Content Options:

Content Options

CHAPTER II RESILIENCE OF TRADING SYSTEMS

SECTION I Testing and deployment of trading algorithms systems and strategies

Article 5 General methodology(Article 17(1) of Directive 2014/65/EU)

  1. (1)

    Prior to the deployment or substantial update of an algorithmic trading system, trading algorithm or algorithmic trading strategy, an investment firm shall establish clearly delineated methodologies to develop and test such systems, algorithms or strategies.

  2. (2)

    A person designated by the senior management of the investment firm shall authorise the deployment or substantial update of an algorithmic trading system, trading algorithm or algorithmic trading strategy.

  3. (3)

    The methodologies referred to in paragraph 1 shall address the design, performance, recordkeeping and approval of the algorithmic trading system, trading algorithm or algorithmic trading strategy. They shall also set out the allocation of responsibilities, the allocation of sufficient resources and the procedures to seek instructions within the investment firm.

  4. (4)

    The methodologies referred to in paragraph 1 shall ensure that the algorithmic trading system, trading algorithm or algorithmic trading strategy:

    1. (a)

      does not behave in an unintended manner;

    2. (b)

      complies with the investment firm's obligations under this Regulation;

    3. (c)

      complies with the rules and systems of the trading venues accessed by the investment firm;

    4. (d)

      does not contribute to disorderly trading conditions, continues to work effectively in stressed market conditions and, where necessary under those conditions, allows for the switching off of the algorithmic trading system or trading algorithm.

  5. (5)

    An investment firm shall adapt its testing methodologies to the trading venues and markets where the trading algorithm will be deployed. An investment firm shall undertake further testing if there are substantial changes to the algorithmic trading system or to the access to the trading venue in which the algorithmic trading system, trading algorithm or algorithmic trading strategy are to be used.

  6. (6)

    Paragraphs 2 to 5 shall only apply to trading algorithms leading to order execution.

  7. (7)

    An investment firm shall keep records of any material change made to the software used for algorithmic trading, allowing it to determine:

    1. (a)

      when a change was made;

    2. (b)

      the person that has made the change;

    3. (c)

      the person that has approved the change;

    4. (d)

      the nature of the change.

Article 6 Conformance testing(Article 17(1) of Directive 2014/65/EU)

  1. (1)

    An investment firm shall test the conformance of its algorithmic trading systems and trading algorithms with:

    1. (a)

      the system of the trading venue in any of the following cases:

      1. (i)

        when accessing that trading venue as a member;

      2. (ii)

        when connecting to that trading venue through a sponsored access arrangement for the first time;

      3. (iii)

        where there is a material change of the systems of that trading venue;

      4. (iv)

        prior to the deployment or material update of the algorithmic trading system, trading algorithm or algorithmic trading strategy of that investment firm.

    2. (b)

      the system of the direct market access provider in any of the following cases:

      1. (i)

        when accessing that trading venue through a direct market access arrangement for the first time;

      2. (ii)

        when there is a material change affecting the direct market access functionality of that provider;

      3. (iii)

        prior to the deployment or material update of the algorithmic trading system, trading algorithm or algorithmic trading strategy of that investment firm.

  2. (2)

    Conformance testing shall verify whether the basic elements of the algorithmic trading system or the trading algorithm operate correctly and in accordance with the requirements of the trading venue or the direct market access provider. For this purpose the testing shall verify that the algorithmic trading system or trading algorithm:

    1. (a)

      interacts with the trading venue's matching logic as intended;

    2. (b)

      adequately processes the data flows downloaded from the trading venue.

Article 7 Testing environments(Article 17(1) of Directive 2014/65/EU)

  1. (1)

    An investment firm shall ensure that testing of compliance with the criteria laid down in Article 5(4)(a), (b) and (d) is undertaken in an environment that is separated from its production environment and that is used specifically for the testing and development of algorithmic trading systems and trading algorithms.

    For the purposes of the first subparagraph, a production environment shall mean an environment where algorithmic trading systems effectively operate, and comprise software and hardware used by traders, order routing to trading venues, market data, dependent databases, risk control systems, data capture, analysis systems and post-trade processing systems.

  2. (2)

    An investment firm may comply with the testing requirements referred to in paragraph 1 by using its own testing environment or a testing environment provided by a trading venue, a DEA provider or a vendor.

  3. (3)

    An investment firm shall retain full responsibility for the testing of its algorithmic trading systems, trading algorithms or algorithmic trading strategies and for making any required changes to them.

Article 8 Controlled deployment of algorithms(Article 17(1) of Directive 2014/65/EU)

Before deployment of a trading algorithm, an investment firm shall set predefined limits on:

  1. (a)

    the number of financial instruments being traded;

  2. (b)

    the price, value and numbers of orders;

  3. (c)

    the strategy positions; and

  4. (d)

    the number of trading venues to which orders are sent.

