Hedge Fund Managers/ Deep Dive 18

When the FCA pulls one of your trades: market-abuse surveillance under UK MAR Article 16

9 min readHedge FundsSurveillance
Anchored to

UK MAR, in particular Article 16(2); the suspicious transaction and order report (STOR) regime; and the FCA's surveillance expectations as set out in its Market Watch newsletters.

MARMAR 7ASYSC 6

An FCA examiner starts with a single trade — often one your own systems never flagged — and works backwards through it. The examiner checks whether surveillance covered it, whether an alert fired, whether the analyst who cleared it recorded why, whether escalation was considered, and whether a dated record of the sequence exists.

Two common assumptions create the gaps. The first is that brokers and venues are already catching market abuse, so the fund needn’t. The second is that licensing a surveillance tool discharges the obligation. Both are wrong.

UK MAR, the onshored Market Abuse Regulation, carries one obligation that does a great deal of work. Article 16(2) requires any person professionally arranging or executing transactions to establish and maintain effective arrangements, systems and procedures to detect and report suspicious orders and transactions. What those arrangements have to look like is set out in the onshored STOR technical standards: they must be appropriate and proportionate to the scale, size and nature of the business, supported by training, capable of escalation, and backed by record-keeping good enough to show the firm analysed the orders and transactions in question.

Two parts of that obligation are routinely misread on the buy-side. The first is who it catches. A hedge fund manager that professionally arranges or executes transactions sits inside Article 16(2). The duty isn’t the sell-side’s alone; it rests with the firm, and the FCA has said plainly that it reaches asset managers, firms trading on their own account, and providers of direct electronic access for their clients’ activity. Brokers have their own surveillance duties, but a fund can’t discharge its duty by leaning on them. Brokers see transaction flow but not fund intent, positions, research access or internal communications — only the fund can watch those.

The second is how much has to be covered. Article 16 reaches the full set of behaviours UK MAR prohibits: insider dealing, unlawful disclosure of inside information, and market manipulation, with the prohibitions themselves sitting in Articles 14 and 15 and read through the FCA’s MAR sourcebook. It covers orders as well as executed transactions, because manipulation often lives in the order book rather than the print. And it covers every asset class the fund trades, not just the cash equities where the vendors’ scenario libraries run deepest. A fund trading equities, credit, rates and derivatives that surveils only equities has left the rest uncovered.

Surveillance has to be behaviour-based, not intent-based. MAR 1.2.3 is explicit that UK MAR doesn’t require an intention to commit abuse; the firm has to detect the prohibited behaviour itself, whatever lay behind it. Desk culture is no substitute for that. Enforcement under FSMA sections 123 and 124, applied through DEPP 6, follows the behaviour that’s detected rather than the state of mind behind it.

The regulator’s focus here comes from the numbers. The FCA received 4,527 STORs in 2024, and more than 70% of its market abuse investigations start from a STOR. Firms’ surveillance feeds straight into whether the FCA’s own enforcement works, which is why its quality draws supervisory attention.

The buy-side sits awkwardly in that picture, because the overwhelming majority of STORs come from the sell-side. The FCA does not treat that as evidence the buy-side risk is lower. Its stated position is that the gap reflects thinner buy-side surveillance, a theme it has returned to in its Market Watch newsletters when engaging small and medium-sized firms.

Those newsletters are where the FCA sets out its expectations most concretely, and a hedge fund manager should read them as supervisory guidance, not commentary. Market Watch 69 gave observations on surveillance drawn from work with smaller firms, warning against over-reliance on un-calibrated vendor scenarios and stressing that the better firms assess each type of market abuse and how it applies across their business and asset classes. Market Watch 79 went further into model governance. It reported a peer review of how firms test their front-running surveillance models, across a sample of firms and a single alert scenario, and found failures driven by data quality and automated alert logic. Its good-practice message was specific: a firm’s policies should describe and justify how often it tests, and the firm should periodically test parameter calibration, model logic, model code, and the completeness and accuracy of the data feeding the model. Through its enforcement the FCA has pointed to the same recurring failures: weak alert calibration, poor management information to the board, and no change-control process.

Together, the newsletters indicate what an exam covers: whether surveillance is calibrated to the firm’s risks, whether alerts are cleared with reasoning, whether models are tested and under control, whether the board sees anything meaningful about it, and whether the firm can evidence all of that when a trade is pulled.

Communications surveillance matters as much as trade surveillance. Trade surveillance catches the market behaviour; communications surveillance catches intent and the flow of information, and a defensible STOR decision usually needs both. The FCA has pressed firms on recording and reviewing electronic communications, especially off-channel messaging on WhatsApp, personal devices and unmonitored chats, which is where inside information and coordination tend to surface. Insider dealing and unlawful disclosure leave their evidence in messages rather than trades. A sound framework covers both, and can show it captured and reviewed the communications around a flagged trade.

