Regulasi Algorithmic Trading - Internasional

Haikal Rahman

 

Electronic trading on a large scale started in 1971 with the creation of the National Association of Securities Dealers Automated Quotations (NASDAQ) in New York, the first electronic trading venue.1 This allowed trading to be conducted completely electronically on a whole venue for the first time2 and since then, the use of computers in the financial industry has risen progressively. Allocating tasks to computers instead of human traders has provided new abilities to the market participants because algorithms on computers are able to execute more trades more quickly than human traders. This has led to an increase in total trades and reduced the costs of trading.3 Smart algorithms are able to analyse data streams at great speed, giving their users an advantage over competitors using slower algorithms, or human traders, enabling them to discover arbitrage opportunities between markets.4 Today, computers and smart algorithms are able to execute trades on their own, reducing the need for humans, whose function now is mainly to programme the algorithms (i.e. the code) and supervise their application.5

The amount of algorithmic trading has risen continuously year by year, to the extent that 80% of the daily trading volume in the United States was executed by machines in 2018.6 This growth in the algorithmic trading market is expected to continue over the next few years7, highlighting its importance in modern capital markets.

Descriptions and Legal Definitions

Algorithmic trading can be broadly described as a trading method in which computers decide what to buy or sell in financial markets.8  A basic feature of algorithmic trading is the automation of trading strategies, a shift away from humans making every single decision to sophisticated computers that are increasingly independent from humans.9 This study focuses on algorithmic trading used on traditional trading venues and excludes algorithmic trading on newly evolving trading venues, such as those based on blockchain technologies.

The exact definitions of algorithmic trading vary slightly between different jurisdictions and their respective existing regulatory frameworks. The EU defines algorithmic trading in the Markets in Financial Instruments Directive II (MiFID II) as

‘trading in financial instruments where a computer algorithm automatically determines individual parameters of orders such as whether to initiate the order, the timing, price or quantity of the order or how to manage the order after its submission, with limited or no human intervention, and does not include any system that is only used for the purpose of routing orders to one or more trading venues or for the processing of orders involving no determination of any trading parameters or for the confirmation of orders or the post-trade processing of executed transactions’.10

Hence, a computer algorithm, without or with only limited human intervention, automatically determines the parameters of the trade orders to be categorised as algorithmic trading. This definition is also applied by the UK financial regulator, the Financial Conduct Authority (FCA).11 Even though European law is no longer directly applicable in the UK, the FCA has maintained the definition introduced by MiFID II in its Handbook.12 In the US, the Securities and Exchange Commission (SEC) and the Financial Industry Regulatory Authority (FINRA) define algorithmic trading strategies as an ‘Automated system that generates or routes orders or order related messages – such as routes or cancellations – but does not include an automated system that solely routes orders received in their entirety to a market center’.13 Although the wording varies between the EU and US definitions, both jurisdictions understand algorithmic trading as an automated order execution method where human intervention after the development phase is no longer required.14

Functions

There are different ways in which algorithmic trading is conducted in financial markets. Many different strategies for automated order execution have been developed over time. The categorisation of the algorithms is based mainly on their respective functions or behaviour of the strategies used.15 There are three common strategies in agent trading. First, impact-driven algorithms are used to minimise the effect of trading on asset prices. Second, cost-driven algorithms are used to adapt their trading to market conditions so as to trade more opportunistically when the market turns in their favour.16 Third, newsreader algorithms, a more recent type of algorithm, can analyse the information provided to them by various news sources and make investment decisions based on the latest news.17 On the proprietary trading side, common algorithmic trading strategies are statistical arbitrage18 and market making.19 Market makers have been an important part of the financial markets for decades, formerly conducted by humans and now by algorithms. They help ensure that the markets work properly by standing ready to trade with those participants who want to sell or buy stocks immediately, thereby creating liquidity in the market.20

High-frequency trading (HFT), which has become a famous term due to extensive news coverage after events such as the flash crash,21 is also a type of algorithmic trading.22 HFT represents a subset of algorithmic trading that can be distinguished from other types of algorithmic trading based on the speed of execution.23 The EU legislator has defined high- frequency algorithmic trading technique as ‘an algorithmic trading technique characterised by:

(a) infrastructure intended to minimise network and other types of latencies, including at least one of the following facilities for algorithmic order entry: co-location, proximity hosting or high-speed direct electronic access; (b) system-determination of order initiation, generation, routing or execution without human intervention for individual trades or orders; and (c) high message intraday rates which constitute orders, quotes or cancellations’.24 Hence, all HFT traders are algorithmic traders, but not all algorithmic traders are HFT traders.

Internal Governance of Algorithms

The complexity of algorithms today makes them prone to flaws that can cause severe damage given the growing sizes of orders that are executed using such algorithms. The Knight Capital Group, for example, used an algorithm to execute a rather large series of orders. However, instead of selling the shares over a couple of days to minimise the market impact, the algorithm was erroneous, causing all the shares to be sold in less than an hour.37 As a result, millions of shares were immediately transferred unintentionally. Reversing all the errant trades cost the firm $440 million, four times their annual profit, and almost led the firm to bankruptcy.38

The risks associated with algorithms do not only affect the firm that uses them but can have significant negative impacts on the whole market and even pose a systemic risk. These risks became obvious during the flash crash, which was not caused by a single algorithmic trader, but the algorithms of multiple traders, especially HFT algorithms. HFT and non-HFT algorithms interacted under the stressed market conditions with each other and pushed the falling prices further.39 The involvement of algorithmic trading strategies and their interconnectedness also increases the likelihood of the transmission of shocks across trading venues.40

These incidents are only some examples that show the risk of algorithmic trading if the algorithms used are flawed or not well-designed. They also highlight the importance of a thorough check of each algorithm by users and platform providers before they are implemented in the market. These risks have been generally recognised by regulators, and the regulatory requirements are to contain and mitigate risks; such requirements include pre-trade risk control measures and the involvement of senior management to ensure safe deployment of algorithms.

