In short
Three-way reconciliation compares three independent records of the same client position: the firm's internal ledger, the statement issued by the safeguarding institution or bank, and the record held by an external custodian, acquirer or scheme. A two-way match proves two records agree with each other. A three-way match proves the position itself is correct, because a methodology error that flows into two records is exposed by the third.
Why a two-way match is not proof of a correct position
Most reconciliation software matches a ledger against a bank statement. That comparison is necessary, and it catches missing entries, duplicates and posting errors. What it cannot catch is an error in the calculation that produced the ledger in the first place.
If a firm excludes a category of receipt from its definition of relevant funds, or applies the wrong value date to card settlement, the internal record and the derived requirement are both wrong in the same direction. The two-way match reconciles cleanly, because both sides descend from the same assumption.
The third record breaks that circularity. An acquirer settlement file, a scheme report, a custodian holdings statement or a distributor ledger is produced outside the firm's own systems and on the counterparty's own basis. When all three agree, the position is corroborated rather than merely internally consistent.
This matters because supervisory findings and audit qualifications rarely arise from a broken matching rule. They arise from a definition or timing assumption that was wrong for a long period and never challenged by an independent source.
The matching hierarchy, from exact identifier to probabilistic candidate
Matching runs as a cascade rather than a single pass. The first tier is exact identifier matching: end to end transaction reference, scheme reference, payment identifier or instruction identifier. Where a counterparty preserves the reference, this resolves the large majority of volume with no interpretation.
The second tier is composite key matching, combining amount, currency, value date and counterparty within a defined window. This handles counterparties that truncate or replace references, which is common in card settlement and in batched payouts.
The third tier is aggregation matching, where a single settlement credit corresponds to many underlying items. The engine must decompose the batch against the underlying population rather than treating the net credit as one item, otherwise a compensating error inside the batch is invisible.
The fourth tier is candidate matching, where the engine proposes a probable pairing with a confidence score and the reason for the score. A proposal is not a match. It is presented for review, and the reviewer's decision is recorded as part of the audit trail.
Timing differences are not breaks, and must be modelled as such
A substantial proportion of apparent differences are legitimate timing effects: funds in transit, cut-off boundaries between the firm's day and the bank's day, weekend and holiday settlement, chargebacks in flight, and pending settlement in custody chains.
If timing differences are treated as breaks, the exception queue fills with noise and genuine breaks are diluted. If they are suppressed as a general rule, real losses hide inside the suppression. Neither approach is defensible.
The correct treatment is to model each timing category explicitly, with an expected ageing profile and a maximum permitted life. An item in transit for one day is expected. The same item unresolved after five days is a break regardless of its original classification, and should escalate on that basis.
This produces a reconciliation where the unexplained residual is genuinely unexplained. That residual, and how quickly it moves to zero, is the number a supervisor and an auditor will look at first.
Tolerance design and the funding obligation
Tolerances exist for rounding, foreign exchange conversion and fee mechanics, not for convenience. A tolerance set wide enough to absorb an operational error is a control weakness that will be identified in testing.
Tolerances should be defined per data source and per difference type, expressed in absolute and relative terms, and versioned. When a tolerance changes, the change, its author, its rationale and its effective date form part of the record.
Under the FCA safeguarding regime, identifying a shortfall is not the end of the obligation. The firm must correct the position from its own resources without delay and evidence the correction. A platform that flags a variance but cannot show the funding transfer, its timing and its approval leaves the most important part of the control unevidenced.
Excesses carry an equivalent obligation in the opposite direction. Money that is not relevant funds should not sit indefinitely in a safeguarding account, and unexplained excess is treated as a control failure rather than a conservative buffer.
A break taxonomy that supports investigation rather than counting
Counting breaks tells a board almost nothing. Classifying them tells it where the operating model is failing. A usable taxonomy separates data breaks, process breaks, counterparty breaks and genuine value breaks.