A framework that can answer a pulled trade has seven parts, and each must leave a dated, attributable record.

Start with the market abuse risk assessment, the document the FCA looks for first. It sets out the market abuse risks the firm runs, behaviour by behaviour and asset class by asset class. Insider dealing risk in a fundamental long-short equity book that leans heavily on expert networks looks nothing like it does in a systematic futures strategy, and manipulation risk differs again. The assessment maps each relevant behaviour to where in the business it could arise, and it’s the yardstick coverage gets judged against. A surveillance configuration that can’t be traced back to it is a set of vendor defaults, and the FCA may treat it as one.

Coverage comes next, mapped to the assessment with no silent gaps. Every risk the assessment names should map to a control that addresses it, whether an automated alert scenario, a manual review, or communications surveillance. Where a fund decides not to run a particular scenario, that should be a decision on the record with a rationale, rather than a scenario that was simply never switched on.

Third is calibration and model governance, the area Market Watch 79 put at the centre. On a documented schedule, the firm should test the calibration of its alert parameters, the logic of its models, the underlying code, and the completeness and accuracy of the data feeding them. Thresholds left at a vendor’s defaults and never tuned to the firm’s own trading either miss real abuse or bury the analyst in false positives. Any change to a model should run through change control, so the firm can show what changed, when, why and on whose authority.

Fourth, alert clearing with a documented rationale. The clear-or-escalate decision is where surveillance produces its evidence. The reasoning has to be written down in enough detail that an outsider could see why the alert was, or wasn’t, suspicious. A log that records only “reviewed and closed” tells the FCA nothing about whether any oversight happened; it’s the surveillance counterpart of a valuation committee minute that states a decision without its basis.

Fifth, STOR decision-making and escalation. Where an alert or a piece of intelligence raises a reasonable suspicion, the firm has to decide whether to submit a STOR, and either way that decision has to be documented and timely. A decision not to file matters as much on the record as a decision to file, because the FCA may later take a different view, and the firm’s defence is its contemporaneous reasoning. The route from analyst to the person who decides on a STOR should be defined and followed.

Sixth, governance and management information. The board, or the senior committee standing in for it, should get management information good enough to let it oversee surveillance: alert volumes and how they were dispositioned, the results of model testing, the STORs considered and filed, the gaps found and closed. The FCA has singled out poor board MI as a control failure, so thin or purely numerical reporting is itself a finding.

Last, record-keeping built for reconstruction. Everything above has to be kept so that, when the FCA pulls a trade, the firm can rebuild the whole story from a file: the trade, whether it was surveilled, whether an alert fired, how it was cleared or escalated, and what was decided. The STOR standards require that evidential trail.

Exhibitthe trade teardown, end to end

The FCA picks a transaction and asks the firm to walk it through. A firm that’s ready produces the following for that one trade, within minutes:

  1. confirmation the trade fell within surveillance coverage, traced back to the risk assessment;
  2. which alert scenarios fired on it and which didn’t, and why the calibration produced that result;
  3. if an alert fired, the analyst’s decision to clear or escalate, with the reasoning recorded at the time;
  4. if it was escalated, the STOR decision and the basis for it;
  5. the communications-surveillance position around the trade, where that’s relevant;
  6. the audit trail showing who did what, and when.

A firm that isn’t ready falls back on what it usually does, a search through email and chat to rebuild context, and an analyst’s memory in place of a record. A licensed vendor tool running on default thresholds, with alerts logged “reviewed and closed”, reads much like a tuned and tested setup right up until someone asks for the reasoning behind a single disposition.

Test the framework by pulling three recent trades yourself and trying to produce the full teardown from records. Was each trade within documented surveillance coverage, traced to the risk assessment? Which scenarios fired or didn’t, and why did the calibration produce that? Is the analyst’s clearing decision documented with its reasoning, or only marked closed? Where something was escalated, is the STOR decision documented? When was the model last tested on parameters, logic, code and data? What surveillance MI did the board get last quarter?

Fix first anything you can only answer from memory.

Boards should assume the exam will run through specific trades, and be ready to produce the full teardown for any one of them from records made at the time.

Getting there is recurring work: reviewing the risk assessment as strategies change, testing models on a set schedule, clearing alerts with same-day reasoning instead of quarter-end summaries, and giving the board management information it reads and acts on. For a lean compliance team that’s a heavy load, and it tends to be the first thing to slip until a trade lands on the desk for examination. Surveillance gaps found during a review are hard to close quickly, so the framework has to be current and running the whole time.

Firms that kept the records answer from them, trade by trade; the parts that can only be reconstructed are what a review writes down.

This insight is provided for general informational purposes only and doesn’t constitute legal, investment, or regulatory advice.