European Union Regulation

Internal risk management: Algorithms, systems, and inter-systems testing

the European regulation for internal risk control measures of algorithmic traders is examined, as it represents the common underlying regulatory basis for the individual regulatory systems of member states. Under MiFID II and its delegated provisions, the EU introduced comprehensive requirements to deal with the risks of algorithmic trading for credit institutions, investment firms, and trading venues.41 For investment firms that engage in algorithmic trading and fall under the purview of Article 17 MiFID II, the European Securities and Markets Authority (ESMA) has developed regulatory technical standards in Regulatory

Technical Standard (RTS) 6, 42 regarding the organisational requirements of the investment firms in accordance with Article 17 (7) MiFID II.43

The basic framework for algorithmic trading is laid out in MiFID II itself, and the detailed requirements that will apply were adopted by the European Commission as Draft Regulations based on the proposals of the European regulator ESMA in RTS 6.44

In the recitals of the delegated regulation RTS 6, the delegated regulation sets out that systems and risk controls by firms engaging in algorithmic trading should be efficient, resilient, and have adequate capacity with regard to the individual business model of the firm, while addressing all risks potentially affecting the core elements of an algorithmic trading system.45 Internal risk management within firms that want to apply algorithmic trading strategies plays an important role in the regulation. Chapter II of RTS 6 addresses the resilience of trading systems and provides detailed regulations for the testing and deployment of trading algorithms in the first section.46

Investment firms conducting algorithmic trading strategies must establish clearly delineated methodologies for the development and testing of trading algorithms, algorithmic trading systems, or algorithmic trading strategies according to Article 5 (1) of RTS 6.47 These methodologies address the design of the algorithmic trading system, its performance, recordkeeping, and approval. The methodologies set out the allocation of responsibilities within the firm for the algorithms applied.48 The methodology system, as established under RTS 6, ensures that the firm’s algorithmic trading system does not behave in an unintended manner and complies with the regulatory obligations of the investment firms under the European regulation as well as with the rules and systems of the trading venues the firm accesses.49 This works well for common algorithmic trading systems, which only execute pre- programmed trades. However, difficulties arise for artificial intelligence (AI)-based self- learning algorithms that can adapt themselves using the data provided.

The requirement foralgorithms not to behave in an unintended manner, as provided by RTS 6, seems to limit the potential of self-learning algorithms and forces their developers to only apply completely predictable AI.50 Although the current regulation limits the ability of self-learning algorithms to adapt themselves, it allows alterations of the algorithms up to a ‘substantial change’ in the algorithm before additional tests are required.51 What exactly a substantial change is, however, is not defined by the legislator and requires a definition by the courts. National regulators have recognised the complex task which the use of AI in financial markets creates and are working on solutions that provide more clarity for the firms developing such methods.52 In a study on big data and AI, BaFin listed some possible governance adaptations to keep up with technological development.53 Facing increasing automation, they see, for example, a need to ensure human responsibility, and they consider complementing existing reporting requirements with a check of the results an algorithm calculates.54

The methodologies also aim to prevent the algorithmic trading system from contributing to disorderly conduct and ensuring that the system continues to work efficiently even under stressed market conditions.55 While all algorithmic trading strategies require methodologies for the development and testing of algorithms, the specified criteria of Article 5 (2)–(5) of RTS 6 only apply to trading algorithms that lead to the execution of orders.56 Order executing algorithms are subject to stricter regulation because orders are executed on the market, and therefore, the execution of an order can have an immediate impact on the market.

To ensure compliance with the aims of the methodology, as set out above, investment firms must test their algorithms or algorithmic trading systems.57 These tests must be conducted in an environment that is separated from the environment where they usually operate effectively.58 Therefore, the pre-trade testing of the algorithms must not be conducted on the market, but in a special testing environment provided either by the trading firm itself or by a trading venue or a market access provider.59

Before algorithmic trading strategies can be deployed, they must undergo performance testing to verify that the basic elements of the algorithmic trading system operate correctly and in accordance with the requirements of the trading venue or the direct market access provider.60 Therefore, the algorithmic trading system has to verify that it interacts with the trading venues matching logic as intended and adequately processes the data flows. This verification is necessary where the firm accesses the trading venue as a member, connects to that trading venue via sponsored access for the first time, and where the trading venue materially changes its system or before the algorithmic trader deploys or materially updates its algorithmic trading system.61 However, the tests are conducted without the involvement of supervisory authorities.62 Market participants are free to decide on which testing environment their algorithms will be tested and to certify the performance of the test themselves.63 One could argue that this shifts the responsibility of supervisory authorities to market participants who conduct the tests. However, full scrutiny of every algorithm by regulators is not possible because of their limited resources and might impede innovation.64 Rather, supervisory authorities should focus on risk-based supervision of selected areas of algorithmic use.65

Pre-trade control measures

To reduce the risks of algorithmic trading activity, European regulations use a set of pre-trade controls on order entry to establish a suite of risk controls.66 Article 15 of RTS 6 establishes the regulatory basis for pre-trade internal control mechanisms. Investment firms are required to set price collars, which block orders that do not fit within certain price parameters set individually for different financial instruments.67 RTS 6 further requires firms to install maximum order values and volumes that shall prevent uncommonly large order values or sizes from entering the order book in the first place and help prevent incidents such as the one involving Knight Capital Group from causing a significant financial loss.68

