What Can You Actually Test
The FCA's August 2025 review of algorithmic trading controls at ten principal firms found significant variation in compliance sophistication — but the structural problem is older than the review. Attestation requires a compliance officer to certify what an algorithm does when she cannot read the code, testing covers yesterday's scenarios, and surveillance measures what someone thought to calibrate. The FCA has named the gap; the attestation merely documents that the firm knows it exists.
The FCA published its review of algorithmic trading controls at ten principal trading firms on 21 August 2025, and it used attestations to make firms commit to progress. The review does not create new rules. It found shortcomings in governance, testing, deployment and market abuse surveillance. The occasion here is not the publication. The occasion is what the compliance officer at one of those ten firms is left holding: a board expectation that she can certify the algorithm does what the developer said it does, when she cannot read the code, the testing documentation covers scenarios from two years ago, and the algorithm traded in three new markets last month.
In major equity markets, approximately 60-75% of trading volume is executed algorithmically. Algorithmic trading firms are a major source of liquidity across actively traded markets and asset classes, and due to their large trading footprint and trading strategies they can have a significant impact on price formation. The compliance officer's job is to confirm the firm is not about to cause the next flash crash. The tools she has are: a self-assessment template designed by a law firm in 2019, the developer's word that the latest version is materially similar to the one tested in March, and a surveillance system that generates 300 alerts a week with no documented process for deciding which ones matter.
The FCA assessed ten proprietary trading firms' compliance with MiFID requirements on algorithmic trading control as set out in RTS 6. Most firms had a good understanding of their obligations under RTS 6, but there was significant variation in the sophistication of firms and their level of compliance. That variation is the entire problem. The regulation says the firm must have controls. It does not specify how technically fluent the person checking those controls must be, and a recurring theme was the limited technical understanding within some compliance teams, while in stronger firms compliance officers were able to explain the basic design and operation of algorithms and provide meaningful challenge.
Can you explain what the algorithm does?
Best practice includes technically proficient compliance staff who can review and challenge algorithmic trading processes, and clear inventories of who owned and was approved to operate each algorithm. That is the line in the FCA document. Translate it into Monday morning. The developer built a momentum strategy that trades European equities between 8:30 and 9:15. The compliance officer must confirm it will not breach position limits, manipulate the close, or ignore a circuit breaker. She asks the developer to walk her through the logic. He opens a Git repository with 14,000 lines of Python. She has a law degree and the CFA. She does not code.
The better firms solve this by hiring compliance officers who can read code, or by pairing the compliance function with a quantitative risk manager who can. Many firms demonstrated strong practices in maintaining algorithm inventories with detailed records outlining each algorithm's objective, ownership, market usage and associated risk parameters, but in some cases the algorithmic inventory did not specify the individuals who were approved to operate the algorithm. The inventory lists the algorithm. It does not list the implicit dependencies: the reference data feed it pulls, the latency assumption baked into the order routing, or the fact that it was tuned on a market regime that ended in Q1 2024.
The weaker firms document the intended behaviour in a Word file that lives in SharePoint and is updated twice a year. The algorithm changes every sprint. Governance arrangements had generally improved since the FCA's 2018 review, but quality remained uneven, with some firms relying on outdated documents or assessments that failed to cover crucial areas such as IT outsourcing and staff training. The compliance officer is measuring against a description that was accurate the day it was written and is now archaeological.
Did you test the failure modes?
Simulation testing was widely adopted, with firms using both theoretical and historical stress scenarios to assess algorithm behaviour under adverse conditions, though the sophistication and frequency of testing varied. Sophistication is carrying weight there that it cannot bear. The test suite runs every scenario the developer thought to write down. It does not run the scenario where the clearing house changes margin at 14:32 and the algorithm is holding 18,000 contracts it cannot roll because the liquidity disappeared.
Weaker programmes lacked breadth and documentation, or relied solely on vendor testing for third-party algorithms. The vendor tested the algorithm in their environment, with their data, against their synthetic order book. The firm is running it in production against Euronext at 47 microsecond latency with a different execution venue priority. The test the vendor ran is not the test the regulator wants to see.
The FCA encourages cross-asset testing where relevant, and controlled deployment typically used slow phased go-lives with small pilot trades. Small pilot trades confirm the algorithm can submit an order. They do not confirm what happens when it submits 6,000 orders in four seconds because a data feed hiccupped and it thought the market moved 11%. The failure mode the regulator cares about is the one you get no warning of, and the test that would surface it requires you to know which assumption in the code is wrong. The compliance officer does not know which assumption is in the code.
Who decided the alert threshold?
Surveillance systems were typically tailored to firms' trading profiles and supported by regular Market Abuse Risk Assessments, but some firms have not sufficiently updated their systems or formalised governance, leading to delays and resource pressures in alert investigation. The surveillance system flags unusual order-to-trade ratios, late-day momentum, spoofing patterns. It generates the alerts. Someone must decide what unusual means. If the threshold is too tight, compliance investigates 80 false positives a day and misses the real event because it is alert 81. If the threshold is too loose, the manipulative behaviour sits below the threshold and nobody flags it until the regulator calls.
