CASS 15 demands more than compliance. Firms must understand their safeguarding model, evidence effective controls and prepare for ongoing FCA scrutiny.
Monthly returns create a continuing safeguarding profile. Qualified audits test what sits beneath it. Together, they show whether a firm has understood the harm the FCA is trying to prevent.
Start with the harm, not the rulebook
CASS 15 is not another layer of compliance introduced to make firms’ lives harder. In 2023, the FCA opened supervisory cases concerning around 15% of firms that safeguard. Among firms that became insolvent between Q1 2018 and Q2 2023, the average shortfall was 65%. In 2024, electronic money institutions safeguarded approximately £26 billion, while payment institutions safeguarded an estimated £6 billion on any given day.
The potential for harm is real. Firms have failed with less money safeguarded than they owed customers and records too weak to show quickly whose money was missing or where the funds were held. CASS 15 is designed to address those failures.
Firms that treat the regime mainly as a regulatory burden risk building surface compliance that looks right but fails to examine the operating model at the depth the new regime demands. Understanding the harm behind the new requirements helps a firm design a credible and appropriate framework, anticipate what is behind an FCA enquiry and manage supervisory engagement more effectively.
The FCA will read the movement, not just the number
The new monthly return creates a continuing and dynamic safeguarding profile of the firm. It allows the FCA to track changes over time and identify apparent outliers across the wider safeguarding portfolio, giving the FCA ongoing supervisory intelligence that will support targeted supervision and assessment of risks across the sector.
A firm may have no safeguarding breach and still attract questions. For example, if a firm’s safeguarding requirement rises from £5 million to £20 million, the movement may reflect legitimate growth, a new programme or different settlement timing. Yet, the FCA may ask what changed and review whether the firm’s controls and resources kept pace.
This is where proactive curiosity matters and firms should use the same returns to challenge themselves before the FCA does. Any material movement or outlier should be understood before submission, with its cause, whether it was expected, and any required action recorded. The return then becomes a diagnostic control over the safeguarding model and the business changes affecting it, rather than data produced mindlessly for RegData.
Safeguarding anomalies may also prompt scrutiny of other areas. For example, the FCA’s recent action against Euro Exchange Securities UK Limited referred to concerns spanning safeguarding, financial crime and governance. Whilst the case does not prove causation, it shows that supervisory concerns are not triggered and assessed in isolation.
The safeguarding profile begins with the operating model
The key is to understand the operating model and how it creates the firm’s safeguarding position, rather than diving straight into the daily reconciliations.
Commercial simplicity does not necessarily mean safeguarding simplicity. For example, a remittance service may appear to have a straightforward customer journey but conceal a complicated operational and accounting chain. Assuming the model is simple can prevent a firm from examining operating mechanics deeply enough.
The daily reconciliation sits at the end of that process. If the firm misunderstands whose money it holds, why it moved or when it left the safeguarding population, the reconciliation may balance perfectly while confirming the wrong position.
Change management must form part of the safeguarding framework. A new account, processor, product or settlement route can invalidate assumptions that were previously correct.
The audit tests what the return cannot show
The annual safeguarding audit gives the FCA a second supervisory lens. A monthly return may appear unremarkable while a serious structural weakness remains beneath it. The qualified audit gives the FCA an independent route to identify that weakness.
Many firms previously used compliance consultants, and safeguarding audits did not have to be submitted to the FCA. Under SUP 3A, a qualified auditor now prepares the report, which must be submitted to the regulator. An issue that might previously have remained internal may therefore reach the FCA as an independent audit finding. Firms accustomed to less formal reviews should not underestimate the preparation and challenge this requires.
CASS 15 raises the authorisation bar for new entrants
The same logic applies to authorisation. The safeguarding model must now be worked through early enough to shape the application, rather than added after the commercial model has already been settled.
For example, an applicant expecting to hold substantial e-money balances should expect the FCA to examine whether its proposed infrastructure and resources are proportionate to that profile. Applicants must therefore factor greater depth, expertise and preparation time into the licensing process.
The same challenge applies to recently authorised firms, which must convert arrangements developed under the earlier framework into a live CASS 15 operating model.
Conclusion
CASS 15 does not prescribe one universal safeguarding operating design. It requires each firm to understand its model in sufficient depth to explain why its methodology is appropriate, how it supports the FCA’s objectives, and how it reflects the firm’s safeguarding profile and underlying operating mechanics.
Firms that remain proactively curious, challenge their methodology and build evidence and timely action into the operating model will be better placed to withstand scrutiny throughout their lifecycle. Those that comply only at the surface remain most exposed to supervisory intervention.


















