PSD2

    PSD2 Safeguarding: What the Rules Require in the EU and the UK

    Article 10 segregation and insurance methods, how national implementation differs, where the UK now sits under the PSRs, EMRs and CASS 15, and the current status of PSD3.

    12 min read March 2026

    In short

    PSD2, Directive (EU) 2015/2366, sets safeguarding in Article 10: a payment institution must either keep customer funds segregated from its own money or cover them with an insurance policy or comparable guarantee. It does not prescribe a reconciliation frequency or an account structure, and each EU member state transposes it into its own national law, so the operative rules for an EU firm are found in that transposition, not in the directive text alone. The UK left this framework at the end of the Brexit transition period and now runs its own regime under the Payment Services Regulations 2017, the Electronic Money Regulations 2011 and, from 7 May 2026, CASS 15.

    What Article 10 of PSD2 actually says

    Article 10 of Directive (EU) 2015/2366 requires a payment institution that holds funds received from payment service users, or received via another payment service provider for executing a payment transaction, to safeguard those funds by one of two methods. The first is segregation: the funds must not be commingled with the money of any other natural or legal person, and where held at the end of the business day following receipt they must be placed in a separate account at a credit institution or invested in secure, liquid low-risk assets, and be insulated from claims of the institution's other creditors, particularly in insolvency. The second is insurance or a comparable guarantee from an insurance company or credit institution not belonging to the same group, covering an amount equivalent to what would otherwise have been segregated, payable if the institution fails to meet its financial obligations.

    That is the extent of what the directive itself fixes. It does not specify a reconciliation frequency, a named account type, or a particular acknowledgement letter format. It also does not distinguish payment institutions from electronic money institutions on this point; the E-Money Directive (2009/110/EC) applies the equivalent safeguarding requirement to e-money issuers by cross-reference. Anyone asserting that PSD2 mandates daily reconciliation, or a specific trust structure, is describing a national transposition or a supervisory expectation, not the directive text.

    The directive leaves member states to transpose these requirements into national law, and it is the national transposing measure, not Article 10 directly, that binds a firm operating in that member state. This matters because Article 10 is a floor with meaningful room for national variation above it.

    Why national transposition is the rule that actually binds you

    A directive does not apply directly to firms; it obliges member states to achieve a result through their own legislation, and it is that domestic legislation a firm must comply with. For safeguarding this means the granular detail, which accounts qualify, what an acknowledgement letter must say, how quickly a shortfall must be corrected, whether the regulator specifies a reconciliation cadence, sits in each member state's implementing law and in guidance from its national competent authority, not in the PSD2 text itself.

    This produces real divergence across the EU. Some competent authorities have issued detailed technical guidance on reconciliation frequency and record-keeping that goes well beyond the directive's wording; others have left more to firm judgement subject to general prudential supervision. A firm passporting services into several member states under PSD2 needs to check the host state's approach to supervision of safeguarding as applied to inbound passporting firms, and should not assume that satisfying its home state regulator's expectations automatically satisfies every other member state's supervisory approach to the same funds.

    The practical consequence for any EU-authorised firm is that the starting question is never simply "does this comply with PSD2". It is "does this comply with the transposing law and supervisory expectations of my home member state", with Article 10 read as the outer boundary those national rules cannot fall below.

    The UK position: not PSD2, but a UK-specific regime

    The UK transposed PSD2 into the Payment Services Regulations 2017 while it was an EU member state, and the safeguarding requirement for payment institutions sits at regulation 23 of that instrument. The equivalent requirement for electronic money institutions is set out in the Electronic Money Regulations 2011, regulations 20 to 24, which cover the safeguarding methods, the treatment of relevant funds and related record-keeping obligations.

    Since the end of the Brexit transition period, the UK is no longer bound by PSD2 as an EU directive, and it will not be bound by PSD3 or its accompanying Payment Services Regulation either. The PSR 2017 and EMR 2011 have continued as UK domestic law, amended and supplemented by the FCA rather than by any EU legislative process. This is a common point of confusion: a firm's own website or a commercial reference frequently describes UK safeguarding as "PSD2 compliance", which is imprecise. A UK payment institution or EMI is complying with UK regulations that originated from PSD2's transposition, not with the directive as currently in force in the EU.

    The consequence of this separation showed up directly in 2025. The FCA identified through its own supervisory work that firms could not reliably demonstrate what they owed customers against what they held, and responded with FCA Policy Statement PS25/12, published 7 August 2025, which introduced a supplementary safeguarding regime that has no EU equivalent and did not need to wait for any EU legislative timetable. See PS25/12 and CASS 15: The FCA Safeguarding Requirements Explained for the detail of that policy statement's content and CP24/20 background.

