2026-07-20
Added · Updated
Safeguarding institutions must maintain a safeguarding resolution pack to enable the timely return of client funds in insolvency and assist the GFSC. Relevant funds must be segregated from other client funds, with specific rules governing the segregation method using GFSC-approved secure liquid assets or the insurance/guarantee method. Institutions are required to promptly identify and allocate receipts, treat unidentified funds as unallocated relevant funds, and ensure third-party acknowledgement letters accurately reflect account details and waive third-party recourse rights.
www.gfsc.gi GFSC Guidance Note Payments and Electronic Money: Safeguarding 1 Month 2017 Version: [1] Publication Date: 16 July 2026
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 2 Contents
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 3
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 4 2) in either case, assist the GFSC. 2.4. Part 2 of Schedule 4 to the Payment Services Regulations and Part 2 of Schedule 4 to the Electronic Money Regulations specify the types of documents and records that must be maintained in the safeguarding resolution pack and the retrieval period for the pack. The contents of the documents that constitute the safeguarding resolution pack will change from time to time (for example, because reconciliations must be included in the pack). 2.5. The safeguarding institution should maintain the component documents of the safeguarding resolution pack in order for them to be retrieved in accordance with paragraph 23(1) of Schedule 4 to the Payment Services Regulations and paragraph 23(1) of Schedule 4 to the Electronic Money Regulations. The safeguarding institution should not use the retrieval period to start producing these documents. A safeguarding institution is only required to retrieve the safeguarding resolution pack in the circumstances prescribed in those paragraphs. 2.6. Where a safeguarding institution anticipates that it might be the subject of an insolvency order, it is likely to have sought advice from an external adviser. The safeguarding institution should make the safeguarding resolution pack available promptly, on request, to such an adviser. 2.7. For the purpose of paragraph 24 of Schedule 4 to the Payment Services Regulations and paragraph 24 of Schedule 4 to the Electronic Money Regulations, an example of a change that would render a document inaccurate in a material respect is a change of institution identified pursuant to paragraph 22(1)(b) of Schedule 4 to the Payment Services Regulations and paragraph 22(1)(b) of Schedule 4 to the Electronic Money Regulations. 2.8. A safeguarding institution may hold in electronic form any document in its resolution pack provided that it continues to be able to comply with paragraphs 23(1) and 24 of Schedule 4 to the Payment Services Regulations and paragraphs 23(1) and 24 of Schedule 4 to the Electronic Money Regulations in respect of that document. Core content requirements 2.9. For the purpose of paragraph 22(1)(j)(i) of Schedule 4 to the Payment Services Regulations and paragraph 22(1)(j)(i) of Schedule 4 to the Electronic Money Regulations, examples of individuals within the safeguarding institution who are critical or important to the performance of operational functions include:
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 5 Existing records forming part of the safeguarding resolution pack 2.10. Paragraph 22(3) of Schedule 4 to the Payment Services Regulations and paragraph 22(3) of Schedule 4 to the Electronic Money Regulations do not change the record-keeping requirements referred to therein. 3. Safeguarding relevant funds Purpose and application General purpose 3.1. The following guidance supplements the following provisions which require safeguarding institutions to safeguard relevant funds: • regulation 30 of, and Schedule 4 to, the Electronic Money Regulations; and • regulation 84 of, and Schedule 4 to, the Payment Services Regulations. This guidance applies with respect to the provision of payment services or issuance of electronic money that is within the scope of the Payment Services Regulations or Electronic Money Regulations. 3.2. Funds received by safeguarding institutions that relate to transactions that are not in scope of the Payment Services Regulations or Electronic Money Regulations do not need to be safeguarded and, where the safeguarding institution uses the segregation method, such funds must be kept separate from relevant funds. 3.3. One of the effects of paragraph 3.2 above is that regulation 84 and Schedule 4 the Payment Services Regulations do not apply where payment services are being provided to both the payer and the payee from outside of Gibraltar and the UK (e.g., a transfer between an account operated by a PSP from a branch in Japan to an account operated by another PSP from a branch in Hong Kong). Funds received for these transactions should not be mixed with relevant funds, even if funds are routed through a correspondent PSP in Gibraltar or the UK. 3.4. Electronic money institutions may execute payment transactions that are not related to the issuance of electronic money. Relevant funds relating to such transactions must be safeguarded separately to relevant funds relating to the issuance of electronic money. In such instances, the safeguarding requirements should be applied accordingly. This will be relevant where the safeguarding institution provides payment services that are independent from its electronic money products. The requirement to separately safeguard relevant funds will not apply where the safeguarding institution simply transfers funds from an electronic money account, such as where a customer uses electronic money to pay a bill.
