Essay — surveillance

What the numbers can and can't prove

A high ratio is not a crime. The metrics a surveillance program runs describe behavior; they do not carry intent. This essay traces five of them from raw log to derived number to the point where the number stops being evidence.

July 30, 2026

A red flag on a compliance screen is, almost always, a number. A ratio has crossed a line. A cancellation rate sits three standard deviations above a desk's peers. A participant's orders live and die in milliseconds. The number is arithmetic, and arithmetic is exact. The temptation is to read the exactness as a verdict.

It is not a verdict. Every offense the number is meant to surface, spoofing, layering, wash trading, turns on intent. The law does not prohibit placing an order and canceling it. It prohibits placing an order you never meant to execute, in order to deceive someone else about supply or demand. No single metric carries that distinction inside it. A number can tell you that a pattern occurred. It cannot tell you why. That gap, between the pattern and the reason for it, is where this essay lives, and it is the reason the discipline of trade reconstruction exists at all.

The argument runs in five parts. First, how a metric is actually made, so the newcomer can see that these numbers are derived, not observed. Then the heart of it: five of the metrics a surveillance program runs, each paired with the legitimate behavior that produces the same signature. Then the pivot, where the number hands off to reconstruction. Then what the enforcement record shows about which of the two, the number or the reconstruction, actually wins cases. And finally the calibration problem that sits underneath all of it: someone has to choose where the line goes, and that choice is never neutral.

How a metric is made

A derived metric is not a thing the market emits. It is a thing computed after the fact from the record every electronic order leaves behind.

Consider the order-to-trade ratio, the most widely cited surveillance metric and the only one written into rule text. It is built from the trail an order leaves at each moment of its life, every event stamped to the microsecond and written to the record:

Moment in an order's lifeWhat the venue records
PlacedThe order identifier, the account behind it, the side, the price, the size, and the microsecond it arrived.
ModifiedThe change to price or size, with a fresh timestamp.
CanceledThe cancellation, and the duration the order survived before it.
FilledThe match against a resting order on the other side.

An order is placed, then modified, canceled, or filled; the ratio ignores all of that structure and performs a single division: orders entered over orders that resulted in a trade. A participant who enters a thousand orders and trades ten has a ratio of a hundred to one.

That is the entire construction. The number is real, and it is reproducible, and two analysts computing it from the same logs will agree. What they will not agree on, and what the number does not contain, is whether a ratio of a hundred to one is a market maker doing its job or a spoofer at work. The arithmetic is settled. The meaning is not.

The comparison that helps here is a batting average. It compresses a season of at-bats into one number that captures a hitter's record without telling you whether any single swing was skill, luck, or a called shot. The order-to-trade ratio is the same: it compresses thousands of orders into one figure, summarizing what happened without explaining any of it.

The legitimate twin

Every metric a surveillance program runs has a twin: a legitimate trading behavior that produces the same signature. This is not an edge case. It is the structural problem at the center of trade surveillance, and it holds across all five metrics. In each row below, one signature fires the alert, and it is produced with equal fidelity by a manipulative pattern and by the legitimate behavior beside it.

MetricThe signature that fires the alertThe legitimate behavior that produces it too
Order-to-trade ratioA high ratio: many orders entered, few filled.A market maker quoting continuous two-sided prices, trading against only a fraction of them by design.
Cancellation rateRapid, high-volume cancellation.Quote management: pulling quotes at once as prices move, news arrives, or risk limits tighten.
Self-match frequencyThe same beneficial owner on both sides of a trade.Two of a firm's own desks or algorithms crossing by coincidence, uncoordinated and blind to each other.
Average order durationOrders canceled milliseconds after entry.A latency-sensitive strategy chasing a quote that itself lasts only a moment.
Market-impact correlationFlagged activity moving together with price.A participant anticipating a move and positioning ahead of it, rather than causing it.

The last of these reaches closest to intent and still falls short of it: correlation shows that activity and price moved together, never which one caused the other, and causation is the entire claim.

The pattern is exact across all five. Each metric measures a real feature of trading, computes it correctly, and flags a signature that manipulation genuinely produces. And each flags, with equal fidelity, a legitimate behavior that produces the identical signature. The metric is not wrong. It is just not, by itself, an answer.

