top of page
Search

Payment Institution Safeguarding Requirements

  • Writer: NUR Legal
    NUR Legal
  • 4 days ago
  • 6 min read

A payment institution can have a well-designed product, strong AML controls and a viable banking relationship, yet still face regulatory intervention if client money is not protected correctly. Payment institution safeguarding requirements are not a back-office formality. They determine whether funds remain protected if the firm fails, whether reconciliations can be relied upon, and whether the FCA sees the business as operationally fit to hold customer funds.

For founders and executives, the practical question is not simply whether a safeguarding account exists. It is whether every payment flow, ledger entry, reconciliation and escalation process proves that relevant funds are protected at the right time. That standard must hold during growth, incidents, partner-bank changes and an FCA review.

What payment institution safeguarding requirements cover

Under the UK Payment Services Regulations 2017, authorised payment institutions that receive funds for the execution of payment transactions must safeguard relevant funds in specified circumstances. The underlying objective is clear: if the institution becomes insolvent, those funds should be protected from the claims of its general creditors and returned to payment service users as far as possible.

Safeguarding is therefore distinct from capital adequacy. Own funds absorb business losses. Safeguarded funds belong to customers and must not be used to finance payroll, marketing, supplier invoices or group-company activity. It is also different from the Financial Services Compensation Scheme. Payment services users should not be told that safeguarding gives them FSCS protection where it does not.

The precise scope depends on the institution's permissions and payment flows. A firm that only initiates payments and never receives or controls customer funds faces a different analysis from a business that accepts funds into a payment account, holds balances pending execution, uses agents, or receives funds through a card programme. E-money issuers have related but separate safeguarding obligations, so a group operating both payment and e-money models must document which rules apply to each entity and product.

Identify relevant funds before drafting policies

Many safeguarding failures begin with an incomplete mapping exercise. A policy may describe customer funds correctly in principle but fail to account for money received via an agent, a programme manager, a card acquirer, a foreign exchange partner or a technical intermediary.

The starting point should be a transaction-level funds-flow map. It should show where money is received, when it becomes relevant funds, which legal entity controls it, which account holds it, when it is paid out and what happens if a payment is rejected or delayed. The map must cover normal processing and exceptions, including chargebacks, reversals, refunds, dormant balances and failed beneficiary payments.

Timing matters. Safeguarding obligations are tied to statutory triggers and prescribed timeframes, not to the date on which a finance team happens to complete a reconciliation. A firm should translate each trigger into a clear operational rule, supported by system controls and accountable owners.

How payment institutions safeguard funds

A payment institution will generally use one of two recognised routes: segregation of relevant funds in a separate account, or an insurance policy or comparable guarantee. The segregation route is more common, but neither option is automatic compliance.

Segregated safeguarding accounts

Under the segregation method, relevant funds are placed in a separate account with an authorised credit institution, a central bank or another permitted safeguarding custodian. The account must be clearly designated as a safeguarding account or otherwise identified in a way that protects the funds from the institution's creditors.

The account title is only one part of the control environment. The institution needs written confirmation of the bank's understanding of the account's status, terms that prevent inappropriate set-off or security interests, and a legal analysis of how the arrangement operates if the bank or the payment institution enters insolvency. Where funds are held outside the UK, the legal and insolvency analysis becomes particularly important.

A common commercial pressure is to use a single operational account for convenience, especially during launch. That may create unacceptable commingling risk. The correct structure depends on the payment flow, but operational convenience is not a defence if customer funds cannot be identified promptly and protected properly.

Insurance or comparable guarantees

An insurance policy or comparable guarantee can be used where it provides equivalent protection if the payment institution cannot meet its financial obligations. This route can assist particular business models, but it requires careful review of the insurer or guarantor, coverage limits, exclusions, duration, claims mechanics and the legal enforceability of customer protection.

It is not a cheaper substitute for understanding the funds flow. If the policy does not cover the full safeguarding exposure, has material exclusions, or cannot be called upon quickly in a failure scenario, it may not meet the required standard. Firms should also plan for renewal risk and the possibility that an insurer's risk appetite changes as transaction volumes increase.

The control framework the FCA will expect to see

Safeguarding compliance is evidenced through daily discipline. A regulator, auditor or prospective banking partner will usually test whether records can establish the safeguarded balance at a specific point in time and explain every difference without delay.