    What CASS 15 changes operationally from 7 May 2026

    CASS 15, together with CASS 10A (resolution packs), SUP 16.14A (the monthly safeguarding return) and SUP 3A (the annual safeguarding audit report), came into force in the FCA Handbook on 7 May 2026. These sit on top of the PSR 2017 and EMR 2011 safeguarding obligations rather than replacing them; the underlying duty to segregate or insure relevant funds is unchanged, but the evidencing and governance layer around it is now materially more prescriptive.

    CASS 15.2.4R requires the firm to allocate to a director or senior manager of sufficient skill, authority and experience responsibility for oversight of the firm's compliance with the safeguarding rules, reporting to the firm's governing body. There is no dedicated FCA controlled function created for this specifically; CF10a is a historic designation and SMF18 is not a prescribed mapping for safeguarding oversight, so firms should not describe either as satisfying CASS 15.2.4R by itself.

    CASS 15 requires internal and external reconciliation of relevant funds and prompt correction of any shortfall or excess identified, and the FCA's stated supervisory expectation is that this happens each business day for firms with meaningful flow, distinct from the position under PSD2's own text, which sets no frequency at all. SUP 16.14A introduces a monthly safeguarding return, to be submitted within 15 business days of month end on the form at SUP 16 Annex 29BR; this is separate from FSA056/CMAR, which is a different return under SUP 16.14 aimed at CASS medium and large investment firms and should not be conflated with the payments and e-money safeguarding return. SUP 3A introduces an annual external safeguarding audit report. The FCA's proposed end-state move to a statutory trust model remains outstanding at this stage and is not yet law.

    The mechanics that apply whichever regime you sit under

    Whether a firm is working from Article 10 as transposed in an EU member state or from the PSR 2017 and EMR 2011 as supplemented by CASS 15, the operational shape of segregation is similar. The firm must first identify which funds are relevant funds, meaning money received in exchange for e-money issued or received for executing a payment transaction, as distinct from the firm's own working capital, fees already earned, or funds held for services outside the regulated activity.

    Relevant funds must reach a segregation account, held with an authorised credit institution or, in some jurisdictions, the Bank of England, or be invested in permitted secure liquid assets with an authorised custodian. The account must be identifiable as holding safeguarded funds, and the credit institution must provide an acknowledgement letter confirming that the firm has no beneficial interest in the account and that no right of set-off applies against the firm's other liabilities. Getting an acknowledgement letter signed, dated and on file before funds flow through the account is a basic control that is nonetheless frequently found missing or out of date at audit.

    Timing matters in both frameworks: funds should reach the segregation account promptly, with a backstop of the close of the business day following receipt under both the PSD2 approach and the UK regulations. The insurance or comparable guarantee method requires cover from an insurer or credit institution unconnected to the firm, sized to match the amount that would otherwise be segregated, with proceeds payable into a segregated account on the firm's insolvency. In practice this method is uncommon in the UK because viable pricing is hard to secure at scale and supervisors scrutinise policy exclusions and payment triggers closely; a firm relying on it should expect to evidence the adequacy of cover on a comparably frequent cycle to a segregating firm evidencing its balances. See EMI Safeguarding: What Electronic Money Institutions Must Do for a fuller treatment of relevant funds identification and the segregation account mechanics for e-money specifically.

    Where reconciliation is actually required, and where it is not

    It is worth being precise about where a reconciliation obligation comes from, because the two regimes discussed here do not impose it identically. PSD2's Article 10 does not itself specify any reconciliation frequency; it is concerned with the safeguarding method and the insolvency-remoteness of the funds, not with how often the firm checks its own working. Any specific cadence quoted for an EU firm is coming from national transposition or supervisory guidance, and firms should check their home state's rules rather than assume a EU-wide standard.

    In the UK, CASS 15 requires internal and external reconciliation of relevant funds against outstanding obligations, and the FCA's articulated expectation is that this happens each business day, with any shortfall corrected immediately from the firm's own resources and any excess withdrawn so firm money is not left commingled. Record-keeping obligations under both the EMR 2011 and CASS 15 require the firm to be able to show which customer's entitlement each safeguarded amount corresponds to, not merely that a global balance is adequate. This distinction, between funds being safeguarded in aggregate and funds being attributable to individual customers, is where firms with manual processes typically fail first.

    UK versus EU: a direct comparison

    The core safeguarding duty is similar in substance because the UK rules descend from the same PSD2/EMD text, but the governing instruments, the supervisory layer, and the trajectory of each regime now differ meaningfully. In the EU, the binding text for a payment institution is Article 10 of Directive (EU) 2015/2366 as transposed into the law of its home member state, supervised by that state's national competent authority, with no EU-wide monthly return or annual audit requirement equivalent to the UK's.

