Topic Resource
Financial Markets Trade Surveillance
Trade surveillance is the process of monitoring orders, cancellations, modifications, executions and related information for activity that may indicate market manipulation, insider trading or other violations of law, regulation or market rules. It is one of the principal mechanisms through which firms, trading venues and regulators protect market integrity and identify conduct requiring further investigation.
Surveillance may operate in real time, near real time or after the trading day. Its design depends on the market, asset class, business model and regulatory obligations involved. A trading venue may monitor activity across its order book, while a broker-dealer may review its customers’ transactions and the activity of its associated persons. Regulators may combine information from multiple venues, firms and reporting systems to develop a broader view.
In every setting, an alert is a starting point rather than a legal conclusion. Effective surveillance identifies potentially suspicious activity, places it in context and creates a documented process for review, escalation and, where required, regulatory reporting.
Who uses trade surveillance?
Trade surveillance is used by market participants, trading venues, regulators and self-regulatory organizations.
Broker-dealers, futures commission merchants and other intermediaries use surveillance to monitor activity conducted through their systems or accounts, including customer, proprietary and employee trading. Banks, investment firms, asset managers, commodity trading firms and proprietary trading firms may use it to oversee the conduct risks arising from their own products, strategies, personnel and market access.
Exchanges, designated contract markets, alternative trading systems and other trading venues monitor activity on their markets. Their responsibilities can include identifying disruptive or manipulative conduct, enforcing venue rules, maintaining orderly markets and referring potentially unlawful activity to regulators. Regulators and self-regulatory organizations conduct surveillance using transaction reports, order-book data, firm and venue referrals and other regulatory information.
Within an organization, surveillance is rarely the responsibility of a single team. Compliance and market-supervision personnel typically operate the program, but legal, trading, operations, technology, data governance and internal audit functions may all contribute to its design, maintenance and review. The precise obligations of each organization depend on its jurisdiction, regulatory status and role in the market.
What does trade surveillance look for?
Trade surveillance looks for orders, transactions and patterns of behavior that may create a false or misleading impression of supply, demand, price or trading activity; misuse material nonpublic information; disadvantage customers; disrupt orderly trading; or violate market-specific requirements.
Common areas of surveillance include:
- False or misleading supply and demand. Spoofing and layering generally involve placing orders without bona fide intent to execute them to influence other market participants or create a misleading appearance in the order book. Related strategies may include quote stuffing, momentum ignition and other forms of disruptive order activity.
- Artificial trading activity. Wash trades, self-trades and matched or prearranged transactions can create the appearance of liquidity, volume or market interest without a genuine change in beneficial ownership or market risk.
- Improper influence on prices or benchmarks. Marking the open or close, ramping and similar conduct may be designed to move a security or contract’s price, affect an auction or settlement, alter a valuation or benefit a related position.
- Misuse of information or position. Surveillance may address insider trading, front-running, trading ahead of customer orders, misuse of confidential order information and potentially abusive pre-hedging. These matters often require evidence beyond trading data to distinguish unlawful conduct from legitimate activity.
- Rule-specific conduct. Depending on the firm and market, surveillance may also test compliance with short-sale, position-limit, order-handling, trade-through or market-making requirements.
- Cross-market and cross-product activity. Conduct in one instrument or venue may be intended to affect the price of a related instrument, benchmark or position elsewhere. A review limited to a single market may therefore miss the activity’s economic purpose.
These categories describe risks rather than automatic findings. The same trading pattern may be suspicious in one context and legitimate in another. Liquidity, volatility, account relationships, market conditions, trading history and the participant’s apparent economic rationale can all affect the analysis. Questions of intent are particularly important in cases such as spoofing, manipulation and insider trading, but intent generally cannot be established by an alert alone.
How does trade surveillance work?
An effective trade-surveillance program begins before the first alert is generated. It translates the risks and legal obligations associated with a firm’s actual business into data requirements, detection procedures and a documented process for investigation and escalation.