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 6 3.5. A firm must not keep funds in respect of which the safeguarding requirements apply in a client bank account held for any other purpose. Organisational requirements Protection of relevant funds 3.6. An effect of paragraph 3(1) of Schedule 4 to the Payment Services Regulations and paragraph 3(1) of Schedule 4 to the Electronic Money Regulations is that a safeguarding institution should consider how to clearly identify relevant funds that are not held in a relevant funds bank account. That includes those segregated in accordance with regulation 31(1) of the Electronic Money Regulations or regulation 84(2)(a) of the Payment Services Regulations but not yet placed in a relevant funds bank account. The word ‘safeguarding’ should be included in account names wherever possible. Allocation of relevant funds receipts 3.7. Paragraph 3(1) of Schedule 4 to the Payment Services Regulations and paragraph 3(1) of Schedule 4 to the Electronic Money Regulations require a safeguarding institution to promptly identify the client to whom a relevant funds receipt relates. Once identified, the receipt of relevant funds must be recorded and allocated to the client in the safeguarding institution’s accounts. Where the crediting of these accounts amounts to the crediting of a payment account, it must be carried out within the time periods required by the Payment Services Regulations and the Electronic Money Regulations. 3.8. Where the safeguarding institution receives relevant funds on behalf of a payee who does not have a payment account with the safeguarding institution, the relevant funds may need to be allocated immediately so that they can be made available to the payee immediately after they have been credited to the safeguarding institution’s account in accordance with regulation 61 of the Payment Services Regulations. 3.9. Where the receipt of relevant funds relates to the issuance of electronic money, the relevant funds may need to be allocated without delay so that the safeguarding institution can comply with its obligation to issue electronic money without delay under regulation 18 of the Electronic Money Regulations. Unidentified receipts of funds 3.10. Paragraph 4 of Schedule 4 to the Payment Services Regulations and paragraph 4 of Schedule 4 to the Electronic Money Regulations recognise that it might not always be possible to identify whether funds are relevant funds and, if they are, the client to which they relate. Where a safeguarding institution is able to identify that the funds have been received from a client to execute a payment transaction or in exchange for electronic money but is unable to identify
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 7 the client entitled to the funds it has received (for example, because they do not have the correct unique identifier), the funds must still be treated as relevant funds and recorded as ‘unallocated relevant funds’. 3.11. If a safeguarding institution is unable to identify funds that it has received as either relevant funds or other funds, it should consider whether it would be appropriate to return the funds to the person who sent them (or, if that is not possible, to the source from where it was received – for example, the bank). 3.12. Where a payment service user provides an incorrect unique identifier, the safeguarding institution will also need to consider the steps it is required to take under regulation 64 of the Payment Services Regulations. The segregation method 3.13. The segregation method is the method of safeguarding relevant funds described in regulation 31 of the Electronic Money Regulations or regulations 84(2) to (4) of the Payment Services Regulations. 3.14. An effect of regulation 30(5) of the Electronic Money Regulations is that where an electronic money institution receives relevant funds for the execution of payment transactions that are not related to the issuance of electronic money, it must keep those funds segregated from relevant funds relating to the issuance of electronic money. Segregation: secure, liquid assets 3.15. Regulation 31(2)(b) of the Electronic Money Regulations provides that safeguarding institutions may invest relevant funds received in exchange for electronic money in secure, liquid, low-risk assets. Assets are liquid if approved as such by the GFSC. 3.16. Regulation 84(2)(b)(ii) of the Payment Services Regulations provides that safeguarding institutions may invest relevant funds received for the execution of payment transactions unrelated to the issuance of electronic money in such secure, liquid assets as the GFSC may approve. 3.17. The GFSC has approved the following assets for the purposes of regulation 31(2)(b) of the Electronic Money Regulations and regulation 84(2)(b)(ii) of the Payment Services Regulations:
