
Citi's pre-trade controls blocked $255 billion of an erroneous order. The other $189 billion still reached the algorithm.
In May 2022 a trader meant to sell $58 million in equities and built a $444 billion basket. The controls caught most of it. But the algorithm sliced up what slipped through and pushed $1.4 billion into European markets before anyone hit cancel. Two years later the fine landed: ~$92 million across BaFin and UK regulators for one control failure.
Here is the part most firms miss. When the regulators investigated, the question was not "what happened." Citi could show the orders. The question was "why did your controls let $189 billion through" — and that is a question about reconstruction, not logging.
That is the shift across SEC Rule 15c3-5 reviews, MiFID II RTS 6 self-assessments, and the EU AI Act regime that hits high-risk financial AI in August 2026. Order logs are no longer audit evidence — an examiner now asks you to walk through what a specific algorithm did at a specific minute, and why. The FCA's 2025 review of ten principal trading firms found most could not even produce a current inventory of who owns each algorithm and what limits govern it.
Meanwhile surveillance drowns in noise: 70% of banks report false positive rates above 25%, burying real signal under alert fatigue.
Our take, from building these: the answer is not a bigger black box. It is an explainability-first layer where every algorithmic decision carries an auditable reasoning chain, and circuit breakers respond in graduated tiers — not the single on/off switch the Citi case proved insufficient.
Save this if you own algo controls at a mid-market bank or asset manager — enterprise vendors are priced for Tier 1, and the gap below them is where exam findings cluster.
When your last examiner asked you to reconstruct a specific algo decision — not just produce the log — could you? 👇
#AlgorithmicTrading #TradeSurveillance #RegTech #FinancialCompliance #ModelRiskManagement