Warning

The content on this page has been converted from PDF to HTML format using an artificial intelligence (AI) tool as part of our ongoing efforts to improve accessibility and usability of our publications. Note:

  • No human verification has been conducted of the converted content.
  • While we strive for accuracy errors or omissions may exist.
  • This content is provided for informational purposes only and should not be relied upon as a definitive or authoritative source.
  • For the official and verified version of the publication, refer to the original PDF document.

If you identify any inaccuracies or have concerns about the content, please contact us at [email protected].

Safeguarding Assurance for Payment and E-Money Institutions - Appendix 13 to the CASS Assurance Standard: Invitation to comment

The FRC does not accept any liability to any party for any loss, damage or costs howsoever arising, whether directly or indirectly, whether in contract, tort or otherwise from any action or decision taken (or not taken) as a result of any person relying on or otherwise using this document or arising from any omission from it.

© The Financial Reporting Council Limited 2026

The Financial Reporting Council Limited is a company limited by guarantee. Registered in England number 2486368. Registered Office: 13th Floor, 1 Harbour Exchange Square, London, E14 9GE

1. Introduction

Background

1The UK payments and e-money sectors have experienced significant growth in recent years and now play an important role in the provision of financial services to consumers and businesses. Firms operating in these sectors hold substantial volumes of customer funds and, unlike deposits held with banks, these funds are protected through statutory safeguarding arrangements.

2Safeguarding requirements are established under the Electronic Money Regulations 2011 (EMRs) and the Payment Services Regulations 2017 (PSRs), and are supplemented by Financial Conduct Authority (FCA) rules and guidance. They are intended to ensure that relevant funds are identified, segregated and protected so that customers receive an appropriate level of protection in the event of firm failure. The effectiveness of these arrangements is therefore an important contributor to consumer confidence and market integrity.

3The FCA has, through its supervisory work, identified areas where safeguarding arrangements at some payment services and e-money firms could be strengthened. These observations have included matters relating to governance, record keeping, reconciliations, and the identification and segregation of relevant funds. In Policy Statement PS25/12 'Changes to the safeguarding regime for payments and e-money firms', the FCA introduced a package of reforms designed to strengthen the safeguarding regime and improve outcomes for consumers.

Safeguarding Audit Requirement

4As part of these reforms, the FCA has introduced a requirement for certain firms to obtain an annual safeguarding audit. The audit requirement is intended to provide independent assurance over firms' compliance with safeguarding obligations and to support greater consistency in the operation of the safeguarding regime.

5The FCA rules require safeguarding audits to be carried out in accordance with a reasonable assurance engagement standard issued by a body recognised by the FCA for that purpose.

6In its guidance at SUP 3A.9.4G, the FCA refers to the proposed Appendix and states that it expects safeguarding auditors to have regard to it when carrying out safeguarding audit engagements.

The Proposed Appendix

7The Financial Reporting Council (FRC), as the UK's competent authority for audit and assurance standard setting, is committed to acting as a proportionate and principles-based regulator that balances the need to minimise the impact of regulatory requirements on business, while working to support the delivery of high-quality audit and assurance work to maintain investor and wider stakeholder confidence in audit and assurance.

8The FRC has therefore developed a proposed Payment and E-Money Safeguarding Assurance Appendix to support the performance of safeguarding audit engagements in accordance with the FCA's rules by providing for a reasonable assurance opinion on compliance with the rules both at the period end and throughout the reporting period.

9Following the introduction of the FCA's safeguarding audit requirements, the FRC issued interim guidance to support practitioners undertaking safeguarding audit engagements pending the development of a dedicated Appendix to the Client Asset (CASS) Assurance Standard. Subject to the outcome of this consultation, the FRC intends that the final Appendix will supersede that interim guidance.

10The development of the Appendix by the FRC supports implementation of the FCA's safeguarding audit requirements. Following the FCA's introduction of the safeguarding audit regime, the FRC engaged with regulators, practitioners, firms and other stakeholders to understand the practical challenges associated with safeguarding audit engagements.

11The proposed Appendix supplements the CASS assurance standard by providing requirements and application material tailored to the specific features of safeguarding engagements. It has been developed following discussions with a dedicated working group comprising representatives from regulators, practitioners, payment services and e-money firms, and other stakeholders. These discussions identified a need for additional guidance in several areas, including safeguarding reconciliations, outsourced arrangements, governance and technology-enabled safeguarding processes.

