2026-07-20

Added · Updated

GFSC Guidance Note on Payments and Electronic Money Safeguarding

Safeguarding institutions must maintain a safeguarding resolution pack to enable the timely return of client funds in insolvency and assist the GFSC. Relevant funds must be segregated from other client funds, with specific rules governing the segregation method using GFSC-approved secure liquid assets or the insurance/guarantee method. Institutions are required to promptly identify and allocate receipts, treat unidentified funds as unallocated relevant funds, and ensure third-party acknowledgement letters accurately reflect account details and waive third-party recourse rights.

Gibraltar Financial Services Commission logo

Gibraltar

Gibraltar Financial Services Commission

Click to view thumbnail

www.gfsc.gi GFSC Guidance Note Payments and Electronic Money: Safeguarding 1 Month 2017 Version: [1] Publication Date: 16 July 2026

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 2 Contents

  1. Introduction .......................................................................................................... 3
  2. Safeguarding Resolution Pack .................................................................................. 3
  3. Safeguarding relevant funds.................................................................................... 5
  4. Safeguarding Audit Requirements.......................................................................... 16
  5. Safeguarding Return ............................................................................................. 22
  6. Safeguarding Account Acknowledgement Letters..................................................... 22

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 3

  1. Introduction 1.1. This Guidance Note is relevant to payment institutions and electronic money institutions that safeguard funds in accordance with regulation 84 of the Payment Services Regulations1 and regulation 30 of the Electronic Money Regulations2 , unless otherwise stated. For the purposes of this Guidance Note, such payment institutions and electronic money institutions are collectively referred to as ‘safeguarding institutions’. 1.2. It sets out the GFSC’s expectations in relation to: • safeguarding relevant funds; • the safeguarding resolution pack; • safeguarding audit requirements; and • safeguarding returns. 1.3. This Guidance Note is intended to complement existing legislation, policies and guidance and is not intended to conflict with, amend or supersede them unless otherwise stated. 1.4. It should be read in conjunction with: • regulations 84 to 86 of, and Schedules 4 and 5 to, the Payment Services Regulations; and • regulations 30 to 40 of, and Schedules 4 and 5 to, the Electronic Money Regulations.
  2. Safeguarding Resolution Pack 2.1. This section applies to a safeguarding institution when it receives or holds relevant funds in accordance with regulation 84 of the Payment Services Regulations and regulation 30 of the Electronic Money Regulations. It applies with respect to the issuance of electronic money and the provision of payment services. 2.2. Regulation 84(1A)(b) of the Payment Services Regulations and regulation 30 of the Electronic Money Regulations require a safeguarding institution to maintain a safeguarding resolution pack at all times when it receives or holds relevant funds. 2.3. The purpose of the safeguarding resolution pack is to ensure that a safeguarding institution maintains and is able to retrieve information that would:
  1. in the event of its insolvency, assist an insolvency practitioner in achieving a timely return of relevant funds held by the safeguarding institution to its clients; and 1 Financial Services (Payment Services) Regulations 2020 2 Financial Services (Electronic Money) Regulations 2020

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 4 2) in either case, assist the GFSC. 2.4. Part 2 of Schedule 4 to the Payment Services Regulations and Part 2 of Schedule 4 to the Electronic Money Regulations specify the types of documents and records that must be maintained in the safeguarding resolution pack and the retrieval period for the pack. The contents of the documents that constitute the safeguarding resolution pack will change from time to time (for example, because reconciliations must be included in the pack). 2.5. The safeguarding institution should maintain the component documents of the safeguarding resolution pack in order for them to be retrieved in accordance with paragraph 23(1) of Schedule 4 to the Payment Services Regulations and paragraph 23(1) of Schedule 4 to the Electronic Money Regulations. The safeguarding institution should not use the retrieval period to start producing these documents. A safeguarding institution is only required to retrieve the safeguarding resolution pack in the circumstances prescribed in those paragraphs. 2.6. Where a safeguarding institution anticipates that it might be the subject of an insolvency order, it is likely to have sought advice from an external adviser. The safeguarding institution should make the safeguarding resolution pack available promptly, on request, to such an adviser. 2.7. For the purpose of paragraph 24 of Schedule 4 to the Payment Services Regulations and paragraph 24 of Schedule 4 to the Electronic Money Regulations, an example of a change that would render a document inaccurate in a material respect is a change of institution identified pursuant to paragraph 22(1)(b) of Schedule 4 to the Payment Services Regulations and paragraph 22(1)(b) of Schedule 4 to the Electronic Money Regulations. 2.8. A safeguarding institution may hold in electronic form any document in its resolution pack provided that it continues to be able to comply with paragraphs 23(1) and 24 of Schedule 4 to the Payment Services Regulations and paragraphs 23(1) and 24 of Schedule 4 to the Electronic Money Regulations in respect of that document. Core content requirements 2.9. For the purpose of paragraph 22(1)(j)(i) of Schedule 4 to the Payment Services Regulations and paragraph 22(1)(j)(i) of Schedule 4 to the Electronic Money Regulations, examples of individuals within the safeguarding institution who are critical or important to the performance of operational functions include:

  1. those necessary to carry out internal safeguarding reconciliations, external safeguarding reconciliations and record checks; and
  2. those in charge of client documentation for business involving relevant funds and relevant assets.

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 5 Existing records forming part of the safeguarding resolution pack 2.10. Paragraph 22(3) of Schedule 4 to the Payment Services Regulations and paragraph 22(3) of Schedule 4 to the Electronic Money Regulations do not change the record-keeping requirements referred to therein. 3. Safeguarding relevant funds Purpose and application General purpose 3.1. The following guidance supplements the following provisions which require safeguarding institutions to safeguard relevant funds: • regulation 30 of, and Schedule 4 to, the Electronic Money Regulations; and • regulation 84 of, and Schedule 4 to, the Payment Services Regulations. This guidance applies with respect to the provision of payment services or issuance of electronic money that is within the scope of the Payment Services Regulations or Electronic Money Regulations. 3.2. Funds received by safeguarding institutions that relate to transactions that are not in scope of the Payment Services Regulations or Electronic Money Regulations do not need to be safeguarded and, where the safeguarding institution uses the segregation method, such funds must be kept separate from relevant funds. 3.3. One of the effects of paragraph 3.2 above is that regulation 84 and Schedule 4 the Payment Services Regulations do not apply where payment services are being provided to both the payer and the payee from outside of Gibraltar and the UK (e.g., a transfer between an account operated by a PSP from a branch in Japan to an account operated by another PSP from a branch in Hong Kong). Funds received for these transactions should not be mixed with relevant funds, even if funds are routed through a correspondent PSP in Gibraltar or the UK. 3.4. Electronic money institutions may execute payment transactions that are not related to the issuance of electronic money. Relevant funds relating to such transactions must be safeguarded separately to relevant funds relating to the issuance of electronic money. In such instances, the safeguarding requirements should be applied accordingly. This will be relevant where the safeguarding institution provides payment services that are independent from its electronic money products. The requirement to separately safeguard relevant funds will not apply where the safeguarding institution simply transfers funds from an electronic money account, such as where a customer uses electronic money to pay a bill.

