Written by a human
Trade Surveillance in Financial Services
In brief:
- What it is: the monitoring of trading activity — orders and transactions — to detect and prevent market abuse and manipulative behavior.
- Why it matters: firms are required to detect and report market abuse, and failures carry record penalties — including JPMorgan’s $920.2 million spoofing settlement in 2020, the largest ever imposed by the CFTC.
- What it detects: insider dealing, spoofing, layering, wash trading, front running, price ramping, and quote stuffing.
- How it works: ingest order, trade, and market data, run it through detection scenarios, generate alerts, investigate, and report.
- The context gap: trade surveillance shows what happened in the market; it takes communications surveillance to show why. Together they form holistic surveillance.
What it is · Why firms need it · What it detects · How it works · The challenges · Trade vs communications surveillance · How AI is changing it · What good looks like · FAQ
What is trade surveillance?
Trade surveillance is the monitoring and analysis of trading activity — orders placed, amended, canceled, and executed, together with the market data around them — to detect and prevent market abuse and other manipulative behavior. Where communications surveillance monitors what people said, trade surveillance monitors what they did in the market.
It works by comparing trading behavior against known patterns of abuse. A single order looks innocent; it is the shape of activity over time — the timing, sizing, cancellation rates, and price impact — that reveals manipulation. Trade surveillance systems run that data against detection scenarios, flag anything that fits a manipulative pattern, and route it to compliance analysts to investigate.
This guide explains why trade surveillance is required, what it detects, how it works, the challenges firms face, and why it is only fully effective when paired with communications surveillance.
Why do firms need trade surveillance?
Trade surveillance is a regulatory requirement, not a discretionary control. Firms that trade or arrange trades in regulated markets must monitor for, and report, potential market abuse. The obligations flow from several regimes:
The Market Abuse Regulation (EU/UK). Requires firms to detect and report suspicious transactions and orders. See our complete guide to the Market Abuse Regulation.
MiFID II (EU/UK). Sets out transaction reporting and record obligations that underpin the data trade surveillance relies on.
US law. The Securities Exchange Act and SEC rules, the Commodity Exchange Act and CFTC rules, and FINRA and exchange rules all require monitoring for manipulative trading. Spoofing, for example, was explicitly outlawed by the Dodd-Frank Act of 2010, which amended the Commodity Exchange Act to prohibit it.
The stakes are high and well-documented. In 2020, JPMorgan agreed to pay $920.2 million — the largest monetary relief ever imposed by the CFTC — to resolve spoofing and manipulation across the precious metals and US Treasury futures markets spanning at least eight years. In 2018, HSBC paid $101.5 million to resolve charges that its traders engaged in front running ahead of a client’s foreign-exchange transaction. Regulators have also turned their attention to the quality of firms’ surveillance itself: the FCA’s Market Watch 79 flagged inadequate trade-surveillance models as a serious concern, as we discussed in this Regulatory Wrap.
What does trade surveillance detect?
Trade surveillance is tuned to the specific forms of market abuse a firm is exposed to. The main categories are:
Insider dealing — trading on material non-public information.
Spoofing — placing orders with no intent to execute, to create a false impression of supply or demand, then canceling them.
Layering — a form of spoofing using multiple orders at different price levels to move the market.
Wash trading — buying and selling the same instrument to create the illusion of activity. See our explainer on wash trading.
Front running — trading ahead of a client order to profit from the price move it will cause.
Price ramping — trading to push a price to an artificial level. See our explainer on price ramping.
Quote stuffing — flooding a venue with orders and cancellations to slow other participants and obscure activity.
Detection depends on complete, high-quality data, and reporting infrastructure plays a role too — regulators have used data from FINRA’s Trade Reporting and Compliance Engine (TRACE) to bring spoofing actions.
How does trade surveillance work?
A trade-surveillance program turns raw market activity into a manageable queue of investigations. The typical stages are:
- Ingest data. Collect order, execution, and market data across venues, asset classes, and desks, plus reference data such as instrument and account details.
- Run detection scenarios. Apply models and thresholds designed to flag each type of abuse — spoofing, wash trading, insider dealing, and so on.
- Generate alerts. Activity that matches a scenario is flagged and prioritized for review.
- Investigate. Analysts examine the alert, gather context, and decide whether it reflects genuine misconduct or a false positive.
- Report. Where suspicion is confirmed, firms file the relevant report — under the Market Abuse Regulation, a Suspicious Transaction and Order Report (STOR) — and take internal action.
A recurring theme is calibration. Thresholds set too tightly bury analysts in false positives; set too loosely, they miss abuse. Models must be tested and tuned continually as markets, products, and tactics change — an area regulators scrutinize closely.
What are the challenges of trade surveillance?
Even well-resourced firms find trade surveillance hard. The persistent challenges are:
- False positives. Scenario-based detection generates large volumes of alerts, most of which are not abuse — consuming analyst time and risking real cases being lost in the noise.
