R
RegNexusGenesis

Authorisation

CASS 15 Safeguarding Requirements Explained for UK Firms

Understand CASS 15 safeguarding requirements: what they mean for UK payment and e-money firms, key obligations, and how to stay compliant.

If your firm holds customer funds as a payment institution or e-money institution, the FCA's new CASS 15 safeguarding regime represents one of the most significant regulatory changes your compliance team will face. Many UK businesses that previously operated under the Payment Services Regulations 2017 or the Electronic Money Regulations 2011 are now confronting a transformed rulebook that replaces the old safeguarding requirements with a more prescriptive, CASS-style framework — and the consequences of getting it wrong range from supervisory intervention to reputational damage that can be very difficult to recover from.

CASS 15 is the FCA's proposed chapter within the Client Assets sourcebook that would bring payment institutions (PIs) and e-money institutions (EMIs) under a coherent, strengthened safeguarding framework. The existing safeguarding requirements under the Payment Services Regulations and Electronic Money Regulations set out broad obligations — segregating relevant funds, holding them in designated accounts, using eligible safeguarding methods — but the FCA has long identified inconsistent practice across the industry. CASS 15 aims to close those gaps by introducing detailed, binding rules on how firms must identify, segregate, and protect the funds they hold on behalf of customers, bringing the regime closer in spirit and structure to the well-established CASS rules that already govern investment firms.

Under the proposed CASS 15 framework, firms will be required to establish and maintain robust internal safeguarding policies and procedures from day one of holding relevant funds. This includes promptly segregating customer money into appropriately designated accounts with eligible credit institutions or, where permitted, investing in qualifying liquid assets. Firms must conduct regular reconciliations — both internal and external — to confirm that the funds held in safeguarding accounts at all times match their liabilities to customers. Record-keeping obligations are heightened, with firms expected to be able to produce accurate, auditable records of their safeguarding position on demand. The FCA has also signalled that firms will need to appoint a senior manager with clear accountability for safeguarding compliance, reinforcing the link between CASS 15 and the Senior Managers and Certification Regime.

One of the most operationally demanding aspects of CASS 15 is the reconciliation discipline it demands. Firms must perform internal reconciliations — comparing their own records of customer balances against the funds actually held in safeguarding accounts — with sufficient frequency to detect and remediate shortfalls quickly. External reconciliations, comparing the firm's records against confirmations received from third-party account holders or custodians, must also be conducted regularly. Where a shortfall is identified, firms are expected to top it up promptly from their own funds. These requirements mean that manual, spreadsheet-based processes that may have served firms adequately under the old regime are likely to be insufficient; robust, automated systems capable of real-time or near-real-time data processing are increasingly necessary to sustain compliance.

Q: Does CASS 15 apply to my firm if we are already compliant with the Payment Services Regulations 2017? A: Existing compliance with the Payment Services Regulations 2017 safeguarding requirements does not automatically mean your firm will meet CASS 15 obligations. CASS 15, once in force, introduces more granular and prescriptive rules — including specific reconciliation methodologies, enhanced record-keeping, and senior manager accountability — that go materially beyond the current regulatory baseline. Firms should therefore conduct a gap analysis against the proposed CASS 15 rules rather than assuming current arrangements will suffice. The FCA's consultation process is the appropriate place to monitor for finalised transitional provisions and implementation timelines.

RegNexus Genesis is built to help payment institutions and e-money institutions manage precisely these kinds of evolving, data-intensive compliance obligations. Genesis provides a structured compliance workflow environment where your team can document safeguarding policies, track reconciliation outputs, assign senior manager responsibilities, and maintain the audit trails that regulators expect to see. Rather than stitching together generic tools, Genesis is designed around the regulatory lifecycle that UK-regulated firms actually experience — reducing the operational burden of staying current as rules like CASS 15 move from consultation to enforcement. Explore Genesis to see how it can underpin your safeguarding compliance programme.

CASS 15 represents a genuine step-change in the standard expected of payment and e-money firms when it comes to protecting customer funds, and early preparation is the most effective risk-management strategy available to your business. Begin by reviewing your current safeguarding arrangements against the FCA's published consultation materials, identify gaps in your reconciliation processes and governance structures, and ensure a senior manager is designated with explicit accountability for safeguarding. The firms that invest in robust frameworks now will be far better placed when final rules come into force. Visit reg-nexus.com today to explore how Genesis can support your CASS 15 readiness journey.

Related RegNexus capability

Explore Genesis