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 6 3.5. A firm must not keep funds in respect of which the safeguarding requirements apply in a client bank account held for any other purpose. Organisational requirements Protection of relevant funds 3.6. An effect of paragraph 3(1) of Schedule 4 to the Payment Services Regulations and paragraph 3(1) of Schedule 4 to the Electronic Money Regulations is that a safeguarding institution should consider how to clearly identify relevant funds that are not held in a relevant funds bank account. That includes those segregated in accordance with regulation 31(1) of the Electronic Money Regulations or regulation 84(2)(a) of the Payment Services Regulations but not yet placed in a relevant funds bank account. The word ‘safeguarding’ should be included in account names wherever possible. Allocation of relevant funds receipts 3.7. Paragraph 3(1) of Schedule 4 to the Payment Services Regulations and paragraph 3(1) of Schedule 4 to the Electronic Money Regulations require a safeguarding institution to promptly identify the client to whom a relevant funds receipt relates. Once identified, the receipt of relevant funds must be recorded and allocated to the client in the safeguarding institution’s accounts. Where the crediting of these accounts amounts to the crediting of a payment account, it must be carried out within the time periods required by the Payment Services Regulations and the Electronic Money Regulations. 3.8. Where the safeguarding institution receives relevant funds on behalf of a payee who does not have a payment account with the safeguarding institution, the relevant funds may need to be allocated immediately so that they can be made available to the payee immediately after they have been credited to the safeguarding institution’s account in accordance with regulation 61 of the Payment Services Regulations. 3.9. Where the receipt of relevant funds relates to the issuance of electronic money, the relevant funds may need to be allocated without delay so that the safeguarding institution can comply with its obligation to issue electronic money without delay under regulation 18 of the Electronic Money Regulations. Unidentified receipts of funds 3.10. Paragraph 4 of Schedule 4 to the Payment Services Regulations and paragraph 4 of Schedule 4 to the Electronic Money Regulations recognise that it might not always be possible to identify whether funds are relevant funds and, if they are, the client to which they relate. Where a safeguarding institution is able to identify that the funds have been received from a client to execute a payment transaction or in exchange for electronic money but is unable to identify

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 7 the client entitled to the funds it has received (for example, because they do not have the correct unique identifier), the funds must still be treated as relevant funds and recorded as ‘unallocated relevant funds’. 3.11. If a safeguarding institution is unable to identify funds that it has received as either relevant funds or other funds, it should consider whether it would be appropriate to return the funds to the person who sent them (or, if that is not possible, to the source from where it was received – for example, the bank). 3.12. Where a payment service user provides an incorrect unique identifier, the safeguarding institution will also need to consider the steps it is required to take under regulation 64 of the Payment Services Regulations. The segregation method 3.13. The segregation method is the method of safeguarding relevant funds described in regulation 31 of the Electronic Money Regulations or regulations 84(2) to (4) of the Payment Services Regulations. 3.14. An effect of regulation 30(5) of the Electronic Money Regulations is that where an electronic money institution receives relevant funds for the execution of payment transactions that are not related to the issuance of electronic money, it must keep those funds segregated from relevant funds relating to the issuance of electronic money. Segregation: secure, liquid assets 3.15. Regulation 31(2)(b) of the Electronic Money Regulations provides that safeguarding institutions may invest relevant funds received in exchange for electronic money in secure, liquid, low-risk assets. Assets are liquid if approved as such by the GFSC. 3.16. Regulation 84(2)(b)(ii) of the Payment Services Regulations provides that safeguarding institutions may invest relevant funds received for the execution of payment transactions unrelated to the issuance of electronic money in such secure, liquid assets as the GFSC may approve. 3.17. The GFSC has approved the following assets for the purposes of regulation 31(2)(b) of the Electronic Money Regulations and regulation 84(2)(b)(ii) of the Payment Services Regulations:

  1. items that fall into one of the categories set out in Article 114 of the Financial Services (Capital Requirements) (Technical Standards) Regulations 20263 for which the specific risk capital charge is no higher than 0%; or 3 Financial Services (Capital Requirements) (Technical Standards) Regulations 2026

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 8 2) units in a UCITS which invests solely in the assets listed in (1). 3.18. However, the GFSC may, in exceptional circumstances, determine that an asset falling within paragraph 3.17 is not secure and liquid. Appointment of a third party to manage relevant assets 3.19. A safeguarding institution is not required to appoint a third party to manage relevant assets but, if it does, it must comply with paragraph 6(3) of Schedule 4 to the Payment Services Regulations and paragraph 6(3) of Schedule 4 to the Electronic Money Regulations. The insurance or guarantee method 3.20. A safeguarding institution can protect relevant funds using an insurance policy or a guarantee provided that the conditions set out in paragraph 7(2) of Schedule 4 to the Payment Services Regulations and paragraph 7(2) of Schedule 4 to the Electronic Money Regulations are met. 3.21. An effect of paragraph 7(2) of Schedule 4 to the Payment Services Regulations and paragraph 7(2) of Schedule 4 to the Electronic Money Regulations is that the insurance policy or guarantee must pay out the full amount of any claim regardless of why the insolvency event occurs. This includes, but is not limited to, where the insolvency event is caused by any fraud or negligence on the part of the safeguarding institution or any of its directors, employees or agents or something outside the control of the safeguarding institution. It also means that there must be no level below which the insurance policy or guarantee does not pay out. Paragraph 7(2)(d) of Schedule 4 to the Payment Services Regulations and paragraph 7(2)(d) of Schedule 4 to the Electronic Moneys Regulations require the proceeds of an insurance policy or guarantee to be payable into a relevant funds bank account. In practice, this means that the safeguarding institution will need to maintain such an account at least for the full term of the insurance policy or guarantee. 3.22. A safeguarding institution may use more than one insurance policy or guarantee, or a combination of insurance policies and guarantees. However, the effect of the condition in paragraph 7(2)(b) of Schedule 4 to the Payment Services Regulations and in paragraph 7(2)(b) of Schedule 4 to the Electronic Money Regulations is that the terms of each insurance policy or guarantee must not enable the insurer or guarantor to refuse to pay out, in whole or in part, on the basis that relevant funds are covered by another insurer or guarantor. Notification 3.23. The assessment referred to in paragraph 7(4) of Schedule 4 to the Payment Services Regulations and paragraph 7(4) of Schedule 4 to the Electronic Money Regulations should consider operational risks such as:

