{"schema_version":1,"research_id":"eoa_inverse_innovation_exp05_external_evaluation_20260803","source_assessment_id":"computability_boundary_mapping__economics_finance:P5:v0","cell_id":"computability_boundary_mapping__economics_finance","search_queries":["site:sec.gov Rule 15c3-5 market access pre-trade risk management controls regulatory requirements","site:sec.gov Knight Capital 2013 inadequate risk management controls order","site:eur-lex.europa.eu 2017/589 RTS 6 algorithmic trading pre-trade controls kill functionality","site:nasdaqtrader.com pre trade risk management controls order gateway","site:fca.org.uk algorithmic trading controls review pre trade controls 2025","Schneider Enforceable Security Policies 2000 PDF runtime monitor safety properties","Ligatti Bauer Walker edit automata runtime enforcement paper PDF","site:iosco.org principles direct electronic access pre-trade controls automated trading","site:cftc.gov spoofing intent to cancel before execution interpretive guidance official","site:cftc.gov disruptive trading practices spoofing final interpretive guidance 2013 pdf","site:finra.org algorithmic trading pre trade controls best practices official notice","Enforceable Security Policies Revisited Basin Juge Klaedtke Zalinescu publication date ACM TISSEC"],"sources":[{"source_id":"S1","title":"Risk Management Controls for Brokers or Dealers With Market Access","publisher":"U.S. Securities and Exchange Commission","url":"https://www.sec.gov/rules-regulations/2011/06/risk-management-controls-brokers-or-dealers-market-access","source_class":"GOVERNMENT_OR_REGULATOR","publication_date":"2010-11-03","accessed_at":"2026-08-03","claims_supported":["Rule 15c3-5 requires documented controls reasonably designed to prevent specified erroneous, excessive, restricted, or noncompliant orders before market entry.","The broker-dealer with market access generally retains direct and exclusive control and must regularly review control effectiveness."]},{"source_id":"S2","title":"SEC Charges Knight Capital With Violations of Market Access Rule","publisher":"U.S. Securities and Exchange Commission","url":"https://www.sec.gov/newsroom/press-releases/2013-222","source_class":"GOVERNMENT_OR_REGULATOR","publication_date":"2013-10-16","accessed_at":"2026-08-03","claims_supported":["Inadequate safeguards allowed millions of erroneous orders to enter markets during the Knight Capital incident.","Knight sent more than four million orders, traded more than 397 million shares, and incurred a loss exceeding $460 million.","The SEC identified missing immediately-pre-submission controls, weak deployment/testing controls, and inadequate review."]},{"source_id":"S3","title":"Commission Delegated Regulation (EU) 2017/589 (RTS 6)","publisher":"European Union, EUR-Lex","url":"https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32017R0589","source_class":"GOVERNMENT_OR_REGULATOR","publication_date":"2017-03-31","accessed_at":"2026-08-03","claims_supported":["RTS 6 requires specified pre-trade controls, testing, kill functionality, real-time alerts, automated market-manipulation surveillance, records, and business-continuity arrangements.","Pre-trade controls operate before venue submission, while market-abuse surveillance remains a separate alert-and-investigation function.","Firms retain responsibility for testing their algorithmic systems and must cover all trading activity in surveillance."]},{"source_id":"S4","title":"Multi-firm review of algorithmic trading controls: high-level observations","publisher":"UK Financial Conduct Authority","url":"https://www.fca.org.uk/publications/multi-firm-reviews/algorithmic-trading-controls-high-level-observations","source_class":"GOVERNMENT_OR_REGULATOR","publication_date":"2025-08-21","accessed_at":"2026-08-03","claims_supported":["The FCA identifies algorithmic-trading controls as a supervisory priority and says controls must keep pace with market speed and complexity.","The review found deficiencies in governance, documentation, testing sophistication, control ownership, compliance oversight, and surveillance investment.","Many firms already prevent orders from leaving an internal gateway when pre-trade controls are breached, while conduct risk is often handled more heavily through post-trade surveillance."]},{"source_id":"S5","title":"NASDAQ Announces Pre-Trade Risk Management Enhanced Product Suite","publisher":"Nasdaq","url":"https://www.nasdaqtrader.com/TraderNews.aspx?id=hta2008-002","source_class":"COMMERCIAL_FIRST_PARTY","publication_date":"2008-01-08","accessed_at":"2026-08-03","claims_supported":["Nasdaq offered port-level validation of orders before admission to its matching system.","The product applies configurable price, order, exposure, and aggregate checks, rejects out-of-parameter flow, and supplies defined rejection reasons.","Nasdaq reported benchmarked, very low latency for configurations ranging from basic fat-finger checks to aggregate checks."]