Ok
logo_outline-1
false

Could You Evidence Every CASS Control, Right Now?

Download the CASS Audit Readiness Checklist

As CASS year end approaches, audit planning, evidence gathering and breach reporting move into sharp focus. For some firms this period feels disruptive. For others, it's a natural extension of a control environment that's already working. The difference is rarely the strength of the underlying controls, it's whether governance discipline and audit readiness are built throughout the year rather than assembled in the final weeks before fieldwork.
 
This checklist pulls together 27 checks across six areas of CASS governance, from rule mapping and day-to-day controls through to board reporting and breach management, so you can see exactly where your firm stands before an auditor asks.

Who is this for?

This checklist is for Heads of Compliance, Risk, Governance, CASS and Operational Resilience, CEOs and CFOs at banks, wealth and asset managers, insurers, pension providers, and e-money and payment firms holding client money or assets. If you're accountable for how your next CASS audit goes, this is built for you. 

Download it to assess:

Pre-audit foundation — whether your CASS rule mapping, control ownership and policy review cycle are current, and whether auditors are engaged early enough to agree timelines and evidence requirements in advance.

Day-to-day controls — whether client money segregation, reconciliations, custody records and third-party oversight are genuinely managed day to day, not just tidied up before month end.

Audit pack readiness — whether your rule mapping, policies, reconciliation evidence, TPA oversight and breach logs could be pulled together quickly, or are scattered across separate spreadsheets and inboxes.

Internal governance — whether every control has a named, active owner, and whether your CASS governance forums produce minutes that show real challenge and tracked actions, not just sign-off.

Board and audit committee reporting — whether your MI gives the Board a clear, evidence-based risk narrative, or reads as a comfort statement.

Breach reporting — whether your breach reports go beyond describing what happened, to root cause, remediation and evidence of closure.

Prefer to talk it through as well?

Download the checklist, and book a discovery call to walk through your firm's specific gaps directly.