Where the number stops

If the metric cannot distinguish the manipulator from the market maker, something else must. That something is reconstruction: assembling the flagged activity back into the sequence it came from, and reading the sequence for what the number cannot show.

Reconstruction is where intent becomes visible, or fails to. The order-to-trade ratio flags a participant; the reconstructed sequence shows whether the large canceled orders sat on the opposite side from a small order that filled just before they vanished. The cancellation rate flags a desk; the reconstruction shows whether the cancellations tracked genuine price moves or preceded, again and again, a profitable fill on the other side. Self-match frequency flags a crossing; the reconstruction shows whether the two sides were coordinated or blind to each other. Duration flags a fleeting order; the reconstruction shows whether the trader ever stood to benefit from its execution. In every case, the metric locates where to look, and the reconstruction supplies what the metric could not: the timing, the repetition, the relationship between the flagged orders and the genuine ones, and, where the records hold it, the contemporaneous evidence of what the trader meant to do.

This is why the metric is the beginning of an inquiry and never the end of one. A number narrows the field. A reconstruction reads it.

What the enforcement record shows

The enforcement record settles the question, because it shows what regulators must actually prove to win. In the cases that hold up, they do not win on a ratio. They win on the reconstructed sequence and on the intent it reveals.

In the United States, the anchor case is the Commodity Futures Trading Commission's 2020 order against JPMorgan. The firm paid a total of 920.2 million dollars, the largest monetary relief the Commission had then imposed for spoofing, comprising a 436.4 million dollar penalty, 311.7 million dollars in restitution, and more than 172 million dollars in disgorgement.1 The order did not rest on an order-to-trade ratio breaching a threshold. It found that, over at least eight years, the firm's traders placed hundreds of thousands of orders with the intent to cancel those orders prior to execution, sending false signals of supply and demand to induce other participants to trade. Intent is the finding. The same order faulted the firm for failing to identify, investigate, and stop the conduct despite its own internal surveillance alerts,1 which is the clearest possible statement that a fired alert is a prompt, not a conclusion: the alerts existed, and they were not the same thing as a case.

JPMorgan · CFTC 2020 · futures
What happenedFrom 2008 to 2016, traders placed large precious-metals and Treasury futures orders they intended to cancel, moving the price toward smaller genuine orders on the opposite side.
The signatureHigh order-to-trade ratios; large orders canceled shortly after entry; internal alerts that fired.
What reconstruction establishedThe sequence tied each large canceled order to a small opposite-side fill; internal communications showed the tactic was routine; intent to cancel before execution was the finding.
Outcome920.2 million dollars total; CFTC Docket 20-69. The firm's own alerts were faulted as insufficient on their own.

The United States equities record makes the point from the opposite procedural direction, through litigation rather than settlement. In Securities and Exchange Commission v. Lek Securities Corporation, a New York federal jury in November 2019 found a trading firm headquartered in Kyiv, Ukraine, and two individuals liable for a scheme that generated more than 25 million dollars in illicit profit.2 The conduct was layering, placing and canceling orders to move prices, together with genuine cross-market manipulation, trading stocks to affect the price of related options. What is instructive is that the case was tried. A jury had to be persuaded that the cancel-heavy pattern was manipulative rather than merely fast, and it was persuaded not by the metric but by the reconstructed scheme and the evidence of intent behind it. The broker had settled first, and the terms of that settlement include a detail that matters for the calibration argument below: the Commission alleged the broker made the scheme possible partly by relaxing its layering controls after the trader complained about them.3 The surveillance threshold existed. It was moved.

Lek / Avalon · SEC 2019 · equities
What happenedA Kyiv-based firm, trading through a New York broker-dealer, placed and canceled orders to move stock prices, and traded stocks to move related options prices.
The signatureCancel-heavy order flow; the layering pattern; co-movement between the stock and options legs.
What reconstruction establishedReconstructed sequences showed orders entered to create false pressure and pulled once genuine orders filled; the cross-market leg linked the stock trades to options gains. Proven to a jury.
OutcomeJury verdict; more than 25 million dollars in illicit profit. The broker had relaxed its layering controls under pressure from the trader.

