The new CASS 15 safeguarding regime has now been in force for several months.
For payment and e-money firms, much of the last year has understandably been about implementation. Policies have been rewritten, safeguarding arrangements reviewed, reconciliations redesigned and new reporting requirements considered.
That work was necessary and, indeed, for some may still be ongoing.
It is not, however, the same thing as demonstrating that the new framework actually works.
There is a useful distinction between implementation and effectiveness. A firm can have a well drafted safeguarding policy, a reconciliation procedure that appears to tick every regulatory box and a project plan marked “complete” and yet still have a process which struggles when the unexpected occurs.
So now that CASS 15 is operating in the real world, firms should be moving from implementation testing to control effectiveness testing.
So, what might this look like?
In practical terms, we would expect a firm’s post-implementation review to include at least the following eight tests.
CAN YOU REPRODUCE THE SAFEGUARDING REQUIREMENT?
Start with the number that matters.
Take a sample day and attempt to reproduce the firm’s safeguarding requirement from the underlying customer and transaction data. Do not start with the reconciliation report. Start further upstream.
Under the standard method, the safeguarding requirement comprises individual safeguarding balances, ignoring negative balances, together with amounts received but not yet allocated to an individual client. The individual safeguarding balance should capture the total amount the firm should be safeguarding for that client.
That gives firms a useful testing question: can we independently reproduce the number?
How does the firm identify relevant funds? How are individual client balances calculated? How are unallocated relevant funds captured? Are different currencies treated correctly? Can the final figure be traced back to the underlying transactions?
The important point is that the calculation should not depend upon the person who prepared it to be available to explain it.
If the safeguarding requirement can only really be understood by the person who built the spreadsheet, that is probably not the level of control evidence a firm should be aiming for.
CAN YOU PROVE THAT THE SAFEGUARDING RESOURCE IS CORRECT?
The safeguarding requirement tells you what should be protected.
The safeguarding resource tells you what the firm actually has available to meet that requirement.
The internal safeguarding reconciliation should establish whether the safeguarding resource is equal to the safeguarding requirement at the reconciliation point, with the safeguarding resource calculated using the firm’s relevant safeguarding arrangements.
That means testing the other side of the reconciliation with the same degree of scepticism.
Select sample dates and trace the safeguarding resource back to independent evidence such as bank statements, account records, confirmations and, where relevant, evidence supporting other safeguarding arrangements.
But do not stop at checking whether the bank balance agrees: test timing.
Was the balance taken at the correct point in time? Does it correspond with the population of relevant funds being tested? Were transfers between safeguarding accounts, operating accounts or currencies reflected correctly?
A reconciliation can be mathematically perfect and still be wrong because the two sides relate to different points in time.
That is precisely the sort of issue a post-implementation review should be designed to find.
BREAK THE RECONCILIATION.
One of the best ways to test a reconciliation is to stop looking only at days when everything agrees. Look at the exceptions.
Take an unmatched transaction, an unexpected receipt, an FX difference or a bank movement which does not appear in the firm’s ledger and follow what happened.
Who identified the difference? Who investigated it? Who decided how it should be treated? How quickly was it resolved? What evidence was retained? And, importantly, did the same problem happen again?
A safeguarding control should not be judged solely by how well it performs when nothing goes wrong.
The more revealing test is what happens when something does.
TEST THE CLOCK, NOT JUST THE CALCULATION.
Safeguarding is partly a calculation exercise, but it is also a timing exercise.
Relevant funds received by a safeguarding institution should be allocated to an individual client promptly and, in any event, no later than the end of the business day following receipt, subject to the specific provisions of the rules.
A firm’s processes should therefore be tested using actual transaction timestamps.
Take a sample of funds entering the business and follow them through the process: receipt, identification, allocation, safeguarding and reconciliation.
Then establish when each event actually occurred.
This is particularly important where different systems operate to different timetables. A processor may produce a transaction report at one point in the day while the corresponding bank balance becomes available later. A payment may therefore appear in one part of the reconciliation population before it appears in another.
That does not automatically mean the process is deficient. It does mean the firm needs to understand the difference, control it and demonstrate why the resulting safeguarding position remains accurate.
A policy saying that something happens “daily” is not evidence that it happens at the right time.
FOLLOW THE MONEY THROUGH THE THIRD PARTIES.
Payment firms rarely operate entirely within their own four walls.
That makes third-party dependencies an important part of post-implementation testing.