Risk assessment and coverage design
The organization first identifies the products, venues, customer types, trading strategies and jurisdictions within its business. It then considers which forms of misconduct or rule violations could arise in those circumstances. This assessment determines what the program should monitor and helps prevent a generic set of procedures from being applied to markets with materially different characteristics.
Data collection and normalization
Surveillance commonly relies on the full order lifecycle, including submissions, modifications, cancellations and executions, together with market data, account information and reference data. Depending on the risk, the analysis may also require positions, beneficial-ownership relationships, short-sale locates, news, communications or activity in related products and venues.
The data must be complete, accurate, timely and consistently mapped. A procedure cannot identify activity that never reaches the surveillance system, and errors in timestamps, account identifiers or instrument mappings can distort the sequence or significance of events. Reconciliation, data-quality checks and monitoring for missing or anomalous feeds are therefore part of the surveillance framework rather than merely technical support functions.
Detection and calibration
Surveillance systems apply rules, thresholds, statistical techniques, anomaly detection or machine-learning models to identify activity for review. Some procedures search for defined patterns, such as a large order that is canceled after smaller orders execute on the opposite side of the market. Others compare an account’s behavior with its own history, peer activity or prevailing market conditions.
Detection methods must be calibrated to the relevant product and business. A threshold suitable for a liquid, highly priced equity may be ineffective for a thinly traded security, while a model designed for a central limit order book may not translate directly to a request-for-quote market. Calibration should balance manageable review volumes with adequate coverage. Reducing false positives is not an end in itself if the adjustment also suppresses meaningful activity.
Triage, investigation and escalation
Analysts review alerts to determine whether the activity has a reasonable explanation or warrants deeper investigation. That review may involve reconstructing the order lifecycle, examining related accounts and instruments, comparing the activity with market conditions and historical behavior and obtaining information from trading, operations or other control functions.
The reviewer documents the evidence considered, the analysis performed and the basis for closing or escalating the matter. Material concerns may be referred to legal or senior compliance personnel, investigated further, addressed through restrictions or other remedial measures and reported to a regulator or trading venue where required.
Governance and continuing review
Surveillance programs must change as the business, markets and regulatory expectations change. Firms commonly maintain written procedures, approval and change records, reviewer training, quality assurance, management reporting and periodic testing of data, scenarios and investigative outcomes. Automated methods can help prioritize alerts, identify recurring patterns and perform routine analysis, but the program must remain explainable and auditable.
Trade surveillance is therefore not simply a technology deployment. It is a continuous supervisory process that integrates legal requirements, market knowledge, data governance, detection tools and human judgment.
The global regulatory framework
Trade surveillance is governed through a combination of laws prohibiting market abuse, rules requiring firms to supervise trading activity and obligations imposed on exchanges and other trading venues. The structure differs by jurisdiction. Some regimes expressly require specified firms to maintain systems for detecting and reporting suspicious orders and transactions; others derive surveillance responsibilities from broader supervisory, market-integrity and venue obligations.
United States
The United States does not have a single trade-surveillance rule that applies uniformly to every market participant. The applicable duties depend on the instrument, the organization’s registration status, its role in the market and the conduct at issue.
In the securities markets, Sections 9 and 10(b) of the Securities Exchange Act of 1934 and SEC Rule 10b-5 prohibit specified forms of manipulation, fraud and deception. Other requirements address particular areas of trading activity. Regulation SHO, for example, governs short sales, including order marking and locate requirements. National securities exchanges and the Financial Industry Regulatory Authority (FINRA) maintain additional rules on conduct and trading practices.
For FINRA members, FINRA Rule 3110 requires a supervisory system and written procedures reasonably designed to achieve compliance with applicable securities laws and FINRA rules. Rule 3110(d), the transaction-review and investigation provision, specifically requires procedures reasonably designed to identify trades that may violate prohibitions on insider trading and manipulative or deceptive devices, covering the firm’s own accounts, accounts it introduces or carries and the accounts of its associated persons. A firm’s surveillance procedures should therefore reflect its own business, including the markets it accesses, the products it offers and the activity conducted through its accounts. FINRA also performs cross-market surveillance on behalf of most U.S. equities and options exchanges under regulatory services agreements, which gives it a consolidated view of order and trade activity across venues that no single exchange or member firm has.
