Blogs

The CASS 15 Deadline Was Not The End Destination

The May 7th CASS 15 deadline has now passed. For many payments and e-money firms, the months leading up to it would have focused on gap analyses, policy rewrites and the pressure to produce something auditable in case regulators came knocking.  

That work was necessary. But for many firms, it was also incomplete. Meeting the deadline and operating to the standard the regulatory body set are not the same thing-and the gap between the two will become increasingly visible over the next twelve months. 

 

Compliance is not a fixed point in time 

CASS 15 is not a project with a defined end date. The rules that came into force are an ongoing obligation to ensure customer funds are properly protected. That means maintaining controls that work in practice, not just on paper.   

Regulators have been clear: firms can have inadequate systems yet avoid any visible problem due to circumstances. But that does not mean they are compliant. The absence of a reported breach is not evidence that controls are effective.  

This matters because scrutiny is increasing and audit cycles are beginning to run. Firms that treated May 7th as the finish line are already falling behind, and those still working through foundational gaps are entering breach territory. Where compliance issues exist, it is always better to engage proactively with the FCA than have deficiencies uncovered during an audit. 

 

Post-deadline problems 

  1. Data quality drift 

Safeguarding reconciliations are only as reliable as the data feeding them.  

As firms scale, data sources evolve, file formats change, and new systems are introduced. Without active governance, inconsistencies will creep in. A reconciliation process that worked at go-live can degrade over time, often without anyone noticing or immediate visibility. 

 

2.  Weak change management 

Safeguarding obligations apply to the whole business, not just the team owning reconciliations.  

New products, new geographies and new systems all introduce risk.  When compliance is treated as a siloed responsibility, gaps are inevitable.   

The FCA previously acted against a firm where the same people making payments from client accounts were also the ones checking whether those payments were correct. Nobody noticed because nobody was looking. No money went missing. But the firm was still penalised, because the risk of it happening had been real and unmanaged the entire time, and critical controls, such as segregation of duties, were absent.  

 

3. Insufficient audit evidence 

The first wave of CASS 15 audits will test whether controls have operated consistently over time, not just whether they exist today. Firms will need: 

  • Sign-off records 
  • Comprehensive breach logs 
  • Documented control testing  
  • Ongoing management attestations  

All requirements need to show continuous operation, not a burst of activity in the weeks before an auditor arrives.  

Regulators have asked firms for months of granular transactional data and questioned individual transaction records. Firms relying on manual processes or spreadsheet-based controls will find it very hard to respond at that level of detail and scrutiny. 

 

The first real test is closer than firms think 

Firms will need to make their first Safeguarding Return to the FCA by the 15th business day of July –  21st July. The accuracy of internal safeguarding reconciliations throughout the month will directly inform that submission. 

This is the regulator’s first opportunity to gauge how prepared payments firms are under the new regime. Firms relying on manual processes or spreadsheet-based controls will find it very hard to respond at that level of detail and scrutiny required. 

 

So, what do firms need to do now?  

For firms that crossed the deadline, the priority is stress-testing what was built. Has every business change since go-live been assessed for CASS impact? Are reconciliations running continuously, or still in batch? Does the governance framework reflect how the business operates today, or how it operated when the policies were written? 

The firms that invested properly in their underlying infrastructure, such as automated reconciliation, clean data governance and segregation of duties, are well placed.  

For those that ‘got over the line’, but know the foundations are not yet robust, the next twelve months are a critical window to fix that. The first audit cycle will expose gaps. Firms that find and address those gaps now will have a very different experience from those that wait to be told about them. There is a significant difference between telling your auditor what you found and having your auditor tell you. 

The May 7th deadline was not the end. It was a starting point. Firms that treat CASS 15 as an ongoing compliance programme will be far better positioned as regulatory scrutiny increases. Because in reality, compliance is not about passing a deadline, it is about proving daily your controls actually work. 

 

This blog was written by Kieran Millar, Principal Product Manager, AutoRek