Short Summary
Why is CASS compliance important for financial firms? Because it ensures client money and assets are safeguarded if a company fails. This article explains the key rules, FCA enforcement trends, common challenges, and best practices for staying compliant.
What is CASS?
CASS, or the Client Assets Sourcebook, is the set of FCA rules that requires firms to safeguard client money and assets so they remain protected if a firm fails.
When a company goes under, the impact reaches far beyond its balance sheet. Jobs disappear, investors take losses, and clients can suddenly find their money or assets locked away. Between 2023 and 2024, England and Wales recorded corporate insolvency levels not seen since the 2008‑09 recession, with 23,872 company insolvencies logged in 2024 alone.
When a financial firm collapses, clients’ actual funds and assets can become entangled with the firm’s financial troubles, making it harder for them to get their money back quickly or in full.
To protect against this risk in the UK, the Financial Conduct Authority (FCA) enforces the Client Assets Sourcebook (CASS). These rules require firms to keep client money and assets properly safeguarded so that, even if the firm fails, clients do not pay the price.
This blog will break down what CASS compliance involves, the key rules firms must follow, how the FCA oversees enforcement, and the challenges companies face in getting it right. We’ll also look at best practices for meeting these standards and explain why strong communication and data management are critical to long-term compliance.
An Overview of CASS Requirements
CASS is the FCA’s rulebook for how firms must look after client money and custody assets. It was overhauled in 2014 after lessons from the financial crisis and is now one of the most detailed areas of UK financial regulation. The goal of CASS is to ensure that, in the event a firm collapses, client assets can be identified and returned quickly, without confusion or loss.
CASS covers a wide range of FCA-regulated firms, from global banks and asset managers to brokers, investment firms, and even some crowdfunding platforms. If you handle client cash or securities in the UK, CASS applies to you.
CASS outlines several rules, including:
- Client money rules: Firms must keep client money completely separate from their own funds, placing it into specially designated accounts. They also need to reconcile records constantly to make sure what’s on their books matches what’s in the bank. Any shortfalls have to be corrected immediately.
- Custody asset rules: Where firms hold securities for clients, they need to prove exactly what belongs to each client at any given time. That requires detailed internal records, strong oversight of third-party custodians, and regular reconciliations between internal records and external statements.
- Acknowledgement letters: Whenever client money is placed in a bank account, the bank must sign a letter confirming it recognizes the money belongs to clients, not the firm. This prevents the bank from treating those funds as the firm’s own in an insolvency.
- Recordkeeping and reporting: Accurate, up-to-date records are central to CASS. Firms must document every client position clearly enough that an administrator could step in and make sense of it immediately. Many firms also have to submit regular reports to the FCA, giving the regulator visibility over how client assets are being managed.
- Physical asset checks: For firms that still hold tangible items like stock certificates, CASS requires periodic spot checks to confirm the assets exist and are correctly recorded.
- The CASS Resolution Pack: Every firm must maintain a resolution pack, which is an emergency file of key documents and data. It must be retrievable within 48 hours of a request so that if the worst happens, an administrator can get to work without delay.
- Governance and accountability: Responsibility for CASS must be clear. Under the UK’s Senior Managers and Certification Regime (SM&CR), a senior manager is formally accountable, supported by an operational lead who monitors day-to-day compliance. The aim is to ensure there’s no doubt about who owns the controls.
Enforcement and Penalties for CASS Non-Compliance
The Financial Conduct Authority (FCA) is the UK’s conduct regulator for financial services firms and markets. It has sweeping powers from writing the rules firms must follow, to supervising day-to-day compliance, and taking enforcement action when standards aren’t met.
The FCA doesn’t have to rely on fines alone. Its toolkit includes:
- Financial penalties: These are the most visible, and they can be hefty, running from six figures to more than £30 million in the most serious cases.
- Business restrictions: The FCA can impose “own initiative requirements” (OIREQs), suspending activities or requiring firms to return client money until issues are fixed.
- Personal accountability: Senior managers with CASS responsibility can be fined, censured, or even banned under the Senior Managers and Certification Regime (SM&CR).
- Criminal action: In rare but high-stakes cases, breaches involving fraud or misappropriation of client money have led to criminal charges.
Where Firms are Falling Short
The FCA’s own letters and final notices point to recurring weaknesses:
- Recordkeeping failures: In a 2024 portfolio letter, the FCA highlighted “weak books and records, end-of-life IT, and heavy manual processing” as key risks undermining accurate CASS compliance. These are precisely the kinds of failures that make it hard to prove what belongs to clients.
- Documentation gaps: The FCA has repeatedly warned about missing or incomplete acknowledgement letters for client money accounts. Resolution packs are another sticking point, with the regulator stressing that they must be kept up to date and retrievable within 48 hours.
