A trade surveillance system has to separate two kinds of activity that look nearly identical in the data. A purchase made on inside information and a purchase made on an ordinary judgment call. A large order placed to move a price and a large order placed and then canceled because the trader changed their mind. A matched trade between related accounts and normal two-sided trading on a busy desk. In each pair, the abusive and the legitimate version share almost all of their observable features. The difference is intent, which the trade record does not capture.
Because the abusive cases are rare and hard to distinguish, the system is set to cast a wide net. A wide net produces false positives: alerts on activity that turns out to be legitimate. This is not, by itself, a defect. It is the expected result of screening for a rare event across a large volume of ordinary trading.
The obvious response is to narrow the criteria: raise thresholds, shorten look-back windows, or switch off scenarios that rarely produce anything. The difficulty is that the same adjustments that reduce false positives also reduce the chance of catching real abuse. False positives and missed abuse are two results of the same calibration decisions. Reduce one without care and you increase the other.
Why false positives arise
Almost every false positive, and almost every missed signal, traces back to a small number of configuration choices. None is unusual. Each is a reasonable decision taken without reference to the specific risk it is meant to address.
The first is a single threshold applied to instruments that do not behave alike. A price move worth reviewing in a FTSE 100 constituent is a different size from a move worth reviewing in an illiquid small-cap, a government bond, or a corporate bond. One common threshold either misses the sensitive instrument or, calibrated to the sensitive one, produces large numbers of alerts on routine moves in every other instrument. The Financial Conduct Authority (FCA) described the effect in its 2022 guidance: a shared threshold across dissimilar instruments will generate "a high amount of 'noise'."1
The second is a look-back window set shorter than the risk. Inside information often exists well before its public release; a takeover approach can exist for weeks. An insider-dealing scenario that examines only trading in the final days before an announcement will not see a position built before that window opened. That trading never generates an alert.1
The third is a coverage gap: order flow that never reaches the surveillance system. A system reviewing only part of a firm's activity will report nothing unusual about the part it cannot see. This failure is the hardest to catch, because an absence of alerts looks like an absence of problems.
The fourth is context removed from the alert. Closing an alert because there is no obvious link between the client and the source of inside information treats the absence of a visible connection as evidence of innocence. It is not. It is only the absence of a connection the reviewer had in front of them.
The fifth is a scenario carried on trust. Where alert logic is taken from a vendor and never examined, a firm may not know which behaviors a scenario captures, or whether it is switched on. A scenario that has produced nothing for a long period is read as a well-behaved market when it may be a scenario that is not working.
| Configuration | Why it misfires | Example |
|---|---|---|
| One threshold across different instruments | Calibrated to the most sensitive instrument, it alerts on routine moves in every other instrument; calibrated loosely, it misses the sensitive instrument. | A 3% move is a normal day in an illiquid small-cap but an event in a large-cap; one threshold cannot suit both. |
| Look-back window set too short | Examines only the period just before an announcement, missing positions built while the information already existed. | A stake accumulated two weeks before a leak never enters a seven-day scenario. |
| Order flow only partly connected | The system reports nothing unusual about activity it cannot see. | A firm adds a new order-routing system but never connects its feed into the surveillance system, so those trades never reach it and cannot raise an alert. |
| Context removed from the alert | An alert is closed because no obvious client-to-issuer link is visible; absence of a known link is treated as absence of suspicion. | Layering across linked accounts is closed as "no connection found" because the connection was never checked. |
| Scenario carried on trust | Vendor logic is never examined; a scenario that never fires is assumed to be working. | An alert type sits switched off for months and the silence is read as an orderly market. |
In each case the system is applying a fixed definition of what a suspicious trade looks like. If that definition does not match the firm's actual risk, the system will be wrong, and it will be wrong consistently, because the error is built into the configuration rather than occurring at random.
A recent case: Dinosaur Merchant Bank Limited
A 2026 enforcement case shows how these failures combine in practice. On March 24, 2026, the FCA fined Dinosaur Merchant Bank Limited (DMBL) £338,000 for failing to identify and report suspicious trading in its contract for difference (CFD) business.2 Every failure in the case is a calibration or coverage failure, and the firm believed its surveillance was working until the regulator asked why expected reports had not arrived.
| Element | What happened |
|---|---|
| The change | In June 2024 the firm introduced a new order system giving clients direct market access. Weekly CFD trades rose about 45% over the following four months. |
| The gap | Trades placed through the new system were never routed into the surveillance system. From June to October 2024, roughly $3.05 billion in notional value went unexamined by the automated review. |
| The signal ignored | Trades rose about 45% while alerts fell about 42%. The divergence sat in the monthly board reports, without a prior-month comparison to make it visible, and was not acted on. |
| The calibration fault | The insider-dealing scenario used a seven-day look-back, equal to five working days, too short to capture information that existed longer before release. |
| The silent scenarios | Several alert types had never fired during the period and were never checked to confirm they were switched on, receiving data, and working. The FCA calls a scenario that produces no output "an indicator that the scenario is not functioning as intended". |
| How it surfaced | Not internally. The FCA contacted the firm asking why the suspicious transaction and order reports (STORs) it expected had not been submitted. |
| The re-run | A later re-run of the June to October 2024 trades produced 2,916 alerts, of which 2,723 concerned insider dealing, and led to multiple STORs submitted after the fact. |
The look-back fault is the detail worth noting. The FCA had described this same error in its 2022 guidance, four years before the fine.1 The firm was not undone by a novel failure but by a known one, encoded into a scenario and never revisited when the business changed around it.
