In short
PS25/12 turns the safeguarding duty for electronic money institutions from a periodic finance task into a daily operating obligation. An electronic money institution must reconcile relevant funds internally and externally each business day, correct any shortfall or excess from its own resources, keep records that distinguish relevant funds at all times, submit a monthly safeguarding return, maintain a current resolution pack and pass an annual safeguarding audit.
What PS25/12 changed for electronic money institutions
The safeguarding duty for electronic money institutions under the Electronic Money Regulations 2011, and how PS25/12 has raised the evidential standard applied to it, is covered in full at PS25/12 and CASS 15: The FCA Safeguarding Requirements Explained. This article assumes that context and focuses specifically on how an EMI runs the obligation day to day: reconciling e-money float, distributor and programme manager balances, and redemption liabilities against the outstanding e-money issued.
For most EMIs, the practical effect is that safeguarding has moved out of the monthly finance close and into daily operations. A control that runs monthly cannot evidence a daily obligation retrospectively. An auditor testing a given business day is entitled to see the reconciliation that was performed on that day, the variance it identified, the decision taken and the individual who took it.
The second effect is on scope. An EMI rarely holds relevant funds in one place. Funds sit with safeguarding institutions, with acquirers pending settlement, with card scheme sponsors, with distributors and programme managers issuing e-money on the institution's behalf, and in some structures with insurers under a comparable guarantee. Each of those relationships is a reconciliation surface, and each must be included in the daily internal and external reconciliation rather than reviewed on an ad hoc basis. Unclaimed and pending redemption liabilities are part of the same surface: e-money that a holder has asked to redeem remains a relevant funds liability until the redemption payment has actually settled, and treating it as discharged the moment a redemption instruction is logged is a common source of quiet under-segregation. The distributor, programme manager and redemption-liability detail specific to e-money balances is set out at EMI Safeguarding: What Electronic Money Institutions Must Do.
The third effect is on accountability. Under the Senior Managers and Certification Regime, a named senior manager carries personal responsibility for the adequacy of safeguarding arrangements. Personal accountability for a daily obligation is very difficult to discharge on the basis of a management pack delivered several weeks in arrears.
The daily obligations an EMI has to discharge
The internal reconciliation compares the institution's own records of relevant funds received and held against its e-money issued and outstanding. It answers a single question: does the firm's ledger say it owes the amount it believes it owes to e-money holders, and does its record of segregated funds match that liability.
The external reconciliation compares those internal records against the balances confirmed by every safeguarding institution and every third party holding relevant funds. It is a distinct obligation with a distinct failure mode. An internal reconciliation can balance perfectly while a safeguarding account is short, because the internal record and the external reality have diverged.
Where either reconciliation identifies a shortfall, the institution must correct it, funding the difference from its own resources. Where it identifies an excess, the excess must be withdrawn so that own funds are not commingled with relevant funds. The obligation is not to observe the variance. It is to correct it, promptly, and to evidence both the decision and its execution.
Underpinning all of this is the records and accounts obligation. At any moment, the institution must be able to distinguish relevant funds held for each e-money holder from every other sum in its possession. That is the requirement a resolution pack exists to satisfy in an insolvency, and it is the requirement that fails first when reconciliation drifts.
Where manual safeguarding processes break down
The first failure is temporal. A reconciliation workbook records a conclusion, not a process. When an auditor asks what the safeguarding position was on a specific historic date, who reviewed it, what variance existed and how it was cleared, a workbook usually requires a reconstruction, and the reconstruction itself becomes a finding.
The second failure is coverage. A workbook reconciles the accounts someone remembered to include. When a new acquirer, corridor or distributor is added, the safeguarding surface widens before the workbook does. A source that has silently stopped reporting is invisible in a manual process, because nothing raises an exception for data that never arrived.
The third failure is correction. Manual processes routinely capture identification and lose remediation. The variance is noted in a tab, an email requests a transfer, the transfer is made, and no single record ties the three together with timestamps and named individuals. That is precisely the sequence a safeguarding audit is designed to test.