In addition to setting the limits on the order values and volumes, pre-trade checks also need to have in place repeated automated execution throttles to control the number of times a single algorithm has been applied.69 After reaching a pre-defined number of trades, the execution throttle disables the application of this algorithm until a human staff member evaluates the situation and where appropriate re-enables the algorithm.70

Appropriate risk level and assessment

One of the most important internal risk management tools required by RTS 6 is market and credit risk limits. Considering a firm’s capital base, trading strategies, experience, and risk tolerance, the firm will set specific market and credit risk limits which can be adjusted to changing circumstances.71 With such limits in place, each firm can individually decide how much risk it wishes to take and ensure that the algorithms applied will not exceed the prior agreed level of risk.

Human oversight and intervention

It is possible that any of the aforementioned pre-trade checks blocks an order for various reasons, yet the firm wants to submit it for any other reason. Therefore, firms are required to have arrangements in place that allow them, after a verification process and authorisation by a human trader, to submit previously blocked trades on a temporary basis in exceptional circumstances.72 Finally, all firms engaging in algorithmic trading activities must be able to cancel any or all of its submitted but unexecuted orders to any trading venue they trade on.73 This so called ‘kill functionality’ protects the integrity of the market by preventing orders that were recognised as flawed from being executed.74 Even with all these pre-trade controls in place (from pre-trade limits to thorough testing of the algorithm and its compliance with the trading environment to kill functionalities), the final decision on whether an algorithm will be deployed is made by a human trader. Before the algorithm or trading strategy is deployed on the market or an existing algorithm is substantially updated, a person designated by the senior management of the firm has to authorise the release of the algorithm to the market.75 This rule ensures that human oversight marks the final step of the automated deployment process.

Direct access

To ensure an overarching regulation for effective internal checks, direct electronic access (DEA) providers are also addressed by the MiFID II regulation. DEA providers enable their clients to participate in financial markets without being dependent on investment firms as their intermediaries.76 This gives the clients of the providers more freedom to apply their individual trading strategies. However, this can increase the risks because clients can use algorithms they have developed without the experience of intermediaries.77 To reduce this risk, Article 20 of RTS 6 requires that DEA providers ensure the MiFID II regulation is complied with by their clients.78 Therefore, all client orders shall pass through the control mechanisms of the DEA provider, who must set the control parameters and remains responsible for the effectiveness of the controls.79 Hence, direct access is only possible through the DEA provider’s regulatory mechanism, and their client’s flawed algorithms can be detected before they affect the market.

The regulation provided by MiFID II, especially RTS 6, establishes a regime that regulates internal checking and pre-trade safeguards for algorithmic trading. However, how well does this regulatory approach for internal checks of algorithms chosen by the European regulators fit their overall regulatory objectives? MiFID II aims to establish a safer, sounder, more transparent, and more responsible financial system that works for the economy and society as a whole.80

The EU views algorithmic trading as a trading strategy that contains many risks for individuals using it as well as for the market as a whole.81 However, because at the same time, the EU recognises the advantages that algorithmic trading brings to markets, market participants, and the economy, a complete ban on algorithmic trading was not favoured.82 The EU maintains a certain neutrality towards algorithmic trading and neither promotes nor prohibits it. Rather, the EU recognises the inherent risks of algorithmic trading and decides that these risks should be effectively regulated and mitigated by a combination of measures addressing trading firms, direct access providers, and trading venues.83

MiFID II tackles the special risks imposed by algorithmic trading on the pre-trade level by setting pre-trade limits, establishing a testing environment, and requiring kill functionalities. All these measures contribute to a safer financial system by reducing the risks originating from algorithmic trading systems. By making DEA providers responsible for the effective control of their clients’ trading activity, these providers cannot easily excuse themselves anymore if their clients use malfunctioning algorithms. Thus, MiFID II brings more responsibility to the internal, pre-trade part of algorithmic trading. The MiFID II regulation on algorithmic trading increased overall market safety and contributed to a sound financial system. However, the enforcement powers conferred on national supervisory authorities are not always used.84 Considering the testing requirement, the national authorities are, in principle, able to demand regular details of the testing conducted by firms as well as a description of firms’ algorithmic trading strategies and details of trading parameters.85 In a consultation paper, ESMA revealed that only a few national regulators use this power on a regular basis.86

United Kingdom Regulation

After the end of the transition period on 31 December 2020, EU legislation was no longer directly applicable in the UK. Therefore, the UK has amended some parts of EU legislation and regulatory requirements, including directly applicable EU legislation, such as MiFID II, so that they can still be applied in the UK in a process called ‘Onshoring’.87 In this way, a major part of EU regulation will still be applied. For other areas where the regulation has changed, the FCA has applied various transitional provisions and regimes88. One of the most notable transitional provisions is called Temporary Transitional Power (TTP), which was given to the FCA by the Treasury.89 This transitional provision requires firms and other regulated persons to immediately adjust to the regulatory changes, but rather allows them to adopt most of the new requirements by 31 March 2022 and to comply until then with the regulatory obligations that have previously been in place. Some requirements however, have to be adopted immediately. Notable for algorithmic traders are especially changes in the MiFID II transaction reporting and the EMIR reporting obligations that establish reporting requirements to UK authorities instead of European authorities.90

