Skip to content
KEDBYTE
How Money Moves
Chapter
50

Reconciliation

Part V · Trust, Failure and the Law|8,387 words|about 36 min read|Volume 5
Fast-moving material. Figures, model names, prices and version numbers in this chapter were verified in August 2026. Claims are separated into established fact, active research and marketing claim. Re-check anything you intend to rely on.

50.0 What this chapter gives you#

  1. You will be able to explain why three records of the same week disagree, and why forcing them to agree is not the job.
  2. You will be able to take a till total, a processor payout and a bank statement and account for every penny of the difference, naming fees, refunds, timing and breaks separately.
  3. You will be able to tell a reason from a question, so that an explained difference is closed and an unexplained one is opened as a break with a date of birth and an owner.
  4. You will be able to age a break register by value as well as by count, and say why the age of the oldest open item is the most diagnostic number in it.
  5. You will be able to name the five assertions a reconciliation makes, completeness, existence, accuracy, cut-off and valuation, and show why equal totals test only the weakest of them.
  6. You will be able to design a ledger that hands you the break list rather than making you hunt for it, using an immutable event log and clearing accounts held per counterparty and per currency.
  7. You will be able to list the five identifiers that must be persisted at the moment of the event, because none of them can be reconstructed afterwards.
  8. You will be able to assign an unexplained item to a known category quickly, whether it is fee netting, an authorisation never captured, a partial capture, a retranslation movement or a Direct Debit return.
  9. You will be able to state what CASS 15 requires of a United Kingdom safeguarding institution on each reconciliation day, and what must happen by the end of the day a shortfall is found.
  10. You will be able to explain why young payments firms die of being unable to prove where the money is rather than of losing it.

The plain version#

Ravi runs a bakery on a side street in Coventry. Hardly anybody pays him in cash any more, so there are three separate written records of what happened in his shop last week, kept by three parties who have never spoken to one another.

The first is Ravi’s own. His till logs every sale as it happens: the time, the amount, the item. That is a record of what he believes he sold.

The second belongs to the company that supplies his card machine. Each day they total what they collected on his behalf, subtract what they charge for the service, and send the remainder onward, publishing all of it in a weekly report. That is a record of what they believe they processed.

The third is his bank statement. It shows money landing in his account: a figure and a date, nothing more. That is a record of what actually arrived.

Three notebooks describing one week. Here is the thing that startles everybody the first time they meet it. The three notebooks will not agree. They will not agree this week, they will not agree next week, and no amount of diligence will make them agree on the first pass. The job is not to force them to agree. The job is to explain, line by line, precisely why they differ.

That job has a name. It is reconciliation, and it is simultaneously the least glamorous and the most load-bearing activity in finance.

Let us walk through Ravi’s week, because the shape of the answer matters more than the numbers. His till says he took 386 card payments between Monday and Sunday, adding up to £4,812.60.

Day Card sales Value taken
Monday 49 £612.40
Tuesday 47 £588.15
Wednesday 56 £701.90
Thursday 52 £655.25
Friday 73 £912.60
Saturday 88 £1,104.30
Sunday 21 £238.00
Total 386 £4,812.60

The card company’s report says three things the till does not. First, it charges him: one and a half per cent of each sale plus five pence per transaction. Second, it records a refund of £38.50, handed back on Wednesday to a customer whose wedding cake order was cancelled. That customer paid three weeks earlier, so the £38.50 appears nowhere in this week’s sales but comes out of this week’s money. Third, and this is the smallest and most interesting difference, the report shows 385 payments, not 386. One sale, £18.75 on Saturday afternoon, is simply not there.

So the report reads: £4,793.85 processed across 385 sales, less a refund of £38.50, less fees of £91.16, leaving £4,664.19 to be paid over.

Finally, the bank statement. Money from a card machine does not arrive the instant the card is tapped. It arrives a couple of working days later, and a weekend’s takings are bundled into the Monday run. These are the deposits that landed.

Day money arrived Amount What it was for
Monday £498.11 The previous week’s Thursday
Tuesday £2,043.77 The previous week’s Friday, Saturday and Sunday
Wednesday £600.76 This Monday
Thursday £576.98 This Tuesday
Friday £650.07 This Wednesday, less the £38.50 refund
Saturday none
Sunday none
Total £4,369.69

Three numbers for one week: £4,812.60, £4,664.19 and £4,369.69. All three are correct. Reconciling means turning that spread into arithmetic that closes.

Take the first gap. £4,812.60 minus £4,664.19 is £148.41, and Ravi can account for every penny: £91.16 of fees, £38.50 of refund, £18.75 for the sale that vanished. The gap is now explained. It is not a problem. It is a set of reasons, each with a name.

The second gap needs one more piece of information: what each day was worth after the card company took its cut. Monday’s £612.40, less £11.64 of fees, is £600.76, which is precisely what landed on Wednesday. Do the same for the rest of the week and the seven days come to £4,702.69 net, which less the £38.50 refund is £4,664.19, exactly what the card company says it is paying.

