Written by a human
Communications Surveillance in Financial Services
In brief:
- What it is: the proactive monitoring of business communications to detect conduct, compliance, and market-abuse risk. Also called eComms surveillance or communications supervision.
- Why it matters: firms are required to supervise their communications, FINRA Rule 3110 in the US, and the Market Abuse Regulation and MiFID II / FCA SYSC 10A in the EU and UK.
- How it works: capture communications, enrich and transcribe them, filter out noise, detect risk with lexicons and AI, then review and escalate.
- The shift: detection is moving from keyword lexicons toward AI and large language models that read context, widening coverage and cutting false positives.
- The state of play: per the 1LOD 2026 Surveillance Benchmarking Survey, AI adoption is accelerating but not yet fully embedded, and data quality is the limiting factor.
What it is · Why firms need it · What it detects · How it works · Lexicon vs AI · Voice surveillance · Trade surveillance & holistic · Where it’s heading · What good looks like · FAQ
What is communications surveillance?
Communications surveillance is the proactive monitoring of business communications, email, instant messaging, chat, voice, and social media, to detect conduct, compliance, and market-abuse risk. It’s also known as eComms surveillance or communications supervision. Some firms draw a fine distinction between supervision (the regulatory obligation to review communications) and surveillance (the monitoring and detection activity that fulfils it), but in practice the terms are used interchangeably.
The purpose is twofold: to identify problems, market manipulation, insider dealing, offensive or threatening language, attempts to move business off-channel, leaks of confidential information, and to deter them, because employees who know their communications are monitored are less likely to cross the line. Surveillance sits directly on top of recordkeeping. You can only monitor what you’ve captured, so if capture is incomplete, surveillance is built on sand.
This guide explains why communications surveillance is required, what it looks for, how it works, how detection has evolved from keyword lexicons to AI, and what an effective surveillance program looks like.
Why do firms need communications surveillance?
Communications surveillance is a supervisory obligation, not a discretionary control. Several regimes require it:
FINRA Rule 3110 (US). Requires broker-dealers to supervise their business, including the review of electronic communications, alongside the recordkeeping duties in SEC Rule 17a-4 and FINRA Rule 4511.
The Market Abuse Regulation (EU/UK). Obliges firms to monitor for, and report, potential market abuse. See our complete guide to the Market Abuse Regulation.
MiFID II and FCA SYSC 10A (EU/UK). Require firms to record and monitor communications relating to transactions and investment services. See our SYSC 10A guide.
Beyond the letter of the rules, surveillance is how firms actually find risk. The off-channel enforcement wave, more than $3 billion in combined SEC and CFTC penalties since 2021, exposed how much business communication was escaping capture and monitoring entirely, and with it any chance of detecting the misconduct those messages might contain. Surveillance closes that loop: it turns captured communications into an early-warning system.
What does communications surveillance detect?
A surveillance program is tuned to a firm’s risks, but the common categories include:
- Market abuse: insider dealing, market manipulation (such as spoofing, wash trading, and front running), and collusion between traders.
- Unlawful disclosure of inside information: leaks of material non-public information and breaches of information barriers.
- Off-channel activity: referrals that move a conversation to an uncaptured channel, such as “contact me on WhatsApp” or “let’s take this offline.”
- Non-financial misconduct: bullying, harassment, and offensive, threatening, or discriminatory language toward colleagues.
- Mis-selling and unsuitable advice: communications that misrepresent products or pressure clients.
- Confidential-information and data risks: disclosure of sensitive client or firm information.
This breadth is expanding. According to the 1LOD 2026 Surveillance Benchmarking Survey (sponsored by Global Relay), 89% of respondents said they would use surveillance tools to proactively monitor workplace culture in 2026, up from 59% in 2024, a shift driven partly by the growing regulatory focus on non-financial misconduct.
How does communications surveillance work?
Modern communications surveillance is a pipeline that turns raw, messy communications data into a manageable queue of genuine risks for human reviewers. The typical stages are:
- Capture and standardization. Communications are captured at source across every channel and normalized into a consistent, enriched format, because inconsistent or incomplete data undermines everything downstream.
- Transcription and translation. Voice and video are transcribed to text, and multiple languages are handled, so spoken communications can be analyzed alongside written ones.
- Noise reduction. Low-risk content, marketing material, disclaimers, spam, previously reviewed threads, is filtered out to reduce false positives before analysis.
- Risk detection. The remaining communications are analyzed against risk scenarios using lexicons and, increasingly, AI models that read context.
- Alert management and review. Flagged items are prioritized and routed to reviewers, who investigate, document their decisions, and escalate where needed.
Global Relay’s surveillance approach reflects this pattern: in November 2024 it moved to a five-layered model spanning data standardization and enrichment, transcription and translation, noise reduction, risk identification, and alert management.
Lexicon vs AI: how has detection evolved?
For years, surveillance ran on lexicons, predefined lists of keywords and phrases that flag potentially risky messages. Lexicons remain a useful, efficient tool for catching high-risk terms, and most programs still use them. But they have a well-known weakness: they do not understand context. A word that is risky in one sentence is harmless in another, so keyword matching generates large volumes of false positives, buries reviewers in noise, and misses coded language or misconduct expressed without the trigger words.
AI, and specifically large language models, address this by analyzing a message in full context rather than scanning for isolated terms. Contextual models can weigh the meaning of a conversation, distinguish genuine risk from innocent use of the same words, and surface subtle or ambiguous misconduct that a lexicon would miss while cutting false positives through techniques such as trusted-sender lists, disclaimer exclusion, and thread suppression. The trade-off firms manage is between recall (catching everything that matters) and precision (not drowning in alerts); the aim of AI-enabled surveillance is to improve both at once, with transparent, explainable reasoning that a reviewer and a regulator can follow.
