CASS

    The CASS Head's Guide to Continuous Compliance Oversight

    How the individual holding client assets oversight uses real-time positions and automated alerting to maintain continuous oversight under CASS 1A.3 and CASS 15.2.4R.

    10 min read March 2026

    In short

    The CASS oversight function is personally accountable for the firm's compliance with the client assets regime, including the adequacy of its systems, controls and records. Continuous oversight means holding a live, corroborated view of the client money requirement and custody positions, an exception register with owned and time-bound resolution, and contemporaneous evidence that the oversight itself occurred.

    What the oversight role is actually accountable for

    The responsibility is defined functionally, not by job title. For firms subject to CASS 1A, CASS 1A.3.1R requires the firm to allocate to a single director or senior manager of sufficient skill and authority responsibility for oversight of the firm's operational compliance with CASS and for reporting to the governing body on that oversight. CASS 15.2.4R imposes the equivalent requirement on safeguarding institutions in respect of the relevant funds regime. Neither rule creates a named function, and the historic CF10a controlled function label no longer describes a live FCA controlled function following the introduction of the senior managers and certification regime. Where a firm is within that regime, the CASS prescribed responsibility is mapped to whichever senior management function its own allocation places it in and recorded in that individual's statement of responsibilities. There is no centrally prescribed senior management function for CASS or for safeguarding oversight, and many payment and e-money institutions authorised only under the Payment Services Regulations or Electronic Money Regulations sit outside the senior management function regime altogether while still carrying the CASS 15.2.4R allocation. For which CASS chapters apply to which type of firm, see What is CASS? The FCA Client Assets Sourcebook Explained; this guide assumes that map and focuses on how the oversight role is actually discharged.

    The accountability is for the control environment as well as the outcome. A shortfall that was detected promptly, corrected from the firm's own resources, escalated and evidenced is a materially different position from one detected late by an auditor.

    This is why oversight cannot be discharged by receiving a monthly pack. A monthly pack describes a period that has closed and offers no opportunity to intervene in it.

    The practical standard is that the officer can, at any moment and without asking anyone to prepare anything, state the current position, the open exceptions, their age and owner, and the last date on which every required reconciliation was completed.

    What a continuous oversight view must surface

    Four things, in order of priority. First, completeness: every account, custodian and counterparty in scope, with any source that has failed to report flagged as an exception rather than silently omitted. Missing data is the most dangerous state because it presents as a clean reconciliation.

    Second, the requirement and the resource, calculated independently and compared, with the corroborating third record shown alongside so that a methodology error is visible rather than absorbed.

    Third, the exception register with each item's category, value, age, owner, next action and deadline. An exception without a named owner and a date is not being managed.

    Fourth, timeliness: whether each required reconciliation and record check was completed within its window, expressed as a compliance rate over the period rather than a status for today.

    Designing escalation that survives scrutiny

    Escalation should be defined before it is needed, documented, and mapped to named roles. A tiered structure works: automated notification at low value and short age, supervisor ownership above a defined threshold, oversight function notification for anything approaching a reportable position, and immediate senior escalation for a confirmed shortfall.

    Each tier needs a response time, and the response time needs to be measured. An escalation policy with no measurement is a document rather than a control.

    Thresholds must be calibrated against the firm's actual variance profile. A threshold set so low that it fires constantly trains the recipients to ignore it, and a demonstrably ignored alert is worse evidence than no alert.

    The record of escalation, including who was notified, when, what they saw and what they decided, is the artefact that answers a supervisory question about whether the firm knew. It should be generated automatically rather than reconstructed.

    Breach identification and notification discipline

    A CASS breach is broader than a shortfall. A reconciliation performed late, a record check not performed, a discrepancy not funded, a resolution pack out of date and an unauthorised withdrawal from a client bank account are each breaches in their own right.

    Firms that only log shortfalls under-report substantially, and the under-reporting is easy for an auditor to identify by comparing the reconciliation timing log against the breach register.

    Every breach should be logged with its rule reference, root cause, client impact, remediation and preventive action, and the register should be reconcilable to the exception data rather than maintained separately.

