Audit trail

(f) Audit trail. A security-based swap execution facility shall establish procedures to capture and retain information that may be used in establishing whether rule violations have occurred. (1) Audit trail required. A security-based swap execution facility shall capture and retain all audit trail data necessary to detect, investigate, and prevent customer and market abuses. Such data shall be sufficient to reconstruct all indications of interest, requests for quotes, orders, and trades within a reasonable period of time and to provide evidence of any violations of the rules of the security-based swap execution facility. An acceptable audit trail shall also permit the security-based swap execution facility to track a customer order from the time of receipt through execution on the security-based swap execution facility. (2) Elements of an acceptable audit trail program(i) Original source documents. A security-based swap execution facility's audit trail shall include original source documents. Original source documents include unalterable, sequentially identified records on which trade execution information is originally recorded, whether recorded manually or electronically. Records for customer orders (whether filled, unfilled, or cancelled, each of which shall be retained or electronically captured) shall reflect the terms of the order, an account identifier that relates back to the account's owner(s), the time of order entry, and the time of trade execution. A security-based swap execution facility shall require that all orders, indications of interest, and requests for quotes be immediately captured in the audit trail. (ii) Transaction history database. A security-based swap execution facility's audit trail program shall include an electronic transaction history database. An adequate transaction history database shall include a history of all indications of interest, requests for quotes, orders, and trades entered into a security-based swap execution facility's trading system or platform, including all order modifications and cancellations. An adequate transaction history database shall also include: (A) All data that are input into the trade entry or matching system for the transaction to match and clear; (B) The customer type indicator code; and (C) Timing and sequencing data adequate to reconstruct trading. (iii) Electronic analysis capability. A security-based swap execution facility's audit trail program shall include electronic analysis capability with respect to all audit trail data in the transaction history database. Such electronic analysis capability shall ensure that the security-based swap execution facility has the ability to reconstruct indications of interest, requests for quotes, orders, and trades, and identify possible trading violations with respect to both customer and market abuse. (iv) Safe-storage capability. A security-based swap execution facility's audit trail program shall include the capability to safely store all audit trail data retained in its transaction history database. Such safe-storage capability shall include the capability to store all data in the database in a manner that protects it from unauthorized alteration, as well as from accidental erasure or other loss. Data shall be retained in accordance with the recordkeeping requirements of 242.826 (Core Principle 9). (3) Enforcement of audit trail requirements(i) Annual audit trail and recordkeeping reviews. A security-based swap execution facility shall enforce its audit trail and recordkeeping requirements through at least annual reviews of all members and persons and firms subject to the security-based swap execution facility's recordkeeping rules to verify their compliance with the security-based swap execution facility's audit trail and recordkeeping requirements. Such reviews shall include, but are not limited to, reviews of randomly selected samples of front-end audit trail data for order routing systems; a review of the process by which user identifications are assigned and user identification records are maintained; a review of usage patterns associated with user identifications to monitor for violations of user identification rules; and reviews of account numbers and customer type indicator codes in trade records to test for accuracy and improper use. (ii) Enforcement program required. A security-based swap execution facility shall establish a program for effective enforcement of its audit trail and recordkeeping requirements. An effective program shall identify members, persons, and firms subject to the security-based swap execution facility's recordkeeping rules that have failed to maintain high levels of compliance with such requirements, and impose meaningful sanctions when deficiencies are found. Sanctions shall be sufficient to deter recidivist behavior. No more than one warning letter shall be issued to the same person or entity found to have committed the same violation of audit trail or recordkeeping requirements within a rolling 12-month period.

Source

17 CFR § 242.819


Scoping language

None
Is this correct? or