Every major capital markets bank operates a compliance surveillance programme. Its purpose is to detect potential market abuse — insider dealing, market manipulation, unlawful disclosure of inside information — before it causes harm, and to identify patterns that might indicate a control failure or cultural problem. Surveillance is not a passive monitoring exercise; it is an active programme that generates alerts, investigations, escalations, and in some cases, reports to regulators or law enforcement. Understanding how it works is essential context for anyone who works on a trading floor.

The Legal Foundation: Market Abuse Regulation

The Market Abuse Regulation (MAR), which applies in both the EU and (in onshored form) the UK, sets out the prohibited behaviours that surveillance is designed to detect:

  • Insider dealing: trading in a financial instrument while in possession of inside information — material, non-public information that would be likely to have a significant effect on the instrument's price.
  • Unlawful disclosure: passing inside information to another person who is not required to receive it in the normal exercise of their employment.
  • Market manipulation: conduct that sends false or misleading signals about the supply, demand, or price of an instrument; creates an artificial price level; or uses fictitious transactions or other deceptive devices.

MAR also establishes the suspicious transaction and order reporting (STOR) obligation: firms that reasonably suspect that a transaction or order constitutes market abuse must report this to the relevant NCA — in the UK, the FCA. This obligation applies to investment firms executing orders, including when they detect suspicious activity in their own employees' trading.

Trade Surveillance: What Systems Look For

Trade surveillance systems analyse trading activity against a set of scenarios — pre-programmed patterns that are associated with specific forms of market abuse. The scenarios are calibrated with thresholds: activity that crosses the threshold generates an alert for a compliance analyst to review.

Insider Dealing Scenarios

The classic insider dealing scenario flags trading activity in a security shortly before a material public announcement — an earnings release, a merger, a regulatory decision. The surveillance system compares the timing and direction of a trader's or employee's position against a database of corporate events. A position established the day before an acquisition announcement that significantly benefits from the announcement will be flagged. The alert does not mean insider dealing has occurred — there may be a legitimate explanation — but it requires investigation.

Insider dealing surveillance extends to personal account dealing (PAD). Employees who trade in securities related to their professional work are subject to restrictions and pre-clearance requirements. PAD surveillance compares employee personal trades (disclosed via a PAD system) against the firm's own deal flow and watch list. A compliance team member who purchased shares in a company the day after that company was added to the watch list would generate a PAD alert immediately.

Layering and Spoofing

Layering and spoofing are forms of market manipulation that involve placing orders with the intention of cancelling them before execution — the purpose being to create a false impression of supply or demand that moves the market, allowing the manipulator to profit on a genuine position. A typical spoofing pattern involves placing a large order on one side of the book, waiting for the price to move in response, executing a genuine trade on the other side, and then cancelling the large order.

Surveillance systems detect layering through order-level analysis: they look for patterns of rapid order submission and cancellation, high order-to-trade ratios, and the correlation between cancelled orders and executed trades on the opposite side. The technical challenge is distinguishing legitimate market-making activity — which also involves placing and cancelling orders rapidly — from manipulative spoofing. Alert calibration requires ongoing tuning to minimise false positives while capturing genuine misconduct.

Ramping and Painting the Tape

Ramping (creating an artificial price movement through a series of transactions) and painting the tape (creating the impression of active trading through wash trades between related accounts) are detected through price impact analysis and cross-account surveillance. Systems that look at transactions between accounts with a common beneficial owner, or sequences of transactions that systematically move a price in one direction without apparent commercial rationale, can flag these patterns.

Electronic Communications Surveillance

Trade surveillance catches what happens in the market. Communications surveillance catches what people say about it. MiFID II requires firms to record and retain communications relating to orders and transactions — telephone calls from trading desks, electronic messaging (Bloomberg IB, Symphony, WhatsApp where used for business), and email. These records must be retained for a defined period (five years in the EU and UK) and must be available to regulators on request.

Compliance teams use e-communications surveillance platforms to monitor recorded communications for language associated with market abuse. Surveillance dictionaries contain keywords and phrases — references to deal names before public announcement, language suggesting coordination between counterparties, discussions of trading positions in the context of non-public information — that trigger alerts. Natural language processing (NLP) tools increasingly supplement keyword searches, identifying patterns of language that may indicate intent even without explicit triggering terms.

Voice recording covers all telephone lines used for front-office business. In a modern trading room, every dealer line is recorded. Compliance can retrieve call recordings in response to an investigation or a regulatory request. The prospect of call recording is itself a deterrent — traders on a dealing floor operate in the knowledge that their conversations are preserved.

Case Management: From Alert to Resolution

Surveillance systems generate large volumes of alerts. The compliance surveillance team — the analysts who review them — must work through each alert and determine whether it represents a genuine concern or a false positive. Most alerts are closed as false positives after the analyst reviews the trading context, the available explanation, and any relevant communications.

Alerts that cannot be closed as false positives are escalated. The escalation pathway typically runs: compliance analyst → surveillance manager → Head of Compliance → if appropriate, Suspicious Transaction and Order Report (STOR) submission to the FCA. At each stage, the investigation deepens: additional trading data, communications records, and interviews with the relevant individuals are gathered and documented.

If the investigation concludes that market abuse has occurred, the firm is obligated to file a STOR with the FCA. The FCA uses STOR data as an intelligence source — it cross-references STORs with its own market data and may open an investigation, interview individuals, or issue a formal information request to the firm. In serious cases, the FCA can prosecute for criminal insider dealing under FSMA 2000, or take civil enforcement action under MAR.

Regulatory Consequences

The FCA's enforcement record in market abuse is extensive. High-profile cases have involved traders at major banks convicted of insider dealing, firms fined for inadequate surveillance systems, and individuals banned from working in financial services. The penalties reflect the seriousness with which regulators view market integrity: a market where participants believe others are trading on inside information or manipulating prices loses the price discovery function that makes it valuable to the economy.

For firms, the enforcement risk extends beyond the specific misconduct. A firm with demonstrably inadequate surveillance infrastructure — insufficient scenario coverage, poorly calibrated thresholds, a team without the resources or skills to review alerts effectively — faces regulatory censure for the control failure, separate from any penalty for the underlying abuse. The FCA expects surveillance programmes to be proportionate to the firm's activities, updated as markets and misconduct patterns evolve, and subject to ongoing senior management oversight.