amBrain
FinTechOct 6, 20268 min read

Real-Time Risk Engine for a Broker or Prop Firm: Build, Buy or Extend, and Who Can Build One

Pre-Trade RiskRisk EngineProp TradingWho Builds It
Error loading image

A broker or prop firm can rely on the pre-trade risk checks its clearing firm, broker or venue already runs, license a ready-made risk gateway, or build or extend an engine it owns. The right route depends on whose rules must be enforced and who needs to change them. Whichever route you choose, ask how long the risk check takes and how that was measured, and watch a test in which the kill switch stops all trading.

Pre-trade risk checks for a broker or prop firm come from one of three places: the controls of your broker, clearing firm or venue; a vendor that licenses a ready-made risk gateway; or an engineering firm that builds or extends an engine you own. Which one fits depends mostly on whose rules must be enforced and who needs to change them. Before you rely on any of them, ask how long the risk check takes and how that figure was measured. Then ask to see a test of the kill switch, the control that stops all trading for an account or a whole firm at once.

The short answer: the broker's controls are enough as long as you need no limits beyond the broker's. When the rules are part of what you sell, as a prop firm's loss limits are, you need an engine you control, whether you license it or build it. Test it four ways: ask how long the risk check takes and how that was measured, run a kill-switch drill, restart the engine mid-session and replay your own orders through it.

What should a risk engine check before an order goes out?

A pre-trade risk engine runs its checks on every new order and on every change to a working order. In its July 2024 paper on automated trading risk controls, FIA, the trade association of the futures industry, says the order size check “should be applied when a new order is submitted or an existing order is modified”.

The core checks are these:

  • Position limits: how much an account or a trader may hold, counting orders that are still working, meaning sent but not yet filled or cancelled
  • Margin or buying power: whether the account can still cover the order
  • Fat-finger limits: caps on the size and value of one order and on how far its price is from the market. FIA's paper says a cap on order size is “commonly referred to as ‘fat-finger’ limits”
  • A kill switch: in the words of FIA's paper, a control that “immediately disables all trading activity for a particular participant or group of participants”, which typically means no new orders and every working order cancelled

What do regulators expect from pre-trade risk checks?

In the US, SEC Rule 15c3-5, adopted in 2010, requires a broker or dealer with market access to keep pre-trade controls on credit, capital and erroneous orders. The article on slow order execution, linked above, quotes it.

In the EU, investment firms that trade by algorithm fall under RTS 6, Commission Delegated Regulation (EU) 2017/589 of 19 July 2016. Article 15 lists price collars, maximum order values, maximum order volumes and maximum message limits. A price collar blocks an order priced outside a set range, and a message limit caps how many new orders, changes and cancels a firm may send. Article 12 requires the firm to be able to cancel “immediately, as an emergency measure, any or all of its unexecuted orders”, and to know which algorithm and which trader, desk or client is responsible for each order.

When are your broker's or venue's controls enough?

The broker's or the venue's controls are enough for a firm that trades through one broker and needs no limits beyond the broker's.

  • Your rules: the broker can only limit what it sees, your account as a whole. Limits per trader or per strategy work only if the broker supports them and every order says which trader or strategy sent it. The broker's risk team changes the limits when you ask
  • Latency: the broker's systems decide it. Your own timestamps on each order and the broker's confirmation show the whole round trip, not the check alone, so ask the broker how long its checks take
  • Cost: nothing to build, but any limit of your own is tracked by hand, so its breaches are found late
  • Regulators: in the US the broker must control these checks. An EU investment firm that trades by algorithm keeps its own RTS 6 duties

FIA's 2024 paper warns that when a customer's connection to its broker drops, its working orders can stay in the market. Passing the customer's cancel requests through to the exchange “is typically unsupported, and the customer would need to contact the broker to manually cancel any working orders”.

When does a licensed risk gateway make sense?

A licensed risk gateway is ready-made software that checks every order before it reaches a broker or venue. It makes sense when your rules look like most firms' rules and you need them at several brokers or venues soon.

  • Your rules: you choose from the rule types the product has, and your staff set the limits in the vendor's screens. The logic stays in the vendor's code, so a missing rule, such as a loss limit measured your way, waits on the vendor or on paid custom work. Ask what happens if the product is withdrawn or repriced
  • Latency: ask where the vendor's figure was measured from and to, and at what load. A gateway that runs as a separate service adds one more hop, and its delay, to every order, usually across the network
  • Cost: the licence model, such as per user, per connection or by order volume, plus fees for new venues, hardware and custom rules
  • Regulators: the duty stays with the firm, whatever it licenses. Check that the product covers every control the regulations you fall under require, and keeps the records to prove it

When should we build or extend our own risk engine?

