PI/EMI

    How Safeheld Gives Safeguarding Banks Real-Time Visibility Over Client Portfolios

    How banks providing safeguarding accounts are using Safeheld to monitor EMI and PI compliance, manage risk scoring, and streamline acknowledgement letter processes.

    11 min read March 2026

    In short

    A bank sponsoring safeguarding accounts for payment institutions and EMIs carries its own obligations: correctly designated accounts, executed acknowledgement letters confirming no right of set-off, and oversight sufficient to know that the client's safeguarding arrangement remains sound between onboarding and any point of stress. CASS 15 sharpens what the bank needs to see about a client it does not directly supervise.

    The position a safeguarding bank occupies

    A bank providing safeguarding accounts to payment institutions and electronic money institutions is not a neutral custodian. It is a named component of the client's regulatory permission. If the account is not properly designated, if the acknowledgement letter is not in place, or if the bank asserts a right of set-off against the balance, the client's safeguarding arrangement fails and the bank sits inside that failure, not outside it.

    That exposure has grown as supervisory attention on safeguarding has intensified under the strengthened regime. Where a payment institution fails and relevant funds cannot be identified cleanly, the quality of the account documentation and the bank's balance reporting becomes part of the examination that follows.

    At the same time, a significant number of banks reduced or exited exposure to this segment over the past decade, generally for reasons concentrated in financial crime risk and the difficulty of supervising a client whose regulatory obligations the bank cannot directly observe. The result is a persistent supply shortage: demand from payment firms for safeguarding accounts consistently exceeds the supply of banks willing to provide them. Banks that can underwrite and monitor the segment with confidence rather than caution are able to serve clients that competitors decline.

    Onboarding and underwriting a safeguarding client

    Traditional onboarding for a payment firm relies on a due diligence questionnaire, policy documents and a discussion with the compliance function. All three describe intent at a point in time. None of them describe how the client's safeguarding controls actually behave once the account is live.

    A materially stronger basis for underwriting is the client's operational reconciliation record: whether daily internal and external reconciliations are performed, what variance profile they produce, how quickly shortfalls are corrected, and whether the resolution pack required under CASS 10A is current. Where the client operates on a platform that seals each reconciliation run cryptographically, the bank can verify these facts rather than accept them on trust, and verification does not require access to the client's own systems, because a sealed run can be checked independently against its published root.

    This shifts the underwriting conversation from a judgement about management quality, which is hard to defend to an internal risk committee, to an assessment of an observable control record, which is considerably easier to defend and to revisit.

    Account designation and acknowledgement letters

    Designation is the first control and the one most often found deficient. The account must be identifiable on the bank's own systems as a safeguarding account held for the benefit of the client's payment service users, not merely titled in a way that suggests it.

    The acknowledgement letter records the bank's confirmation that it holds the account as a safeguarding account, that it will not exercise any right of set-off, combination or security interest against the balance in respect of sums owed by the institution, and that it understands the funds are not the institution's own money. The operational failure mode is drift: letters are executed at onboarding and not revisited when the institution opens further accounts, changes entity structure, or migrates to a different product within the same bank. A safeguarding estate with three accounts and one acknowledgement letter is a documented breach waiting to be found.

    A correctly worded letter does not, by itself, stop an automated collections, sweep or overdraft process from touching a balance that is not flagged as safeguarding within the bank's own core systems. Designation has to be enforced operationally, in systems, not only in documents, so that no internal process can treat the balance as available to meet the institution's obligations to the bank.

    Portfolio-level monitoring and what the bank can and cannot see

    Annual review is the weakest point in most safeguarding portfolios. A client reviewed in January can deteriorate materially by March, and the bank typically will not know until the following review or until an incident forces the issue. Continuous monitoring reframes the portfolio as a live surface: whether reconciliations remain current, whether variance frequency is rising, whether correction times are lengthening, and whether documentation has been refreshed after a structural change.