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 9

  1. the insurance policy or guarantee not being extended or renewed;
  2. the safeguarding institution not: i. being able to find an alternative insurer or guarantor; or ii. having sufficient liquid assets to safeguard using the segregation method on the expiry of the insurance policy or guarantee; and
  3. adverse impacts on the institution’s short-term liquidity caused by restrictions on accessing funds that would otherwise be available if they were protected using the segregation method, contrary to regulation 9(4) of the Electronic Money Regulations and regulation 10(4) of the Payment Services Regulations. Expiration of the insurance policy or guarantee 3.24. If a safeguarding institution decides to continue to use the insurance or guarantee method, but there are changes to the insurer or guarantor, or to the amount of the cover, it will also need to comply with paragraph 7(3) of Schedule 4 to the Payment Services Regulations and paragraph 7(3) of Schedule 4 to the Electronic Money Regulations. 3.25. A safeguarding institution should decide whether to continue using the insurance or guarantee method in good time before the expiry of the policy or guarantee. In practice, this means that a decision should be made while there is sufficient time to enable the safeguarding institution to make alternative arrangements to meet its obligations to customers. The greater the amount of cover provided by the insurance or guarantee method, the sooner a decision should be made. The safeguarding institution should keep the GFSC informed at all stages in accordance with Core Principle 12. 3.26. If a safeguarding institution is unable to use the segregation method to protect funds that were previously covered by an insurance policy or guarantee, it should consider its financial position and take any appropriate steps (such as placing itself into administration) in good time before the lapse of the policy or guarantee so that a claim can be made. 3.27. Where a safeguarding institution is required to safeguard, it is a condition of its authorisation or registration that it takes adequate measures for the purpose of doing so. If it does not have adequate measures in place to protect relevant funds in good time before the expiry of an insurance policy or guarantee, the GFSC may consider whether it is appropriate to use its supervision powers to protect the interests of clients, including, but not limited to, its powers to apply to court to appoint an insolvency practitioner. Selection and appointment of third parties 3.28. Safeguarding institutions should ensure that their consideration of a third party focuses on the specific legal entity in question and not simply that person’s group as a whole.

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 10 3.29. In complying with paragraph 8(3) of Schedule 4 to the Payment Services Regulations and paragraph 8(3) of Schedule 4 to the Electronic Money Regulations, a safeguarding institution should consider, as appropriate, together with any other relevant matters:

  1. the capital of the third party;
  2. the amount of relevant funds or relevant assets placed, insured or guaranteed as a proportion of the third party’s capital and (where relevant) deposits;
  3. the extent to which relevant funds or relevant assets that the safeguarding institution deposits or holds with any third party would be protected under a deposit protection scheme or other compensation scheme;
  4. the creditworthiness of the third party;
  5. to the extent that the information is available, the level of risk in the investment and loan activities undertaken by the third party and affiliated companies; and
  6. the arrangements referred to in paragraph 3(1) of Schedule 4 to the Payment Services Regulations and paragraph 3(1) of Schedule 4 to the Electronic Money Regulations. 3.30. In complying with the requirement in paragraph 8(4) of Schedule 4 to the Payment Services Regulations and paragraph 8(4) of Schedule 4 to the Electronic Money Regulations to periodically review whether diversification (or further diversification) is appropriate, a safeguarding institution should have regard to:
  7. whether it would be appropriate to deposit relevant funds in relevant funds bank accounts opened at a number of different approved banks;
  8. whether it would be appropriate to limit the amount of relevant funds or relevant assets the safeguarding institution holds with third parties that are in the same group as each other;
  9. whether risks arising from the safeguarding institution’s business model create any need for diversification (or further diversification);
  10. the market conditions at the time of the review;
  11. the outcome of any due diligence carried out in accordance with paragraph 8(1) and (2) of Schedule 4 to the Payment Services Regulations and paragraph 8(1) and (2) of Schedule 4 to the Electronic Money Regulations; and
  12. the arrangements referred to in paragraph 3(1) of Schedule 4 to the Payment Services Regulations and paragraph 3(1) of Schedule 4 to the Electronic Money Regulations. Acknowledgement letters 3.31. The main purposes of an acknowledgement letter are:
  13. to put third parties on notice of a safeguarding institution’s client’s interests in relevant funds or relevant assets that have been deposited or invested with them;
  14. to ensure that a relevant funds bank account or relevant assets account has been opened in accordance and in compliance with the relevant funds regime, and is

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 11 distinguished from any account containing funds or assets that are not relevant funds or relevant assets; and 3) to ensure that a third party understands and agrees that it will not have any recourse or right against funds or assets standing to the credit of a relevant funds bank account or relevant assets account in respect of any liability of the safeguarding institution to the third party (or a person connected to the third party), except to the extent provided for by the Electronic Money Regulations or the Payment Services Regulations, as the case may be. Review and replacement of safeguarding account acknowledgement letters 3.32. Under paragraph 9(11) of Schedule 4 to the Payment Services Regulations and paragraph 9(11) of Schedule 4 to the Electronic Money Regulations, a safeguarding institution should draw up a replacement acknowledgement letter whenever:

  1. there has been a change in any of the parties’ names or addresses or a change in any of the details of the relevant account(s) as set out in the letter; or
  2. it becomes aware of an error or misspelling in the letter. Records, accounts and reconciliations Policies and procedures 3.33. In complying with the requirement in paragraph 10(1) of Schedule 4 to the Payment Services Regulations and paragraph 10(1) and (7) of Schedule 4 to the Electronic Money Regulations, a safeguarding institution should establish and maintain policies and procedures that include (but are not limited to):
  3. the frequency and method of the reconciliations the safeguarding institution is required to carry out under this section;
  4. the resolution of reconciliation discrepancies; and
  5. the frequency at which the safeguarding institution is required to review its arrangements. Records and accounts 3.34. An effect of paragraph 10(2) of Schedule 4 to the Payment Services Regulations and paragraph 10(2) of Schedule 4 to the Electronic Money Regulations is that a safeguarding institution that provides services that are not payment services or the issuance of electronic money must ensure it has adequate policies and procedures in place to identify and determine when it is holding relevant funds and when it is holding or in receipt of funds relating to its other activities.