- Data quality and completeness. Surveillance is only as good as the data feeding it; gaps across venues, desks, or asset classes create blind spots.
- Cross-product and cross-venue manipulation. Abuse that spans instruments or trading venues is hard to see in systems that monitor each in isolation.
- Evolving tactics. Manipulation techniques change, and static models trained on yesterday’s patterns miss tomorrow’s.
- Model testing and governance. Regulators expect firms to test alerts, evidence coverage, and govern their models — the FCA’s Market Watch 79 highlighted cases where surveillance gaps went undetected for extended periods.
The hardest challenge of all is proving intent. Trading data can show that a pattern occurred, but establishing that it was deliberate often requires the communications around the trade — which is where communications surveillance becomes essential. See our analysis of the challenge of proving market abuse.
Trade surveillance vs communications surveillance — and why you need both
Trade surveillance and communications surveillance are distinct disciplines that answer different questions. Trade surveillance tells you what happened in the market — the orders and executions that form a suspicious pattern. Communications surveillance tells you why — the messages, calls, and chats that reveal intent, collusion, or knowledge of inside information.
Neither is complete on its own. A suspicious trading pattern is far more defensible as market abuse when the communications around it show intent; a suspicious message means more when tied to the trading it accompanied. Bringing the two together is called holistic surveillance, and it is increasingly what regulators and firms expect. In practice, trade surveillance and communications surveillance are often delivered by different specialist systems, and firms integrate them to get a complete picture.
Global Relay is a communications surveillance specialist, not a trade-surveillance vendor. Our role in this picture is the communications and context layer — capturing and analyzing the messages, voice, and chat that sit alongside trading activity, so that a firm’s trade-surveillance system has the intent and context it needs to turn an alert into a defensible case.
How is AI changing trade surveillance?
Trade surveillance is being reshaped by AI and machine learning, which can detect anomalies that fixed thresholds miss, reduce false positives by learning what normal behavior looks like, and connect signals across products and venues. But adoption is uneven. According to the 1LOD 2026 Surveillance Benchmarking Survey (sponsored by Global Relay), around 70% of firms are in proof-of-concept or active deployment of AI for surveillance, yet not one respondent said AI was fully embedded — and 22% of banks admitted their current infrastructure does not effectively manage market-abuse risk.
The consistent message is that data quality, not algorithms, is the real constraint: AI-enabled surveillance is only as good as the completeness and consistency of the data feeding it. See our analysis of what the 1LOD 2026 survey tells us.
What does good trade surveillance look like?
Effective programs share the same characteristics:
- Risk-based scenario coverage. Detection is mapped to the firm’s actual products, markets, and abuse risks, and documented.
- Complete, high-quality data. Order, trade, and market data is captured accurately across every venue and asset class.
- Calibrated, tested models. Thresholds are tuned to balance detection against false positives, and models are tested and governed.
- Holistic integration. Trade signals are combined with communications surveillance so intent and context sit alongside the trading pattern.
- Evidenced governance. Coverage, testing, and investigation decisions are documented and defensible to a regulator.
Frequently asked questions
What is trade surveillance?
The monitoring of trading activity — orders and transactions, together with market data — to detect and prevent market abuse and manipulative behavior.
What is the difference between trade surveillance and communications surveillance?
Trade surveillance monitors what people did in the market; communications surveillance monitors what they said. Combining the two is called holistic surveillance.
What does trade surveillance detect?
Insider dealing, spoofing, layering, wash trading, front running, price ramping, and quote stuffing, among other manipulative patterns.
What rules require trade surveillance?
In the EU and UK, the Market Abuse Regulation and MiFID II. In the US, the Securities Exchange Act, the Commodity Exchange Act, and FINRA and exchange rules. Spoofing was specifically outlawed by the Dodd-Frank Act.
What is a STOR?
A Suspicious Transaction and Order Report — the report firms must file under the Market Abuse Regulation when they suspect market abuse.
Why do trade-surveillance systems produce so many false positives?
Scenario-based detection flags any activity that resembles a manipulative pattern, and much legitimate trading does. Calibration and, increasingly, AI are used to reduce the noise without missing genuine abuse.
Does Global Relay provide trade surveillance?
Global Relay is a communications surveillance specialist, not a trade-surveillance vendor. It provides the communications and context layer that complements a firm’s trade-surveillance system to enable holistic surveillance.
How Global Relay helps
Trade surveillance tells you what happened in the market; it takes communications to tell you why. Global Relay is a communications surveillance specialist, and provides the context layer that sits alongside your trade-surveillance system: Global Relay Surveillance captures and analyzes messages, voice, and chat to surface intent, collusion, and knowledge of inside information — turning a trading alert into a defensible case. Learn more about Global Relay’s communications monitoring.
Related reading (internal links):