SECTION 2 Post-deployment management

Article 9 Annual self-assessment and validation(Article 17(1) of Directive 2014/65/EU)

  1. (1)

    An investment firm shall annually perform a self-assessment and validation process and on the basis of that process issue a validation report. In the course of that process the investment firm shall review, evaluate and validate the following:

    1. (a)

      its algorithmic trading systems, trading algorithms and algorithmic trading strategies;

    2. (b)

      its governance, accountability and approval framework;

    3. (c)

      its business continuity arrangement;

    4. (d)

      its overall compliance with UK law corresponding to Article 17 of Directive 2014/65/EU, having regard to the nature, scale and complexity of its business.

    The self-assessment shall also include at least an analysis of compliance with the criteria set out in Annex I to this Regulation.

  2. (2)

    The risk management function of the investment firm referred to in Article 23(2) of Commission Delegated Regulation (EU) 2017/565, shall draw up the validation report and, for that purpose, involve staff with the necessary technical knowledge. The risk management function shall inform the compliance function of any deficiencies identified in the validation report.

  3. (3)

    The validation report shall be audited by the firm's internal audit function, where such function exists, and be subject to approval by the investment firm's senior management.

  4. (4)

    An investment firm shall remedy any deficiencies identified in the validation report.

  5. (5)

    Where an investment firm has not established a risk management function referred to in that Regulation, the requirements set out in relation to the risk management function in this Regulation shall apply to any other function established by the investment firm in accordance with Article 23(2) of that Regulation.

Article 10 Stress testing(Article 17(1) of Directive 2014/65/EU)

As part of its annual self-assessment referred to in Article 9, an investment firm shall test that its algorithmic trading systems and the procedures and controls referred to in Articles 12 to 18 can withstand increased order flows or market stresses. The investment firm shall design such tests, having regard to the nature of its trading activity and its trading systems. The investment firm shall ensure that the tests are carried out in such a way that they do not affect the production environment. Those tests shall comprise:

  1. (a)

    running high messaging volume tests using the highest number of messages received and sent by the investment firm during the previous six months, multiplied by two;

  2. (b)

    running high trade volume tests, using the highest volume of trading reached by the investment firm during the previous six months, multiplied by two.

Article 11 Management of material changes(Article 17(1) of Directive 2014/65/EU)

  1. (1)

    An investment firm shall ensure that any proposed material change to the production environment related to algorithmic trading is preceded by a review of that change by a person designated by senior management of the investment firm. The depth of the review shall be proportionate to the magnitude of the proposed change.

  2. (2)

    An investment firm shall establish procedures to ensure that any change to the functionality of its systems is communicated to traders in charge of the trading algorithm and to the compliance function and the risk management function.

SECTION 3 Means to ensure resilience

Article 12 Kill functionality(Article 17(1) of Directive 2014/65/EU)

  1. (1)

    An investment firm shall be able to cancel immediately, as an emergency measure, any or all of its unexecuted orders submitted to any or all trading venues to which the investment firm is connected ("kill functionality").

  2. (2)

    For the purposes of paragraph 1, unexecuted orders shall include those originating from individual traders, trading desks or, where applicable, clients.

  3. (3)

    For the purposes of paragraph 1 and 2, an investment firm shall be able to identify which trading algorithm and which trader, trading desk or, where applicable, which client is responsible for each order that has been sent to a trading venue.

Article 13 Automated surveillance system to detect market manipulation(Article 17(1) of Directive 2014/65/EU)

  1. (1)

    An investment firm shall monitor all trading activity that takes place through its trading systems, including that of its clients, for signs of potential market manipulation as referred to in Article 12 of Regulation (EU) No 596/2014.

  2. (2)

    For the purposes of paragraph 1, the investment firm shall establish and maintain an automated surveillance system which effectively monitors orders and transactions, generates alerts and reports and, where appropriate, employs visualisation tools.

  3. (3)

    The automated surveillance system shall cover the full range of trading activities undertaken by the investment firm and all orders submitted by it. It shall be designed having regard to the nature, scale and complexity of the investment firm's trading activity, such as the type and volume of instruments traded, the size and complexity of its order flow and the markets accessed.

  4. (4)

    The investment firm shall cross-check any indications of suspicious trading activity that have been generated by its automated surveillance system during the investigation phase against other relevant trading activities undertaken by that firm.

  5. (5)

    The investment firm's automated surveillance system shall be adaptable to changes to the regulatory obligations and the trading activity of the investment firm, including changes to its own trading strategy and that of its clients.

  6. (6)

    The investment firm shall review its automated surveillance system at least once a year to assess whether that system and the parameters and filters employed by it are still adequate to the investment firm's regulatory obligations and trading activity, including its ability to minimise the generation of false positive and false negative surveillance alerts.

