Ticket#75DE25
DeskORDER-
Executed
Size704 w

When a Primary FX Venue Goes Dark: Reroutes, Spreads and Fix Risk

Spot majors still price off two central limit order books. When one halts, algos lose their reference mid, spreads widen across alternates, and fix orders need a policy written in advance.

What Happens When a Primary FX Venue Goes Offline? - The Full FX
What Happens When a Primary FX Venue Goes Offline? - The Full FXAI-generated

Execution notes

  • Spot price discovery in the majors concentrates in two CLOBs — CME Group's EBS Market and LSEG's Refinitiv Matching — inside a $7.5-trillion-a-day market the BIS measured in April 2022.
  • DORA applies to EU financial entities from 17 January 2025; the UK's PRA/FCA operational resilience regime reaches full compliance on 31 March 2025.
  • The FX Global Code, updated in July 2021, calls for tested business-continuity arrangements, but adherence is voluntary — a principle is not a runbook.

Spot price discovery in the major pairs still runs through two central limit order books — CME Group's EBS Market and LSEG's Refinitiv Matching — even though most of the $7.5 trillion in daily global turnover the BIS measured in April 2022 trades dealer-to-client, away from either book. That concentration makes one question worth asking on any execution desk: what actually happens when a primary FX venue goes offline?

The division of labor is pair-specific and never fully dissolved. Refinitiv Matching anchored EUR/USD; EBS anchored USD/JPY and the yen crosses; and many dealer pricing engines still treat one book or the other as the primary mark in those pairs. An outage is therefore not a generic event. It is a USD/JPY event or a EUR/USD event, and the desks hit hardest are the ones whose pricing references the halted book.

Mechanically, three things break in sequence. First, the reference price. Execution algos that benchmark to the primary book's mid lose their anchor; the better-built ones kill their logic or degrade to a defined secondary feed, and the rest trade against stale marks. Second, the top of book. Liquidity providers hedge on the primary book. When it vanishes, they pull or widen quotes across single-dealer platforms, multi-dealer portals and second-tier ECNs, because they can no longer lay off risk at a known price. Third, routing. Smart order routers that rank venues on captured depth re-rank in real time, and the mid-outage ranking reflects quote withdrawal as much as available liquidity.

Where does the flow go? Into the fragmented periphery: dealer-to-client platforms, RFQ, prime-brokered ECNs and, for size, voice and message channels. Spot FX has no cross-venue circuit breaker and no coordinating authority. The redundancy is emergent, not designed. The market does not stop; it scatters.

Benchmark orders raise the harder problem. The WM/Refinitiv 4pm London fix leans on contributor panels and minimum-data thresholds, and an outage overlapping the fix window thins the panel and tests those thresholds. Order-execution policies written for normal conditions rarely say whether a desk should work a fix order early, late, or not at all. Compliance should have that answer on paper before the outage, not after.

The regulatory mandates are real but indirect. DORA — proposed by the European Commission in September 2020, in force since 16 January 2024, applying to EU financial entities from 17 January 2025 — requires ICT incident classification, reporting and resilience testing, including threat-led penetration tests. The UK's operational resilience regime, which the PRA and FCA finalized in 2021, set 31 March 2025 as its full-compliance deadline. Neither rule tells a desk where to route EUR/USD when a primary book is down. The FX Global Code, updated in July 2021, calls for tested business-continuity arrangements in its operational-risk principles — but adherence is voluntary, and a principle is not a runbook.

Venue statements deserve the same scrutiny as any vendor claim. Every major platform asserts redundant data centers, tested failover and rapid recovery. Desks should treat those as assertions and measure the rest: time-to-detect, time-to-reroute, spread widening on alternates, last-look rejection rates, fill ratios on benchmark orders. A status page is an assertion until your TCA contradicts it.

The workflow questions are concrete. Do your algos degrade to a named secondary feed or halt? Does your routing policy permit RFQ fallback, and does compliance sign-off cover it? Are resting orders on the halted venue still live, and can you cancel them? What do your prime broker's last-look terms allow during a declared outage? Who decides whether a fix order executes, and by when? Firms that rehearse these answers in failover drills — DORA and the UK regime both expect testing — will find the outage expensive. Firms that have not rehearsed will find it expensive and slow.

On paper, the answer to the headline question is clean: flow migrates, spreads widen, redundancy absorbs the shock. The next outage will test whether that answer holds in practice, and desks will read the result in their own execution data long before any venue statement confirms it.

via Google News: Market microstructure (Source)

More from Marcus Bennett

Marcus Bennett

Show full bio

Staff writer covering industry trends and analytics at Order Flow Brief.

48 articles

Blotter · related prints

  1. Lit Volume Decline Pushes Flow Into Closing Auctions, Dark Pools

    900
  2. LMAX's Jay Moore on Buy-Side FX Market Structure Shifts

    200
  3. Fast-Money Firms Deepen Presence in Currency Options

    700
  4. European Block Trading Shifts Further Into Dark Venues

    400
  5. Japan Unveils Market Structure Reform as PTS Volumes Surge

    600

« Previous printNext print »