In short
The CASS 15 safeguarding audit is the annual external audit required under SUP 3A, in which an auditor reports to the FCA on whether the firm maintained systems and controls adequate to comply with the safeguarding rules throughout the period, not merely at the period end. That period-long scope has a direct evidential consequence: the auditor does not test every reconciliation performed, they test populations and draw samples from them. A sample is only meaningful if the population it is drawn from is demonstrably complete, so proving completeness, not producing a handful of well-documented examples, is the pivotal issue in the engagement.
What the SUP 3A safeguarding audit tests
SUP 3A requires safeguarding institutions to obtain an annual report from an independent auditor on the adequacy of their systems and controls for complying with the safeguarding requirements set out in the CASS 15 requirements. The critical feature of that scope is the period basis of the opinion. The auditor is not asked whether the firm's records were correct on the balance sheet date; they are asked whether the systems and controls operated adequately throughout the reporting period, including at every point in between where a supervisor or an insolvency practitioner might later need to rely on them.
The auditor's report is addressed to the FCA, not to the firm's board, even though the firm commissions and pays for it. That reporting line changes the character of the engagement. The auditor is performing a regulatory function on behalf of the supervisor, which means findings cannot be negotiated away in the way a management letter point on a statutory audit sometimes can be. A qualified or adverse safeguarding audit report is a matter the FCA will follow up directly with the firm.
Firms preparing for their first SUP 3A engagement typically underestimate the request list. Expect the auditor to ask for the full population of internal and external reconciliations performed in the period, evidence of the frequency actually achieved against the frequency the firm asserts, the complete exception register with resolution status and timing for each break, records of any corrective funding transfers made to cover shortfalls, governance minutes showing that oversight of safeguarding was substantive rather than nominal, and the resolution pack as it stood at one or more selected dates during the period.
The reason completeness is tested before individual items are examined is straightforward statistically and evidentially. A sample of thirty reconciliations tells the auditor something about control operation only if those thirty are drawn from a population the firm can show is the entire population, with no reconciliations performed but not retained, no days silently skipped, and no records excluded from what is presented. If the population itself cannot be verified as complete, any conclusion drawn from a sample of it is unsound, and the auditor has no basis for forming an opinion on the period as a whole.
A qualified or adverse conclusion typically follows from one of a small number of recurring patterns: gaps in the reconciliation record that the firm cannot explain, evidence that was assembled or amended after the fact rather than created contemporaneously with the control, exceptions that were resolved outside the timeframes the firm's own procedures require, or a resolution pack that does not match the accounts and counterparties actually appearing in the reconciliation population. Each of these undermines the auditor's ability to conclude that controls operated adequately throughout the period, which is the specific question SUP 3A asks.
Preparation therefore has to happen across the year rather than in the weeks before fieldwork begins. Evidence assembled retrospectively, however diligently, carries a tell: metadata showing a document was created or last modified shortly before the audit visit, rather than on the date it purports to evidence, is precisely the signal an experienced auditor is trained to notice, and it tends to extend testing rather than satisfy it. Firms that treat the monthly oversight review as a rehearsal for the annual audit, examining the same population, the same exception register and the same resolution pack an auditor would ask for, in the same form, generally find the engagement itself materially shorter and less contentious. Where audit evidence has been sealed and made independently verifiable throughout the year, as described in our note on evidence packs and what regulators and auditors expect, the completeness question the auditor is really asking becomes straightforward to answer rather than a scramble.
What else a safeguarding auditor asks for during fieldwork
The annual safeguarding audit is performed against a specified assurance standard and reports to the FCA. The auditor's opinion covers whether the firm has maintained systems and controls adequate to comply throughout the period, not whether the position was correct on the final day.
That distinction determines the request list. The auditor asks for a complete population of reconciliations performed in the period, evidence of the frequency actually achieved, the exception population with resolution status and timing, the funding transfers made to correct shortfalls, the governance records showing oversight, and the resolution pack as it stood at selected dates.
Each request is then sampled. A sample selected from a population the firm supplied is only meaningful if the population itself is demonstrably complete, which is why auditors test completeness before they test items.
Firms consistently underestimate the completeness testing. Producing thirty well-documented reconciliations is easy. Proving that thirty is the whole population and none were missed is where manual processes fail.
This is also where the request list tends to grow mid-engagement. An auditor who cannot get comfortable with completeness from the primary population will ask for corroborating sources, such as bank statements, payment scheme confirmations or system logs, to reconcile the count independently. Each corroborating request adds days to fieldwork and shifts the tone of the engagement from confirmatory to investigative.
Why manual collection breaks under sampling
Manual collection is organised around documents, not events. Someone locates the workbook, the statement, the email approving a transfer and the meeting minute, and assembles them into a folder for each sampled date.
The weakness is that these artefacts were never linked at the time. The email approving a transfer does not reference the exception identifier. The minute records a decision without the underlying figures. The statement was re-saved and its retrieval date is later than the reconciliation date.
Auditors are trained to notice that the evidence was created after the fact. Where metadata shows a document assembled the week before fieldwork, the auditor cannot rely on it as contemporaneous evidence of the control operating, and will extend testing.
Extended testing is expensive and generates further requests, which is why manual audit preparation reliably consumes several weeks of senior compliance and finance time and still produces findings.
Evidence as a by-product of the control, not a separate exercise
In a controlled platform, the evidence is created by the same action that performs the control. Ingesting a file records its hash and arrival time. Running a reconciliation records the rule versions and the population. Resolving an exception records the investigation, attachments, decision and approver.
Nothing is assembled later because nothing needs to be. The artefacts exist at the moment the control operates and are immutable from that point.
