SEC Rule 15c3-5 (Market Access Rule): A 2026 Compliance Guide for Broker-Dealers
What SEC Rule 15c3-5 requires in 2026 — pre-trade risk controls, financial and regulatory checks, direct market access oversight, annual CEO certification, and the technology choices that make compliance defensible.
*A plain-English guide to the SEC Market Access Rule for broker-dealers, prop firms, and fintechs providing or consuming market access in 2026.*
If your firm sends orders to a US exchange or ATS — or lets a client do so through your MPID — you live under SEC Rule 15c3-5, the Market Access Rule. It is the single most important pre-trade control regulation for broker-dealers, and the SEC has made clear through recent enforcement actions that "we outsourced the checks" is not a defense. This guide explains what the rule requires, where firms most often fall short in 2026, and how to build a control stack that holds up to examination.
What is SEC Rule 15c3-5?
SEC Rule 15c3-5, adopted in 2010 and known as the Market Access Rule, requires any broker-dealer with market access — or that provides market access to customers — to establish, document, and maintain a system of risk management controls and supervisory procedures reasonably designed to manage the financial, regulatory, and operational risks of that access. The controls must be applied on a pre-trade, automated basis and be under the direct and exclusive control of the broker-dealer.
In practice, that means every order routed to an exchange or ATS must pass through the broker-dealer's own risk layer before it reaches the market — not a client's, not a vendor's, not a downstream broker's.
Who does the Market Access Rule apply to?
The rule reaches further than many firms assume:
- Broker-dealers trading for their own account—on an exchange or ATS.
- Broker-dealers providing customer market access—, including sponsored access, direct market access (DMA), and access provided to another broker-dealer.
- Introducing brokers—whose orders are routed through a clearing firm's MPID — both the introducing and clearing broker have obligations.
- Prop trading firms operating as broker-dealers—and any registered entity that touches an exchange or ATS in the routing chain.
If an order carries your MPID to a market, Rule 15c3-5 applies to you.
The four categories of required controls
The rule groups obligations into four buckets. A defensible program addresses all four, pre-trade and automated where the rule demands it.
1. Financial risk controls
Pre-trade, automated checks designed to prevent the entry of orders that exceed appropriate credit or capital thresholds, or that appear to be erroneous. In 2026, examiners expect to see, at a minimum:
- Credit and capital limits—per customer, per desk, and firm-wide, enforced before the order leaves.
- Buying power and margin checks—including real-time Reg-T and portfolio-margin awareness for accounts that qualify.
- Fat-finger and erroneous-order controls—: price collars against the NBBO, maximum order size and notional, and duplicate-order detection.
- Kill-switch capability—at the customer, strategy, and firm level, tested regularly.
2. Regulatory risk controls
Pre-trade checks that prevent orders that would violate regulatory requirements. This includes short-sale marking and locate compliance under Reg SHO, restricted-list and watch-list enforcement, Rule 15c3-5's own market-wide protections (e.g., preventing orders that would breach exchange or trading-halt restrictions), and controls to prevent access by unauthorized persons.
3. Post-trade surveillance and supervisory procedures
Documented written supervisory procedures (WSPs) that describe how the controls are set, changed, monitored, and reviewed; a supervisory chain accountable for market access; and post-trade surveillance that detects manipulative activity (spoofing, layering, marking the close, wash trades) and feeds exceptions back into control tuning.
4. Annual review and CEO certification
At least annually, the broker-dealer must conduct a documented review of the effectiveness of its market-access controls, and the CEO must certify in writing that the risk management controls and supervisory procedures comply with Rule 15c3-5. The certification is not a formality — it is a personal attestation reviewed in exams and enforcement actions.
"Direct and exclusive control": the phrase that trips firms up
The rule's most consequential phrase is that the required controls must be under the direct and exclusive control of the broker-dealer with market access. Two patterns still get firms in trouble:
- Delegating checks to a customer or sub-broker.—Allowing a sophisticated client, a downstream broker, or an unaffiliated technology vendor to set or bypass your limits is not permitted, even by written agreement.
- Using vendor risk controls without owning them.—A broker-dealer may use third-party technology to implement its controls — but the parameters, monitoring, and ability to modify them in real time must sit with the broker-dealer. If your vendor is the only party that can change a limit, you do not have direct and exclusive control.
A narrow reasonable allocation to a customer is permitted only in specific circumstances (typically another registered broker-dealer with its own 15c3-5 obligations, meeting the SEC's staff guidance) and must be documented in writing.
Where firms most often fall short in 2026
Recent enforcement and exam priorities point to a consistent set of gaps:
- Static limits that never get retuned.—Credit and size limits set at onboarding and never revisited as the client's activity, capital, or strategy changes.
- Controls that are pre-trade in name only.—Checks that run after the order has been acknowledged by the exchange, or that can be bypassed by a "manual" route.
- Weak erroneous-order controls.—Missing price collars, no notional cap, or thresholds so wide they never fire.
- Kill switches that have never been tested—end-to-end under production conditions.
- Incomplete audit trail.—Inability to reconstruct exactly which limits were in force when a given order was accepted or rejected.
- Reg SHO integration gaps.—Short-sale marking and locate evidence held in a separate system that the pre-trade layer cannot see in time.
- CEO certification without underlying evidence.—An annual sign-off that is not backed by a documented, testable review.
How to build a defensible 15c3-5 stack
A modern, exam-ready Market Access Rule program has five layers:
- 1. A single pre-trade risk gateway that every order must traverse — no side doors, no manual bypass. Limits are enforced at wire speed and denials are logged with reason codes.
