The spreadsheet that runs your compliance risk
Every fintech I have worked with has one process that everyone quietly dreads: reconciliation. It starts as a spreadsheet someone built in a weekend. Two years later it is still running the business, held together by macros, tribal knowledge, and one person who knows why row 4,000 always breaks.
The problem is not that manual reconciliation is slow. The problem is that it stops being a process and becomes a liability, both financial and regulatory. And in 2025 and 2026, the regulatory side got a lot less forgiving.
What manual reconciliation actually costs
According to the AICPA's 2025 Firm Operations Benchmarking Report, manual bank reconciliation consumes 22% of total capacity at firms with 10 to 50 staff, work that generates zero direct revenue. That is nearly a quarter of your operations headcount matching records instead of building the business.
The error cost compounds this. Manual matching processes typically run error rates in the low single digits, and on payment volumes in the millions, even a small percentage translates into real reconciling items that someone has to chase, explain, and document. Every hour spent chasing a break is an hour not spent on the growth work you actually hired people for.
The regulatory ground has shifted
For UK payment and e-money institutions, this is no longer just an efficiency question. The FCA published PS25/12 in August 2025, confirming a new Supplementary Safeguarding Regime that takes effect on 7 May 2026. It requires enhanced fund reconciliation, annual safeguarding audits, resolution packs, and a new monthly safeguarding return, form REP027, due within 15 business days of each month end. Firms already have to reconcile safeguarded funds daily. Now they also have to prove, monthly, that the reconciliation held up, with dates, methods, shortfalls, and rectifications documented.
A spreadsheet process cannot produce that trail reliably, month after month, without someone spending days assembling it by hand and hoping nothing was missed.
At the same time, the EU's Digital Operational Resilience Act has been fully applicable since 17 January 2025, harmonising ICT risk management rules across banks, payment firms, and e-money institutions. DORA expects firms to identify single points of failure in the systems that support critical functions. A manual reconciliation process run by one analyst in a spreadsheet is exactly the kind of dependency that shows up badly in a DORA risk assessment or an incident review.
Signs you are patching, not operating
A few patterns tell you the process has outgrown its foundation:
- You add a new exception rule to the spreadsheet almost every month, and no one remembers why the old ones are there.
- Month end reconciliation still depends on one specific person being available.
- Your team can tell you what broke last time, but not what will break next time.
- Producing an audit trail for a regulator takes days of manual assembly instead of a few clicks.
- New payment rails or providers get bolted onto the same fragile file instead of a real data model.
If two or more of these sound familiar, you are not maintaining a process anymore. You are managing its decay.
When to stop patching and rebuild
Patching makes sense when the process is fundamentally sound and the issue is a one-off gap. Rebuilding makes sense once the cost of patching, in hours, in error risk, in regulatory exposure, starts to exceed the cost of doing it properly. Given the FCA's monthly reporting deadline and DORA's resilience expectations, that line has moved much closer for most regulated fintechs than it was two years ago.
A rebuilt process does not mean throwing people at more manual checks. It means automated matching against your safeguarding ledgers, exception queues that route themselves, and an audit trail that exists because the system produced it, not because someone compiled it under deadline pressure.
How Novafin helps
At Novafin, we work with fintech operations and compliance teams to map where manual reconciliation is quietly creating risk, then design and implement the automation that fixes it for good, built to hold up under FCA and DORA scrutiny, not just to survive this quarter's audit. If your reconciliation process feels like it is one busy month away from breaking, get in touch and let's look at what rebuilding it properly would actually take.