  7. (7)

    Using a sufficiently detailed level of time granularity, the investment firm's automated surveillance system shall be able to read, replay and analyse order and transaction data on an ex-post basis, with sufficient capacity to be able to operate in an automated low-latency trading environment where relevant. It shall also be able to generate operable alerts at the beginning of the following trading day or, where manual processes are involved, at the end of the following trading day. The investment firm's surveillance system shall have adequate documentation and procedures in place for the effective follow-up to alerts generated by it.

  8. (8)

    Staff responsible for monitoring the investment firm's trading activities for the purposes of paragraphs 1 to 7 shall report to the compliance function any trading activity that may not be compliant with the investment firm's policies and procedures or with its regulatory obligations. The compliance function shall assess that information and take appropriate action. Such action shall include reporting to the trading venue or submitting a suspicious transaction or order report in accordance with Article 16 of Regulation (EU) No 596/2014.

  9. (9)

    An investment firm shall ensure that its records of trade and account information are accurate, complete and consistent by reconciling as soon as practicable its own electronic trading logs with records provided by its trading venues, brokers, clearing members, central counterparties, data providers or other relevant business partners, where applicable and appropriate considering the nature, scale and complexity of the business.

Article 14 Business continuity arrangements(Article 17(1) of Directive 2014/65/EU)

  1. (1)

    An investment firm shall have business continuity arrangements in place for its algorithmic trading systems which are appropriate to the nature, scale and complexity of its business. Those arrangements shall be documented in a durable medium.

  2. (2)

    Business continuity arrangements of an investment firm shall effectively deal with disruptive incidents and, where appropriate, ensure a timely resumption of the algorithmic trading. Those arrangements shall be adapted to the trading systems of each of the trading venue accessed and shall include the following:

    1. (a)

      a governance framework for the development and of the deployment of the business continuity arrangement;

    2. (b)

      a range of possible adverse scenarios relating to the operation of the algorithmic trading systems, including the unavailability of systems, staff, work space, external suppliers or data centres or loss or alteration of critical data and documents;

    3. (c)

      procedures for relocating the trading system to a back-up site and operating the trading system from that site, where having such a site is appropriate to the nature, scale and complexity of the algorithmic trading activities of the investment firm;

    4. (d)

      staff training on the operation of the business continuity arrangements;

    5. (e)

      usage policy regarding the functionality referred to in Article 12;

    6. (f)

      arrangements for shutting down the relevant trading algorithm or trading system where appropriate;

    7. (g)

      alternative arrangements for the investment firm to manage outstanding orders and positions.

  3. (3)

    An investment firm shall ensure that its trading algorithm or trading system can be shut down in accordance with its business continuity arrangements without creating disorderly trading conditions.

  4. (4)

    An investment firm shall review and test its business continuity arrangements on an annual basis and modify the arrangements in light of that review.

Article 15 Pre-trade controls on order entry(Article 17(1) of Directive 2014/65/EU)

  1. (1)

    An investment firm shall carry out the following pre-trade controls on order entry for all financial instruments:

    1. (a)

      price collars, which automatically block or cancel orders that do not meet set price parameters, differentiating between different financial instruments, both on an order-by-order basis and over a specified period of time;

    2. (b)

      maximum order values, which prevent orders with an uncommonly large order value from entering the order book;

    3. (c)

      maximum order volumes, which prevent orders with an uncommonly large order size from entering the order book;

    4. (d)

      maximum messages limits, which prevent sending an excessive number of messages to order books pertaining to the submission, modification or cancellation of an order.

  2. (2)

    An investment firm shall immediately include all orders sent to a trading venue into the calculation of the pre-trade limits referred to in paragraph 1.

  3. (3)

    An investment firm shall have in place repeated automated execution throttles which control the number of times an algorithmic trading strategy has been applied. After a pre-determined number of repeated executions, the trading system shall be automatically disabled until re-enabled by a designated staff member.

  4. (4)

    An investment firm shall set market and credit risk limits that are based on its capital base, its clearing arrangements, its trading strategy, its risk tolerance, experience and certain variables, such as the length of time the investment firm has been engaged in algorithmic trading and its reliance on third-party vendors. The investment firm shall adjust those market and credit risk limits to account for the changing impact of the orders on the relevant market due to different price and liquidity levels.

  5. (5)

    An investment firm shall automatically block or cancel orders from a trader if it becomes aware that that trader does not have permission to trade a particular financial instrument. An investment firm shall automatically block or cancel orders where those orders risk compromising the investment firm's own risk thresholds. Controls shall be applied, where appropriate, on exposures to individual clients, financial instruments, traders, trading desks or the investment firm as a whole.

