border Dimension
For firms operating across the UK and EU, the complexity multiplies. While the UK is implementing CASS 15, the EU is progressing with PSD3 — expected to take effect in 2027 — alongside MiCA, which has been live since December 2024. The approaches differ in important ways: the UK leans toward a statutory trust model, while the EU emphasises strict segregation without trust concepts.
Cross-border firms will need safeguarding frameworks that satisfy both regimes simultaneously. Payment flows may need to be restructured so that relevant funds are received directly into safeguarding accounts in each jurisdiction. This is not a theoretical concern — it has immediate operational and documentation implications for any firm with a presence in both markets.
What Firms Should Be Doing Right Now
With less than three months until the deadline, the priority actions are clear:
Map your current state against CASS 15. Conduct a structured gap analysis comparing your existing safeguarding arrangements against each requirement in CASS 15, CASS 10A, SUP 3A and SUP 16.14A. Identify where systems, processes and controls need to be strengthened.
Build or update your resolution pack. This should be treated as an ongoing operational document, not a compliance deliverable. Link it to your latest reconciliations, account information and contracts. Make sure it is retrievable within 48 hours.
Establish your daily reconciliation process. If you are still reconciling weekly or monthly, you need to redesign the process now. Consider whether your current systems can support daily comparison of safeguarding requirements against safeguarding resources, and invest in automation if they cannot.
Engage a qualified auditor. If you have not already appointed a CASS-experienced auditor, do so immediately. Capacity among qualified auditors is finite, and firms that wait until the last moment may find themselves without coverage.
Update your governance framework. Ensure a named senior manager is formally responsible for safeguarding. Ensure board-level sign-off on safeguarding policies, including a clear definition of what constitutes a material discrepancy.
Prepare for monthly reporting. Review the data points required in the monthly FCA return and ensure your internal systems can produce accurate, timely submissions within the 15 business day window.
The Bigger Picture
CASS 15 is not happening in isolation. It sits alongside the broader expansion of the UK cryptoasset regulatory regime toward full FSMA authorisation, increasing regulatory expectations across governance, prudential resilience and consumer protection. For firms operating at the intersection of payments, e-money and crypto, the combined documentation and compliance burden is substantial — and growing.
The firms that will navigate this transition most effectively are those that treat regulatory documentation as operational infrastructure rather than a periodic compliance task. The ones that will struggle are those that continue to rely on reactive, consultant-led approaches to documentation that was designed to be proactive, structured and continuously maintained.
The 7 May 2026 deadline is not the end of the journey. It is the beginning of a permanently higher standard of safeguarding governance in the UK payments ecosystem. The question is not whether your firm will need to comply — it is whether you will be ready when the FCA starts looking.
메타데이터
- post_id
- 9c17cda19d2d
- slug
- safeguarding-2026-what-e-money-and-payments-firms-need-to-prepare-now-9c17cda19d2d
- url
- https://medium.com/@asena.k/safeguarding-2026-what-e-money-and-payments-firms-need-to-prepare-now-9c17cda19d2d
- canonical_url
- https://medium.com/@asena.k/safeguarding-2026-what-e-money-and-payments-firms-need-to-prepare-now-9c17cda19d2d
- author_url
- https://medium.com/@asena.k
- status
- ok
- fetched_at
- 2026-06-18 00:10:23