PS25/12 safeguarding, met in a single platform.

    Meet the FCA's new safeguarding requirements under PS25/12 in one platform.

    PS25/12 safeguarding position

    Coverage 101.2% · all notification triggers clear

    Barclays logo

    Safeguarding, primary

    101.2%

    Matched
    HSBC logo

    Safeguarding, secondary

    100.4%

    Matched

    Built for: Authorised Payment Institutions · Authorised E-Money Institutions · Small EMIs · UK credit unions issuing e-money

    PS25/12 does not apply to firms providing only payment initiation (PISP) or account information (AISP) services.

    IN FORCE 7 MAY 2026

    WHAT SAFEHELD DOES

    The PS25/12 operating layer for payment and e-money firms.

    One platform that runs the day-to-day work PS25/12 demands, so your team focuses on exceptions rather than assembly. Plain English, no Handbook references required.

    Daily reconciliations

    Internal and external safeguarding reconciliations run automatically every business day.

    Monthly FCA reporting

    The new monthly safeguarding return is auto-populated from your live data.

    Audit-ready year round

    An always-current evidence pack so the annual audit is review, not reconstruction.

    Live resolution pack

    Your CASS 10A resolution pack stays current and is exportable on request.

    Notifications & oversight

    Notification triggers, policy controls and third-party oversight tracked continuously.

    PS25 OPERATING LAYER · PRODUCT DEMO

    See your PS25/12 position in one working session.

    A 30-minute working session. We map your current setup against PS25/12 and show you what Safeheld would automate.

    WHY MANUAL PS25 COMPLIANCE BREAKS

    Spreadsheets cannot carry PS25/12. Here's what fails first.

    Six operational fault lines we see in every firm still running PS25 readiness on Excel, email and shared drives. Each one is a direct route to an FCA notification, an audit finding, or a senior manager attestation that cannot be defended.

    Daily reconciliation risk

    Spreadsheets break under daily three-way reconciliation across multiple safeguarding banks, currencies and ledgers. Discrepancies sit unowned and unevidenced.

    Monthly returns become projects

    SUP 16.14A is a monthly submission, not a quarterly one. Manual data assembly turns each return into a multi-day cross-team scramble.

    Audits become evidence hunts

    SUP 3A auditors expect a continuous evidence pack. Reconstructing it from inboxes and folders inflates audit fees and surfaces findings.

    Policies and resolution packs drift

    Safeguarding policies and the CASS 10A resolution pack go stale between annual reviews, out of step with how the firm actually safeguards funds.

    Notifications missed or late

    The four CASS 10A notification triggers require near-real-time detection. Manual processes miss them or report after the deadline.

    Senior managers lack live oversight

    Heads of Compliance and SMF holders have no real-time view of coverage, breaches and audit readiness. Attestations rely on month-old snapshots.

    PS25/12, THE FIVE CORE REQUIREMENTS

    Every PS25/12 obligation. One operating layer.

    PS25/12, the FCA's Supplementary Regime, strengthens the safeguarding obligations on payments and e-money firms. It adds rules across CASS 10A, CASS 15, SUP 16.14A, and SUP 3A. Safeheld is purpose-built to evidence each one continuously: not at year-end, not on request, but every day.

    CASS 10ARequirement 1 of 5

    Daily safeguarding reconciliations

    PS25/12 requires firms to perform internal and external safeguarding reconciliations at least once each business day, excluding weekends, public holidays, and days when relevant foreign markets are not open. Internal reconciliations check the firm's own records and ledgers; external reconciliations compare them to balances held by third parties such as safeguarding banks.

    • Automated internal and external reconciliations on every business day
    • Three-way match across bank balances, internal ledgers, and customer liabilities
    • Multi-currency support with per-currency coverage ratios
    • Discrepancy investigation workflow with named owner, status, and audit trail
    • Every reconciliation run sealed and indexed for the SUP 3A audit evidence pack

    Relevant funds reconciliation

    Coverage

    99.88%

    Designated safeguarding · GBP

    Matched

    62,004,118

    Designated safeguarding · EUR

    Part matched

    18,206,440

    SUP 16.14ARequirement 2 of 5

    Monthly safeguarding return to the FCA

    PS25/12 introduces a new monthly safeguarding regulatory return under SUP 16.14A, covering relevant funds, safeguarding methods, reconciliation outcomes, and notifications. The return enables the FCA to identify shortfalls earlier and supervise the sector more effectively.