Inventories and senior management regime

As a former member state of the EU, the UK has implemented MiFID II and its regulatory framework through a combination of primary and secondary legislation by HM Treasury and regulatory rules provided by the FCA and the Prudential Regulation Authority (PRA).91 From the implementation day onwards, the MiFID II standard of compliance has been enforced by the UK regulators.92

The FCA has identified five key areas of focus: defining algorithmic trading, development and testing, risk controls, governance and oversight, and market conduct.93 Split into these five areas, the FCA implements the regulatory requirements set by MiFID II and RTS 6 for algorithmic trading.94 While mostly requiring identical risk mitigation settings as laid out in RTS 6, UK regulators go beyond the minimum requirements of MiFID II and RTS 6 in the FCA’s statements of good practice and the PRA’s proposed supervisory statement.95 A point where they go beyond the minimum requirements can be seen in the provisions for an algorithm inventory.96 It is good practice to retain a detailed inventory for firms across the business, clearly documenting the different types of algorithms and trading strategies that firms apply as well as their respective owners and those who have approved them to operate.97 For an inventory to be considered as good practice, it has to include the technical details of the coding protocols, the relevant market information, and a comprehensive list of all the risk controls that apply to the individual trading strategy.98 These detailed inventories shall provide information for senior management to ensure that the complex algorithmic trading activities of firms are identified and appropriately managed.99

The FCA’s good practice recommendations also propose further measures for the development and testing framework. The development and testing procedures should be supported by a person appointed as a project leader to oversee the entire process. Independent checks should be established after the separate phases. Furthermore, a thorough due diligence performed to effectively recognise and mitigate conduct risks should be recorded for a review during the approval process.100

Another area where UK regulators go beyond European requirements focuses on the responsibility of senior management. The PRA expects the firm’s management body to understand its algorithmic trading activity and risk control.101 As part of the internal risk mitigation, the management body should also ensure that traders understand the essential characteristics of algorithmic trading, have controlled access to algorithms, and ensure general oversight of the use of algorithms.102 Furthermore, the management body has to identify senior management functions related to algorithmic trading, to ensure that firms correctly allocate responsibility to individuals who have the greatest potential to cause harm in accordance with the Senior Managers Regime.103

These requirements by the Senior Manager and Certification Regime have led to higher professional standards as well as to an overall positive change in behaviour in the industry since its implementation in 2016.104 However, there have been only 34 investigations since 2016, of which 11 were closed without any further action. Such an investigation typically takes two to three years to be concluded.105 Enforcement under the Senior Manager and Certification Regime takes rather long and is rare. Hence, the Senior Manager Regime is not well suited for the fast-evolving algorithmic trading market.

United States Regulation

The regulatory system in the US differs from systems in Europe and the UK. At the federal level, there are two main regulators for the securities markets: the Securities and Exchange Commission (SEC) and the Commodity Futures Trading Commission (CFTC).106 While the SEC governs a major part of the securities markets, the CFTC regulates the commodities market and contracts for future delivery, to which securities can be subject.107 Concurrently, there is a self-regulatory organisation overseen by the SEC that acts as the front-line regulator for broker-dealers— the Financial Industry Regulatory Authority (FINRA).108 There are different rules for the internal pre-trade testing requirements of algorithmic traders, depending on which regulator has jurisdiction over the firm. We first discuss SEC’s regulation, followed by the proposed CFTC regulation for algorithmic trading.

Systems

The SEC adopted Regulation Systems Compliance and Integrity (Reg SCI) to strengthen the technology infrastructure of US securities markets.109 Reg SCI applies to certain selected entities, so-called SCI entities, such as the national securities exchanges, higher volume equity ATS, and FINRA.110 Regulation SCI mostly sets compliance obligations for the security and integrity of the systems used by the SCI entities to ensure that the systems in use and the personnel using them are able to maintain operational capabilities and promote fair and orderly markets.111 The entities have to monitor their technological standards and report any disruptive behaviour immediately to the SEC to provide sufficient oversight of the markets.112

Intermediaries with market access

The SEC Market Access Rule requires broker-dealers with market access (to trading in securities on an exchange or alternative trading system) or providing market access to their customers to establish a system of risk management.113 Regarding the internal scrutiny of algorithms, the market access rule requires firms to establish reasonable pre-trade financial thresholds for market orders and tailor erroneous or duplicate orders.114 Therefore, firms are required to implement reasonable measures to ensure that their orders are stopped from entering the market if they exceed the thresholds or are erroneous.115 Furthermore, reasonably designed measures shall prevent orders not in compliance with the regulatory requirements on the pre-trade level and orders that the trader is restricted from trading from being placed.116 These measures must be under the exclusive control of broker-dealers and must be regularly reviewed to check their effectiveness.117

The reason for concern is the requirement that all measures have to be reasonably designed. This means that firms are not required to always take the best possible measures to prevent harm, but only those measures that do not exceed the cost of the harm to itself.118 This leaves the individual firm to assess the potential risk originating from their algorithms and decide what internal measures must be taken to prevent the risk from occurring. On the one hand, the costs for firms to implement the regulation can be reduced significantly. Smaller firms that use rather simple algorithms do not have to establish the same complex governance measures as market participants using highly complex algorithms. However, on the other hand, this approach does not address the negative externalities surrounding algorithmic trading environments where even small errors can result in significant damages in these fast, highly interdependent markets.119

In addition to the SEC rules, any firm that intends to conduct securities transactions and business with the investing public must be registered with FINRA and is subject to FINRA supervision.120 Any employee of a FINRA member firm, who is primarily responsible for the design, development, or modification of algorithmic trading strategies or their day-to-day supervision, must pass a qualification examination and register with FINRA as a security trader.121

