RTS 6 assurance: moving from documents to evidence

A practical view of connecting regulatory conclusions to the controls and operating evidence behind them.

RTS 6 assurance: moving from documents to evidence

For many firms, the annual RTS 6 self-assessment remains one of the most resource-intensive exercises in the electronic trading compliance calendar.

Despite being an annual requirement, the exercise can run for months. Regulatory requirements need to be interpreted, scope confirmed, evidence gathered from across the organisation, controls assessed, conclusions challenged, deficiencies remediated and the final assessment taken through governance.

At larger firms, that can mean hundreds of hours of work across the first, second and third lines of defence. By the time remediation from one assessment has been completed, planning for the next may already be beginning.

RTS 6 itself is not new. MiFID II and RTS 6 have applied since January 2018, but the market that RTS 6 governs has continued to change.

Algorithmic trading was already dominant in parts of the market when the regime was introduced. Since then, electronic and automated trading has spread further across asset classes, trading systems have become more sophisticated, and firms have become increasingly dependent on complex trading technology.

ESMA's view of how far this has gone is striking. Its 2026 supervisory briefing notes that the use of computers in trading has continued to increase and evolve, to the point that “professional trading without the use of computer algorithms can be considered an exception nowadays.”

Yet in many firms, the assurance process overseeing this increasingly sophisticated activity has changed far less.

The rules have not suddenly been rewritten. What has changed is the clarity with which regulators are signalling what they expect firms to be able to demonstrate.

The supervisory bar is getting higher

In August 2025, the FCA published its Multi-firm review of algorithmic trading controls: high-level observations.

The FCA reviewed ten principal trading firms of different sizes and examined each firm's latest RTS 6 self-assessment, validation report and supporting documentation. Importantly, the FCA did not just ask whether a self-assessment existed. It looked specifically at the quality of the assessment and the evidence supporting the firm's conclusions.

The results were mixed.

The FCA found that the overall self-assessment process had improved since its previous review in 2018, but that the level of information and detail still varied widely between firms.

In some cases:

  • key policy documentation was not linked or referenced in the self-assessment;

  • policies were out of date;

  • processes and documentation were unclear;

  • governance and accountability were insufficiently formalised; and

  • some RTS 6 requirements, including areas such as IT outsourcing and Compliance training, had not been assessed at all.

That matters because it gets to the heart of what a self-assessment is supposed to do.

It is not enough to reach the conclusion that a firm is compliant. The firm needs to be able to demonstrate why that conclusion is justified.

ESMA has since made that expectation even more explicit.

Its February 2026 supervisory briefing states that firms should conduct and document the RTS 6 self-assessment on an article-by-article basis, covering all relevant articles. For each relevant article, the assessment should indicate whether the firm considers itself compliant and provide a clear rationale for its overall compliance position.

ESMA also reiterates the governance around the exercise: primary responsibility sits with Risk Management, Internal Audit should review it where applicable, and the assessment must receive senior-management approval.

This is not a new RTS 6 obligation. The FCA explicitly says its 2025 review creates no new requirements, and ESMA describes its briefing as a non-binding supervisory convergence tool. But both give firms a much clearer indication of what supervisors will look for when assessing whether the existing requirements have actually been met.

AI is widening the assurance challenge

The technology being assessed is changing too.

Neither MiFID II nor RTS 6 was drafted around the current generation of artificial intelligence and machine-learning systems. Yet AI is increasingly relevant to the development, calibration and operation of trading algorithms.

ESMA has now made clear that this should be reflected in the RTS 6 assurance process.

Its 2026 supervisory briefing states under Article 9 of RTS 6:

“NCAs should assess how firms are taking into consideration the use of AI as part of their self-assessment and validation”

That is an important development.

ESMA has not amended RTS 6 to create a separate AI self-assessment requirement. Rather, it has made explicit that where AI affects algorithmic trading systems, algorithms or strategies, firms should consider that use as part of the existing Article 9 assessment.

It also highlights a particularly difficult risk: incremental recalibrations or small changes to a model may accumulate over time until its behaviour has materially changed, without any individual adjustment necessarily appearing significant enough to trigger a conventional material-change process.

That makes traceability more important, not less.

A firm increasingly needs to understand not simply which algorithms it operates, but how they work, how they change, which risks arise from them, what controls mitigate those risks, and what evidence demonstrates those controls remain effective.

The problem with the traditional self-assessment

Despite that increasing sophistication, many RTS 6 self-assessments are still managed using tools that were never designed for regulatory assurance.

A typical process may involve a large Excel workbook containing requirements and responses; policies and procedures stored elsewhere in SharePoint; evidence requested by email; control information maintained in another system; review comments exchanged between Compliance, Risk and Technology; remediation tracked separately; and a Word or PowerPoint document eventually taken through governance for approval.

None of those tools is necessarily a problem in isolation.

The problem is what sits between them.

Links become stale. Evidence becomes detached from the conclusion it was intended to support. Spreadsheet cells are overwritten. Comments lose their context. Multiple copies of an assessment begin circulating. Review decisions are recorded in email chains. Remediation actions become separated from the finding that created them.