},{"source_id":"S6","title":"Enforceable Security Policies Revisited","publisher":"Association for Computing Machinery / ETH Zurich","url":"https://ethz.ch/content/dam/ethz/special-interest/infk/inst-infsec/information-security-group-dam/research/publications/pub2012/basin-tissec13.pdf","source_class":"PRIMARY_RESEARCH","publication_date":"2013-06","accessed_at":"2026-08-03","claims_supported":["Runtime enforcement depends on whether relevant actions are observable and controllable and whether compliance can be decided from the trace prefix.","A monitor can prevent a violation only when it intercepts a controllable action before execution and its compliance check terminates.","The paper supplies necessary and sufficient enforceability conditions and reports decidability and complexity results for restricted policy languages."]},{"source_id":"S7","title":"2026 FINRA Annual Regulatory Oversight Report: Market Access Rule","publisher":"Financial Industry Regulatory Authority","url":"https://www.finra.org/rules-guidance/guidance/reports/2026-finra-annual-regulatory-oversight-report/market-access-rule","source_class":"OFFICIAL_GUIDANCE","publication_date":"2025-12","accessed_at":"2026-08-03","claims_supported":["FINRA continues to identify insufficient, fragmented, poorly documented, or improperly excluded pre-trade controls.","Effective practices include systemic hard blocks, tailored controls, aggregate assessment, documented reviews, and verification that blocks work.","FINRA identifies firms with market access as responsible for protecting firm condition, market participants, market integrity, and financial stability."]},{"source_id":"S8","title":"Antidisruptive Practices Authority: Interpretive Guidance and Policy Statement","publisher":"U.S. Commodity Futures Trading Commission","url":"https://www.cftc.gov/LawRegulation/FederalRegister/FinalRules/2013-12365.html","source_class":"GOVERNMENT_OR_REGULATOR","publication_date":"2013-05-28","accessed_at":"2026-08-03","claims_supported":["The statutory spoofing prohibition concerns bidding or offering with intent to cancel before execution.","The CFTC interprets spoofing as requiring intent or scienter beyond recklessness and does not treat accidental or negligent activity as spoofing.","Intent-dependent misconduct therefore cannot be equated with a purely mechanical forbidden order prefix without changing the legal rule."]}],"problem_evidence":{"support":"MODERATE","rationale":"Serious failures of automated order generation and incomplete controls are directly visible: Knight Capital caused major market disruption and loss, and the 2025 FCA and 2026 FINRA materials identify continuing weaknesses in testing, ownership, documentation, aggregation, and surveillance. However, no searched source documents the proposal's narrower asserted practice of an exchange issuing a universal SAFE_STRATEGY label after a timed-out analyzer or bounded replay. The externally verified problem is therefore control failure and overreliance on incomplete testing, not the prevalence of the exact computability-category error.","source_ids":["S2","S4","S7"]},"stakeholder_evidence":{"support":"STRONG","rationale":"Identifiable adopters and authorizers exist. Rule 15c3-5 places responsibility and generally direct control with the broker-dealer providing market access; RTS 6 places testing, control, surveillance, and continuity duties on investment firms; FCA and FINRA expressly call for stronger controls. A broker market-access risk/compliance authority is the clearest adopter, with an exchange gateway operator also plausible subject to its rule and governance processes.","source_ids":["S1","S3","S4","S7"]},"prior_art":{"proximity":"SUBSTANTIAL_COLLISION","closest_analogues":[{"name":"Rule 15c3-5 systemic pre-trade market-access controls","similarity":"Already requires automated controls positioned to prevent specified orders before market entry, retained under the authority of the market-access broker.","remaining_difference":"It is a reasonableness-based regulatory framework, not a proved finite-state conduct-rule compiler with explicit formal-fragment and failure labels.","source_ids":["S1","S7"]},{"name":"Nasdaq Pre-Trade Risk Management","similarity":"Already performs port-level runtime interception, stateful or aggregate checking, order rejection, and machine-readable