Individual certification

The other main federal regulator, the CFTC, proposed a comprehensive regulation for algorithmic trading in 2015, the Regulation Automated Trading (Reg AT). However, this has not been implemented.122 Reg AT focuses on ‘AT Persons’ and makes market participants subject to additional regulatory requirements.123 At the internal risk management level, Reg AT would require pre-trade risk controls, such as maximum message frequency and maximum execution frequency per unit time, as well as order price parameters and limits.124 Furthermore, all systems would need to have the ability to immediately disengage trading or cancel orders, similar to a kill functionality in MiFID.125 Similar to the MiFID II requirements, Reg AT would also require a thorough testing of the algorithms in a separate environment before they are released and implemented in the market.126

The SEC has declared its mission to protect investors; maintain fair, orderly, and efficient markets; and facilitate capital formation.127 Compared to the primary objective of MiFID II, the SEC’s aims are more focused on maintaining an open, smoothly working market, while the EU emphasises the security of the markets. The SEC, as well as the EU, has recognised the new risks associated with the technological development of algorithmic trading strategies, but given the benefits of this technique, a thorough regulation is preferred over a ban.128

Issues for the Regulation Caused by Machine Learning

The algorithms applied by financial firms are continuously evolving and becoming more sophisticated, profitable, and independent. A growing number of algorithms rely on machine- learning strategies to achieve better automated decisions.129 Machine learning refers to computer programmes that are able to learn from their experience and improve their performance by changing their behaviour based on previous practice.130 Such learning algorithms can be beneficial for firms that use them; however, they pose new challenges for

The reason for concern is the requirement that all measures have to be reasonably designed. This means that firms are not required to always take the best possible measures to prevent harm, but only those measures that do not exceed the cost of the harm to itself.118 This leaves the individual firm to assess the potential risk originating from their algorithms and decide what internal measures must be taken to prevent the risk from occurring. On the one hand, the costs for firms to implement the regulation can be reduced significantly. Smaller firms that use rather simple algorithms do not have to establish the same complex governance measures as market participants using highly complex algorithms. However, on the other hand, this approach does not address the negative externalities surrounding algorithmic trading environments where even small errors can result in significant damages in these fast, highly interdependent markets.119

In addition to the SEC rules, any firm that intends to conduct securities transactions and business with the investing public must be registered with FINRA and is subject to FINRA supervision.120 Any employee of a FINRA member firm, who is primarily responsible for the regulators. The major problem with these algorithms for regulators coincides with their largest benefit for firms and their independence.131 With increasing automation, operators would no longer have absolute control over the operations of the technologies used, owing to their self- improvement. The technologies can become unpredictable, and the increased model complexity makes it harder for humans to understand how they reach their decisions.132 An algorithm that can amend itself might become flawed without the developers’ knowledge after its initial pre-trade check, raising the question of allocating responsibility and causing severe damage to the firm, or in the worst case, the market as a whole.133

Regulators have not yet addressed the topic by issuing specific instructions to financial institutions applying such machine learning algorithms.134 The European Commission has issued a white paper on artificial intelligence with suggestions for mandatory requirements to mitigate the new risks of machine learning and other forms of artificial intelligence (AI).135 Following a risk-based approach, the paper makes suggestions for mandatory requirements for training algorithms with data and human oversight. However, since financial services are not classified as a high-risk sector according to the paper, the extent to which the proposed new rules should be applied remains unclear.136

In the US, the situation is not very different from the government’s focus on ensuring that regulation is not becoming a hindrance to AI development. There are only a few guidelines issued by regulators. The main responsibility for AI and machine learning risk management has been allocated to financial firms and technology companies.137 With a lack of clear legislative action on both sides of the Atlantic, the additional risks of machine learning strategies are currently not well addressed by regulators. Even though it might be an option for firms to restrict the use of machine learning models to low-risk applications, as some firms currently do, it is not the best measure to take since, as in algorithmic trading, the risks of the technology have various advantages for the users and possibly the whole market.138 A comprehensive regulatory approach is required for the financial services sector that specifically addresses the risks of such complex algorithms with improved oversight, adjusted responsibility allocation, and improved pre-trade testing standards. It is recommended that a global regulatory sandbox environment be created to test the algorithms.139

Direct Market Interventions

This section focuses on possible interventions from the state or trading venue to mitigate the risks of algorithmic trading. State interventions to regulate trading activity are not new phenomena. The first state intervention dates back to the earliest days of trading; the first ban on naked short selling was in 1610 in the Netherlands.140 While back then a simple prohibition was sufficient to address the problem, the development and increasing automation of the financial markets have made a diversified and fast-reacting system of interventions necessary. Because modern algorithms trade at a tremendously fast pace, in the worst-case scenario, markets could crash in a few seconds without immediate proper interventions. Besides a quick reaction, the intervening measure must also create a way back to regular trading once the markets have calmed, without causing too much volatility. Each jurisdiction follows its own way of addressing these issues. The following section shows individual regulatory approaches to using circuit breakers as a direct market intervention method.