The fourth failure is volume. An EMI processing high transaction volumes across multiple currencies and settlement cycles will generate a residual break population that grows with the business. Adding analysts to that population is a linear response to an exponential problem, and it degrades quality because investigation time per break falls as volume rises.
Continuous reconciliation instead of a nightly batch
Safeheld reconciles continuously rather than on an overnight cycle. Source data is ingested as it arrives, in the formats the institution already receives, with automated schema mapping handling statement layouts, acquirer settlement files, ledger extracts and scheme reports without a bespoke integration project for each counterparty.
Internal and external reconciliations are executed and evidenced as separate processes, because the FCA treats them as separate obligations and an auditor will test them separately. Collapsing both into a single match run produces a result that cannot be decomposed when challenged.
Multi-account and three-way reconciliation matters more for EMIs than for most regulated firms, because the relationship between e-money issued, ledger position and safeguarding balance involves at least three independent records. A two-way match between ledger and bank will not detect a divergence between issuance and ledger.
Continuous operation also changes the detection window. A daily batch means that a shortfall arising at nine in the morning is discovered the following day at the earliest. Continuous reconciliation collapses that window to the interval between data arriving and the match running.
Autonomous investigation of the residual break population
Automated matching is not the differentiator. Every serious platform clears the bulk of the population. The cost sits in the residual, the breaks that require a person to look at surrounding records, form a view and document it.
Safeheld investigates each break before a human sees it. The platform assembles the supporting records, forms an explanation, attaches its reasoning to the break and routes onward only those items where confidence is insufficient for automatic resolution. The reasoning is retained against the item, so a reviewer sees why a conclusion was reached rather than being asked to trust it.
This matters for evidence as much as for efficiency. A break resolved without a recorded rationale is an unevidenced control action. Under the annual safeguarding audit, the quality of the reasoning attached to resolved exceptions is testable in a way that a cleared status flag is not.
The operational effect is that compliance teams spend their time on judgement and escalation rather than on matching and chasing. That is the only sustainable way for a safeguarding function to scale with transaction volume without proportional headcount growth.
Breach detection, escalation and notification triggers
Detection without escalation is a dashboard. Safeheld routes every detected variance into a six-level escalation ladder, where each level has its own trigger condition, recipients, delivery channels and clock. Nothing waits for a person to notice a red cell in a report.
The lower levels handle coverage drift, where the safeguarded position falls below its internal buffer without a confirmed shortfall. The middle levels handle confirmed shortfalls and prepare the notification artefacts. The upper levels handle material breaches, unresolved positions at the following business day and systemic failures that engage board oversight and wind-down considerations.
Inside that ladder, Safeheld uses its own internal labels, NT-1 to NT-4, for four notification stages. These are Safeheld's operating methodology, not FCA terminology and not a regulatory classification: NT-1 is an internal notification to the accountable owner, NT-2 is notification to the oversight holder, NT-3 is preparation of an external notification artefact for the firm to consider, and NT-4 is board notification. The firm decides what it is required to report and when. The value of encoding the stages is that the artefact is prepared from reconciliation data at the moment the trigger fires, rather than drafted from memory once someone has decided a notification is required.
Speed of response is itself an evidential matter. A firm that identifies a shortfall within minutes, corrects it within the hour and can demonstrate both is in a materially different supervisory position from a firm that identifies the same shortfall three days later.
Monthly returns, resolution packs and audit evidence
The monthly safeguarding return should be an output of the reconciliation process, not a separate assembly exercise. Where the return is compiled independently of the daily reconciliations, the two records can diverge, and a return that cannot be traced back to underlying reconciliations invites challenge.
The resolution pack is subject to the same logic and fails in the same way. A pack that is refreshed when someone remembers to refresh it is out of date by definition, and a resolution pack that does not reflect current arrangements is a breach in its own right. Generating it continuously from live data removes the refresh decision entirely.
For the annual safeguarding audit, the practical test is whether the institution can export a complete evidence set for an arbitrary date range without vendor assistance. Auditors do not accept curated samples, and an evidence request that requires engineering effort signals that the underlying records are not organised around the obligation.