reject reasons before matching.","remaining_difference":"The disclosed product centers on configurable risk parameters and aggregates; the source does not establish arbitrary versioned finite-state conduct rules, proof artifacts, exhaustive compilation validation, or the proposal's label taxonomy.","source_ids":["S5"]},{"name":"EU RTS 6 pre-trade controls and automated surveillance","similarity":"Combines mandatory pre-trade blocking controls, kill functions, real-time monitoring, manipulation surveillance, testing, and continuity requirements.","remaining_difference":"It separates fixed pre-trade limits from alert-based market-abuse surveillance and does not claim that all conduct obligations can be enforced synchronously at the gateway.","source_ids":["S3","S4"]},{"name":"Execution-monitor enforcement of safety policies","similarity":"Formal research already characterizes runtime enforcement through prefix inspection, controllable actions, terminating checks, and restricted specification languages.","remaining_difference":"The paper is domain-general and does not demonstrate a trading-gateway implementation, legal-rule compilation, complete venue mediation, recovery behavior, or production latency.","source_ids":["S6"]}],"distinctive_claim_remaining":"The remaining testable claim is not that pre-trade runtime blocking is new. It is that, for an enforceable finite-state subset of mechanically defined order-conduct rules, a versioned compiler and completely mediating gateway monitor can provide a checked trace-level invariant, prefix witnesses, explicit out-of-fragment/failure labels, and better sequential-rule coverage than ordinary scalar or aggregate pre-trade controls without implying whole-strategy or intent compliance. No source establishes that combined trading-specific implementation.","confidence":"HIGH"},"implementation_evidence":{"support":"MODERATE","rationale":"Technical plausibility is supported by deployed low-latency port-level controls and formal results for enforcement of decidable prefix properties over controllable actions. Regulatory materials support pre-trade interception, testing, recordkeeping, and continuity workflows. Feasibility remains conditional on lossless event normalization, atomic and persistent monitor state, complete routing coverage, acceptable tail latency, rule-compilation fidelity, recovery correctness, and legal review. Intent-based spoofing and cross-venue or future-effect rules are outside the mechanically enforceable fragment. None of the sources validates the proposed compiler or complete-mediation architecture in a production gateway.","source_ids":["S1","S3","S5","S6","S8"]},"scores":{"meaningful_impact":{"score":4,"rationale":"Order-control failures can cause rapid, market-wide harm and very large losses; a correctly scoped preventive control could materially reduce exposure, although realized impact is unmeasured.","source_ids":["S2","S7"]},"stakeholder_pull":{"score":5,"rationale":"Regulators and SROs expressly require or prioritize robust pre-trade controls, testing, surveillance, accountability, and documentation.","source_ids":["S1","S3","S4","S7"]},"incremental_advantage":{"score":3,"rationale":"Formal sequential rules, checked compilation, witnesses, and honest failure labels could improve on conventional thresholds, but port-level blocking and aggregate stateful checks are long-established.","source_ids":["S3","S5","S6","S7"]},"distinctiveness_plausibility":{"score":3,"rationale":"The combined formal-governance package is plausibly distinguishable, but its two foundations—runtime enforcement and gateway pre-trade blocking—already have substantial prior art.","source_ids":["S5","S6"]},"technical_implementability":{"score":4,"rationale":"Finite-state monitors with total transitions are technically credible and low-latency pre-trade systems exist; production correctness, complete mediation, persistence, and recovery still require testing.","source_ids":["S3","S5","S6"]},"adoption_authority_feasibility":{"score":4,"rationale":"Market-access brokers and regulated investment firms already possess control duties and authority. Production deployment would still require internal compliance, operations, continuity, and possibly venue or regulatory change processes.","source_ids":["S1","S3","S4"]},"evidence_readiness":{"score":3,"rationale":"A small synthetic exhaustive exercise is well bounded and needs no customer data, but no compiler, proof, benchmark, or gateway integration evidence is presently supplied.","source_ids":["S3","S6"]},"safety_net_benefit":{"score":4,"rationale":"Per-event blocking can prevent an in-scope bad prefix