An electronic money institution holds value that belongs to its customers, not to itself. When a customer loads funds onto a platform, the money they hand over remains theirs in substance even though the platform operates the accounts that move it. Safeguarding is the regulatory obligation that keeps that principle intact: customer funds are separated from the firm's own money and protected so that, if the firm fails, those funds can be returned. Ledger records are what allow the obligation to be demonstrated — the evidence that issued value and safeguarded funds still agree.
That combination of a legal duty and an evidential burden is why safeguarding is rarely a single control. It reaches the executive weighing the regulatory risk of getting it wrong, the technology owner whose systems must produce accurate records without manual intervention, and the compliance function that must show, on request, that the money is where it should be. All three rely on the same underlying record.
This article sets out what safeguarding requires of an e-money platform, how issued value relates to safeguarded funds, why the ledger is the record that evidences the obligation, and how reconciliation, retention and audit make that record dependable. It stays at the level of concept and evaluation rather than implementation, since the design that satisfies these duties varies with a platform's size, markets and funding model.
What Safeguarding Means
Safeguarding is the requirement that an authorised payment or electronic money firm protect the funds it receives from customers by keeping them separate from its own resources. In practice this is achieved either by holding the money in a designated account with a credit institution, kept apart from the firm's operating funds, or by covering it with an insurance policy or comparable cover. The common purpose is that customer money remains identifiable as such and is placed beyond the reach of the firm's own creditors.
Two features of the obligation are easy to overlook. The first is that safeguarding concerns the money itself, not the balance a customer sees in an app; the displayed balance is a record, while the safeguarded funds are the resource that stands behind it. The second is that the firm remains responsible even where the funds physically sit with a third-party credit institution. Delegating custody does not delegate the duty, and a platform should say that funds are safeguarded at a regulated institution rather than implying that it holds or safeguards the money itself.
Issued Value and Safeguarded Funds
Every unit of electronic money a platform issues is a claim its customers hold against it. The sum of those claims — the total of all customer balances — is the amount the firm is obliged to safeguard at any given moment. Safeguarding holds when the funds set aside equal that total, so that the resource held always matches the requirement the balances represent.
This is where records and money meet. The customer balances live in the platform's ledger; the safeguarded funds sit in an account at a credit institution. The two are maintained by different systems, updated on different timelines, and reconciled against each other rather than assumed to agree. When a customer loads funds, both should rise together; when value is redeemed or spent out of the safeguarded environment, both should fall. The discipline of safeguarding is keeping those movements in step and being able to show that they are.
The Ledger as the Record of Safeguarding
The ledger is the authoritative record of how much electronic money the platform has issued and to whom. For safeguarding its role is specific: it establishes the requirement — the total that must be covered — against which the safeguarded resource is checked. A ledger that records every issuance, redemption and transfer accurately, in order and without loss produces a defensible figure for the amount to be safeguarded; one that does not leaves the firm unable to state its own obligation with confidence.
What matters for safeguarding is not the internal accounting technique but the properties of the record. It must be complete, so that no movement of value is missing; consistent, so that the same event is never counted twice; and durable, so that the history cannot be quietly rewritten. These properties are what let the ledger stand as evidence rather than a working estimate, and they determine how quickly the requirement can be produced — frequently rather than once a quarter.
Safeguarding Reconciliation
Safeguarding reconciliation is the comparison of two independently maintained figures: the requirement calculated from the ledger, and the resource actually held in the safeguarding account or covered by the safeguarding arrangement. When the two agree, the firm can show that customer funds are fully protected; when they diverge, the difference is a signal that must be explained and corrected rather than smoothed over.
The expectations around this exercise have become more demanding. In the United Kingdom, the rules governing how payment and e-money firms safeguard customer money were strengthened during 2026, with more frequent reconciliation and regular reporting anticipated of firms. The practical consequence is that reconciliation shifts from a periodic accounting task to a routine operational control, run often enough that a shortfall is caught in hours rather than at month-end.
As with any reconciliation, the value lies in how differences are handled. Timing effects, funds in transit, returned payments and misattributed credits all produce temporary gaps, and a dependable design records each as a defined, investigated state rather than absorbing it. A persistent or unexplained difference between requirement and resource is what a safeguarding process exists to surface.
