For trade surveillance teams, generating an alert is only the beginning. The real challenge is ensuring alerts are meaningful, giving analysts the context they need to investigate them efficiently, and continually assessing whether the parameters behind them remain effective.
KPMG’s 2026 trade surveillance research highlights how traditional surveillance is struggling with increasingly algorithmic markets, creating “alert noise, missed signals, and rising costs” as outdated detection systems generate large numbers of false positives. With alert volumes continuing to place pressure on compliance teams, firms need to consider where efficiency can be gained across the entire lifecycle of an alert.
The first opportunity comes at the point of alert generation. Standard surveillance logic can generate significant noise when it is applied without enough context around the market or the client. On the other hand, considering factors such as volatility, liquidity, corporate actions, client type and trading behaviour can help firms establish more relevant thresholds and ensure any alerts that reach analysts warrant genuine attention.
At the other end of the process, parameters cannot simply be set and left unchanged as market conditions and trading behaviours evolve. And throughout the alert lifecycle, fragmented data and manual investigation can also make it harder for analysts to reach decisions quickly and consistently.
So, how can surveillance teams improve efficiency without compromising the quality or defensibility of their surveillance programme?
Combining data quietens (unnecessary) noise
Excessive false positive alerts are still one of the most common frustrations firms face with their trade surveillance systems. Often, the two main reasons given for this are, one, static alert thresholds and, two, a limited use of wider market context. The two are interlinked, but the data available for context influences what thresholds can be set, so is a good starting point.
Regulations like UK MAR now expect firms to connect their trade and communications data. And for a good reason. Trade data outlines patterns for detecting market abuse, but it doesn’t reveal its intent – and that’s key.
Comms data, on the other hand, allows firms to understand the reasons behind abuse, which is particularly useful for types like insider trading. Of course, these non-compliant actions might take place without any interactions between the parties involved, or traders could use unmonitored channels, and that’s why a combination of the two data types is necessary.
However, while firms might surveil all of this client data, they might not be combining it with wider market data – and this provides further crucial context. Market volatility, time of day, asset class, specific trader activity can all alter the context behind an alert and whether it should be deemed suspicious. By bringing this data and context into one place, teams can make alerts more meaningful and reduce unnecessary noise.
This data combination is also key for the next stage in the alert lifecycle: triage. But it needs to work in tandem with dynamic thresholds.
Dynamic surveillance
Traditional thresholds typically focus on certain asset classes, markets and a predefined understanding of what constitutes market abuse.
A static threshold could be flagging unusually high price movements within a fixed timeframe, which could be an indicator of price ramping or spoofing. Yet this threshold doesn’t consider any market activity or fluctuations that could explain why this change happened. As such, when it’s applied across the board, teams can end up with a stream of alerts for market abuse that could have been avoided with the right context.
The sweeping movements in the market set off by the recent US tariffs, for example, would have triggered huge waves of false positives based on these static thresholds alone. The trouble is these alert parameters are often set up from the outset and then left in place, so the false positive problem exacerbates.
Instead of using a one-size-fits-all approach, the latest trade surveillance systems allow firms to use dynamic parameters. These account for contextual factors like individual trader behaviour and market conditions to prioritise cases through risk scores and then automatically escalate more meaningful and high-quality alerts to compliance teams, thereby helping them to triage faster and more effectively. Crucially, these scores can adapt as markets, behaviours and abuse types do, building ongoing prioritisation.
It’s for these reasons that ‘set and forget’ surveillance parameters are no longer defensible to regulators. This is also why it’s so important that data is consolidated. Even if more configurable and dynamic thresholds are applied, if they are only set for client and transaction data, then alerts will still be missing a lot of critical context that comes from communications and market activity.
Ongoing explainability and auditability
Dynamic parameters can automatically adapt to contextual data and significantly reduce the time teams spend triaging alerts – but they still need rigorous oversight. Given how quickly market conditions can change, it’s imperative that firms regularly test and reassess their alert parameters.
For this, they need to use a sandbox environment. This is a replica of a firm’s trading system that enables them to test and validate any changes safely and securely. It allows them to show regulators the real-life impact of the changes and the rationale behind their decision-making. The alternative is to change alert parameters in a live environment, but this can trigger unforeseen surges in alert volumes and delay their rollout.
However, not only do firms need to explain why they have chosen their alert thresholds, but also how decisions were made. This means they have to establish a transparent audit trail that shows how and why an alert was generated – for example, what data and parameters were used – and how decisions around its escalation and resolution were made. That’s why using a trade surveillance system that provides end-to-end documentation of the process is vital.
These two capabilities can help firms build a more efficient and defensible surveillance programme across the entire alert lifecycle.
A surveillance programme for today’s world
Every day, compliance teams are required to surveil millions of daily orders and trades happening across different markets and jurisdictions. Alert volumes are already a big issue for firms, but fragmented data coupled with reliance on traditional thresholds means teams can be left dealing with an unmanageable load of false positives.
With data consolidated and dynamic thresholds in place, however, teams can generate and triage alerts faster and more effectively, even gaining additional context to identify abuse that might otherwise go undetected. As such, they have more time to conduct investigations into alerts that warrant attention and ensure parameters and escalation processes are working effectively, or to identify where they need updating.
This dynamic and adaptable approach not only reduces false positives but, in the eyes of regulators, also strengthens the defensibility of a firm’s strategy. As a result, firms gain valuable operational efficiency while ensuring that their regulatory obligations continue to be met.