before market entry and produce a witness, but false blocks, stale state, fail-closed outages, and misplaced confidence create material operational risks.","source_ids":["S2","S3","S5"]},"scalability":{"score":3,"rationale":"Finite-state evaluation can scale per event, but rule/state growth, cross-account context, multiple venues, schema variation, high availability, and repeated reverification limit straightforward diffusion.","source_ids":["S3","S5","S6"]}},"score_confidence":"MODERATE","costs":{"first_evidence":{"band_2026_usd":"50K_TO_250K","scope":"Synthetic mirror-only proof-of-concept: rule grammar, four rules, compiler, reference monitor, proof obligations, exhaustive traces through length six, witness checker, fault tests, benchmark harness, and independent review.","confidence":"MODERATE","assumptions":["Approximately three to six specialist person-months plus independent formal-methods review.","Synthetic events only; no proprietary gateway, live feed, participant account, or production certification.","Resource-equivalent estimate, not a vendor quote."],"source_ids":["S3","S6"]},"initial_deployment_startup":{"band_2026_usd":"1M_TO_5M","scope":"One broker or venue integration including event normalization, durable state, gateway interception, rule governance, audit logs, redundancy, security review, legal mapping, and continuity design.","confidence":"LOW","assumptions":["One venue or broker gateway and a small initial rule set.","Several engineering, formal-methods, SRE, compliance, legal, and operations contributors over roughly 9–18 months.","Existing gateway and observability infrastructure can be extended rather than replaced.","No public source among the eight provides implementation pricing."],"source_ids":["S1","S3","S5"]},"operational_launch":{"band_2026_usd":"1M_TO_5M","scope":"Production-readiness phase covering independent validation, conformance and stress testing, shadow operation, disaster recovery, operator training, approvals, staged rollout, and rollback exercises.","confidence":"LOW","assumptions":["Launch is separate from initial software construction.","High-availability testing and business-continuity approval are mandatory scope.","Rollout remains limited to one organization and a bounded rule fragment."],"source_ids":["S3","S4"]},"annual_recurring":{"band_2026_usd":"1M_TO_5M","scope":"Ongoing high-availability operations, monitoring, incident response, rule/compiler maintenance, schema and gateway change review, periodic independent verification, surveillance handoffs, and continuity exercises.","confidence":"LOW","assumptions":["Continuous production support for a market-critical gateway.","Every material schema, rule, compiler, state, or routing change triggers review and selective reverification.","Estimate excludes exchange-wide replacement of existing gateway infrastructure and regulatory enforcement staffing."],"source_ids":["S3","S4","S7"]}},"verified_pipeline_gates":{"externally_supported_problem":{"status":"YES","reason":"Official enforcement and current supervisory reviews demonstrate consequential automated-order failures and continuing deficiencies in algorithmic controls, although the exact SAFE_STRATEGY-by-timeout behavior is not documented.","source_ids":["S2","S4","S7"]},"externally_credible_adopter_or_authorizer":{"status":"YES","reason":"Broker-dealers with market access and regulated investment firms are identifiable duty holders with authority over pre-trade controls; regulators and SROs express the need.","source_ids":["S1","S3","S4","S7"]},"distinct_testable_incremental_claim":{"status":"YES","reason":"The proposal can be tested against existing scalar/aggregate controls for exact in-fragment sequential-rule enforcement, witness correctness, label preservation, and complete mediation without asserting whole-strategy legality.","source_ids":["S3","S5","S6","S8"]},"bounded_next_evidence_step":{"status":"YES","reason":"A finite event alphabet, four rules, complete traces through length six, synthetic strategies, explicit comparators, independent review, and enumerated falsifiers bound the next exercise.","source_ids":["S3","S5","S6"]},"no_unresolved_safety_or_authority_stop":{"status":"YES","reason":"The authorized first step can remain synthetic and mirror-only, with no live transmission, blocking, participant decision, or legal-conduct determination. Production fail-closed authority remains explicitly outside this step.","source_ids":["S1","S3","S8"]},"credible_cost_scope_and_range":{"status":"UNCERTAIN","reason":"Four broad resource-equivalent ranges can be scoped bottom-up, but the eight sources provide no directly comparable