Pre-trade, or it is not a control
Every firm here already has post-trade surveillance, and every firm here
knows what it is worth on the day something goes wrong: it tells you
precisely what happened, after it has happened. The control that matters
is the one in front of the action.
That is the whole shape of an authorisation call. Nine gates in a fixed
order, cheap structural checks first, and the answer returned before the
agent acts — not a callback, not an async review, not a report the next
morning. An action refused at gate one never reaches policy evaluation,
which is why the check can sit on the path at all.
- Latency is a design constraint, not a footnote
- One call before a consequential action, with the gates ordered so
that the common refusals are the cheap ones.
- Enforcement moves one rung at a time
- Observe and shadow record without refusing, so a desk can see what
the control would have done to a live book before it does it. Canary
and enforce refuse. Nobody is asked to switch a trading system from
nothing to blocking in one step.
- An exhausted limit is not a denial
- Six distinct outcomes, because "not permitted" and "permitted but
out of allowance" send a desk to different places.