CASS Enforcement Watch: The £31.7m WealthTek Settlement, and Your First Safeguarding Audit Deadline
News & regulatory update — clientmoney.co.uk
Two developments from this summer are worth a compliance officer’s attention this week: a substantial FCA enforcement outcome that turns on a firm’s failure to check a counterparty’s actual permissions before holding client assets, and the practical mechanics of the first safeguarding audit cycle now running under CASS 15. Neither is brand new, but both are live issues for payment, e-money and crypto firms right now, and both carry lessons worth acting on rather than filing away.
CACEIS Bank UK: a £31.7m lesson in checking who you’re really dealing with
On 19 June 2026 the FCA published a Final Notice against CACEIS Bank, UK Branch, arising from its role as custodian for WealthTek LLP — the wealth manager whose collapse in 2023 triggered one of the FCA’s largest client asset failure cases in recent years. The Notice finds CACEIS breached Principle 2 (a firm must conduct its business with due skill, care and diligence).
The detail matters for anyone providing, or relying on, custody and safeguarding infrastructure. CACEIS identified, at the point WealthTek’s accounts were migrated onto its platform in December 2020, that WealthTek did not hold the FCA permission for “safeguarding and administering investments.” It proceeded regardless. Two subsequent checks of the Financial Services Register — in February 2021 and December 2022 — again showed the same permissions gap, and again nothing was done. WealthTek’s authorisation carried an explicit restriction preventing it from holding client money; CACEIS missed it. Separately, sixteen transaction-monitoring alerts raised against WealthTek’s accounts between October 2021 and February 2022 went unresolved for over two years, while more than £314 million in credits flowed through the accounts in question.
The FCA did not impose a financial penalty. Instead it issued a public censure and accepted a voluntary ex-gratia payment from CACEIS of £31,714,068 to WealthTek’s former clients — larger than the £23,091,900 penalty (already discounted 30% for cooperation) the FCA would otherwise have imposed. CACEIS chose to make its clients whole rather than pay a smaller fine to the Treasury; the FCA credited its “full and significant cooperation” throughout.
For smaller PIs, EMIs and crypto firms the read-across isn’t really about CACEIS’s scale — it’s about the nature of the failing. A regulated firm’s authorisation is not a single fact you check once at onboarding; permissions, restrictions and limitations sit on the Register and can matter enormously to how a counterparty is allowed to use money or assets you hand it. If your firm places relevant funds with a bank, custodian or e-money issuer, or if you provide safeguarding, custody or account infrastructure to other regulated firms, this Notice is a clean prompt to check that your due diligence — at onboarding and on an ongoing basis — actually verifies scope of permission, not just authorised status, and that monitoring alerts have an owner and a closure deadline.
Your first CASS 15 safeguarding audit cycle is already running
CASS 15 came into force on 7 May 2026, and firms in scope are now several months into their first “relevant funds” reporting period. Two points are worth flagging while there’s still time to act on them.
First, on the audit itself. The Financial Reporting Council published interim guidance on 17 March 2026 to support safeguarding auditors through this transition. It creates no new legal obligations and doesn’t supersede the Payment Services Regulations or Electronic Money Regulations — but it does shape what your auditor will expect until a dedicated Safeguarding Assurance Standard arrives, following a consultation planned for winter 2026 and adoption expected in spring 2027. In the meantime, the guidance points auditors toward a controls-focused, risk-based approach aligned with the existing Client Asset Assurance Standard, reconciliation testing conducted with an “insolvency mindset,” specific assessment of IT general controls, and — notably — a zero materiality threshold for breach reporting: every safeguarding breach identified must be reported to the FCA, regardless of size.
Second, on timing. The safeguarding report is due to the FCA within four months of the end of your relevant funds period — extended to six months for firms whose first period ends within twelve months of the 7 May 2026 commencement date. Firms newly in scope should set their reporting period deliberately rather than assuming it lines up with their financial year end, and should not leave auditor engagement until the period closes: readiness is built through the year, via contemporaneous reconciliation records and documented exception-handling, not reconstructed retrospectively. Firms that have not safeguarded more than £100,000 of relevant funds at any point over a rolling 53-week period remain outside the audit requirement, but should keep evidence of that threshold position in case it’s ever tested.
Between them, these two items say something similar: the new safeguarding regime is judged less on the policy on paper and more on whether the everyday controls — permission checks, alert handling, reconciliations, evidence trails — actually hold up when someone looks closely, whether that’s an auditor or, in CACEIS’s case, the FCA itself.
If you’d like a second opinion on your safeguarding audit readiness or your due diligence on custody and banking partners, get in touch — I’m happy to talk it through.