The data backbone for U.S. securities surveillance is the Consolidated Audit Trail, or CAT. SEC Rule 613 required the national securities exchanges and FINRA to build a single audit trail that captures the full lifecycle of every order, quote and trade in NMS stocks, listed options and over-the-counter equity securities, reported by exchanges and broker-dealers and linked to the customer and account information needed to attribute activity. CAT replaced FINRA’s Order Audit Trail System and the earlier patchwork of exchange-specific audit trails, and it is the principal dataset the SEC and the self-regulatory organizations use to reconstruct market events and surveil conduct across venues. The scope of customer-identifying information that CAT collects has been narrowed by SEC exemptive relief and remains subject to change, but the order-lifecycle data at its core is what makes cross-market surveillance of the equities and options markets possible. Broker-dealers’ own surveillance runs on their own order data; CAT is what allows the regulators to see the same activity in the context of the whole market.
The Commodity Futures Trading Commission (CFTC) administers the parallel federal framework for futures, options on futures, swaps and commodity markets within its jurisdiction. The Commodity Exchange Act prohibits manipulation and attempted manipulation, and Section 4c(a)(5) prohibits specified disruptive practices, including spoofing. CFTC Regulation 180.1 prohibits manipulative and deceptive devices in connection with swaps, commodity sales in interstate commerce and futures contracts.
Designated contract markets also serve as frontline regulators of their markets. The Commodity Exchange Act’s core principles require them to monitor trading, prevent market disruption, maintain audit trails and enforce rules against abusive practices. The CFTC conducts its own oversight and surveillance using exchange data, large-trader information, reports and other regulatory sources.
The National Futures Association (NFA) is the registered futures association for the U.S. derivatives industry. Futures commission merchants, introducing brokers, commodity pool operators, commodity trading advisors, retail foreign exchange dealers and swap dealers must be NFA members, and NFA Compliance Rule 2-9 requires each member to diligently supervise its employees and agents in the conduct of their commodity interest activities. NFA examines members’ supervisory systems, operates its own surveillance of members’ retail forex activity and provides trade practice and market surveillance services to swap execution facilities under regulatory services agreements. Unlike the securities markets, the futures markets have no consolidated audit trail; each designated contract market maintains its own audit trail, and the CFTC’s cross-market view is built from exchange data and its large-trader reporting system.
Across both the securities and derivatives regimes, firms may use third-party systems or services to support surveillance. Doing so does not transfer the regulated entity’s responsibility for maintaining an appropriately designed and functioning supervisory program.
European Union
The European Union’s principal market-abuse framework is Regulation (EU) No 596/2014, commonly known as the Market Abuse Regulation or MAR. MAR prohibits insider dealing, unlawful disclosure of inside information, market manipulation and attempted market manipulation across the financial instruments and markets within its scope.
Article 16 places express prevention, detection and reporting obligations on market operators, investment firms operating trading venues and persons professionally arranging or executing transactions. Covered organizations must maintain effective arrangements, systems and procedures for detecting potentially abusive orders and transactions. When there is a reasonable suspicion of market abuse or attempted market abuse, the relevant authority must be notified without delay through a suspicious transaction and order report, or STOR.
Delegated Regulation (EU) 2016/957 provides further detail on the arrangements, systems, procedures and reporting templates associated with that duty. The framework expects surveillance to be proportionate to the organization’s business while remaining capable of analyzing orders as well as completed transactions. MiFID II and MiFIR provide surrounding requirements concerning trading systems, algorithmic trading, transaction reporting and market data, but those requirements should be distinguished from MAR’s specific market-abuse framework.
United Kingdom
Following the United Kingdom’s departure from the European Union, UK MAR provides a broadly comparable domestic framework, administered and enforced by the Financial Conduct Authority (FCA). Firms and trading venues within its scope must maintain effective arrangements, systems and procedures to detect and report suspicious orders and transactions, including attempted market abuse.
