The Pattern: Violations, Fines, Business as Usual
2023: The Mismarking Scandal ($7 Million Fine)
In September 2023, the SEC charged Citadel Securities with violating order marking requirements under short-sale regulations for five years (2015-2020). The violation was systematic: millions of orders were incorrectly marked as long sales when they were actually short sales, or vice versa.
The SEC's official press release stated: "Citadel Securities agreed to a cease-and-desist order imposing a censure, a $7 million penalty, and other remedies."
The reality:- Citadel Securities reported approximately $3-5 billion in annual revenue (2023 estimates) - $7 million fine = 0.14-0.23% of revenue - The violation occurred for 5 years without detection - Citadel Securities is one of the largest market makers in America—executing roughly 25-30% of US equity trades - The coding error affected regulatory oversight of short selling, a sensitive area of enforcement
The SEC claimed the issue was a "coding error in automated trading systems." Perhaps. But the failure to detect and report a five-year compliance problem raises a question: What else isn't being caught?
The firm had systems and controls that were supposed to prevent this — the SEC's Reg SHO order describes two purpose-built surveillance tools that failed to catch a five-year error. Whoever held the relevant chairs at the relevant times, the controls didn't function.
2024: The CAT Reporting Disaster — A Data-Infrastructure Failure With No Named Owner ($1 Million Fine)
In October 2024, FINRA fined Citadel Securities $1 million for violations of the Consolidated Audit Trail (CAT) reporting system. The firm inaccurately reported approximately 42.2 billion equity and options order events — 42.2 billion individual reporting events, a count, not dollars — between June 2020 and July 2022, with roughly 3.2 billion additional events affected by problems FINRA found through June 2024.
42.2 billion misreported order events.
The fine? $1 million.
The math:- Misreported order events: approximately 42.2 billion - Fine: $1 million - Fine per misreported event: roughly $0.000024 — about one four-hundred-thousandth of a cent per event - Measured against Citadel Securities' estimated $3-5 billion in annual revenue, the penalty is roughly 0.02-0.03 percent of a single year's revenue
Where's the failure point? CAT reporting is a data-accuracy function.This wasn't a trader's error or a market-insight problem — it was a data infrastructure failure, at a firm whose parent employs a Chief Operating Officer of Data (Kevin Nutter, per professional directories). Citadel does not publicly say who owns regulatory reporting infrastructure as between Citadel LLC's data organization and Citadel Securities, and neither FINRA's action nor any public filing names a responsible executive. In our opinion, that is a governance failure in its own right: 42.2 billion misreported events, and no identifiable human being publicly accountable for the systems that produced them.
The Broader Pattern
Since 2009, Citadel Securities has paid approximately $35-40 million in regulatory fines. Compare this to:
- Revenue: ~$3-5 billion annually - Cumulative fines over 15+ years: ~$0.7-1.3% of single year's revenue - Cost as percentage of 15-year cumulative revenue: Negligible (0.05-0.10%)
For an average firm, a regulatory fine should: 1. Sting enough to prevent recurrence 2. Force operational changes 3. Damage reputation 4. Risk license revocation
For Citadel Securities, in our view, fines at these levels function as a business expense — smaller than many tech companies' quarterly bug-bounty budgets.
The Data Infrastructure and Regulatory Failure
Citadel's data infrastructure is supposed to serve as the foundation for compliance at Citadel. Instead, it has repeatedly failed to catch problems that regulators later discovered:
- Mismarked trades (5-year oversight) - CAT reporting failures (42.2 billion order events) - Inadequate data validation systems
These aren't trader errors. They're infrastructure failures. And in our opinion, infrastructure failures belong to whoever leads the data organization — a question Citadel has never publicly answered.
When FINRA announced the CAT fine, it named no executive at all. It fined "Citadel Securities," a corporate entity. Whoever is responsible for the data systems that failed received no public attention, faced no individual accountability, and — unlike the CEO who testifies before Congress — was never even identified. The closest thing to a public answer is a title in a professional directory: Chief Operating Officer of Data, Kevin Nutter.
Why Regulators Can't Effectively Punish
Problem 1: Citadel Is Too Systemically Important
Citadel Securities executes roughly 25-30% of US equity trades. If regulators threatened to revoke its market-making license, the impact would be:
- Massive spike in bid-ask spreads - Tens of millions of retail investors losing their "free trading" benefits - Potential market dysfunction - Economic panic among wholesale clients
The regulatory agency that shut down Citadel Securities would be blamed for the market chaos that followed. This creates regulatory capture—not through corruption, but through logical incentives.
Peng Zhao, as CEO of Citadel Securities, implicitly operates with this knowledge. The firm is too big to punish.
Problem 2: The Fines Are Calculated to Be Tolerable
FINRA and the SEC publish enforcement guidelines. For a firm Citadel's size, with estimated trading volumes and margins, a $1 million fine represents the regulatory equivalent of "a hand slap."
Regulators could: - Fine Citadel 10% of annual revenue ($300-500 million) - Require disgorgement of profits from affected trades - Restrict market-making in specific securities - Reduce allowable order volumes
None of these happen. Instead: $1 million, Citadel settles without admitting wrongdoing, and business continues unchanged.Problem 3: Enforcement Looks for Intentionality
SEC and FINRA enforcement actions require showing either: 1. Intentional misconduct, or 2. Negligence/recklessness
In Citadel's case, the firm attributes violations to "system errors" and "operational failures"—not intentional cheating. This is probably even true. The firm's technology and data infrastructure is extraordinarily sophisticated.
