OpenChainGraph Suite · ART-501 · UK CASS 15 Safeguarding · Audit Evidence

CASS 15 Safeguarding Audit Evidence Pack

A UK payment or e-money firm gets a safeguarding audit once a year, and the auditor opens it by asking for the same things: the reconciliations across the period, how each funds stream is safeguarded, what those two raised, and who inside the firm prepared, reviewed and signed the reconciliation export. This page assembles that set from figures the firm already holds, in the engagement's own field names.

The reconciliation export is a spreadsheet or a report builder's file, produced by a tool that is not part of this graph. Its §27.4 subject identifier is computed by the attested artifact subject binder and echoed here verbatim. This page does not recompute it: a second implementation of that preimage would be a second canon, and the binding is independently checkable against art-502 from the echoed preimage alone.

First §27.4 consumer Distinct-identity trail No clock anywhere
Rule set pinned in every artifact this page exports: FCA-CASS15-PS25-12 · FCA CASS 15 safeguarding rules, as made by PS25/12 · in force from 2026-05-07 · field set version 1.0.0 · sourced from handbook.fca.org.uk on 2026-07-30.
What this is, and what it is not

The output is evidence assembled for the engagement. A regulatory filing is a different thing: this pack is not submittable to the FCA, it does not reproduce the prescribed report as a fillable form, and it does not discharge the audit. An approval record inside it is evidence that a named human acted, never a claim that a regulator has accepted anything.

Neither audit opinion is expressed here. The report carries two: whether the firm maintained systems adequate to enable it to comply throughout the period, and whether the firm was in compliance at the period end. Both are emitted as open slots naming the auditor as the decider. A tool that filled them in would be pretending to be the auditor.

The attested subject evidences producer pinning, input binding and content integrity. It carries no §18 compute proof and no §16 or §17 re-execution claim, and it never evidences that the arithmetic inside the firm's export is correct. Because no replay was attempted, the exported artifact omits replay_verified entirely rather than setting it false.

The schedule below lists matters for the auditor's attention. Nothing here is recorded as a breach: whether any of these is a breach of CASS 15 is for the firm's own records and its safeguarding auditor.

🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data – use synthetic or anonymised inputs only.
⚠ No clock is read anywhere on this page. The audit period and every as-of date are values you supply. Because there is no clock, a time-boxed §27.5 override cannot be tested for expiry here, so an override never satisfies a required role and is reported instead.
Engagement
Attested subject (paste the art-502 output_payload)
Reconciliation results across the period (art-499 outputs)
Method classification (art-500 output)
Accountability records over the subject (§27)
Management responses, keyed by exception item_ref
Attested subject, echoed from art-502
Reconciliation results carried
Matters for the auditor's attention, by rule reference
Accountability trail (§27)
Auditor opinions
Pack completeness
Execution Hash (SHA-256)
Related

Consumes the safeguarding reconciliation check, the safeguarding method classifier, and the attested artifact subject binder. The subject class it is the first consumer of is described at §27.4 of the OpenChainGraph specification.