Why client money is not an ordinary finance process

CASS 5 applies to client money received or held during insurance distribution activity. The handbook covers segregation, designation of client bank accounts, mixed remittances, reconciliations, and the treatment of money held on behalf of clients. The purpose is asset protection: a firm must be able to identify client money, separate it from its own, and maintain a clear evidential basis for how those balances are held and reconciled.

What makes it different from every other finance discipline is trust law. Client money trust arrangements mean the broker acts as trustee and owes fiduciary duties to the beneficiaries of the trust. That is why apparently technical errors — poor account naming, an invalid acknowledgement letter, a mixed remittance mistake, premature commission extraction — become legal, regulatory, and conduct issues rather than ordinary back-office corrections.

The goal is therefore not simply to avoid breach. It is to build a framework that stays accurate, explainable, and defensible under audit, FCA scrutiny, staff turnover, business growth, and operational disruption. The strongest message from the Handbook, the CII good practice guide, audit commentary, and supervisory letters is consistent: client money control depends on disciplined execution rather than policy wording. Signed TOBAs, correct risk transfer treatment, properly designated trust accounts, valid bank acknowledgement letters, accurate calculations, controlled commission extraction, timely reconciliation, and clear governance all have to work together. When one fails, weaknesses in the others surface quickly behind it.

Three ways of holding insurance money

The obligations differ sharply by method, and misclassification is itself a common failure.

Table 1 — Holding methods, obligations, and audit triggers
MethodDescriptionCASS 5 obligationsAudit requirement
Risk transferThe insurer grants the broker authority to hold money as its agent. Premium paid to the broker is treated as received by the insurer, and credit risk transfers to the insurer.Not subject to CASS 5 — provided the TOBA is valid, in writing, signed, non-conditional, and cascades correctly through any sub-agent chain.Not required unless the insurer TOBA specifically demands it.
Statutory trust (ST)Client money held in a designated statutory trust account under CASS 5.3. Trust status arises automatically; no deed required. The broker may not advance credit from the account.Full CASS 5 obligations: segregation, bank acknowledgement letters, a client money calculation at least every 25 business days, reconciliation, commission extraction rules.Required if the balance exceeds £30,000 at any point in the year.
Non-statutory trust (NST)Client money held under a formal trust deed executed under CASS 5.4. The deed permits credit to be extended to clients or insurers from the account, subject to controls.Full CASS 5 obligations plus the additional controls required by the deed. Higher capital requirements apply for retail-facing firms.Required irrespective of balance.

Six principles that hold the model together

  1. Segregation is structural, not administrative. Client money is held on trust and separated from firm money and from other client pools by account design, not by ledger annotation.
  2. Legal basis before account treatment. How money is held follows from a valid, signed, unconditional TOBA or trust deed — not from operational convenience.
  3. Contemporaneous evidence. Working papers, sign-offs, and reconciliations captured as they happen, not reconstructed at year-end. Reconstructed evidence is not the same thing.
  4. Timely calculation. Running the client money calculation close to the 25-business-day limit, or treating it as a month-end formality, is what turns small errors into large ones.
  5. Controlled extraction. Commission moves out of the client money account only on a valid calculation showing a surplus — not on cash-flow preference, monthly schedule, or treasury convenience. The calculation must precede the extraction, and the evidence linking the two must be retained.
  6. Continuous challenge. Firms are expected to test and validate system outputs, not accept software reports as inherently correct. Automating the calculation does not transfer responsibility for its accuracy.

Why control fails in practice

Most client money failures are caused by weak control design, incomplete understanding, and process drift rather than by one dramatic event. That is why many firms appear stable until an audit, acquisition, system migration, or staffing change exposes how much of the model depends on manual memory and informal workarounds.

Control fragmentation

Many firms have the right components on paper but not in one coherent operating model. Legal manages TOBAs. Finance runs reconciliations. Operations handle transaction posting. Account teams chase insurers and clients. Compliance reviews breach logs. No single control framework connects them end to end.

The result is that problems surface as symptoms in one area while the root cause sits in another. A stale risk transfer clause drives incorrect account treatment. Weak commission logic creates repeated calculation breaks. An appointed representative’s balances never reach the calculation because operations and finance never agreed how to exchange the data. This is also why the same findings recur across years of CASS audits: each function remediates its own symptom, and nobody owns the end-to-end model.

Over-reliance on systems without validation

The CII good practice guide warns specifically that firms often rely on standard broking-system reports without testing or validating them. Software can automate calculation and reporting, but it cannot transfer accountability for rule interpretation, data classification, or output validation away from the broker. A calculation is only as accurate as the data and logic feeding it, and firms that accept the output without tracing it to source records lose the ability to detect errors before they accumulate.

Reconciliation as a periodic formality

Where the client money calculation is treated as a periodic compliance task rather than the primary adequacy control, problems accumulate between cycles. Running close to the 25-business-day maximum satisfies the outer rule limit while leaving far too much room between detection points.

