When the Financial Conduct Authority (FCA) executes a surprise spot-check, a firm has exactly 48 hours to produce a complete Client Assets Resolution Pack under CASS 10 rules. To test real-world readiness, the regulatory specialist firm Compliance Consultant designed and executed a simulated gone-concern drill for a 100-person London-based investment firm holding client money under CASS 7. The exercise revealed that while the firm maintained standard regulatory binders, they could not physically extract their live daily reconciliation data within the regulatory timeframe without relying on absent personnel. By transitioning from static documents to an automated living-document architecture, the firm reduced its retrieval window from multiple business days to under 12 hours, ensuring full operational resilience ahead of a real supervisory visit.
The CASS 10 regulatory environment and Compliance Consultant’s diagnostic baseline
The rules governing client asset protection are some of the most strictly enforced in the UK financial sector. Under the FCA Handbook CASS 10, the purpose of a CASS resolution pack (CASS RP) is to ensure that a firm maintains and is able to retrieve information that would assist an insolvency practitioner in achieving a timely return of client money and safe custody assets. The regulation is designed to prevent the protracted delays that historically left client funds frozen for years during famous corporate collapses.
In our diagnostic review of a mid-sized London wealth manager holding client money under CASS 7, we found a familiar sense of security. The firm possessed a beautifully formatted master document stored in a shared drive, which had been signed off during their annual compliance cycle. They believed this folder constituted a fully compliant CASS RP.
However, a CASS RP is only as good as its retrieval speed during an actual crisis. The FCA expects firms to be able to deliver the complete pack within 48 hours of a request, whether the business is operating as a going concern or has suddenly become a gone concern. Our diagnostic baseline showed that while the firm had the structural policy documents in place, they had never stress-tested the operational extraction of their daily ledger data under simulated emergency conditions.

Identifying structural operational gaps in client asset management
To understand why the firm struggled during the initial assessment, it is necessary to separate the resolution pack into its two functional parts. Many compliance officers treat the pack as a single, static manual, but in reality, it is a combination of permanent organizational records and constantly changing transactional data.
The static document trap
A standard Client Assets Sourcebook compliance file often includes bank schedules, custodian agreements, trust letters, and corporate governance maps. In the firm we audited, these files were saved as static PDFs.
The problem with static storage is that corporate structures are fluid. During our baseline review, we discovered that three of the bank accounts listed in the master schedule had been closed during an unrecorded treasury transition. Furthermore, the designated individual responsible for client asset oversight had recently changed, but the internal records still listed the former officer. This meant that an insolvency practitioner relying on the pack would have spent critical hours chasing non-existent bank accounts and contacting departed personnel.
The daily extract gap
The second, more challenging component of a CASS RP consists of daily extracts. Under CASS 10, a firm must be able to produce the exact client money balances, safe custody asset balances, outstanding reconciliation breaks, and open breach logs from the previous business day.
Our audit revealed that compiling this information was a highly manual process. It required data extracts from three separate back-office software platforms. Worse, the administrator credentials for the primary legacy database were held exclusively by a senior operations manager who happened to be away on annual leave during our initial check. Because no one else had the system permissions to run the database query, the firm could not retrieve their outstanding reconciliation breaks, creating a single point of failure.
The Compliance Consultant simulated insolvency methodology
To address these systemic vulnerabilities, Compliance Consultant implemented a targeted operational restructuring. We utilize a structured approach known as the “engage, execute, embed” methodology, which is defined across four clear principles:
- Demonstrating business return on investment before implementation by providing exceptional value.
- Driving process and organizational change early in parallel with infrastructure development.
- Starting with a sample department or area to test processes and technology in real business situations, then applying scale to other or all areas as required.
- Compliantly gaining momentum and then rapidly deploying solutions to the remainder of the organization while providing hands-on support through to embedding.
Initiating the surprise drill
We initiated a surprise gone-concern drill at exactly 09:00 on a Tuesday morning. The compliance and operations teams were notified that an emergency scenario had commenced, simulating a sudden liquidity failure where key staff were unavailable.
The 48-hour countdown began immediately. The team spent the first twelve hours trying to locate original bank acknowledgment letters and custody agreements. Because their systems for record-keeping had not been consolidated, staff were forced to search physical archives and disparate electronic folders. This operational friction is a common reason why firms struggle to maintain regulatory standards, a risk we emphasize when guiding firms through the process of how to get FCA authorisation in 2026.
Mapping the retrieval process
To fix these issues, we used our professional compliance support services to conduct a thorough mapping of the entire data retrieval process. We traced every piece of information required by CASS 10 back to its primary source.
Our team mapped the software systems, identified the personnel who held access credentials, and documented the exact steps needed to generate the daily extracts. This mapping exercise highlighted that the firm’s compliance team was entirely separated from the IT and treasury departments. By documenting these connections, we created a clear blueprint that allowed any trained employee to locate and extract the necessary files without relying on a single key individual.

