In short
FCA action on client money and safeguarding follows a consistent pattern. Cases are rarely about a single incorrect calculation. They concern firms that could not identify client funds reliably, reconciled infrequently or late, failed to evidence corrective action, and lacked governance able to challenge the numbers. Supervisory intervention also frequently precedes enforcement through requirements imposed on the firm's permissions.
The recurring pattern across cases
Four themes recur. The first is records and accounts: the firm could not demonstrate, at a given date, which funds were client funds and which were its own, particularly where receipts were unallocated or held in mixed accounts.
The second is reconciliation: performed infrequently, performed late, performed against an incomplete population, or performed in a way that could not be reproduced afterwards.
The third is correction: discrepancies identified but not funded promptly, or funded without evidence of the transfer, its timing and its authorisation.
The fourth is governance: oversight that received summary reporting and did not test it, with no evidence of challenge, and no clear line of accountability to a named senior individual.
Supervisory intervention usually arrives before enforcement
Firms tend to focus on financial penalties, but the more common and more immediately damaging outcome is a supervisory requirement imposed on the firm's permissions.
Requirements can restrict the firm from taking on new clients, from holding client money above a stated level, or from certain activities until remediation is complete and independently verified. They take effect quickly and are visible on the public register.
The commercial consequences are immediate: banking partners review the relationship, institutional clients pause onboarding, and diligence in any funding or acquisition process becomes materially harder.
By the time a penalty is published, the operational and commercial damage has usually already been absorbed. Treating the supervisory stage as the real risk is the correct posture.
Skilled person reviews and what they test
Where the FCA has concerns about client money controls, a common step is a review by an independent skilled person commissioned under statutory powers and paid for by the firm.
Such reviews test the same things an auditor tests but with wider scope and less tolerance: population completeness, reconciliation methodology, the definition of protected funds, exception handling, corrective evidence and governance effectiveness.
Firms that rely on manual processes fare badly, not because the underlying position is necessarily wrong, but because they cannot evidence what the position was on the dates selected, and inability to evidence is itself the finding.
The cost is substantial and the management time is greater than the fee. A firm able to produce sealed, reproducible runs for any historic date reduces both.
Individual accountability is now explicit
Under the senior managers regime, responsibility for client assets and safeguarding is allocated to a named individual whose statement of responsibilities records it.
That individual is expected to have taken reasonable steps, which is assessed against what a reasonable person in the role would have done with the information available and the information they should have obtained.
Passive receipt of a summary pack is a weak position. Evidence of active oversight, including thresholds set, escalations received and acted upon, challenges raised and matters pursued to closure, is what supports a reasonable steps defence.
That evidence has to be contemporaneous. Reconstructing an oversight narrative after an issue emerges is not persuasive and is easy to identify from metadata.
The controls that answer each theme
Against records failures: relevant funds identified at the point of receipt rather than classified later, unallocated receipts treated as a monitored exception with an ageing limit, and entity and client attribution captured at ingestion.
Against reconciliation weakness: reconciliation across at least three independent records, timeliness measured as a compliance rate, and any source that stops reporting raised as an exception rather than dropped from the population.
Against unevidenced correction: a closed corrective loop in which detection, investigation, funding, approval and closure are recorded as a single chain with authority checks enforced at the point of approval.
Against governance gaps: escalation mapped to named roles with response times measured, board metrics traceable to source runs, and a breach register that reconciles to exception data rather than being maintained separately.
Demonstrating maturity before anyone asks
The firms that come through supervisory attention well are not the ones with no breaches. They are the ones whose breaches were self-identified, promptly corrected, properly escalated and fully evidenced.
Self-identification is a strong signal. It demonstrates a control environment that works, whereas a breach identified by an auditor or a supervisor demonstrates the opposite regardless of its size.
The practical test a firm should be able to pass at any time is to select a date at random, produce the safeguarding position as it stood, show the exceptions open on that date with owners and ages, show every correction with its funding evidence, and show who reviewed it.
A firm that can do this in minutes is in a fundamentally different position from one that needs a fortnight, and the difference is visible to a supervisor within the first meeting.
What credible remediation looks like
When an issue is identified, the response is judged as much as the issue. Credible remediation begins with scoping: establishing the full period affected and the complete population of clients and balances, rather than the instances first noticed.
It then addresses root cause rather than symptom. Correcting a shortfall without fixing the ingestion gap that caused it produces a recurrence, and a recurrence after remediation is treated far more seriously than the original event.
It includes independent validation. A remediation signed off only by the function that failed carries little weight, whereas one tested by internal audit or an external reviewer is evidence of seriousness.
And it is documented as it proceeds. A remediation plan with dated milestones, owners and evidence of completion is the artefact that closes a supervisory conversation.
Early warning indicators a firm can monitor itself
Several indicators reliably precede a client money problem. A rising population of unallocated receipts is the most common, because unallocated money is money the firm cannot attribute and therefore cannot protect correctly.
Deteriorating reconciliation timeliness is the second. Timeliness usually degrades before accuracy does, as the same team absorbs growing volume without additional capacity.
Ageing exceptions are the third. A stable break count with a lengthening age profile indicates that new items are being handled while old ones are being deferred, which is how a small difference becomes a material one.
The fourth is data supply instability: increasing frequency of late or malformed counterparty files. Each of these can be monitored continuously and reported to governance long before any breach occurs.
Frequently asked questions
What causes most client money enforcement?
Not arithmetic error. The recurring causes are inadequate records distinguishing client funds from firm funds, infrequent or late reconciliation, corrections that were not evidenced, and governance that received reporting without testing it.
Is a supervisory requirement worse than a fine?
Often, commercially. Requirements restricting new clients or client money levels take effect quickly and appear on the public register, affecting banking relationships, client onboarding and diligence long before any penalty is published.
What does a reasonable steps defence require?
Contemporaneous evidence of active oversight: thresholds set, escalations received and acted upon, challenges raised and pursued to closure. Narratives assembled after an issue emerges carry little weight.
Does self-identifying a breach help?
Yes. A breach that the firm found, corrected, escalated and evidenced demonstrates a working control environment. A breach found by an auditor or supervisor demonstrates the opposite, irrespective of its value.