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 12 3.35. The effect of paragraph 10(2) of Schedule 4 to the Payment Services Regulations and paragraph 10(2) of Schedule 4 to the Electronic Money Regulations includes that:

  1. the safeguarding institution will need to carry out a separate reconciliation of its unrelated payment services asset pool and of its electronic money asset pool; and
  2. an electronic money institution or credit union must ensure it has adequate policies and procedures to distinguish between relevant funds received or held for the provision of payment services unrelated to the issuance of electronic money and relevant funds it receives in exchange for electronic money. 3.36. The requirements in paragraph 10(2) and (3) of Schedule 4 to the Payment Services Regulations and paragraph 10(2) and (3) of Schedule 4 to the Electronic Money Regulations are for a safeguarding institution to keep internal records and accounts of relevant funds. Therefore, any records falling under those requirements should be maintained by the safeguarding institution and are separate to any records the safeguarding institution may obtain from any third parties, such as those with which it may have deposited relevant funds. 3.37. A safeguarding institution may use data that is received from third parties for the purpose of creating and maintaining such records where no other method could reasonably be employed (for example, where funds are applied automatically to client balances via application programming interfaces). 3.38. A safeguarding institution’s records must cover all relevant funds held by an institution, including those not held in relevant funds bank accounts. Internal safeguarding reconciliations 3.39. Where an electronic money institution provides payment services that are unrelated to the issuance of electronic money, paragraphs 10 to 20 of Schedule 4 to the Payment Services Regulations and paragraphs 10 to 20 of Schedule 4 to the Electronic Money Regulations apply to the safeguarding institution’s unrelated payment services asset pool and electronic money asset pool separately, in line with paragraph 10(2) of Schedule 4 to the Payment Services Regulations and paragraph 10(2) of Schedule 4 to the Electronic Money Regulations. 3.40. The purpose of paragraph 11(1)(a)(ii) of Schedule 4 to the Payment Services Regulations and paragraph 11(1)(a)(ii) of Schedule 4 to the Electronic Money Regulations is to check that the right amount of relevant funds has been paid into a relevant funds bank account or invested in relevant assets. If all relevant funds are received into a relevant funds bank account or were invested in relevant assets before the last reconciliation, this step is not required. 3.41. In accordance with paragraphs 3.35 to 3.37 of this Guidance Note, paragraph 11(4) of Schedule 4 to the Payment Services Regulations and paragraph 11(4) of Schedule 4 to the Electronic Money Regulations do not prevent a safeguarding institution from using data obtained from

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 13 third parties to create and maintain its internal records where no other method could reasonably be employed. 3.42. An internal safeguarding reconciliation should:

  1. be one of the steps a safeguarding institution takes to arrange adequate protection for relevant funds when the safeguarding institution is responsible for them;
  2. be one of the steps a safeguarding institution takes to satisfy its obligations under regulation 35 of the Electronic Money Regulations or regulation 86 of the Payment Services Regulations (as the case may be) and paragraphs 3 and 4 of Schedule 4 to the Payment Services Regulations and paragraphs 3 and 4 of Schedule 4 to the Electronic Money Regulations to ensure the accuracy of the safeguarding institution’s records; and
  3. check whether the amount of relevant funds recorded in the safeguarding institution’s records as being safeguarded meets the safeguarding institution’s obligations to its clients under the relevant funds regime. Frequency of internal safeguarding reconciliations 3.43. Paragraph 11(5) of Schedule 4 to the Payment Services Regulations and paragraph 11(5) of Schedule 4 to the Electronic Money Regulations require a minimum of one internal safeguarding reconciliation to be performed each reconciliation day. It does not prevent a safeguarding institution from deciding it is appropriate to perform internal safeguarding reconciliations on business days that are not reconciliation days due to the nature, volume and complexity of its business. 3.44. The reference point for the internal safeguarding reconciliation under paragraph 11(8)(a) of Schedule 4 to the Payment Services Regulations and paragraph 11(8)(a) of Schedule 4 to the Electronic Money Regulationsshould be the precise point in time at which the insolvency event occurred. 3.45. When a safeguarding institution decides whether it is necessary at any particular point in time to perform an internal safeguarding reconciliation under paragraph 11(8)(b) of Schedule 4 to the Payment Services Regulations and paragraph 11(8)(b) of Schedule 4 to the Electronic Money Regulations, it should have particular regard to the need to maintain its books and accounts in order to ensure that its asset pools are correctly composed and maintained. 3.46. Depending on the circumstances of the safeguarding institution and the scale, frequency and nature of activity after an insolvency event that affects relevant funds, a safeguarding institution may conclude that it is necessary to perform internal safeguarding reconciliations each business day for a period of time after the insolvency event. Standard method of internal safeguarding reconciliation: safeguarding resource

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 14 3.47. Item B (set out in paragraph 12(1)(b) of Schedule 4 to the Payment Services Regulations and paragraph 12(1)(b) of Schedule 4 to the Electronic Money Regulations) should include all relevant funds that have been segregated but are not held in a relevant funds bank account – for example, funds held as cash, funds held by agents and funds held in a segregated account that is not a relevant funds bank account. 3.48. A safeguarding institution may calculate the individual safeguarding balance set out in paragraph 14 of Schedule 4 to the Payment Services Regulations and paragraph 14 of Schedule 4 to the Electronic Money Regulations either:

