An MT5 login, a working website and a live price feed do not prove a brokerage is ready to accept clients. The gaps usually appear between systems: an approved client receives the wrong trading conditions, a deposit is credited twice, or nobody can authorise action when an LP disconnects.
This forex broker operational checklist covers seven approval gates before launch. For each gate, record an owner, test evidence and a pass or fail decision. Apply the requirements relevant to your entity, markets and operating model. Any item marked not applicable needs a reason.
1. Legal and Regulatory Readiness
Confirm which entity contracts with clients, what activities it may conduct and where it may market and provide those services. Company incorporation alone does not authorise a regulated brokerage business. An application in progress is not an active permission.
Check:
- Licence or registration status, permitted products, client categories and country restrictions.
- Client agreements, risk disclosures, privacy notices, AML procedures and complaints handling.
- Applicable capital, reporting and client protection requirements.
- Consistent entity identification across the website, CRM, agreements and payment instructions.
For the compliance documents and controls a new broker needs, see our compliance requirements guide.
For UK business, the FCA’s expectations for CFD firms provide a relevant regulatory reference. Other markets require their own assessment.
Pass condition: Legal and compliance approve the intended client markets and confirm that onboarding controls enforce those boundaries.
2. MT5 and Server Readiness
Confirm platform licensing and production access, then check the deployed Trade, Access, History and Backup components against the approved architecture. MetaQuotes describes MT5 as built on a distributed architecture; the recovery plan must cover the environment actually deployed.
Check network connectivity, DNS, firewall rules, time synchronisation and TLS certificates for web services. Restrict Administrator, Manager and integration permissions to their required functions.
Test each account product against its published terms: symbol access, contract sizes, leverage, margin, stop out, commissions, swaps, sessions and holidays. Our MT5 group configuration guide explains the settings that need checking together.
Verify monitoring alerts and restore evidence. As covered in MT5 Backup Server Explained, a backup component and a complete recovery process are different things.
Pass condition: Trading conditions match approved specifications, alerts reach the responsible person and recovery meets documented targets.
3. Liquidity and Execution Readiness
Confirm signed LP agreements, LP onboarding approval for live trading, required collateral, available margin and support contacts. The liquidity provider selection guide covers the commercial checks behind the connection.
Validate symbol mapping, contract sizes, price precision and routing through the chosen Bridge, Gateway or aggregator. FIX API and MT5 Gateway serve different roles; a separate Bridge is not required in every setup.
Test order sizes, rejects, partial fills where supported, slippage recording, rollover and volatile market scenarios. Set acceptance criteria before testing. There is no universal acceptable slippage or reject rate for every product and market condition.
For A Book, B Book or hybrid models, verify external hedging and retained exposure separately. With multiple LPs and aggregation, test each route and its failure behaviour.
Pass condition: Orders follow approved rules, exposure reconciles and an LP disconnect triggers a tested response. Backup routing requires an available, funded and compatible destination.
4. CRM, KYC and Client Portal
Test the complete onboarding sequence:
Registration → Verification → Compliance approval → MT5 account → Group assignment → Deposit → Trade → Withdrawal
If your portal uses a wallet before creating a trading account, test that sequence too. Funding and trading permissions must still follow the approved policy.
Include identity verification, sanctions screening, manual review and any required product assessment. A document verification result alone should not determine whether a client may trade. The forex broker KYC workflow explains these separate decisions.
Check account synchronisation, IB attribution, email and SMS delivery, password resets and audit records. Test rejected applications, duplicate submissions, provider timeouts and repeated API requests. Confirm retries cannot create duplicate accounts or balance credits.
Pass condition: Eligible clients receive the correct account and permissions; incomplete or rejected cases cannot bypass restrictions.
5. Banking and Payments
Confirm that each bank, electronic money institution (EMI) and payment service provider (PSP) has approved the actual business activity and payment flows. A corporate account approval does not establish compliance with client money rules.
Document where client funds are held, who receives them and what segregation or safeguarding arrangements apply. If the payment recipient differs from the trading entity, verify the legal relationship, provider acceptance and client disclosures.
Test deposits, withdrawals, refunds, failed payments, currency conversion, limits and restricted countries. Reconcile provider records, bank movements, the client ledger and MT5 balances. Assign ownership of settlement delays, chargebacks and unresolved differences.
Pass condition: Finance can trace each movement and complete a withdrawal through the approved route. Any backup payment channel has its own approval and test evidence.
6. Operations and Incident Response
Name the people responsible for dealing and risk, compliance, finance, payments, technical support and customer support. Include deputies, coverage hours and vendor escalation contacts.
Prepare response procedures for MT5 outages, LP disconnections, stale prices, payment failures, incorrect symbol settings and cyber incidents. Each procedure should state who investigates, who communicates and who can authorise changes.
Define authority to restrict a symbol to closing positions, suspend trading or switch liquidity routes. Document effects on open positions and pending orders, along with the conditions for restoring normal service.
Use the MT5 maintenance checklist to turn launch controls into recurring operational tasks.
Pass condition: A rehearsal shows that alerts reach the right people and authorised staff can act without improvising permissions.
7. Final UAT and Launch Approval
User acceptance testing (UAT) should follow a complete client lifecycle:
Create client → Complete KYC → Create and assign MT5 account → Deposit → Trade → Verify execution and hedging where applicable → Close position → Issue statement → Withdraw
Reconcile balances, fees, positions and external transactions across the systems involved. Test representative account types and products, including rejected orders and unsuccessful payments.
Rehearse server restarts, LP disconnection, Access Server failure, CRM outage and backup restoration in an isolated environment or an approved maintenance window. Measure recovery time and any data loss against agreed targets. Use controlled production checks only after the necessary approvals.
Pass condition: All mandatory gates pass, no critical defects remain and authorised business owners approve launch. Minor issues need a named owner, deadline and explicit acceptance. Keep a rollback plan ready, then begin with a controlled launch and closer monitoring.
Final Broker Launch Approval Checklist
The seven gates group into five sign off areas. Mark each item complete only when its evidence has been reviewed:
- Legal: Operating entity, regulatory permissions, target markets, website disclosures and client agreements.
- Infrastructure: MT5, server security, backups, Groups, Symbols and monitoring.
- Execution: LP approval and funding, Bridge or Gateway where required, routing and exposure reconciliation.
- Client operations: CRM, KYC, bank or EMI arrangements, payments and tested withdrawals.
- Launch control: Incident plan, UAT, recovery tests, rollback plan and final approval.
How EBS FinTech Supports Broker Launches
EBS FinTech supports MT5 main label setup, hosting, maintenance, CRM integration, LP connectivity, integration with the broker’s selected Bridge or aggregation solution, monitoring, testing and launch support within the agreed project scope. The broker procures and licenses its Bridge directly from its chosen provider.
For a launch readiness review, share your current architecture, selected providers and outstanding test results. This gives the technical team a concrete starting point for identifying dependencies and work still required. Regulatory approvals and the final business launch decision remain with the broker.



