What happens after a reconciliation break is found?

Most firms have some form of reconciliation. The weakest link is what happens after a break is found: who owns it, what they do about it, and how it feeds into a resolution pack that has to be current, not archived.

A reconciliation break appears at 09:42 on a Tuesday. The internal comparison between what the customer ledger says the firm owes and what the safeguarding records say it holds no longer agrees. The gap is small, £412 across three transactions in one currency, and if the firm is paying attention, someone in the operations team sees it before their coffee is finished. What happens in the next hour is where CASS 15 firms are quietly separated into two groups.

The first group has a clear answer to a specific set of questions. Who owns this break, right now? What is its severity? By when does it need to be corrected? Who will investigate the cause? What evidence needs to be gathered along the way? Who signs it off, and what qualifies as closed? The break enters a defined workflow that leaves nothing to memory or chance.

The second group has some of those answers, some of the time, and a shared assumption that someone will look at it. The break enters an email thread. Sometimes a spreadsheet. Sometimes both. It usually gets resolved, eventually, but the trail behind that resolution is thinner than it needs to be, and no one in the firm could tell an auditor with complete confidence when the break was first spotted, who investigated it, or when it was actually closed.

Under CASS 15, finding the break is the easy part. The hard part is what happens next, and it is the part firms most consistently underestimate.

What CASS 15 and CASS 10A actually expect

Before the argument, a short grounding in what the regime asks for. The safeguarding chapter introduced by Policy Statement PS25/12 is clear about the immediate obligation. Where a firm identifies a shortfall between what it should be holding for its customers and what it actually holds, that shortfall is to be corrected promptly, the investigation into cause is to be evidenced, and the correction itself is to be recorded. The obligation does not distinguish sharply between small breaks and large ones for the purpose of finding and correcting them. Whether or not a specific breach must be individually notified to the FCA depends on materiality, resolution status and what it says about the firm’s controls, but the internal process of investigation, correction and evidence applies across the board.

Sitting alongside this is the resolution pack expectation in CASS 10A. A resolution pack is not, or should not be, a filed document. It is the firm’s live capability to identify relevant funds and return them to customers quickly if the firm fails. Mandatory documents, from account documentation and acknowledgement letters to reconciliation records and evidence of break resolution, are expected to be current, complete and ready to be used at short notice. What connects CASS 15 and CASS 10A operationally is straightforward. The resolution pack draws its confidence from the state of the firm’s day-to-day reconciliation and break resolution. If the break resolution is patchy, the resolution pack is untrustworthy, whatever the file it sits in says.

Ownership is the weak link

Most payments and e-money firms already have some form of reconciliation. What separates the ones that hold up under a CASS audit from the ones that don’t is not usually the reconciliation itself, but what happens to a break the moment it is found. The most common weakness we see is that a break has no clear owner.

“Someone will look at it” is not ownership. Ownership means a named person, or a named role covered by a named deputy, whose responsibility it is to move the break through investigation, correction, evidence and sign-off to closure, within a defined time, with a clear escalation path if any of those steps stalls. Without ownership, breaks tend to move sideways rather than forwards. They enter shared inboxes, group chats and multi-recipient emails, and each person who reads them assumes another person is dealing with them. Sometimes the assumption is right. Often it is not, until the reconciliation runs again the next day and the break is still there.

Ownership is not the same as authority. Some breaks require sign-off from a senior manager, notification to compliance or, in specific cases, notification to the FCA. Ownership is the operational thread that runs from first identification to formal closure. It says who is responsible for making sure each step happens, in order, with the appropriate escalation. Authority is what happens at each step. Both matter. Firms that confuse them, or that combine them into a single person who is expected to do everything, tend to find that breaks either move too slowly or bypass the checks that give the closure its credibility.

A properly-owned break carries five pieces of information from the moment it is opened: an owner, a severity, a deadline, an escalation path and a defined closure test. Firms that make sure every break carries all five, every time, find that resolution stops being ad hoc. Firms that leave any of them implicit find that resolution is only as reliable as the individual on shift that morning.

The stages of a defensible break resolution

Under that ownership, five stages describe what a defensible break resolution actually looks like in practice.

Investigation comes first. Understand what caused the discrepancy: an FX conversion error, a duplicate transaction, a missed refund, a late acknowledgement from a payment processor, a bank fee not accounted for in the internal cashbook. The cause matters more than the number. Two breaks of the same value can carry very different levels of risk depending on what produced them.

Correction is next. Where the segregation resource is below the segregation requirement, the shortfall is to be topped up promptly. That is not a monthly adjustment. It is an operational action, taken as soon as the shortfall is confirmed, with the mechanism recorded. Where the discrepancy is a matter of records not agreeing rather than money being wrong, the correction is to the records, but the same principle applies: prompt, mechanical, evidenced.

Evidence gathering runs alongside both. The evidence is not a summary produced after the fact. It is the trail of the underlying activity: system logs, bank confirmations, internal notes, the reconciliation outputs before and after, the timestamps of every action. Firms that leave evidence to the end find that they are reconstructing it. Firms that capture it as they go find that it is already there when it is needed.

