Why D+1 Reconciliation Matters Under CASS 7, PS25, and MiCA

Why D+1 Reconciliation Has Become the Regulatory Baseline

Across every major safeguarding framework, from the FCA's CASS 7 rules to PS25 and the EU's MiCA regulation, the expectation is the same: firms holding client funds must reconcile those balances no later than the business day following the date to which the reconciliation relates. This is the D+1 standard.

D+1 is not aspirational. It is the minimum. Under CASS 7.15.11R, investment firms must perform internal and external reconciliation of client money on a D+1 basis. PS25 reinforces this for payment institutions and e-money institutions. MiCA, while not prescribing a specific frequency in the Level 1 text, defers to ESMA technical standards that establish an expectation of daily or near-daily verification for custody providers.

The practical consequence is that any firm still performing reconciliation on a weekly, fortnightly, or monthly basis is operating outside the regulatory expectation, regardless of whether enforcement action has yet been taken. When the FCA, CBI, or BaFin reviews a firm's safeguarding arrangements, the first question is invariably: how frequently do you reconcile, and can you prove it?

What D+1 Actually Requires in Practice

Meeting the D+1 standard requires more than running a reconciliation script the morning after trade date. It demands a complete operational pipeline: data must be ingested from every relevant source, internal ledgers, bank statements, payment processor feeds, custodian records, normalised into a consistent format, and matched against client liability positions.

The reconciliation must be three-way at minimum: matching client liabilities (what you owe) against internal ledger positions (what you think you hold) against external confirmations (what the bank or custodian says you hold). Any variance between these three positions must be identified, investigated, and either resolved or escalated, all before the next business day's cycle begins.

This creates a compounding operational challenge. If Day 1's reconciliation reveals a variance that cannot be resolved by Day 2, the Day 2 reconciliation must still be completed, and must clearly distinguish between inherited breaks and new discrepancies. Firms that fall behind on resolution quickly find themselves unable to distinguish between legitimate timing differences and genuine shortfalls.

How D+1 Requirements Differ Across Frameworks

While the principle of daily reconciliation is consistent across major frameworks, the specific obligations vary in important ways. CASS 7 requires both internal reconciliation (client ledger vs. firm records) and external reconciliation (firm records vs. bank/custodian statements) on a D+1 basis. The rules are prescriptive about what constitutes an acceptable break and the timeline for resolution.

PS25 applies the same D+1 expectation to payment institutions and e-money institutions, but the reconciliation scope is different, it centres on safeguarded relevant funds rather than segregated client money pools. The practical distinction matters: PIs and EMIs must reconcile the total quantum of relevant funds against the balances held in designated safeguarding accounts.

Under MiCA, the reconciliation obligation for CASPs providing custody services is framed around the ability to demonstrate, at any point, that client crypto-assets are properly segregated and can be returned promptly. While the Level 1 text does not specify 'D+1' explicitly, the ESMA technical standards and supervisory expectations establish daily verification as the practical minimum.

For firms operating across multiple frameworks, a common reality for groups with UK, EU, and US operations, the challenge is maintaining parallel reconciliation processes that meet the specific requirements of each regime while avoiding duplication of effort.

Why Manual Reconciliation Cannot Scale to D+1

The most common failure mode for D+1 reconciliation is not regulatory misunderstanding, it is operational incapacity. Firms that rely on spreadsheets, manual data extraction, and email-based escalation routinely fail to complete reconciliation within the D+1 window, particularly during high-volume periods or when bank statements arrive late.

Manual processes introduce three categories of risk. First, data latency: if bank statements are only available via download at 9am, and the compliance team does not begin reconciliation until mid-morning, the effective window for identifying and investigating breaks is compressed to a few hours. Second, human error: transposing figures, misclassifying transactions, or overlooking small variances compounds over time and creates systemic inaccuracy. Third, evidence gaps: a reconciliation performed in a spreadsheet produces no immutable audit trail, making it difficult to prove to regulators that reconciliation was actually performed, let alone performed correctly.

As client volumes grow, the operational burden of manual reconciliation grows linearly, or worse, exponentially when the number of accounts, currencies, and custodians increases. Firms that have not automated their reconciliation infrastructure will eventually face a choice: hire additional headcount to maintain D+1 compliance, or accept the risk of falling behind.

What Automated D+1 Reconciliation Looks Like

Automated reconciliation infrastructure eliminates the operational bottleneck by performing the entire D+1 cycle, data ingestion, normalisation, three-way matching, variance identification, and evidence generation, without manual intervention. The compliance team's role shifts from performing the reconciliation to reviewing the results and managing exceptions.

In a well-designed system, data feeds from banks, custodians, and internal ledgers are ingested automatically, via SFTP, API, or file upload, and normalised into a common schema regardless of source format (CSV, MT940, SWIFT, proprietary). The matching engine applies configurable rules to identify exact matches, partial matches, and breaks. Each cycle produces a complete, timestamped, immutable evidence pack that documents the entire process.

This approach does not eliminate the need for human judgement, genuine breaks still require investigation and resolution. But it ensures that the mechanical work of data matching is completed reliably, consistently, and within the D+1 window, every business day, regardless of volume or complexity.

How Safeheld Delivers D+1 Reconciliation at Scale

Safeheld's reconciliation engine is purpose-built for the D+1 standard across CASS 7, PS25, and MiCA. The platform ingests data from any source, bank statements, custodian feeds, payment processor exports, and internal ledgers, in any format, and performs automated three-way matching against client liability positions.

Each reconciliation cycle produces a complete evidence pack: timestamped results, variance analysis, exception logs, and resolution records, all stored immutably with SHA-256 integrity verification. The compliance team receives a summary of results and exceptions requiring attention, rather than performing the reconciliation itself.

For firms operating across multiple frameworks, Safeheld manages parallel reconciliation streams, each configured to the specific requirements of the applicable regime, while presenting a unified dashboard to the Head of Compliance. The result is D+1 compliance that scales with the business, not against it.