How the investment firm restructured its data pipelines
The initial surprise drill failed at hour 36 because the team could not produce the daily reconciliation break ledger or verify the signatures on three historic custodian agreements. In total, we identified seven distinct missing documents and three critical system access failures.
Transitioning to a living document
The firm had to abandon the practice of maintaining a static PDF folder. As pointed out by regulatory analysts at Safeguarding Regime Changes – Neopay, the most effective resolution packs are designed as living documents that link directly to active system records rather than offline spreadsheets.
We helped the firm build a digital master index. Instead of containing static files, this index uses automated file-path links and secure API connections that pull the previous day’s bank ledger balances and outstanding breaks directly into a secure, centralized compliance dashboard. If a bank account is closed or a custodian agreement is updated, the master index reflects that change automatically. This change eliminated the need for manual file transfers and spreadsheet exports.
The second drill success
Three months after implementing the automated digital index, we initiated a second surprise drill. This test was designed to simulate a complete network outage at the firm’s physical office in London, forcing the team to work from a secure backup location.
The results were completely different. The operations team logged into the digital master index from their secure remote portals. They retrieved the full suite of structural agreements, bank letters, and live daily extracts in just 9 hours and 45 minutes. Every bank schedule matched the ledger balances perfectly, and all documentation was complete, proving that the firm could successfully pass a real FCA inspection under the tightest constraints.
Applying CASS 10 operational principles to your business
The lessons from this case study apply to any regulated firm holding client money or managing custody assets in the UK, Europe, or the Middle East. A resolution pack is not a bureaucratic checkbox; it is an active operational system.
| CASS RP Component | Traditional Static Approach | Living Document Approach |
| — | — | — |
| Master Index | Static PDF updated once a year | Digital index with live file-path links |
| Bank Schedules | Manual spreadsheet entries | Automatic API ledger sync |
| System Access | Single compliance manager | Shared, secure credential vault |
| Update Cadence | Annual review cycle | Real-time operational change control |
| Drill Readiness | Untested paper files | Tested quarterly via surprise drills |
For investment firms
If your firm is regulated under CASS 6 or CASS 7, you should assume that the FCA will eventually test your readiness. The regulator frequently uses surprise spot-checks, giving firms only 48 hours to deliver their complete CASS RP.
Failing to meet this standard carries heavy penalties. Historically, three multinational financial institutions were fined more than £143 million for failing to maintain adequate resolution packs. To protect your business, you must move away from manual record-keeping and implement regular, independent reviews of your extraction capabilities.
For payment firms facing new safeguarding rules
This operational burden is no longer restricted to traditional investment managers. Under the new CASS 15 sourcebook, which came into effect on May 7, 2026, via policy statement PS25/12, payment and e-money institutions face identical pressures.
As highlighted in the Deloitte UK Safeguarding Shift, payment firms are now required to maintain a fully compliant safeguarding resolution pack. This change means that payment boards must dedicate sufficient resources to document their safeguarding flows and run regular recovery drills. If you manage a payment institution, you must build these data pipelines now to avoid severe regulatory action.

Securing operational resilience with Compliance Consultant
Building and maintaining a compliant CASS RP requires continuous focus and specialized expertise. Many mid-sized financial firms do not have the budget to employ a full-time, senior compliance director to manage these complex projects.
Our compliance retainer services offer an expert-led alternative to hiring expensive full-time staff. We provide two structured retainer tiers designed to give your firm complete budget certainty and access to qualified advisors:
- Compliance Professional (Silver): Suited to established firms wanting proactive compliance management. Priced at £895 per month (billed quarterly at £2,685) or £795 per month on annual billing (£9,540/year). It includes 8 hours of advisory support, a 1-business-day response SLA, quarterly compliance reviews, and full access to our digital templates worth £1,194.
- Compliance Partner (Gold): Suited to firms wanting a dedicated compliance partner. Priced at £1,495 per month or £1,345 per month on annual billing (£16,140/year). It includes 16 hours of advisory support, a guaranteed 4-hour response SLA, monthly board-level MI reporting, and access to our complete template library worth £3,638.
Our comprehensive Gold retainer costs less than 17% of employing a standard, full-time compliance manager (based on a typical £60,000 UK base salary, with London roles historically commanding 20% to 40% more). This represents a direct annual saving of over £84,000, with no recruitment fees, National Insurance contributions, or single-point-of-failure risks.
To discuss an independent benchmark audit or to review your current CASS RP readiness, contact us today to book a free 30-minute discovery call. You can reach our team by emailing info@complianceconsultant.org with the subject “Retainer Discovery Call” or by calling our UK freephone number at 0800 689 0190.