This changes the nature of preparation. Instead of building evidence, the firm selects a period and exports it. The export includes the population, the sample support, the timing data and the approval chain, with each item cryptographically sealed.
It also removes the incentive problem. Where evidence must be assembled manually, there is pressure to present the tidiest version. Where it accrues automatically, the firm and the auditor see the same record.
The assurance pack and its manifest
An assurance pack is not a folder of exports. It is a defined structure with a manifest listing every artefact, its type, its period, its hash and its relationship to the control it evidences.
The manifest is what allows an auditor to verify integrity independently. Recomputing the hash of an exported artefact and comparing it to the manifest confirms that the file has not changed since it was sealed, without requiring trust in the firm or in the platform's interface.
A complete pack covers reconciliation runs and their inputs, the exception register with full lifecycle, corrective funding transfers, rule and tolerance version history, access and approval logs, governance minutes referencing the underlying identifiers, and the resolution pack as at each selected date.
Safeheld generates this structure automatically for any period, so the pack requested in the second week of fieldwork is produced in the same session rather than over the following fortnight.
The resolution pack is a live obligation, not an annual document
The resolution pack exists so that an insolvency practitioner or the regulator can identify and return client funds quickly without reconstructing the firm's books. Its content must be current, and the firm must be able to produce it promptly on request.
In practice, packs drift. A safeguarding account is added, a signatory changes, a system is replaced, a counterparty relationship ends, and the pack retains the previous state until someone reviews it, typically once a year.
Drift is straightforward for a supervisor to detect: compare the accounts listed in the pack with the accounts appearing in the reconciliation population. Any divergence is direct evidence that the pack is not maintained.
Deriving the pack from the same live configuration that drives the reconciliation removes the drift entirely, because adding an account to the operating process necessarily updates the pack.
How the engagement changes when evidence is continuous
The most visible change is duration. Fieldwork that spanned weeks of iterative requests compresses when the population, samples and supporting artefacts are available immediately and are internally consistent.
The more important change is the nature of the discussion. When evidence gathering is not in dispute, the engagement concentrates on methodology: whether the definition of relevant funds is right, whether tolerances are appropriate, whether escalation thresholds are calibrated, and whether governance is genuinely challenging the numbers.
That is a more valuable conversation for the firm, because those are the areas where a supervisory issue would actually originate.
It is also a more defensible position. A firm that can demonstrate contemporaneous, sealed evidence for every day of the period is making an argument about control operation that does not rely on recollection.
For firms newly subject to CASS 15, this shift is worth planning for from the first month of operation rather than waiting for the first audit cycle to expose the gap. An engagement built on continuous, verifiable evidence tends to be shorter, less adversarial and less likely to surface findings that then require a remediation plan reported separately to the board and, in a qualified case, to the FCA.
Interim testing and why year-end preparation is the wrong model
Auditors increasingly test at interim points during the period rather than concentrating on the year end, because the opinion concerns the period as a whole.
A firm that prepares evidence annually is therefore preparing twice, and each preparation carries the same reconstruction risk. A firm whose evidence accrues continuously is indifferent to when testing occurs.
Interim testing also surfaces issues early enough to remediate them within the period, which changes the character of the finding. An issue identified in month four and corrected by month six is a control that worked; the same issue found at year end is a qualification risk.
The operational implication is that the monthly oversight review should examine the same artefacts the auditor will request, in the same form, so that nothing is seen for the first time during fieldwork.
Why cryptographic sealing matters to an independent reviewer
An auditor cannot rely on an assertion that a system is immutable. Reliance requires either testing the general IT controls of the platform or verifying the artefacts independently.
Hashing each artefact at the moment it is created, and publishing the hash in a manifest, allows independent verification without any reliance on the platform's interface. The reviewer recomputes the hash from the exported file and compares it.
This also protects the firm. Where an artefact is challenged years later, the hash establishes that the file produced now is identical to the file sealed then, which is a stronger position than a description of internal controls.
Safeheld seals each completed run and each evidence export in this way, so the assurance pack can be verified by an auditor, a skilled person or an insolvency practitioner without privileged access.
Frequently asked questions
What is the CASS 15 safeguarding audit?
It is the annual external audit required under SUP 3A for safeguarding institutions. An independent auditor reports to the FCA on whether the firm's systems and controls were adequate to comply with the safeguarding requirements throughout the reporting period, not only at its end.
Who must have a safeguarding audit?
The SUP 3A audit requirement applies to firms that hold safeguarding institution permissions and are therefore subject to CASS 15. The obligation follows directly from that permission status rather than from any separate threshold or election.
How often is the safeguarding audit required?
SUP 3A requires the safeguarding audit report to be produced annually, covering the firm's systems and controls across the preceding reporting period as a whole rather than testing a single point in time.
What is an assurance pack?
A structured export covering a defined period that contains every artefact evidencing the safeguarding controls, together with a manifest listing each artefact and its cryptographic hash so integrity can be verified independently.
Why do auditors test population completeness first?
Because a sample drawn from an incomplete population proves nothing. If the firm cannot demonstrate that the list of reconciliations performed is exhaustive, the auditor cannot rely on any testing performed against that list.
How often should a resolution pack be reviewed?
It must be kept current rather than reviewed periodically. The practical standard is that any change to safeguarding accounts, counterparties, signatories or systems is reflected immediately, which is achievable when the pack is derived from live configuration.
Does automated evidence reduce audit fees?
It reduces the evidence gathering component of the engagement and the volume of follow-up requests. Fee outcomes depend on the auditor and the scope, but the effort profile shifts from reconstruction towards methodology and judgement.