    Notification obligations to the FCA sit alongside this. The oversight function needs a clear internal standard for what triggers notification, applied consistently, because inconsistent notification is itself evidence of weak oversight.

    Reporting upwards without losing the signal

    A board does not need a break count. It needs to know whether client money is intact, whether the control operated throughout the period, where the control is under strain, and what is being done about it.

    Four measures carry that message: unexplained residual variance and its trend, detection and correction latency, reconciliation timeliness as a percentage of obligations met on time, and the ageing profile of open exceptions by category.

    Trend matters more than level. A stable residual with improving latency describes a maturing control. A low residual with deteriorating timeliness describes a control that is about to fail.

    Every figure presented should be traceable to the underlying run, so that a challenge from a non-executive can be answered with the source rather than with a promise to check.

    Running the year so the audit is uneventful

    The annual CASS audit tests the period, not the year end. An oversight function that operates continuously accumulates the evidence the auditor will request as a by-product of ordinary operation.

    The most common findings are avoidable by design: incomplete populations, late reconciliations, unevidenced corrections, breach registers that do not reconcile to exception data, and resolution packs that have drifted from the live account structure.

    Each of those is a monitoring question during the year rather than a preparation question in the final quarter. Reviewing them monthly against the same data the auditor will receive removes almost all of the surprise.

    Safeheld supports this by maintaining the exception lifecycle, timeliness record, breach register and resolution pack from one live configuration, and by sealing completed runs so that the evidence produced in fieldwork is provably the evidence that existed at the time.

    The first ninety days in the role

    An incoming oversight officer should begin with completeness rather than accuracy. Obtain the full list of accounts, custodians, counterparties and systems in scope, and compare it against the population actually reconciled. Any difference is the first finding.

    Next, test reproducibility. Select three dates in the previous year and ask for the position as it stood, with the exceptions open on those dates. The time taken is a direct measure of the control environment.

    Then review the definition of protected funds against the firm's actual product set, paying particular attention to unallocated receipts, agent and distributor float and any category treated as out of scope by convention rather than by analysis.

    Finally, reconcile the breach register to the exception data. A breach register that is materially smaller than the underlying exception population indicates under-recording, which is a finding an auditor will reach independently.

    Oversight of outsourced and group-provided functions

    Where reconciliation, treasury or reporting is performed by a group service company or a third party, the regulatory responsibility remains with the authorised entity and its named senior individual.

    Oversight of an outsourced function requires the same evidence as an in-house one: population completeness, timeliness, exception lifecycle, corrective funding and approval authority, delivered at a frequency that allows intervention.

    Reliance on a service organisation report is not sufficient on its own. The report covers the provider's stated controls over a stated period, and the firm must still evidence its own oversight of the arrangement.

    Contractual arrangements should therefore specify data access, retention, reproducibility and exit rights, because an oversight officer who cannot obtain the underlying records cannot discharge the function.

    Frequently asked questions

    What does the CASS oversight function cover?

    Oversight of the firm's operational compliance with the client assets regime, including the adequacy of systems, controls and records, allocated to a named director or senior manager under CASS 1A.3.1R or CASS 15.2.4R. Neither rule creates a prescribed FCA controlled function, and not every firm carrying the allocation sits within the senior managers and certification regime. A full map of which CASS chapters apply to which firm type is at What is CASS? The FCA Client Assets Sourcebook Explained.

    Is a late reconciliation a breach?

    Yes. The obligation is to reconcile at the required frequency and correct discrepancies without delay. A correct reconciliation performed after its window has closed is a breach of the timing requirement even where no shortfall existed.

    What should be reported to the board?

    Unexplained residual variance and its trend, detection and correction latency, reconciliation timeliness against obligations, and the ageing profile of open exceptions by category, each traceable to the underlying reconciliation run.

    How can an oversight officer avoid alert fatigue?

    Calibrate thresholds to the firm's real variance profile, tier escalation by value, age and category, assign each tier to a named role with a response time, and measure whether those response times are met.

    Back to Resources

    The system of record for client funds and reserves