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 8 2) units in a UCITS which invests solely in the assets listed in (1). 3.18. However, the GFSC may, in exceptional circumstances, determine that an asset falling within paragraph 3.17 is not secure and liquid. Appointment of a third party to manage relevant assets 3.19. A safeguarding institution is not required to appoint a third party to manage relevant assets but, if it does, it must comply with paragraph 6(3) of Schedule 4 to the Payment Services Regulations and paragraph 6(3) of Schedule 4 to the Electronic Money Regulations. The insurance or guarantee method 3.20. A safeguarding institution can protect relevant funds using an insurance policy or a guarantee provided that the conditions set out in paragraph 7(2) of Schedule 4 to the Payment Services Regulations and paragraph 7(2) of Schedule 4 to the Electronic Money Regulations are met. 3.21. An effect of paragraph 7(2) of Schedule 4 to the Payment Services Regulations and paragraph 7(2) of Schedule 4 to the Electronic Money Regulations is that the insurance policy or guarantee must pay out the full amount of any claim regardless of why the insolvency event occurs. This includes, but is not limited to, where the insolvency event is caused by any fraud or negligence on the part of the safeguarding institution or any of its directors, employees or agents or something outside the control of the safeguarding institution. It also means that there must be no level below which the insurance policy or guarantee does not pay out. Paragraph 7(2)(d) of Schedule 4 to the Payment Services Regulations and paragraph 7(2)(d) of Schedule 4 to the Electronic Moneys Regulations require the proceeds of an insurance policy or guarantee to be payable into a relevant funds bank account. In practice, this means that the safeguarding institution will need to maintain such an account at least for the full term of the insurance policy or guarantee. 3.22. A safeguarding institution may use more than one insurance policy or guarantee, or a combination of insurance policies and guarantees. However, the effect of the condition in paragraph 7(2)(b) of Schedule 4 to the Payment Services Regulations and in paragraph 7(2)(b) of Schedule 4 to the Electronic Money Regulations is that the terms of each insurance policy or guarantee must not enable the insurer or guarantor to refuse to pay out, in whole or in part, on the basis that relevant funds are covered by another insurer or guarantor. Notification 3.23. The assessment referred to in paragraph 7(4) of Schedule 4 to the Payment Services Regulations and paragraph 7(4) of Schedule 4 to the Electronic Money Regulations should consider operational risks such as:
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 9
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 10 3.29. In complying with paragraph 8(3) of Schedule 4 to the Payment Services Regulations and paragraph 8(3) of Schedule 4 to the Electronic Money Regulations, a safeguarding institution should consider, as appropriate, together with any other relevant matters:
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 11 distinguished from any account containing funds or assets that are not relevant funds or relevant assets; and 3) to ensure that a third party understands and agrees that it will not have any recourse or right against funds or assets standing to the credit of a relevant funds bank account or relevant assets account in respect of any liability of the safeguarding institution to the third party (or a person connected to the third party), except to the extent provided for by the Electronic Money Regulations or the Payment Services Regulations, as the case may be. Review and replacement of safeguarding account acknowledgement letters 3.32. Under paragraph 9(11) of Schedule 4 to the Payment Services Regulations and paragraph 9(11) of Schedule 4 to the Electronic Money Regulations, a safeguarding institution should draw up a replacement acknowledgement letter whenever:
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 12 3.35. The effect of paragraph 10(2) of Schedule 4 to the Payment Services Regulations and paragraph 10(2) of Schedule 4 to the Electronic Money Regulations includes that:
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 13 third parties to create and maintain its internal records where no other method could reasonably be employed. 3.42. An internal safeguarding reconciliation should:
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 14 3.47. Item B (set out in paragraph 12(1)(b) of Schedule 4 to the Payment Services Regulations and paragraph 12(1)(b) of Schedule 4 to the Electronic Money Regulations) should include all relevant funds that have been segregated but are not held in a relevant funds bank account – for example, funds held as cash, funds held by agents and funds held in a segregated account that is not a relevant funds bank account. 3.48. A safeguarding institution may calculate the individual safeguarding balance set out in paragraph 14 of Schedule 4 to the Payment Services Regulations and paragraph 14 of Schedule 4 to the Electronic Money Regulations either:
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 15 a safeguarding institution to reconcile the quantity of relevant assets, rather than the value of those assets. The relevant assets should be compared by asset type. For example, the safeguarding institution should compare its records of the number of units in a particular UCITS against the number of units as set out in the statements provided by the custodian of the units or issuer (as the case may be). 3.54. Insurance policies and guarantees are not subject to the external safeguarding reconciliation. However, safeguarding institutions using the insurance or guarantee method are reminded of their obligations in paragraph 7 of Schedule 4 to the Payment Services Regulations and paragraph 7 of Schedule 4 to the Electronic Money Regulations and the need to ensure that any insurance policy or guarantee provides appropriate cover at all times. Reconciliation discrepancies 3.55. Paragraph 19(1) to (3) of Schedule 4 to the Payment Services Regulations and paragraph 19(1) to (3) of Schedule 4 to the Electronic Money Regulations set out some of the steps that a safeguarding institution must carry out to ensure that it is segregating the right amount of relevant funds, and that it is holding the right amount of relevant funds in relevant funds bank accounts or as relevant assets. Where discrepancies are identified, safeguarding institutions are required to make payments, investments or withdrawals to remedy those discrepancies. 3.56. Paragraph 19(3) of Schedule 4 to the Payment Services Regulations and paragraph 19(3) of Schedule 4 to the Electronic Money Regulations make provision for a safeguarding institution that has a deficiency in its D+1 segregation resource but is unable to access relevant funds to remedy it. Such lack of access could be, for example, because of a delay in the release of relevant funds by a third party. In such circumstances, the safeguarding institution must topup the shortfall from its own funds, even where this leads to a surplus in the safeguarding resource. The discrepancy will be resolved by subsequent reconciliations. 3.57. Where the discrepancy identified under paragraph 19(1) or 19(2) to (3) of Schedule 4 to the Payment Services Regulations and paragraph 19(1) or 19(2) to (3) of Schedule 4 to the Electronic Money Regulations has arisen as a result of a breach of the safeguarding requirements, the safeguarding institution should ensure it takes sufficient steps to avoid a reoccurrence of that breach. 3.58. Paragraph 19(4) and (7) of Schedule 4 to the Payment Services Regulations and paragraph 19(4) and (7) of Schedule 4 to the Electronic Money Regulations recognise that, following an insolvency event, a safeguarding institution is required to investigate discrepancies, but the extent to which it is able to resolve discrepancies may be limited by insolvency law, for example. Notification requirements