Circuit Breaker

Initially adopted as a response to the 1987 market crash in the US, circuit breakers are market intervening mechanisms that monitor the market continuously. They can partially or wholly impede security trading, or the entire market, once a certain threshold is crossed.141 The term circuit breaker originates from electrical engineering, where a circuit breaker is a mechanism that reduces electrical activity in excess of a system’s designed capacity. The activation level is the anticipated capability of the system.142 Algorithmic trading can increase the risk of a highly volatile market during which the price is not determined by demand and supply but by unintentionally interacting algorithms or other excesses of stressed markets.143 Circuit breakers attempt to re-establish price efficiency by stopping trading and providing market participants the opportunity to become aware of the situation and respond to significant price movements.144 There are two main categories of circuit breakers: trading halts and price limits. Trading halts stop trading completely on a venue for a predefined time. Price limits require trade to be within a defined price range and reject any trade outside this range.145 The thresholds which trigger the circuit breaker are either static, referring to the closing price of the previous trading day, or dynamic, using the price of the last transaction as a reference.146 Since volatility can erupt during continuous trading phases as well as during a call auction, circuit breaking mechanisms should react in both situations.147 During the auction phase, a triggered circuit breaker should extend the auction phase to allow the market to cool down. During continuous trading, a circuit breaker should either stop trading for a certain period or switch the continuous trading phase to a call auction phase.148

Most trading venues rely on circuit breakers as a measure to protect investors and increase the integrity and stability of the market.149 We next assess the EU, UK, and US regulations regarding circuit breakers.

Circuit breaker in the European Union

Article 48 (5) MiFID II requires regulated markets in member states to have systems in place that allow them to temporarily halt or constrain trading in case of significant price movements during a short period of time.150 ESMA considers the following types of circuit breakers as trading halts under Article 48 (5) MiFID II: Mechanisms that stop trading on a certain security for a predefined period of time and mechanisms that switch trading from continuous trading to a call auction. Both types are applied during continuous trading phases and can extend the time frame during a call auction phase.151 The parameters for these trading halts should be appropriately calibrated with regard to the different classes of securities and market models.152 To ensure common standards, Article 48 (13) MiFID II empowered ESMA to develop guidelines on the calibration of trading halts for trading venues to take into consideration when calibrating their systems.153

In their guidelines, ESMA requires trading venues to calibrate their circuit breakers in accordance with a pre-defined, statistically supported methodology which takes certain elements into account.154 Among these elements that should be taken into account are the nature of the financial instrument, its liquidity and volatility profile, based on statistical studies of previous liquidity and volatility, as well as potential order imbalances that would require a re-calibration of the circuit breaker.155

The circuit breakers applied to EU markets are only stock-specific and interrupt trading for only one security where the thresholds are triggered. In other countries outside of the EU, market-wide circuit breakers are in use which stop trading on whole markets or segments if an index price triggers a threshold.156

However, the ESMA guidelines are not too detailed and leave some space for member states and their trading venues to design volatility safeguards. That is why there is strong heterogeneity, and the circuit breakers and price collars applied across the EU are very different and not harmonised.157 A good example of this is the different duration of a trading halt which can be set by each venue independently. It varies from less than a minute up to 50 minutes in some venues, by an average of 4 minutes across all venues.158 The fact that each trading venue has its own approach towards mitigating volatility can also be seen in the fact that only about half of the EU venues disclose their triggering thresholds, while the other half prefers to keep them under closure.159

Although the circuit breakers on individual trading venues differ in practice and can have different impacts on trading, the mechanisms are not fundamentally different from a calibration perspective.160 The mechanisms introduced on the venues apply similar principles to their calibration following the flexible approach designed by the framework.161 This flexible approach allows each venue to design circuit breakers that best fit their needs while ensuring that common principles are applied. By requiring all venues to implement mechanisms that allow them to stop trading following basic guidelines for their calibration, while leaving the details to the individual venue, the EU regulations ensure a common level of security against algorithmic trading risks that is most effective because it is suitable for the unique characteristics of each venue.

Circuit breaker in the United Kingdom

The UK had already implemented mechanisms to halt trading before MiFID II required such safeguards and only had to slightly adapt the existing circuit breakers to the new EU-wide requirements and basic guidelines.162 The London Stock Exchange (LSE), the major UK trading venue, operates continuously monitoring mechanisms and circuit breakers. The objective is to ensure that trading on the markets is operated fairly and the risks of algorithmic trading are mitigated.163 The LSE uses stock-specific circuit breakers rather than market-wide circuit breakers or price limits.164 The circuit breakers on the LSE can be triggered by static and dynamic reference prices which are determined at the market sector level and at values that take into account the liquidity of the securities in that sector.165 The LSE discloses the thresholds for single security circuit breakers applied to the venue.166 The stocks on the FTSE- 100 have a dynamic threshold of 3% above or below the price of the last trade in a particular security and a static threshold of 8% above or below the last auction price for a particular security.167 When a price exceeds either of these thresholds, a circuit breaker is triggered that stops trading for five minutes and makes corresponding reference prices on alternative venues unavailable.168 During the trading halt, a call auction takes place which, at the end of the halt, executes matched trades before continuous trading resumes.169 The trading halts can be further extended beyond five minutes if the resulting price of the auction deviates too much from the last price of continuous trading, or if the auction results in unfilled market orders.170 The circuit breaker mechanisms on the LSE have been tested during recent months of high volatility and proven to be able to keep the markets working even under periods of market stress.171

Circuit breaker in the United States

The US follows a different approach to controlling volatility than the EU and the UK. In contrast to their European counterparts, US regulators and trading venues have adopted market- wide circuit breakers that halt trading for all securities on the index.172 These market-wide circuit breakers react differently depending on the severity of market disturbance.173 There are three circuit breaker thresholds for the S&P 500: Level 1, which is triggered at a decrease of 7%; Level 2 at 13%; and Level 3 thresholds are triggered at a decrease of 20%.174 If the market volatility triggers a Level 1 or Level 2 circuit breaker before 3:25 p.m., the circuit breaker will halt trading on the entire market for 15 minutes. If such a decline occurs after 3:25 p.m., trading will not be interrupted.175 However, a decrease of 20% triggers a Level 3 circuit breaker, which halts trading at any time for the remainder of the day.176 The reference points for the circuit breakers are based on the closing price of the S&P 500 on the previous trading day.177