Where a critical reconciliation input comes from a processor, banking partner, payment platform, agent or other outsourced service provider, the firm should understand where that data originates, what exactly is being received and how its completeness and accuracy are checked.
It should also be clear what happens when the file arrives late, is incomplete or does not agree with the firm’s own records.
It cannot be repeated often enough that the fact that a process is outsourced does not mean that the firm’s responsibility for safeguarding has been outsourced.
If the firm’s safeguarding calculation depends upon another organisation producing an accurate file at the right time, that dependency is itself a control which should be tested.
TEST THE UNCOMFORTABLE SCENARIOS.
A good post-implementation review should not simply select routine transactions.
It should deliberately look at the situations most likely to expose weaknesses.
What happens if a customer pays twice? What happens if a payment is received but not allocated? What happens if the safeguarding account is debited incorrectly? What happens if a transaction appears after the reconciliation cut-off? What happens if a bank transfer is delayed? What happens if a third party’s report is incomplete? And what happens if the safeguarding resource falls below the safeguarding requirement?
The purpose of testing these scenarios is not to manufacture theoretical problems.
It is to establish whether the firm has thought through the operational consequences of an actual exception, and whether the documented response matches what would happen in practice.
There is a considerable difference between a procedure which says, “escalate the issue” and a process which identifies who escalates it, to whom, within what timeframe, using what information, and what happens next.
ASK THE BOARD WHAT IT ACTUALLY KNOWS.
Safeguarding is not simply a finance or operations issue.
Responsibility for oversight of safeguarding, including reporting to the governing board, should be allocated to a single director or senior manager with sufficient skill and authority.
The FCA also expects firms to maintain organisational arrangements sufficient to minimise the risk of the loss or diminution of relevant funds or assets through fraud, misuse, negligence or poor administration. This requirement pre-dates CASS 15 and remains an important prop for the safeguarding regime as a whole.
All the above makes management information another important area for testing.
Take the information that reaches the Board or relevant committee and ask a relatively simple question:
Would this tell us if the safeguarding framework was beginning to fail?
A statement that reconciliations were completed is unlikely to be enough on its own. Senior management should have sufficient visibility of exceptions, unresolved discrepancies, shortfalls or near misses, recurring timing issues, third-party failures and outstanding remediation to understand whether the control environment is operating as intended.
The objective is not to produce more MI for the sake of it.
It is to ensure that senior management has enough information to identify when a control is deteriorating before it becomes a customer-impacting problem.
TAKE THE EVIDENCE AWAY FROM THE PERSON WHO OWNS THE PROCESS.
This is perhaps the simplest test of all.
Take a completed safeguarding reconciliation from several months ago and give it to someone who was not involved in preparing it.
Can they establish what the safeguarding requirement was, what the safeguarding resource was, what data was used, when the reconciliation took place, whether there were any discrepancies, how those discrepancies were resolved and who reviewed the outcome?
Firms should retain sufficient evidence of their safeguarding reconciliations to demonstrate when the process took place, what was done, the outcome and, where relevant, the safeguarding resource calculation and D+1 comparison. They should also maintain records and accounts sufficient to distinguish relevant funds from other funds and to ensure their accuracy and correspondence to relevant funds held for clients.
If the evidence does not allow someone independent to understand what happened, the firm may have a functioning process but an inadequate evidence trail.
That distinction matters.
Under the new regime, firms need to be able to demonstrate not merely that they believe their safeguarding arrangements work, but that they have appropriate evidence to support that conclusion.
CONCLUSION: FROM “IMPLEMENTED” TO “EMBEDDED.”
These eight tests have a common theme.
They move the assessment of CASS 15 away from: “have we implemented the new requirements?” towards: “can we demonstrate that the controls are operating effectively?”
That is an important change in mindset.
Implementation testing tends to focus on policies, procedures, systems and governance arrangements.
Effectiveness testing follows the process into the real world. It looks at actual transactions, actual bank balances, actual timestamps, actual exceptions and actual evidence.
The firms which should be most comfortable with CASS 15 are not necessarily those with the longest safeguarding policies or the most elaborate reconciliation spreadsheets. They are the firms that can take an apparently ordinary day, reproduce their safeguarding position from the underlying records, explain the differences and demonstrate what happens when the process does not go according to plan.
That is what being CASS 15 compliant in practice should look like.
And, rather usefully, it is also something that can be tested.
Want to know more about CASS 15 and the new safeguarding regime? Please contact our industry-leading experts at Cosegic.