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 16 3.59. Safeguarding institutions are reminded that the auditor of the safeguarding institution must confirm in the report submitted to the GFSC whether the safeguarding institution has maintained systems adequate to enable it to comply with the relevant funds regime. 4. Safeguarding Audit Requirements Application 4.1. This section is relevant to electronic money institutions and payment institutions (other than those providing payment initiation services or account information services) that have been required to safeguard more than £100,000 of relevant funds for at least 53 weeks. 4 It is also relevant to their external auditors. 5 For the purposes of this section, these institutions are collectively referred to as ‘relevant institutions’. 4.2. This section applies to relevant institutions whether they safeguard relevant funds through the segregation method, the insurance or guarantee method, or both. It also sets out guidance on the role that auditors play in the GFSC’s monitoring of relevant institutions’ compliance with their safeguarding obligations. 4.3. This guidance should be read in conjunction with the Payment Services Regulations, the Electronic Money Regulations and the Companies Act 2014, which provide the statutory framework for relevant institutions’ and auditors’ obligations. Voluntary application 4.4. The GFSC expects safeguarding institutions that are not subject to this guidance to have in place adequate arrangements to safeguard relevant funds under paragraph 3(1) of Schedule 4 to the Payment Services Regulations and paragraph 3(1) of Schedule 4 to the Electronic Money Regulations and to minimise the risk of their loss or diminution under regulation 84(12) of the Payment Services Regulations and regulation 34(3) of the Electronic Money Regulations. Voluntarily arranging an audit in accordance with this guidance may help ensure they meet these expectations. The senior management of such institutions are also expected to determine, on a continuing basis, whether the institution must comply with the safeguarding audit requirements in Schedule 5 to the Payment Services Regulations and Schedule 5 to the Electronic Money Regulations and appoint an auditor. Rights and duties of auditors 4.5. The rights and duties of auditors are set out in Schedule 5 to the Payment Services Regulations and Schedule 5 to the Electronic Money Regulations. Paragraphs 4.27 and 4.28 below refer to statutory auditors’ duty to report certain matters to the GFSC under regulations 85 and 85B of 4 Paragraph 1 of Schedule 5 to the Payment Services Regulations and paragraph 1 of Schedule 5 to the Electronic Money Regulations 5 Paragraph 3 of Schedule 5 to the Payment Services Regulations and paragraph 3 of Schedule 5 to the Electronic Money Regulations
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 17 the Payment Services Regulations and regulations 39 and 40 of the Electronic Money Regulations. An auditor should bear these rights and duties in mind when carrying out safeguarding report work, including whether anything should be notified to the GFSC immediately. Appointment of auditors 4.6. Paragraph 3 of Schedule 5 to the Payment Services Regulations and paragraph 3 of Schedule 5 to the Electronic Money Regulations require a relevant institution to appoint an auditor and provide the GFSC with information about its auditor. The GFSC requires such information to ensure that the relevant institution has an auditor. Appointment by institutions 4.7. Relevant institutions must appoint an auditor under paragraph 3(1) of Schedule 5 to the Payment Services Regulations and paragraph 3(1) of Schedule 5 to the Electronic Money Regulations, even if they have already appointed an auditor to meet another legal obligation, for example under the Companies Act 2014. The appointed auditor does not have to be, but may be, the same auditor as is appointed to meet another legal obligation. Appointment by the GFSC 4.8. The GFSC may appoint an auditor if the relevant institution fails to do so within the 28-day period under paragraph 3 of Schedule 5 to the Payment Services Regulations and paragraph 3 of Schedule 5 to the Electronic Money Regulations. When considering whether to appoint an auditor, the GFSC will consider the likely delay until the institution can make an appointment and the urgency of any pending duties of the appointed auditor. Auditors’ qualifications 4.9. The GFSC expects the auditor of a relevant institution to have the necessary skill and experience to audit the business of the institution. Qualifications 4.10. A relevant institution should ensure that any auditor it proposes to appoint has the necessary skills, resources and experience commensurate with the nature, scale and complexity of the relevant institution’s business and to the regulatory requirements and standards that apply to it. A relevant institution should have regard to whether the proposed auditor has expertise in the relevant requirements and standards and possesses or has access to appropriate specialist skill. The relevant institution should seek confirmation of this from the auditor concerned as appropriate.
