Hatch resource banner image for How to conduct an external safeguarding audit

How to conduct an external safeguarding audit

An external safeguarding audit provides the FCA with independent proof that your business is correctly protecting customer funds from risk.

To complete an external safeguarding audit, you must appoint an independent auditor with specific expertise in the Payment Services Regulations (PSRs) or Electronic Money Regulations (EMRs) to review how you protect customer money. The core goal is to produce a formal report for the Financial Conduct Authority (FCA) that confirms your systems, controls, and records are robust enough to keep client funds safe and separate from your own business capital.

Why this audit matters

Safeguarding is a cornerstone of the UK’s financial regulatory regime. If your business is an Authorised Payment Institution (API) or an Electronic Money Institution (EMI), you have a legal duty to safeguard "relevant funds." This ensures that if your business were to become insolvent, customer money is protected and can be returned to them as quickly as possible. The FCA requires an annual independent audit to verify that you aren't just saying you safeguard money, but that you are actually doing it correctly in practice.

Step 1: Choose the right auditor

You cannot use just any accountant for this task. The FCA expects the auditor to be independent (not your internal compliance officer or a close business partner) and to possess significant expertise in the specific regulations governing payments. When selecting your auditor, ask for:

  • Evidence of previous safeguarding audits they have conducted.
  • Confirmation of their understanding of the FCA's Approach Document regarding safeguarding.
  • A clear breakdown of their methodology for testing your controls.

Step 2: Review your safeguarding methods

Before the auditor arrives, ensure you have clearly documented which safeguarding method you use. Most firms use one of two methods:

  1. The Segregation Method: Keeping customer funds in a dedicated account at an authorised bank, separate from your own business money.
  2. The Insurance/Guarantee Method: Protecting funds via an insurance policy or a guarantee from an authorised insurer or bank.

The auditor will check that your chosen method is applied correctly every single day, not just on the day of the audit. They will look for "segregation of duties," meaning the person who reconciles the accounts isn't the same person who can authorise payments out of them.

Step 3: Prepare your documentation

The auditor will need to see a clear paper trail. To make the process smoother, prepare a folder containing:

  • Acknowledgement letters: Confirmations from your bank that they have no right of set-off against your safeguarding accounts.
  • Reconciliation records: Daily or periodic logs showing that the money in your bank accounts matches the money owed to customers.
  • Governance documents: Minutes from board meetings where safeguarding risks were discussed.
  • Breach logs: Evidence of any times safeguarding didn't go as planned and how you fixed it.

Step 4: The audit process and report

The auditor will perform "substantive testing." This involves looking at specific transactions to see how the money moved from the customer, through your platform, and into a safeguarded environment. They will also interview key staff to ensure the culture of the business prioritises customer fund protection.

Once finished, the auditor will produce a report. This report should conclude whether your firm has maintained "adequate systems and controls" to protect customer money. If they find issues, these are called "management points" or "findings" that you must address immediately.

Step 5: Submitting to the FCA

While you don't always have to proactively send the report to the FCA the moment it's finished (unless you are a large firm or they specifically ask for it), you must have it ready to provide upon request. You will usually need to confirm that the audit has taken place during your annual regulatory returns via the RegData portal.

Relatable Example: Imagine you run a digital wallet app. A customer tops up £100. That £100 must move into a specific "Client Money" account that you don't touch to pay your office rent. The auditor’s job is to look at that £100 and make sure it stayed where it was supposed to be until the customer spent it.

Best practices for success

DoDon't
Perform regular internal "mock" audits to catch errors early.Wait until the end of the year to start reconciling your accounts.
Ensure your bank letters specifically use the wording required by the FCA.Assume your general business auditor is qualified to do a safeguarding audit.
Keep a detailed "Safeguarding Policy" document that is updated annually.Ignore "minor" discrepancies in reconciliations; they often point to bigger system flaws.

Created by hatch. • Updated on April 28, 2026