The United Kingdom supplies the case that states the thesis most plainly, because there the legitimate twin was the defense. In Lopez Gonzalez, Sheth and Urra v Financial Conduct Authority, three traders on the European government bond desk at Mizuho International traded Italian government bond futures on the Eurex order book across the summer of 2016.4 The regulator's case was that they placed large orders they did not intend to execute, to create a false impression of demand and shift the price toward smaller genuine orders on the opposite side, canceling the large orders once the small ones filled. The traders' defense was that the same large orders were an information-discovery strategy: a third-tier market maker, seeing only a fragment of client flow and operating at an informational disadvantage, entering conspicuous orders to test where genuine interest lay.5 One order-book signature; two accounts of it, manipulation and legitimate market making, advanced in the same courtroom. The Upper Tribunal upheld the regulator's findings in July 2025, determining the conduct was deliberate and dishonest,4 but it reached that conclusion by weighing the pattern across the flagged occasions, testing the traders' explanations, and finding them not credible, not by pointing at a cancellation rate. The proof was hard to assemble: the regulator's decision notices came more than six years after the 2016 conduct, and the matter concluded only in 2025.5 The difficulty was never the number. It was proving what the number could not show.

Mizuho · FCA / Upper Tribunal 2025 · futures
What happenedThree traders placed large Italian government bond futures orders they did not intend to execute, canceling them once smaller genuine orders on the opposite side had filled.
The signatureLarge orders, high cancellation, a cancel-on-fill pattern indistinguishable on its face from market making or information discovery.
What reconstruction establishedThe pattern across the flagged occasions, weighed against the traders' information-discovery defense, established the intent the signature alone could not.
OutcomeUpper Tribunal upheld the bans, July 2025; the conduct was found deliberate and dishonest.

Three regimes, two offense types, one pattern: in each, the signature located the conduct, and the reconstruction proved it.

A note on the European Union, kept deliberately brief because the record itself is brief. The apparatus is there: the Market Abuse Regulation defines manipulation to include placing orders that give false or misleading signals as to supply, demand, or price, and its indicator framework treats such patterns as signals of possible manipulation rather than manipulation as such.6 But the visible enforcement by national competent authorities runs heavily to disclosure and insider-dealing matters rather than order-book spoofing and layering. The metrics are universal arithmetic. The depth of order-book enforcement is not, and the same signature that produces a litigated case in New York or London may produce no case at all elsewhere. That asymmetry is worth naming, because it shows the metric is not self-executing. Someone has to choose to run it to a conclusion.

The threshold problem

Which returns us to the choice underneath everything. There is no correct order-to-trade ratio. The regulation that governs it in the European Union, Regulatory Technical Standard 9 under the second Markets in Financial Instruments Directive, requires trading venues to limit the ratio of unexecuted orders to transactions, and then, tellingly, declines to set the number. It leaves each venue to set the maximum ratio it judges appropriate to prevent disorderly trading, calculated per member and per instrument.7 The most codified metric in surveillance is codified as a discretion, not a value.

That discretion is the whole game, and it is not neutral. Set a threshold low and the surveillance program drowns in false positives, flagging every market maker and every fast desk, burying the genuine cases in noise and burning analyst hours on the innocent. Set it high and the program misses the manipulator operating just under the line. There is no setting that eliminates both errors, because the manipulator and the market maker occupy the same range of the distribution. Every threshold is a policy choice about which error to prefer, made by a person or a committee, revisited or left alone, and, as the Lek settlement showed, sometimes moved under pressure from the very participant it was meant to watch. The mechanics of that tradeoff, the thresholds applied across instruments that do not behave alike, the windows set shorter than the risk, the order flow that never reaches the system at all, are the subject of a companion essay: Why trade surveillance produces false positives.

For the practitioner, the other half of the twin table: what reconstruction must establish, metric by metric, to separate the legitimate behavior from the manipulation. The order-to-trade ratio is set at venue discretion under RTS 9; the rest are matters of surveillance calibration, not codified values.

MetricWhat reconstruction must establish to separate the twin from the manipulation
Order-to-trade ratioWhether the large canceled orders sat opposite a small fill that benefited from them.
Cancellation rateWhether the cancellations preceded profitable opposite-side fills, again and again.
Self-match frequencyWhether the two sides were coordinated or blind to each other.
Average order durationWhether the trader ever stood to gain from the order's execution.
Market-impact correlationWhether the activity caused the price move or merely read it.