The eight most common failure modes

The FCA’s Dear CEO letters, the CII guide, and CASS audit commentary identify the same patterns repeatedly. The same symptom can have different causes, and treating the symptom without the cause reproduces the finding at the next audit.

Table 2 — Failure pattern, root cause, and consequence
Failure patternWhy it happensWhy it matters
Non-compliant client money calculationsWrong inputs: live balances used instead of prior day; third-party balances not captured; incorrect methodology; system outputs accepted without validation.Creates false comfort about adequacy. Over half of assessed firms failed this in the FCA’s 2021 review.
Premature commission extractionTreasury sweeps run on a fixed schedule, overriding the control sequence. Calculation sign-off treated as a formality that follows extraction rather than precedes it.Risks misuse of client money. The FCA treats commission drawn before entitlement is evidenced as a potential financial crime concern.
Weak TOBA governanceTOBAs outdated, unsigned, or ambiguous. Risk transfer provisions not reviewed when relationships change or sub-distribution tiers are added.Undermines the legal basis for account treatment. Invalid risk transfer means CASS 5 obligations apply from the date the provision became invalid.
Defective acknowledgement lettersWrong template; fixed text deleted; signed by bank staff without authority; not updated after account or bank changes.Weakens the account-level legal protection trust status is meant to provide. A defective letter is a breach from the point of deficiency.
Co-mingling without authorityOperational convenience overrides legal structure — risk transfer money and client money in the same account without the required insurer consent.Can break the trust and expose all beneficiaries to loss, not just the affected transaction.
Poor third-party oversightAppointed representatives and delegated operators report balances late or not at all. No process connects external holdings to the firm’s own calculation.Understates the client money requirement, making the calculation unreliable even when executed correctly.
Weak evidence retentionFiles assembled retrospectively. Working papers, sign-off records, and bank reconciliations spread across systems with no single audit trail.Increases audit and supervisory risk. Reconstructed evidence is not contemporaneous evidence.
Low-quality governance MIBoards receive status summaries without root-cause analysis. Clean dashboards reflect weak detection rather than strong control.Problems persist until an audit or enforcement trigger exposes them — and the personal accountability consequences fall on the senior managers who received those summaries.

What a compliant operating model looks like

A defensible CASS 5 model is a connected set of processes, controls, systems, and governance arrangements that together ensure client money is always correctly identified, held, calculated, reconciled, and evidenced. Eight components.

  1. Governance and accountability. A named CASS oversight role with genuine authority, board-level management information that carries root-cause analysis rather than status counts, and clear ownership for breaches, reconciliations, and bank diversification.
  2. Account architecture. Correctly designated and titled trust accounts, valid acknowledgement letters for every one of them, and concentration risk monitored across banks rather than assumed away.
  3. Risk transfer management. A live register of which insurer relationships carry valid risk transfer, reviewed whenever a relationship changes or a distribution tier is added, with the cascade through sub-agents explicitly checked.
  4. The client money calculation. Correct inputs — prior-day balances, all third-party holdings included — a documented methodology, and outputs traced back to source records rather than accepted from a report.
  5. Reconciliation discipline. Frequent internal reconciliation with every break investigated, owned, and aged; external reconciliation to bank statements signed off by CASS oversight rather than by the team that produced it.
  6. Commission extraction. A hard control sequence: valid calculation, evidenced surplus, then extraction. Never the other way round, and never on a treasury timetable.
  7. Systems and technology. A single evidential trail rather than working papers spread across finance, operations, and compliance tooling — with the ability to interrogate any figure back to source.
  8. Delegated and third-party oversight. A defined process that pulls appointed representative and delegated operator balances into the calculation on a known cadence, with escalation when they are late.

What boards should be asking

  • Can we evidence that every client money calculation in the last twelve months used prior-day balances and captured all third-party holdings?
  • For every trust account we operate, do we hold a valid, current acknowledgement letter — and who checked?
  • Which insurer relationships rely on risk transfer, when was each TOBA last reviewed, and does the provision cascade correctly through our sub-agents?
  • In the last quarter, did any commission extraction precede its calculation sign-off?
  • How long would it take to assemble a complete evidence pack for an auditor from current data, without anyone reconstructing anything?
  • When the board last saw a clean client money dashboard, what evidence accompanied it that detection is actually working?

A 90-day starting point

  1. Weeks 1–2. Inventory every client money account, its designation, and its acknowledgement letter. Flag anything unsigned, out of date, or on the wrong template.
  2. Weeks 3–4. Re-perform the most recent client money calculation independently from source records. Document every difference.
  3. Weeks 5–8. Map the extraction sequence end to end and prove the calculation precedes it in every case. Where it does not, fix the sequence before fixing the reporting.
  4. Weeks 9–12. Rebuild the governance pack around root cause: breaks by cause, repeat findings, ageing, third-party balance timeliness, bank concentration.

Client money control and commission accuracy are the same evidence chain viewed from two ends. If the commission calculation is unreliable, extraction cannot be evidenced — we cover that side in The Hidden Cost of Commission Leakage.