Algorithmic Trading in India: Approval, Controls and Disclosure
Algorithmic trading in Indian regulation is order generation or placement by a system rather than by a person deciding each order. Such a system needs approval through the exchange before it runs, controls that bound it while it runs, and records once it has run. Which controls are required and what must be disclosed sit in the Securities and Exchange Board of India (SEBI) requirements and the exchange rules, read at sebi.gov.in.
A machine on a pavement shows the shape of the problem more clearly than a market does. A shopkeeper who hands a customer a packet of tea across a counter can be asked that same evening why she charged what she charged. She was standing there. She decided. A vending machine on the same pavement is a different matter. At three in the morning it takes a note from somebody and returns the wrong change, and it does that eleven times before anybody notices. There is nobody to ask. The machine has no account of itself and no view about what it did. A machine that was not thinking cannot be asked what it was thinking. The questions worth asking are who set it up, what bounds they put on it, whether anybody could switch it off in the middle of the night, and whether it kept any tally of what it handed out.
Regulation of anything automatic moves the questions to a moment when somebody can still answer them. Two moments qualify: before the thing started, and after it stopped. A person placing an order can be asked about it afterwards, and the asking works because a person holds a reason. A system placing orders faster than anybody can read them holds no reason at all, so the asking is moved backwards in time, into a permission obtained before it ran, and forwards in time, into records that show what it did. Every requirement below is one of those two moves. Once the two moves are clear, no requirement is arbitrary.
In India, two layers of requirement apply to the same arrangement at the same time. The Securities and Exchange Board of India sets the framework, and the exchange the firm is a member of sets its own requirements on top of that framework as a condition of connecting to it. A firm meets both layers or it has met neither usefully. Requirements in this area are also revised more often than in most parts of securities regulation. The technology keeps moving, the regulator responds to what it sees happening in the market, and a figure from either layer is therefore read at its source on the day it matters.
Bhadra Securities Private Limited, an invented broker and depository participant, carries 11,400 client accounts. Sumana Rege heads technology there and Yashodhan Pai is the compliance officer. Anasuya Kolhapure is one of the 11,400 client accounts. She once held 3 physical certificates covering 1,200 shares. The certificates became a single electronic holding of 1,200, and she later sold 400 of them, leaving 800. She placed that sale of 400 herself, on a screen, in one decision, on one afternoon. Her ordinary sale of 400 shares is the reference point. Algorithmic trading is what happens when nobody makes a decision like that one.
What counts as algorithmic trading in Indian regulation?
Algorithmic tradingOrder generation or placement by a system rather than by a person acting order by order. is order generation or placement by a system rather than by a person acting order by order. The definition ends there, and it is worth reading twice. Almost every wrong answer on this subject comes from quietly adding something to it that is not there.
The silences of the definition matter as much as its words. The definition says nothing about speed, so a slow system is not outside it. Volume is absent too, so a system placing a handful of orders in a day is not outside it. Sophistication is absent as well, so neither a mathematical model nor a list of simple instructions gets a different answer. Nor does the definition care whether the system was bought, rented or written in-house on a Sunday. Above all, the definition ignores the purpose of the system, and purpose is the one thing most people assume a rule about algorithms would care about.
The test is who decided, not how clever the deciding was. Run it in both directions and it becomes very hard to get wrong. Ten lines of instructions that place a sell order whenever a price crosses a level, written by one person in an afternoon and never touched again, sit inside the definition. No person decides each of those sell orders. A large analytical tool that ranks two hundred securities every morning, colours them, sorts them and then sits there waiting for Sumana Rege to click on one, is outside the definition. The click is a person deciding that order. Complexity went one way and the answer went the other.
The trap sits in the middle of those two, and it catches careful people. Somebody sets a system running at the start of a session, watches it for a moment, and then goes to a meeting. Was there a human decision? There was one, and it was a decision to start a system rather than a decision about an order. Deciding order by order means what it says. A single instruction at nine in the morning that produces four hundred orders by three in the afternoon is not four hundred decisions, and treating it as though it were is the most comfortable mistake available on this subject.
A very simple script places orders on one rule, with no person involved after it starts. Is it caught by these requirements?
Why do these rules exist when a person placing orders needs no approval?
Go back to Anasuya Kolhapure selling 400 of her 1,200 shares. Nobody approved that sale in advance. No exchange looked at her reasoning, no control bounded what she could enter, and no framework required a record of her intentions. If anybody ever questions that sale, there is an obvious route: ask her. She will remember roughly why, Bhadra Securities Private Limited will hold the instruction she gave, and between the two of them a complete account of one order exists.
Now replace her with a system running inside Bhadra Securities Private Limited that places orders through the session without anybody deciding each one. The market impact might be identical. The harm, if there is harm, might be identical. The route to an answer has vanished, and the route is the only thing that changed.
Answerability is not removed by automation, it is relocated, and Indian regulation of algorithmic trading is essentially the exercise of following it to where it went. Answerability went to two places. One is backwards, into the moment before anything ran, when a person could still describe the arrangement and what would bound it. The other is forwards, into the record of what happened, and a record can be read long after everybody has forgotten what they expected. The middle holds no answers at all. While the system runs, controls have to act by themselves rather than by anybody deciding anything.
An incident is therefore a poor moment to start caring. Every question anybody asks after an unexpected session was settled well before that session opened. Was this covered by what was approved? Settled at the approval. Did the controls bound it? Settled when the controls were built, or when somebody decided a sentence in a document would do instead. Can anybody show what it actually did? Settled by whether a record was being written while it ran. Three questions, three answers, and not one of them can be created on the day it is asked.
What approval does an algorithmic arrangement need, and from whom?
The route runs through the exchange. A firm that wants to run an algorithmic arrangement applies to the exchange it is a member of. The connection physically lands there, and the orders arrive there. The Securities and Exchange Board of India sets the framework that the exchange administers, and the exchange attaches its own conditions to membership on top of it. So the two layers appear again in a very practical form: the regulator decides what kind of thing must be approved and on what terms, and the exchange is the party a firm actually deals with.
The object of the approval is worth stating slowly. Almost everybody starts with the wrong one. Nobody at the exchange is forming a view on whether the strategy is any good. Nobody is checking whether it will make money, whether the reasoning behind it is sound, or whether a different idea would be better. ApprovalThe permission obtained before an algorithmic arrangement may run, attaching to the arrangement rather than to the firm in general. here means permission for an arrangement: the broad behaviour of the system, what bounds it, what checks sit in front of it, who can stop it, and what record it produces.
The approval attaches to an arrangement rather than to the firm's general permission to trade. An arrangement can therefore be outgrown without anybody noticing. A permission to trade is a status. A status just sits there. An approval for an arrangement is a description, and a description stops being true when the thing described changes. Nothing announces that moment. There is no letter, no alert, and nobody at the exchange watching the code.
The burden of noticing falls on the firm, and the word for it is material changeA change large enough that what is now running is no longer the thing that was approved.: a change large enough that what is now running is no longer what was approved. Who decides whether a change is material? Bhadra Securities Private Limited decides in the first instance, and Yashodhan Pai is answerable for that decision afterwards. Placing that judgement inside the firm is uncomfortable, and far better than the alternative. The alternative is nobody deciding at all until an incident forces the question. The practical habit that follows is dull and completely decisive: every change to the arrangement gets written down with its date, and somebody reads that list against the approval on a fixed rhythm rather than when it feels necessary.
India, and where the approval requirement actually sits
In India, the requirements on algorithmic trading are issued by the Securities and Exchange Board of India through its circulars and frameworks on algorithmic trading, read at sebi.gov.in, and the exchanges publish their own requirements for members connecting algorithmic arrangements to them, read at nseindia.com and bseindia.com. Both were consulted on 18 August. Order rates, position limits, latency figures, fees and penalties are set in those instruments. Requirements in this area are revised more often than in most of securities regulation, and a number carried from memory would read most confidently on exactly the day it stopped being true. The current text is opened at the source, and the document title written down beside the date it was read.
What is actually being approved when an algorithmic arrangement goes through the exchange?
Which controls must sit around a running algorithm?
