PS25

    Payment Institution Safeguarding: Obligations, Reconciliation and Evidence

    What safeguarding requires of a UK payment institution: relevant funds, D+1 segregation, daily reconciliation, resolution packs, returns and audit.

    10 min read March 2026

    In short

    Safeguarding requires a UK payment institution to identify relevant funds from the moment of receipt and either segregate them by the close of the business day following receipt or cover them under an insurance or comparable guarantee arrangement. It must reconcile relevant funds internally and externally under CASS 15, correcting any shortfall or excess promptly, and keep records that distinguish each payment service user's funds from another's and from the firm's own money at all times. It must also maintain a current CASS 10A resolution pack, submit the monthly safeguarding return under SUP 16.14A (REP027 in RegData, due within 15 business days of month end on the form at SUP 16 Annex 29BR), and pass the SUP 3A annual external safeguarding audit.

    The safeguarding obligations a payment institution actually carries

    Relevant funds are the sums a payment institution receives from, or for the benefit of, a payment service user in order to execute a payment transaction. The obligation to safeguard attaches from the moment those funds are received, not from the moment they are identified or booked, which means a delay in labelling a receipt correctly does not delay the safeguarding clock. A firm that only decides two days after receipt which portion of an inbound file was relevant funds has already missed the point at which the duty began, even if segregation itself is still within the deadline.

    Most receipts are not pure. A single inbound settlement file from an acquirer or a scheme typically bundles relevant funds owed to merchants or payment service users together with the institution's own merchant service charges, interchange, scheme fees and chargeback recoveries. That gross figure has to be decomposed before segregation can happen at all. The decomposition rule, whatever percentage, fee schedule or transaction-level logic drives it, is itself a control: if the split has not been revisited since the last pricing change, the firm can under-segregate for months while its ledger and its safeguarding account continue to agree with each other, because both are wrong in the same direction.

    Agent and distributor float sits inside the same perimeter. Money collected by an agent on the institution's behalf, or held by a distributor pending onward transfer, remains relevant funds for as long as it is held for a payment service user, and it must be reconciled externally in the same way as a bank-held balance. In practice this is where safeguarding surfaces are weakest, because the quality of the data depends on the agent's own record-keeping rather than the principal's, and a firm that treats a missing agent report as a data gap rather than an exception is quietly excluding a real balance from its reconciliation.

    Money in transit is the same problem in a different guise. Funds pending settlement with an acquirer, held across a card scheme's clearing cycle, or sitting with a correspondent bank in a corridor where the institution has no direct membership, do not stop being relevant funds because the institution cannot currently move them. They have to be included in both segregation and reconciliation, valued as at the reporting date, even though the firm's control over them is indirect.

    Fee deduction timing is a recurring source of finding. Where a firm nets its own fee off a gross settlement before segregating the balance, the deduction has to be evidenced: the amount, the basis for it and the date it was taken. An unevidenced deduction from funds otherwise held for a payment service user is not distinguishable, on the record, from an unexplained outflow of client money, and an auditor will treat it that way regardless of whether the deduction was in fact legitimate.

    The segregation deadline itself is unforgiving of the calendar. Funds must reach a safeguarding account, or be covered by an equivalent insurance or comparable guarantee, by the close of the business day following the day of receipt. Receipts that land late on a Friday, over a bank holiday weekend, or after a bank's own cut-off for same-day transfers, compress the working window rather than extending the deadline, and a firm that has not mapped its cut-off times against its settlement calendar will discover the gap only when it has already missed it.

    The reconciliation requirements that CASS 15 imposes on top of segregation, and how the internal and external cycles interact, are covered in depth at CASS 15 Safeguarding Reconciliation: Daily Requirements and Evidence. The regime itself, including how PS25/12 changed the evidential standard, is set out at PS25/12 and CASS 15: The FCA Safeguarding Requirements Explained, and the equivalent obligations for e-money balances specifically are addressed at EMI Safeguarding: What Electronic Money Institutions Must Do.

    The payment institution safeguarding obligation in operational terms

    The safeguarding duty for authorised payment institutions under the Payment Services Regulations 2017, and how PS25/12 has raised the operational and evidential standard applied to it, is covered in full at PS25/12 and CASS 15: The FCA Safeguarding Requirements Explained. This article assumes that context and focuses on how a payment institution runs the obligation specifically: decomposing mixed settlement receipts, reconciling agent and distributor float, and maintaining the three-way reconciliation the regime effectively demands.

    In practice the difficulty is timing and identification. Payment flows do not arrive labelled. A single inbound settlement from an acquirer can contain relevant funds, merchant service charges, chargeback recoveries and scheme fees. The institution must decompose that receipt, identify the relevant funds within it and segregate them within the prescribed timeframe.