But here's the perverse outcome: The infrastructure is sophisticated enough that serious problems, once found, get fixed fast — the Reg SHO error was fixed in three business days. In our opinion the record therefore poses an uncomfortable question: is prevention failing because it is impossible, or because it has not been worth the money? For the firm, paying occasional fines has been, in our view, demonstrably cheaper than whatever it would cost to prevent them.Consider the arithmetic facing any executive who owns compliance infrastructure at a firm this size. Re-engineering a reporting pipeline of this scale plausibly costs tens of millions of dollars and months of engineering time; the historical fines have cost one to seven million. A pure profit-maximizer would conclude that the fines are cheaper — and nothing in the public record tells us whether anyone at Citadel has ever run that calculation, which is precisely the problem with penalties this small. The incentive exists whether or not anyone acts on it, and the person best positioned to act on it, whoever that is, never testifies before Congress and never appears in enforcement announcements.
What Independent Experts Say
Independent research on wholesale market making has documented wide variation in execution quality across the handful of firms that dominate retail order flow, and academic and SEC analyses accompanying the 2022 market-structure proposals estimated that exposing retail orders to competition could save investors on the order of $1.5 billion a year — savings that currently accrue to wholesalers. What no outside researcher has been able to test is the question specific to Citadel's dual structure: whether information from market-making order flow confers any advantage on the affiliated hedge fund. No public dataset would reveal it, no regulator has published a system-level audit of the information barriers, and Citadel does not open its systems to researchers. In our opinion, the fact that this question is untestable from the outside is itself the strongest argument for the independent audits proposed in Part 5 of this series.
The Leadership Question
When a firm of this sophistication acknowledges regulatory violations only after the fact — settling without admitting or denying them — what does that say about its internal controls?
Two possibilities:1. Incompetence: The systems and controls are inadequate—but this is implausible given the firm's overall sophistication.
2. Rational Choice: The firm made a trade-off: occasionally fail compliance tests, pay small fines, continue operating at full capacity. The alternative (investing heavily in preventive compliance infrastructure) would reduce returns and competitive advantage.
There's no evidence of malice here — and, to be clear, no direct evidence of calculation either. Just an incentive structure that would reward it.
What Would Actually Deter Citadel?
Real regulatory solutions would require:1. Structural Separation: Legally force Citadel LLC (hedge fund) and Citadel Securities (market maker) into completely independent companies with separate ownership 2. Meaningful Fines: Enforce penalties that equal 20-50% of profits from affected transactions, not 0.002% 3. License Restrictions: Revoke or restrict market-making authority for serious violations 4. Leadership Accountability: Hold individuals personally liable (not just companies)
None of these are politically feasible because Citadel's market-making operations genuinely benefit retail investors through competitive pricing. Destroying that system to punish leadership would create collateral damage.
So the current equilibrium persists: Citadel operates a structural conflict, gets caught occasionally, pays negligible fines, and continues profiting from the edge.
The Role of Data Leadership
The Chief Operating Officer of Data — a title professional directories assign to Kevin Nutter — is a crucial and largely invisible position. A data organization at a firm like Citadel builds the infrastructure through which:- Market data informs both business models - Compliance monitoring is reported - Regulatory violations are (belatedly) discovered - Information barriers between business units are implemented — whether robustly or not, no outside party has ever verified
Mr. Nutter has no media presence and no public statements, and whether his remit reaches Citadel Securities' reporting systems is not publicly known. Yet whoever runs data at Citadel oversees systems that touch every aspect of the dual-model conflict.
If meaningful change were to occur, it would require whoever holds that seat to prioritize compliance above competitive advantage. The current incentive structure doesn't encourage that.
Next Week: Part 4 — The C-Suite at Citadel: Profiles and Incentives
Who are these executives shaping Citadel? Kenneth Griffin, Gerald Beeson, Andrew Philipp, Peng Zhao, Matt Culek, Josh Woods, Shyam Rajan, and Kevin Nutter—what's their background and what drives their decision-making?
---
The Ethics Reporter investigates conflicts of interest in finance that affect everyday investors. This journalism is supported entirely by reader donations. Please consider supporting our work: theethicsreporter.com/donate- SEC Press Release 2017-11 and settled administrative order (Jan. 13, 2017): sec.gov
- SEC Press Release 2023-192 and Administrative Order No. 34-98482 (Sept. 22, 2023): sec.gov
- FINRA Letter of Acceptance, Waiver and Consent regarding Citadel Securities’ CAT reporting (Oct. 2024): FINRA disciplinary actions database
- Citadel LLC/Point72 $2.75 billion investment in Melvin Capital (Jan. 25, 2021): contemporaneous reporting
- Public comment file for the SEC’s proposed Order Competition Rule (File No. S7-31-22), including Citadel Securities’ March 2023 comment letter: sec.gov/comments/s7-31-22. The rule was among fourteen proposals formally withdrawn by the SEC in June 2025 (Notice 33-11377).
- Kenneth Griffin political contributions: OpenSecrets donor lookup