A controlA limit or a check that bounds what a running system can do, built into the system rather than described in a document. is a limit or a check that bounds what a running system can do. The word does a lot of quiet work in this subject, so it is worth pinning down: a control is a mechanism. Somebody can point at where it lives, show what it does when it acts, and demonstrate it acting. If none of those three is possible, the thing being described is an intention rather than a control.
The control set has a shape, and the shape is more useful to hold than any list of names. The names change between the regulator's framework and each exchange's own requirements. The rows below are questions the arrangement must be able to answer, and read that way the requirement is recognisable whichever words it arrives in.
| The control | What it actually is | The question it answers |
|---|---|---|
| A ceiling the system may not exceed | A bound set inside the running system, not a paragraph in a policy | How far can this go before something other than judgement stops it? |
| A check before each order leaves | A test applied to every order on its way out of the firm | Could an obviously wrong order reach the market untouched? |
| A stop that works immediately | One action, available to a named person, needing nobody's agreement | Can this be ended now, by somebody who is actually in the room? |
| Testing kept away from the live market | A place where changes are proven that is not the market itself | Is the market where this firm discovers that new instructions are wrong? |
| A record written while it runs | A trail produced by the running rather than reconstructed afterwards | Can anybody establish what happened once everybody has forgotten? |
| A named person watching, able to act | Authority and access held by the same pair of hands | Is there a hand on the stop, or only a name on a document? |
The running system has never read the policy and will not be slowed down by it, so a control that exists only as a sentence in a policy is not a control. The point sounds obvious written down, and it is the single most common gap anybody finds when they look properly. The document says orders above a certain size are not permitted. The system has no idea. Somebody wrote the sentence sincerely, somebody else approved it, and nothing at all happens when an order above that size is generated at eleven in the morning.
One of the rows matters more than the others at exactly one moment, and it is worth naming that now. Every row except the stop bounds what happens. The stop ends it. A kill switchThe ability to halt a running system immediately, in one action, without waiting for anybody to agree. is the ability to halt a running system immediately, and its whole value lies in requiring no discussion. If using it needs three people to agree, it is a meeting rather than a switch, and meetings are exactly what a bad session does not leave time for.
Something unexpected is happening in the market right now. Which control matters most in that minute?
What is API Trading, and how does it sit inside these rules?
API tradingPlacing orders through a programmatic interface rather than through a screen a person is looking at. means placing orders through an application programming interface (API) rather than through a screen. Instead of a person looking at a display and clicking, another piece of software connects to the firm's systems and submits orders directly. Bhadra Securities Private Limited offers exactly that to some of its clients, who connect their own systems to it, and around 11,400 client accounts sit at the firm in total, so most of them are on a screen and a minority are not.
Here is where a great deal of confusion lives, and clearing it costs one sentence. API trading describes the route an order takes. Algorithmic trading describes what decided the order. Route and decision are two different questions about the same order, and answering one has never answered the other.
Work the four combinations and the point becomes hard to argue with. A person can click on a screen, giving a human decision on a screen route. A person can send an order through a programmatic interface, still a human decision, just arriving differently. A system can place orders that reach the market through a screen-facing route. And a system can place orders through a programmatic interface, the combination people picture when they hear either term. Only the deciding half of each pair is what the algorithmic trading requirements are asking about.
Reaching the market through a programmatic interface is a route rather than an exemption, so who decided the order gets asked in exactly the same words. A firm that thinks of its interface as a neutral pipe has misread its own position twice over. First, orders leaving through Bhadra Securities Private Limited are orders for which Bhadra Securities Private Limited is answerable, whatever produced them. Second, a client system connected to that interface is itself an arrangement, and somebody has to be answerable for what it does. The firm does not become a bystander because the deciding happened on the other end of a connection.
Orders arrive at Bhadra Securities Private Limited through a programmatic interface rather than a screen. Does that change whether these requirements apply?
Who is answerable when an algorithm behaves unexpectedly?
Picture the session going wrong at Bhadra Securities Private Limited. Something in the running arrangement does what nobody anticipated, for a stretch of the afternoon, and by the time it stops there are questions coming from the exchange, from inside the firm, and eventually from clients. Watch where those questions try to land. The first two places they try are both dead ends.