The closing price is the result of free market activity during the trading day and may be manipulated by malicious traders to change the benchmark for the circuit breakers on the next trading day.178 Market manipulation has been prohibited in the US since the implementation of the Securities and Exchange Act in 1934. 179 With the frequent adaptation of existing rules and reporting requirements, market manipulation is enforced by the SEC and the Department of Justice.180 In Europe, market manipulation is specifically prohibited by the EU Market Abuse Regulation,181 and the member states’ financial regulators consider detecting and investigating cases of market manipulation as one of their main functions.182 These rules on both sides of the Atlantic attempt to protect the integrity of closing prices as thresholds for circuit breakers.

In addition to market-wide circuit breakers that halt trading, the SEC and the exchanges have also implemented single-stock circuit breakers based on a limit up/limit down principle.183 They address volatility by preventing trades of individual security outside of a certain price range, which is set above or below the average price of the security over the last five minutes.184 How far away from the average price the price limits are set depends on the individual security and limits during the opening and closing periods of the markets.185 If the price at which the security is traded does not move back within the price frame within 15 seconds, the limit up/limit down mechanisms will halt trading of the security for five minutes.186

Limit up/limit down mechanisms achieve the same aim of volatility control as a trading halt circuit breaker without the need to stop trading completely in every situation.187 If the prices return to normal within 15 seconds, a trading halt is not necessary, and the trading can continue without any interruption of the execution of the orders within the price frame. This mechanism provides a steadier alternative to circuit breakers and adds market stability.188

Effectiveness of circuit breakers

Many studies have been conducted on the effectiveness of circuit breakers in many different aspects and environments.189 The results of these studies vary widely, partly because of the different methodologies used for the assessment and partly because circuit breaker mechanisms vary widely between individual exchanges, even among European venues and more so globally. These different circuit breaker calibrations have different impacts on the markets and lead to different results.190 An in-depth examination of the individual effects of circuit breakers under specific circumstances would provide too much detail. Some articles argue that circuit breakers would lead to an increase in volatility when approaching a threshold and therefore contradict their initial aim. They argue that circuit breakers are the wrong answer to the risks of algorithmic trading.191


In addition to the critique of circuit breakers, one assumption has been established in multiple studies. Circuit breakers generally have the ability to decrease volatility in highly volatile markets and lead to calmer trading circumstances at the expense of reduced liquidity, which can be seen in higher bid-ask spreads.192 Higher bid-ask spreads show that there is less consensus between the participants of a trade with respect to the value of a share.193 If the differences between the bid and ask offers increase, then stocks cannot be sold at their optimal value and the transaction costs for every participant increase as well, and the liquidity decreases.194 Although their application reduces liquidity temporarily, circuit breakers are an important tool for mitigating the risks of modern trading and controlling volatility, which is why they are commonly used in trading venues around the world.195

Liability

The final part explores the enforcement of the safety requirements and the liabilities the parties are faced with. First, we focus on firms and trading venues and examine how regulators enforce the rules on them and how they can be held liable by regulators and individual investors. Second, we assess the potential liabilities for the regulators themselves.

Liability for Private Firms and Venues

Regulatory sanctions

Since MiFID II had to be implemented recently in 2018, not too many sanctions have been imposed by national regulators.196 In 2018, only a few countries imposed sanctions on violations of the MiFID II provisions.197 A reason for this can be seen in the way in which some national regulators handled the transformation towards the new framework. The FCA, for example, prioritised ensuring that the markets kept functioning well during the implementation process; therefore, the FCA did not enforce all the rules but preferred to focus on supervising firms during the first six months after the implementation to give them sufficient time to comply.198 After this first period of leniency on firms that had to comply with MiFID II, the number of measures and sanctions imposed by national regulators increased in 2019 to a total of 371 in all European member states.199 Sanctions for failing to comply with the requirements for algorithmic trading as laid out in Article 17 have been imposed, for example, by the Czech, Greek, and Hungarian regulators.200 National regulators are increasingly enforcing compliance with MiFID II; however, ESMA considers this data to be insufficient to determine clear trends and tendencies of compliance because of the considerable time enforcement action takes from the occurrence of the violation until their conclusion and the differences among the national frameworks.201

Algorithmic traders are subject to a broad regulatory regime and are, therefore, likely to be subject to the enforcement action of regulators. In the UK, the Swiss bank UBS has been held liable for a failure to report their transactions properly and was fined a record sum of 27.6 million pounds.202 Although the fine was imposed in 2019, failures occurred from 2007 until 2017, before the implementation of MiFID II. They violated the requirements of its predecessor MiFID I.203 However, such reporting requirements are also part of MiFID II; in particular, algorithmic high-frequency traders are required to keep detailed records of their transactions and make them available to the authorities on their demand.204 Hence, algorithmic traders will be held liable for failing to properly report their transactions under the MiFID II regime.