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 18 Disqualified auditors 4.11. If it appears to the GFSC that an auditor of a relevant institution has failed to comply with a duty imposed on them, it may take disciplinary measures, including disqualification of the auditor under section 174 of the Financial Services Act 2019 (“FSA”). Requests for information by the GFSC 4.12. The GFSC may request information about the auditor’s relevant experience and skills to assess their ability to audit a relevant institution. This may include written requests to auditors who have not previously audited a relevant institution. The relevant institution should instruct the auditor to provide a full reply (and should not appoint an auditor who fails to respond). The GFSC may also seek further information from an auditor of a relevant institution on an ongoing basis. Auditors’ independence 4.13. To carry out their duties properly, an auditor needs to be independent of the institution they are auditing so they are not subject to conflicts of interest. 4.14. The GFSC will regard an auditor as independent if their appointment or retention does not breach the Code of Ethics for Professional Accountants published by the International Ethics Standards Board for Accountants, as amended from time to time, on the appointment of an auditor in circumstances which could give rise to conflicts of interest. Relevant institutions’ cooperation with their auditors Auditor’s access to accounting records 4.15. In complying with paragraph 6 of Schedule 5 to the Payment Services Regulations and paragraph 6 of Schedule 5 to the Electronic Money Regulations, a relevant institution should give a right of access at all times to the institution’s accounting and other records, in whatever form they are held, and documents relating to its business. A relevant institution should allow its auditor to copy documents or other material on the premises of the institution and to remove copies or hold them elsewhere, or give its auditor such copies on request. 4.16. Section 165 of the FSA provides that an auditor of a relevant institution appointed under Schedule 5 to the Payment Services Regulations and under Schedule 5 to the Electronic Money Regulations:
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 19 2) is entitled to require from the relevant institution’s officers such information and explanations as they reasonably consider necessary for the performance of their duties as auditor. 4.17. Section 257 of the Companies Act 2006 give similar rights to auditors of companies. 4.18. Section 514 of the FSA, under which no person is required to produce a document or disclose information if the person would be entitled to refuse to produce or disclose it on grounds of legal privilege in proceedings in the Supreme Court, is relevant to paragraph 6 of Schedule 5 to the Payment Services Regulations, paragraph 6 of Schedule 5 to the Electronic Money Regulations and paragraph 4.16 of this Guidance Note. Access and cooperation: agents, distributors, operational outsourcing, employees 4.19. In complying with paragraph 6 of Schedule 5 to the Payment Services Regulations and paragraph 6 of Schedule 5 to the Electronic Money Regulations, a relevant institution should take reasonable steps to ensure that:
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 20 4.21. A relevant institution should consider whether it should notify the GFSC under Core Principle 12 if it receives a written communication from its auditor commenting on internal controls. Rights and duties of auditors 4.22. The following paragraphs provide guidance on the rights and duties that enable or require auditors of a relevant institution to obtain information from the institution and pass information to the GFSC in specified circumstances. Cooperation with the GFSC 4.23. The GFSC may ask the auditor to attend meetings and to supply it with information about the institution. In complying with paragraph 7 of Schedule 5 to the Payment Services Regulations and paragraph 7 of Schedule 5 to the Electronic Money Regulations, the auditor should attend such meetings as the GFSC requests and supply it with any information the GFSC may reasonably request about the relevant institution to enable the GFSC to discharge its functions under the FSA, the Payment Services Regulations and the Electronic Money Regulations. Communication between the GFSC, the relevant institution and the auditor 4.24. Within the legal constraints that apply, the GFSC may pass on to an auditor any information which it considers relevant to the auditor’s function. An auditor is bound by the duty of confidentiality and professional secrecy set out in section 498 of the FSA in respect of confidential information received from the GFSC. An auditor may not pass on such confidential information without lawful authority. For example, if an exception applies as set out in section 498(2) of the FSA or with the consent of the person from whom that information was received (see section 46(4) of the FSA) and, if different, to whom that information relates. Auditors’ statutory duty to report 4.25. Statutory auditors of safeguarding institutions are subject to regulation 85 of the Payment Services Regulations and regulation 18 of the Electronic Money Regulations. Those regulations require statutory auditors to communicate matters of material significance to the GFSC. A failure to safeguard relevant funds will usually be of material significance and should be communicated to the GFSC. This is especially the case where an institution claims not to be required to safeguard relevant funds at all. 4.26. Sections 166(6) and 167(7) of the FSA provide that an auditor does not contravene any duty by giving information or expressing an opinion to the GFSC, if they are acting in good faith and reasonably believe that the information or opinion is relevant to any functions of the GFSC. These provisions continue to have effect after the end of the auditor’s term of appointment. Duties of auditors: notification and safeguarding report