  1. one individual safeguarding balance for each client, based on the totality of all the payment services or electronic money products provided to that client; or
  2. multiple individual safeguarding balances for each client, based on the individual payment services or electronic money products provided to that client. External safeguarding reconciliations 3.49. The purpose of an external safeguarding reconciliation is to ensure the accuracy of a safeguarding institution’s internal records and accounts against those of any third parties that hold relevant funds or hold or manage relevant assets. 3.50. The records used for external safeguarding reconciliations should, so far as possible, relate to the same point in time as the reconciliation point(s) used for internal safeguarding reconciliations (see paragraph 11(6) of Schedule 4 to the Payment Services Regulations and paragraph 11(6) of Schedule 4 to the Electronic Money Regulations). 3.51. If the records and accounts used for external safeguarding reconciliations cannot be aligned with the reconciliation point(s) referred to in paragraph 3.50 above, the policies and procedures referred to in the safeguarding obligations should set out how the safeguarding institution will ensure its external safeguarding reconciliations achieve the purpose set out in paragraph 3.49 above. Frequency of external safeguarding reconciliations after an insolvency event 3.52. The reference point for the external safeguarding reconciliation under paragraph 17(4) of Schedule 4 to the Payment Services Regulations and paragraph 17(4) of Schedule 4 to the Electronic Money Regulationsshould be the precise point in time at which the insolvency event occurred. External safeguarding reconciliations: method 3.53. The reconciliation described in paragraph 18(a)(ii) of Schedule 4 to the Payment Services Regulations and paragraph 18(a)(ii) of Schedule 4 to the Electronic Money Regulations require

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 15 a safeguarding institution to reconcile the quantity of relevant assets, rather than the value of those assets. The relevant assets should be compared by asset type. For example, the safeguarding institution should compare its records of the number of units in a particular UCITS against the number of units as set out in the statements provided by the custodian of the units or issuer (as the case may be). 3.54. Insurance policies and guarantees are not subject to the external safeguarding reconciliation. However, safeguarding institutions using the insurance or guarantee method are reminded of their obligations in paragraph 7 of Schedule 4 to the Payment Services Regulations and paragraph 7 of Schedule 4 to the Electronic Money Regulations and the need to ensure that any insurance policy or guarantee provides appropriate cover at all times. Reconciliation discrepancies 3.55. Paragraph 19(1) to (3) of Schedule 4 to the Payment Services Regulations and paragraph 19(1) to (3) of Schedule 4 to the Electronic Money Regulations set out some of the steps that a safeguarding institution must carry out to ensure that it is segregating the right amount of relevant funds, and that it is holding the right amount of relevant funds in relevant funds bank accounts or as relevant assets. Where discrepancies are identified, safeguarding institutions are required to make payments, investments or withdrawals to remedy those discrepancies. 3.56. Paragraph 19(3) of Schedule 4 to the Payment Services Regulations and paragraph 19(3) of Schedule 4 to the Electronic Money Regulations make provision for a safeguarding institution that has a deficiency in its D+1 segregation resource but is unable to access relevant funds to remedy it. Such lack of access could be, for example, because of a delay in the release of relevant funds by a third party. In such circumstances, the safeguarding institution must top￾up the shortfall from its own funds, even where this leads to a surplus in the safeguarding resource. The discrepancy will be resolved by subsequent reconciliations. 3.57. Where the discrepancy identified under paragraph 19(1) or 19(2) to (3) of Schedule 4 to the Payment Services Regulations and paragraph 19(1) or 19(2) to (3) of Schedule 4 to the Electronic Money Regulations has arisen as a result of a breach of the safeguarding requirements, the safeguarding institution should ensure it takes sufficient steps to avoid a reoccurrence of that breach. 3.58. Paragraph 19(4) and (7) of Schedule 4 to the Payment Services Regulations and paragraph 19(4) and (7) of Schedule 4 to the Electronic Money Regulations recognise that, following an insolvency event, a safeguarding institution is required to investigate discrepancies, but the extent to which it is able to resolve discrepancies may be limited by insolvency law, for example. Notification requirements

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 16 3.59. Safeguarding institutions are reminded that the auditor of the safeguarding institution must confirm in the report submitted to the GFSC whether the safeguarding institution has maintained systems adequate to enable it to comply with the relevant funds regime. 4. Safeguarding Audit Requirements Application 4.1. This section is relevant to electronic money institutions and payment institutions (other than those providing payment initiation services or account information services) that have been required to safeguard more than £100,000 of relevant funds for at least 53 weeks. 4 It is also relevant to their external auditors. 5 For the purposes of this section, these institutions are collectively referred to as ‘relevant institutions’. 4.2. This section applies to relevant institutions whether they safeguard relevant funds through the segregation method, the insurance or guarantee method, or both. It also sets out guidance on the role that auditors play in the GFSC’s monitoring of relevant institutions’ compliance with their safeguarding obligations. 4.3. This guidance should be read in conjunction with the Payment Services Regulations, the Electronic Money Regulations and the Companies Act 2014, which provide the statutory framework for relevant institutions’ and auditors’ obligations. Voluntary application 4.4. The GFSC expects safeguarding institutions that are not subject to this guidance to have in place adequate arrangements to safeguard relevant funds under paragraph 3(1) of Schedule 4 to the Payment Services Regulations and paragraph 3(1) of Schedule 4 to the Electronic Money Regulations and to minimise the risk of their loss or diminution under regulation 84(12) of the Payment Services Regulations and regulation 34(3) of the Electronic Money Regulations. Voluntarily arranging an audit in accordance with this guidance may help ensure they meet these expectations. The senior management of such institutions are also expected to determine, on a continuing basis, whether the institution must comply with the safeguarding audit requirements in Schedule 5 to the Payment Services Regulations and Schedule 5 to the Electronic Money Regulations and appoint an auditor. Rights and duties of auditors 4.5. The rights and duties of auditors are set out in Schedule 5 to the Payment Services Regulations and Schedule 5 to the Electronic Money Regulations. Paragraphs 4.27 and 4.28 below refer to statutory auditors’ duty to report certain matters to the GFSC under regulations 85 and 85B of 4 Paragraph 1 of Schedule 5 to the Payment Services Regulations and paragraph 1 of Schedule 5 to the Electronic Money Regulations 5 Paragraph 3 of Schedule 5 to the Payment Services Regulations and paragraph 3 of Schedule 5 to the Electronic Money Regulations