    What the bank can properly see is its own side of the relationship: the balances it holds, the timing and completeness of its own confirmations, and, where the client permits it, independently verifiable confirmation that the client's reconciliation runs occurred, on which dates, with which outcome. What the bank cannot and should not see is the client's underlying customer-level entitlement data or its internal ledgers; verification of a sealed reconciliation run does not require access to the client's tenant, and it should not require it. That distinction matters commercially as well as legally, because a client that has to expose privileged operational detail to its bank in order to demonstrate control is being asked for more than the relationship requires.

    The institution's external reconciliation also depends entirely on the balance data the bank supplies. Late, incomplete or badly formatted confirmations create a control gap the client cannot close by itself, however good its own systems are, which makes confirmation quality a service characteristic for the bank rather than an administrative detail.

    Where CASS 15 changes the bank's counterparty picture

    Before the supplementary safeguarding regime, a bank's comfort with a payment institution or EMI client rested largely on the client's own attestations about controls the bank could not observe. CASS 15, together with CASS 10A, SUP 16.14A and SUP 3A, gives the client a defined set of obligations, a monthly regulatory return, a maintained resolution pack, and an annual external audit report, each of which produces evidence the bank can reasonably ask to see confirmation of, without needing the underlying detail.

    This changes the counterparty picture in a specific way: a client that can point to a current SUP 3A audit report with no material findings, and to sealed reconciliation runs the bank can verify independently, is a materially different credit and operational proposition from a client asserting the same facts unsupported. Banks that build this into their monitoring cadence are pricing and managing the relationship on evidence that did not previously exist as a routine artefact.

    It also sharpens the bank's own resolution planning. If the institution fails, the bank will be asked to confirm balances at a precise moment and support identification of beneficial entitlement. Where the client's records are sealed and timestamped, the historic position is fixed and the bank's involvement shrinks to confirmation; where they are not, the bank inherits a reconstruction problem it did not create, on a timetable it does not control.

    How Safeheld supports the bank side of the relationship

    Safeheld ingests bank data in the formats banks already produce, with automated schema mapping, so the bank is not required to build bespoke reporting for each safeguarding client. Where a normally daily confirmation feed does not arrive, the absence is raised as an exception rather than passing unnoticed, protecting both parties to the relationship.

    Because each reconciliation run the client performs is sealed with a SHA-256 Merkle root, a bank can confirm that a reconciliation occurred on a given date with a given outcome without a login to the client's tenant and without receiving privileged operational detail. A register tracking each safeguarding account against its designation status, its executed acknowledgement letter and its last confirmation date turns the documentation estate from an annual hunt into a monitored control with a visible exception queue.

    Frequently asked questions

    What does an acknowledgement letter commit a safeguarding bank to?

    It records that the bank holds the account as a safeguarding account for the benefit of the institution's payment service users, that it will not exercise any right of set-off, combination or security interest over the balance for the institution's own obligations, and that it understands the funds are not the institution's money. It should be re-executed whenever accounts or entity structure change.

    Can a bank verify a client's reconciliation without seeing its underlying systems?

    Yes, where the client's reconciliation runs are sealed with a SHA-256 Merkle root and the root is independently verifiable. The bank can confirm a reconciliation occurred on a given date with a given outcome without a login to the client's tenant and without receiving customer-level entitlement data.

    What is the most common documentation failure banks find in a safeguarding portfolio?

    Drift between the account estate and the letter estate. Letters are executed at onboarding and not revisited when the institution opens further accounts, changes legal entity or migrates products, leaving accounts that are undocumented in practice even though the relationship began correctly.

    Has CASS 15 changed what a bank should ask a safeguarding client for?

    It has given the client a defined set of obligations to point to: the monthly SUP 16.14A return, a CASS 10A resolution pack, and an annual SUP 3A audit report. A bank can reasonably ask for confirmation that these exist and are current, without needing the underlying customer-level detail behind them.

    Back to Resources

    The system of record for client funds and reserves