Build when the rules are part of what you sell or no product applies them your way. Extend your current order path with a risk layer when it works but its checks are slow, missing or kept in a spreadsheet.

  • Your rules: each rule is written the way your contracts and your clients' terms define it, and your risk staff change the limits in screens you specify. On setting and changing limits, FIA's paper says “Authorized staff independent of trading activities should manage the process whenever possible to avoid conflicts.” Your contract should also say who owns the code
  • Latency: the check can run inside your own order path with no extra hop, and must be measured again whenever rules are added
  • Cost: engineering and testing time, connections to each broker or venue and their feeds of your fills, and the people who run the engine after launch
  • Regulators: the duties stay the same, and your own software now has to meet them. Record every rejected order and limit change, test the kill switch, and under RTS 6 make sure each order can be traced to its algorithm and to its trader, desk or client

How should a prop firm enforce daily loss and drawdown limits?

A prop firm's trading rules are part of its product, and they must apply the same way to every trader on the same plan. Two such rules are a maximum daily loss and a maximum drawdown, which is how far an account may fall from its starting balance or its highest point.

FTMO, a prop trading firm that publishes its trading rules, measures these limits on equity, meaning the account balance plus the profit or loss on open positions. Its Trading Objectives page, read on 6 October 2026, defines the Maximum Daily Loss as a limit below which account equity “cannot drop”.

A trader can break an equity-based limit without sending a single order, just because the price moved. So the check runs on every price change, blocks orders that add risk the moment the limit is hit, and closes positions if your rules say so. An end-of-day spreadsheet finds the breach hours late.

Limits also differ in how their level is set. On the same page, the Maximum Loss of FTMO's 1-Step challenge is an “end-of-day trailing” limit. Its level is reset once a day from the highest balance recorded at midnight Central European time and can only go up. The 2-Step challenge uses “a static limit” instead. Note what each rule is measured on and when it resets, and log every breach with its time, prices and equity.

How do we check who can build a real-time risk engine?

Put four tests to every firm on your list:

  • How long the risk check takes, and how that was measured. Ask for the time of the risk check alone, separate from the time of the whole order, with where the timing starts and stops, the percentile, the load and the hardware. For a target well under a millisecond, ask for the 99th percentile at your busiest load, the time that 99 of every 100 checks stay under
  • A kill-switch drill. In a test environment with working orders, press the switch for one account and then for the whole firm, and time how long until new orders are refused and working orders are cancelled. FIA's paper says an automated trader “should not be able to override a kill switch invoked by the broker”, so try to override it from a trading account and check that it holds
  • Recovery after a restart. Stop the engine mid-session and restart it. Positions, working orders and used limits should come back correct, checked against the broker's or venue's record, before any account trades
  • A replay of your own order flow. Run a recorded day of your orders and prices through the engine, busiest minute included, and have the firm explain every decision that differs from your current controls. Include an order in an instrument that has no size limit set. FIA's paper says systems should block such an order

Any latency figure quoted before a firm has seen your rules and your order flow was measured on someone else's. Ask for it again from the replay of your own day.

Where does amBrain fit?

amBrain builds algorithmic trading infrastructure: order execution, market data and pre-trade risk controls.

amBrain builds platforms for proprietary trading firms: evaluation challenges, trading rules and accounting. Its trading work also includes trading terminal development, order management systems, and FIX protocol exchange integration.

amBrain diagnoses slow systems in trading and ad tech: the running platform is measured end to end and the report names where the time goes.

amBrain has been building software since 2019. It works in three formats: full delivery, a dedicated team, or engineers embedded in your team. The client keeps full ownership of the product and the code, except amBrain's reusable components.

If your risk checks are slow or kept in a spreadsheet, write the four tests into the contract with whichever firm you choose, amBrain included.

This article is not a case study and describes no client work. It quotes no latency figure for any system amBrain has built, and no prices or timelines.

Common questions

  • Will checks inside the order path slow down order entry? Yes, a little. Each check adds its time to every order, so that time must be small and measured. The article on pre-trade risk in the order path, linked above, explains how
  • How much does a risk engine cost, and how long does it take to build? Both the cost and the time grow with the number of brokers and venues, the asset classes, the margin rules and who runs the engine. Ask each firm to price and schedule a first phase, with the four tests above as pass marks

Have a design like this on the table?

Bring your current architecture and the failure mode that worries you, and we will go through it together in half an hour.