Now the second gap closes. The card company paid £4,664.19; the bank shows £4,369.69 arriving; the difference is £294.50, and it is pure timing. Four days of this week’s money had not landed when Sunday ended: Thursday at £642.82 net, Friday at £895.26, Saturday at £1,064.92 and Sunday at £233.38, which is £2,836.38 in transit. Against that, £2,541.88 of last week’s money landed on Monday and Tuesday. Subtract the second from the first and you get £294.50. Explained.

That is the entire discipline in miniature. Ravi did not make the numbers match. He wrote down a reason for every difference, and the reasons added up.

Except for one. The fees are a reason. The refund is a reason. The timing is a reason. The missing £18.75 is not a reason; it is a question. A customer bought two loaves and a coffee cake, the machine said approved, and no money ever moved. The likeliest explanation is that the payment was reserved against the card but never claimed before the machine closed its day, so the reservation expired and the card released the money back. Ravi is out the bread and out the cash.

An unexplained difference of this kind is called a break, and the most important fact about a break is not what caused it but how old it is.

A break one day old is normal. Money is in transit, files arrive late, somebody will look at it tomorrow. A break ninety days old is a different animal: a standing statement in Ravi’s accounts that he owns £18.75 which does not exist, quietly making him richer on paper than in life. Do that a thousand times and the gap between the books and the bank stops being a rounding error and becomes a hole.

This is why serious operations do not merely count their breaks; they age them. Every unexplained difference gets a date of birth, an owner with a name, and a bucket: under two days, under a week, under a month, over a month. A business with a flat ageing profile knows where its money is; a business with a lengthening tail does not.

Then scale it. Ravi had one break in 386 payments, roughly a quarter of one per cent, which is an unremarkable rate. At a hundred thousand payments a day, the same rate produces around 260 new breaks daily and 1,800 a week, arriving forever. At ten minutes of attention each, that is more than a full working week of somebody’s time every week just to stand still.

Which brings us to the sentence this chapter exists to deliver. Young financial technology companies do not usually die of fraud, and they do not usually die of being hacked. They die because they could not prove where the money was. Not because they lost it. Because they could not prove it. The two are different, and the second is fatal on its own.

Where the plain version stops being true#

There are not three notebooks, and “the processor report” is not one document. A real payments business reconciles between six and fifteen sources at once: an order system, a gateway, one or more acquirers, the card schemes, a wallet provider, a foreign exchange counterparty, a Bacs bureau or sponsoring bank for Direct Debits, an operating bank account, and, if the firm is regulated, a safeguarding account whose contents are legally not its own. Worse, a single processor issues several reports covering the same period, deliberately keyed on different dates, which will never tie to one another without work. Stripe’s public documentation, at the time of writing in August 2026, shows the seam plainly: a balance transaction carries an available_on date, when its net funds become available in the Stripe balance, and separately an automatic_payout_effective_at date, when the payout is expected to reach your bank account. Reconcile on the first and you get one population; on the second, another, both correct. Adyen’s settlement details report, again at the time of writing, changes shape with the acquirer: where the acquirer supplies transaction information at interchange level, the Commission column is empty and the Markup, Scheme Fees and Interchange columns are populated instead; where it does not, Commission carries the total and those three are blank. Identical economics, different structure, and a reconciliation written against one shape will silently produce nonsense against the other.

Matching is not the control. Explanation is. Two systems can match on amount and reference and both still be wrong, because both were fed by the same faulty upstream event. Two errors of opposite sign can cancel, producing a difference of zero across a population containing a five-hundred-pound overstatement and a five-hundred-pound understatement. This is why mature reconciliation runs on gross, signed values and never on the net, why a reported difference of nil is the beginning of the check rather than the end, and why the useful metric is not “what proportion of lines matched” but “what is the total absolute value of items I cannot yet explain, and how old is the oldest one”.

“As at close of business” describes a moment that never existed. The bakery assumed a single instant at which all three records can be photographed. There is none: the United Kingdom’s payment systems settle at fixed and different times of day. On the Bank of England’s published summary of the Real-Time Gross Settlement daily timetable, as it stood at the time of writing in August 2026, CHAPS settlement starts at 6am, Faster Payments settles three times each working day at 7am, 1pm and 5pm, Bacs settles at 9.30am, LINK at 11am, Mastercard at 11.15am, Visa at 12.15pm and the Image Clearing System at 4.30pm, with CHAPS closing for customer payments at 5.40pm and for financial institution payments at 6pm. A payment can therefore be irrevocable in one system, provisional in another and invisible in a third at the same wall-clock second. A bank statement line also carries at least two dates, booking and value, frequently not the same day. A reconciliation that does not define in writing which clock and which date field it cuts on produces a different answer depending on when it is run, which is the same as producing no answer.

