
The gap in most algorithmic trading compliance programs is not the kill switch. It is what happens when a regulator asks you to reconstruct, decision by decision, what your algorithm was doing at 9:47 AM on a given morning. That question — not the trade itself — is what cost Citigroup $92 million across three jurisdictions in 2024.
Citi's traders could produce the orders. What they could not adequately reconstruct was the decision chain of the algorithm that executed them, or explain why its risk thresholds were set where they were. Germany's Federal Financial Supervisory Authority (BaFin) imposed EUR 12.975 million for failing to maintain effective systems and risk controls for algorithmic trading operations. Two British regulators added GBP 61.6 million for the same incident. The root cause was not a technical failure. It was a compliance architecture that could log the outcome but not explain the logic behind it.
What Examiners Actually Ask

A Financial Industry Regulatory Authority (FINRA) examiner arrives for a Rule 15c3-5 market access review. A Financial Conduct Authority (FCA) supervisor requests an RTS 6 self-assessment. The sequence that exposes most firms follows a predictable shape.
Inventory is the opening move. The FCA's August 2025 multi-firm review of 10 principal trading firms found that most had incomplete or out-of-date documentation — no clear record of who owns each algorithm, which markets it trades, or what risk parameters govern it. One class of omission stood out: IT outsourcing sections were missing from self-assessments at multiple firms, because compliance teams assumed vendor service-level agreements covered the obligation. They don't. The RTS 6 self-attestation requirement sits with the firm, not the vendor, and FCA examiners now test for this explicitly.
With the inventory in hand, examiners pivot to the harder question: not what the algorithm executed, but why the risk controls allowed it to proceed. Post-trade, examiners want to know whether the algorithm's thresholds were set at the right levels and whether the decision chain can be reconstructed. The Citigroup case turned precisely here — the firm could produce execution records but could not explain its threshold-setting logic in a way that satisfied regulators across three jurisdictions.
The third pressure point is the one most compliance architectures were never designed to answer: can the compliance function actually interrogate the algorithm's logic, or does it depend entirely on the engineering team to translate? The FCA flagged "variable technical knowledge in compliance" as a systemic weakness across the firms it reviewed. Hiring technically literate compliance staff is the market response, but people who understand both Commodity Futures Trading Commission (CFTC) market access rules and graph neural network (GNN) model architectures are rare enough that most mid-market firms cannot source them at a sustainable cost.
The structural alternative is building systems that translate algorithmic decision logic into audit-ready explanations that compliance teams can review and present to examiners without reading source code.
Most firms can produce the orders. The ones that fail examinations cannot explain why those orders were legal.
Alert Fatigue Is a Surveillance Architecture Problem

The trade surveillance market was built to solve a different problem: detecting manipulation. NICE Actimize, Nasdaq's surveillance platform, Eventus (Validus) — these systems flag spoofing, layering, wash trading, and cross-venue manipulation. For that purpose, they function.
What they also produce, at scale, is noise. According to an Eventus and Datos Insights survey of banks and broker-dealers, 70% report false positive rates above 25% in their trade surveillance systems. One alert in four, at minimum, demands review time and produces nothing actionable. Compliance teams call this alert fatigue, and it is not a staffing problem. It is a design artifact of pattern-matching against historical manipulation schemes in single-asset market data.
The manipulation patterns that matter in 2026 involve cross-asset contagion, multi-venue coordination, and the algorithmic amplification dynamics that produced the August 2024 flash crash. The Nikkei fell 12.4% in a single session — its biggest single-day drop since 1987. The S&P 500 fell roughly 3%. The Bank for International Settlements attributed the speed and magnitude to algorithmic strategies that had built up correlated positions during a prolonged low-volatility period and unwound simultaneously when the Bank of Japan rate decision and U.S. jobs data arrived at once. No individual firm's kill switch mattered to the system-level dynamics.
A kill switch stops your algorithm. It does not stop your algorithm's contribution to a market-wide correlation that a dozen other algorithms are simultaneously amplifying.
Generative Adversarial Network (GAN)-based anomaly detection research published in 2025 demonstrates 94.7% accuracy at sub-3ms latency for novel manipulation pattern detection, processing up to 150,000 transactions per second. GNN-LSTM hybrid models for interbank risk contagion detection achieve meaningfully higher detection accuracy than conventional approaches and extend early warning lead times by 11.5 days, according to research published in Springer Nature and ACM. These architectures are in academic production; they are not yet standard in commercial surveillance platforms.
The SR 11-7 Gap No One Is Documenting