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 21 Auditor’s safeguarding report 4.27. Paragraph 8(1) of Schedule 5 to the Payment Services Regulations and paragraph 8(1) of Schedule 5 to the Electronic Money Regulations provide that an auditor must ensure that a safeguarding report is prepared in accordance with the terms of a reasonable assurance engagement. The GFSC also expects an auditor to have regard, where relevant, to any material published by the GFSC that deals specifically with the safeguarding report which the auditor is required to submit to the GFSC. In the GFSC’s view, a safeguarding report that is prepared in accordance with that material is likely to comply with paragraph 8(1) and (3) of Schedule 5 to the Payment Services Regulations and paragraph 8(1) and (3) of Schedule 5 to the Electronic Money Regulations where that report is prepared for a relevant institution within the scope of the material in question. Auditor’s safeguarding report: timing of submission 4.28. An auditor should bear the rights and duties set out in Schedule 5 to the Payment Services Regulations and in Schedule 5 to the Electronic Money Regulations in mind when carrying out safeguarding report work, including whether anything should be notified to the GFSC immediately. Auditor’s safeguarding report: requirements not met or inability to form opinion 4.29. The GFSC expects that the list of breaches will include every breach of a regulation in the relevant funds regime insofar as that regulation is within the scope of the safeguarding report and is identified in the course of the auditor’s review of the period covered by the report, whether identified by the auditor or disclosed to it by the relevant institution or by any third party. 4.30. For the purpose of determining whether to qualify its opinion or express an adverse opinion, the GFSC expects an auditor to exercise its professional judgment as to the significance of a breach of a regulation, as well as to its context, duration and incidence of repetition. The GFSC expects an auditor to consider the aggregate effect of any breaches when judging whether a relevant institution failed to comply with the requirements in paragraph 8(3) of Schedule 5 to the Payment Services Regulations and paragraph 8(3) of Schedule 5 to the Electronic Money Regulations. Review of auditor’s safeguarding report 4.31. The GFSC expects a relevant institution to use the safeguarding report as a tool to evaluate the effectiveness of the systems it has in place for the purpose of complying with paragraph 8(3) of Schedule 5 to the Payment Services Regulations and paragraph 8(3) of Schedule 5 to the Electronic Money Regulations. Accordingly, a relevant institution should ensure that the report is integrated into its risk management framework and decision-making.
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 22 4.32. Paragraph 4(1) of Schedule 5 to the Payment Services Regulations and paragraph 4(1) of Schedule 5 to the Electronic Money Regulations provide that a relevant institution must take reasonable steps to ensure that its auditor has the required skill, resources and experience to perform its functions. The GFSC expects a relevant institution to keep under review the adequacy of the skill, resources and experience of its auditor and critically assess the content of the safeguarding report as part of that ongoing review. 5. Safeguarding Return 5.1. Regulation 84A of the Payment Services Regulations and regulation 32A(1) of the Electronic Money Regulations set out the requirement for safeguarding institutions to submit a safeguarding return. 6. Safeguarding Account Acknowledgement Letters 6.1. This part sets out guidance on when and how safeguarding institutions should amend the acknowledgement letter variable text that is in square brackets. 6.2. Safeguarding institutions are required to request duly signed and countersigned acknowledgement letters for their relevant funds bank accounts and relevant assets accounts. 6.3. For each account, a safeguarding institution is required to complete, sign and send to the approved bank or authorised custodian (‘the counterparty’) an acknowledgement letter identifying that account in the form set out in the Annex to the Payment Services Regulations and the Annex to the Electronic Money Regulations. 6.4. When completing an acknowledgement letter using the appropriate template, a safeguarding institution is reminded that it must not amend any of the text which is not in square brackets (acknowledgement letter fixed text). A safeguarding institution should also not amend the non-italicised text that is in square brackets. It may remove or include square bracketed text from the letter, or replace bracketed and italicised text with the required information, in either case as appropriate. Clear identification of relevant accounts 6.5. A safeguarding institution is reminded that for each relevant funds bank account or relevant assets account it needs to request an acknowledgement letter. It is important that it is clear to which account or accounts each acknowledgement letter relates. As a result, the template in the Annex to the Payment Services Regulations and the Annex to the Electronic Money Regulations require that the acknowledgement letter includes the full title and at least one unique identifier, such as a sort code and account number, deposit number or reference code, for each account.