development, integration, certification, or operating-cost data.","source_ids":["S3","S4","S5"]}},"next_evidence_step":"Run a mirror-only synthetic exercise with no live orders or accounts: at most five normalized event types, all traces through length six, four independently specified finite-state safety rules, and eight synthetic strategies. Compare (A) the compiled stateful monitor, (B) a Nasdaq-like scalar/aggregate threshold baseline, and (C) pre-deployment replay or bounded analysis. Require a separately implemented reference interpreter and witness checker, independent review of the rule semantics and compiler, exhaustive acceptance-table comparison, state-loss/restart tests, deliberate bypass-path tests, label-propagation tests, and p50/p99/p99.99 latency and throughput measurements against a predeclared budget. Falsify the claim upon any accepted in-fragment forbidden prefix, rejected permitted prefix, nonterminating transition, compiler/reference disagreement, invalid witness, unmediated outbound path, fail-open state loss, collapsed OUT_OF_FRAGMENT or MONITOR_FAILURE label, or inability to restore consistent state. Treat latency-budget failure as an operational—not computability—falsifier.","blocking_evidence":["No external source demonstrates that exchanges or brokers currently make the exact unrestricted universal SAFE_STRATEGY claim attributed to the baseline.","No implementation, formal rule grammar, compiler, monitor proof, or independent proof review is supplied.","No evidence establishes complete observation and mediation across actual gateway, recovery, drop-copy, account, or venue paths.","No comparative evidence shows an advantage over existing configurable and aggregate pre-trade controls.","No production latency, capacity, race, persistence, or state-restoration measurements exist.","No adopter has validated which real conduct rules fit the finite-prefix fragment or accepted the proposed continuity policy.","Intent-dependent, cross-venue, future-effect, and other legally contextual conduct requirements cannot be inferred from the monitored prefix alone.","The cost ranges lack externally published comparable-project or vendor pricing."],"research_disposition":"PARTNERED_RESEARCH_PROGRAM","world_novelty_boundary":"The search establishes substantial prior art for pre-trade gateway blocking, aggregate controls, runtime policy enforcement, and finite-state enforceability analysis. It does not establish whether the proposed combination of a trading-conduct rule fragment, checked compiler, complete mediation, prefix witnesses, and explicit boundary labels has previously been implemented or published. World novelty, patentability, freedom to operate, market size, realized impact, and production economics remain unmeasured.","arm":"COMPLETE_PROPOSAL_PORTFOLIO","candidate_version":0,"controller_recommendation":{"action":"STOP_EMPIRICAL_RESEARCH_NEEDED","repairable":false,"material_progress_observed":false,"progress_targets":["Obtain a named broker or exchange market-access sponsor and a signed synthetic mirror-only evaluation charter defining rule ownership, latency budget, continuity constraints, and prohibited inferences.","Produce the formal rule grammar, compiler, reference semantics, monitor invariant, reduction artifact, assumption register, and independent review record.","Complete the bounded comparator exercise and publish the exhaustive trace table, counterexamples, witness checks, bypass and recovery results, and latency distribution.","Demonstrate a material sequential-rule coverage or assurance advantage over existing scalar and aggregate pre-trade controls without increasing false blocks beyond a predeclared tolerance.","Document which candidate conduct rules are genuinely prefix-observable and controllable and route intent, cross-venue, liveness, and future-effect requirements outside the enforcement claim.","Develop a sourced or partner-validated production cost model for gateway integration, high availability, reverification, and continuing operations."],"reason":"Web research establishes a material problem, credible duty holders, technical plausibility, and substantial collision with established pre-trade control practice. It cannot determine whether the remaining formalized sequential-rule package works, mediates every path, meets latency and recovery requirements, improves on existing controls, or is accepted by an adopter. Those questions require building artifacts, proprietary workflow engagement, and controlled testing; under the controller rule this requires an empirical-research stop, which is non-repairable within bounded web research."},"proposal_index":5}