    • Monthly return auto-populated from live reconciliation, breach, and policy data
    • Mapped to the SUP 16.14A data fields and FCA submission format
    • Internal sign-off workflow with named approver, evidence trail, and version history
    • Submission tracking with FCA acknowledgement capture and resubmission alerts
    • Board pack auto-generated alongside each return for senior management and Head of Compliance review

    Regulatory return pipeline

    SUP 16.14A

    146/148 fields

    Annual audit pack

    212/212 fields

    SUP 3ARequirement 3 of 5

    Annual safeguarding audit

    In-scope firms must appoint a qualified auditor each year to perform a safeguarding audit and submit the report to the FCA. Firms holding less than £100,000 of relevant funds are not required to arrange a safeguarding audit, and firms holding no relevant funds are exempt from the limited assurance audit.

    • End-to-end audit lifecycle: auditor appointment, evidence gathering, draft, FCA submission
    • Evidence pack auto-compiled across reconciliations, notifications, policies, and resolution-pack records
    • Auditor portal with read-only access, sample selection, and management response workflow
    • Standing audit-readiness score updated continuously, with no end-of-year scramble
    • Prior-year findings tracked through to closure with documented remediation evidence
    CASS 10A · CASS 15Requirement 4 of 5

    Policies, controls and third-party due diligence

    Firms must maintain documented safeguarding policies and procedures, carry out due diligence on third parties that hold or manage relevant funds, and maintain contingency plans where safeguarding is achieved through insurance or a comparable guarantee. Each policy and control must be mapped to a named owner and reviewed continuously, not at year-end.

    • Policy library covering safeguarding, reconciliation, notifications, and third-party due diligence, with version control and review date tracking
    • Each policy mapped to live controls; coverage scored continuously, not at review date
    • Third-party due diligence register for safeguarding banks, custodians and insurers
    • Acknowledgement letter register with signed-date, expiry, and renewal automation
    Policy Library
    AI-assisted

    TOTAL CONTROLS

    37

    AVG COVERAGE

    89.5%

    AI-ASSISTED

    3/4

    NEXT REVIEW

    14 Apr

    Safeguarding Policy

    v3.212 controls
    94
    94%
    12 Mar

    Reconciliation Policy

    v2.88 controls
    100
    100%
    28 Feb

    Breach Notification

    v1.46 controls
    88
    88%
    05 Mar

    Wind-Down Plan

    v1.111 controls
    76
    76%
    18 Jan
    37 controls mapped · Version history tracked All policies current
    CASS 15Requirement 5 of 5

    Resolution pack, kept current and available on request

    Firms must maintain a resolution pack under CASS 10A. It contains the records and documents that support a timely return of relevant funds to customers in the event of insolvency. The pack must be kept current and made available to the FCA, an insolvency practitioner or an administrator on request.

    • Live resolution pack assembled from your current safeguarding data, with no annual rebuild
    • Customer ledgers, safeguarding bank statements, acknowledgement letters and reconciliation evidence in one structured pack
    • Third-party due diligence records and contingency plans tracked alongside the pack
    • Version history with named owner and last-reviewed date for every component
    • Single-click export for the FCA, insolvency practitioner or administrator
    CASS 15 Resolution Pack
    v.2026.04

    Components

    6

    Current

    100%

    Last assembled

    2m

    Customer ledgers

    Owner: Finance Ops

    Today, 09:42

    Safeguarding bank statements

    Owner: Treasury

    Today, 06:15

    Acknowledgement letters

    Owner: Compliance

    12 Apr

    Reconciliation evidence

    Owner: Finance Ops

    Today, 09:42

    Third-party due diligence

    Owner: Risk

    08 Apr

    Contingency arrangements

    Owner: COO

    02 Apr
    Available on request to FCA, IP or administrator
    Export pack

    Review your PS25/12 position in one working session.