Model risk management in U.S. financial institutions runs on SR 11-7 — the 2011 Federal Reserve and OCC guidance covering validation, documentation, governance, and monitoring. For parametric models with deterministic logic and stable challenger alternatives, the framework holds.
It strains under modern AI architectures. The standard SR 11-7 challenger-model test requires comparing your primary model's outputs against an alternative model on the same inputs. When the primary model is a GNN processing counterparty relationship topology and the challenger is a logistic regression on historical price data, they cannot be validly compared — the challenger doesn't establish model validity; it establishes that two architecturally incompatible systems produce different numbers. GARP noted in February 2026 that SR 11-7 "remains one of the few stable reference points for model governance" while acknowledging that generative and agentic AI "break its assumptions by introducing opacity, stochasticity, and autonomy."
A challenger model that cannot answer the same question as the primary model does not establish validity. It confirms that the two architectures are different.
For firms building GNN-based contagion detection or agentic compliance monitoring, the practical path is extending SR 11-7 rather than replacing it: custom validation templates for graph-topology inputs, explainability requirements calibrated to what compliance teams can actually interrogate, documentation designed to answer the examiner question the firm hasn't yet received.
At Veriprajna's algorithmic trading compliance practice, this is where most engagements surface their first difficult conversation: the model the firm wants to deploy and the validation framework the compliance team can sign off on are not designed for each other.
What Enterprise Vendors Don't Solve for Mid-Market Firms

The top five trade surveillance vendors hold roughly 55-59% of a market valued between $1.3 billion and $3 billion today, projected to reach $4.2 to $9.3 billion by 2033. These platforms — NICE Actimize, Nasdaq's surveillance platform, FIS, and others — were built for Tier 1 institutions with compliance budgets in the hundreds of millions and dedicated technology teams managing multi-year implementations.
NICE Actimize and Nasdaq's platforms run $1 million to $5 million annually in licensing for a full deployment, before implementation, configuration, and ongoing customization. For mid-size broker-dealers and asset managers, that is not the surveillance line item — that is the compliance budget.
More fundamentally, the problems that most frequently produce examination findings at mid-market firms are not the detection problems these platforms solve. They are explainability gaps (compliance teams that cannot interrogate what the algorithm did), multi-regulatory mapping failures (coordinating SEC Rule 15c3-5 with MiFID II RTS 6 with EU AI Act with DORA with SEBI requirements simultaneously), and documentation lifecycle breakdowns (algorithm inventories that were current eighteen months ago and aren't). No enterprise surveillance platform at enterprise pricing closes these gaps for a mid-market compliance budget.
Three Deadlines Already in Motion

For firms with any EU market access, three regulatory timelines have moved from future to concurrent.
The Digital Operational Resilience Act (DORA) has been in force since January 2025. First Register of Information submissions to European Supervisory Authorities were due April 30, 2025. Information and communications technology (ICT) third-party providers operating under trading infrastructure now have ongoing resilience-testing and incident-reporting obligations. This is current state, not a horizon event.
By August 2, 2026, financial firms with EU exposure must have technical documentation, conformity assessments, CE marking, and EU database registration for AI systems classified as high-risk under Article 6 of the EU AI Act. February 2026 European Commission guidelines were expected to clarify whether algorithmic trading AI qualifies as high-risk. If the classification lands there, firms have roughly two quarters from this article's publication to have documentation and governance in place.
For any desk with Indian market exposure, the clock ran out in October 2025. The Securities and Exchange Board of India (SEBI)'s February 2025 directive required a unique Algo-ID per strategy, exchange approval before live deployment, static-IP authentication, kill-switch capability, and comprehensive order logging by October 1, 2025. Firms trading Indian markets without an algorithm inventory capable of generating Algo-ID applications per strategy are past the deadline.
No major vendor offers a unified compliance framework that maps controls across SEC Rule 15c3-5, MiFID II RTS 6, EU AI Act, DORA, and SEBI simultaneously. Mid-market firms managing this complexity are running parallel compliance processes per jurisdiction or accepting exposure in some.
The Compliance Intelligence Layer

What the examination gap actually requires is not a more sensitive surveillance platform. It is a compliance intelligence layer: decision-chain audit logs that reconstruct what an algorithm did and why, in language compliance staff can present to an examiner; multi-regulatory mapping that tracks a single control change across all five frameworks simultaneously; intelligent circuit breakers with graduated behavioral responses rather than binary position-limit halts; and GNN-based contagion monitoring that identifies correlated-position buildups before the flash-crash trigger arrives.
We built this system for the mid-market segment at Veriprajna. The architecture decisions came from understanding examination failures at the mechanism level — kill switches that don't halt fast enough because the latency between the order-generation thread and the risk gateway's circuit-breaker check exceeds the time to fill; RTS 6 self-assessments that omit IT outsourcing sections because compliance assumed the vendor SLA covered it; SR 11-7 model validation reports that reach an examiner with a highlighted gap because nobody built the GNN validation template before the examination was scheduled.
The compliance question is not whether your current system will detect the next manipulation attempt. It is whether, when an examiner asks you to reconstruct your algorithm's decision at 9:47 AM on a given morning, the answer takes thirty seconds or three months.
If your team is working through what an examination-ready compliance architecture looks like for a multi-jurisdictional algorithmic trading program, we'd like to understand the specific gaps you're navigating. The structural problems are consistent enough across mid-market firms that direct comparison tends to be useful.