The FCA has repeatedly emphasized that surveillance should be appropriate and proportionate to the nature, scale and complexity of the business. Its supervisory observations address market-abuse risk assessments, data quality, calibration, alert review, governance, recordkeeping and coverage across products and asset classes. In Market Watch 79 (May 2024), for example, the FCA reiterated that firms must be able to identify and report potential market abuse and maintain effective systems for doing so.
STORs are one source of information for the FCA, which also performs its own monitoring using order-book data, transaction reports and other regulatory information. A firm’s decision not to submit a STOR should therefore be based on a documented assessment rather than an assumption that the regulator will not identify the activity independently.
Other global markets
Although national requirements vary, many jurisdictions follow a similar division of responsibilities: the law prohibits insider trading and manipulation; trading venues monitor and enforce their markets; intermediaries supervise relevant customer and employee activity; and the regulator conducts market-wide surveillance and investigates referrals.
Australia provides one example. The Australian Securities and Investments Commission (ASIC) performs real-time and post-trade surveillance of licensed markets and oversees compliance with the Corporations Act and market integrity rules. Market participants must report suspicious activity as soon as practicable and are expected to maintain controls for identifying, assessing and escalating potentially manipulative conduct. Singapore, Hong Kong and other major financial centers likewise combine statutory market-abuse prohibitions with supervisory and venue-level controls, although the precise scope and reporting process differ.
International standards developed by the International Organization of Securities Commissions (IOSCO) encourage effective market oversight, access to trading information and cross-border cooperation. Those standards provide a common reference point, but the operative duties remain those imposed by each jurisdiction.
Trade surveillance across markets and asset classes
The same underlying categories of market abuse recur across financial markets, but their observable signs depend on how each market operates. Surveillance must account for differences in liquidity, trading protocols, venue fragmentation, price formation, trading hours and the relationships among instruments.
In equities, trading may be dispersed across exchanges and off-exchange venues. A complete review may require orders, cancellations and executions from several sources, as well as information about opening and closing auctions, short-sale activity and related options. Thinly traded or low-priced securities may require different thresholds from highly liquid stocks because a smaller order can have a greater effect on price or apparent demand.
Options, futures and other derivatives introduce relationships between the contract and its underlying asset. Surveillance may need to evaluate whether trading in one instrument was intended to influence the price, settlement or value of another. Expirations, position limits, delivery mechanisms and benchmark-setting periods can create additional risks.
Fixed-income, foreign-exchange and swaps markets often include bilateral, dealer-to-client or request-for-quote trading rather than a single visible order book. Liquidity may be episodic, pricing information may be distributed across sources, and communications may provide important context for a transaction. Procedures designed for exchange-traded equities cannot simply be transferred to these markets without adjustment.
Longer trading hours add another layer. Overnight sessions may have thinner liquidity, fewer reference points and different patterns of participation than regular hours. As markets move toward near-continuous trading, surveillance programs must account for regional handoffs, system availability and behavior that crosses one trading day or session boundary.
The same principle applies across all asset classes: surveillance should reflect the economic and structural characteristics of the activity being monitored. A pattern that is meaningful in one market may be ordinary in another.
How the framework fits together
Trade surveillance sits at the point where substantive law, institutional responsibility and operational controls meet. Laws and regulations define prohibited conduct, such as manipulation, insider trading and disruptive trading practices. Registration requirements, supervisory rules and venue obligations determine which organizations must monitor activity, maintain records, enforce rules or report suspicions.
Firms and trading venues translate those duties into risk assessments, written procedures, data controls, detection methods, investigations and escalation paths. Regulators and self-regulatory organizations conduct their own surveillance, receive reports and referrals, request records and bring enforcement actions. These layers are related but not interchangeable: a regulator’s market-wide monitoring does not displace a firm’s supervisory obligations and the use of a surveillance provider does not transfer responsibility away from the regulated organization.
A single course of conduct may engage several parts of the framework at once. The activity may violate a statutory prohibition, expose a weakness in a firm’s supervisory system, breach a trading venue’s rules and trigger a reporting obligation. Effective surveillance therefore requires legal analysis, business and product knowledge, reliable data, appropriately designed technology, trained reviewers and defensible records to work together as a connected system.
