top of page

EXPERTS INSIGHTS

SR 26-2 & Trade Surveillance: Greater Flexibility, Greater Responsibility

Writer: SEDA Experts
SEDA Experts
1 day ago
10 min read


Introduction

In April 2026, the Federal Reserve Board (FRB), the Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corporation (FDIC) jointly issued letter SR 26-2 revising supervisory guidance on model risk management.   

The revised guidance reflects changes in technology, model use and risk management practices, emphasizing that model risk management should be tailored to a banking organization’s model risk profile and the size and complexity of its operations. 

 

The publication is a welcome reflection of model evolution in markets. Overall, definitions and expectations have been adapted to be more representative of the actual risk posed, but the message is clear: although requirements have been relaxed in some cases, that flexibility does not eliminate accountability. Institutions remain responsible for protecting the market from any risks arising from their models, systems and business activity, and for demonstrating that appropriate measures have been taken.  

 

For trade surveillance functions, the question is not simply whether a particular control falls within the regulatory definition of a model.  Firms must also determine whether their overall surveillance program is reasonably designed to identify, investigate and escalate the market abuse risks particular to their business. 

 

Our analysis of recent enforcement actions and cases shows that the quality as well as the coverage of trade surveillance is paramount. Critical to an effective trade surveillance program is the necessary expertise to be able to make the correct judgment calls and apply the new guidance. In many instances, an industry expert is well placed to identify the full range of risks. 

 

We assess surveillance programs across four key areas: 


  1. Risk Identification 

  2. Validation and Calibration 

  3. User Procedures and Education 

  4. Evidential Documentation 


 It’s important to think about how these areas are each affected by 26-2.  

 

Risk Identification 

 

There are known knowns; there are things we know we know. We also know there are known unknowns; that is to say we know there are some things we do not know. But there are also unknown unknowns—the ones we don't know we don't know. 

Donald Rumsfeld, US Secretary of Defense, 2002 

 

With the new guidance being less prescriptive and more judgement based, proper risk identification is a critical starting point for an effective trade surveillance program.  

 

26-2 has given us further guidance. For example, rules-based or agentic/generative AI-based surveillance resources may not be subject to the new guidance, whereas those utilizing machine learning or risk scoring techniques are likely to qualify.  As a result, rules-based systems may seem an appealing option for broad surveillance coverage especially as they are often easy to understand.  However, there is a risk that their detection capabilities are too narrow, their calibration not always appropriate, or the output might suffer from parameter cliff-edges. Time saved at the outset can be lost many times over by maintenance obligations further down the line.  

     

A surveillance risk assessment should therefore consider whether: 

 

  1. The firm has identified the specific market abuse risks associated with its business. 

    Example risk: Market conditions change and introduce a new abuse risk that is not addressed 


  2. Surveillance covers the relevant ways in which those risks may arise.  

    Example risk: Not being aware of realistic manifestations of a particular abuse. 


  3. Each system can effectively detect the conduct it is intended to identify. 

    Example risk: Abuse is occurring in a blind spot in the system 


  4. True positives are appropriately escalated and remediated. 

    Example risk: Internal processes aren’t sufficiently refined to handle cases where a primary false positive is masking a potential secondary abuse. 


  5. The number of false positives is manageable and does not compromise review quality. 

    Example risk: The team is overwhelmed by false positives and fails to identify a true positive. 


  6. Data going into the surveillance system is complete, accurate and timely. 

    Example risk: There is a data source that is no longer connected, and it is not caught 


  7. Controls and parameters are appropriately calibrated as markets and activities change.  

    Example risk: Market conditions change but calibration does not and opportunistic abuse at the margin is not detected. 


  8. Models have been correctly assessed for 26-2 relevance   

    Example risk: Models are determined to be unaffected by 26-2 guidance and so are left out of key aspects of the surveillance program 

 

A big area for unknown unknowns is the alignment of trade surveillance to all relevant abuse risk. For example, the belief that a spoofing control is effective without being aware that there are some rare instances of spoofing it is not designed to detect. Experts external to the team with direct industry experience can help identify such unknown unknowns. 

 

Case Study: Instinet LLC’s $1.2M fine and censure by FINRA in February 2026 for numerous failings in its surveillance systems and processes.  

 

These failings included: 

  1. Insufficient coverage of existing surveillance due to misidentifying risks 

  2. Validation that was insufficient to properly investigate positives 

  3. Procedures that did not explicitly define key aspects of the process 

 

Expert view: The extent of the issues highlighted by the regulator suggests that the surveillance department either did not conduct an assessment to determine the risks it was required to cover, or it did not conduct exercises to determine whether the controls and processes employed were sufficient to detect and escalate instances of potential market abuse. Engaging an industry expert to identify the risks as a first step and taking appropriate action to address those risks would likely have prevented the fine and censure, as well as the subsequent damage to the firm’s reputation. 

 

Targeted Validation and Calibration 

 

The purpose of surveillance is to identify potential abuse. While effective trade surveillance should focus on detecting true positives, systems are imperfect. For many firms, managing the volume of false positives is a practical necessity. The better and more accurate the system, the fewer false positives generated per true positive.  

 

Validation provides evidence of what a system can and cannot detect, often confirming (or disproving) the claims made by the vendor.  Calibration ensures that the system is appropriately tuned for the prevailing conditions. 

 

The guidance provided by 26-2 tightens the validation scope. It removes the historic validation obligations for both rules-based and agentic/generative AI systems, allowing users to focus resources on risk-based models. It also removes the historic validation obligations for institutions with less than $30 billion in assets. However, institutions can still potentially be held liable for undetected market abuse on their watch, including for cases in which institutions have so-called “gatekeeper” responsibilities, for example in a broker / hedge fund relationship. Surveillance needs to be effective whether or not the regulator requires comprehensive validation.    

 

Where a thorough validation is required, the use of real historical trade and market data can be used to assess alert quality, data reliability and false positive volumes.  This data can also be used to train users. However, assessing a system’s detection capabilities across all relevant manifestations of each abuse type and the system’s response to changing market conditions can only be achieved through simulated abuse scenarios using curated trade and market data with numerous variations over multiple dimensions. A comprehensive library of relevant simulated abuse is critical to confirm that controls remain effective and correctly calibrated.  It can also be used as evidence to regulators of a robust validation approach. 

 

A poor calibration approach can render a good system ineffective. Controls with fixed parameters are particularly vulnerable at the margin to changes in market conditions and may generate cliff edge results where a seemingly minor shift in activity can make the difference between an alert being generated or not. Ultimately, it is important to know which parameters are particularly sensitive to changing market conditions and which are not.       

 

Based on our experience and recent enforcement actions, a robust calibration framework must encompass four main pillars: 

 

  1. External developments. Have changing market conditions, new products, emerging misconduct patterns or enforcement actions created a need for review? 

  2. System developments. Has the vendor released new surveillance functionality,  identified defects or changed how a scenario operates?  

  3. Regular review and iteration. Does your surveillance team analyze parameters on a regular basis to ensure that your surveillance functionality remains effective? 

  4. External review.  Do you periodically engage experts external to your team (either from within your firm or outside it) to review your parameters and calibration for gaps or issues? 

 

Case Study: SpeedTrader Inc.’s $165,000 fine and censure by FINRA in July 2024 for not adapting a vendor surveillance system to match their requirements.  

 

The firm also did not conduct periodic assessments of parameters or exceptions to determine if the system was functioning as intended. Follow-up or review of flags and alerts were also inadequate. 

 

Expert view: Using a vendor trade surveillance system does not relieve the firm’s responsibility for detecting potentially abusive conduct.  The advantages of vendor solutions are strong functionality, established support and faster implementation.  There is also comfort in knowing that a solution is widely used in the industry. The disadvantages are that they may not be best suited to specific business requirements, understanding the analytics can be challenging, and precise calibration is not always obvious.  Firms might assume that certain risks are covered where in fact they are not. The SpeedTrader case illustrates the risks of implementing a vendor solution “straight out of the box” without verifying its capabilities, determining whether its parameters required adjustment, or determining whether it adequately addressed the firm’s specific business and surveillance risks.     

 

Flexible User Procedures 

 

Surveillance procedures should be robust enough to ensure that trade surveillance is performed in a consistent manner, but they should not reduce alert review to a mechanical checklist. Effective procedures establish minimum expectations while allowing qualified personnel to exercise judgement when the facts or market conditions require deeper analysis.  Different levels of experience between control users can be addressed through appropriate training and education. Users who are allowed to apply common sense judgement where appropriate are likely to produce more accurate assessments and be more engaged in the process. Procedures designed under 11-7 guidance may require updating. 

