# Risk Controls and Kill Switches

> Pre trade risk checks and kill switches stop a trading algorithm before a bug becomes a disaster. Learn the essential limits, how to layer them and how to test them.

Source: https://learn.tradelabsai.com/algo-trading/risk-controls-and-kill-switches/  
Track: Algorithmic Trading · Level: Intermediate · Updated: 2026-10-03  
Publisher: TradeLabs AI (https://tradelabsai.com). Education, not financial advice.  
Cite as: TradeLabs Learn, "Risk Controls and Kill Switches", https://learn.tradelabsai.com/algo-trading/risk-controls-and-kill-switches/

An algorithm can send thousands of orders before a human notices anything is wrong. Risk controls are automatic checks that sit between the strategy and the market, blocking orders that break predefined limits. A kill switch is the emergency brake: a way to stop all trading, cancel open orders and, if needed, flatten positions immediately. Regulators require broker dealers to have such controls; in the US, the SEC's Market Access Rule (Rule 15c3-5) requires firms with market access to have pre trade risk controls. Individual traders running bots need the same thinking on a smaller scale.

## Layers of protection

| Layer | Who runs it | Examples |
|---|---|---|
| Strategy level | Your own code | Position limits, signal sanity checks |
| System level | Your order gateway | Order size, rate and daily loss limits |
| Broker level | Your broker | Buying power checks, credit limits |
| Exchange level | The exchange | Price bands, limit up and limit down, circuit breakers. See [Trading Halts and Circuit Breakers](https://learn.tradelabsai.com/markets/trading-halts/) |

Never rely on only one layer. Your own controls should trigger well before the broker's.

## Essential pre trade checks

| Check | Blocks |
|---|---|
| Maximum order size | Fat finger errors, such as 10,000 shares instead of 100 |
| Maximum position | Runaway accumulation from repeated orders |
| Price collar | Orders far from the current market price |
| Order rate limit | Loops that send orders too fast |
| Daily loss limit | Continued trading after large losses. See [Maximum Trade Risk and Daily Loss Limits](https://learn.tradelabsai.com/risk/daily-loss-limit/) |
| Gross and net exposure | Too much total risk |
| Duplicate order detection | Repeated identical orders within seconds |
| Allowed instruments | Trading symbols the strategy should never touch |
| Stale data check | Trading on prices that stopped updating |

## Designing a kill switch

A good kill switch:

- **Is fast:** one command or button, no navigation.
- **Works when the strategy is broken:** it runs separately from the strategy code.
- **Cancels all open orders first,** then optionally closes positions.
- **Blocks restart** until a human reviews and re-enables trading.
- **Triggers automatically** on breaches such as the daily loss limit or a rate limit.
- **Logs everything** for later review. See [Logging, Audit Trails and Incident Response](https://learn.tradelabsai.com/algo-trading/audit-trails/).

**Example: A loop caught by a rate limit**
A trader's bot has a bug: after a partial fill, it thinks the order failed and resends the full order every second. Without controls, the bot would buy 100 shares per second until buying power ran out. With controls, the order rate limit (no more than 5 orders per 10 seconds) triggers after the sixth attempt, the maximum position check would have blocked orders above 300 shares anyway, and the automatic kill switch cancels open orders and halts the bot. The trader receives an alert, finds the bug and loses only the slippage on the extra shares bought.

## Setting limit levels

| Limit | Starting point |
|---|---|
| Order size | No larger than the biggest order the strategy should ever send |
| Position | Slightly above the maximum intended position |
| Daily loss | A level that matches your risk plan, such as 2% to 3% of the account |
| Price collar | A few percent from the last price for liquid stocks; wider for volatile assets |
| Order rate | Well above normal activity but far below runaway levels |

Review limits regularly and whenever the strategy or account size changes. See [Risk, Position, Loss and Drawdown Limits](https://learn.tradelabsai.com/portfolio/risk-limits/).

## Testing the controls

Controls that are never tested may fail when needed. Test them in a paper or test environment by deliberately sending orders that should be blocked, simulating a loss breach and pressing the kill switch. Repeat after every major code change.

## Lessons from Knight Capital

In August 2012, Knight Capital lost about $440 million in roughly 45 minutes after a faulty deployment. The SEC later found that Knight lacked adequate controls to prevent erroneous orders and did not have procedures to respond quickly. The firm was fined $12 million under the Market Access Rule. Strong pre trade limits and a fast kill switch could have reduced the damage. See [Lessons From Market Failures](https://learn.tradelabsai.com/history/lessons-from-market-failures/).

## Frequently asked questions

### What is a kill switch in trading?

An emergency control that immediately stops an algorithm, cancels its open orders and can close its positions.

### What risk controls should a trading bot have?

At minimum: maximum order size, maximum position, price collars, order rate limits, a daily loss limit, stale data checks and a kill switch.

### Do brokers provide risk controls?

Yes, brokers run their own checks, but they are usually loose. Your own controls should be tighter and trigger first.

Next, learn how to move a strategy safely from testing to real money in [From Backtest to Live: Paper, Shadow and Canary](https://learn.tradelabsai.com/algo-trading/backtest-to-live/).

## Continue learning

- Next lesson: [From Backtest to Live: Paper, Shadow and Canary](https://learn.tradelabsai.com/algo-trading/backtest-to-live/)
- Previous lesson: [Developing, Testing and Monitoring Algorithms](https://learn.tradelabsai.com/algo-trading/algorithm-development/)
- Related: [Developing, Testing and Monitoring Algorithms](https://learn.tradelabsai.com/algo-trading/algorithm-development/): A step by step process for developing a trading algorithm, from idea and specification to coding, testing, review and staged deployment with real controls.
- Related: [Risk, Position, Loss and Drawdown Limits](https://learn.tradelabsai.com/portfolio/risk-limits/): Risk limits turn a risk policy into hard rules on position size, exposure, daily loss and drawdown. Learn how to set them, enforce them and avoid mistakes.
- Related: [Automated vs Semi-Automated Trading](https://learn.tradelabsai.com/algo-trading/automated-trading/): Automated trading systems place and manage orders without manual input. Learn levels of automation, platforms, what to automate first and the safeguards.
- Related: [Monitoring Positions, P&L and Risk](https://learn.tradelabsai.com/algo-trading/live-monitoring/): Running algorithms need constant monitoring. Learn the key health, trading and risk metrics to track, how to design useful alerts and how to avoid alert fatigue.
- Related: [Alerts, Error Handling and Reconnection](https://learn.tradelabsai.com/algo-trading/error-handling/): Trading systems face rejected orders, disconnects, bad data and partial fills. Learn how to classify errors, retry safely, use idempotent orders and fail closed.
- Related: [Operational and Model Risk](https://learn.tradelabsai.com/portfolio/operational-and-model-risk/): Operational risk comes from failed processes, people and systems; model risk from wrong or misused models. Learn real examples and the key controls.
