Trading Manually When The System Is Down
The backup procedures a desk falls back on when its automated execution or order management system fails mid-day, so positions can still be managed by phone or a backup terminal.
Automated trading systems fail — a connectivity drop, a bad software deploy, an exchange outage, a bug that starts sending malformed orders — and when they do, a desk cannot simply stop managing risk until the system is fixed. Manual fallback procedures are the pre-agreed playbook for that moment: who gets paged, which backup terminal or broker phone line takes over, and what the trader is authorized to do without the usual automated checks running underneath them.
In practice this usually means a trader switching to a broker's manual voice-trading desk or a simplified backup GUI, working from a known snapshot of current positions (since the primary system may not be trustworthy for live position data anymore), and following strict, pre-approved limits on size and instrument scope until the primary system is confirmed healthy again. Firms rehearse this with periodic fire drills specifically so the first time someone executes the manual procedure isn't during an actual live-market emergency with real risk on the book.
The core discipline is knowing, in advance, exactly which positions must be hedged or flattened manually if the automated system can't be trusted, rather than deciding that under time pressure. A desk that has never tested its manual fallback path typically discovers, in the middle of an actual outage, that some critical piece — an updated contact list, a broker credential, a position reconciliation step — was quietly out of date.
Manual fallback procedures are the rehearsed, pre-agreed steps a desk uses to keep managing risk by phone or backup terminal when its automated trading system fails — their value depends entirely on being drilled in advance, not improvised during a live outage.
Further reading
- Standard desk business-continuity and operational-risk procedures