Frameworks

    PS25 and PSD3 Convergence: What UK Firms Should Prepare For

    How the simultaneous evolution of UK (PS25) and EU (PSD3) safeguarding frameworks is creating convergence pressure: and what dual-regulated firms need to know.

    10 min read March 2026

    In short

    The UK safeguarding regime under PS25/12 and CASS 15 and the EU package replacing PSD2 with PSD3 and a directly applicable Payment Services Regulation are moving in the same direction: tighter segregation, stronger records, more frequent verification and more explicit accountability. For dual-authorised firms the practical task is to run one operating model that satisfies the stricter requirement at each point and evidences each regime separately.

    Both regimes are tightening the same joints

    The UK reforms respond to a consistent supervisory finding: firms could not demonstrate, at short notice, what was owed to clients and what was held. The remedies are operational rather than conceptual, covering records and accounts, reconciliation, prompt correction, a maintained resolution pack, a monthly return and an annual audit.

    The EU package pursues the same outcome through different drafting, moving substantial parts of the framework into a directly applicable regulation to reduce national divergence, and tightening safeguarding and prudential expectations for payment and e-money institutions.

    For a firm operating in both, the strategic point is that neither regime is relaxing and both are increasing the frequency and evidential quality of verification.

    Status matters here more than direction. The UK supplementary safeguarding regime is law: CASS 15, CASS 10A, SUP 16.14A and SUP 3A came into force on 7 May 2026, with the FCA's end-state proposals still outstanding. The EU package is not yet law. PSD3 and the Payment Services Regulation (Commission proposals COM(2023) 367 and COM(2023) 366) reached provisional political agreement between the European Parliament and the Council on 27 November 2025 and, as at August 2026, have not been formally adopted or published in the Official Journal. Entry into force, application and national transposition dates are all calculated from Official Journal publication and cannot be stated until it happens.

    The practical implication is that a UK firm should be building to the UK rules now and designing for the EU package rather than dating it. Firms should track status through the FCA and EUR-Lex directly, because commentary consistently reports provisional agreement as settled law. Background on the UK rules referenced throughout this article, PS25/12 and CASS 15, is at PS25/12 and CASS 15: The FCA Safeguarding Requirements Explained, and the EU baseline being replaced, PSD2 safeguarding under Article 10, is set out at PSD2 Safeguarding: What the Rules Require in the EU and the UK.

    Where the two regimes align in practice

    Both require client funds to be identifiable and separated from the firm's own money, held with an appropriate institution or invested in permitted secure liquid assets, and recorded so that each client's entitlement can be determined.

    Both require reconciliation between the firm's internal records and the balances confirmed by the institutions holding the funds, and prompt correction of differences.

    Both attach personal accountability to the individuals responsible, and both expect governance to demonstrate active oversight rather than passive receipt of reports.

    This alignment is the reason a single operating layer is viable. The underlying evidence, that the position is corroborated across independent records and that differences were corrected and evidenced, satisfies both regimes even where the reporting artefacts differ.

    Where divergence creates real operational cost

    Divergence is concentrated in four areas. Definitions of protected funds and the treatment of edge categories such as unallocated receipts, agent and distributor float and card scheme balances are not identical across the regimes.

    Reporting artefacts diverge sharply. The UK monthly safeguarding return and the annual safeguarding audit have no exact EU equivalent, while national competent authorities operate their own returns and templates.

    Assurance expectations diverge. The UK audit against a specified assurance standard is a distinctive feature that shapes how evidence must be retained.

    Permitted holding arrangements diverge, including the range of institutions and instruments in which safeguarded funds may be held, which affects treasury policy as well as reconciliation design.

    One operating model, two evidential outputs

    The workable architecture separates the calculation layer from the reporting layer. The calculation layer ingests all sources, reconciles across independent records and maintains one authoritative position per entity, currency and account.

    Regime-specific logic is applied as a configuration over that layer: which funds are in scope under which definition, which frequency applies, which thresholds trigger escalation and which artefacts are produced.