Once the money belongs to somebody else, this stops being bookkeeping and becomes law. In the bakery the money was Ravi’s, so a break was his problem alone. The moment a firm holds funds for customers, the arithmetic acquires a statutory deadline and a regulator at the other end of it. In the United Kingdom, at the time of writing in August 2026, authorised payment institutions and electronic money institutions must safeguard relevant funds under regulation 23 of the Payment Services Regulations 2017 and regulations 20 to 22 of the Electronic Money Regulations 2011, and since 7 May 2026 those requirements have been supplemented by a new chapter of the FCA’s Client Assets sourcebook, CASS 15, which converts reconciliation from good practice into a rule with a same-day remedy attached. Under CASS 15 as it stands at the time of writing, a shortfall found by an internal safeguarding reconciliation must be paid in by the end of the day on which the reconciliation was performed, out of the firm’s own money if customer money cannot be reached. No version of that obligation can be met with a spreadsheet somebody updates on Fridays.

The technical version#

On dating#

Everything below is stated as accurate at the time of writing, in August 2026, and this corner of the subject moves fast. The FCA’s Supplementary Regime for safeguarding came into force on 7 May 2026, three months before this was written, following Policy Statement PS25/12 of 7 August 2025. In that statement the FCA declined, for now, to proceed with the end-state proposals it had consulted on, rebranding them the Post-Repeal Regime, so the rule references below have a known revision ahead of them. The Payment Systems Regulator still existed as a separate body as this was written: the Government announced in March 2025 that it intended to abolish the PSR and consolidate its functions primarily within the FCA, consulted in September 2025, and on 21 April 2026 published a response confirming full consolidation and noting that this requires primary legislation, to be brought forward as soon as Parliamentary time allows. Check the Handbook, the Bank of England’s timetable and your own scheme documentation before relying on any figure here.

What a reconciliation actually asserts#

A reconciliation is not a comparison. It is an assertion, and most weak processes fail by never having stated the assertion at all. It has five parts. Completeness: every event that occurred appears in the record. Existence: every event in the record occurred, and nothing has been invented or duplicated. Accuracy: each event is recorded at the right amount, in the right currency, against the right counterparty. Cut-off: each event falls in the right period, on a defined and documented clock. Valuation: where an amount has been translated between currencies, or is subject to later adjustment, the value carried is the right one on the right basis.

Notice that “the two numbers are the same” tests a weak form of accuracy and nothing else. A process producing a matching total while a hundred transactions are absent from both sides has passed a test never worth taking, which is why a processor restatement of a closed period must be posted as a versioned, dated correction referencing the original rather than an edit to it.

The three legs, named properly#

Leg one is the internal ledger. In a serious build this is not the order table. It is a double-entry sub-ledger fed by an append-only, immutable event log, in which a payment is a state machine with explicit transitions: initiated, authorised, captured in full or in part, settled, refunded in full or in part, disputed, represented, written off. Each transition posts a balanced journal. Critically, the design includes a clearing account, sometimes called cash-in-transit or settlement suspense, held per counterparty and per currency, debited when a payment is captured and credited when the cash lands. Its balance is, by construction, the exact population of open items. Designed this way, you do not hunt for breaks; the ledger hands you the list.

Leg two is the processor or acquirer record. It arrives as files or API objects, and it is where the commercial complexity lives. Under an interchange-plus-plus arrangement it decomposes the cost of a transaction into interchange, paid to the card issuer; scheme fees, paid to Visa or Mastercard; and the acquirer’s own markup. In the United Kingdom, at the time of writing, the UK Interchange Fee Regulation caps interchange on consumer card transactions where the merchant, the acquirer and the card issuer are all within the UK, at 0.2 per cent of transaction value for consumer debit cards including prepaid cards and 0.3 per cent for consumer credit cards, with some American Express cards outside the regime. Commercial cards and most cross-border transactions fall outside those caps, and UK to European Economic Area card-not-present interchange rose substantially after the UK left the European Union, prompting a Payment Systems Regulator market review of cross-border interchange fees. That is why a fee reconciliation built on one blended assumed rate drifts the moment a business acquires foreign or corporate customers. On a blended contract the same economics arrive as one undifferentiated deduction: simpler to reconcile, impossible to audit.

Leg three is the bank record. In modern form that means ISO 20022: a camt.053 end-of-day statement, a camt.052 intraday report, a camt.054 debit or credit notification. Legacy estates still consume SWIFT MT940 and MT942, or BAI2 in North American systems. All distinguish booking date from value date, and all carry remittance information of wildly varying quality, which is why bank-side matching is harder than processor-side matching. A processor gives you its own reference on every line. A bank frequently gives you eighteen characters of free text typed by a stranger.

A reconciliation is only as strong as the weakest identifier in the chain, so five keys must be persisted as each event happens: the internal payment identifier and idempotency key, the processor’s reference, the modification or capture reference for anything amending an earlier event, the payout or settlement batch identifier, and the bank’s end-to-end reference on the credit. None can be reconstructed later, and the break a missing one causes will be unclosable rather than merely open.

Why they never match: a taxonomy#

These causes account for the overwhelming majority of differences in a card-and-bank-transfer business, and they are worth learning as a taxonomy, because break investigation is mostly the work of assigning an unexplained item to a known category quickly.

