The fastest way to fail a best execution review is to write a policy that says the firm routes to the venue offering the best available terms, and then hand the examiner a platform that can connect to almost two hundred of them. The policy has described an intention. What is required is a schedule, and the difference between the two is where every uncomfortable question comes from.
The Brokers panel is unusually good raw material for that schedule, because it presents the venue universe as counts and filters rather than as prose. At capture the catalog read 195 showing, split into 115 crypto exchanges and 80 stock and forex brokers, spread across seven regions. Three accounts were actually connected and the live counter read 3. The gap between 195 and 3 is not an oversight. It is the policy, and your job is to write down the reasoning that produced it.
Availability is not approval
Start by separating three lists that firms routinely collapse into one.
- The connectable universe. What the platform can technically reach. 195 at capture.
- The approved universe. Venues that have passed your selection criteria and appear on the schedule for at least one asset class.
- The connected universe. Venues with live credentials against the account that carries mandate flow. Three at capture, listed as Alpaca and two Hyperliquid API wallets.
Each list needs its own governance. The connectable universe is a vendor fact and changes without your involvement. The approved universe changes only by a documented decision. The connected universe changes when someone in operations pastes a key, which is precisely why it is the list that drifts, and why the reconciliation between approved and connected belongs on a recurring calendar rather than in someone's head.
A policy sentence that does real work reads more like this. Orders in a given asset class may be routed only to venues appearing on the schedule for that asset class, and a venue may appear on that schedule only while it holds a current selection memo and a completed periodic review.
The 186 to 9 split is your first filter
The panel carries a second filter row that most people scroll past, and it is the most useful single number on the page for an institutional reader.

Nine venues out of 195 carried the institutional tag at capture. That does not make the other 186 unusable, and for some crypto pairs the deepest book will sit on a venue whose primary customer is retail. What it does mean is that the default direction of travel should be outward from the nine rather than inward from the 195. Every consumer tagged venue on your schedule should have a written reason it is there, and the reason should be a market structure fact about the instrument rather than convenience.
The region row underneath is a screening axis before it is an execution quality axis. At capture it offered all regions, United States, UK and EU, Asia and APAC, India, LATAM, Canada and Russia. Permissions, sanctions and client domicile screening happen at that layer and they are owned by compliance, not by the desk. A venue that fails that screen never reaches the conversation about spreads, and your schedule should record the screen result and its date alongside the venue rather than treating it as an unwritten assumption.
Schedules are per asset class, not per venue
The execution factors your policy enumerates will be the familiar ones whatever regime you sit under. Price, total cost, speed, likelihood of execution and of settlement, size, and the nature of the order. The mistake is to rank them once, globally, and apply the ranking everywhere. The panel splits the catalog into crypto exchanges and stock and forex brokers for a reason, and those two halves do not have the same risks.
| Asset class | Factor that dominates the ranking | What the schedule must record |
|---|---|---|
| US equities | Price and likelihood of execution | Routing arrangements, any payment or rebate arrangements, periodic price improvement sample |
| Crypto spot and perpetuals | Likelihood of settlement, meaning counterparty and custody risk | Where assets sit between trades, withdrawal controls, concentration limit per venue |
| FX | Total cost, since it is embedded in the spread rather than invoiced | Spread sampling against an independent reference, at your actual trade sizes |
The crypto row is the one that differs most from a traditional policy and the one an examiner will press on. On a venue that is simultaneously exchange, broker and custodian, likelihood of settlement is not a technicality about clearing. It is a question about whether the venue still exists next quarter, and it dominates a two basis point spread advantage by an order of magnitude that nobody should have to be reminded of.
Credential scope belongs in the policy
The page states that credentials are encrypted with Google Cloud KMS and describes the keys as trade only. Both facts belong in the operational controls section of the policy, and the second one carries more weight than it first appears to.
A key that can trade but cannot withdraw changes the shape of your exposure to a venue. It does not remove counterparty risk, since your assets are still on the venue's balance sheet, but it removes an entire class of operational and compromise risk, and it is the sort of control that is trivially verifiable and therefore worth stating as a requirement rather than a preference. Write it as a standard. Keys issued to the platform for any venue on the schedule are scoped to trading only, verified at issuance and at each periodic review, with the verification recorded.
Then record the things that will be asked for. Who issued the key, when, its scope, when it was last rotated, and who has authority to issue a replacement. This is the evidence trail that turns a claim about controls into a demonstrated control.
Cadence, and what forces an off cycle review
An annual review with quarterly monitoring is the usual shape and it is defensible. What separates a policy that works from one that is theatre is the list of events that pull a venue forward out of that cycle. Write the triggers down, because a trigger that has to be argued for in the moment will not be invoked.
- The connected count changes. If the live counter moves and no approval preceded it, that is an incident, not a configuration change.
- A material outage, or degraded performance during a period you were trying to trade. Record the date, the flow affected, and the fallback used.
- A change in the venue's ownership, domicile, or regulatory standing, which is also the point at which the region screen has to be re run rather than assumed.
- A step change in reject rates or in the gap between expected and achieved prices in your monitoring sample.
- Any change in credential scope, in either direction.
The quarterly monitoring sample is where most firms cut corners, and the corner they cut is size. Sampling execution quality at sizes you do not trade produces a document that is technically complete and practically worthless, because the venue that looks best on a nominal clip is frequently not the venue that absorbs your real order. Sample at your actual distribution of order sizes, keep the raw sample rather than only the summary, and when a venue drops off the schedule, keep the memo explaining why. The removals are the part of the file that demonstrates the process was ever capable of saying no.