Then, months later, Internal Audit, senior management or a regulator asks a deceptively simple question:

Why did you conclude that you comply with this requirement?

Answering it should be easy.

A reviewer should be able to identify which algorithms, systems and activities are in scope; the regulatory requirement being assessed; the policies and procedures addressing it; the controls implementing those requirements; the operating evidence supporting those controls; any exceptions identified; who challenged the conclusion; and who ultimately approved it.

In a fragmented process, answering those questions can mean opening several spreadsheets, searching document repositories, retrieving historic emails and speaking to multiple control owners.

That creates two problems.

The first is regulatory. The firm may have reached the right conclusion, but struggle to demonstrate the reasoning and evidence behind it when challenged.

The second is operational. Skilled people across Compliance, Risk, Technology, the front office and Internal Audit spend significant amounts of time finding, reconciling and reproducing information, rather than assessing whether the risks are actually being controlled.

The self-assessment should be an assurance chain

There is a better way to think about the exercise. An RTS 6 self-assessment should not primarily be treated as a document that has to be produced once a year. It should be treated as a connected assurance process.

At its simplest:

Regulatory requirement → Scope → Control → Evidence → Assessment → Challenge → Approval

For every applicable requirement, the firm should be able to move through that chain in both directions.

Start with an RTS 6 article and the reviewer should be able to see which trading activities, systems and algorithms are relevant; which controls the firm relies upon; what evidence supports those controls; what issues have been identified; and how the compliance conclusion was reached.

Start with a piece of evidence and the firm should equally be able to see which control it supports, which requirement that control addresses and which regulatory conclusion ultimately depends upon it.

That is more than good record keeping. It creates traceability. That matters because the annual self-assessment is ultimately an assertion by the firm about the adequacy of its algorithmic trading framework.

An assertion without a visible evidential chain is harder to challenge internally and harder to defend externally.

Evidence must demonstrate operation, not just existence

There is another distinction that becomes important once the self-assessment is approached in this way.

A control can exist without being demonstrated to operate effectively.

A policy describing the firm's pre-trade control framework may demonstrate that an appropriate framework has been designed. It does not, by itself, demonstrate that the relevant controls were appropriately calibrated, monitored and reviewed during the assessment period.

Operating evidence may instead include testing results, control reports, exception logs, committee minutes, algorithm inventories, approval records, surveillance outputs, calibration reviews and evidence of periodic testing.

ESMA's latest supervisory briefing reinforces that distinction. For pre-trade controls, for example, ESMA expects firms to collect relevant statistics and use them to evaluate whether controls are effective and remain appropriately calibrated.

The self-assessment therefore needs to connect three different things:

what the firm says it does; what controls it has implemented; and what actually happened.

A robust assurance process makes the relationship between those three visible.

Better assurance should mean less work

There is a tendency to assume that greater regulatory scrutiny must mean a larger compliance exercise. It should not.

A significant part of the cost of the traditional RTS 6 process comes not from the regulatory analysis itself, but from the fragmentation surrounding it.

Compliance asks Technology for evidence. Technology searches for the evidence. Risk has its own control inventory. Internal Audit asks for many of the same materials. Evidence is copied between folders. Comments travel over email. Different versions of spreadsheets need to be reconciled. The previous year's assessment is opened and somebody tries to determine what has changed.

The regulation does not require that administrative complexity. The operating model creates it.

Once requirements, scope, controls, evidence, ownership, challenge and approval are connected, information can be reused rather than repeatedly reconstructed.

A control supporting several RTS 6 requirements can be maintained once and mapped to each relevant obligation. Evidence can remain attached to the control and assessment it supports. Open issues can remain linked to the underlying finding. Changes between assessment cycles can be identified directly rather than discovered manually by comparing spreadsheets.

The objective should not be to automate regulatory judgement.

It should be to remove as much of the administration surrounding that judgement as possible.

That leaves Compliance, Risk, Technology and Internal Audit with more time to do the thing the self-assessment actually requires of them: exercise judgement and challenge whether the firm's controls are effective.

From annual document to regulatory assurance

The FCA's 2025 review and ESMA's subsequent supervisory briefing do not point towards firms producing longer self-assessment documents.

They point towards something more fundamental.

Firms increasingly need to be able to demonstrate the basis for their conclusions.

That means connecting the regulatory requirement to the firm's scope, algorithms, policies, controls, operating evidence, assessment, challenge and approval.

When those relationships are maintained throughout the year, the annual self-assessment becomes an output of the assurance framework rather than a document assembled separately from it.

That is a subtle distinction, but an important one.

Because when a regulator, Internal Audit, Risk Committee or senior manager asks why the firm concluded that it complies with a particular requirement, the answer should not require someone to reconstruct twelve months of emails, spreadsheets and documents.

The evidence should already be there.

Daniel Shearer, Founder of Cerylis

Daniel Shearer is the founder of Cerylis and a capital-markets compliance specialist with experience across investment banking, professional services and RegTech. His work has covered MiFID II and MiFIR, algorithmic and electronic trading governance, RTS 6, regulatory controls and wider markets compliance.