In an automated trading setup, who is actually regulated? 

In an automated trading setup, who is actually regulated? 

 

The broker is. The API is not a person. The bot is software. Almost every misunderstanding about automated trading starts with someone assuming the protection travels further than it does. 

What does a typical automated setup consist of? 

Four components, usually owned by four different parties. A broker holding your money and executing orders. A platform or API connection through which orders are sent. A strategy, which is either code you wrote or code you bought. And often a server somewhere, rented from a fifth party, keeping the thing running while you sleep. Each of those sits in a different regulatory position, and the differences are not intuitive. Money moves through the chain. Regulatory protection does not. 

Where does FCA authorisation actually attach? 

To the firm holding your money and executing your trades. That firm needs permission to deal in investments, it has to segregate client money, it is covered by the Financial Services Compensation Scheme up to GBP 85,000 per client if it fails, and it is subject to the conduct rules. That is a real and substantial protection and it is worth having. 

It attaches to the venue. It does not attach to the decision to trade, whoever or whatever made that decision. If your strategy loses money, the broker executed your instructions correctly and there is nothing to complain about. The FSCS is a backstop against the firm collapsing, not against the strategy being wrong. 

Component  Typically regulated?  What happens if it fails you 
Broker holding your money  Yes, FCA authorised  FSCS up to GBP 85,000 if the firm fails 
Order execution  Yes, covered by conduct rules  Complaint, then the Financial Ombudsman 
API or platform bridge  Part of the broker’s service  Broker’s responsibility if theirs 
The strategy or bot itself  Generally not  Commercial dispute with the vendor, if that 
Signal or subscription seller  Usually not, unless advising  Little recourse 
VPS or hosting provider  No  A hosting contract, nothing more 

Where the regulatory perimeter sits in a typical retail automation stack. The money crosses every row. The protection covers the top three. 

 

Is selling a trading bot a regulated activity? 

Usually not, and this surprises people. Selling software that executes a rule you have chosen is generally not the same as advising you on investments or managing them on your behalf. The vendor is selling a tool. Where a firm crosses into making personal recommendations, or into managing your money at its discretion, that is a different matter and does require authorisation. 

The boundary is genuinely blurry in places, and the FCA has taken action where marketing strayed into advice. But the default position a buyer should assume is that the person who sold them an Expert Advisor is not regulated in respect of that sale, and that the performance claims in the sales page carry none of the constraints that would apply to a regulated firm’s promotions. 

What about API keys and permissions? 

This is the part with the sharpest practical consequences. Connecting a strategy to a broker means issuing credentials, and those credentials carry whatever permissions you granted. Trading permission is necessary. Withdrawal permission almost never is. A key that can move money off the platform is a key that can be abused, whether by the vendor, by someone who compromises the vendor, or by you configuring something wrongly at two in the morning. 

Grant trade permission, withhold withdrawal permission, restrict by IP address where the broker supports it, and rotate the credentials when you stop using a tool. None of that is regulatory protection. It is the ordinary discipline that has to substitute for regulatory protection in the part of the stack where there is none. Choosing a broker with granular permissions matters more than most feature comparisons suggest, and The Investors Centre is one of the sites that opens and funds live accounts with its own money to test UK trading platforms, rather than compiling rankings from providers’ published fee schedules. 

Somebody else’s key is not your key 

Take any published account of broker permissions for what it can be. Whoever writes it reports the permissions their own key was issued with, on the entity they were onboarded into, on the day they looked. Brokers revise permission sets quietly, and a professional client or a client routed through an overseas arm is often offered a different set again. So any published account of what an API allows is a snapshot of one account rather than a specification, and the useful thing to do with it is to check the same handful of items on your own key instead of assuming they carry across. 

Does the FCA regulate the strategy’s performance? 

No, and no regulator anywhere does. There is no approval process for a trading strategy, no register of validated Expert Advisors and no authority that has checked whether a backtest is honest. A firm can be impeccably authorised and still offer you access to run a strategy that loses you everything, and it has done nothing wrong. This is the gap that vendor marketing exploits, usually without lying. Phrases like works with FCA-regulated brokers are true and mean nothing about the tool. The regulated party is the broker. The claim is borrowing credibility across a boundary the regulation does not cross. 

What about crypto? 

A separate trap, and worth stating explicitly because it catches people who have otherwise done their homework. Being registered with the FCA for anti-money-laundering purposes is not the same as being authorised to conduct regulated investment business. Registered and authorised are different words describing very different things, and firms are not always eager to clarify which applies to them. 

On top of that, cryptocurrency contracts for difference have been banned for UK retail clients since 6 January 2021. An automated setup trading crypto CFDs is, for a UK retail client, trading something they are not permitted to be sold, which raises the obvious question of who exactly they are dealing with. 

The line has been redrawn before 

Crypto is also the clearest reminder that a perimeter is a moving object. The UK treatment of cryptoassets has been rewritten several times since 2019 and is being rewritten again, and the boundary between selling a tool and giving advice has been tested repeatedly and will be tested again. Anything written about where either line currently sits, this article included, is worth checking against current FCA material rather than trusted, and a piece of software that was outside the perimeter when it was sold to you does not stay outside it by right. 

What should you check before connecting anything? 

Look the broker up on the FCA register using its reference number. Names can be duplicated by clone operations and a convincing website costs nothing to build. Confirm which legal entity you would be contracting with, since a global brand may operate several. Read what permissions the API key grants and switch off the ones you do not need. And accept that the strategy itself sits outside all of it. 

That last point is the one to internalise. The regulatory question in automated trading is answered entirely at the broker layer. Everything above it is a commercial relationship in which you are on your own. 

None of that is advice about your own arrangement, and anyone running automation at meaningful size, or taking other people’s money to do it, has crossed into territory where the perimeter question stops being academic and wants a qualified answer rather than an article. For everyone else the sequence is short enough to run in an afternoon: check the register entry, confirm the legal entity, read the permissions on the key and switch off the ones you will never use, then run one small live position before you run a large one. The order matters, because every step after the first is only worth doing if the first one came back clean. 

 

 

Leave a Reply

Your email address will not be published. Required fields are marked *