Trading technology

Designing risk controls for automated trading systems

Pre-trade checks, loss limits, circuit breakers, kill switches and monitoring: the layers of protection every automated trading system should consider.

Quant HFT AI · · 2 min read

Automated trading systems execute rules quickly and consistently. That is their strength, and their danger: a faulty rule or a broken data feed can also be executed quickly and consistently. Well-designed risk controls are the difference between a contained problem and an expensive one. This guide outlines the layers of control every automated system should consider.

Principle: separate risk logic from strategy logic

Strategy code decides what to trade. Risk code decides whether a trade is allowed and how large it may be. Keeping them separate means a change to the strategy can’t silently weaken the safeguards, and the safeguards can be tested on their own.

Layer 1: pre-trade checks

Before any order is sent, check:

  • Position size limits: a maximum size per order and per instrument.
  • Exposure limits: total exposure across correlated instruments and the whole account.
  • Spread and liquidity filters: skip trades when spreads are abnormally wide or the market is thin.
  • Session filters: avoid illiquid hours, rollovers or scheduled high-impact events if the strategy was not designed for them.
  • Sanity checks: reject orders with prices far from the current market, or with zero or negative sizes. These usually mean a bug.

Layer 2: loss limits and circuit breakers

  • Daily loss limit: stop opening new positions after a defined loss for the day.
  • Maximum drawdown: pause the system if equity falls a set percentage from its peak, and require a human to review it before restarting.
  • Consecutive-loss breaker: an unusual losing streak can signal that conditions have changed or that something is broken.

Circuit breakers should fail safe: if the system cannot determine the account state, it should stop trading rather than guess.

Layer 3: operational safeguards

  • Kill switch: a simple, tested way to stop all trading immediately, and optionally to close positions.
  • Heartbeat and data-freshness checks: stop if market data stops updating or arrives out of order.
  • Duplicate-order protection: guard against reconnect logic re-sending the same order.
  • Restart behaviour: after a crash, reconcile open positions with the trading account before acting.

Layer 4: monitoring and alerting

You cannot manage what you cannot see. Log every decision with its inputs, and alert a person when:

  • a limit is hit;
  • an order is rejected;
  • connectivity drops;
  • behaviour deviates from expectations, such as unusual trade frequency.

Test the controls themselves

Risk controls are code, and code has bugs. Write tests that deliberately break the rules:

  • send an oversized order;
  • simulate a stale feed;
  • force a drawdown.

Confirm that each safeguard responds as designed. Repeat these tests whenever the system changes.

Keep a human in the loop

Automation should reduce manual work, not remove responsibility. Decide in advance who monitors the system, how often, and what conditions require it to be switched off. Document the answers.


This article is educational and is not financial advice. Risk controls reduce some risks but cannot eliminate losses. See our Trading Risk Disclosure.

Want to discuss this with our team?

We're happy to talk through how these ideas apply to your project.