- 2. Real-time capital, buying-power, and margin awareness, including native Reg-T for equities and options and portfolio-margin support where relevant, so limits reflect actual exposure rather than yesterday's snapshot.
- 3. Regulatory checks in the same path — Reg SHO marking and locate validation, restricted lists, trading-halt awareness — so a single "accept" decision covers both financial and regulatory risk.
- 4. Immutable audit and monitoring. Every accepted and rejected order, with the exact limit set in force at the time, captured in a tamper-evident log and surfaced in a supervisor-facing dashboard that also drives post-trade surveillance.
- 5. A governed change process. Documented WSPs, role-based access to limit changes, four-eyes approval for material changes, tested kill switches, and an annual review package that supports the CEO certification with evidence.
Rule 15c3-5 quick reference
| Obligation | What it requires | Pre-trade? |
|---|---|---|
| Financial risk controls | Credit, capital, buying power, margin, size, price, erroneous-order checks | Yes |
| Regulatory risk controls | Reg SHO, restricted lists, trading-halt and market-wide protections, authorized access | Yes |
| Direct and exclusive control | Controls set, monitored, and modifiable only by the broker-dealer | Yes |
| Supervisory procedures | Written WSPs, accountable supervisors, documented processes | Ongoing |
| Post-trade surveillance | Detection of manipulation and control-effectiveness feedback | Post-trade |
| Annual review + CEO certification | Documented effectiveness review; written CEO attestation | Annual |
How Gato Systems supports Rule 15c3-5 compliance
Gato Systems' modular platform maps directly onto the four control categories. gPrecision is a wire-speed pre-trade risk engine with native Reg-T margin, real-time buying power, configurable price, size, and notional collars, and firm-wide and per-account kill switches — the "single gateway every order must traverse" the rule contemplates. gHub provides the broker-independent FIX connectivity and order-routing layer so those controls sit in the actual order path, not beside it. gNexus centralizes supervisory dashboards, exception workflows, and the evidence trail that supports annual review and CEO certification, while gReg handles the downstream CAT and CAIS reporting fed by the same audit-quality data.
The design principle is exactly the one the rule demands: the broker-dealer keeps direct and exclusive control, with the technology configured to its risk appetite rather than the other way around.
The bottom line
SEC Rule 15c3-5 is no longer a checkbox — it is the operational backbone of every broker-dealer that touches a US market. Firms that treat it as a pre-trade engineering problem, backed by documented governance and an evidence-rich annual review, come out of exams with credit to spare. Firms that treat it as paperwork learn about it the hard way.
Frequently Asked Questions
What is SEC Rule 15c3-5?
SEC Rule 15c3-5, known as the Market Access Rule, requires any broker-dealer with market access — or providing market access to customers — to maintain automated, pre-trade risk management controls and written supervisory procedures reasonably designed to manage the financial, regulatory, and operational risks of that access. The controls must be under the direct and exclusive control of the broker-dealer.
Who does the Market Access Rule apply to?
It applies to any broker-dealer that trades on an exchange or ATS for its own account, provides customer market access (including sponsored access and direct market access), or routes orders under its MPID on behalf of another firm. Introducing and clearing brokers both have obligations, and prop trading firms registered as broker-dealers are covered.
What pre-trade controls does Rule 15c3-5 require?
At a minimum: credit and capital limits per customer, desk, and firm-wide; buying power and margin checks (including Reg-T where applicable); erroneous-order controls such as price collars, maximum order size, and notional caps; duplicate-order detection; kill-switch capability; and regulatory checks including Reg SHO marking, locate compliance, restricted lists, and trading-halt awareness. All must run pre-trade and automatically.
What does 'direct and exclusive control' mean under Rule 15c3-5?
It means the broker-dealer with market access must be the party that sets, monitors, and can modify the risk controls in real time. Delegating limits to a customer or downstream broker is not permitted, and using a third-party vendor is only acceptable if the broker-dealer — not the vendor — controls the parameters. A narrow reasonable allocation to another registered broker-dealer with its own 15c3-5 obligations is permitted under SEC staff guidance and must be documented in writing.
Does Rule 15c3-5 require a CEO certification?
Yes. The broker-dealer must conduct a documented annual review of the effectiveness of its market-access controls, and the CEO (or equivalent officer) must certify in writing that the risk management controls and supervisory procedures comply with Rule 15c3-5. Examiners expect the certification to be backed by evidence — testing results, exception reports, and change logs — not just a signature.
How is Rule 15c3-5 different from FINRA supervisory rules?
Rule 15c3-5 is an SEC rule specifically about market access — it mandates pre-trade, automated controls that sit in the order path. FINRA rules such as 3110 (Supervision) impose broader supervisory obligations across a member's business. In practice they overlap: the WSPs, escalation, and post-trade surveillance a firm builds for 15c3-5 typically live inside its FINRA 3110 supervisory framework.
What technology do broker-dealers need to comply with the Market Access Rule?
A pre-trade risk gateway every order must traverse, with real-time capital and margin awareness, configurable financial and regulatory checks (including Reg SHO), tested kill switches, immutable audit logging, supervisor dashboards, and a governed change process. Gato Systems addresses this with gPrecision (pre-trade risk with native Reg-T and buying power), gHub (FIX connectivity so the controls sit in the actual order path), gNexus (supervisory dashboards and evidence for annual review), and gReg (downstream CAT and CAIS reporting from the same audit-quality data).
See how Gato handles risk & compliance in production
Book a working session with our team. We walk through your venues, volumes, and reporting obligations on a live environment — no slideware.
Topics covered in this article
Related Gato modules
The platform components that handle the workflows covered in this article.
