PI/EMI

    How Safeheld Helps BaaS Providers Manage Safeguarding Risk Across Their Client Base

    How Banking-as-a-Service providers are using Safeheld to monitor safeguarding compliance across their portfolio of EMI and PI clients in real time.

    10 min read March 2026

    In short

    A banking as a service provider holds regulatory responsibility for funds flowing through every embedded programme it operates. That requires reconciliation and evidence at programme level as well as in aggregate, because supervisory questions and client money entitlements are asked per programme, not across the platform as a whole.

    Why the BaaS structure concentrates safeguarding risk

    In an embedded finance structure, the regulated entity sits behind a set of distribution partners who own the end customer relationship. Funds belonging to end customers flow through the regulated entity's accounts, but the records that identify those customers frequently originate with the partner.

    That separation creates a specific exposure. The regulated entity carries the safeguarding or client money obligation, but depends on partner systems for the data required to discharge it. If a partner's ledger is wrong, the regulated entity is in breach even though the error was not made in its own systems.

    The exposure compounds with programme count. Each new partner adds a data source, a settlement pattern, an operating rhythm and a set of edge cases. A provider running twenty programmes is running twenty reconciliation problems that share a balance sheet.

    Aggregate reconciliation hides this. A platform-wide position can reconcile perfectly while two programmes are individually wrong in offsetting directions, which is the failure mode most likely to survive undetected until a partner exits.

    Reconciliation at programme level, not only in aggregate

    The correct unit of reconciliation is the programme. Each programme has its own end customer liability, its own settlement flows and, in most structures, its own designated account or sub-ledger position within a pooled account.

    Safeheld reconciles at programme level and rolls up, so that the aggregate position is a sum of individually evidenced positions rather than a single match performed at the top. Offsetting errors between programmes are surfaced because each programme is proved independently.

    Where funds are pooled, the sub-ledger becomes the entitlement record and its integrity is the control that matters. Reconciling a pooled account against a sub-ledger, and the sub-ledger against partner records, is a three-way relationship rather than a two-way one.

    This is also what makes programme exits manageable. A partner leaving with a clean, evidenced programme position is an operational event. A partner leaving from an aggregate position is a reconstruction project.

    Ingesting partner data without a project per partner

    Partner data quality is uneven by nature. Distribution partners are frequently technology businesses rather than financial institutions, and their reporting reflects that. Formats change, files arrive late, and definitions differ between partners for the same concept.

    Requiring every partner to conform to a single specification before onboarding is commercially unrealistic and delays revenue. Building a bespoke integration per partner is operationally unsustainable once programme count grows.

    Format-agnostic ingestion with automated schema mapping resolves this by taking the data as the partner produces it and mapping it on arrival. A new programme becomes a configuration exercise measured in days rather than an engineering project measured in quarters.

    Missing data must be treated as an exception. A partner file that fails to arrive should raise an alert against that programme rather than allowing the programme to reconcile against an incomplete population.

    Supervising programmes you do not operate

    Regulatory expectation is that the regulated entity supervises its distribution partners rather than relying on them. Supervision means monitoring behaviour continuously and acting on deviation, not collecting annual attestations.

    Continuous programme level reconciliation is the most direct form of that supervision, because it observes the partner's actual behaviour through the data rather than through its self-description. A partner whose reconciliation quality is deteriorating is visible in the break profile before it becomes a formal issue.

    Escalation should be programme aware. A variance in one programme routes to the relationship owner for that programme as well as to central compliance, with the six-level ladder applying the same trigger discipline used elsewhere.

    Board and sponsor reporting then presents the estate as a portfolio, with each programme's control status evidenced rather than summarised.

    Scaling programme count without scaling headcount

    The economics of banking as a service depend on marginal programme cost. If each additional programme adds reconciliation analysts, the model stops working before it reaches scale.

    Autonomous break investigation is what breaks that linkage. Each break is investigated before a person sees it, with supporting records gathered, an explanation formed and the reasoning retained. Only low-confidence items reach a reviewer.

    The compliance function then supervises a portfolio rather than processing exceptions, and programme count grows without a proportional increase in operational staff.

    The evidential quality also improves, because a documented rationale is attached to every resolved exception rather than depending on an analyst's recollection during an audit six months later.

    Frequently asked questions

    Why is aggregate reconciliation insufficient for a BaaS provider?

    An aggregate position can reconcile perfectly while individual programmes are wrong in offsetting directions. Because end customer entitlement, supervisory questions and partner exits all operate at programme level, reconciliation must prove each programme independently and roll up, rather than proving only the total.

    Who is responsible when a distribution partner's ledger is wrong?

    The regulated entity. Regulatory responsibility for funds flowing through the structure sits with the licensed firm, regardless of where the error originated. That is why partner data must be reconciled continuously against independent records rather than accepted, and why deteriorating partner data quality should be treated as a supervisory signal.

    How should pooled accounts be reconciled in an embedded structure?

    The sub-ledger is the entitlement record, so the control is three-way: pooled account against sub-ledger, and sub-ledger against partner records. A two-way match between the pooled account and the sub-ledger proves internal consistency only, and will not detect a divergence between the sub-ledger and what the partner's own records say is owed.

    What do sponsor banks typically ask for?

    Programme specific evidence, on short deadlines. Reconciliation history, variance investigations, correction records and governance documentation for a named programme and date range. Providers that can produce a complete sealed set within hours protect the relationship. Those requiring a week of assembly invite closer scrutiny.

    How does a provider add programmes without adding analysts?

    By removing the linear relationship between break volume and headcount. Automated schema mapping removes the per partner integration project, and autonomous break investigation removes the per break analyst task, with reasoning retained for audit. The compliance function then supervises a portfolio rather than processing exceptions.

    Back to Resources

    The system of record for client funds and reserves