    A 30-minute working session walking through your current safeguarding setup against each of the five PS25/12 requirements, identifying the gaps in your current safeguarding operation.

    PS25/12, FREQUENTLY ASKED

    What firms are asking about PS25/12.

    Who does PS25/12 apply to?

    Authorised Payment Institutions (excluding firms providing only payment initiation or account information services), Authorised E-Money Institutions, Small E-Money Institutions, and UK credit unions that issue e-money.

    When does PS25/12 take effect?

    The FCA's Supplementary Regime under PS25/12, and the related amendments to the Approach Document, came into force on 7 May 2026. There was a single in-force date, with no phased rollout and no transitional relief. Firms must be fully compliant.

    What is the Supplementary Regime?

    The Supplementary Regime is the set of FCA rules introduced by PS25/12 that supplements the existing safeguarding requirements in the Electronic Money Regulations 2011 and Payment Services Regulations 2017. It strengthens books and records, reconciliation, monitoring and reporting, and audit. The end-state "Post-Repeal Regime" was consulted on but has been deferred for further consultation.

    What is the new monthly FCA safeguarding return?

    PS25/12 introduces a new monthly safeguarding regulatory return under SUP 16.14A. Safeheld auto-populates the return from live reconciliation, breach, and policy data and tracks submission, acknowledgement, and any required resubmissions.

    What does the SUP 3A annual safeguarding audit involve?

    In-scope firms must appoint a qualified auditor each year to perform a safeguarding audit and submit the report to the FCA. Firms holding less than £100,000 of relevant funds are not required to arrange a safeguarding audit, and firms holding no relevant funds are exempt from the limited assurance audit.

    How often must safeguarding reconciliations be performed?

    PS25/12 requires both internal and external safeguarding reconciliations at least once each business day, excluding weekends, public holidays, and days when relevant foreign markets are not open.

    Are PISPs and AISPs in scope?

    No. PS25/12 explicitly excludes firms that solely provide payment initiation services or account information services.

    Do credit unions need PS25/12 compliance?

    UK credit unions that issue e-money are in scope of the Supplementary Regime. Credit unions that do not issue e-money are not subject to these requirements.

    How quickly can Safeheld be deployed for PS25/12?

    Implementation timelines depend on the number of data sources and the availability of statement feeds. We scope this at demo.

    AI COPILOT, DELIVERY ADVANTAGE

    Ask your safeguarding data anything.

    The operating layer runs PS25/12 for you. The AI Copilot lets your team query it in plain English, coverage today, exceptions this week, what to put in front of the board on Monday, with answers grounded in your live data.

    • Plain-English answers across reconciliations, breaches, returns and policies
    • Exceptions explained with the correct citation, no Handbook lookup
    • Board-ready narratives drafted from your current position
    • First-pass remediation plans for every notification trigger
    Compliance Assistant
    Online · Context loaded

    What's our current compliance position?

    Your overall compliance score is 94.2%. You have 2 active findings, both low-severity, and zero overdue remediation actions. GBP coverage is at 100.9%, USD at 100.4%. No breaches detected.

    What about the EUR account?

    EUR coverage is at 100.1%, approaching your 100.0% threshold. At current outflow rate, it could dip below threshold in ~3.6 hours. I've flagged this for monitoring and auto-escalation is armed.

    Ask about reconciliation, coverage, or compliance...
    PS25/12 Demo

    Request a PS25/12 demo.

    A 30-minute working session. We map your current setup against PS25/12 and show you what Safeheld would automate.

    Connect

    Bank, ledger and processor data in one model

    Reconcile

    Liabilities against the funds that protect them

    Resolve

    Shortfalls and breaks routed for investigation

    Prove

    An auditable evidence trail behind every run

    Get Started

    Request a demo

    By continuing, you agree to our terms and privacy policy.

    See Safeheld for PS25/12Demo