CASS 15 & client money
CASS 15 compliance software for EMIs and payment institutions
If you hold or control client money as part of payment services or e‑money issuance, the FCA expects you to operate CASS‑style controls: clear records, timely reconciliations, and evidence that client money is protected. Guardexia is built to operationalise those requirements—not just tick boxes—with viability decision support and risk-gated governance controls.
What is CASS 15 and who does it apply to?
CASS (Client Assets) is the FCA handbook sourcebook for client money and safe custody. CASS 15 is the chapter that applies to certain payment institutions and e‑money institutions when they hold or control client money in the course of business. It sits alongside your broader conduct (including safeguarding under the Payment Services Regulations and the E‑Money Regulations). If you are in scope, you need a coherent system: designated accounts or arrangements, accurate books, regular reconciliations between internal records and external providers, and a process to identify and resolve discrepancies quickly.
What firms must be ready for by 7 May 2026
The FCA’s supplementary regime for safeguarding and prudential risk management (often discussed alongside PS25/12) tightens expectations for many firms. By the relevant date, you should be able to show—not only in policy but in operational records—that you reconcile safeguarding client money on a frequency that matches your risk, that exceptions and breaches are identified, escalated and closed, and that governance (including board packs and attestations where applicable) reflects reality. Regulators care about evidence: dated snapshots, who approved what, and how long gaps stayed open.
What supervisors typically test
In a skilled persons review or a visit, regulators do not only read your policy PDF. They ask for samples of reconciliations across dates, evidence that differences were cleared or escalated within your own timelines, and proof that approvals were independent (for example, a checker who did not upload the underlying files). They may also trace a breach from detection through to closure. Guardexia is structured so those artefacts are system-generated—timestamps, user IDs and immutable audit lines—rather than reconstructed from email months later.
How Guardexia supports each CASS‑style obligation
- Daily (or agreed) external reconciliation — Upload customer and bank balances via CSV or API; run reconciliations for each balance date; retain differences and materiality in one place.
- Segregation and safeguarding evidence — Link uploads and approvals to immutable audit events so you can reconstruct what happened for a given day.
- Exceptions and breaches — Classify differences against your firm’s thresholds; log incidents with root cause and remediation; drive the breach register toward “resolved” when work is complete.
- Dual control — Maker / checker style workflows for submission and approval so one person cannot silently sign off their own work.
- Viability controls — Coverage ratio, stage progression, and explain-your-position evidence.
- Exports — Board packs and CSV exports for supervisory and internal governance use, including attestation risk context.
Pricing and how to start
Guardexia is priced for teams that need defensible operations, not a one‑off spreadsheet. See pricing for current plans. You can start a free trial without a sales call: create your company, connect your first feed, and run a reconciliation in minutes. If you want to talk through CASS scope and PS25/12 together, contact us.
PS25/12 supplementary regime: PS25/12 compliance software. Automated reconciliation: safeguarding reconciliation for FCA firms. CASS 15 insolvency data — 65% average shortfall across 12 firm failures. wind-down plans under PS25/12 — FCA supervisory findings.
Frequently Asked Questions
What is CASS 15?
CASS 15 is the FCA's new safeguarding sourcebook for payment institutions and electronic money institutions, coming into force on 7 May 2026. It introduces CASS-style controls for firms that hold or control client money, requiring daily reconciliations, monthly regulatory returns, annual safeguarding audits and a resolution pack retrievable within 48 hours.
Who does CASS 15 apply to?
CASS 15 applies to FCA-authorised payment institutions, authorised e-money institutions, small e-money institutions and credit unions that issue e-money in the UK. It does not apply to firms that solely provide payment initiation or account information services.
What does CASS 15 require by 7 May 2026?
From 7 May 2026 firms must perform daily internal and external safeguarding reconciliations, submit monthly safeguarding returns to the FCA, arrange annual safeguarding audits by a qualified independent auditor, maintain a CASS 10A resolution pack retrievable within 48 hours, and demonstrate board-level oversight with named SMF accountability.
How often must reconciliations be performed under CASS 15?
CASS 15 requires firms to perform daily internal and external reconciliations on each reconciliation day, excluding weekends and UK bank holidays. Each reconciliation must be documented, differences explained, and the record locked with an immutable audit trail.
What is a CASS 15 safeguarding audit?
A CASS 15 safeguarding audit is an annual audit carried out by a qualified independent auditor to verify that a firm's safeguarding arrangements comply with the FCA's requirements. The first audit report is due within six months of the firm's first audit period end date. The audit must be separate from the firm's statutory audit.
What happens if a firm fails to comply with CASS 15?
Firms that fail to comply with CASS 15 face FCA supervisory action including requirements, restrictions on permissions, financial penalties and in serious cases cancellation of FCA authorisation. The FCA has made clear that safeguarding compliance is a supervisory priority following persistent failures identified across the sector.
How does Guardexia support CASS 15 compliance?
Guardexia automates daily safeguarding reconciliation, flags variances, locks each snapshot into an immutable audit trail, and generates the FCA Supervisory Visit Pack in one click. It also covers prudential capital adequacy monitoring, wind-down plan trigger tracking and SMF attestation — all the operational requirements of CASS 15 and PS25/12 in one platform.
What is the difference between CASS 15 and PS25/12?
PS25/12 is the FCA Policy Statement that introduced the new safeguarding regime. CASS 15 is the specific FCA Handbook chapter containing the rules that firms must comply with. PS25/12 describes the policy intent and transition arrangements, while CASS 15 contains the binding regulatory requirements.