    In the UK, the binding text is regulation 23 of the PSR 2017 for payment institutions and regulations 20 to 24 of the EMR 2011 for electronic money institutions, both supervised by the FCA, and now supplemented from 7 May 2026 by CASS 15, CASS 10A, SUP 16.14A and SUP 3A, none of which have a direct EU equivalent. The UK also has a named allocation of individual accountability under CASS 15.2.4R that goes beyond what Article 10 requires.

    Looking forward, the EU package intended to replace PSD2, comprising PSD3 and a directly applicable Payment Services Regulation (based on Commission proposals COM(2023) 367 and COM(2023) 366), reached provisional political agreement between the European Parliament and the Council on 27 November 2025. As at the time of writing it has not been formally adopted or published in the Official Journal, so no entry-into-force or application date can be stated, and describing it as settled law would be inaccurate. The UK, having left the framework, will not adopt PSD3 or the Payment Services Regulation in any form; its own regime moves on the FCA's separate timetable. Firms operating in both jurisdictions should read PS25 and PSD3 Convergence: What UK Firms Should Prepare For for how the two trajectories compare and where a single operating model can serve both.

    Common failure points across both regimes

    The most common failure is treating the two frameworks as interchangeable: a firm authorised in the UK describing itself as PSD2-compliant, or an EU firm assuming a customer briefing written for the UK regime answers a question about its own member state's transposition. This produces answers that are confidently wrong rather than merely imprecise.

    The second is missing or stale acknowledgement letters, which undermine the insolvency-remoteness the segregation method exists to achieve regardless of which jurisdiction's rules apply.

    The third is treating aggregate balance adequacy as sufficient evidence, when both the UK record-keeping rules and good EU practice require the firm to show individual customer attribution, not just a total that happens to be large enough.

    The fourth, specific to firms tracking regulatory change, is citing PSD3 or the EU Payment Services Regulation as though its terms are already binding. Provisional political agreement is not adoption, and a firm building a compliance programme around draft terms that may still change before formal adoption is building on an unstable foundation.

    What a compliance programme still has to supply itself

    Neither Article 10 of PSD2 nor the PSR 2017 or EMR 2011 mandates any particular software, ledger or reconciliation tool; the law sets the outcome, and firms choose how to evidence it. Safeheld's role is confined to that evidencing layer: it tracks relevant funds identification, monitors the age of unsegregated receipts against the relevant deadline, and runs internal and external reconciliation across every safeguarding account so that a shortfall or excess is identified and attributable to the run that found it, whether the firm needs to demonstrate compliance with a member state's PSD2 transposition or with CASS 15 in the UK.

    Runs are hash-sealed so a stored reconciliation position can be checked against its original state rather than taken on trust, which supports the individual customer attribution that both regimes ultimately expect but that neither dictates a specific method for. It does not replace the acknowledgement letters, the account structure decisions, or the legal analysis of which member state's transposition applies to a given flow; those remain judgements for the firm and its legal advisers, informed by which jurisdiction's rules actually bind the entity in question. See CASS 15 Safeguarding Reconciliation: Daily Requirements and Evidence for why the timing discipline around receipt and placement is the control most worth automating, and /solutions/psd2 for how the underlying reconciliation and evidencing engine is configured for payment institutions and EMIs specifically.

    Frequently asked questions

    Does PSD2 require daily reconciliation of safeguarded funds?

    No. Article 10 of Directive (EU) 2015/2366 sets the safeguarding methods, segregation or insurance/comparable guarantee, but does not specify a reconciliation frequency. Any specific cadence applied to an EU firm comes from its home member state's transposing law or supervisory guidance, not from the directive text. In the UK, CASS 15 does carry an articulated expectation of business-day reconciliation, but that is a UK rule, not a PSD2 requirement.

    Is a UK payment institution or EMI subject to PSD2?

    No, not directly. The UK left the EU framework at the end of the Brexit transition period. UK firms are governed by the Payment Services Regulations 2017 (regulation 23) and the Electronic Money Regulations 2011 (regulations 20 to 24), now supplemented by CASS 15, CASS 10A, SUP 16.14A and SUP 3A from 7 May 2026. These originated from the UK's earlier transposition of PSD2 but have since developed independently and will not track PSD3.

    Will PSD3 change safeguarding rules for firms operating in the UK?

    Not for UK-authorised entities. PSD3 and the accompanying Payment Services Regulation reached provisional political agreement on 27 November 2025 but have not been formally adopted or published in the Official Journal, so no application date exists yet. Even once adopted, they will bind EU member states and firms authorised there; the UK left that framework and runs its own regime under the FCA.

    Why do EU member states apply PSD2 safeguarding differently?

    PSD2 is a directive, which obliges each member state to achieve the stated result through its own national legislation rather than applying directly to firms. Article 10 sets the outer requirement, but the detail, including any reconciliation expectations, account specifics and supervisory guidance, is set at member state level, so a firm must check its home state's transposing law and, where passporting, the host state's supervisory approach.

    Back to Resources

    The system of record for client funds and reserves