Compliance surveillance is one of the most important — and least glamorous — functions in a bank's markets business. The surveillance team is responsible for monitoring the firm's trading activity and employee communications to detect and investigate potential market abuse, conduct breaches, and regulatory violations. Their work is invisible when it is done well, but the consequences of failure are severe: regulatory enforcement action, criminal prosecution, and reputational damage that can shake client confidence for years.

The Morning Alert Review

The compliance surveillance day begins with alert review. Surveillance systems — increasingly sophisticated technology platforms using algorithmic detection and, more recently, machine learning — generate alerts based on predefined rules and patterns applied to the previous day's (and real-time) trading data. An alert might be triggered by:

  • A trade executed shortly before a significant market-moving event (potential insider dealing)
  • A pattern of small orders designed to move a benchmark rate (potential benchmark manipulation)
  • A series of trades that appear designed to create a false impression of market activity (potential layering or spoofing)
  • Unusually large trades by an individual relative to their own historical activity or their desk's book
  • Communications flagging keywords associated with collusion, front-running, or other misconduct

A large bank's surveillance system may generate hundreds or thousands of alerts per day across all business lines. The surveillance analyst's job is to triage these alerts — identifying which require immediate investigation, which can be closed as false positives with brief documentation, and which require escalation. Well-designed surveillance systems include scoring and prioritisation tools to help analysts focus on the most significant alerts first.

Investigating Suspicious Trades

When an alert requires investigation, the surveillance analyst assembles the relevant evidence: the trade blotter showing the timing, size, and price of the flagged transactions; the trader's position history; market data showing price movements around the trade; and communications records (emails, chat messages, recorded telephone lines) from the relevant time window. The analyst looks for a coherent explanation — was the trade within normal parameters of the trader's strategy? Is there a legitimate business rationale? — or for red flags suggesting misconduct.

Investigation of a potentially serious matter will involve: reviewing a broader window of communications; consulting with the front-office manager to understand the business context; escalating to senior compliance and, if appropriate, legal counsel; and making a preliminary assessment of whether the matter requires regulatory reporting. This process must be handled carefully — premature disclosure to the trader being investigated can compromise the investigation, while failure to escalate appropriately creates its own regulatory risk.

Reviewing Flagged Communications

Communications surveillance — the systematic monitoring of trader emails, instant messages, and recorded telephone calls — is a major component of surveillance operations. Under MAR (Market Abuse Regulation) in the UK and EU, and equivalent frameworks in other jurisdictions, firms are required to monitor employee communications for evidence of market abuse. The volume of communications generated by a large trading floor makes comprehensive human review impossible; technology solutions use keyword detection, natural language processing, and behavioural analytics to identify communications that warrant human review.

Communications flagged for review are assessed in context: a message containing a keyword associated with price coordination must be read alongside the full conversation thread, the trading activity around the time of the message, and the relationship between the parties. The analyst must make a judgment call: is this an innocuous use of language, or does it suggest coordination that amounts to market abuse?

Wall-Crossing Requests

Wall-crossing is the process by which an individual who is on the public side of an information barrier (the "Chinese wall") is brought across to the private side — gaining access to material non-public information (MNPI) — typically in connection with a capital markets transaction such as a block trade, a new issuance, or an M&A deal. The compliance surveillance team is closely involved in managing wall-crossing: they review and approve (or decline) wall-crossing requests, maintain registers of who has been crossed, and monitor the subsequent trading activity of crossed individuals and their teams to ensure that the MNPI has not been misused.

Wall-crossing is a frequent source of regulatory concern. If a trader is wall-crossed into knowledge of a pending block trade and then adjusts their book in a way that benefits from that information — even if they believe their trading was based on public information — the appearance of impropriety requires careful investigation and documentation.

Suspicious Transaction and Order Reports (STORs)

Under MAR, investment firms are required to submit a Suspicious Transaction and Order Report (STOR) to the FCA (or relevant national competent authority) whenever they have a reasonable suspicion that a transaction or order may constitute market abuse. The STOR must be filed as soon as possible after the suspicion arises — typically within one business day. Filing a STOR does not imply that market abuse has occurred; it is a regulatory obligation triggered by reasonable suspicion, not certainty. The FCA uses STORs as an input to its own market abuse surveillance and investigation functions.

Compliance teams maintain STOR registers documenting all STORs filed, the rationale for each filing, and the outcome of any subsequent investigation. The number and quality of STORs filed is a metric that regulators assess in supervisory reviews — too few STORs relative to the firm's activity level may suggest insufficient surveillance; poorly documented STORs suggest inadequate investigation.

Preparing Reports for Senior Management

Surveillance teams report regularly to senior management and the board's risk and compliance committees on the state of the surveillance framework: alert volumes and closure rates by category, significant investigations, STORs filed, regulatory developments, and thematic conduct risks. These reports are used by senior management to assess whether the control environment is functioning effectively and to prioritise investment in surveillance technology and headcount.

Regulatory Examination Preparation

Regulatory examinations — whether the FCA's Supervisory Review and Evaluation Process (SREP), a targeted thematic review, or an enforcement investigation — require compliance teams to produce large volumes of documentation at short notice. Preparation involves maintaining current, accurate records of all surveillance policies and procedures; ensuring that the surveillance technology is well-documented and its effectiveness can be demonstrated; and having completed a recent assessment of the surveillance framework against regulatory expectations. Teams that have invested in clear documentation and regular internal testing are far better positioned when a regulator arrives than those that scramble to reconstruct records under pressure.

Key Terms

Market Abuse Regulation (MAR)
The EU (and retained UK) regulation prohibiting insider dealing, market manipulation, and unlawful disclosure of inside information. The primary legal framework within which compliance surveillance operates.
STOR (Suspicious Transaction and Order Report)
A report filed by an investment firm with the regulator (FCA in the UK) when there is reasonable suspicion that a transaction or order constitutes market abuse. Required under MAR.
Wall-Crossing
The controlled process of bringing an individual across an information barrier to receive material non-public information in connection with a specific transaction, subject to trading restrictions and compliance oversight.
Chinese Wall (Information Barrier)
Policies, procedures, and physical barriers designed to prevent the flow of material non-public information between different parts of a bank — typically between the private side (deal advisory, M&A) and the public side (sales and trading).
Layering / Spoofing
A form of market manipulation in which a trader places large orders on one side of the market with no intention of executing them, to create a false impression of supply or demand and move the price, then cancels the orders after trading on the other side.
MNPI (Material Non-Public Information)
Information that is not publicly available and that a reasonable investor would consider significant in making an investment decision. Trading on MNPI constitutes insider dealing under MAR.