Why audit trails matter under CASS 15

Under the safeguarding regime, doing the work is not the same as being able to prove the work was done. The audit trail has quietly become the mechanism through which compliance is judged.

Ask a safeguarding lead in a payments or e-money firm whether the reconciliation ran yesterday, and the answer is almost always yes. Ask whether the shortfall found on Tuesday morning was corrected, and the answer is almost always yes. Ask whether the sign-off on that correction was recorded at the right level, whether the acknowledgement letter for the safeguarding account is current, whether the resolution pack reflects the state of things as of close of business Thursday, and the answer becomes slower and more qualified. Ask whether all of that could be evidenced, cleanly, to a CASS auditor next month, without reconstructing anything, and the answer often changes altogether.

That gap between having done the work and being able to demonstrate having done the work is where CASS 15 has quietly moved the ground under firms’ feet. The regime has always cared about outcomes. What is different now is that it also cares, in a specific and enforceable way, about the trail behind those outcomes. Records must be complete. Sign-offs must be attributable. Evidence must be produced without delay. The audit trail is no longer the paperwork behind the work. It is the evidence that the work happened.

This article is about why that shift matters. It matters because the burden of proof has moved. It matters because audit trails and the controls they record are two halves of the same sentence: neither is credible on its own. And it matters because the annual safeguarding audit under SUP 3A now provides the eventual test of both, in a form that leaves less room than firms sometimes assume for a plausible explanation of missing evidence.

What the regime actually expects on the record

Before the argument, a short grounding in what the rules ask for. Under CASS 15, introduced by Policy Statement PS25/12 and in force since 7 May 2026, firms must maintain books and records that identify relevant funds at any time, without delay. Reconciliation activity on each reconciliation day, the investigation and correction of any shortfall, the acknowledgement letters that govern safeguarding accounts, the mandatory documents that populate the resolution pack under CASS 10A, and the sign-off trail that runs through all of it are expected to be current, complete and available. The chapter does not treat records as an administrative byproduct of the operational work. It treats them as evidence that the operational work took place.

Sitting behind the day-to-day expectation is the annual safeguarding audit under SUP 3A. Firms holding relevant funds above the exempted threshold must arrange for a qualified auditor to conduct the audit and to report on whether the firm has complied with the safeguarding requirements. That report is not a private matter between the firm and its auditor. It goes to the FCA, which uses it as one of the more concrete inputs into how confident it is that customer money is properly protected. The auditor is looking for evidence that the controls the firm claims to operate actually produced the outcomes the firm claims they produced.

Between them, CASS 15 and SUP 3A make one thing clear. The regime has moved from asking whether the firm has controls to asking whether the firm can prove those controls operated.

The burden of proof has moved

The shift is subtle but complete. Under the previous position, a firm that did the work and could describe what it had done was, broadly, in a defensible place. If the reconciliation had run, and the person who ran it could explain how, that was often enough for internal purposes and, up to a point, for external ones. Under CASS 15, that position has narrowed. The firm still has to do the work. It also has to be able to show, in a form an auditor accepts, that the work was done, when it was done, by whom, and what it produced.

That is a genuinely different bar. Doing the reconciliation is not the same as having a timestamped, attributable record of the reconciliation running. Correcting a shortfall is not the same as being able to show the correction happened within the window the firm’s own policy requires. Maintaining an acknowledgement letter is not the same as being able to demonstrate that the letter reflects the current arrangements with the bank. Each of those gaps is small in isolation. Across a full audit cycle, and across the range of activity CASS 15 covers, they aggregate into a picture that either persuades the auditor or does not.

There is a specific pattern that experienced auditors recognise quickly. A firm that has done the work but has not built an audit trail commensurate with it tends to answer questions with a mix of description and reconstruction. The reconciliation ran; here is the person who ran it; here is an email confirming they did. The break was corrected; here is a screenshot of the current balance; here is the person who remembers approving it. The letters are up to date; here is the file where we keep them; the most recent one is from March, we think. None of this is dishonest, and much of it is broadly accurate. It is also, from an evidentiary standpoint, thin. What the regime asks for, and what an auditor will look for, is a trail that stands on its own without the person who created it standing next to it.

Audit trails and controls are the same sentence

A common mistake is to think of controls and audit trails as separate things. They are not. A control without an audit trail is only credible for as long as the person who operated it remembers what they did. An audit trail without a control is theatre: a record of activity that has no discipline behind it. The two are inseparable, and firms that treat them separately tend to build one at the expense of the other.

Consider a four-eyes sign-off on a shortfall correction. As a control, it is straightforward. The person who identifies the shortfall proposes the correction; a second person, with the appropriate authority, reviews and approves it before it is made. That is the control. The audit trail is the timestamped, attributable record of both steps: who proposed, who approved, when, and against what supporting evidence. If the control operates but the trail is not captured, the firm has done the right thing and cannot prove it. If the trail is captured but the control did not actually operate as designed, the firm has a record of activity with no discipline behind it. Either failure mode, presented to an auditor, produces the same response: this control cannot be relied upon.

