Automated Safeguarding Reporting: From FSA056 to Board Packs
The Dual Reporting Burden in Safeguarding
Every regulated firm managing client funds faces two distinct reporting obligations: regulatory returns submitted to supervisors (the FCA, CBI, BaFin, or national competent authority), and governance packs prepared for the board, risk committee, or CASS oversight function. Both are mandatory. Both are time-consuming. And in most firms, both are produced manually.
Regulatory returns, FSA056 for UK payment and e-money institutions, CMAR for investment firms, RegData submissions under the FCA's new data collection framework, require structured data in prescribed formats, submitted on defined schedules. Governance packs require a different kind of synthesis: narrative summaries, trend analysis, exception highlights, and risk commentary that helps non-specialist board members understand safeguarding status.
The manual production of both creates a recurring operational burden that consumes senior compliance resource, the same people who should be managing risk are instead formatting spreadsheets and assembling slide decks.
Regulatory Returns: What Supervisors Expect
The FCA's FSA056 return requires payment institutions and e-money institutions to report safeguarded balances, segregation method, custodian details, and reconciliation frequency. Under PS25, these reporting obligations are being refined, with expectations for more granular data and more frequent submission.
For investment firms, the Client Money and Assets Return (CMAR) requires detailed reporting on client money balances, asset positions, reconciliation status, and any breaches that occurred during the reporting period. The FCA has signalled that the CMAR may evolve to require more frequent filing for larger firms.
The shift to RegData, the FCA's new data collection platform, introduces additional technical requirements: structured data submission in prescribed schemas, replacing the legacy Gabriel system. Firms that continue to produce reporting data manually will face increasing friction as RegData's requirements become more granular.
Across all of these, the common challenge is the same: the data required for regulatory returns already exists within the firm's reconciliation and monitoring systems. The bottleneck is extracting, formatting, and validating it for submission, a process that should be automated, not manual.
Board Packs: Governance Reporting for Non-Specialists
Board and risk committee reporting serves a different purpose from regulatory returns. Where FSA056 demands structured data, board packs demand insight: what is the current safeguarding status? Are there any emerging risks? Have any breaches occurred, and how were they resolved? Is the firm's safeguarding programme adequate?
The challenge is translating operational compliance data into a format that non-specialist directors can understand and act upon. A board member does not need to see every reconciliation result, they need to see trends, exceptions, and risk indicators presented in a way that supports governance decisions.
In most firms, board pack production is a manual exercise performed quarterly by the compliance team. This creates lag, the board is reviewing data that may be two to three months old, and consumes significant senior resource. Automating board pack generation from live compliance data eliminates the lag and frees the compliance team to focus on risk management rather than report assembly.
What Automated Reporting Looks Like
Automated reporting infrastructure generates both regulatory returns and governance packs from the same underlying compliance data, the reconciliation results, breach events, coverage ratios, and resolution records that the platform captures continuously.
For regulatory returns, the system maps internal data fields to the prescribed submission format, FSA056, CMAR, RegData schema, and generates the return automatically at the required frequency. The compliance team reviews and approves the return before submission, but does not need to assemble it.
For board packs, the system generates narrative summaries with embedded data visualisations: safeguarding status over time, reconciliation completion rates, breach frequency and resolution speed, coverage ratio trends. The pack is assembled automatically from live data, ensuring the board receives current information rather than stale snapshots.
How Safeheld Automates Safeguarding Reporting
Safeheld generates both regulatory returns and board-ready governance packs from the same compliance data that powers reconciliation and breach detection. FSA056, CMAR, and RegData-formatted exports are produced automatically at configurable intervals. Board packs are assembled with narrative summaries, trend visualisations, and exception highlights, ready for review and distribution.
Every generated report is stored with full version history and user attribution, creating an immutable record of what was reported, when, and by whom. This transforms reporting from a manual assembly exercise into a governed, auditable process.