For how this connects to the wider compliance stack, see digital communication compliance: from email to AI.
What about voice surveillance?
Voice is a business communication channel like any other, and it is squarely within scope. MiFID II and FCA SYSC 10A require firms to record calls relating to transactions, and in the US the Dodd-Frank Act imposes recording obligations on certain registrants. History underlines the stakes: the LIBOR manipulation scandal turned in large part on collusion conducted over voice and messaging that went undetected for years.
Voice is harder to monitor than text: audio must be transcribed accurately despite accents, slang, code words, background noise, and multiple languages, and voice features are now embedded in messaging and collaboration apps as well as phones and trading turrets. Accurate transcription is what makes voice searchable and analyzable alongside eComms. See our guidance on voice recordkeeping requirements and enhancing voice surveillance controls.
Communications surveillance, trade surveillance, and holistic surveillance
Communications surveillance and trade surveillance answer different halves of the same question. Trade surveillance monitors orders and transactions for manipulative patterns; communications surveillance monitors what people said around those trades. Neither is complete on its own. A suspicious trade is far more defensible as market abuse when the messages around it show intent. And a suspicious message means more when tied to the trading it accompanied. Bringing the two together is called holistic surveillance.
This matters most for market abuse. Under the Market Abuse Regulation, firms must monitor for insider dealing and market manipulation and file Suspicious Transaction and Order Reports (STORs) where warranted. The off-channel enforcement wave exposed a hard truth here: the missing communications the fines were about may also have contained the evidence of market abuse that firms and regulators never got to see. See our analysis of the challenge of proving market abuse.
Where is communications surveillance heading?
Two shifts define the next few years, both captured in the 1LOD 2026 Surveillance Benchmarking Survey. The first is AI: around 70% of firms report being in proof-of-concept or active deployment of AI for eComms and voice surveillance, yet not a single respondent said AI was fully embedded in their operating model, the technology is arriving faster than the data foundations needed to use it. The second is scope: surveillance built for market abuse is increasingly being pointed at conduct and culture, including non-financial misconduct.
The survey also carried a pointed regulator message, a foreword from the FCA describing the current period as “the calm before the storm,” and a finding that 22% of banks admit their current surveillance infrastructure does not effectively manage market abuse risk. The through-line is that data quality, not algorithms, is the real constraint: AI-enabled surveillance is only as good as the completeness and consistency of the communications feeding it.
As firms adopt tools like Copilot, ChatGPT, and other LLM-based assistants, the communications landscape is changing, employees may be pasting sensitive data into external AI tools or having AI-generated content enter the surveillance pipeline.
What does good communications surveillance look like?
- Complete capture. Surveillance covers every channel used for business, because monitoring an incomplete data set produces false confidence.
- Risk-based coverage. Detection is mapped to the firm’s actual risks and documented, rather than applied uniformly or arbitrarily.
- Contextual detection. Lexicons and AI are combined to balance recall and precision, with false-positive management built in.
- Holistic view. Communications, voice, and trade signals are brought together rather than reviewed in silos.
- Strong governance. Systems are tested, alerts are evidenced, and decisions are documented, an area regulators have flagged as frequently under-resourced.
- Efficient review workflows. Reviewers spend their time on genuine risk, not clearing noise, supported by prioritization and explainable alerts.
Frequently asked questions
What is communications surveillance?
The proactive monitoring of business communications such as: email, chat, voice, and social media, to detect conduct, compliance, and market-abuse risk. It is also called eComms surveillance or communications supervision.
What is the difference between communications surveillance and supervision?
They are largely used interchangeably. Where firms distinguish them, supervision refers to the regulatory obligation to review communications, and surveillance to the monitoring and detection activity that satisfies it.
What is the difference between communications surveillance and trade surveillance?
Trade surveillance monitors orders and transactions for manipulative patterns; communications surveillance monitors what people say. Combining the two, holistic surveillance, gives a fuller picture of conduct and market-abuse risk.
What rules require communications surveillance?
In the US, FINRA Rule 3110 (supervision) alongside recordkeeping rules such as SEC Rule 17a-4 and FINRA Rule 4511. In the EU and UK, the Market Abuse Regulation and MiFID II / FCA SYSC 10A.
What does communications surveillance detect?
Market abuse (insider dealing and manipulation), unlawful disclosure of inside information, off-channel activity, non-financial misconduct such as harassment, mis-selling, and disclosure of confidential information.
Is AI replacing lexicon-based surveillance?
Not entirely. Lexicons remain useful for flagging high-risk terms, but AI and large language models add contextual understanding that reduces false positives and catches coded or ambiguous misconduct. Most firms use both.
Does communications surveillance cover voice calls?
Yes. Voice is in scope under MiFID II, FCA SYSC 10A, and Dodd-Frank. Calls are transcribed so they can be analyzed alongside written communications, though accents, slang, and audio quality make voice harder to monitor.
How Global Relay helps
Good surveillance starts with complete, high-quality data and ends with accurate, explainable alerts.
Good surveillance starts with complete, high-quality data and ends with accurate, explainable alerts. Global Relay Surveillance captures communications across email, chat, voice, and collaboration channels, then uses AI with an integrated chain-of-thought process to analyze each message in context, improving recall while cutting false positives through noise filtering and trusted-sender lists. Learn more about Global Relay’s communications monitoring.
Related reading: