Hedge Fund Managers/ Deep Dive 21

Choosing and calibrating a trade-surveillance vendor without buying shelfware

6 min readHedge FundsSurveillance
Anchored to

UK MAR Article 16(2); the FCA's surveillance expectations in Market Watch 69 and Market Watch 79; and the outsourcing requirements in SYSC 8.

MARSurveillance

A firm licenses a respected vendor platform, switches on the standard scenario library at the thresholds the vendor shipped, and writes in its compliance plan that it now has trade surveillance. A licensed system running on vendor defaults does not meet the FCA’s Article 16(2) requirement to maintain effective arrangements to detect and report suspicious orders and transactions. It generates alerts, or fails to, and no one inside the firm can say why.

The FCA has been clear that licensing a tool does not discharge the obligation. Under UK MAR Article 16(2) the duty to maintain effective arrangements to detect and report suspicious orders and transactions sits with the firm, and it stays there whether the firm builds its surveillance or buys it. SYSC 8 says the same about outsourcing generally: a firm remains responsible for the functions it delegates. The question is how to choose and calibrate a vendor so it functions as a real control, not just a licence.

The clearest FCA statement on this is Market Watch 79, its newsletter on surveillance model testing. The regulator reported it had become aware of surveillance alerts not working the way firms assumed they did, in both in-house-built and vendor-supplied systems. Some scenarios were partially effective: they generated alerts, but not for every instance they were meant to catch. Others did nothing at all, having never been adequately tested. The common factor was not the choice of vendor but the absence of testing and understanding. Firms did not know how their own alerts worked, so they could not see the gaps.

The FCA drew the line plainly. Where firms use vendor-supplied systems, it said, they should make sure they understand how the alert scenarios work, or they may fail to spot gaps and weaknesses in their surveillance; and it recommended appropriate, independent assurance that any third-party surveillance system is operating as intended. A firm that cannot explain how its alerts are generated, has not tested them, and has no independent assurance they work has not met Article 16(2) by buying a platform.

What the firm can own, even with a bought platform, is the configuration: which scenarios run, the thresholds at which they fire, how complete the data feeding them is, and the judgement about whether they are working. Ownership in that sense carries three obligations the firm cannot hand to the vendor.

Understand the logic. For each scenario it runs, the firm should be able to explain in plain terms what behaviour the scenario is meant to detect, what data it uses, what parameters drive it, and where its known limits are. A firm that cannot explain its own front-running scenario has no way of knowing whether it covers the front-running risk in the trading it actually does.

Test the model. Understanding isn’t enough if the scenario doesn’t fire; Market Watch 79 showed that risk is live. The firm has to test, on a documented schedule, that each scenario fires when it should, against the four dimensions the FCA named: the calibration of the parameters, the logic of the model, the underlying code, and the completeness and accuracy of the data.

Govern the output. Alerts matter only if they are worked; unmanageable false positives defeat the control. The firm owns the false-positive problem, the tuning that manages it, and the governance that stops tuning from quietly suppressing genuine risk.

A vendor can support all three with documentation, testing tools and assurance reports, but under Article 16(2) and SYSC 8 the obligation stays with the firm.

On the build-buy-hybrid question: building in-house gives the most control and the deepest understanding, but for a sub-billion-pound firm it rarely justifies its cost or the expertise it demands. Buying a vendor platform brings scale, a tested scenario library and better economics, with the risk that the firm consumes it passively, without understanding or testing it. What matters is whether the firm owns the configuration. Take the vendor’s engine and library, then make the scenario selection, the calibration, the testing and the false-positive governance the firm’s own work, evidenced by the firm.

Selection should start from the risk assessment, not the vendor demo. A firm that lets a vendor walk it through an impressive platform and then works out which scenarios to switch on has inverted the order. Selection should start from the firm’s market-abuse risk assessment, which defines what the system has to do. The following questions test whether a vendor will give you a working control.

Does it cover your behaviours and asset classes? The scenario library has to address the behaviours your risk assessment identifies (insider dealing and the relevant forms of manipulation) across every asset class you trade, not just the cash equities where the libraries run deepest. A platform that covers equities but nothing for your credit or derivatives leaves open the gap the risk assessment told you to close.

Can it ingest your data, completely and accurately? Surveillance depends on complete, accurate data, which Market Watch 79 emphasised. The system has to take in all your orders and trades across every venue and broker, ideally your communications too, and you need to be able to check the feeds are complete. Incomplete feeds produce alerts you cannot rely on.

Can you see how an alert was generated? Explainability is what lets you reconstruct an alert for the FCA and understand your own coverage. If you cannot trace how each alert was produced, you cannot meet the FCA’s expectation that you understand your scenarios.

Can you configure and test it? The firm has to be able to tune thresholds to its own trading and to test the scenarios, ideally without paying the vendor for every change. A system that only runs vendor defaults, or that makes calibration and testing a gated service, locks the firm out of the very ownership the regulator requires.

Will it support independent assurance? The FCA recommends independent assurance that the system works, so the vendor should provide the documentation, model descriptions and testing support that make assurance possible, whether it is done internally or by a third party.

Does it pass outsourcing and resilience due diligence? A surveillance vendor is a material outsourcing, so SYSC 8 [R/UK], which carries the MiFID Organisational Regulation outsourcing requirements, applies, along with the operational resilience rules and the critical-third-parties framework. SYSC 8 is explicit that outsourcing a critical or important function must not impair the firm’s controls or the FCA’s ability to supervise, and that the firm stays responsible. That is the systems-and-controls counterpart to the delegation rules, and the reason a vendor can never absorb the firm’s Article 16 obligation. Do the due diligence, define oversight, secure audit and information rights, plan for exit, and weigh concentration risk, because a surveillance system that fails silently, or a vendor that fails commercially, is a control failure the firm owns.

The biggest coverage gap is in asset classes beyond equities. Surveillance vendors have mature, well-tested scenario libraries for cash equities and far thinner coverage for fixed income, foreign exchange and over-the-counter derivatives, where liquidity is fragmented, reference prices are harder to pin down, and manipulation looks different. A multi-strategy fund trading across those markets cannot assume the equities-grade library protects the rest of the book. Often the better answer is to cover some non-equity risks by targeted manual review; the firm should make that call deliberately and record it. An evidenced surveillance function knows which asset classes are covered by tested automation and which rely on manual review, and can justify the split.

In calibration, tune thresholds to your own trading rather than the vendor’s defaults. Default thresholds are set for generic trading patterns. They have to be recalibrated to your instruments, your volumes, your strategy and your typical order patterns, and the reasoning behind where each threshold sits should be written down.

This insight is provided for general informational purposes only and doesn’t constitute legal, investment, or regulatory advice.