    This avoids the failure mode of running two parallel reconciliations. Two reconciliations over the same money will diverge, and a supervisor who identifies a difference between the UK and EU view of the same balance will treat it as a records failure in both jurisdictions.

    The consistency requirement runs the other way too. The monthly return, the board pack and the audit sample must all descend from the same sealed run, so that any figure can be traced to the same source in either regime.

    Entity structure, intragroup flows and the hardest reconciliations

    Most dual-authorised groups run a UK authorised entity and an EU authorised entity, frequently with shared technology, shared operations staff and a shared ledger platform.

    The hardest reconciliations are intragroup: a payment received by one entity for a client of the other, shared acquiring arrangements, and central treasury operations that touch balances belonging to both.

    Each of these must be attributable to a single regulated entity at every moment, because both regimes are entity-level obligations. A group-level view that nets across entities is not evidence of compliance for either.

    Practical control requires entity tagging at the point of ingestion rather than allocation at the point of reporting, since allocation applied later cannot be evidenced as contemporaneous.

    What to do now, ahead of the EU timetable

    Complete the UK work first. It is in force and audited, and the controls it requires are a superset of most of what the EU changes will demand operationally.

    Map protected funds definitions side by side and identify every category treated differently. Those categories are where a single ledger will produce two legitimate answers, and they must be modelled explicitly rather than reconciled by hand.

    Confirm entity attribution across every source, including acquirers and distributors that report at group level, and obtain entity-identified reporting where it is missing.

    Build the reporting layer as configuration rather than code, so that a new national template or a changed frequency is a configuration change rather than a project. Firms that hard-code the current UK return will pay for it twice.

    Data architecture that survives both regimes

    The durable design holds one transaction record with regime-relevant attributes attached, rather than separate records per regime. Attributes include the authorised entity, the client, the currency, the fund classification under each applicable definition and the safeguarding account.

    Classification should be applied at ingestion and versioned. Where a definition changes, historic records retain the classification that applied at the time and gain the new one prospectively, so both periods remain explicable.

    Reporting then becomes a query over that record set rather than a transformation of exported figures, which is what allows two regimes to be served without two reconciliations.

    The test of the design is whether adding a third jurisdiction requires new configuration or new engineering. If it requires engineering, the regime logic has leaked into the calculation layer.

    Governance across two regulators

    Dual-authorised groups frequently run a single compliance committee covering both entities. That is workable provided the record distinguishes decisions taken for each entity, because each regulator will read the minutes as evidence about its own firm.

    Escalation thresholds should be set per entity and per regime, since a value that is immaterial in one entity may be significant in the other. A group threshold applied uniformly will under-escalate in the smaller entity.

    Senior accountability differs in form between the regimes but converges in substance: a named individual is expected to have understood the position and acted on it, evidenced contemporaneously.

    Where a matter affects both entities, the record should show that each entity's governance considered it separately rather than inheriting a group conclusion.

    Frequently asked questions

    Will PSD3 apply to UK firms?

    Not directly, and not yet at all. PSD3 and the Payment Services Regulation reached provisional political agreement on 27 November 2025 and have not been adopted or published in the Official Journal as at August 2026. UK authorised entities are governed by the UK regime under PS25/12 and CASS 15. A group with an EU authorised entity will be subject to the EU package through that entity, which is why dual-authorised groups need one operating model with two evidential outputs.

    Should a group run two reconciliations?

    No. Two reconciliations over the same underlying money will diverge, and a divergence between jurisdictional views of the same balance is a records failure in both. Run one calculation layer with regime-specific configuration above it.

    What is the biggest source of divergence cost?

    Definitional differences in what counts as protected funds, particularly for unallocated receipts, agent and distributor float and scheme balances, because they cause the same ledger to produce two legitimate answers that must both be evidenced.

    What should firms do first?

    Complete the UK safeguarding work, since it is in force and independently audited, then map definitions across regimes, fix entity attribution at ingestion, and implement reporting as configuration so new templates do not require engineering.

    Back to Resources

    The system of record for client funds and reserves