The number as prompt

The metric, then, does exactly one thing well, and it is a valuable thing. It narrows a market of billions of orders to a handful worth a human's attention. That is not a small service. A surveillance program without metrics is a program reading the whole tape by hand, which is to say no program at all.

But narrowing is not proving. The number surfaces a candidate. Reconstruction builds, or fails to build, the case. And intent, which neither the number nor the reconstruction can read directly, has to be inferred from the assembled sequence and whatever contemporaneous record survives. The enforcement that holds up honors that order every time: the ratio flags, the reconstruction reads, the intent decides. Reverse it, treat the flag as the finding, and you have accused a market maker of doing its job.

The discipline of trade reconstruction exists precisely because the metric is insufficient. That is not a flaw in the metric. It is the metric's honest limit, and the work begins where the number stops.

Notes

Links captured and verified July 30, 2026. Regulatory pages, enforcement notices, and court decisions are updated or withdrawn over time; a link resolving correctly at capture is not a guarantee it will still resolve, or still say the same thing, when read later.

  1. On the record 920.2 million dollar total, its composition, and the finding that the firm's traders placed orders with the intent to cancel before execution while its own surveillance alerts went unaddressed, see Commodity Futures Trading Commission, “CFTC Orders JPMorgan to Pay Record $920 Million for Spoofing and Manipulation,” Press Release 8260-20, September 29, 2020 (In the Matter of JPMorgan Chase & Co. et al., CFTC Docket No. 20-69): cftc.gov.
  2. On the November 2019 jury verdict, the more than 25 million dollars in illicit profit, and the layering and cross-market manipulation charges, see Securities and Exchange Commission, “SEC Wins Jury Trial in Layering, Manipulative Trading Case,” Press Release 2019-236, November 12, 2019 (SEC v. Lek Securities Corporation, No. 17-cv-1789, S.D.N.Y.): sec.gov.
  3. On the broker settlement and the allegation that the firm relaxed its layering controls after the trader complained, see Securities and Exchange Commission, “SEC Obtains Final Judgments Against Lek Securities and CEO in Layering, Manipulation Case,” Press Release 2019-205, October 1, 2019: sec.gov.
  4. On the conduct in BTP futures on Eurex from 1 June to 29 July 2016, the Article 15 Market Abuse Regulation basis, and the Tribunal's determination that the conduct was deliberate and dishonest, see Financial Conduct Authority, “Tribunal upholds the FCA's market manipulation bans,” July 1, 2025, and the Upper Tribunal judgment, Lopez Gonzalez, Sheth and Urra v The Financial Conduct Authority [2025] UKUT 214 (TCC): fca.org.uk, gov.uk.
  5. On the traders' information-discovery defense, the Tribunal's rejection of it after testing their credibility, and the timeline (decision notices dated 31 October 2022, published December 2022; final notices dated 5 August 2025, more than six years after the 2016 conduct), see Lopez Gonzalez, Sheth and Urra v The Financial Conduct Authority [2025] UKUT 214 (TCC), together with Financial Conduct Authority, Final Notice: Poojan Sheth, 5 August 2025 (reference PXS02369): fca.org.uk, fca.org.uk.
  6. On the definition and prohibition of market manipulation, the indicator framework, and the legitimate-reasons exemption, see Regulation (EU) No 596/2014 (Market Abuse Regulation), Article 12 (definition), Article 15 (prohibition), Article 13 (accepted market practice), and Annex I, with the indicators specified by Commission Delegated Regulation (EU) 2016/522, Article 4 and Annex II: eur-lex.europa.eu, eur-lex.europa.eu.
  7. On the requirement that trading venues limit the ratio of unexecuted orders to transactions, with the maximum ratio set by each venue per member and per instrument, see Commission Delegated Regulation (EU) 2017/566 (Regulatory Technical Standard 9) of 18 May 2016, supplementing Directive 2014/65/EU (MiFID II): eur-lex.europa.eu.

The enforcement actions, court decisions, and regulatory instruments described here are current to July 2026 and continue to change as regulators and courts issue new findings and amend the rules.

Responses from readers

This website does not host open comments. Verified responses are published here at the editor's discretion. Submit a response to editorial@tradesreconstructed.com.