What are the limits of trade surveillance?
Trade surveillance can identify activity that warrants review, but it cannot determine automatically whether a legal violation occurred. An alert reflects a rule, threshold, model or observed pattern. Establishing misconduct may require evidence of intent, knowledge, beneficial ownership, communications, market impact or the absence of a legitimate economic rationale.
The quality of the result also depends on the quality and scope of the information available. Missing orders, inaccurate timestamps, incomplete account mappings, absent market data or activity occurring on another venue can obscure a pattern or produce a misleading one. Cross-market surveillance can reduce these gaps, but no individual firm necessarily has access to the same breadth of information as a regulator.
Detection methods have limitations of their own. Rules and models encode assumptions about normal and suspicious behavior. If thresholds are too broad, reviewers may be overwhelmed by alerts with little investigative value. If they are too restrictive, meaningful activity may never be presented for review. Models can also become less effective as markets, products and participant behavior change. Calibration, validation and periodic testing are therefore continuing requirements rather than one-time implementation tasks.
Legitimate activity can resemble abuse. Market making, hedging, liquidity management, error correction or trading in correlated instruments may produce patterns similar to wash trading, spoofing, marking or front-running. Trading data alone may not resolve the distinction; communications, positions, customer information and input from the business may be necessary.
Finally, technology cannot compensate for weak governance. Insufficient staffing, poor training, outdated procedures, inconsistent investigations or failures to escalate concerns can undermine an otherwise capable system. The purpose of surveillance is not to guarantee that misconduct will never occur. It is to make relevant risk visible, support consistent and timely review and preserve a defensible record of how the organization responded.
Key authorities
United States, securities. Securities Exchange Act of 1934, Section 9, 15 U.S.C. § 78i; Section 10(b), 15 U.S.C. § 78j; SEC Rule 10b-5, 17 C.F.R. § 240.10b-5; Regulation SHO, 17 C.F.R. §§ 242.200 to 242.204; SEC Rule 613 (Consolidated Audit Trail), 17 C.F.R. § 242.613; FINRA Rule 3110.
United States, derivatives. Commodity Exchange Act, Section 6(c)(1), 7 U.S.C. § 9; Section 9(a)(2), 7 U.S.C. § 13; Section 4c(a)(5), 7 U.S.C. § 6c; CFTC Rule 180.1, 17 C.F.R. § 180.1; Section 5(d) core principles, 7 U.S.C. § 7 and 17 C.F.R. Part 38; NFA Compliance Rule 2-9.
European Union. Regulation (EU) No 596/2014 (MAR), Article 16; Commission Delegated Regulation (EU) 2016/957; Directive 2014/65/EU (MiFID II); Regulation (EU) No 600/2014 (MiFIR).
United Kingdom. UK MAR (Retained Regulation (EU) No 596/2014); FCA Market Watch 79 (May 2024).
Australia and international. Corporations Act 2001 (Cth); ASIC Market Integrity Rules (Securities Markets) 2017; IOSCO, Objectives and Principles of Securities Regulation (May 2017).
Further Reading
Insightful thought leadership, offered as a resource for readers.
Martina Rejsjö · Eventus Systems, Inc. · July 2025
Published by Eventus, a trade surveillance software vendor, and written by its Head of Product Strategy. The author argues that surveillance conducted within single asset-class silos misses conduct whose economic purpose spans related products and venues, and makes the case for cross-product analysis that follows the activity rather than the instrument.
Considerations for Spoofing Detection – Proving Intent
Chris Waitz · Eventus Systems, Inc. · October 2022
Published by Eventus, a trade surveillance software vendor, and written by its Director of Regulatory Affairs at the time; the piece closes with a description of the vendor’s own product. It summarizes the trading-pattern indicators the CFTC cited as evidence of intent in a set of spoofing enforcement orders, including the relative size of genuine and non-bona fide orders, order display, cancellation timing and fill rates. The article was also republished on TabbFORUM.