What good looks like is easier to describe than to build. A strong audit trail is attributable, so every action is tied to a specific person or role rather than a shared login. It is timestamped, so the sequence of actions is unambiguous rather than reconstructed. It is sequential and complete, so each stage of a process produces its own record rather than being folded into a summary at the end. And it is unalterable in the sense that matters: past entries cannot be quietly edited to fix a problem the firm noticed later. Shared logins, editable spreadsheets, screenshots taken after the fact and summaries written from memory each fail one or more of these tests. The trail that survives an audit is the one that was captured as the work happened, by the systems that did the work, in a form that does not depend on anyone’s later description of events.

What SUP 3A auditors look for

An auditor conducting a safeguarding audit under SUP 3A is not looking for something exotic. The auditor is looking for evidence that specific things happened in specific ways over the period under review. In broad terms, and without pretending to speak for individual firms, that evidence typically includes the following.

Evidence that internal and external reconciliation ran on each reconciliation day, in a form that shows both sides of the comparison and the outcome. Evidence that any shortfall between the segregation requirement and the segregation resource was corrected promptly, with the mechanism of correction visible in the record. Evidence that discrepancies below the reporting threshold were nonetheless investigated and closed, so the firm’s own threshold policy is applied consistently rather than selectively. Evidence that sign-off happened at the level the firm’s policy required, by a person with the appropriate authority, not simply the person who was available. Evidence that mandatory documents in the resolution pack are current, that acknowledgement letters reflect the actual arrangements with banks, and that changes to any of the above are themselves recorded and dated.

What a firm that passes looks like, at a high level, is a firm whose audit trail is not different in character from its day-to-day operational activity. The two are the same activity, captured in the same place, in the same form, at the same time. Questions from the auditor tend to be answered by producing records rather than describing what happened. Discrepancies, where they exist, are ones the firm has already identified, investigated and closed.

What a firm that fails looks like, at a similarly high level, is a firm whose operational activity was probably fine but whose evidentiary support is thin. Records are recognisable but incomplete. Sign-offs are described but not attributable. The story is broadly plausible but requires the firm to fill in the pieces the record does not show. That gap is what auditors report on, and it is what firms most consistently underestimate until the report lands on the FCA’s desk.

What this changes in practice

Read together, the shifted burden of proof, the inseparability of controls and audit trails and the way SUP 3A audits are conducted describe a fairly specific operational requirement. The firm’s work and the firm’s record of the work should be the same activity, captured in the same place, as the work happens. Retrospective assembly, however careful, is a poor substitute.

This is the work Imperium(L) Prism is built for. Every reconciliation, every break resolution stage, every sign-off, every configuration change and every user action is captured, timestamped and attributable inside the platform. Role-based access controls determine who can do what, so segregation of duty is built into the system rather than relying on shared logins. Multi-tier sign-off enforces the firm’s own policy on who approves what, at what level. Mandatory-document tracking against the resolution pack surfaces gaps continuously rather than at audit. The audit trail is not something the firm produces at year end. It is a byproduct of running the system, which is exactly the form the regime and the auditor now expect it to take. The technology behind Prism has supported businesses in live, high-volume environments for over 12 years, so the operational logic has already been tested against real reconciliations and real audits.

Under CASS 15, the audit trail has quietly stopped being the paperwork behind the work. It has become the evidence that the work happened, and it is judged on its own terms. Firms that build their audit trail as a byproduct of running their controls, in a system that captures activity as it happens, tend to find that SUP 3A audits are exercises in retrieval rather than reconstruction. Firms that build their audit trail as an afterthought tend to find that the auditor’s report writes itself, and not in the direction they would have chosen.

Frequently Asked Questions

What is SUP 3A, and does it apply to every payments or e-money firm?

SUP 3A is the chapter of the FCA Handbook that sets out the annual safeguarding audit requirement for payments and e-money firms holding relevant funds. Under the arrangements introduced by Policy Statement PS25/12, firms whose relevant funds do not exceed £100,000 are exempt from the audit requirement. Firms above that threshold must arrange for a qualified auditor to carry out the safeguarding audit and produce a report, which goes to the FCA.

At a general level, an auditor will typically look for evidence that internal and external reconciliation ran on each reconciliation day, that shortfalls between the segregation requirement and the segregation resource were corrected promptly, that discrepancies were investigated and closed consistently against the firm’s own threshold policy, that sign-off happened at the appropriate level, and that mandatory documents in the resolution pack (including acknowledgement letters) are current and reflect actual arrangements. The specifics vary by audit firm and by engagement.

A defensible audit trail is attributable, so every action is tied to a specific person or role rather than a shared login. It is timestamped, so the sequence of actions is unambiguous. It is sequential and complete, so each stage of a process produces its own record rather than being folded into a summary. And it is captured as the work happens, by the systems that did the work, rather than reconstructed later from memory, screenshots or summaries.

Shared logins break the attributability that an audit trail depends on: if two or more people use the same credentials, no action can be tied cleanly to a specific person. That failure mode is one of the more common sources of findings in CASS reviews. Individual user accounts, with role-based access controls that determine what each user can do, are the practical route to a defensible trail.

Scroll to Top