- Reconciliation errors: Enforcement cases show firms failing to perform daily or external reconciliations properly, leaving discrepancies unresolved and client money potentially exposed.
- Oversight and governance: The regulator often finds that CASS Operational Oversight Officers (CF10a) lack real authority or visibility across business lines, reducing accountability to a paper exercise.
- Audit/reporting quality: In 2024, the FCA publicly censured audit firm MHA for failing to report CASS breaches, a move that underlines its determination to hold external gatekeepers to account too.
Penalty Trends and Examples
The numbers make clear that CASS enforcement is not slowing down:
- Large fines for big institutions: Several high-profile banks and brokers have faced multi-million-pound penalties in recent years. For example, Barclays was fined £38 million for failing to properly safeguard client custody assets worth around £16.5 billion.
- Smaller firms in the crosshairs: The FCA has fined boutique and mid-tier firms for reconciliation failures and missing resolution pack documentation, sending a clear message that size is no excuse.
- Individuals on the hook: Prohibition orders and personal fines are increasingly common. The regulator has banned senior managers found to have presided over weak CASS controls, making accountability personal.
One of the starkest reminders of what can go wrong came with the collapse of WealthTek LLP. In 2023, the FCA ordered the firm into special administration after uncovering serious failings in how it handled client money and records.
Investigators later estimated an £81 million shortfall in client assets, a gap made worse by disorganised and incomplete books. In practice, this meant administrators struggled to work out exactly what belonged to which client, slowing down efforts to return funds.
The case escalated further in 2024 when WealthTek’s founder, John Dance, was charged with fraud and money laundering involving £64 million of client funds. For regulators, it was a stark demonstration that poor recordkeeping can turn a regulatory breach into a crisis that leaves clients exposed and trust in the market shaken.
What Are the Common Challenges Firms Face with CASS Compliance?
If the rules are so clearly defined, why do firms keep running into trouble? The reality is that compliance with CASS is technically demanding and operationally heavy. Even firms with strong intent can slip up when controls aren’t watertight.
- Fragmented systems and legacy tech: Many firms still rely on outdated platforms that don’t integrate smoothly. Custody records may live in one system, reconciliations in another, and client communications somewhere else entirely. That fragmentation makes it difficult to produce a single, reliable view of client assets.
- Complex reconciliations: Daily reconciliations are central to CASS, but for firms handling large transaction volumes, even small delays or data mismatches can snowball into regulatory risk. Investigating breaks requires speed, coordination, and often a level of automation that smaller firms don’t yet have.
- Recordkeeping under pressure: Under CASS, records have to be complete, accurate, and immediately retrievable, which is where many firms stumble. Large transaction volumes create constant data churn; multiple platforms mean information isn’t always consistent; and manual processes introduce human error.
- Resource intensity: CASS compliance is resource-hungry. Daily reconciliations, periodic audits, constant oversight, and the infrastructure to store and retrieve records all carry costs. Larger firms can spread these costs across teams and systems; for smaller firms, they can feel overwhelming.
- Cross-border operations: Many firms operate across multiple jurisdictions, with different time zones, banking partners, and legal frameworks. Ensuring that CASS standards are met consistently across international operations adds another layer of complexity.
- Culture and awareness: Perhaps the most overlooked challenge is human. CASS compliance requires buy-in beyond the compliance team. Without a strong internal culture, CASS controls can end up being seen as “compliance admin” rather than essential safeguards.
What Are the Best Practices for Meeting CASS Requirements?
If enforcement actions show anything, it’s that waiting until the FCA knocks on the door is far more expensive than getting it right from the start. The firms that manage CASS well tend to treat compliance as part of their core operations rather than an add-on.
Here’s how to stay ahead of compliance crises:
- Automate wherever possible: Manual processes are where most errors creep in. Automated reconciliation tools, recordkeeping systems, and alerts for discrepancies reduce both operational risk and regulatory exposure.
- Strengthen governance and accountability: Giving the CASS Oversight Officer real authority and making sure senior managers are actively engaged is essential. Compliance should be supported at the board level, not left to one individual with limited resources.
- Keep records complete and current: Accurate, up-to-date records are the lifeblood of CASS. That includes maintaining acknowledgement letters, ensuring books reconcile daily, and keeping the resolution pack retrievable within 48 hours.
- Use regular audits as a safety net: Internal audits and periodic external reviews help spot weaknesses before they become breaches.
- Invest in staff training: From operations teams to senior management, everyone who touches client money should understand their responsibilities under CASS. Many breaches happen not out of malice, but because people simply don’t know what’s required.
- Focus on communication governance: Many CASS requirements depend on clear documentation and accurate records. Ensuring that client instructions, internal approvals, and reconciliation communications are captured and retrievable is becoming as critical as the financial records themselves.