 

Expert training can help users understand the relevant market structure and market abuse risks, how traders may seek to exploit that market, how surveillance analytics are designed to detect misconduct and, crucially, the limitations of each control.  This knowledge enables users to exercise sound judgement when appropriate and recognize when prescribed procedures or escalation are required.  Firms should identify control weaknesses explicitly rather than assume users are aware of them. AI tools may also improve the process by supporting the review and disposition of lower-risk alerts, subject to appropriate validation, governance and human oversight. 

 

An audit of existing processes and skillsets can help identify any issues that need to be addressed under 26-2. 

 

Case Study: Western Asset Management Company LLC’s $100M fine, cease-and-desist order and censure by SEC in July 2026 for failing to detect cherry picking by senior leadership.  

 

While the firm had controls, policies, and a surveillance system in place, some employees operated outside of the system and their activities were not monitored. 

 

Expert view: The case illustrates the importance of implementation and escalation.  A policy or control has little value if employees do not use it consistently, exceptions are normalized or warning signs involving senior personnel do not receive effective challenge.  An audit of the control function by an external party could have identified these issues. 

 

Evidential documentation 

 

SR 26-2 is less prescriptive than SR 11-7, but documentation remains essential. Documentation is required as evidence of the process used to determine how each control is treated and why that approach is appropriate.   A comprehensive portfolio of ongoing documentation demonstrating that the firm understands the processes it uses, the risks involved, how those risks are managed and its responsibilities to the market and the authorities can provide a significant defense against any future external challenges.  An expert review or audit of documentation can provide feedback and identify weaknesses in relation to the new guidance.  

 

Case Study: Virtu Americas LLC’s $84,375 fine and censure from FINRA in November 2025 for “failing to establish, document and maintain a system of risk management controls” for its market access business, and for failing to maintain a system for regularly reviewing the effectiveness of those controls.  

 

There was very little documentation available that explained the design behind the controls in place, and as a result, it was impossible for regulators to understand the context in which decisions were made and the subsequent reasonableness of a control. 

 

Expert view: This case highlights the importance of recording all actions regarding trade surveillance processes and the basis for those actions. Firms are expected to show reasonable judgement in setting thresholds and be able to demonstrate that such judgements have been considered appropriately.  For example, it may be tempting for a firm to calibrate thresholds and other parameters according to the volume of alerts generated, but that approach may increase  the risk of missing a true positive.  The correct procedure is to calibrate the system to capture all true positives and take other action to reduce the number of false positives, if possible. Appropriate documentation can demonstrate that a reasonable approach has been taken.   

 

Conclusion 

 

A trade surveillance program can be likened to an insurance contract with the cost of the program akin to the insurance premium. Naturally, if nothing untoward happens, the cost is written off as a business expense. However, if there is an issue, an effective surveillance program should allow the firm to quickly identify, escalate, and address the matter. Understanding the gaps in the system, like understanding the small print in an insurance contract, can help to keep a handle on costs and to avoid any future  surprises.  

 

With the new guidance of 26-2, the agencies have given firms greater freedom to exercise their judgement in designing surveillance programs and assessing their models. However, that freedom may necessitate a change in approach and a more proactive mindset to remain compliant and avoid incidents. This letter presents an opportunity for surveillance departments to step back and rethink their strategy and approach. By anchoring analysis and planning across four key areas, it’s easier to ensure there are no blind spots and build a surveillance program for the future that’s both effective and efficient. 

 

At SEDA Experts, our professionals bring decades of practical experience in running front office trading desks as well as in trade surveillance, market conduct, regulatory compliance and model governance. We work alongside financial institutions to assess surveillance coverage, challenge system design and calibration, strengthen investigative processes, and develop governance and documentation that can withstand regulatory scrutiny. To learn more about how SEDA Experts can support your trade surveillance program, please contact us. 

The opinions, views, and statements expressed in this article are solely those of the individual authors and do not represent, reflect, or constitute the views or opinions of SEDA Experts.

EXPERT INVOLVED

Hugh Clark - Managing Director


Hugh Clark is a trading expert with a career spanning multiple asset classes and both buy-side and sell-side roles. He spent 18 years as CIO responsible for strategies and trading at a boutique FX hedge fund. In recent years he operated as a leading expert on market abuse and trade surveillance advising tier 1 banks on detection strategy and system design.







Contact Us

+1 646-626-4555

 
 
 

Comments


bottom of page