Frequently asked questions
What is trade surveillance?
Trade surveillance is the monitoring of orders, cancellations, modifications, executions and related information for activity that may indicate market manipulation, insider trading, disruptive conduct or other violations of law or market rules. It includes the processes used to generate and review alerts, investigate activity, document conclusions and escalate or report concerns.
Is trade surveillance required by law?
The answer depends on the jurisdiction, market, organization’s regulatory status and activity involved. Some regimes impose explicit detection and reporting duties. Article 16 of EU MAR and UK MAR, for example, requires covered organizations to maintain systems for detecting and reporting suspicious orders and transactions. In the United States, surveillance responsibilities may arise through broker-dealer supervisory duties, exchange and SRO rules, designated contract market core principles and other market-specific requirements. There is no single rule that applies identically to every market participant.
Does a trade-surveillance alert mean that market abuse occurred?
No. An alert indicates that activity met specified criteria or differed from an expected pattern and should be reviewed. The investigation may identify a legitimate explanation, insufficient evidence or conduct requiring escalation. A finding of market abuse generally depends on the applicable legal standard and the full factual context, which may include intent, communications, customer relationships, market impact and economic rationale.
What information does trade surveillance use?
Surveillance commonly uses order-lifecycle data, executions, market data, account and customer identifiers, instrument reference data and positions. Depending on the risk, it may also incorporate beneficial-ownership information, short-sale locates, communications, news, related-product activity and data from multiple venues. Complete and accurate data is essential because omitted or incorrectly mapped activity can prevent a procedure from identifying the relevant pattern.
What is the difference between trade surveillance and transaction monitoring?
The terminology is not uniform. In a market-conduct context, transaction monitoring may refer broadly to reviewing trading activity and can overlap with trade surveillance. In anti-money-laundering programs, however, transaction monitoring generally means reviewing movements of money or assets for suspicious financial activity. The two functions may share data and identify related concerns, but they address different risks and reporting regimes. Trade surveillance focuses principally on market conduct, trading behavior and market integrity.
Can a firm outsource trade surveillance?
A firm may use third-party technology, managed services or other outside expertise to support its surveillance program. Outsourcing does not ordinarily transfer the regulated firm’s responsibility for compliance. The firm must still understand its risks, ensure that coverage and data are appropriate, oversee the service, investigate and escalate relevant matters, maintain required records and be able to explain its program to regulators.
Is trade surveillance conducted in real time?
It can be. Real-time or near-real-time surveillance may be appropriate where conduct could disrupt a market or require prompt intervention. Post-trade surveillance allows firms and regulators to analyze completed activity with a broader dataset and may be better suited to patterns that emerge across accounts, products, venues or longer periods. Many programs use both approaches, depending on the risk and applicable requirement.
How this page connects
Trade surveillance draws on several areas covered elsewhere in this resource center. The SEC, CFTC, FINRA and NFA framework governing U.S. financial markets is covered in Foundation One (Market Regulation). Conduct standards, supervisory obligations, recordkeeping and customer relationships are covered in Foundation Two (Trading Conduct & Supervision). How surveillance referrals become regulatory investigations, enforcement actions and NFA or FINRA arbitration is covered in Foundation Three (Disputes & Enforcement). The SEC and CFTC whistleblower programs, a parallel channel through which misconduct reaches regulators, are covered in Foundation Five (Whistleblower Programs). Manipulation, spoofing and other conduct issues in U.S. derivatives and foreign-exchange markets are covered in Foundation Six (Futures, FX & Trading Conduct). How the same surveillance objectives are pursued in cryptocurrency and other digital asset markets is covered in Digital Asset Trade Surveillance on digitalasset.law.
If you need counsel
This page is general legal information, not advice about a specific situation. G. Dowd Law LLC maintains this resource center and practices in this area; the Contact page explains how to reach the firm.
Eventus Systems, Inc., a trade surveillance software vendor, contributed to the drafting of this page. Neither party paid the other for its contribution, and G. Dowd Law LLC retains editorial control.