
Safeguarding and Consumer Duty
FCA safeguarding requirements, Consumer Duty compliance and APP fraud reimbursement for payment firms
A payment institution or an electronic money institution must hold customer funds separately from its own operational money, under the Payment Services Regulations 2017 and the Electronic Money Regulations 2011. Bratby Law advises on the design, implementation and governance of safeguarding arrangements that meet those requirements and work reliably every business day. Rob Bratby holds fractional general counsel appointments in the payments and telecoms sectors. That is day-to-day work on how a regulated payment firm runs safeguarding, rather than a view from outside the business.
When safeguarding obligations apply
Safeguarding is a regulatory obligation of every authorised payment institution and electronic money institution that holds relevant funds. The FCA’s Supplementary Regime under CASS 15 has applied since 7 May 2026. CASS 15 applies to authorised payment institutions, electronic money institutions, credit unions that issue electronic money, and small payment institutions that safeguard voluntarily under regulation 23 of the Payment Services Regulations 2017, in each case where they receive or hold relevant funds (CASS 15.1.2R). There is no de minimis threshold: a firm holding a modest balance of relevant funds is bound by CASS 15 in the same way as a large one. The £100,000 threshold operates elsewhere. An institution is exempt from the auditor’s safeguarding report under SUP 3A if it has not been required to safeguard more than £100,000 of relevant funds at any time for a period of at least 53 weeks (SUP 3A.1.1R(2)). The exemption reaches the report and nothing else: the institution remains bound by CASS 15 (SUP 3A.1.3G). Senior management must determine on a continuing basis whether the institution is still exempt, and appoint an auditor if it is not (SUP 3A.1.4G).
A firm that has had a safeguarding shortfall, a discrepancy in its cash position or a reconciliation failure must establish the cause and remediate it. A buyer of a regulated payment firm will examine its safeguarding arrangements in due diligence, and treats them as an indicator of operational maturity and compliance culture. A firm facing FCA supervisory engagement on safeguarding needs specialist support to remediate the control failures and to show the regulator what it has changed.
The FCA has not decided whether to proceed with the full end-state regime, known as the Post-Repeal Regime. It will consider the feedback it received alongside its review of the effectiveness of the Supplementary Regime, and the timing and feasibility of any transition depend on HM Treasury’s approach to revoking the PSRs 2017 and the EMRs 2011. A firm reviews its arrangements periodically to confirm that they still operate as designed and to prepare for that end state.
Why safeguarding matters now
The FCA published final rules in PS25/12 in August 2025 and the Supplementary Regime came into force on 7 May 2026, which gave a firm nine months to build the systems and processes it needed.
An authorised payment institution or electronic money institution must reconcile its safeguarded funds daily, file a monthly safeguarding return with the FCA within 15 business days of month-end, commission an annual safeguarding audit from a qualified auditor giving reasonable assurance, and name a designated senior individual responsible for safeguarding oversight. The FCA set those requirements in the Supplementary Regime; they prescribe how a firm discharges the existing statutory duty to safeguard relevant funds and do not add to it. A firm may still protect relevant funds by the insurance or guarantee method (EMRs 2011 regulation 22; PSRs 2017 regulation 23(12) and (13)), and CASS 15.5 sets the conditions on which it may do so. The policy or guarantee must pay out on an insolvency event with no condition or restriction other than certification of that event (CASS 15.5.4R). A firm must notify the FCA at least two months before it relies on the method for the first time, changes the amount of cover or changes its insurer or guarantor (CASS 15.5.7R), and must decide whether to continue with the method, and notify the FCA of that decision, at least three months before the policy or guarantee expires (CASS 15.5.10R). Every firm must also maintain a resolution pack containing everything needed to trace and return customer funds if it fails or enters resolution, and must be able to retrieve that pack within 48 hours.
A firm is exempt from the auditor’s safeguarding report if it has not been required to safeguard more than £100,000 of relevant funds at any time for a period of at least 53 weeks. A single day above the threshold within that period defeats the exemption. The end-state regime the FCA consulted on in CP24/20 would replace the safeguarding requirements of the PSRs 2017 and the EMRs 2011 with a CASS-style regime, including a statutory trust over relevant funds. That consultation closed on 17 December 2024 and PS25/12 is the FCA’s response to it. The FCA will decide whether to take the end-state regime forward after it has reviewed the Supplementary Regime, so further requirements may follow.