    The segregation deadline is what makes this an operational rather than an accounting problem. Funds must be placed in a designated safeguarding account by the end of the business day following the day of receipt. An institution that identifies relevant funds correctly but two days late has still breached.

    Alongside segregation sits the reconciliation duty. Each business day the institution reconciles its internal records of relevant funds against its payment service user liability, and reconciles those internal records against the balances confirmed by each safeguarding institution and each third party in the flow.

    Mapping the reconciliation surface across acquirers, agents and schemes

    The reconciliation surface for a payment institution is wider than for most regulated firms because relevant funds pass through intermediaries the institution does not control. Acquirers hold settlement in transit. Card schemes hold funds across clearing cycles. Agents and distributors receive funds on the institution's behalf. Correspondent banks hold balances in corridors where the institution has no direct scheme membership.

    Each of those relationships reports differently. Settlement files vary by acquirer and change without notice. Scheme reports arrive on scheme timetables rather than the institution's. Agent reporting is frequently the weakest link, because the agent's operational maturity determines the quality of the data the institution depends on.

    The consequence is that the reconciliation cannot assume a complete data set. A robust process treats absent data as an exception in its own right. If an acquirer file that normally arrives daily has not arrived, that is a finding, not a quiet gap in the population.

    Mapping the surface completely is the single highest value exercise a payment institution can undertake before selecting any platform. Firms routinely discover accounts, corridors and intermediary relationships that were never included in the safeguarding reconciliation at all.

    Identifying relevant funds inside mixed settlement flows

    Identification is where safeguarding most often fails quietly. A gross settlement receipt must be split into the portion held for payment service users and the portion representing the institution's own revenue. Where that split is performed by a rule that has not been revisited since a pricing change, the institution can under-segregate for months without any reconciliation flagging it, because the internal record and the segregated balance agree with each other.

    This is why a three-way relationship matters. Reconciling the ledger against the safeguarding account proves internal consistency. Proving that the segregated amount is the correct amount requires a third reference, typically the underlying transaction population that generated the liability.

    A control designed around that third reference, matching ledger, safeguarding account and underlying transaction population together rather than as a single two-way check, is what closes this gap. No two-way match, however frequently it runs, can detect a divergence that both sides of the pair share.

    The same logic applies to excesses. Over-segregation is not a safe error. Holding own funds in a safeguarding account commingles the institution's money with relevant funds and undermines the segregation the account exists to provide.

    Continuous reconciliation and the detection window

    The interval between an event and its detection determines the cost of the event. A segregation failure detected the same morning is a transfer. The same failure detected at month end is a breach with a notification obligation, a remediation trail and a management explanation.

    Reconciling as data arrives, rather than waiting for a nightly batch, is what closes that window regardless of which tooling performs it. The practical constraint is usually ingestion, not logic: a new acquirer file or a changed statement layout should not force a manual rebuild before reconciliation can resume.

    Continuous operation also changes how coverage is monitored. Rather than reviewing a position once a day, tracking the safeguarded position against the liability throughout the day means drift toward a shortfall is visible before the shortfall crystallises.

    For institutions operating across time zones and settlement cycles, this removes the artificial constraint of a single daily cut-off that suits none of the underlying flows.

    Autonomous break investigation and the analyst workload

    Matching rates are a poor basis for platform selection because every credible platform matches the easy population. The meaningful comparison is what happens to the residual.

    What matters is what happens to items that do not match automatically: whether the surrounding records are assembled, an explanation formed and a rationale attached before a reviewer ever sees the item, or whether a reviewer starts from a blank list of unmatched rows each time.

    The retained reasoning is what makes a resolution defensible. An exception cleared without a recorded rationale is an unevidenced control action, and unevidenced control actions are exactly what a safeguarding audit isolates.

    The scaling consequence is significant for payment institutions specifically, because break volume tracks transaction volume. A process whose cost is linear in transactions caps the growth rate of the business at the growth rate of the compliance team.

    Escalation, notification and senior manager oversight

    Every detected variance enters a six-level escalation ladder with defined triggers, recipients, channels and timings. The lower levels address coverage drift. The middle levels address confirmed shortfalls and prepare notification artefacts. The upper levels address material breaches, positions unresolved at the following business day and systemic failures requiring board attention.

    The value of encoding notification stages into the ladder, rather than deciding case by case, is that the artefact needed at each stage can be prepared from reconciliation data the moment the trigger fires, removing the delay between deciding a notification is needed and being able to produce one. The reporting decision itself always remains the firm's.