Cause Where it shows Typical age How it clears
Fees netted at settlement Ledger gross, payout net Same day Post fee journal from itemised fee data
Settlement timing Processor paid, bank silent 1 to 3 days Clears on arrival; monitor the tail
Authorised but never captured Ledger sale, no processor line Days to weeks Write off or re-attempt; fix capture logic
Partial capture Amounts differ on one reference Same day Model capture separately from authorisation
Refund crossing a period Payout smaller than sales 1 to 30 days Link refund to original charge, not to the day
Chargeback and representment Money out, then possibly back 30 to 180 days Separate dispute sub-ledger
Foreign exchange Amounts differ by a few per cent Ongoing Retranslate; recognise the difference explicitly
Duplicate submission Two ledger events, one payout line Same day Idempotency keys; deduplicate at source
Processor restatement A closed period changes Weeks Versioned correction, never an overwrite
Lump-sum bank credit One credit, many payouts Same day Match many-to-one on batch reference
Direct Debit unpaid Collection made, then returned 2 to 10 days Consume the returns file as a first-class event
Missing or partial file A whole day absent Hours File-level completeness control

Four deserve expansion.

Fee netting. Fees break reconciliations not because they exist but because they are deducted at a different point from where they are incurred. Adyen documents that per-transaction payment fees are booked when captured funds are settled, while its own processing fees are invoiced and adjusted monthly, with the adjustment booked separately. A business reconciling on one monthly total therefore finds two fee populations arriving on two cadences, and the difference between them is not an error. Accrue from itemised data, not an assumed rate.

Authorisation versus capture. These are separate events with separate lifetimes, and treating them as one is probably the commonest structural defect in an early-stage ledger. An authorisation places a hold on a customer’s available balance; a capture claims it. Authorisations expire. Captures can be partial, so an authorisation for £120 may be captured at £97.40 when an item is out of stock, and a system recognising revenue on authorisation is permanently overstated by the difference. Some schemes and acquirers support incremental authorisation and over-capture within a tolerance, so a captured amount can legitimately exceed the amount authorised, and a validation rule forbidding that will reject good data.

Foreign exchange. A single cross-border card payment can involve four amounts: the transaction currency the customer sees, the presentment currency in which the scheme presents it to the acquirer, the settlement currency in which the acquirer pays, and the functional currency of the books. Each conversion carries its own rate and its own rounding to the minor unit, struck at different moments. Under IAS 21, or Section 30 of FRS 102 for most UK small and medium-sized companies, monetary balances are retranslated at the closing rate with the resulting exchange differences taken to profit or loss. So an unreconciled receivable in euros changes value every month without anybody touching it, and a reconciliation that does not separate genuine breaks from retranslation movement produces an unreadable break register within a quarter. Refunds are worse: a sale converted at January’s rate and refunded in April is refunded at April’s rate, so a full refund of a full sale does not net to zero and never will.

Direct Debits. For anyone operating on Bacs there is a whole reconciliation layer with no card equivalent, and it is the one most often bolted on late. Bacs runs a fixed three-working-day cycle: day one is input day, when the service user submits the file, the transmission window closing at 22.30 for processing on the following processing day; day two is processing day, when Bacs validates and distributes; day three is entry day, when the payer’s account is debited and the service user’s credited. Nothing has moved on days one or two, so a ledger recognising cash on submission is wrong for two days on every collection. Then the returns arrive. ARUDD, the Automated Return of Unpaid Direct Debits, reports collections that failed and are being returned, with a reason code attached; ARUCS does the equivalent for unapplied credits; ADDACS carries amendments to and cancellations of instructions; AWACS advises that account details used for a credit were wrong; and indemnity claims, notified through DDICA, reverse a collection under the Direct Debit Guarantee at the payer’s bank’s initiative, long after the event. Each is a file, each is a financial event, and each must be consumed as a first-class ledger entry rather than read by a human and typed into a spreadsheet. A firm that reconciles Bacs collections but not Bacs returns will show cash it has already given back.

Break investigation and ageing#

A break register is a small database and should be treated as one, not as a tab in a workbook. Every open item carries a unique identifier that never changes, the date first detected, the source systems on both sides, the signed amount and currency, a category from a controlled list, a named individual owner, an expected clearing date, a timestamped investigation trail, and a resolution code recorded when it closes.

Three rules separate a register that works from one that is theatre. First, a break with no named owner is not a break, it is a rumour: ownership sits with an individual rather than a team, and the register reports the count of unowned items, which should be zero. Second, ageing is measured gross, and by value as well as by count, because ten thousand two-pence breaks and one four-hundred-thousand-pound break are different problems and a register reporting only counts hides the second behind the first; workable buckets are nought to one day, two to five days, six to thirty days, thirty-one to ninety days and over ninety days, in reconciliation days rather than calendar days. Third, explained is not the same as cleared. An item can be fully understood and still open, because the cash has not arrived. An item can be cleared by a manual journal and still not understood, which is far more dangerous, because the journal removes the symptom and leaves the defect. Every clearing journal should require a second approver and should be counted, and a rising count is among the earliest reliable signs that a reconciliation process has begun to fail.