A payment firm selling products or services to retail customers must also meet the Consumer Duty under PRIN 2A. It must design its products and services to deliver good outcomes, charge a fair price for fair value, give consumers the information and understanding they need, and provide appropriate support. For safeguarding that means the firm must explain its arrangements to customers clearly, and must build them into its complaint handling and its incident response.
A payment service provider must reimburse a customer who falls victim to authorised push payment fraud in most cases, unless the customer acted with gross negligence, under the mandatory reimbursement regime that came into force on 7 October 2024. That affects a payment firm’s cash management and its reporting alongside safeguarding.
Safeguarding requirements in practice
Safeguarding is an operational system that must work every business day, not a policy document produced for the regulator. A firm that reconciles by hand on spreadsheets will not keep pace beyond a few hundred accounts: detection lag grows and a discrepancy surfaces weeks or months after it arises.
A firm must not co-mingle relevant funds with its operational cash. Co-mingling breaches the core safeguarding requirement and makes the whole arrangement non-compliant. Segregation must exist in the bank as well as in the accounting ledger, because the test applied if the firm fails is where the money actually is.
Professional indemnity or fidelity cover is not safeguarding and does not satisfy the requirement. Where a shortfall arises, the claim will be contested and the underlying breach remains a regulatory failure.
The resolution pack is a living document. A firm must update it whenever its safeguarding accounts, custodial arrangements, account signatories, systems or customer data change. A pack that is out of date when the firm needs it exposes customers and gives the FCA a further ground for criticism.
A safeguarding policy must set out the firm’s own process: which accounts hold safeguarded funds, which systems detect a discrepancy, who is told when a reconciliation fails, what happens on a shortfall, and what records the firm keeps. A policy that restates the regulatory requirements without those details cannot be operated by the staff who have to follow it.
The board must approve the safeguarding policy, and must approve the definition of material discrepancy that the firm uses to trigger escalation or external reporting. That definition is a matter of substance and goes to whether the firm’s safeguarding arrangements are fit for purpose; it is not a procedural step for delegation.
Consumer Duty and safeguarding are one exercise. A firm must build safeguarding features and risks into its product design, test outcomes to verify that safeguarding works as it tells customers it does, and analyse complaints and incidents to see whether a safeguarding failure contributed to customer harm.
A safeguarding framework that meets the requirements
Safeguarding done well is operational infrastructure. The firm holds segregated accounts at one or more banks, has a clear definition of which transactions create relevant funds, and reconciles those accounts daily through an automated system that flags exceptions within hours. A discrepancy goes straight to a named senior individual, into the risk register, and to root cause.
The firm updates the resolution pack monthly, and whenever its accounts, systems, processes or customer base change. The pack lists the accounts and the customers, and holds the bank’s signed account acknowledgement letters confirming safeguarding status, the system documentation, the reconciliation procedures and the details of any third-party custodian or segregation provider.
The senior individual responsible for safeguarding understands the operation as well as the rules. That person knows the reconciliation process, can read a discrepancy, knows the firm’s contacts at the bank and can move the firm quickly in a crisis. The board approves the safeguarding policy, the definition of material discrepancy, the escalation procedure for a shortfall, and the scope and findings of the annual audit.
Consumer Duty runs through the whole arrangement. The firm discloses its safeguarding features accurately in its terms and conditions and its marketing, tells customers how their money is held and what happens if the firm fails, and tests outcomes through sample transaction testing and customer feedback to verify that safeguarding works as promised.
Rob Bratby’s fractional general counsel work in the payments sector is day-to-day exposure to how this infrastructure is built and maintained, and to how it works alongside treasury, customer service and complaint handling.
When to instruct a safeguarding specialist
A firm whose arrangements fall short of the Supplementary Regime, which has applied since 7 May 2026, needs specialist advice. A firm remediating a shortfall or replacing its reconciliation systems needs the design and the implementation plan validated from outside. Where the FCA is conducting supervisory engagement on safeguarding, independent legal advice both manages the exchange with the regulator and evidences the board’s commitment to remediation.