CASS Compliance: Don’t Lose Sight of the Detail
CASS compliance exists for one reason: to protect clients when firms fail. The rules around segregation, reconciliations, and resolution packs are demanding because the stakes are high. Enforcement shows that the firms that fall short often do so because their records aren’t complete, their systems don’t connect, or their documentation can’t be retrieved quickly enough.
That’s why communication data matters. Client instructions, approvals, and internal sign-offs often form part of the evidentiary trail regulators expect firms to produce. If those conversations are missing, incomplete, or scattered across personal messaging apps, the integrity of a firm’s CASS records is compromised.
The LeapXpert Communications Platform addresses that risk directly by maintaining a complete record of all conversations between enterprise employees and customers, ensuring adherence to data privacy and governance requirements. Integrated with leading third-party archiving, surveillance, monitoring, and e-discovery systems, LeapXpert ensures that all message records are securely stored and made available to various compliance, audit, and management applications.
The LeapXpert Communications Platform also helps businesses enforce their policies with built-in governance controls such as strict data access control, antivirus/antimalware, advanced information barriers, and data leakage prevention, flagging breaches and preventing any threat or loss of data.
For financial institutions, that means fewer blind spots, stronger governance, and a much lower chance of being caught out in an enforcement case.
Book a demo today.
FAQs
What is CASS compliance?
CASS compliance refers to meeting the requirements of the FCA’s Client Assets Sourcebook, the rulebook that governs how firms must safeguard client money and assets. The purpose is to make sure clients are protected if a firm becomes insolvent. Compliance involves segregating client funds, performing reconciliations, maintaining clear custody records, and keeping documentation like the CASS Resolution Pack up to date. CASS compliance gives regulators confidence and clients peace of mind that their assets will be returned quickly and fairly.
Which firms must follow CASS rules?
Any FCA-regulated firm that holds or controls client money or safe-custody assets must comply with CASS. That includes banks, brokers, asset managers, investment firms, and some newer financial service providers such as crowdfunding platforms. The rules apply proportionately, meaning smaller firms don’t face the same volume of reporting as large banks, but they are still expected to meet the same fundamental standards. If a firm touches client money or assets in any capacity, CASS rules will apply.
What is a CASS audit, and why is it required?
A CASS audit is an independent review, carried out annually, that assesses whether a firm is complying with its obligations under the Client Assets Sourcebook. The audit must be performed by an external auditor who tests reconciliations, reviews records, and evaluates governance arrangements. The aim is to assure the FCA that firms are handling client money and assets correctly. For firms, it’s also an opportunity to identify weaknesses early and demonstrate that their controls are robust and effective.
What must a CASS report contain?
A CASS report sets out the findings of the annual CASS audit. It should confirm whether the firm has complied with all relevant CASS rules, detail any breaches that occurred, and explain how those breaches were addressed. Reports often include commentary on reconciliations, acknowledgement letters, recordkeeping quality, and the status of the CASS Resolution Pack. The report is provided to both the firm and the FCA, giving the regulator visibility over compliance and allowing it to intervene if serious failings are identified.
When are CASS reports due to the FCA?
CASS reports are typically due to the FCA within four months of a firm’s accounting reference date. This timeline ensures that the regulator receives timely, accurate information about how client assets are being managed. Firms are responsible for appointing an auditor in good time and making sure that all necessary records and documentation are available. Missing deadlines or submitting incomplete reports can themselves be treated as a breach, which makes early preparation essential to staying compliant.
How should firms respond to CASS audit findings?
When an audit uncovers weaknesses, firms are expected to act quickly. That means investigating the root cause, correcting any errors, and documenting remediation steps. If a material breach is found, firms must notify the FCA and keep it updated on progress. The regulator pays close attention not just to whether problems occur, but to how swiftly and effectively they are resolved. Treating the audit as a learning process rather than a one-off inspection helps firms strengthen their controls over time.
How can firms maintain ongoing CASS compliance?
Staying compliant requires consistent daily attention. Firms should automate reconciliations where possible, maintain strong oversight by the CASS Operational Oversight Officer, and regularly review documentation such as acknowledgement letters and the resolution pack. Staff training is also crucial, so that everyone understands the role they play in safeguarding client assets. Embedding compliance into everyday operations is the only way to avoid last-minute issues and reduce the risk of enforcement.
What are common CASS compliance failures?
The FCA’s enforcement record highlights recurring themes. Poor recordkeeping is one of the biggest issues, as incomplete or inaccurate books make it difficult to identify client assets. Firms are also frequently cited for reconciliation failures, missing or outdated acknowledgement letters, and resolution packs that aren’t ready when needed. Weak governance, where the CASS oversight function has limited authority, is another common problem. Each of these failures undermines client protection, which is why they continue to attract regulatory scrutiny and fines.
Book a personalized
product demo