12The FRC considers that a dedicated Appendix will support a more consistent approach to safeguarding assurance engagements, promote high-quality assurance work and enhance confidence in the safeguarding framework.

13The FRC has developed the proposals as an appendix to the CASS Assurance Standard rather than as a standalone standard. This approach reflects the fact that safeguarding and CASS assurance engagements are performed using a common assurance framework and involve many similar underlying assurance principles. The Appendix provides additional material tailored to safeguarding engagements while preserving consistency with the existing CASS Assurance Standard.

Invitation to Comment

14The FRC is requesting comments on this consultation by 26 November 2026.

15Comments are invited in writing on all aspects of the consultation and the proposed Appendix, particularly in relation to questions 1-5 as detailed below. Comments should be emailed to Sonya Patel at [email protected].

16Respondents are not expected to comment on every question and may choose to focus on those matters they consider most significant.

2. Summary of the proposal

1The proposed Appendix draws on the requirements and application material in the CASS Assurance Standard and develops them to address specific matters that are relevant to payment and e-money safeguarding engagements.

2The FRC concluded that a dedicated appendix was preferable to undertaking a broader revision of the CASS Assurance Standard. The Appendix enables safeguarding-specific requirements and application material to be introduced while retaining the existing assurance framework and avoiding unnecessary changes to parts of the standard that continue to operate as intended.

3The requirements and application material contained in the Appendix have been developed specifically for safeguarding assurance engagements within the payment services and e-money sectors. They should be interpreted in the context of those engagements and the underlying safeguarding regime. The Appendix does not create new expectations for other assurance engagements performed under the CASS Assurance Standard.

4The proposed Appendix builds on the interim guidance, both of which reflect feedback received from stakeholders throughout the development process. The Appendix seeks to provide a more comprehensive and permanent framework for safeguarding assurance engagements, while retaining a proportionate and scalable approach that can be applied across firms of different sizes and complexities.

5The FRC's primary objectives in developing the Appendix are to:

  • support consistent implementation of the FCA's safeguarding audit requirements;
  • promote high-quality safeguarding assurance engagements;
  • provide guidance tailored to the specific features and risks of safeguarding engagements;
  • support a proportionate and scalable approach to assurance work; and
  • enhance confidence in safeguarding arrangements and related assurance reporting.

6The Appendix includes guidance and application material relating to:

  • safeguarding-specific risk assessment;
  • governance and oversight arrangements;
  • safeguarding reconciliations and record keeping;
  • safeguarding accounts and relevant funds;
  • outsourced activities and third-party service providers;
  • technology-enabled safeguarding processes;
  • data integrity and completeness; and
  • reporting considerations relevant to safeguarding engagements.

7The proposals are intended to promote consistency in practice while allowing practitioners to apply professional judgement based on the size, complexity and nature of individual firms.

Technology-enabled safeguarding processes

8Stakeholder outreach highlighted the importance of technology to safeguarding arrangements within the payment services and e-money sectors. Many firms rely extensively on automated processes, interfaces between systems, reconciliation tools and outsourced technology platforms to identify, calculate, record and protect relevant funds.

9As a result, practitioners undertaking safeguarding engagements will often need to obtain an understanding of technology-enabled processes and the controls that support them. The Appendix therefore includes additional requirements and application material designed to assist practitioners in identifying and responding to technology-related risks within safeguarding engagements.

10The enhanced coverage in the Appendix reflects the particular characteristics of the safeguarding regime, its regulatory framework, feedback received from the working group, and the need to provide additional implementation support in an area where many firms operate highly automated business models.

11The FRC wishes to emphasise that the increased focus on technology within the Appendix should be understood only within the context of e-money engagements. It should not be interpreted as suggesting technology considerations are any less relevant to other assurance engagements performed under the Client Assets Sourcebook (CASS) Assurance Standard. Technology remains a key component of many CASS engagements and practitioners are expected to give appropriate consideration to technology risks and controls when performing those engagements.

Proposed effective date

12We are proposing an effective date for Appendix 13 for reports to the FCA with respect to relevant funds for periods commencing on or after 1 January 2028. Early adoption is permitted.

13In developing this proposal, the FRC considered feedback from stakeholders that an earlier effective date may not provide sufficient time for implementation. The proposed date is intended to allow firms and practitioners adequate time following publication of the final Appendix to update methodologies, develop or enhance relevant capabilities, and undertake the planning and interim work necessary for safeguarding audit engagements.