Transaction due diligence is a common trigger. A buyer of a payment firm will conduct a detailed safeguarding review and will find control weaknesses. A seller who takes advice before the process starts can remediate them first, rather than concede a price reduction later.
How Bratby Law helps with safeguarding and Consumer Duty
Bratby Law advises payment and e-money firms on safeguarding and Consumer Duty. That work starts with the design of a safeguarding framework from first principles, working from the firm’s business model and customer base through to its operational procedures and its governance. It covers the definition of relevant funds, the design of the segregation model, and the specification of a daily reconciliation process that will hold as the firm grows.
The work covers the daily reconciliation process itself, automated or manual, so that it runs reliably and detects a discrepancy within an acceptable time. For a firm installing new systems or replacing existing processes it covers exception handling, escalation and reporting to senior management, and the systems selection, data requirements and control testing needed to verify that reconciliation works as designed.
Bratby Law prepares and maintains resolution packs, keeping the required information current, complete and retrievable within 48 hours. That includes obtaining and refreshing account acknowledgement letters from the banks, documenting the firm’s customer database and safeguarding procedures, and producing system documentation that would let another firm or an insolvency practitioner return customer funds if the firm failed.
For the annual safeguarding audit under PS25/12, Bratby Law works with the firm’s chosen auditor to scope the audit, prepares the documentation package, and advises on the response to the findings and recommendations.
On Consumer Duty, the work covers product design review, terms and conditions, outcome testing and complaint cause analysis, so that a firm describes its safeguarding accurately to customers and can demonstrate that it is meeting the four outcomes.
Bratby Law advises on the APP fraud mandatory reimbursement regime and how it works alongside safeguarding and cash management, including claims assessment procedures, consumer support arrangements and the Consumer Duty expectations that apply to them.
Where the FCA is engaging with a firm on safeguarding, Bratby Law advises on the response to information requests, the liaison with the FCA, the remediation plan, and the governance record that evidences the board’s commitment to it.
Safeguarding is one part of a firm’s authorisation position. Authorisation and Licensing covers the perimeter analysis and the FCA authorisation process, including application strategy. The statutory duty itself is in regulation 23 of the Payment Services Regulations 2017.
Advice on safeguarding and Consumer Duty compliance
Frequently asked questions about safeguarding and Consumer Duty
What are the FCA safeguarding requirements for payment institutions?
An authorised payment institution or electronic money institution must safeguard customer funds under the Payment Services Regulations 2017 and the Electronic Money Regulations 2011. It must hold those funds in segregated accounts separate from its own operational funds, reconcile them regularly and keep records demonstrating compliance. Since 7 May 2026 it must also reconcile daily under CASS 15 (CASS 15.8.19R), report monthly to the FCA under SUP 16.14A (SUP 16.14A.3R), obtain an auditor’s safeguarding report under SUP 3A (SUP 3A.3, SUP 3A.9.1R) unless it is exempt, and maintain a resolution pack under CASS 10A (CASS 10A.1.3R). The FCA set those operational requirements in its Supplementary Regime (PS25/12); they prescribe how a firm discharges its existing statutory obligations and do not add new ones.
What changes are coming on 7 May 2026?
Under the Supplementary Regime in PS25/12, published in August 2025, a firm must reconcile its safeguarded funds daily rather than on an ad hoc basis, report monthly to the FCA on the relevant funds it holds within 15 business days of month-end, appoint an auditor and obtain an annual safeguarding report prepared as a reasonable assurance engagement under SUP 3A unless it is exempt, and maintain a resolution pack containing everything needed to trace and return customer funds, retrievable within 48 hours. Those four requirements set out how a firm discharges the existing statutory safeguarding obligation. An institution is exempt from the auditor’s safeguarding report if it has not been required to safeguard more than £100,000 of relevant funds under the relevant funds regime at any time for a period of at least 53 weeks (SUP 3A.1.1R(2)). A single day above the threshold within that period defeats the exemption. A small payment institution sits outside SUP 3A altogether, because the chapter applies to authorised payment institutions authorised to carry out payment services other than payment initiation services or account information services, and to electronic money institutions (SUP 3A.1.1R(1)(a)).
What is a resolution pack?
