UK MAR and MiFID II establish interlocking obligations that together require investment firms to record, retain, and surveil communications — and to detect market abuse before it escalates. Post-Brexit, the FCA enforces UK MAR independently, but the substantive obligations are closely aligned with their EU counterparts.
Article 16 of the Market Abuse Regulation requires persons professionally arranging or executing transactions to establish and maintain effective arrangements, systems, and procedures to detect and report suspicious orders and transactions. The obligation is behavioral — the FCA expects firms to demonstrate that their surveillance would have detected a specific pattern of manipulation, not merely that monitoring exists. The FCA's Market Watch publications have consistently noted that keyword-based surveillance is insufficient to meet this standard.
Article 16(7) of MiFID II requires investment firms to record telephone conversations and electronic communications relating to, or which are intended to lead to, transactions in financial instruments. Records must be retained for a minimum of five years, or seven years where required by a competent authority. The obligation applies to communications conducted on firm-provided or personally owned devices used for business purposes — a practical challenge firms cannot address by restricting permitted channels alone.
FCA Market Watch publications and supervisory findings have repeatedly noted that effective market-abuse surveillance requires systems capable of detecting behavioral patterns, not just known phrases. The FCA expects firms to conduct regular reviews of the effectiveness of their surveillance — including testing whether the system would have detected historical cases of manipulation — and to document those reviews.
The FCA has signaled through its supervisory program — particularly through Market Watch and Dear CEO letters — that it expects firms to move beyond static keyword lists and demonstrate dynamic, behaviorally calibrated surveillance. Firms are asked to evidence how their surveillance would have caught specific types of misconduct, not merely that a surveillance system exists.
Cross-border operations create data-residency complexity. A UK firm with an EU subsidiary, or an EU firm with UK operations, faces overlapping FCA and ESMA obligations, and surveillance data cannot routinely transit jurisdictions. A surveillance tool that runs entirely in the firm's own environment — with no cross-border data transfer to a vendor cloud — removes a category of legal and privacy risk that centralized surveillance vendors cannot avoid.
The technology-neutral framing of MAR Article 16 means AI agents operating in a trading context are within scope. An AI agent that generates or routes orders, or whose communications could influence trading decisions, is subject to the same surveillance obligations as a human trader. Most firms do not yet have a real-time control layer on those agents.
Compiled deploys inside your Azure tenant in your chosen region. Communications data never crosses a jurisdictional boundary to a vendor cloud. The surveillance obligation and the data-residency obligation are met by the same architecture.
FCA supervisory requests typically ask firms to demonstrate their surveillance effectiveness with reference to specific scenarios. Compiled produces a structured record that answers those questions from inside your own environment.