Data breaks are missing files, late files, schema changes and truncated fields. They are frequently the leading indicator of a larger failure, because a file that stops arriving silently removes an account from the reconciliation population.
Process breaks are internal: an unposted journal, a mis-sequenced batch, a manual adjustment applied without a corresponding entry. Counterparty breaks originate at a bank, acquirer or custodian and require external chase, with the chase itself forming part of the record.
Value breaks are the residual, and are the only category that should ever reach the funding obligation. Reporting the four categories separately allows a firm to demonstrate that its variance profile is driven by data hygiene rather than by client money loss, which is a materially different conversation with a supervisor.
What the reconciliation must be able to reproduce two years later
The operational test of a reconciliation platform is not what it displays today. It is whether the firm can reconstruct the position as at a specific historic date, with the data as it stood at that time, and show who reviewed it and on what basis.
That requires immutable retention of the source files as received, the transformation applied to them, the rule versions in force, the match decisions, the exceptions raised, the corrections funded and the approvals given.
Safeheld seals each completed run with a cryptographic hash over the inputs, rule versions and outputs, so a later export can be shown to be identical to the run that was reviewed at the time. Reproducibility, not presentation, is what converts a reconciliation into audit evidence.
This is also what makes an external audit efficient. When the auditor can select a date, obtain the sealed run and trace a sample from source file to funded correction without a single manual request, the engagement narrows to judgement rather than evidence gathering.
Currency, valuation and the third record in cross-border operation
Where relevant funds are held in more than one currency, the reconciliation must be performed per currency before any consolidated view is produced. Converting first and reconciling afterwards hides a shortfall in one currency behind a surplus in another, which is not a permitted offset.
Valuation introduces a second issue. The rate used to express the requirement must be the rate applied to the resource, drawn from the same source and the same time. Where the ledger uses a daily fixing and the bank applies an execution rate, the difference is structural and must be modelled as a named category rather than investigated as a break.
Conversion itself creates an in-flight state. Funds leaving one currency account and arriving in another exist briefly in neither, and a reconciliation performed at that moment will show a shortfall unless the in-flight leg is represented.
The third record resolves most of this. A treasury confirmation or counterparty execution record establishes the rate and the timing independently of both the ledger and the statement, which converts a recurring investigation into a modelled expectation.
Designing for volume without losing the item-level trail
High-volume firms reconcile millions of items daily. The temptation is to reconcile at summary level, comparing daily totals rather than individual transactions, because the totals agree most of the time.
Summary reconciliation is not equivalent. Two compensating errors of equal value net to zero at total level and are invisible, and a summary match cannot support the item-level sample an auditor will select.
The correct approach is item-level matching with summary presentation. The engine resolves each item, then reports at the level the reader needs, with the ability to expand any figure to the items behind it.
Performance is an engineering problem rather than a control compromise. Where a firm has been advised to reconcile on totals for performance reasons, the advice describes a limitation of the tool, not a property of the obligation.
Frequently asked questions
What is three-way reconciliation in safeguarding?
It is the comparison of three independent records of the same client position: the firm's internal ledger, the safeguarding institution's statement, and an external record from a custodian, acquirer or scheme. Agreement across three independently produced sources corroborates the position, whereas a two-way match only proves internal consistency.
Is three-way reconciliation required by the FCA?
The FCA requires internal reconciliation of a firm's own records and external reconciliation against third parties holding relevant funds. Three-way reconciliation is the operating method that satisfies both simultaneously and, in addition, exposes methodology errors that a single two-way comparison would not reveal.
How should timing differences be handled?
They should be modelled as named categories with an expected ageing profile and a maximum permitted life, not suppressed and not treated as breaks. An item that exceeds its expected life escalates as a break regardless of its original classification.
What happens when a shortfall is identified?
The firm must correct the position from its own resources without delay and retain evidence of the correction, including the transfer, its timing and its approval. Identification alone does not discharge the obligation.