Escalation and notification follow, where required. Some breaks stay within the operations team. Others require sign-off from a senior manager, notification to compliance or, where the regime’s reporting expectations are engaged, notification to the FCA. This step is not a matter of individual judgement in isolation. It should follow a defined threshold policy so that the trigger is the same regardless of who is on shift.

Sign-off and closure complete the cycle. A break is not closed because someone marks it closed. It is closed because a defined closure test has been met: the correction is in place, the evidence is captured, the sign-off has been recorded at the level the severity requires, and any downstream reporting has been triggered. Anything less leaves the break formally open, which is where auditors expect to see rigour and where boards expect to see risk.

The resolution pack is a daily readiness exercise, not an archive

CASS 10A introduces the resolution pack expectation, and most firms still misread it as a periodic document that lives in a folder somewhere until the auditor asks for it. It is not. It is the firm’s live ability to identify relevant funds and return them to customers quickly if the firm fails. Everything in the pack, from account documentation and acknowledgement letters to reconciliation records and evidence of break resolution, is expected to be current, complete and usable at short notice.

The connection to break resolution is the connective tissue. Every break that is investigated, corrected, evidenced and signed off contributes to the reliability of the pack, because it demonstrates that the firm knows what it is holding, why, and how any discrepancies have been handled. Every break that lingers, or is closed without a proper trail, weakens the pack by exactly the amount it would take to reconstruct that story under time pressure.

Most firms discover the gap between what a resolution pack says and what the underlying operational reality can support only when an auditor or the FCA asks a specific question. Which acknowledgement letter is missing. Which reconciliation break has no evidence of sign-off. Which mandatory document has not been updated since the account changed. The firms that answer cleanly are the ones that have treated the pack as something that gets a little more accurate every day, not something that gets pulled together at year end.

The practical problem most firms face is not a shortage of data. The data exists. It is simply spread across customer ledgers, bank portals, payment processor exports, spreadsheets and the working memory of whoever ran the last reconciliation. Assembling that picture once a month is demanding enough. Assembling it every business day, to a standard that survives an audit, is a different order of task altogether. That is the operational control challenge PS25/12 has created, and it is precisely the part that never appears on the face of the return.

What this changes in practice

Read together, ownership, staged resolution and a daily resolution pack describe an operational rhythm that is genuinely different from break management run through spreadsheets and email threads. It is a specific set of habits: every break carries an owner, a severity, a deadline, an escalation path and a closure test; every stage produces evidence as it happens rather than after; every closure feeds into a resolution pack that is treated as live rather than filed.

This is the work Imperium(L) Prism is built for. Prism wraps every reconciliation break in a structured workflow: owner, severity, deadline, evidence, escalation and sign-off, with a timestamped audit trail of every action. Resolution-pack completeness is tracked continuously against a mandatory-document checklist, so gaps surface immediately rather than at audit. The evidence trail is captured automatically inside the system, not reconstructed from workbooks and emails after the fact. The technology behind Prism has supported businesses in live, high-volume environments for over 12 years, so the operational logic has already been tested against real reconciliations and real audits.

Finding a reconciliation break under CASS 15 is now the easy part. The hard part, the part that decides how a CASS audit reads, is what happens between the moment the break appears and the moment a defined closure test is met. Firms that make that part of the work a disciplined workflow tend to find that resolution stops eating their operations time. Firms that leave it to memory, judgement and shared inboxes tend to find, at audit, that memory, judgement and shared inboxes are exactly what auditors do not accept as evidence.

Frequently Asked Questions

What is a resolution pack under CASS 10A?

A resolution pack is the set of records and documents that would allow relevant funds to be identified and returned to customers quickly if the firm failed. Under CASS 10A, mandatory documents including account documentation, acknowledgement letters, reconciliation records and evidence of break resolution are expected to be current, complete and ready to be used at short notice. It is a live operational capability, not a filed document.

No. Every reconciliation break identified on a reconciliation day has to be investigated, corrected promptly if a shortfall exists, and evidenced internally. Whether a specific breach must be individually notified to the FCA depends on its materiality, its resolution status and what it indicates about the firm’s controls. Firms should follow a defined threshold policy so that the notification trigger is consistent regardless of who is on shift.

A break should have a named owner, or a named role covered by a named deputy, whose responsibility it is to move the break through investigation, correction, evidence and sign-off to closure, within a defined time, with a clear escalation path. Ownership is the operational thread from identification to closure. It is distinct from authority, which is what happens at each individual step, such as sign-off or notification.

Five stages: investigation, to understand the cause; correction, to top up any shortfall or fix the records; evidence gathering, captured as the work happens rather than reconstructed after; escalation and notification where required, following a defined threshold policy; and sign-off and closure against a defined closure test. A break is not closed because someone marks it closed. It is closed because the closure test has been met.

Scroll to Top