Why the new test for trade surveillance is not whether a control exists, but whether a firm can prove it worksMore than 1,000 wash trades. More than 600 client accounts. More than 700 securities. Nearly two years.
And in multiple instances, the misconduct generated just one alert.
Those numbers sit at the center of a recent Hong Kong Securities and Futures Commission enforcement action against a securities firm whose market-abuse detection systems failed to keep pace with the risk. Despite warnings, updates proved ineffective. A pre-trade prevention system was not introduced until halfway through the relevant time period—and when it was, it too was inadequate.
The lesson travels far beyond Hong Kong: a control on paper is no longer enough. Regulators increasingly expect firms to demonstrate that their systems are effective, resilient and capable of doing the job they were put in place to do.
The Question Has Changed
On July 7, SEC Chairman Atkins issued a statement on the Commission’s 2026 Regulatory Agenda, pointing to what he called “significant progress” in returning the agency to its core mission: protecting investors, facilitating capital formation and maintaining fair, orderly and efficient markets.
That mission dates back to the Securities Exchange Act of 1934. The mandate is longstanding; the way regulators pursue it is not. As technology changes the speed and scale at which misconduct can occur, enforcement is evolving with it—and the shift is visible well beyond the SEC.
Traditionally, law enforcement has been reactive: a crime is committed, investigators work out who did it and how, and penalties are intended to deter the next would-be offender. Financial-services enforcement has often followed the same pattern: surveillance systems process a day’s data overnight; alerts are reviewed the next morning—after the damage may have already been done. By then, the rogue trader is probably already making their escape, if not (quite literally) already a continent away.
Technology has begun to rewrite that timeline. High-speed data feeds and more advanced analytics can now detect some forms of market abuse in real time, or close to it. A suspicious action can be questioned before the trading day is over—and before anyone reaches the airport.
No system can read minds and apprehend someone before they do something bad, so the practical goal is to increase the likelihood of timely detection and tip the risk-reward calculation away from attempted market abuse. Being able to achieve that at scale has changed what regulators expect from both their own capabilities and the firms that serve as gatekeepers to the markets.
Regulators Are Raising Their Capabilities — and Their Expectations
Regulators have responded on two fronts. First, they have strengthened their own analytical capabilities. If the COVID pandemic reinforced anything in regulation, it was the value of high-powered data analysis. Major regulators have since invested heavily in the people and technology needed to process enormous volumes of information every day.
Second, regulators increasingly view banks, broker-dealers and other intermediaries as gatekeepers to the markets. The systems and controls firms are required to maintain must remain proportionate to the nature and scale of the business, as it scales. More importantly, they must actually work.
Together, those two developments mark the critical shift: the focus is moving from the mere presence of a control, to proof of its effectiveness.
In the United States, regulated firms faced more than $2 billion in fines and sanctions for recordkeeping failures between 2022 and 2025. In some cases, technical systems were inadequate; in others, business communications were not routinely recorded. Chairman Atkins has noted that these sweeps uncovered no instances of actual market abuse, and both the SEC and CFTC have recently said that campaign is over.
But the scrutiny has not disappeared; rather, it is being refocused. Regulators have seen too many control failures create real opportunities for wrongdoing for them to ignore whether or not those controls are actually doing what firms say they do. The emerging expectation is clear: systems and controls must be provably, demonstrably effective. And the United States is only one part of a much wider pattern.
A Global Pattern, Not an Isolated Warning
Enforcement actions across jurisdictions tell the same story. In early 2026, the UK Financial Conduct Authority fined a firm whose market-abuse detection systems had not kept pace with an expansion of its business. The failure was compounded when the firm did not remediate the problems promptly.
The pattern extends beyond market surveillance. Around 2020, Australia’s anti-money-laundering regulator, AUSTRAC, fined several firms over failures in AML detection and reporting controls. In 2026, the SEC and FINRA have acted against firms where due-diligence and control-environment shortcomings meant suspicious trades were not properly investigated or reported—and earlier weaknesses had not been adequately corrected.
In August 2026, FinCEN imposed its largest-ever AML fine, emphasizing that deficiencies in implementing and maintaining an effective AML program—first identified in 2018—had still not been adequately addressed by 2023. The latest penalty was 8.6 times the one imposed on the same firm in 2018.
The message behind these cases is hard to miss. Finding a weakness is serious, but failing to fix it can be worse. Taken together, the cases point to an urgent operational question: what does provably effective surveillance require?
Three Pillars of Effective Surveillance
For firms, the answer is not simply to install another piece of technology. It is to maintain an operating discipline that ensures the right data reaches the right platform, outputs are understood and tested, accountability is clear, identified problems are corrected, and investigations, escalations and reporting are thorough.
Across the enforcement examples, the details differ, but the underlying weaknesses are strikingly consistent: gaps in coverage, understanding, testing or response. Add the constant pressure to work efficiently, and three connected pillars emerge: completeness, explainability and intelligence.
Complete: Can You Prove Nothing Was Missed?
Completeness starts with coverage. Was every venue captured? Every communications channel? Every in-scope business activity? Were orders linked with the relevant communications and messages? And, crucially, can the firm prove that nothing fell through the gaps?
The amount of data a firm holds is not the measure that matters. What matters is whether all relevant activity was captured, connected and available when scrutiny arrives.
Explainable: Can You Show Why the System Responded the Way it Did?
Completeness is only the beginning. A firm must also understand why an alert did - or did not - trigger for a given data set. How were thresholds and parameters calculated? When were they last reviewed? What tests were run? Could the firm demonstrate all of this during a regulatory examination?
An alert without a clear decision trail may identify a result; however it does not prove the control operated as intended. And even a fully explained alert has limited value if the surrounding evidence remains fragmented.
Intelligent: Can You Connect the Full Story?
Effective surveillance must produce useful intelligence - and firms must use that intelligence well. That means correlating trades with communications, reconstructing the events behind a set of facts and doing it quickly, even under pressure.
AI can help by connecting information, accelerating analysis and supporting these tasks within one platform. But intelligence is not automation for its own sake; it is the ability to turn complete information into meaningful context that helps human experts investigate, decide and act. Together, completeness, explainability and intelligence turn surveillance from a control the firm possesses into a capability it can defend.
The Real Standard is Effectiveness
The question is no longer simply whether a firm has surveillance controls: it is whether the firm can prove those controls are complete, explainable, tested and ultimately, effective.
That proof has practical consequences. Firms that can demonstrate comprehensive coverage, explain how their controls operate, validate performance and respond quickly when weaknesses emerge will be better positioned to satisfy regulators. Those that cannot may discover that enforcement focuses not only on misconduct, but on the controls that should have detected or prevented it - particularly where a process failure can be linked to financial crime or an increased risk that one could occur.
At its heart, effectiveness is simple to describe but demanding to deliver: a surveillance system must be appropriate and proportionate to the business, it must work, and the firm must test it regularly - if not continuously - to be sure. When it does not work, the firm must be able to find the problem and fix it.
Sometimes it is not the market abuse itself, but the absence of adequate and effective systems to detect it, that brings regulatory censure. Ignoring red flags or failing to act on warnings can make the consequences more severe.
As expectations continue to evolve, the challenge is no longer simply implementing surveillance. It is demonstrating effectiveness in a way that is defensible, repeatable and regulator-ready.
Ready to move from having controls to proving they work? Learn how NICE Actimize helps financial institutions build more complete, explainable and intelligent surveillance.