All firms conducted regular reviews of the Market Abuse Risk Assessment, and many had customised their surveillance systems to the type of trading they carried out, with some scoping their systems to monitor activity across different asset classes and trading venues. Customised means the parameters were set by someone. That someone was either a quant who understood the trading strategy and built the surveillance logic around it, or a compliance officer who took the vendor default and added three thresholds recommended by external counsel. The measurement error is identical in both cases: the surveillance system measures what you thought to measure, and market abuse finds the edge you did not think to cover.
Some firms have not done enough to update or invest in their market surveillance systems to keep up with the nature, scale and complexity of their trading activities, and some firms do not have formalised procedures or governance structures to investigate market abuse alerts. No formalised procedures means the alert goes to someone's inbox, that person applies judgement, and the judgement is not written down. When the regulator reconstructs the event eight months later, the record shows the alert fired, the position was closed two hours later, and nobody documented why they concluded it was fine. The compliance officer certified the surveillance system was adequate. What she certified was that alerts were being generated. She could not certify they were being investigated correctly, because there is no correct that survives contact with novel behaviour.
What changed since the last deployment?
Most firms operated formal sign-off procedures and cautious rollouts of new algorithms, often using pilot trades before full deployment, but in some firms governance was undermined by out-of-date policies, unclear ownership of processes, or insufficient escalation of new market entries to senior management. Out-of-date policies are the structural norm. The policy was drafted for the firm as it was. The firm added a new desk, a new venue, a co-location agreement in Frankfurt and an intern who refactored the order router. The policy has a version number and a review date in 2027.
Documentary gaps arose where deployment ownership and procedures were unclear. The algorithm went live. Someone approved it. That someone is not named in the log, because the approval was verbal in the 8am call and the compliance officer wrote "approved per discussion" in the tracker. When the regulator asks who validated that the new market's tick size would not break the pricing logic, the answer is nobody validated it explicitly, it was assumed to be covered by the testing that was done in April.
Ownership of pre- and post-trade controls is sometimes poorly defined. The pre-trade control is a position limit configured in the risk management system. It was set by the CRO in 2023. The algorithm now trades four additional instruments. Nobody updated the limit because nobody owns the end-to-end view that connects the limit, the algorithm's scope, and the compliance sign-off.
What does the attestation actually commit you to?
The regulator has already acted on the findings with attestations, and the FCA will continue to assess firms' algorithmic trading controls as part of its supervisory role and has already used attestation to ensure progress. An attestation is a letter the firm sends to the FCA confirming it has addressed the findings. The compliance officer drafts it. The CEO signs it. The attestation does not say the algorithm is safe. It says the firm has a control framework that meets RTS 6, and that framework has been reviewed and updated in line with the FCA's observations.
The regulator has already acted on the findings with attestations, and further supervisory engagement is inevitable; for firms engaged in algorithmic trading the message is clear: be ready to demonstrate robust controls, up-to-date documentation, and active governance from the board down. Demonstrate is the load-bearing word. The compliance officer must produce evidence that the board was briefed, the testing was done, the surveillance is calibrated. The evidence is: a slide deck from the July board meeting with two minutes of discussion noted in the pack, a test summary spreadsheet that says "Pass" in 87 cells, and a surveillance configuration file nobody in compliance can interpret. She signs the attestation because the alternative is telling the CEO that the firm cannot actually prove its algorithms are under control, which will delay trading in three markets and cost the firm $4 million a month in lost opportunity.
Firms should tighten trade control governance, calibrate by strategy and asset class, enforce at the internal gateway, and ensure compliance visibility over thresholds, overrides and breaches, and strengthen market abuse surveillance by aligning systems to Market Abuse Risk Assessment, documenting alert and logic calibration, and formalising investigation and escalation playbooks. That is what the FCA wants. What the firm has is a compliance officer who can write the policy that says those things will happen, but who cannot independently verify that they did happen, because verification requires the technical fluency to read the commit log, rerun the test, and check whether the surveillance query matches the risk the policy names. Some firms have that fluency in compliance. There was significant variation in the sophistication of firms and their level of compliance. Most do not.
The job is to measure what the algorithm does. The tool is a conversation with the person who built it, a policy document that describes what it should do, and a testing report that confirms it did what it should do in the scenarios that were tested. The measurement is accurate only if the developer described it honestly, the policy anticipated the behaviour that matters, and the test covered the scenario that breaks. The compliance officer signs the attestation. The algorithm trades. The measure is not the algorithm. The measure is confidence in the governance that wraps it, and that confidence is a second-order construct that depends on people she does not control, applying judgement she cannot verify, in code she cannot read. The FCA has identified the gap. The attestation does not close it. It documents that the firm knows the gap exists.
Tarry Singh is the founder and CEO of Real AI (realai.eu), an enterprise AI advisory and deployment firm working with global enterprises on production agent systems, model risk, and AI sovereignty strategy. He also leads Earthscan (earthscan.io) for Energy AI, and is a founding contributor to the EU-funded HCAIM and PANORAIMA programmes for responsible AI education across European universities. He writes at tarrysingh.com.