The questions cannot land on the algorithm. The algorithm has no account of itself, no memory of a reason, and no view about what it did. Asking it what happened produces a description of behaviour. A description is evidence, and never an answer. The questions cannot usefully land on whoever wrote it either. The author can say sincerely what they intended eight months ago, and intention is precisely what has stopped being relevant. The question asks what happened rather than what was meant.
Answerability lands on named people inside the firm: whoever approved the arrangement, whoever was responsible for the controls that were meant to bound it, and the firm itself as a member of the exchange. At Bhadra Securities Private Limited that means Sumana Rege for the systems and the controls, Yashodhan Pai for the approval and the records, and the firm for both. None of them was watching the screen at the moment it happened, and it does not matter in the slightest. Their answerability was fixed long before.
The consequence is worth sitting with. For anybody working inside a firm it outranks everything else in the subject. The quality of a firm's answers on the worst day of the year is decided entirely on ordinary days. Not by how quickly it responds, not by how well it explains, but by whether an approval covers what was running, whether the controls were mechanisms rather than sentences, and whether a record was being written. Nothing done in the hour after the event improves any of the three.
An algorithm at Bhadra Securities Private Limited behaves unexpectedly through an afternoon. Who answers for it?
What must be disclosed, and to whom?
Disclosure on this subject is not one duty pointing at one audience. Disclosure is three different kinds of telling, aimed at three parties who want different things, and the commonest error is assuming that satisfying one of them settles the others.
Telling the exchange is a permission question. The exchange needs to know what arrangement is connected to it, and it needs to be told when that arrangement becomes something else. Material change stops being an abstraction at exactly that point. Telling the regulator, through whatever reporting route the requirements set, is a supervision question. Supervision exists so that the Securities and Exchange Board of India can see across firms rather than inside one. Telling a client is a conduct question entirely. A conduct duty exists because a person handing money and instructions to a firm is entitled to understand what will happen to them.
Telling the exchange does not discharge what is owed to a client, and telling a client does not discharge what is owed to the exchange. The two duties look similar written down and they answer to different things. An exchange wants to know what is connected to its market. Anasuya Kolhapure, if her orders ever touched an automated arrangement, would want to know something quite different: what decides, what bounds it, and what happens to her instruction if the thing fails halfway through. A firm can be perfectly correct with the exchange and quite unfair to her, and the requirements treat those as separate failures because they are.
There is a household version of this that makes it stick. Somebody who hires a driver for the family car tells the insurer. The insurer is being asked to carry a different risk. Whoever is in the car is told as well, and for a different reason: they are entitled to know who is driving. Doing the first and skipping the second is not a technicality. The second omission is the one a passenger would actually mind.
A firm has told the exchange exactly what its algorithmic arrangement is and has kept that filing current. What has it settled?
What records must exist afterwards, and what are they evidence of?
Three kinds of record come out of an algorithmic arrangement, and they answer different questions. The first is the audit trailThe record of what was placed, when, and by which system.. The trail records what was placed, when, and by which system. The second is the record of order to trade behaviourWhat a system did in the market, as recorded, rather than as it was intended to behave.. The behaviour record shows what the system did in the market, as recorded rather than as intended. The third is the least glamorous and often the most decisive: the record of the arrangement itself over time, meaning which version was running, what changed, when it changed, who changed it, and against which approval.
Records are evidence of what the system actually did, as against what everybody sincerely believed it would do, and the distance between those two is where this entire subject lives. Nobody keeps records because a bad session is expected. Records exist because the account of a bad session assembled afterwards from memory is worthless, and everyone involved knows it is worthless while they are assembling it.
One property of the third record deserves particular attention. An audit trail is produced by the running, so it tends to exist whether anybody cares or not. The change history of the arrangement is produced by discipline, so it tends not to exist unless somebody deliberately made it exist. The asymmetry explains why firms that can say precisely what was placed at 11:42 can often not say which version placed it. How long each record must be kept, and in what form, is set out in the requirements and read there.