  6. (6)

    An investment firm shall have procedures and arrangements in place for dealing with orders which have been blocked by the investment firm's pre-trade controls but which the investment firm nevertheless wishes to submit. Such procedures and arrangements shall be applied in relation to a specific trade on a temporary basis and in exceptional circumstances. They shall be subject to verification by the risk management function and authorisation by a designated individual of the investment firm.

Article 16 Real-time monitoring(Article 17(1) of Directive 2014/65/EU)

  1. (1)

    An investment firm shall, during the hours it is sending orders to trading venues, monitor in real time all algorithmic trading activity that takes place under its trading code, including that of its clients, for signs of disorderly trading, including trading across markets, asset classes, or products, in cases where the firm or its clients engage in such activities.

  2. (2)

    The real-time monitoring of algorithmic trading activity shall be undertaken by the trader in charge of the trading algorithm or algorithmic trading strategy, and by the risk management function or by an independent risk control function established for the purpose of this provision. That risk control function shall be considered to be independent, regardless of whether the real-time monitoring is conducted by a member of the staff of the investment firm or by a third party, provided that that function is not hierarchically dependent on the trader and can challenge the trader as appropriate and necessary within the governance framework referred to in Article 1.

  3. (3)

    Staff members in charge of the real-time monitoring shall respond to operational and regulatory issues in a timely manner and shall initiate remedial action where necessary.

  4. (4)

    An investment firm shall ensure that the competent authority, the relevant trading venues and, where applicable, DEA providers, clearing members and central counterparties can at all times have access to staff members in charge of real-time monitoring. For that purpose, the investment firm shall identify and periodically test its communication channels, including its contact procedures for out of trading hours, to ensure that in an emergency the staff members with the adequate level of authority may reach each other in time.

  5. (5)

    The systems for real-time monitoring shall have real-time alerts to assist staff in identifying unanticipated trading activities undertaken by means of an algorithm. An investment firm shall have a process in place to take remedial action as soon as possible after an alert has been generated, including, where necessary, an orderly withdrawal from the market. Those systems shall also provide alerts in relation to algorithms and DEA orders triggering circuit breakers of a trading venue. Real-time alerts shall be generated within five seconds after the relevant event.

Article 17 Post-trade controls(Article 17(1) of Directive 2014/65/EU)

  1. (1)

    An investment firm shall continuously operate the post-trade controls that it has in place. Where a post-trade control is triggered, the investment firm shall undertake appropriate action, which may include adjusting or shutting down the relevant trading algorithm or trading system or an orderly withdrawal from the market.

  2. (2)

    Post-trade controls referred to in paragraph 1 shall include the continuous assessment and monitoring of market and credit risk of the investment firm in terms of effective exposure.

  3. (3)

    An investment firm shall keep records of trade and account information, which are complete, accurate and consistent. The investment firm shall reconcile its own electronic trading logs with information about its outstanding orders and risk exposures as provided by the trading venues to which it sends orders, by its brokers or DEA providers, by its clearing members or central counterparties and by its data providers or other relevant business partners. Reconciliation shall be made in real-time where the aforementioned market participants provide the information in real-time. An investment firm shall have the capability to calculate in real time its outstanding exposure and that of its traders and clients.

  4. (4)

    For derivatives, the post-trade controls referred to in paragraph 1 shall include controls regarding the maximum long and short and overall strategy positions, with trading limits to be set in units that are appropriate to the types of financial instruments involved.

  5. (5)

    Post-trade monitoring shall be undertaken by the traders responsible for the algorithm and the risk control function of the investment firm.

Article 18 Security and limits to access(Article 17(1) of Directive 2014/65/EU)

  1. (1)

    An investment firm shall implement an IT strategy with defined objectives and measures which:

    1. (a)

      is in compliance with the business and risk strategy of the investment firm and is adapted to its operational activities and the risks to which it is exposed;

    2. (b)

      is based on a reliable IT organisation, including service, production, and development;

    3. (c)

      complies with an effective IT security management.

  2. (2)

    An investment firm shall set up and maintain appropriate arrangements for physical and electronic security that minimise the risks of attacks against its information systems and that includes effective identity and access management. Those arrangements shall ensure the confidentiality, integrity, authenticity, and availability of data and the reliability and robustness of the investment firm's information systems.

  3. (3)

    An investment firm shall promptly inform the competent authority of any material breaches of its physical and electronic security measures. It shall provide an incident report to the competent authority, indicating the nature of the incident, the measures taken following the incident and the initiatives taken to avoid similar incidents from recurring.

  4. (4)

    An investment firm shall annually undertake penetration tests and vulnerability scans to simulate cyber-attacks.

  5. (5)

    An investment firm shall ensure that it is able to identify all persons who have critical user access rights to its IT systems. The investment firm shall restrict the number of such persons and shall monitor their access to IT systems to ensure traceability at all times.