A resolution pack is the file or document set holding everything an insolvency practitioner, an administrator or another firm would need to identify and return customer funds if the firm failed or entered resolution. It holds the safeguarding accounts, the customers and their identification, the amount held for each customer, the bank account acknowledgement letters, the systems documentation, the reconciliation procedures and the contacts at the banks and custodians. A firm must keep the pack up to date as its circumstances change, and must be able to retrieve it within 48 hours.
Do small payment institutions need a safeguarding audit?
No. SUP 3A applies to relevant institutions, which are authorised payment institutions authorised for payment services other than payment initiation or account information services, and electronic money institutions (SUP 3A.1.1R(1)(a)). A small payment institution is not a relevant institution, so the auditor’s safeguarding report is not required of it at any level of relevant funds. A small payment institution that safeguards voluntarily remains bound by CASS 15 and by the duty to maintain adequate safeguarding arrangements, and the FCA has said that arranging an audit voluntarily may help it meet those obligations (SUP 3A.1.3G). An authorised payment institution or an electronic money institution must obtain the report unless it has not been required to safeguard more than £100,000 of relevant funds at any time for a period of at least 53 weeks (SUP 3A.1.1R(2)).
How does Consumer Duty apply to payment firms?
The Consumer Duty under PRIN 2A applies to every authorised payment firm providing products or services to retail customers. The firm must design and sell its products and services to deliver good outcomes, charge a fair price for fair value, give consumers the information and support they need to make good decisions, and provide appropriate support after sale. For safeguarding that means disclosing the arrangements accurately, testing outcomes to verify that safeguarding operates as promised, and analysing consumer complaints to see whether a safeguarding failure contributed to harm.
What is the APP fraud mandatory reimbursement requirement?
A payment service provider must reimburse a customer who falls victim to authorised push payment (APP) fraud in most cases, unless the customer acted with gross negligence, under the PSR’s mandatory reimbursement requirement for Faster Payments, in force since 7 October 2024. Reimbursement is capped at £85,000 per claim, and the cost is shared equally between the sending and the receiving payment firm. The Bank of England, as operator of CHAPS, set the same £85,000 cap for CHAPS. The PSR said in PS24/7 that it would keep the cap under review. That creates material compliance and cash management obligations for a payment institution, and affects its cash position and its reporting to the FCA alongside safeguarding.
How often must firms reconcile safeguarded funds?
Under the Supplementary Regime (PS25/12) a firm must reconcile its safeguarded funds daily. It must perform an internal safeguarding reconciliation as frequently as necessary and no less than once each reconciliation day (CASS 15.8.19R). A reconciliation day is a business day that is not a Saturday, a Sunday, Christmas Day, Good Friday or a bank holiday in any part of the United Kingdom, and is not a day on which a relevant market outside the United Kingdom is closed. Daily reconciliation means a discrepancy is detected and investigated within hours rather than weeks, and a shortfall does not grow undetected.
When should I review my safeguarding arrangements?
Every payment institution and electronic money institution should review its safeguarding arrangements now, and in particular if it has not done so since PS25/12 was published in August 2025. The Supplementary Regime has applied since 7 May 2026, so a firm that is not yet compliant is exposed now. A firm that has had a discrepancy in its cash position, a reconciliation failure or a dispute with its bank needs a specialist review to establish the cause and prevent a recurrence. A change to the customer base, the business model or the banking arrangements should also trigger a review.
Related payments regulation pages
These pages cover the other payments obligations that apply to the same firms:
- Payments Regulation
- Authorisation and Licensing
- Open Banking and Variable Recurring Payments
- PSR and Scheme Governance
- Operational Resilience and DORA
- E-Money Regulation and EMI Compliance
- FCA Investigations and Enforcement
- Digital Money and Central Bank Digital Currencies
Credentials
Rob Bratby is Managing Partner of Bratby Law and Fractional General Counsel to UK Payments Initiative Limited, the industry body developing the UK’s commercial account-to-account payments scheme. He also holds Fractional General Counsel appointments at The One Touch Switching Company, TelXL and Core. He is ranked Band 2 for Telecommunications in Chambers UK 2026, listed by The Legal 500 as a Leading Partner for IT and telecoms in London, and recognised in the Lexology Index as a Global Elite Thought Leader for telecoms and media and a Thought Leader for data privacy and protection.