Ageing thresholds should trigger action, not merely reporting. A serviceable ladder runs: over five days, the owner records a root cause hypothesis; over thirty days, the item escalates to the finance lead and a provision is considered; over ninety days, the item is written off to profit or loss but deliberately kept open in the register, because writing an item off is an accounting decision and closing it is an operational lie. Items written off but held open are the raw material for root cause analysis. Items closed on write-off vanish, and the defect that generated them runs forever.

Reconciliation is also a fraud control, and quietly one of the best available, because internal misappropriation almost always leaves an anomaly in exactly this data: a payout corresponding to no settled transaction, a refund with no matching original, a clearing account that never returns to a plausible balance. The defensive value comes from the segregation of duties around it rather than from the matching itself. Whoever can create a payment must not be whoever can approve a reconciliation adjustment, and neither should be able to amend the break register without leaving a record.

Where the law arrives#

For a UK firm holding customer money this is a regulatory obligation with named rules, deadlines and notification duties. What follows is the position at the time of writing, in August 2026.

Authorised payment institutions, small payment institutions that elect to safeguard, electronic money institutions and credit unions issuing electronic money are, as safeguarding institutions, subject to CASS 15, in force since 7 May 2026. Firms providing only payment initiation or account information services do not hold relevant funds and are outside it. CASS 15.8 is the records, accounts and reconciliations chapter, and its architecture is worth knowing precisely.

An internal safeguarding reconciliation compares what the firm’s own records say it owes customers, the safeguarding requirement, against what those records say it holds, the safeguarding resource. CASS 15.8.19R requires this as frequently as necessary and no less than once each reconciliation day. That term was a late and practically significant change during the consultation: the Handbook glossary defines a reconciliation day, at the time of writing, as a business day that is not a Saturday or Sunday, Christmas Day, Good Friday or a bank holiday in any part of the United Kingdom, and, where a reconciliation requires anything to be done by reference to a market outside the United Kingdom, not a day on which that market is not normally open for business. The standard method also includes a forward-looking comparison of the firm’s D+1 segregation requirement against its D+1 segregation resource. A firm relying on an insurance policy or guarantee unlimited in cover need not perform an internal safeguarding reconciliation at all, but must record a daily calculation of its safeguarding requirement.

An external safeguarding reconciliation compares the firm’s internal records against statements or confirmations from the third parties actually holding the money. Under CASS 15.8.42R it too must be performed as frequently as necessary and no less than once each reconciliation day, and as soon as reasonably practicable after the date to which it relates.

The consequences of a discrepancy are where the rules bite hardest. Where an internal reconciliation reveals a difference between resource and requirement, CASS 15.8.50R requires the firm to determine the reason and then ensure either that any shortfall is paid into a relevant funds bank account or invested in relevant assets as soon as possible and in any case by the end of the day on which the reconciliation is performed, or that any excess is withdrawn. CASS 15.8.51R applies the same end-of-day deadline to a deficiency in the D+1 segregation resource and goes further: where relevant funds cannot remedy it, the firm must use its own, even where that produces a surplus, with the position corrected by later reconciliations. Where an external reconciliation reveals a discrepancy, CASS 15.8.56R requires investigation and all reasonable steps to resolve it without undue delay, unless it arises solely from timing differences between the two parties’ accounting systems. And CASS 15.8.57R provides that where the firm cannot immediately resolve such a discrepancy, and one set of records indicates a need for a greater amount of relevant funds or assets than another, it must assume until the matter is finally resolved that the record showing the greater amount is accurate, and pay its own funds in accordingly. The regulatory default is to assume you are short.

Then the notifications. CASS 15.8 requires a safeguarding institution to inform the FCA in writing without delay if its internal records and accounts of relevant funds are materially out of date, inaccurate or invalid; if it will be unable to, or materially fails to, conduct an internal or an external safeguarding reconciliation in compliance with the rules; if it will be unable to, or materially fails to, pay in a shortfall or withdraw an excess after an internal reconciliation; if it will be unable to, or materially fails to, identify and resolve discrepancies after an external reconciliation; or if it becomes aware that at any time in the preceding twelve months the amount of relevant funds safeguarded was materially different from the total aggregate amount it was required to safeguard. That last limb deserves reading twice. Discovering historic under-safeguarding is itself notifiable, so an honest clean-up of a legacy break population is a conversation with the regulator, not a quiet weekend of journals.

Around the reconciliation sit the monitoring obligations. Under SUP 16.14A a safeguarding institution must submit a safeguarding return to the FCA within fifteen business days of each month end, and that return asks directly whether internal safeguarding reconciliations were carried out every reconciliation day during the period. An annual safeguarding audit by a qualified auditor is required, with an exemption at the time of writing for firms not required to safeguard more than £100,000 of relevant funds at any point over a period of at least 53 weeks; the report is due within four months of the period covered, extended to six months for the first report under the new regime. Under SUP 3A.9 the auditor must confirm whether the firm has maintained systems adequate to enable compliance with the relevant funds regime. Oversight must be allocated to a single named director or senior manager.