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 17 the Payment Services Regulations and regulations 39 and 40 of the Electronic Money Regulations. An auditor should bear these rights and duties in mind when carrying out safeguarding report work, including whether anything should be notified to the GFSC immediately. Appointment of auditors 4.6. Paragraph 3 of Schedule 5 to the Payment Services Regulations and paragraph 3 of Schedule 5 to the Electronic Money Regulations require a relevant institution to appoint an auditor and provide the GFSC with information about its auditor. The GFSC requires such information to ensure that the relevant institution has an auditor. Appointment by institutions 4.7. Relevant institutions must appoint an auditor under paragraph 3(1) of Schedule 5 to the Payment Services Regulations and paragraph 3(1) of Schedule 5 to the Electronic Money Regulations, even if they have already appointed an auditor to meet another legal obligation, for example under the Companies Act 2014. The appointed auditor does not have to be, but may be, the same auditor as is appointed to meet another legal obligation. Appointment by the GFSC 4.8. The GFSC may appoint an auditor if the relevant institution fails to do so within the 28-day period under paragraph 3 of Schedule 5 to the Payment Services Regulations and paragraph 3 of Schedule 5 to the Electronic Money Regulations. When considering whether to appoint an auditor, the GFSC will consider the likely delay until the institution can make an appointment and the urgency of any pending duties of the appointed auditor. Auditors’ qualifications 4.9. The GFSC expects the auditor of a relevant institution to have the necessary skill and experience to audit the business of the institution. Qualifications 4.10. A relevant institution should ensure that any auditor it proposes to appoint has the necessary skills, resources and experience commensurate with the nature, scale and complexity of the relevant institution’s business and to the regulatory requirements and standards that apply to it. A relevant institution should have regard to whether the proposed auditor has expertise in the relevant requirements and standards and possesses or has access to appropriate specialist skill. The relevant institution should seek confirmation of this from the auditor concerned as appropriate.

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 18 Disqualified auditors 4.11. If it appears to the GFSC that an auditor of a relevant institution has failed to comply with a duty imposed on them, it may take disciplinary measures, including disqualification of the auditor under section 174 of the Financial Services Act 2019 (“FSA”). Requests for information by the GFSC 4.12. The GFSC may request information about the auditor’s relevant experience and skills to assess their ability to audit a relevant institution. This may include written requests to auditors who have not previously audited a relevant institution. The relevant institution should instruct the auditor to provide a full reply (and should not appoint an auditor who fails to respond). The GFSC may also seek further information from an auditor of a relevant institution on an ongoing basis. Auditors’ independence 4.13. To carry out their duties properly, an auditor needs to be independent of the institution they are auditing so they are not subject to conflicts of interest. 4.14. The GFSC will regard an auditor as independent if their appointment or retention does not breach the Code of Ethics for Professional Accountants published by the International Ethics Standards Board for Accountants, as amended from time to time, on the appointment of an auditor in circumstances which could give rise to conflicts of interest. Relevant institutions’ cooperation with their auditors Auditor’s access to accounting records 4.15. In complying with paragraph 6 of Schedule 5 to the Payment Services Regulations and paragraph 6 of Schedule 5 to the Electronic Money Regulations, a relevant institution should give a right of access at all times to the institution’s accounting and other records, in whatever form they are held, and documents relating to its business. A relevant institution should allow its auditor to copy documents or other material on the premises of the institution and to remove copies or hold them elsewhere, or give its auditor such copies on request. 4.16. Section 165 of the FSA provides that an auditor of a relevant institution appointed under Schedule 5 to the Payment Services Regulations and under Schedule 5 to the Electronic Money Regulations:

  1. has a right of access at all times to the relevant institution’s books, accounts and vouchers; and

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 19 2) is entitled to require from the relevant institution’s officers such information and explanations as they reasonably consider necessary for the performance of their duties as auditor. 4.17. Section 257 of the Companies Act 2006 give similar rights to auditors of companies. 4.18. Section 514 of the FSA, under which no person is required to produce a document or disclose information if the person would be entitled to refuse to produce or disclose it on grounds of legal privilege in proceedings in the Supreme Court, is relevant to paragraph 6 of Schedule 5 to the Payment Services Regulations, paragraph 6 of Schedule 5 to the Electronic Money Regulations and paragraph 4.16 of this Guidance Note. Access and cooperation: agents, distributors, operational outsourcing, employees 4.19. In complying with paragraph 6 of Schedule 5 to the Payment Services Regulations and paragraph 6 of Schedule 5 to the Electronic Money Regulations, a relevant institution should take reasonable steps to ensure that:

  1. each of its agents and distributors gives the institution’s auditor the same rights of access to the books, accounts and vouchers of the agent or distributor and entitlement to information and explanations from the agent’s or distributor’s officers as are given in respect of the relevant institution by section 165 of the FSA;
  2. each of its suppliers under a material outsourcing arrangement gives the institution’s auditor the same rights of access to the books, accounts and vouchers of the institution held by the supplier, and entitlement to information and explanations from the supplier’s officers as are given in respect of the relevant institution by section 165 of the FSA; and
  3. all its employees cooperate with its auditor in the discharge of its auditor’s duties. Provision of false or misleading information to auditors 4.20. Relevant institutions and their officers, managers and controllers are reminded that, under section 169 of the FSA, knowingly or recklessly giving false information to an auditor appointed under Schedule 5 to the Payment Services Regulations and under Schedule 5 to the Electronic Money Regulations constitutes an offence in certain circumstances, which could render them liable to prosecution. This applies even when an auditor is also appointed under an obligation in another enactment. Notification of matters raised by auditor Notification