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 23 6.6. The title and unique identifiers included in an acknowledgement letter for an account should be the same as those reflected in both the records of the safeguarding institution and the relevant counterparty, as appropriate, for that account. Where a counterparty’s systems are not able to reflect the full title of an account, that title may be abbreviated to accommodate that system, provided that:
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 24 with [the following [insert common unique identifier]] [an account number from and including [XXXX1111] to and including [ZZZZ9999]] [clearly identify range of unique identifiers].’. Signatures and countersignatures 6.10. A safeguarding institution should ensure that each acknowledgement letter is signed and countersigned by all relevant parties and individuals (including where more than one signatory is required). 6.11. An acknowledgement letter that is signed or countersigned electronically should not, for that reason alone, result in a breach of paragraph 9 of Schedule 4 to the Payment Services Regulations and paragraph 9 of Schedule 4 to the Electronic Money Regulations. However, where electronic signatures are used, a safeguarding institution should consider whether, taking into account the governing law and choice of competent jurisdiction, it needs to ensure that the electronic signature and the certification by any person of such signature would be admissible as evidence in any legal proceedings in the relevant jurisdiction in relation to any question as to the authenticity or integrity of the signature or any associated communication. Completing a safeguarding account acknowledgement letter 6.12. A safeguarding institution should use at least the same level of care and diligence when completing an acknowledgement letter as it would in managing its own commercial agreements. 6.13. A safeguarding institution should ensure that each acknowledgement letter is legible (e.g., any handwritten details should be easy to read), produced on the safeguarding institution’s own letter-headed paper, dated and addressed to the correct legal entity (e.g., where the counterparty belongs to a group of companies). 6.14. A safeguarding institution should also ensure each acknowledgement letter includes all the required information (such as account names and numbers, the parties’ full names, addresses and contact information, and each signatory’s printed name and title). 6.15. A safeguarding institution should similarly ensure that no square brackets remain in the text of each acknowledgement letter (e.g., after having removed or included square bracketed text, as appropriate, or having replaced square bracketed and italicised text with the required information as indicated in the template) and that each page of the letter is numbered. 6.16. A safeguarding institution should complete an acknowledgement letter so that no part of the letter can be easily altered (e.g., the letter should be signed in ink rather than pencil). 6.17. In respect of the acknowledgement letter’s governing law and choice of competent jurisdiction (see paragraphs (12) and (13) of the template letter), a safeguarding institution should agree
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 25 with the counterparty and reflect in the letter that the laws of a particular jurisdiction will govern the acknowledgement letter and that the courts of that same jurisdiction will have jurisdiction to settle any disputes arising out of, or in connection with, the acknowledgement letter, its subject matter or formation. 6.18. If a safeguarding institution does not, in any acknowledgement letter, utilise the governing law and choice of competent jurisdiction that is the same as either or both:
Gibraltar Financial Services Commission Guidance Note – Payments and Electronic Money: Safeguarding 26 be inserted to confirm that the acknowledgement letter was signed by the TPA on behalf of the safeguarding institution. 6.24. In these circumstances, the safeguarding institution should first provide the TPA with the requisite authority (such as a power of attorney) before the TPA will be able to sign the acknowledgement letter on the safeguarding institution’s behalf. A safeguarding institution should also ensure that the acknowledgement letter continues to be drafted on letter-headed paper belonging to the safeguarding institution. Naming 6.25. A safeguarding institution must ensure that each of its accounts is designated in accordance with regulation 31(3)(a) of the Electronic Money Regulations and regulation 84(3)(a) of the Payment Services Regulations. 6.26. All references to the term ‘Relevant Funds Bank Account[s]’ or ‘Relevant Assets Account[s]’ in an acknowledgement letter should also be made consistently in either the singular or plural, as appropriate.
www.gfsc.gi Published by: Gibraltar Financial Services Commission PO Box 940 Suite 3, Ground Floor Atlantic Suites Europort Avenue Gibraltar www.gfsc.gi © 2026 Gibraltar Financial Services Commission