CASS 15 Safeguarding Audit
Specialist safeguarding audits for payment and e-money firms under FCA CASS 15 and SUP 3A, delivered by a registered auditor.
Let’s talkFrom 7 May 2026, firms within the scope of CASS 15 that hold £100,000 or more in relevant funds must arrange an annual safeguarding audit conducted by a registered auditor. Black Maple delivers these engagements under SUP 3A and ISAE (UK) 3000, with the report submitted directly to the FCA.
Do you need a CASS 15 safeguarding audit?
Answer four questions to find out whether your firm has a legal obligation to appoint a registered auditor under FCA PS25/12 and SUP 3A. Your result includes the relevant regulatory references.
What CASS 15 now requires
- Daily reconciliations of safeguarded funds, both internal and external, on every business day.
- Resolution packs maintained per CASS 10A, containing all documentation an insolvency practitioner would need to identify and begin returning customer money, retrievable within 48 hours of appointment.
- A monthly safeguarding return submitted to the FCA providing standardised data on the firm’s safeguarding position.
- Named senior manager accountability, with a single director or senior manager responsible for operational oversight of the regime and annual reporting to the board.
- Third-party due diligence on all banks, custodians, and other parties involved in holding or managing relevant funds.
- Prescribed acknowledgement letters in a standard template form (CASS 15 Annex 1) for every relevant funds bank account and relevant assets account.
Who needs a safeguarding audit?
From 7 May 2026, a mandatory annual safeguarding audit is required for any firm that falls within the scope of CASS 15 and holds £100,000 or more in relevant funds during its audit period. The following firm types are in scope:
- Authorised payment institutions (APIs): businesses authorised by the FCA to provide payment services, such as money transfer companies, payment processors, and firms that move funds on behalf of customers.
- Authorised e-money institutions (AEMIs): businesses authorised to issue electronic money, such as digital wallets, prepaid card providers, and fintech firms that hold customer funds in an e-money account.
- Small e-money institutions (SEMIs): smaller e-money issuers that operate under a lighter-touch registration rather than full authorisation.
- Credit unions that issue e-money in the UK: member-owned financial cooperatives that have expanded into issuing electronic money products.
- Small payment institutions (SPIs) that have voluntarily opted in: smaller payment firms that are not required to safeguard but have chosen to do so, bringing themselves within the full CASS 15 regime.
Firms that solely provide payment initiation services or account information services are excluded. The audit must be conducted by a registered auditor and the report submitted to the FCA by the firm within six months of the first audit period end, and within four months for all subsequent periods.
Common questions
What is the difference between the safeguarding audit and our existing statutory audit?
They are separate engagements with different objectives, different governing standards, and different reporting outputs. Your statutory audit is an audit of your financial statements conducted under International Standards on Auditing (UK), with the objective of forming an opinion on whether those statements give a true and fair view. It is addressed to your shareholders and filed at Companies House. The safeguarding audit is an assurance engagement conducted under ISAE (UK) 3000, with the objective of assessing whether your firm has complied with the relevant funds regime under CASS 15 across the audit period. It is addressed to both your governing body and the FCA, and submitted directly to the regulator. The two audits can be conducted by the same firm, but they are distinct pieces of work with distinct reports.
What is a Resolution Pack and do I need one?
A resolution pack is a set of documents and records that an insolvency practitioner would need to identify and begin returning customer money in the event your firm fails. The requirement is set out in CASS 10A, in force from 7 May 2026. Every firm subject to CASS 15 must maintain a resolution pack, regardless of whether they are also required to appoint a safeguarding auditor. The critical operational requirement is retrievability: the complete pack must be capable of being produced within 48 hours of an insolvency officer being appointed or an FCA or Bank of England request.
Can our existing auditor do the CASS 15 audit?
Only if they are a registered audit firm under the Companies Act and have the relevant experience. Many firms that handle a payment institution’s statutory audit are not set up to issue the CASS 15 report. Ask your current auditor in writing before assuming the answer is yes.
What does the engagement actually look like?
We scope it against the size of the safeguarded balance and the complexity of your reconciliation process. For a smaller e-money firm with one safeguarding account and clean daily reconciliations, fieldwork is usually a week to ten days plus a partner review. For larger firms with multiple jurisdictions or complex flows, it is longer. We give you a fixed fee before we start.
When should we appoint an auditor?
Sixty to ninety days before your year-end is the comfortable window. The first reporting cycle under CASS 15 will be busy, and appointing late means you may find the firm you want is already at capacity.
Our footprint
A UK regulated service
CASS 15 and SUP 3A are UK regimes. Safeguarding audits are delivered through our UK-registered London office.
Work with us
Ready to get started?
Every engagement starts with understanding your business. Reach out to discuss how we can help.
Get in touch