The case of Financial Conduct Authority v Da Vinci Invest Ltd 205 addresses the issues of whether the activities of a trader can be attributed to the firm that helps him gain direct market access. The court ruled that because the firm never made any proper attempts to check the background of the traders, to understand their trading strategies or supervise them, the firm acted irresponsibly and recklessly. Therefore, the behaviour of the traders, which constituted market abuse, was attributable to the firm and the firm could be held liable.206 As illustrated in Part 1, the MiFID II regulation requires direct access to be mediated through the regulatory mechanisms of the provider. This provision makes the firm liable if it does not sufficiently check the algorithms of its clients. The regulatory framework not only includes rules for traders, but also ensures the safety and functioning of the market as a whole. Many rules exist regarding trading venues. Trading venues might also be subject to regulatory measures and be held liable for breaches of the regulatory framework. A case where the trading venue itself was held liable took place in 2015 when the French regulator AMF sanctioned Virtu Financial Europe for market manipulation and also handed down a penalty of 5 million euros to Euronext Paris for violating its neutrality and impartiality obligations.207 Euronext offered Virtu, a high- frequency market-making firm, an unlimited order-to-trade ratio free of charge, in order to test a new business model.208 This unlimited order-to-trade ratio gave Virtu an advantage compared to its competitors and enabled the firm to conduct market-manipulating spoofing techniques. This led to a fine for Euronext in the same amount as the fine for Virtu.209 This illustrates that trading venues can be held to the same standards as traders operating on their floors. The case took place before the implementation of MiFID II; however, the behaviour of a trading venue under the MiFID II regime would probably be a violation of the co-location, fee structure, and market making requirements as well as a violation of the duties of a trading venue to monitor algorithms and detect market manipulation.210 Trading venues can also be held liable if they wrongly apply other safety measures imposed by MiFID II or RTS 6, such as circuit breaker requirements.

On the other side of the Atlantic, the liability issue has been addressed among other measures by a rule change in the SEC. The SEC changed NASD Rule 1032 after a proposal by FINRA.211 The new rule requires the developers of algorithmic trading strategies to register as securities traders with FINRA, which requires them to take a test before they are allowed to work and, more importantly, make them liable.212 Before this rule change, only financial firms could be held liable for flaws in the algorithms. Since then, developers can be held directly responsible for the software they develop.213 This rule makes developers liable if their software is not compliant with the regulatory requirements, as well as if their software is used to abuse the market. In the US, there have been some cases of algorithmic traders violating the regulatory framework, which required SEC intervention. A high-frequency algorithmic trader, Athena Capital Research, was charged with market manipulation and settled the claims with the SEC for $1 million.214 Athena used its technical abilities as a high-frequency trader to place a large number of orders just seconds before the end of the trading day to manipulate the closing price in its favour.215 For such manipulative behaviour, the firm was held liable by the SEC and sanctioned with a fine.216 If Rule 1032 had been in place when the violation occurred, the developers of the software that manipulated the closing price would have been held liable as well for the creation of software that enabled market abuse.

Another case in which a trading firm faced civil liability was the above-mentioned case of the Knight Capital Group, where a mistake in Knight Capital’s software led to the execution of a large number of errant trades.217 Besides its losses of approximately $440 million due to the executed trades, Knight Capital was fined another $12 million by the SEC for not adequately safeguarding the market access of the algorithm and for failing to properly review the algorithms before their application to the real market that put the firm and the whole market at risk.218

Liability to investors

Trading firms can be liable under special circumstances to individual investors. If there is only a general fluctuation in the market or a global event, it is not possible to sue the trading firm for compensation.219 However, if the trading firm failed to protect investors’ interests, breached their contractual, tortious, or fiduciary duty, investors would be able to sue for compensation.220 The investor has to prove that their financial representative breached its obligations or acted negligently, and that there is a connection between the firms’ behaviour and financial losses. The exact requirements for such a claim depend on the jurisdiction in which they are suing and on the nature of their claim, whether contractual or tortious.221 Investors might claim compensation for losses suffered if the losses occurred because of the trading firm not complying with the regulatory rules.222

The options for investors to claim compensation from trading venues for losses suffered are not well established. The recent case of Burford Capital LTD v London Stock Exchange Group Plc223 dealt with the claim of a company for losses suffered due to fluctuations in its share price. However, the company sued the LSE to force them to disclose the identity of every person involved in placing orders of the company’s shares over a specific period. They did not sue the LSE to compensate for the losses they suffered. Whether a compensation claim can be brought successfully against a trading venue has not been established.

However, fines for companies are not the only option to enforce liability for violations. Firms can also be banned from trading for a certain period.224 This option was used to sanction a firm for abusing the market; however, it could also be used to sanction it for regulatory non- compliance.

In the aforementioned market abuse case, Panther Energy Trading was engaged in market manipulation and settled a civil enforcement action with the CFTC for this violation, which resulted in a fine and a one-year ban from trading on CFTC-registered entities.225 In addition to the corporate liability for Panther Energy, the owner of the company, Michael Coscia, was criminally charged with spoofing and commodities fraud and sentenced by a federal court to three years in prison.226 Some authors argue in favour of using individual criminal liability more often as a measure to better regulate and prevent misconduct among algorithmic traders.227 They base their arguments on two main grounds. First, an individual criminal liability for the trader responsible for the misconduct would have a higher deterrence effect compared to corporate liability or even individual civil liability.228 Second, since the burden of proof in a criminal trial is higher, a criminal conviction would have a higher standard, which could guarantee that the trading behaviour really was illegal. Illegality can be difficult to prove, especially for fast-changing algorithmic trading activities.229

Trading firms as well as trading venues face severe liability issues if they do not comply with the thorough regulatory framework for algorithmic trading activity, whether they violate regulatory compliance rules or perpetuate market abuse. Although the cases of civil liability under MiFID II are rather rare at the moment, regulatory action will increase in time, and liability will play an important part in ensuring compliance with the rules for the safety of the individual investor and the market as a whole.

 

Sumber : Joseph Lee and Lukas Schu 

Haikal Rahman
Bisnis Digital - FE Unimed
Komentar