India, and the two layers that both apply to the same records
In India, requirements about what an algorithmic arrangement must record, and for how long, sit in the frameworks and circulars issued by the Securities and Exchange Board of India, read at sebi.gov.in, and alongside them in the requirements each exchange places on its own members, read at nseindia.com and bseindia.com. Both sources were consulted on 18 August. Retention periods, reporting windows and format requirements are set there. A firm that meets only the regulator's requirements has not met the exchange's, and membership binds it to those just as firmly. A compliance officer therefore keeps two open tabs rather than one.
When it matters, what are the records actually evidence of?
What does a firm do when something goes wrong during a session?
There is an order to the response, and the order is the whole lesson. Stop it. Contain it. Tell the people who must be told. Then, and only then, work out what happened.
Stopping comes first for a reason that has nothing to do with tidiness. While the arrangement runs, the cost of the episode keeps growing, and every minute spent understanding it is a minute it spends producing more of whatever it is producing. Worse, diagnosis consumes exactly the attention of exactly the people who could have stopped it. A firm that diagnoses first often finds nobody at all is watching the arrangement.
Diagnosis while the system is still running is the expensive way round, every single time, and the instinct to understand before acting is the instinct that has to be trained out. Understanding first feels responsible. Stopping something without knowing why feels careless. The feeling is wrong in this specific situation and in very few others, so the order of the four steps has to be settled in writing before anybody is under pressure.
Containing comes second because a stopped arrangement is not the same as a contained one. Three separate questions follow: what else is connected to it, what else was relying on its output, and what happens to whatever it left half done. Telling comes third: the exchange, the regulator through whichever route the requirements set, and any client whose instructions were caught up in it. Diagnosis comes last, and it is the only step that improves when it is unhurried.
One dull step turns the sequence into a capability. The sequence is written down, and rehearsed, when nothing is wrong. Nobody designs a sequence well at four in the afternoon with a bad session in progress, everybody in the room holding an opinion, and the one person who understands the system busy explaining it upward.
How does a compliance officer, an analyst or a household investor use any of this?
A compliance officer uses it as a single reconciliation, repeated. Yashodhan Pai at Bhadra Securities Private Limited has one question that outranks every other question on this subject: is what is running still what was approved? Everything practical follows from taking that seriously. Keep the approval and the change history in one place. Date every change. Read the list against the approval on a fixed rhythm rather than when it occurs to somebody. And when a change looks borderline, record the reasoning for calling it material or not. The reasoning is what will be examined afterwards, rather than the change itself.
An analyst or a lender looking at a broking firm uses it as a set of three questions that reveal a great deal quickly. Which systems can be stopped, how fast, and who has the authority to do it without asking anybody? How would the firm show what a system did last Tuesday? When was what is running last compared against what was approved? None of those asks for a strategy or a secret, and a firm that cannot answer them comfortably has revealed something structural about how it runs itself, without meaning to.
A household investor needs one narrow part of the subject, and for that reader it outweighs everything else in it: knowing which questions to ask before handing instructions to anything automatic. Where a service places orders on an investor's behalf, the questions are what decides, what bounds it, how it is stopped and by whom, and what would be shown if somebody wanted to know what it did on a particular day. Not one of those questions is about returns. The four are the same questions the regulation asks, in the words a person would use standing at a counter, and a service that finds them awkward has answered them.
Where are these requirements read, and why do they move faster here than elsewhere?
Two places, and both of them, always. The Securities and Exchange Board of India issues the framework and the circulars on algorithmic trading, read at sebi.gov.in. The exchanges publish the requirements they place on members connecting such arrangements, read at nseindia.com and bseindia.com.
The route is four steps and needs nobody's cooperation. First, the arrangement is described in plain words. Half the confusion on this subject is somebody asking about a category rather than about a thing. Second, the regulator's current requirement is found. Third, the requirement of the exchange the firm is a member of is found, in a separate search and a separate document. Fourth, each document title is written down beside the date it was read, and both are kept with whatever was done next.
