FCA / MiFID II

Communications and market-abuse surveillance that goes beyond keywords.

MiFID II communications-recording and market-abuse obligations (MAR Article 16) require you to detect manipulation and misconduct you cannot catch with rules alone. Compiled inspects every channel in real time and explains every finding — in your own tenant. Findings carry full policy attribution for your audit trail.

MAR Article 16MiFID II Article 16FCA comms recordingMarket abuseCross-border residencyReal-timeExplainableIn-tenant
MAR
Market Abuse Regulation — binding FCA obligation post-UK MAR
Article 16 surveillance duty
5yr
Minimum communications retention under MiFID II Article 16
Extended to 7yr for certain instruments
100%
Channel coverage required — sampling is not sufficient
FCA supervisory expectation
7%
Maximum GPAI fine under EU AI Act — cross-border exposure
Global annual turnover
Regulatory landscape

The rules and what they require

UK MAR and MiFID II establish interlocking obligations that together require investment firms to record, retain, and surveil communications — and to detect market abuse before it escalates. Post-Brexit, the FCA enforces UK MAR independently, but the substantive obligations are closely aligned with their EU counterparts.

01
UK MAR / EU MAR — Article 16

Market-abuse surveillance duty

Article 16 of the Market Abuse Regulation requires persons professionally arranging or executing transactions to establish and maintain effective arrangements, systems, and procedures to detect and report suspicious orders and transactions. The obligation is behavioral — the FCA expects firms to demonstrate that their surveillance would have detected a specific pattern of manipulation, not merely that monitoring exists. The FCA's Market Watch publications have consistently noted that keyword-based surveillance is insufficient to meet this standard.

  • Effective surveillance arrangements covering all relevant financial instruments and trading venues
  • Detection of wash trading, layering, spoofing, and cross-instrument manipulation
  • Timely suspicious transaction and order reports (STORs) to the FCA
  • Documented basis for why a suspicion was or was not reported
02
MiFID II — Article 16(7)

Communications recording and retention

Article 16(7) of MiFID II requires investment firms to record telephone conversations and electronic communications relating to, or which are intended to lead to, transactions in financial instruments. Records must be retained for a minimum of five years, or seven years where required by a competent authority. The obligation applies to communications conducted on firm-provided or personally owned devices used for business purposes — a practical challenge firms cannot address by restricting permitted channels alone.

  • All relevant communications recorded, regardless of the device used
  • Retention for the required period in a tamper-evident format
  • Ability to produce records promptly in response to a supervisory request
  • Procedures for notifying clients that communications will be recorded
03
FCA supervisory expectations

Behavioral detection beyond keyword lists

FCA Market Watch publications and supervisory findings have repeatedly noted that effective market-abuse surveillance requires systems capable of detecting behavioral patterns, not just known phrases. The FCA expects firms to conduct regular reviews of the effectiveness of their surveillance — including testing whether the system would have detected historical cases of manipulation — and to document those reviews.

  • Regular effectiveness reviews of surveillance calibration and coverage
  • Cross-channel and cross-product surveillance for correlated manipulation
  • Documented governance over how surveillance thresholds are set and reviewed
  • Senior manager accountability for the adequacy of the surveillance program
Enforcement reality

What the FCA and ESMA are actually examining

The FCA has signaled through its supervisory program — particularly through Market Watch and Dear CEO letters — that it expects firms to move beyond static keyword lists and demonstrate dynamic, behaviorally calibrated surveillance. Firms are asked to evidence how their surveillance would have caught specific types of misconduct, not merely that a surveillance system exists.

Cross-border operations create data-residency complexity. A UK firm with an EU subsidiary, or an EU firm with UK operations, faces overlapping FCA and ESMA obligations, and surveillance data cannot routinely transit jurisdictions. A surveillance tool that runs entirely in the firm's own environment — with no cross-border data transfer to a vendor cloud — removes a category of legal and privacy risk that centralized surveillance vendors cannot avoid.

The technology-neutral framing of MAR Article 16 means AI agents operating in a trading context are within scope. An AI agent that generates or routes orders, or whose communications could influence trading decisions, is subject to the same surveillance obligations as a human trader. Most firms do not yet have a real-time control layer on those agents.

Risk scenarios

Where exposures arise in practice

Layering signal across channelsBlock

A trader places and cancels orders in a pattern consistent with layering while communications on a separate channel suggest coordination with a counterpart. Neither the order book data nor the communications alone trigger a keyword alert. Compiled correlates the behavioral signatures across both surfaces and flags the combined pattern.

Cross-desk information sharingFlag

An analyst in a research function shares non-public findings with a colleague on the trading desk via a collaboration platform before the research is published. The message contains no flagged terms. Compiled recognizes the structure of the exchange — pre-publication selective disclosure — and flags it for the compliance officer.

AI agent generating order-adjacent outputFlag

An AI agent used for client communication generates a response that, while not constituting an explicit recommendation, characterizes market conditions in a way that could influence a client's trading decision. The response is flagged before delivery, and the finding is attributed to the firm's own client communication policy and MAR Article 12.

Cross-border communication attempting to avoid recordingBlock

An employee switches to an unmonitored personal messaging channel to continue a conversation about a pending transaction. Compiled detects the shift in behavior — the attempted migration to an unrecorded channel — and blocks the business communication from proceeding on that channel, preserving the firm's recording obligation.

How Compiled works

Behavioral detection inside your data residency boundary

Compiled deploys inside your Azure tenant in your chosen region. Communications data never crosses a jurisdictional boundary to a vendor cloud. The surveillance obligation and the data-residency obligation are met by the same architecture.

Behavioral pattern recognition

Antibodies detect manipulation structures — layering, spoofing, wash trading signals in communications — regardless of vocabulary. A trader who avoids trigger words is not evading the surveillance.

Total channel coverage

Every communication is inspected in full, in real time. Sampling is not sufficient for FCA expectations, and Compiled is designed for 100% coverage at operational cost.

Cross-channel correlation

Communications and agent actions across email, chat, and voice (where transcribed) are correlated. Patterns that span channels — invisible to single-surface tools — are surfaced.

Data residency by construction

Compiled runs in your tenant, in your jurisdiction. No surveillance data transits to a vendor cloud. FCA, ESMA, and GDPR data-residency obligations are addressed at the architectural level.

Policy-attributed findings

Every finding cites the specific MAR article, MiFID II provision, or firm surveillance policy it matched. The STOR documentation process begins with a structured, attributable record.

SIEM and case-management routing

Findings route directly to your existing SIEM or case-management platform. The evidence chain for a potential STOR begins in your environment and stays there.

Examination readiness

What you produce for the FCA or ESMA

FCA supervisory requests typically ask firms to demonstrate their surveillance effectiveness with reference to specific scenarios. Compiled produces a structured record that answers those questions from inside your own environment.

TimestampUTC timestamp of each communication or agent action, preserved in your environment
ChannelThe specific channel — email, chat, voice transcript, or agent output — recorded in the finding
VerdictAllow, flag, or block — rendered inline, before the communication was completed or the action was taken
Behavioral scoreRisk score against the matched surveillance policy, calibrated to your firm's trading context
MAR / MiFID attributionThe specific article — MAR Article 16, MiFID II Article 16(7), or your firm surveillance procedure — matched by the finding
STOR readinessFindings flagged as potential market abuse are structured for direct use in the STOR documentation process
Effectiveness evidenceAggregate surveillance activity logs exportable to evidence your surveillance effectiveness review to the FCA
FAQ

Questions from compliance teams

Chat with usBook a 30-minute walkthroughFinancial services