Skip to main content
Finin2minCurrent Action Brief · 13 Aug 2026
SEBI & SecuritiesUpdated 5 October 2026

Broker Trading Software Change: Client Orders, Algo/API Access and UAT Evidence

By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026

SEBI's 22 June 2026 trading-software and MII IT paper is a consultation. Brokers and exchanges can nevertheless use it as a UAT-readiness benchmark for software changes, API/algo access, order integrity and rollback evidence.

Finin2min 2-Minute Summary

Do not label the draft as current circular

The consultation contains proposed IT controls; current exchange/SEBI rules continue to apply. Maintain a proposal-to-current matrix so implementation work does not accidentally cite a draft obligation as binding.

After finalisation, update only the adopted clauses.

UAT should test money-risk scenarios

Include duplicate order submission, timeout after order acceptance, stale price, exchange rejection, partial fill, session reconnect, kill switch and incorrect client mapping. A green login screen is not adequate UAT for trading software.

Compare front-end status with exchange order/trade records.

API and algo change management

Record API version, client/application identity, authentication, order-rate controls and permission scope. If an algo vendor changes logic, treat it as a model/software release requiring testing rather than a harmless configuration tweak.

Keep a rapid disable mechanism for abnormal order flow.

Release case: app shows 'failed' while exchange accepted the order

A dangerous trading-software defect occurs when the client screen reports failure after the exchange has already accepted the order. The client may retry and create a duplicate position. UAT should deliberately simulate timeout between exchange acknowledgement and front-end confirmation, then verify that order status reconciles correctly after reconnect.

The production runbook should define when to block new orders, when to issue client alerts and how to reconcile every potentially duplicated order. Technology, operations and compliance should share the same incident identifier so post-event investigation does not rely on separate logs.

Release-governance cadence

Broker technology teams should maintain a quarterly register of production releases that touched order routing, risk checks, exchange connectivity, APIs or client authentication. Select at least one high-risk release for post-implementation review: compare approved scope, incidents, rollback readiness and client complaints. This turns UAT from a pre-release ritual into a measurable control over actual trading outcomes.

Release-evidence checklist

Questions readers commonly ask

Is the June 2026 draft circular operative?

No. It is a consultation paper.

What is the most important UAT test?

End-to-end order integrity under both normal and failure scenarios.

Should API changes be treated like software releases?

Yes, especially where order permissions or logic change.

Why preserve rollback evidence?

It shows the firm can contain a faulty release and reconstruct what happened.

Official / primary sources

Disclaimer

Important: General educational and professional-reference material. Verify the current operative regulation/circular, portal version and exact facts before acting. Consultation papers are proposals unless a later operative instrument adopts them. Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.

Educational and professional reference only — not financial, tax or legal advice. Verify the current official position from the primary source before relying on any figure, rate, provision or deadline.