Evidence, Retention and Audit
Records satisfy safeguarding only if they can be produced later, in a form that a supervisor, an auditor or an administrator can rely on. That means the ledger and the reconciliation results are retained for the period the applicable rules require, stored so that they cannot be altered after the fact, and organised so that the position on any past date can be reconstructed. Evidence that exists only as a current balance, with no defensible history behind it, does little to demonstrate that the obligation was met yesterday or last year.
Note: A record that customer funds are safeguarded is not the same as the platform holding those funds. The money is held at, or covered by, a regulated institution; the platform's responsibility is to keep the record that proves how much must be safeguarded and to reconcile it against what is held. Presenting the internal balance as if it were the safeguarding account is a common and consequential error.
For the compliance function, this retained history is the working material of supervision: regular safeguarding reporting, ad-hoc requests and a clean audit trail all draw on it. For the technology owner, the implication is that safeguarding is not a report produced at the end but a property of how value is recorded throughout, captured as events occur.
Roles and Regulatory Boundaries
The responsibilities in a safeguarding arrangement are shared but distinct. The regulated institution that holds or insures the funds provides the protected environment; the platform operates the accounts, keeps the ledger, calculates the requirement and performs the reconciliation. Where a platform relies on a partner for both, the boundary must be understood precisely, because the firm issuing the electronic money remains accountable regardless of where the money sits.
The regulatory context frames these duties without dictating a single design. In the United Kingdom, registration under the money-laundering rules is not the same as authorisation to issue electronic money or hold customer funds, and the strengthened safeguarding expectations described above apply to firms that are authorised. In the European Union, electronic money is issued under the current payments and e-money framework, with an updated single EU payments rule-set incoming but not yet in force. Across both markets the consistent principle is that customer funds are protected and demonstrably accounted for. We do not provide legal opinions or guarantee authorisation. We implement regulatory and audit requirements across technology, infrastructure and operations. Regulatory readiness in this area is a property of the platform's records and controls, not a certificate it can hold.
Evaluating Safeguarding and Records
Assessing whether a platform — built in-house or supplied by a vendor — can support safeguarding is less about features than about the qualities of its records and the reliability of its reconciliation. The areas below tend to separate an arrangement that will withstand supervision from one that looks adequate until it is tested.
| Area | What to confirm |
|---|---|
| Requirement calculation | How the platform derives the total that must be safeguarded, and how quickly that figure can be produced on demand. |
| Reconciliation | How the safeguarding requirement is compared with funds held, how frequently, and how differences are investigated and cleared. |
| Record integrity | Whether the record of issued value is complete, protected against retrospective change, and able to reconstruct any past position. |
| Exceptions | How funds in transit, returned payments and unattributed credits are recorded and resolved rather than absorbed. |
| Retention and reporting | How long records are kept, in what form, and how regular and ad-hoc safeguarding reporting is produced. |
| Roles and boundaries | Which regulated institution holds or insures the funds, and where the platform's responsibility begins and ends. |
| Ownership and deployment | Whether the firm can operate and evidence these controls on infrastructure it controls, including on-premises or dedicated deployment where required. |
A recurring question is how much of this to build and how much to obtain from a partner: a partner can provide accounts and the protected environment, but not the firm's own duty to record and reconcile. Architecture advisory at this stage is usually less about technology selection than about the controls that are costly to add once a platform is live.
Summary and Next Steps
Safeguarding protects customer money by keeping it separate and demonstrably accounted for, and ledger records are what make the demonstration possible. The obligation is met not by a single report but by a record that is complete, durable and reconciled often against the funds actually held, with differences investigated and evidence retained for as long as the rules require. Treated this way, safeguarding becomes a continuous property of how a platform records value rather than a control added before an inspection. Grumpio approaches it as part of a wider e-money platform architecture designed to be regulatory-ready from the outset.
Build safeguarding and records that hold up to reconciliation and audit. Grumpio designs e-money platform architecture around accurate records, frequent reconciliation and regulatory readiness.