Investment firms holding client money live under the older parallel regime in CASS 7.15, which requires an internal client money reconciliation each business day under CASS 7.15.15R, based on the records as at close of business on the previous business day. CASS 15 borrows heavily from CASS 7, which is useful rather than merely tidy: the enforcement history and audit methodology built up around CASS 7 over more than a decade are largely transferable.

The direction of travel is visible elsewhere. The Bank of England’s draft Code of Practice for systemic sterling-denominated stablecoin issuers, published in 2026, requires at paragraph 3.5 that a systemic issuer carry out an internal safeguarding reconciliation as regularly as necessary and at least once each business day. Where money is held for others, daily reconciliation is becoming the floor across UK financial regulation. And the Payment and Electronic Money Institution Insolvency Regulations 2021 created a special administration regime whose objectives include returning relevant funds to customers as soon as is reasonably practicable, exactly the objective unreconciled records defeat.

Why young firms actually die here#

This part of the chapter is an argument rather than a description, and it should be made without hedging.

The FCA’s own published evidence is stark. In consultation paper CP24/20, published in September 2024, it reported that twelve payments firms which safeguarded relevant funds became insolvent between the first quarter of 2018 and the second quarter of 2023, that the weighted average shortfall in client funds across those cases was 65 per cent, and that seven of the twelve showed shortfalls over 50 per cent. Its table of selected averages put mean client funds owed at £11.3m against mean total assets available of £4.0m, a shortfall of £7.3m; for electronic money institutions alone, £16.3m owed against £3.3m available, a shortfall of £13.0m or 80 per cent. Of the six cases in which some funds had been distributed, a first distribution took on average over two years. The FCA was careful to say these shortfall figures are likely underestimates, because the data available did not record safeguarded funds and total assets at insolvency had to serve as a proxy. The same paper recorded that in 2023 it opened supervisory cases about safeguarding arrangements at approximately 15 per cent of the firms that safeguard.

Read those numbers with the reconciliation lens on. A weighted average shortfall of 65 per cent is not embezzlement; embezzlement on that scale across twelve firms would have been a national scandal. It is what happens when firms do not know, at any given moment, what they owe. The requirement side drifted from the resource side over months and years, nobody computed the difference daily, and the gap was first measured on the day an administrator arrived to measure it. The two years to a first distribution is the same failure from the other end: an insolvency practitioner cannot pay customers until they know who is owed what, and the records did not say.

The proximate causes are almost always mundane. Corporate and customer money commingled in one operating account, because opening a safeguarding account was slow and the founders were busy. Revenue recognised on authorisation rather than capture, so the profit and loss account told a happier story than the bank did. Fees accrued at a blended estimate rather than from itemised data, so the estimate drifted into a suspense account nobody owned. A break register that was a spreadsheet, so its oldest item was whatever the last person to open the file had not deleted. Customer float treated as working capital, because float behaves exactly like money right up until the customers ask for it back at the same time.

The legal machinery makes the consequences harder rather than easier. In the administration of the electronic money institution Ipagoo, the Court of Appeal held in 2022 that the Electronic Money Regulations do not impose a statutory trust over funds received from e-money holders, while also holding that a shortfall in the customer asset pool should be topped up. A subsequent judgment following the insolvency of Allied Wallet, [2022] EWHC 1877 (Ch), extended that reasoning to the Payment Services Regulations, so relevant funds held with authorised payment institutions are likewise not subject to a statutory trust. The FCA’s assessment in CP24/20 was that this leaves practitioners seeking directions from the court on the treatment of the safeguarded asset pool, raising costs and delaying returns. All of that litigation is downstream of one fact: the records did not make it obvious which money was whose. Wirecard illustrates the same point at scale. When it collapsed in June 2020 the missing €1.9 billion, said to be held in trustee accounts in Asia, turned out not to exist: an asset asserted on a balance sheet that no independent third-party record ever confirmed.

So why do founders under-invest in this, consistently, across an industry that has watched other firms die of it?

Because reconciliation has no demo. It cannot be shown to an investor, and when it works perfectly its entire visible output is a report saying nothing is wrong. Every hour spent on it is an hour not spent on something a customer can see.

Because its cost curve is deceptive. At a hundred transactions a day, reconciliation genuinely is a spreadsheet and half an hour on a Monday, and the founder who says “we will do this properly later” is right that it is not urgent today. At a hundred thousand transactions a day it is a team, a data pipeline and a rules engine, and the transition does not happen gradually. It happens in the eight weeks after a large partner goes live, on top of a data model designed when none of it mattered. Migrating from “our ledger is the payments table” to an immutable double-entry event log with clearing accounts per counterparty and currency is a rewrite of the most sensitive code in the business, invariably attempted while that code is under maximum load.

