Skip to content
Learning path Gold Professional operator

Compliance in trading: obligations, controls, and evidence

Compliance connects applicable obligations, procedures, controls, and evidence. It is not the same as a trader's personal discipline and varies by role, activity, and jurisdiction.

Compliance is the system through which an organisation identifies the obligations that apply, translates them into procedures, checks that they are followed, and preserves evidence. The rules depend on who is acting, what activity is performed, which product and client are involved, and in which jurisdiction.

In plain terms — First identify the rule, then build a control, and finally retain evidence that the control worked.

Compliance: a verifiable cycle Five stages from defining scope to reviewing controls, evidence, and exceptions. Compliance: a verifiable cycle Scope, rule, control, evidence, and review complete the process Who and what: Define entity, activity, product, client, and jurisdiction before assigning an obligation. 1 · SCOPE Who and what Role + activity product + country OPEN THIS STAGE Source: Tie each requirement to a current source: law, permission, agreement, rulebook, or internal policy. 2 · RULE Source Law + agreement applicable policy OPEN THIS STAGE Procedure: Translate the rule into a procedure with ownership, frequency, data, and an exception criterion. 3 · CONTROL Procedure Owner + frequency input + threshold OPEN THIS STAGE Demonstrate: Retain inputs, rule version, result, exception, and corrective action in a reconstructable form. 4 · EVIDENCE Demonstrate Log + version result + exception OPEN THIS STAGE Update: Review the control when rules, services, systems, or risks change and after incidents or failed tests. 5 · REVIEW Update Regulatory change incidents + tests OPEN THIS STAGE A rule without a control or evidence is not a verifiable process Cyclepedia diagram · Emiciclo
Compliance is a cycle: when the scope changes, rules and controls must be reviewed.
Select the highlighted points to explore the detail

Three levels that should not be confused

Legal and regulatory obligations. These may concern authorisation, organisation, conflicts, communications, suitability or appropriateness, records, client asset protection, market integrity, and resilience. They are not identical for every firm or client.

Contractual duties and internal controls. Contracts, policies, and procedures determine who approves an activity, which exceptions are allowed, which data is retained, and how a problem is handled. They must remain consistent with the higher-level rules that apply.

A trader's personal discipline. Following a playbook, risk limit, or journal matters, but it does not turn private rules into “regulatory compliance”. Operational documentation and personal audit address this layer.


The control cycle

Scope

Identify the entity, role, activity, instruments, clients, and countries involved. A European rule for an investment firm should not automatically be applied to every trader or service worldwide.

Rule

Use the current legal text and guidance from the competent authority. A summary can provide orientation, but the current authentic text prevails.

Procedure and control

Assign responsibility and design an observable control: approval, blocking, reconciliation, sampling, surveillance, or review. A document without execution is not evidence of compliance.

Evidence and exception

Retain the rule version, inputs, outcome, owner, date, and any exception. The evidence makes it possible to reconstruct what happened and correct the process.

Review

Update the system for regulatory change, new products, incidents, complaints, and control results. Compliance is not a one-off certification.


Example: communications to clients

Within the European Union, MiFID II requires investment firms to act honestly, fairly, and professionally in accordance with the best interests of their clients, and requires information to be fair, clear, and not misleading. A control does not stop at the sentence “returns are not guaranteed”: it checks the audience, product, risks, costs, conflicts, and channel in the version that was actually published.

This example describes a principle for firms within the MiFID II perimeter; it does not assign the same obligation to every author, trader, or platform. To assess an intermediary as a user, follow the due diligence process.

Common mistake — Calling every personal trading rule “compliance”, or copying a checklist from another jurisdiction without checking the entity, service, and date.


Professional reading

A mature programme maps every obligation to a risk, control, owner, frequency, and item of evidence. It also measures effectiveness: a completed control may still fail to detect the risk it was designed to address. Conflicts, continuity, outsourcing, systems security, and client asset protection require clear ownership throughout the operating chain.


Sources

This page is educational and does not determine the obligations in a specific case. Current law, the relevant jurisdiction, and the competent authority prevail.