    Under the Senior Managers and Certification Regime, the individual accountable for safeguarding needs evidence that oversight was exercised, not merely that reports existed. A ladder that records who was notified, through which channel and when, is that evidence.

    Board reporting is generated from the same data rather than assembled separately, which means the position described to the board is provably the position the control produced.

    How Safeheld automates this for payment institutions

    Safeheld reconciles continuously as data arrives, across the internal and external cycles and across the three-way relationship between ledger, safeguarding account and underlying transaction population, using format-agnostic ingestion so a new acquirer file or a changed statement layout does not require a rebuild before reconciliation can resume.

    Unmatched items are investigated autonomously: the platform assembles the surrounding records, forms an explanation and attaches its reasoning to the break, routing onward only those items where confidence is insufficient for automatic resolution, together with the evidence behind the proposed conclusion.

    Every detected variance is routed through a six-level escalation ladder with defined triggers, recipients, channels and timings, using Safeheld's own internal notification labels, NT-1 to NT-4, to prepare the artefact needed at each stage from reconciliation data as the trigger fires. These are Safeheld's operating labels, not FCA terminology, and the decision on what to report and when always remains the firm's.

    The monthly safeguarding return, the CASS 10A resolution pack and the SUP 3A audit evidence set are generated from the same sealed reconciliation runs that produced the daily positions, rather than assembled separately, so a return or a pack can always be traced back to the reconciliation that produced it. The resolution pack is maintained continuously rather than refreshed periodically, and the institution can export a complete evidence set for any date range without vendor involvement.

    Each run is sealed with a SHA-256 Merkle root that fixes the inputs, the matching logic, the outcome and the reviewer, and that can be verified independently of Safeheld and without the institution's cooperation, so an auditor can confirm that the record produced during fieldwork is the record produced at the time of the reconciliation.

    What payment institutions should test during selection

    Test ingestion with a real file the platform has not seen, in the format the counterparty actually sends, and measure the time to a working reconciliation. Demonstration data proves nothing about the institution's data.

    Test the residual. Take one month of breaks that the team investigated manually, remove the conclusions, and measure how many the platform resolves without human involvement, how many of those resolutions match the team's original conclusions and whether the reasoning is legible enough for a reviewer to sign off.

    Test evidence. Choose a historic date, request the full control cycle for it and ask how the institution would demonstrate to an auditor that the record has not been altered since.

    Test regime breadth. If the institution also operates under the Electronic Money Regulations 2011, PSD2 in EU corridors or CASS obligations elsewhere in the group, establish whether one platform carries all of them or whether each regime adds a system, a contract and a reconciliation of reconciliations.

    Frequently asked questions

    When must a payment institution segregate relevant funds?

    Relevant funds must be placed in a designated safeguarding account by the end of the business day following the day of receipt. Correct identification is not sufficient on its own. An institution that identifies relevant funds accurately but segregates them outside that window has breached, which is why identification inside mixed settlement receipts needs to be automated rather than performed as a periodic finance exercise.

    Why is a two-way reconciliation insufficient for payment institutions?

    Reconciling the ledger against the safeguarding account proves the two records agree. It does not prove the segregated amount is correct. If the rule that splits relevant funds from own revenue inside a gross settlement is wrong, the ledger and the bank will continue to agree while the institution under-segregates. A third reference, the underlying transaction population, is required to detect that.

    How should agent and distributor balances be treated?

    Funds held by agents and distributors on the institution's behalf form part of the safeguarding surface and must be included in the external reconciliation. Agent reporting is frequently the weakest data source in the chain, so the process should treat missing or late agent data as an exception rather than as an absence, otherwise the population reconciles cleanly while omitting a material balance.

    Is over-segregation a safe position?

    No. Holding own funds in a safeguarding account commingles the institution's money with relevant funds and weakens the segregation the account exists to provide. PS25/12 requires excesses to be withdrawn as well as shortfalls to be corrected, and an auditor will test excess withdrawal alongside shortfall funding.

    What should a payment institution test in a platform evaluation?

    Ingestion against a real unseen file in the counterparty's own format, the residual break population against conclusions the team reached manually, evidence retrieval for an arbitrary historic date without vendor assistance, and regime breadth across every framework the group operates under. Matching rate comparisons are the least informative test because every credible platform clears the straightforward population.

    How does continuous reconciliation reduce regulatory exposure?

    It compresses the detection window. A segregation failure found the same morning is corrected with a transfer. The same failure found at month end carries a notification obligation, a remediation trail and a management explanation. Supervisory outcomes are shaped as much by response time as by the underlying error, and response time is a function of when the error was detected.

    Back to Resources

    The system of record for client funds and reserves