Because the early signals look benign. A small unexplained surplus reads as a pleasant surprise rather than a defect, and a growing business generates surpluses constantly through timing alone. Inflows exceed outflows, so the safeguarding account never looks empty, and the difference between what is held and what is owed is masked by growth for as long as growth continues. When growth stops the hole is instantly visible, and it has been there for two years.

Because the first person who would notice has usually not been hired. Reconciliation sits in the seam between engineering, which owns the data and not the balance sheet, and finance, which owns the balance sheet and cannot query the data. It is nobody’s specialism until somebody is made responsible by name, which under CASS 15, at the time of writing, is a rule.

And because the consequences are back-loaded and then arrive at once: a qualified audit opinion; a due diligence process that stalls because the acquirer’s accountants cannot tie revenue to cash; a notification to the FCA under CASS 15.8 that a reconciliation was not performed; a monthly safeguarding return that has to answer “no”; or a report from a skilled person, required under section 166 of the Financial Services and Markets Act 2000 and paid for by the firm. Any one of those can consume a management team for six months. All are cheaper to prevent than to survive.

What competence looks like#

The automatic match rate at T+1, by count and by value, is the headline health metric; in a well-instrumented card business it should sit comfortably above 99 per cent by value on the day after settlement. The absolute value of unexplained items in each ageing bucket matters far more than the net figure. The age of the oldest open item is the most diagnostic number in the register and belongs in the board pack. Mean time to clear, by break category, tells you which defect to fix next. The count of manual clearing journals, and their aggregate value, tells you how much of the match rate is real. And the number of reconciliation days on which the reconciliation was not completed should be zero, because for a safeguarding institution a failure to perform it is itself notifiable.

Around those numbers sit four practices. Persist every identifier at the moment of the event, because none can be reconstructed afterwards. Use idempotency keys on every mutating call, because duplicate submission is the cheapest break to prevent and among the most expensive to unwind. Reconcile file-level completeness before line-level content, because a missing file produces a thousand phantom breaks and one real problem. And write the reconciliation before the product ships, because the data model that makes reconciliation possible is the same one that makes the product correct.

What will date this chapter#

Three things, and a reader in 2029 should check all of them before quoting any of the above.

The CASS 15 rule set is explicitly staged. The Supplementary Regime in force since 7 May 2026 is, in the FCA’s own framing, an intermediate step. The end-state proposals consulted on in CP24/20, including a statutory trust over relevant funds and a requirement to receive funds directly into a designated safeguarding account, were not taken forward in that form; renamed the Post-Repeal Regime, they await further consultation once HM Treasury has repealed and replaced the Payment Services Regulations 2017 and the Electronic Money Regulations 2011. Rule numbers will move, and the substance may move further.

The regulatory perimeter is being redrawn. Abolition of the Payment Systems Regulator and transfer of its functions to the FCA was confirmed as government policy in the April 2026 consultation response, but requires primary legislation not enacted at the time of writing, so any sentence here naming the PSR as a live regulator has a foreseeable expiry date.

And the plumbing is changing underneath. The Bank of England confirmed in February 2026 that it intends to move the start of CHAPS settlement from 6am to 1.30am in September 2027, and has since consulted on further steps towards near twenty-four-hour, seven-day settlement on its renewed RTGS platform, with Bacs, Faster Payments, the Image Clearing System, Visa, Mastercard and LINK expected to keep their existing timelines under that first extension. The timetable quoted earlier is therefore a snapshot of a moving object. Migration to ISO 20022 continues to widen the structured data on the bank leg, which will make bank-side matching materially easier than the account given here. When the timetable moves, every cut-off assumption built on it moves too, which is a useful reminder that a reconciliation is not a piece of software but a standing relationship with external clocks you do not control.

50.98 Common wrong ideas#

Wrong: Reconciliation means making the numbers match. Right: It means explaining, line by line, exactly why they differ; Ravi’s three totals were all correct, and the discipline is writing a reason against each difference until the reasons add up.

Wrong: There are three records to reconcile. Right: A real payments business reconciles between six and fifteen sources, and a single processor issues several reports covering the same period deliberately keyed on different dates, which will never tie to one another without work.

Wrong: A reported difference of nil means the reconciliation passed. Right: Two errors of opposite sign cancel, so nil is the beginning of the check; mature processes run on gross signed values and measure the total absolute value of items they cannot yet explain.

Wrong: “As at close of business” is a single moment at which all the records can be photographed. Right: CHAPS, Bacs, Faster Payments, LINK, Visa, Mastercard and the Image Clearing System settle at fixed and different times of day, and a bank line carries booking and value dates, so a reconciliation that does not define its clock in writing gives a different answer depending on when it is run.

Wrong: Authorisation and capture are one event. Right: They have separate lifetimes; authorisations expire, captures can be partial, and some schemes permit over-capture within a tolerance, so recognising revenue on authorisation overstates permanently and a rule forbidding over-capture rejects good data.