14The FRC also recognises that some practitioners currently performing safeguarding engagements under ISAE (UK) 3000-based methodologies may require time to transition to the CASS Assurance Standard framework. In addition, the proposed implementation timetable seeks to support an orderly transition across the market, taking into account capacity and competition considerations.

Consequential amendments to the CASS Assurance Standard

15Alongside the final publication of Appendix 13, the FRC intends to make a small number of consequential amendments to the CASS Assurance Standard. These amendments will not change the scope, requirements or application of the Standard, and do not represent a revision of the CASS Assurance Standard. Rather, they will update references within the CASS Standard that have become outdated as a result of changes to auditing standards and related guidance (for example, quality management has replaced quality control).

16The FRC does not expect these amendments to have a substantive impact on existing CASS assurance engagements or on the nature and extent of assurance procedures performed under the CASS Assurance Standard.

3. Request for Comments

Consultation Questions

1Do you agree that the proposed Payment and E-Money Safeguarding Assurance Appendix provides an appropriate framework to support consistent implementation of the FCA's safeguarding audit requirements?

If not, please explain why.

2Do you agree that the proposed Appendix appropriately addresses the principal risks and characteristics of safeguarding arrangements operated by payment services and e-money firms?

If not, please identify any areas that should be added, removed or amended.

3Do you agree with the proposed requirements and application material?

If not, please explain your reasons.

4Do you agree that the proposed Appendix can be applied in a manner that is proportionate to firms of different sizes and complexities?

If not, please explain your concerns.

5Do you have any other comments on the proposed Appendix, in particular in relation to implementation challenges or costs that the FRC should consider?

Comments relating to the existing requirements of the CASS Assurance Standard fall outside the scope of this consultation, as do comments on the FCA's Rules.

Responses should be sent to [email protected] and marked for the attention of Sonya Patel. Responses should be received by 26 November 2026.

4. Impact Assessment

Impact on Practitioners and Firms

1The FRC recognises that firms within the payment services and e-money sectors vary significantly in size and complexity. The requirement for certain firms to obtain a safeguarding audit is established by the FCA's rules, and the cost and benefits arising from that framework has already been part of the FCA's own due process. In developing the proposed Appendix, the FRC has sought to support the performance of these engagements in a manner that is proportionate and scalable, while remaining consistent with the requirements of the FCA's safeguarding regime.

2The Appendix has therefore been developed with a view to supporting scalable and proportionate assurance engagements. The FRC does not intend the proposals to create unnecessary additional requirements or burdens on preparers beyond those arising from the FCA's rules. Rather, the proposals aim to provide practitioners with guidance and application material tailored to common safeguarding arrangements and emerging risks observed across the sector.

3Practitioners may need to consider whether additional training, methodologies or specialist expertise are required in areas such as technology-enabled controls, data flows and outsourced service arrangements. However, the FRC believes these considerations are consistent with the evolving nature of safeguarding engagements and the underlying risks associated with the protection of customer funds.

4The implementation considerations described above relate to the introduction of safeguarding audit engagements and the transition to the proposed Appendix. They are not intended to imply a change in the scope or nature of procedures that may be required on other assurance engagements, including CASS engagements, which should continue to be planned and performed based on the applicable assurance framework and the specific facts and circumstances of each engagement.

Relationship with Existing CASS Assurance Engagements

5The proposed Appendix has been developed specifically to support safeguarding audit engagements within the payment services and e-money sectors. The FRC does not expect the Appendix, in itself, to necessitate changes to the scope of assurance procedures performed for CASS engagements.

6Assurance engagements should continue to be designed in accordance with the requirements of the applicable assurance framework and the specific risks and circumstances of the engagement. The inclusion of additional application material relating to technology, outsourcing and data integrity within this Appendix reflects the characteristics of safeguarding engagements and should not be interpreted as creating new expectations for unrelated assurance engagements.

7The FRC therefore does not expect the introduction of the Appendix to result in any additional costs for firms subject solely to existing CASS assurance requirements.

Financial Reporting Council

London office: 13th Floor, 1 Harbour Exchange Square, London, E14 9GE

Birmingham office: 5th Floor, 3 Arena Central, Bridge Street, Birmingham, B1 2AX

+44 (0)20 7492 2300

www.frc.org.uk

Follow us on Linked in

File

Name Safeguarding Assurance for Payment and E-Money Institutions - Appendix 13 to the CASS Assurance Standard: Invitation to comment
Publication date 30 September 2026
Type Consultation paper
Format PDF, 227.5 KB