Safeheld generates the return, the resolution pack and the audit evidence set from the same sealed reconciliation runs that produced the daily positions. There is one safeguarding record and every downstream artefact traces back to it.
Sealed runs and independently verifiable evidence
Every reconciliation run in Safeheld is sealed with a SHA-256 Merkle root. The seal fixes the inputs, the matching logic applied, the outcome and the reviewer, and any subsequent alteration to the sealed content changes the root and is therefore detectable.
The seal can be verified independently, without a login to the institution's tenant and without the institution's cooperation. That is the distinction between asserting that a control operated and proving it. An auditor comparing a produced record against a published root is not relying on the firm's representation.
This is increasingly the direction of supervisory expectation. Regulators and auditors are less interested in whether a firm says a reconciliation happened and more interested in whether the record relied upon today is demonstrably the record produced at the time.
For an EMI, the practical benefit is a shorter audit. Where evidence is complete, structured and tamper evident, the audit becomes a verification exercise rather than an evidence-gathering exercise, and the internal cost of the audit falls accordingly.
What implementation looks like in practice
Implementation starts with the safeguarding surface rather than the software. The institution enumerates every place relevant funds can sit, every source that reports on those places and the frequency and format of each report. Firms are frequently surprised by the length of that list, and the exercise has value independently of the platform.
Data connection follows. Because ingestion is format agnostic and schema mapping is automated, connection is generally a matter of pointing the platform at existing files and feeds rather than commissioning transformation work for each source.
Reconciliation logic is then defined for internal and external cycles, with the multi-account and three-way relationships mapped explicitly. Parallel running against the existing workbook for a period gives the compliance function comfort that the platform reproduces known results before it becomes the control of record.
The final stage is governance. Escalation recipients, notification triggers, review responsibilities and board reporting cadence are configured so that the ladder reflects the institution's actual accountability map rather than a generic default.
Frequently asked questions
How often must an EMI reconcile relevant funds under PS25/12?
The regime requires internal and external reconciliation each business day. The internal reconciliation compares the institution's own records of relevant funds against its outstanding e-money liability. The external reconciliation compares those internal records against balances confirmed by safeguarding institutions and other third parties holding relevant funds. Both must be evidenced separately, because an auditor will test them as distinct obligations rather than as a single control.
What must an EMI do when a safeguarding shortfall is identified?
The institution must correct the shortfall from its own resources, promptly, and evidence both the decision and its execution. Identification alone does not discharge the obligation. The evidential trail should tie the variance, the funding decision, the transfer and the confirmation together with timestamps and named individuals, because manual processes commonly record the identification and lose the remediation.
Does PS25/12 replace the Electronic Money Regulations 2011?
No. The Electronic Money Regulations 2011 remain the source of the underlying safeguarding duty for electronic money institutions. PS25/12 raises the operational and evidential standard applied to that duty, specifying reconciliation frequency, treatment of shortfalls and excesses, records and accounts, resolution pack content, the monthly return and the annual safeguarding audit.
What is a resolution pack and how current does it have to be?
A resolution pack is the set of records that allows an insolvency practitioner or the regulator to identify and return relevant funds without reconstructing the institution's books. It must reflect current arrangements at all times. A pack refreshed periodically is out of date between refreshes, which is why generating it continuously from live reconciliation data is materially safer than maintaining it as a document.
Can an EMI use the same platform for safeguarding and financial reconciliation?
It can, provided the safeguarding cycles are executed and evidenced as regulatory controls rather than as finance processes. The distinction matters at audit. Safeguarding reconciliation must separate internal from external cycles, evidence correction of shortfalls and excesses, and produce records that tie to the monthly return and the resolution pack.
How does cryptographic sealing help at a safeguarding audit?
A sealed run fixes the inputs, the logic applied, the outcome and the reviewer under a SHA-256 Merkle root. Because the root can be verified independently, an auditor can confirm that the record produced today is the record produced at the time, without relying on the institution's assurance. That converts evidence gathering into evidence verification and shortens the audit.