About a-team Marketing Services
The knowledge platform for the financial technology industry
The knowledge platform for the financial technology industry

A-Team Insight Blogs

UK FSA Pokes Holes in Investment Firms’ Protection of Client Assets

Subscribe to our newsletter

This week, the UK Financial Services Authority published another “Dear CEO” letter, this time aimed at compelling insurance brokers and investment firms to improve the way they protect client assets, including record keeping considerations. The letter, sent by the FSA’s managing director of risk, Sally Dewar, warns that firms must take heed of the regulator’s client money and custody requirements (CASS) or face further action.

Dewar’s letter is a response to the findings of the regulator’s recent report into firms’ compliance with FSA Principle 10, which states that a firm must arrange adequate protection for clients’ assets when it is responsible for them. The report is itself a follow up to the FSA’s “Dear Compliance Officer” letter, issued back in March last year, in which it warned firms of the impending research into their client asset management practices.

The FSA has indicated that many of the 50 firms it surveyed during the six month research period were found wanting in terms of their control of client assets, including their recordkeeping and data management around the storage of these assets. Thus far the regulator has taken action against four firms by freezing one firms assets, banning another from taking on new business and referring two others to its enforcement division for possible disciplinary action.

This is all part of the regulator’s crackdown on the systems and controls aspects of its overall regulatory reporting regime. It is seeking to prove its seriousness in cracking down on those that are found to be lacking. “This intensive supervision will persist and we will continue to take action where we believe that client assets are not sufficiently protected,” warns Dewar in her letter.

The range of problems identified in the report must be tackled immediately and due diligence must be restored, the FSA contends. Much like the FSA’s recent letter on liquidity risk, these CEOs must now write back and confirm that they are taking heed of these problems.

The next month or so should see an increase in investment in firms’ compliance systems and controls in order to meet these demands. This will likely include an extra level of data scrutiny with regards to providing an audit trail for the storage of these client assets.

Subscribe to our newsletter

Related content

WEBINAR

Recorded Webinar: How to simplify and modernize data architecture to unleash data value and innovation

The data needs of financial institutions are growing at pace as new formats and greater volumes of information are integrated into their systems. With this has come greater complexity in managing and governing that data, amplifying pain points along data pipelines. In response, innovative new streamlined and flexible architectures have emerged that can absorb and...

BLOG

From Sandbox to Scale-Up: How the FCA Plans to Shape UK Fintech Growth

In her address at Merchant Taylors’ Hall on 17 September 2025, Jessica Rusu, the FCA’s Chief Data, Information and Intelligence Officer, set out a comprehensive programme of initiatives underpin the regulator’s growth and innovation agenda. The speech, “Regulating for growth – the future is now”, presented four central pillars: strengthening crypto oversight, advancing artificial intelligence...

EVENT

AI in Capital Markets Summit London

Now in its 2nd year, the AI in Capital Markets Summit returns with a focus on the practicalities of onboarding AI enterprise wide for business value creation. Whilst AI offers huge potential to revolutionise capital markets operations many are struggling to move beyond pilot phase to generate substantial value from AI.

GUIDE

The DORA Implementation Playbook: A Practitioner’s Guide to Demonstrating Resilience Beyond the Deadline

The Digital Operational Resilience Act (DORA) has fundamentally reshaped the European Union’s financial regulatory landscape, with its full application beginning on January 17, 2025. This regulation goes beyond traditional risk management, explicitly acknowledging that digital incidents can threaten the stability of the entire financial system. As the deadline has passed, the focus is now shifting...