Wrong: A full refund of a full sale nets to zero. Right: Across currencies the sale converts at one date’s rate and the refund at another’s, so it does not net to zero and never will.

Wrong: An item cleared by a manual journal is an item resolved. Right: Explained is not the same as cleared and cleared is not the same as understood; the journal removes the symptom and leaves the defect, which is why every clearing journal needs a second approver and a rising count of them is an early sign of failure.

Wrong: A break that has been written off can be closed. Right: Writing an item off is an accounting decision and closing it is an operational lie; items written off but held open are the raw material for root cause analysis.

Wrong: A small unexplained surplus is a pleasant surprise. Right: A growing business generates surpluses constantly through timing alone, which masks the gap between what is held and what is owed for exactly as long as growth continues.

Wrong: A legacy safeguarding shortfall can be tidied up quietly over a weekend. Right: CASS 15.8 makes it notifiable if at any time in the preceding twelve months the amount safeguarded was materially different from the amount required, so an honest clean-up is a conversation with the regulator.

50.99 Chapter summary in 20 lines#

  1. A card-accepting business has several separate records of the same week, kept by parties who have never spoken to one another, and they will not agree on the first pass.
  2. Reconciliation is not the work of making them agree; it is the work of explaining every difference by name.
  3. Ravi’s till, his card company’s report and his bank statement differ by fees, a refund from an earlier period, settlement timing and one sale that never became money, and all three totals are correct.
  4. A difference with a name is a reason and is closed; a difference without one is a break and is opened.
  5. The most important fact about a break is not its cause but its age, which is why serious operations age their register by value as well as by count.
  6. The plain picture understates the problem, because real firms reconcile between six and fifteen sources and one processor issues several reports of a period keyed on different dates.
  7. Matching is not the control, since two systems fed by the same faulty upstream event can agree while both are wrong, and errors of opposite sign cancel.
  8. There is no single moment called close of business, because the United Kingdom’s payment systems settle at fixed and different times and bank lines carry two dates.
  9. A reconciliation asserts completeness, existence, accuracy, cut-off and valuation, and equal totals test only a weak form of accuracy.
  10. Done properly, the internal leg is a double-entry sub-ledger over an immutable event log, with clearing accounts per counterparty and currency whose balance is by construction the population of open items.
  11. The processor leg carries the commercial complexity, interchange, scheme fees and markup, which is why a fee accrual built on one blended assumed rate drifts the moment foreign or corporate cards arrive.
  12. The bank leg is the hardest to match, because a processor gives you its own reference on every line and a bank frequently gives you free text typed by a stranger.
  13. Five identifiers must be persisted as each event happens, because a missing one makes the resulting break unclosable rather than merely open.
  14. Most differences fall into a known taxonomy, of which fee netting, authorisation versus capture, foreign exchange and the Bacs returns files deserve particular attention.
  15. Once the money belongs to somebody else this stops being bookkeeping and becomes law, and United Kingdom safeguarding institutions have fallen under CASS 15 since 7 May 2026.
  16. CASS 15.8 requires internal and external safeguarding reconciliations on each reconciliation day, with any shortfall paid in by the end of the day the reconciliation was performed, from the firm’s own money if customer money cannot be reached.
  17. Where a discrepancy cannot be resolved the firm must assume the record showing the greater amount is accurate, and a whole list of failures, including historic under-safeguarding, is notifiable to the FCA.
  18. The FCA’s own evidence records twelve insolvent safeguarding firms with a weighted average shortfall of 65 per cent and a first distribution taking on average over two years, which is what not knowing what you owe looks like from the outside.
  19. Founders under-invest because reconciliation has no demo, its cost curve jumps rather than climbs, its early signals look benign, and nobody owns it until somebody is named.
  20. Young financial technology firms rarely die of fraud or of being hacked; they die because they could not prove where the money was, and being unable to prove it is fatal on its own.

Sources, all consulted in August 2026: the FCA Handbook, CASS 15.8, CASS 7.15, SUP 3A.9, SUP 16.14A and the glossary definition of reconciliation day; FCA Policy Statement PS25/12 and Consultation Paper CP24/20, including Table 3 and its methodology caveat; the Payment Services Regulations 2017, the Electronic Money Regulations 2011 and the Payment and Electronic Money Institution Insolvency Regulations 2021; the Bank of England’s summary of the RTGS daily timetable, its 2026 papers on extending RTGS and CHAPS settlement hours, and its 2026 draft Code of Practice for systemic sterling stablecoin issuers; Bacs Payment Schemes Limited and Pay.UK on the Bacs cycle, the 22.30 cut-off and the ARUDD, ARUCS, ADDACS, AWACS and DDICA services; the Payment Systems Regulator on the UK Interchange Fee Regulation; HM Treasury’s April 2026 response on payment systems regulation; Ipagoo LLP in the Court of Appeal and Allied Wallet [2022] EWHC 1877 (Ch); Stripe and Adyen developer documentation; and IAS 21 and Section 30 of FRS 102.