Order rates, position limits, latency figures and penalties are read at their source rather than carried from memory. Requirements in this part of securities regulation are revised more often than in most others. The technology in the market keeps changing, and the regulator keeps responding to what it observes. A figure carried from memory would read at its most authoritative on precisely the day it became wrong, and the reader relying on it would discover the problem at the worst available moment. The date a requirement was read is part of the answer, not an administrative detail attached to it.
Why do two sources apply rather than one?
An arrangement is approved, and then changed twelve times across a year, each change small and sensible on its own. Predict what is running at the end of that year.
The failure: treating the approval as a formality obtained once
The reading is entirely understandable, and it is not laziness. The paperwork went in. Somebody spent three weeks on it. The approval came back and went into a file, and the file has not been opened since. In most of a firm's dealings that is exactly what an approval is for. An approval is obtained, it is kept, and the firm carries on. Meanwhile the arrangement improved, as arrangements that nobody improves get switched off. A bound was widened after a quiet month. A check was relaxed because it kept catching orders that were fine. A new instrument was added. None of those was the moment anybody should have stopped and reconsidered. The absence of that moment is the entire problem.
The wrong reading is that the approval attaches to the firm's general permission to trade algorithmically, when it attaches to an arrangement, and a materially different arrangement is a different thing from the one that was approved. Nobody in this story behaved badly. Nobody hid anything. Twelve people made twelve sensible decisions across a year and not one of them was the decision to run something unapproved. The failure has no villain and no moment, so there is nothing for anybody's conscience to catch.
The cost arrives at exactly the wrong moment and lands on people who were not careless. Something unexpected happens, the exchange asks what was approved, and the firm goes to the file. The file describes an arrangement the firm no longer runs. Now every good thing the firm did becomes hard to use: the controls existed, the records exist, the people are competent, and none of it answers the question actually being asked. The question is why the running arrangement was not the approved one. The way out costs almost nothing and has to be built before it is needed: a dated change history read against the approval on a rhythm somebody else can check.
Order rates, position limits, latency figures, penalties, fees, retention periods, reporting windows and effective dates sit in the instruments named below and are read there on the day they matter. How trading strategies are designed, tested or evaluated is a question of method and is taught separately, and no requirement above turns on whether a strategy is worth running. How an order is matched, and how obligations between two sides are worked out and settled afterwards, is covered under pay-in and pay-out and under settlement finality. Whether algorithmic trading is a sensible thing for any firm, any professional or any household to be involved in is a question of advice. No requirement described above answers it, and none of them was written to. Each exchange sets what it currently requires of its own members, in its own published conditions.
References
| Source | Document | Where |
|---|---|---|
| Securities and Exchange Board of India | The circulars and framework issued on algorithmic trading by members of recognised stock exchanges, named here for the existence of an approval requirement, a control requirement and a record requirement | sebi.gov.in |
| Securities and Exchange Board of India | The circulars addressing access to the market through programmatic interfaces offered by members to their clients, named only to mark that the route an order takes is dealt with as a route and never as an exemption | sebi.gov.in |
| Securities and Exchange Board of India | The regulations governing stock brokers, named because the conduct duties a broker holds toward its own clients continue to apply whatever technology sits between the client and the market | sebi.gov.in |
| The recognised stock exchanges, in their own published requirements | The conditions a member must meet before connecting an algorithmic arrangement, and what it must tell the exchange when that arrangement changes, named for the existence of a second layer of requirement and never as the source of the first | nseindia.com, bseindia.com |
| Securities and Exchange Board of India | The cyber security and cyber resilience requirements placed on regulated entities, named only to mark that a system placing orders is also a system that has to be protected and reported on, a subject covered under cybersecurity for regulated entities | sebi.gov.in |
| Securities Appellate Tribunal | Named only to mark that an order made against a member in connection with any of the requirements described above carries an appeal route, which is dealt with separately | sat.gov.in |
| International Organization of Securities Commissions | Named for the existence of international work on automated trading and market integrity, which is where a reader who wants the cross border framing of this subject should begin rather than in any national rulebook | iosco.org |
Bhadra Securities Private Limited, Anasuya Kolhapure, Sumana Rege and Yashodhan Pai are invented.
Educational material. Not advice on any investment, tax, budget or market position.
