The Central Bank asked every payment and electronic money institution in Cyprus for an independent review of how it safeguards client money, against eighteen areas the regulator listed. We have been doing that work. A review of this kind rarely finds client money that has gone missing. What it finds, again and again, is work that was being done and had never been written down. That is the pattern this piece is about, because a board can fix it in weeks.
What the regulator actually asked for
It is worth being clear about the deliverable, because it shapes everything that follows. The Central Bank asked for a limited assurance report under a named international standard, on the year that ended on 31 December, covering two questions: whether the safeguarding arrangements were properly designed, and whether they operated through that year. The reference period and the standard are both fixed, and the reviewer's conclusion is about that year only. Most institutions have done a great deal since then. Policies have been rewritten and procedures issued beneath them. All of that goes into the report as the institution's response, and it matters, because it is what the regulator will look at next. Work done in 2026 improves the position for 2026, which is why it is worth doing. The conclusion for 2025 is unaffected by it.
The policies read well
The safeguarding policies we read are, on the whole, decent documents. They track the regulation and the regulator's stated expectations, and they have been revised as the rules moved. Where they fall short, it is usually in the same way: they describe what happens without describing how. If a review stopped at the policy, it would be a short review. The gap opens the moment the reviewer asks how any of it is done. The policy says client money is reconciled every week, so the reviewer asks who does it, from which system, by what day, and who checks it, and there is no document with the answer. The policy says the institution keeps client money at carefully chosen banks, and there is no written criterion for choosing one or for deciding when to stop using one. The policy says the institution knows where the money is, and the first request in a review of this kind, a list of every account that held client money during the year, often takes days to assemble, because no policy required anyone to maintain a register.
None of this means the work is not being done. The reconciliations run, somebody did look at the banks before the accounts were opened, the money is in separate accounts, and the people know what they do every morning. But nothing on file says how any of it is done, and that matters for a reason that has nothing to do with the regulator.
A procedure that lives in someone's head can be performed. It cannot be tested or handed over.
Work that was done but cannot be shown
Most findings sit in this category, and a board should read them differently from a control that failed. Decisions about which accounts count as safeguarding accounts are often taken properly and recorded nowhere, so that a year later the decision can be explained but not shown. Bank due diligence was done once, is not dated, and shows no sign of who prepared or approved it. Reconciliations were performed but carry no evidence of review, or the review was done by someone the policy does not name. Board approval follows the same pattern: approval dates trail the date the policy took effect, sometimes by weeks or more, and where the board has discussed and adopted a document, the minutes need to show it.
Then there is a category of work that only exists if you did it. A bank's written confirmation that an account holds client money, that the bank has no right of set-off against it, and that it sits within a deposit guarantee scheme, is not a record of something else. The letter is the control. Without it there is nothing to test. The same goes for the signing mandate: the board approves a list of signatories and a two-signature rule, and the question is whether each bank holds that list and applies that rule. Often the question has been asked of some banks and not all.
When the internal audit report says nothing
An institution will sometimes hand the reviewer an internal audit report on safeguarding, produced by an outside provider, with no findings in it. That is not a reason to criticise the provider. Internal audit works from a plan, a sample and a set of questions, and a report with no findings tells you those questions were answered. It does not tell you there was nothing else to find. This is why a licensed institution has more than one line of defence. It is common for the compliance function to have already found something the internal audit report does not mention, tracked the fix and dated it. One control function catches what another missed, which is what several lines of defence are for. A board that treats a clean audit report as the end of the matter is not using them.
The blind spot is usually in the scope
The finding that surprises boards most is about what nobody was asked to look at. An institution that safeguards by holding client money at banks may, at some point in the year, hold some of it in another form, in a short-term instrument for example. That puts it under a different set of rules, with limits, valuation and a policy of its own, and an institution that does this only occasionally usually has no such policy at all. The finding is still made, because nobody drew the boundary of what counted as safeguarding, so one way of doing it was never examined.
Where the governance work comes in
The reader who runs a payment or electronic money institution will recognise most of this from a different document. The Central Bank's governance directive, which we wrote about when it was published, asks for a documented allocation of responsibilities, control functions that report to the board on a stated schedule, a segregation of duties that keeps the person operating a process away from the person reviewing it, and a route for escalating a problem. Action plans went in during August, and full compliance is due in February.
The safeguarding findings and the governance directive cover much of the same ground. It is common for the accountable safeguarding officer also to run the functions that operate the client accounts and review the reconciliations, and that is a governance finding as much as a safeguarding one. The absence of a safeguarding report to the board, or of an escalation route, is the governance directive's subject matter. So is an internal audit programme that treats safeguarding as one area among many. An institution that builds its governance action plan properly produces most of what the safeguarding review looks for. Treating the review as a stand-alone exercise for the regulator means repeating it next year.
What to do with this
The test is a simple one and it can be run in an afternoon. Take the safeguarding policy. For each thing it says the institution does, ask three questions. Is there a written procedure that says how? Is there a document, signed and dated, that shows it was done last week? And if the person who does it left tomorrow, could someone else pick it up from what is on file? Where the answer to any of those is no, the reviewer will find it, because that is the question the eighteen areas are built to ask. It costs a great deal less to find it first.