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 20 4.21. A relevant institution should consider whether it should notify the GFSC under Core Principle 12 if it receives a written communication from its auditor commenting on internal controls. Rights and duties of auditors 4.22. The following paragraphs provide guidance on the rights and duties that enable or require auditors of a relevant institution to obtain information from the institution and pass information to the GFSC in specified circumstances. Cooperation with the GFSC 4.23. The GFSC may ask the auditor to attend meetings and to supply it with information about the institution. In complying with paragraph 7 of Schedule 5 to the Payment Services Regulations and paragraph 7 of Schedule 5 to the Electronic Money Regulations, the auditor should attend such meetings as the GFSC requests and supply it with any information the GFSC may reasonably request about the relevant institution to enable the GFSC to discharge its functions under the FSA, the Payment Services Regulations and the Electronic Money Regulations. Communication between the GFSC, the relevant institution and the auditor 4.24. Within the legal constraints that apply, the GFSC may pass on to an auditor any information which it considers relevant to the auditor’s function. An auditor is bound by the duty of confidentiality and professional secrecy set out in section 498 of the FSA in respect of confidential information received from the GFSC. An auditor may not pass on such confidential information without lawful authority. For example, if an exception applies as set out in section 498(2) of the FSA or with the consent of the person from whom that information was received (see section 46(4) of the FSA) and, if different, to whom that information relates. Auditors’ statutory duty to report 4.25. Statutory auditors of safeguarding institutions are subject to regulation 85 of the Payment Services Regulations and regulation 18 of the Electronic Money Regulations. Those regulations require statutory auditors to communicate matters of material significance to the GFSC. A failure to safeguard relevant funds will usually be of material significance and should be communicated to the GFSC. This is especially the case where an institution claims not to be required to safeguard relevant funds at all. 4.26. Sections 166(6) and 167(7) of the FSA provide that an auditor does not contravene any duty by giving information or expressing an opinion to the GFSC, if they are acting in good faith and reasonably believe that the information or opinion is relevant to any functions of the GFSC. These provisions continue to have effect after the end of the auditor’s term of appointment. Duties of auditors: notification and safeguarding report

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 21 Auditor’s safeguarding report 4.27. Paragraph 8(1) of Schedule 5 to the Payment Services Regulations and paragraph 8(1) of Schedule 5 to the Electronic Money Regulations provide that an auditor must ensure that a safeguarding report is prepared in accordance with the terms of a reasonable assurance engagement. The GFSC also expects an auditor to have regard, where relevant, to any material published by the GFSC that deals specifically with the safeguarding report which the auditor is required to submit to the GFSC. In the GFSC’s view, a safeguarding report that is prepared in accordance with that material is likely to comply with paragraph 8(1) and (3) of Schedule 5 to the Payment Services Regulations and paragraph 8(1) and (3) of Schedule 5 to the Electronic Money Regulations where that report is prepared for a relevant institution within the scope of the material in question. Auditor’s safeguarding report: timing of submission 4.28. An auditor should bear the rights and duties set out in Schedule 5 to the Payment Services Regulations and in Schedule 5 to the Electronic Money Regulations in mind when carrying out safeguarding report work, including whether anything should be notified to the GFSC immediately. Auditor’s safeguarding report: requirements not met or inability to form opinion 4.29. The GFSC expects that the list of breaches will include every breach of a regulation in the relevant funds regime insofar as that regulation is within the scope of the safeguarding report and is identified in the course of the auditor’s review of the period covered by the report, whether identified by the auditor or disclosed to it by the relevant institution or by any third party. 4.30. For the purpose of determining whether to qualify its opinion or express an adverse opinion, the GFSC expects an auditor to exercise its professional judgment as to the significance of a breach of a regulation, as well as to its context, duration and incidence of repetition. The GFSC expects an auditor to consider the aggregate effect of any breaches when judging whether a relevant institution failed to comply with the requirements in paragraph 8(3) of Schedule 5 to the Payment Services Regulations and paragraph 8(3) of Schedule 5 to the Electronic Money Regulations. Review of auditor’s safeguarding report 4.31. The GFSC expects a relevant institution to use the safeguarding report as a tool to evaluate the effectiveness of the systems it has in place for the purpose of complying with paragraph 8(3) of Schedule 5 to the Payment Services Regulations and paragraph 8(3) of Schedule 5 to the Electronic Money Regulations. Accordingly, a relevant institution should ensure that the report is integrated into its risk management framework and decision-making.

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 22 4.32. Paragraph 4(1) of Schedule 5 to the Payment Services Regulations and paragraph 4(1) of Schedule 5 to the Electronic Money Regulations provide that a relevant institution must take reasonable steps to ensure that its auditor has the required skill, resources and experience to perform its functions. The GFSC expects a relevant institution to keep under review the adequacy of the skill, resources and experience of its auditor and critically assess the content of the safeguarding report as part of that ongoing review. 5. Safeguarding Return 5.1. Regulation 84A of the Payment Services Regulations and regulation 32A(1) of the Electronic Money Regulations set out the requirement for safeguarding institutions to submit a safeguarding return. 6. Safeguarding Account Acknowledgement Letters 6.1. This part sets out guidance on when and how safeguarding institutions should amend the acknowledgement letter variable text that is in square brackets. 6.2. Safeguarding institutions are required to request duly signed and countersigned acknowledgement letters for their relevant funds bank accounts and relevant assets accounts. 6.3. For each account, a safeguarding institution is required to complete, sign and send to the approved bank or authorised custodian (‘the counterparty’) an acknowledgement letter identifying that account in the form set out in the Annex to the Payment Services Regulations and the Annex to the Electronic Money Regulations. 6.4. When completing an acknowledgement letter using the appropriate template, a safeguarding institution is reminded that it must not amend any of the text which is not in square brackets (acknowledgement letter fixed text). A safeguarding institution should also not amend the non-italicised text that is in square brackets. It may remove or include square bracketed text from the letter, or replace bracketed and italicised text with the required information, in either case as appropriate. Clear identification of relevant accounts 6.5. A safeguarding institution is reminded that for each relevant funds bank account or relevant assets account it needs to request an acknowledgement letter. It is important that it is clear to which account or accounts each acknowledgement letter relates. As a result, the template in the Annex to the Payment Services Regulations and the Annex to the Electronic Money Regulations require that the acknowledgement letter includes the full title and at least one unique identifier, such as a sort code and account number, deposit number or reference code, for each account.

