A UK payment or e-money firm gets a safeguarding audit once a year, and the auditor opens it by asking for the same things: the reconciliations across the period, how each funds stream is safeguarded, what those two raised, and who inside the firm prepared, reviewed and signed the reconciliation export. This page assembles that set from figures the firm already holds, in the engagement's own field names.
The reconciliation export is a spreadsheet or a report builder's file, produced by a tool that is not part of this graph. Its §27.4 subject identifier is computed by the attested artifact subject binder and echoed here verbatim. This page does not recompute it: a second implementation of that preimage would be a second canon, and the binding is independently checkable against art-502 from the echoed preimage alone.
The output is evidence assembled for the engagement. A regulatory filing is a different thing: this pack is not submittable to the FCA, it does not reproduce the prescribed report as a fillable form, and it does not discharge the audit. An approval record inside it is evidence that a named human acted, never a claim that a regulator has accepted anything.
Neither audit opinion is expressed here. The report carries two: whether the firm maintained systems adequate to enable it to comply throughout the period, and whether the firm was in compliance at the period end. Both are emitted as open slots naming the auditor as the decider. A tool that filled them in would be pretending to be the auditor.
The attested subject evidences producer pinning, input binding and content integrity. It carries no §18 compute proof and no §16 or §17 re-execution claim, and it never evidences that the arithmetic inside the firm's export is correct. Because no replay was attempted, the exported artifact omits replay_verified entirely rather than setting it false.
The schedule below lists matters for the auditor's attention. Nothing here is recorded as a breach: whether any of these is a breach of CASS 15 is for the firm's own records and its safeguarding auditor.
Consumes the safeguarding reconciliation check, the safeguarding method classifier, and the attested artifact subject binder. The subject class it is the first consumer of is described at §27.4 of the OpenChainGraph specification.