A workable framework normally contains at least five connected controls:

  • a documented funds-flow analysis for each product, currency, channel and third-party arrangement;

  • segregation or guarantee arrangements that have been legally reviewed and correctly documented;

  • frequent internal and external reconciliations, with a defined method for calculating the safeguarding requirement;

  • a clear process for identifying, investigating, correcting and escalating discrepancies; and

  • governance, management information, training and independent review proportionate to the scale and risk of the business.

Internal reconciliation compares the firm's own records of relevant funds with customer balances and payment obligations. External reconciliation compares those records with the balance held at the safeguarding bank or custodian. Both are necessary. A bank statement that appears correct does not prove that the firm has calculated its customer liability correctly; equally, a correct ledger does not prove that the funds are actually present at the bank.

The reconciliation process must address timing differences rather than conceal them. Cut-off times, weekend processing, inbound transfers not yet allocated, card settlement delays and foreign-exchange conversion can all create temporary breaks. These may be legitimate, but only if they are understood, recorded and resolved within a controlled process.

Governance cannot sit solely with finance

The board or senior management should receive safeguarding management information that highlights the safeguarded balance, reconciliation breaks, aged exceptions, material third-party dependencies and any use of manual adjustments. Where an issue threatens customer funds, escalation must be immediate and decision-making authority must be clear.

Compliance, finance, operations and technology all have a role. Finance may perform the reconciliation, but operations controls payment statuses, technology controls ledger logic and access rights, while compliance assesses regulatory reporting and remediation. Fragmented ownership is one of the fastest ways for a small discrepancy to become a systemic failure.

Common failures that delay authorisation or trigger remediation

The most persistent weakness is treating safeguarding as a template policy exercise. The FCA will look beyond policy wording to test whether arrangements operate in practice.

Typical issues include opening an account that is labelled as safeguarded without obtaining adequate contractual protections; calculating the safeguarded amount from incomplete data; failing to include agent or distributor flows; using customer money temporarily to settle business expenses; and leaving reconciliation discrepancies unresolved for extended periods.

Third-party dependencies require particular attention. A payment institution may outsource technology, card processing, customer onboarding or operational support, but it cannot outsource regulatory accountability. Contracts should define ownership of funds, data availability, reporting deadlines, audit rights, incident notification and business continuity expectations. If a partner's ledger is essential to reconciliation, the firm needs reliable, timely access to that data.

Safeguarding during growth, acquisitions and product changes

A safeguarding model that works for one domestic payment product may fail when the business adds multi-currency accounts, acquires a portfolio, introduces agents or expands into a new jurisdiction. Every material product change should trigger a safeguarding impact assessment before launch, not after funds have begun moving.

For acquisition-minded operators, the due diligence exercise should go further than checking that a regulated entity has a licence and a bank account. Review historical reconciliations, safeguarding account mandates, partner agreements, audit findings, incident logs and the practical ability to produce customer-fund records. A ready-made payment vehicle can reduce time to market, but inherited safeguarding weaknesses can be more expensive than a fresh build.

The same principle applies to fast-growth fintechs. Automate where possible, but do not automate an untested calculation. Reconciliation logic should be validated against real payment scenarios, and manual fall-back processes should be tested before an outage makes them necessary.

A practical implementation sequence

The most effective route is to establish the operating model before submitting an authorisation application or launching a new product. First, map each funds flow and decide whether, when and where relevant funds arise. Next, select the safeguarding method and obtain bank, insurer or guarantor documentation that supports the legal analysis.

Then build the ledger, reconciliation and exception-management processes around that model. Assign accountable senior owners, prepare management information, and test the process using sample transactions and failure scenarios. Finally, ensure the safeguarding policy, risk assessment, wind-down plan, outsourcing arrangements and financial projections all describe the same operating reality.

NUR Legal supports payment and e-money businesses with the legal structure, compliance documentation and regulator-facing execution needed to turn that model into an authorisation-ready operation.

The right safeguarding arrangement is one that still works on the firm's worst operational day: when a payment partner is delayed, balances are moving quickly and management needs to prove, without guesswork, that every customer fund is protected.

 
 
 

Comments


Contact

NUR Legal OÜ

Registry code: 17142784

VAT nr. EE102815012

+37258339358

  • Facebook
  • Телеграмма
  • Linkedin
  • Instagram
NUR Legal map_edited.jpg

Thanks for submitting!

JURISFIN Verification Badge

News & Articles •  Terms of UsePrivacy Policy
© 2026 NUR Legal All rights reserved.

bottom of page