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 23 6.6. The title and unique identifiers included in an acknowledgement letter for an account should be the same as those reflected in both the records of the safeguarding institution and the relevant counterparty, as appropriate, for that account. Where a counterparty’s systems are not able to reflect the full title of an account, that title may be abbreviated to accommodate that system, provided that:

  1. the account may continue to be appropriately identified in line with the safeguarding requirements and obligations set out in the Payment Services Regulations and the Electronic Money Regulations (for example, ‘account’ may be shortened to ‘acct’ etc.); and
  2. when completing an acknowledgement letter, such letter must include both the long and short versions of the account title. 6.7. A safeguarding institution should ensure that all relevant account information is contained in the space provided in the body of the acknowledgement letter. Nothing should be appended to an acknowledgement letter. 6.8. In the space provided in the template letter for setting out the account title and unique identifiers for each relevant account, a safeguarding institution may include the required information in the format of the following table: Full account title Unique identifier Title reflected in [name of counterparty] systems [Safeguarding Institution Relevant Funds Bank Account/Relevant Assets Account] [00-00-00 12345678] [SI Relevant Funds A/C] 6.9. Where an acknowledgement letter is intended to cover a range of accounts, some of which may not exist as at the date the acknowledgement letter is countersigned by the counterparty, a safeguarding institution should set out in the space provided in the body of the acknowledgement letter that it is intended to apply to all present and future accounts which:
  3. are titled in a specified way; and
  4. which possess a common unique identifier or which may be clearly identified by a range of unique identifiers (e.g. all accounts numbered between XXXX1111 and ZZZZ9999). For example, in the space provided in the template letter which allows a safeguarding institution to include the account title and a unique identifier for each relevant account, a safeguarding institution should include a statement to the following effect: ‘Any account open at present or to be opened in the future which contains the term [‘relevant funds’] [insert appropriate abbreviation of the term ‘relevant funds’ as agreed and to be reflected in the approved bank’s systems] in its title and which may be identified

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 24 with [the following [insert common unique identifier]] [an account number from and including [XXXX1111] to and including [ZZZZ9999]] [clearly identify range of unique identifiers].’. Signatures and countersignatures 6.10. A safeguarding institution should ensure that each acknowledgement letter is signed and countersigned by all relevant parties and individuals (including where more than one signatory is required). 6.11. An acknowledgement letter that is signed or countersigned electronically should not, for that reason alone, result in a breach of paragraph 9 of Schedule 4 to the Payment Services Regulations and paragraph 9 of Schedule 4 to the Electronic Money Regulations. However, where electronic signatures are used, a safeguarding institution should consider whether, taking into account the governing law and choice of competent jurisdiction, it needs to ensure that the electronic signature and the certification by any person of such signature would be admissible as evidence in any legal proceedings in the relevant jurisdiction in relation to any question as to the authenticity or integrity of the signature or any associated communication. Completing a safeguarding account acknowledgement letter 6.12. A safeguarding institution should use at least the same level of care and diligence when completing an acknowledgement letter as it would in managing its own commercial agreements. 6.13. A safeguarding institution should ensure that each acknowledgement letter is legible (e.g., any handwritten details should be easy to read), produced on the safeguarding institution’s own letter-headed paper, dated and addressed to the correct legal entity (e.g., where the counterparty belongs to a group of companies). 6.14. A safeguarding institution should also ensure each acknowledgement letter includes all the required information (such as account names and numbers, the parties’ full names, addresses and contact information, and each signatory’s printed name and title). 6.15. A safeguarding institution should similarly ensure that no square brackets remain in the text of each acknowledgement letter (e.g., after having removed or included square bracketed text, as appropriate, or having replaced square bracketed and italicised text with the required information as indicated in the template) and that each page of the letter is numbered. 6.16. A safeguarding institution should complete an acknowledgement letter so that no part of the letter can be easily altered (e.g., the letter should be signed in ink rather than pencil). 6.17. In respect of the acknowledgement letter’s governing law and choice of competent jurisdiction (see paragraphs (12) and (13) of the template letter), a safeguarding institution should agree

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 25 with the counterparty and reflect in the letter that the laws of a particular jurisdiction will govern the acknowledgement letter and that the courts of that same jurisdiction will have jurisdiction to settle any disputes arising out of, or in connection with, the acknowledgement letter, its subject matter or formation. 6.18. If a safeguarding institution does not, in any acknowledgement letter, utilise the governing law and choice of competent jurisdiction that is the same as either or both:

  1. the laws of the jurisdiction under which either the safeguarding institution or the counterparty are organised; or
  2. as is found in the underlying agreement(s) (e.g., banking services agreement) with the relevant counterparty, the institution should consider whether it is at risk of breaching paragraph 8(1) and (2) or (3) of Schedule 4 to the Payment Services Regulations and paragraph 8(1) and (2) or (3) of Schedule 4 to the Electronic Money Regulations. Authorised signatories 6.19. A safeguarding institution is required to use reasonable endeavours to ensure that any individual that has countersigned an acknowledgement letter returned to the safeguarding institution was authorised to countersign the letter on behalf of the relevant counterparty.6 6.20. If an individual that has countersigned an acknowledgement letter does not provide the safeguarding institution with sufficient evidence of their authority to do so, the safeguarding institution is expected to make appropriate enquiries to satisfy itself of that individual’s authority. 6.21. Evidence of an individual’s authority to countersign an acknowledgement letter may include a copy of the counterparty’s list of authorised signatories, a duly executed power of attorney, use of a company seal or bank stamp, and/or material verifying the title or position of the individual countersigning the acknowledgement letter. 6.22. A safeguarding institution should ensure it obtains at least the same level of assurance over the authority of an individual to countersign the acknowledgement letter as the safeguarding institution would seek when managing its own commercial arrangements. Third party administrators 6.23. If a safeguarding institution uses a third party administrator (‘TPA’) to carry out the administrative tasks of drafting, sending and processing an acknowledgement letter, the text ‘[Signed by [Name of Third Party Administrator] on behalf of [safeguarding institution]]’ should 6 Paragraph 9(7) of Schedule 4 to the Payment Services Regulations and paragraph 9(7) of Schedule 4 to the Electronic Money Regulations

Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 26 be inserted to confirm that the acknowledgement letter was signed by the TPA on behalf of the safeguarding institution. 6.24. In these circumstances, the safeguarding institution should first provide the TPA with the requisite authority (such as a power of attorney) before the TPA will be able to sign the acknowledgement letter on the safeguarding institution’s behalf. A safeguarding institution should also ensure that the acknowledgement letter continues to be drafted on letter-headed paper belonging to the safeguarding institution. Naming 6.25. A safeguarding institution must ensure that each of its accounts is designated in accordance with regulation 31(3)(a) of the Electronic Money Regulations and regulation 84(3)(a) of the Payment Services Regulations. 6.26. All references to the term ‘Relevant Funds Bank Account[s]’ or ‘Relevant Assets Account[s]’ in an acknowledgement letter should also be made consistently in either the singular or plural, as appropriate.

www.gfsc.gi Published by: Gibraltar Financial Services Commission PO Box 940 Suite 3, Ground Floor Atlantic Suites Europort Avenue Gibraltar www.gfsc.gi © 2026 Gibraltar Financial Services Commission