The Swiss franc move in January 2015 is the reference case for everyone who works on this. Positions did not fill anywhere near their stops, accounts went through zero, and firms that had promised clients could not lose more than their deposit had to decide, in a weekend, whether to honour that promise. Some did. Some did not, and pursued clients for the debit. Some did not exist by the following month. Every design decision below traces back to that scenario.
Per account, not per position
The scope of the protection is the first thing to settle, and it is where careless wording creates real exposure. Protection applied per position means a client whose one position goes negative is written back to zero on that position while other positions carry on. Protection applied per account means the client's total balance across all positions with the firm cannot go below zero. The EU retail regime, introduced through ESMA product intervention and then adopted by national regulators, is built around per-account protection for retail CFD clients, and the United Kingdom applies an equivalent requirement. Per-position wording is a promise you cannot keep in a gap, because a client can be net negative even when each individual position was closed at a non-negative price.
The second scope question is which accounts are covered. Where the requirement is a retail protection, professional clients may sit outside it, which means the platform has to apply the flag from client categorisation and not from a global toggle. A firm that voluntarily extends protection to everyone is free to do so, but it should know it is doing it, and the finance team should see the cost.
The mechanism is a correction, not a prevention
Nothing in the platform prevents an account going negative. Market gaps do not care about a margin level. What the implementation actually does is detect the negative equity after a close-out and post an adjustment that brings the balance back to zero, from the firm's own funds, with a ledger entry that identifies it as a negative balance correction rather than a bonus, a rebate or a goodwill credit.
That labelling matters more than it looks. The correction is a firm expense, it is reportable in the client's account history, it will be examined in any audit, and it is one of the entries a supervisor will trace when checking whether client money rules were respected. Mixing it into a generic credit line makes the year-end reconciliation painful and the audit worse. We treat it as its own transaction type for the same reason we version everything else in audit trails.
Negative balance protection limits how much a client can lose to their deposited funds. It does not make leveraged trading safe. Clients can still lose their entire balance quickly, and firms must take their own legal advice on where the protection is mandatory.
Who absorbs the gap
This is where the platform build meets the business model. If the firm passes flow to a liquidity provider, the LP's agreement will not usually mirror a retail protection: the firm owes the LP the full loss and separately writes the client back to zero. The gap between those two amounts is the firm's own money, and it lands in a single day with no warning. Firms that internalise flow keep the loss too, in a different form.
The controls that reduce it are risk controls, not compliance controls, and they need to be visible in the same system: exposure concentration limits per instrument and per correlated group, tighter margin ahead of scheduled events, reduced or suspended leverage on instruments with a known pegged or managed rate, and a close-out engine that acts on the account rather than waiting for a client to respond. We wrote about the wider set in broker risk management. The honest framing for a founder is that negative balance protection converts a client credit risk into a firm market risk, and the firm has to hold capital against it.
What the close-out engine has to do under stress
Normal-market behaviour is easy. The design work is in the abnormal case. A close-out engine has to keep functioning when quotes are stale or absent, when spreads have widened past anything in the test data, and when every account in a correlated book breaches at the same second. The decisions to make explicitly, before the event rather than during it: whether to close the largest loss first or reduce proportionally, whether to act on an indicative price when no tradeable price exists, what happens when the venue itself is unreachable, and how the resulting fills are explained to clients afterwards.
Whatever the firm decides, it should be written down and disclosed, because the difference between a defensible outcome and a complaint is usually whether the client was told the rule in advance. The same principle drives best execution obligations: the policy exists so behaviour under stress can be judged against something.
Reconciling the promise with the marketing
Two lines on a website cause more trouble than the whole engine. "You can never lose more than your deposit" is a per-account claim. "Guaranteed" is a word to avoid entirely, because the protection depends on the firm remaining solvent, and a client of a failed firm relies on whatever investor compensation scheme covers that jurisdiction, if any. The accurate statement is narrow: retail clients of this entity are covered by negative balance protection, which entity, which client category, and nothing more.
Firms operating two entities, one onshore and one offshore, need the claim to be entity-specific on every page, including localised versions. The claim is one of the first things an ad platform's financial services review checks against the licence, and one of the first things a regulator picks up when the promise on the site is broader than the promise in the terms.
My position on the build: implement per-account protection for every retail client of an entity where it is required, post it as its own labelled ledger entry, and hold the risk deliberately rather than hoping the gap never comes. Firms that treated it as a checkbox on a platform configuration screen are the ones who discovered, in a fast market, that the setting existed and the capital did not.
"Negative balance protection is not a feature you switch on, it is a liability you accept. Price it into your risk book before you put it on the website."
— Roman Onta, Executive Director, SINGUARD
Key Takeaways
- Protection is applied per account, not per position, because a client can be net negative even when each position closed at a non-negative price.
- The platform does not prevent a negative balance, it detects one and posts a labelled correction from the firm's own funds.
- Where the firm hedges externally, the liquidity provider agreement rarely mirrors retail protection, so the gap is the firm's own market risk.
- Website wording must name the entity and the client category, and should avoid the word guaranteed, because the promise depends on the firm's solvency.
Frequently Asked Questions
Does negative balance protection apply to professional clients?
Not automatically. Where the protection comes from a retail product intervention regime it attaches to retail clients, and elective professional clients may sit outside it. A firm can extend it voluntarily, but the platform must apply it from the client category flag rather than a single global setting.
Who pays when an account goes below zero?
The firm does. It writes the client balance back to zero from its own funds while still owing any hedging counterparty the full loss. That difference is a firm expense that can arrive in a single session, which is why exposure and margin controls matter as much as the protection itself.
Can a broker still close positions during a gap if there is no price?
The close-out engine acts on whatever the firm's execution policy says it acts on, and in a gap the fill can be far from the stop level. Firms should publish that policy in advance, because it is what a complaint or a supervisory review is judged against.
About the Author
Roman Onta is an Executive Director at SINGUARD. He builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals side by side with his brother Alex Onta, and he helped on the design of eTrader, the division Alex built and leads. His ground is worldwide payment processing, AML compliance and the corporate structures brokers are built on, work the two of them carry together, shaped by executive roles in the UAE and international corporates. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.