Safeguarding client funds: why governance and board oversight must move up the agenda
.jpg)
Recent regulatory enforcement across Europe has sent a clear signal. Safeguarding of client funds is no longer a back-office compliance exercise. It is a front-line governance priority and an essential component of maintaining the operational licence on which every regulated firm depends.
For Boards and senior management, the message is clear. Substantive oversight of safeguarding arrangements is a licence condition and falling short carries material consequences. In 2025, a safeguarding breach resulted in the revocation of a financial institution's licence, together with the imposition of regulatory penalties.
The Regulatory Landscape and Common Weaknesses
Under Chapter 3 of the Financial Institutions Rulebook (FIR/03), licensed entities must maintain segregated accounts, appoint a dedicated Safeguarding Officer, implement Board-approved safeguarding policies, and conduct risk-based reconciliations with same-day correction of discrepancies. Acknowledgement letters, annual audits, and timely notification to the MFSA of any changes to safeguarding arrangements are also key obligations for financial institutions.
However, thematic reviews and enforcement actions undertaken by the MFSA have continued to highlight recurring weaknesses in safeguarding arrangements. The MFSA's January 2025 “Dear CEO” letter highlighted governance gaps such as the absence of a formally designated Safeguarding Officer, Boards that are not actively engaged, and insufficient segregation of duties on safeguarding accounts. Documentation deficiencies, including policies created only in response to the review itself, and reconciliation procedures lacking proper sign-off or frequency were equally prevalent. Concentration risk, where firms rely on a single safeguarding provider without documented justification, remains a further area of concern.
Beyond these findings, a number of recurring patterns emerge across enforcement actions. Poor segregation of duties, whereby individuals responsible for handling client money also perform the associated control checks, remains a persistent vulnerability. Equally common is inadequate oversight of outsourced or intra-group safeguarding functions, where licensed entities assume that a group entity or third-party administrator is managing compliance without conducting documented monitoring or challenge. Delayed or missing regulatory notifications and weak reconciliation practices, characterised by infrequent reviews, incomplete documentation trails, and discrepancies left uncorrected beyond the same business day, further compound these weaknesses.
European case studies reinforce these themes. A prominent Irish enforcement action saw a payment services firm fined over €324,000 for co-mingling client funds and failing to oversee group-provided safeguarding operations. In the United Kingdom, the absence of adequate maker-checker controls exposed clients to fraud, ultimately resulting in criminal charges against a firm principal and a voluntary payment approaching £20 million.
Strengthening Board Responsibility
Effective safeguarding governance demands that the Board does more than receive periodic reports. Boards must actively approve safeguarding policies and reconciliation methodologies, challenge the adequacy of controls and third-party arrangements, and ensure that meeting minutes record substantive discussion, specific questions raised, and follow-up actions with clear owners and deadlines. Additionally, a structured reporting framework equips Boards to move from passive receipt of information to genuine, evidence-based oversight.
The Role of Internal Audit
As the third line of defence, internal audit plays a critical role in providing independent assurance over the safeguarding framework. Amongst other matters, this includes reviewing the effectiveness of governance arrangements and monitoring the timely remediation of prior audit findings. Where outsourced or intra-group safeguarding arrangements are in place, internal audit should assess whether the licensed entity retains genuine operational accountability rather than relying on assumed compliance by service providers.
Looking Ahead
The common thread running through recent enforcement is not a lack of rules but a lack of governance rigour. Firms that invest in practical controls and meaningful Board engagement, are far better positioned to protect client funds and demonstrate compliance. For those yet to act, the time to close governance gaps is now, before the regulator does it for you.
The common thread running through recent enforcement is not a lack of rules but a lack of governance rigour. Firms that invest in practical controls and meaningful Board engagement are far better positioned to protect client funds and demonstrate compliance. For firms looking to strengthen their position, a proactive review of safeguarding governance, starting with the areas highlighted above, is a practical and worthwhile first step.