How the regulators frame it
The three regions in view address this problem in different terms.
The FCA frames it as calibration and false comfort. Its guidance treats alert scenarios as choices that must match the specific risks of the business, and its enforcement treats a quiet system as a claim to be tested rather than a result to be trusted. The DMBL notice is that position applied to a specific firm.
The European Securities and Markets Authority (ESMA) approaches from the reporting side. Its annual work on STORs tracks reporting behavior across national competent authorities (NCAs),3 and its 2019 peer review pressed regulators to challenge poor-quality reporting4: the defensive filing that mirrors, on the reporting side, what over-broad calibration produces on the alert side. The volume figures track how much is reported; the peer review addresses whether it is useful.
The Monetary Authority of Singapore (MAS) and Singapore Exchange Regulation (SGX RegCo) address the operational core directly. Their joint practice guide treats surveillance quality as a standing review question and names both failure directions plainly, calling for more frequent review of programs with "no or few exceptions, or too many false positives."5 A near-silent program and one buried in false positives are treated as equally in need of attention. The guide also notes that most of the brokers it reviewed still examined exception reports by hand, an approach it warns is inefficient and open to error.
The Financial Industry Regulatory Authority (FINRA) frames the tension as a supervision problem. In its 2026 findings it names the calibration failures directly: surveillance thresholds "set too low or too high to identify meaningful activity,"6 thresholds not built for the relevant class of securities or for both customer and proprietary trading, and a failure to re-evaluate controls when the business, the customer base, or the market changes. It also records the failures further downstream: alerts not reviewed in time, too little resource and training to work them, and review findings left undocumented. An unreviewed backlog is the same problem seen from the enforcement side: alerts generated but never worked.
No common benchmark
One limit is worth stating directly. Unlike anti-money-laundering monitoring, trade surveillance has no accepted public benchmark for alert quality. There is no agreed figure for how much noise is too much, and no shared measure a firm can hold its calibration against. Firms and regulators discuss thresholds without a common scale, which is part of why the same errors recur across institutions and across years.
That absence does not weaken the conclusion. Calibration is not a maintenance task. It sets what the system treats as suspicious, and every threshold, window, and scenario is part of that definition. A system calibrated to the wrong definition will still report confidently, and a firm reading those reports may see nothing wrong until a regulator asks why they were empty.
Notes
Links captured and verified July 29, 2026. Regulatory pages and enforcement notices are updated or withdrawn over time; a link resolving correctly at capture is not a guarantee it will still resolve, or still say the same thing, when read later.
- On the calibration of order and trade surveillance to the characteristics of each asset class, the risk that a generic threshold generates excessive noise, and the weakness of look-back windows set too short for insider-dealing scenarios, see Financial Conduct Authority, Market Watch 69, May 2022: fca.org.uk. ↩
- On the £338,000 penalty, the roughly $3.05 billion left unexamined, the seven-day look-back, the divergence between a 45% rise in trades and a 42% fall in alerts, the retrospective re-run, and the quoted phrase on scenarios that produce no output, see Financial Conduct Authority, Final Notice: Dinosaur Merchant Bank Limited, March 24, 2026 (reference 436215): fca.org.uk. ↩
- On STOR volumes and composition across national competent authorities, see European Securities and Markets Authority, Report on Suspicious Transaction and Order Reports (STORs), December 19, 2025 (ESMA74-268544963-1554): esma.europa.eu. ↩
- On the call for national regulators to challenge poor-quality and defensive reporting, see European Securities and Markets Authority, Final Report: Peer Review on the collection and use of STORs under the Market Abuse Regulation as a source of information in market abuse investigations, December 12, 2019 (ESMA42-111-4916): esma.europa.eu. ↩
- On the call for more frequent review of programs with no or few exceptions, or too many false positives (paragraph 2.14, under Principle 2), and the finding that most brokers reviewed exception reports manually (paragraph 2.4), see Monetary Authority of Singapore and Singapore Exchange Regulation, MAS-SGX Trade Surveillance Practice Guide, August 2019: sgx.com. ↩
- On surveillance thresholds set too low or too high to identify meaningful activity, thresholds not tailored to the class of securities or to both customer and proprietary trading, the failure to re-evaluate controls as the business or market changes, and the alert-review and documentation failures (Manipulative Trading, page 20; the supervision obligation under FINRA Rule 3110 at page 19), see Financial Industry Regulatory Authority, 2026 Annual Regulatory Oversight Report, December 2025: finra.org. ↩
The enforcement actions, reports, and guidance described here are current to July 2026 and continue to change as regulators issue new findings and amend their rules.
Responses from readers
This website does not host open comments. Verified responses are published here at the editor's discretion. Submit a response to editorial@tradesreconstructed.com.