Prompt
How do I choose between different market abuse detection platforms for exchange and OTC surveillance?
Latest observation
Choosing between market abuse detection platforms for exchange surveillance and OTC surveillance comes down to how well the system matches your market structure, data complexity, regulatory scope, and operational workflow. The best platform is rarely the one with the most features; it’s the one that fits your products, venues, and investigations process.
1) Start with your surveillance scope
Ask first:
- What markets do we cover? Equities, futures, options, FX, fixed income, crypto, OTC derivatives?
- Which venues and books matter? Lit exchange, dark pools, ATS/MTF/OTF, voice, RFQ, chat, bespoke OTC tickets?
- What abuse types are in scope? Spoofing, layering, wash trades, marking the close, insider dealing, front-running, cross-market manipulation, collusion, benchmark manipulation, quote stuffing, quote fading, inappropriate alloc/tilt behavior.
Exchange-only platforms often excel at high-volume, event-driven detection on standardized feeds. OTC surveillance needs support for less structured data, relationship/context analysis, and manual workflows.
2) Check data ingestion and normalization
This is usually the biggest differentiator.
For exchange surveillance, confirm support for:
- Real-time market data and order book feeds
- Order, trade, cancel/replace lifecycle data
- Venue-specific message protocols
- Low latency processing and replay
For OTC surveillance, confirm support for:
- RFQ, quote, and negotiation data
- Voice trade capture and transcription metadata
- Chat/e-comms integration
- Ticket systems, confirmations, allocations, amendments
- Entity resolution across clients, accounts, desks, and beneficial owners
If the platform cannot normalize all relevant communications and lifecycle data into one timeline, your alert quality will suffer.
3) Evaluate detection logic depth
A strong platform should support both:
Rules-based detection
Useful for:
- Prescriptive regulatory scenarios
- Simple thresholds and pattern rules
- Known typologies
Behavioral/anomaly detection
Useful for:
- Unusual trader behavior
- New manipulation patterns
- Cross-product and cross-venue activity
- OTC relationship-based patterns
For OTC especially, look for:
- Sequence analysis
- Peer-group benchmarking
- Network/relationship analytics
- Contextual detection across communications and trades
A platform that only does fixed rules may be too rigid; one that is “AI-first” without explainable rules may be hard to defend to regulators.
4) Assess explainability and auditability
You need to be able to explain:
- Why an alert fired
- Which data points were used
- What thresholds or model features mattered
- How an investigator validated or dismissed it
This matters for:
- Internal model governance
- Compliance reviews
- Regulatory exams
- Consistent case disposition
Look for:
- Clear alert narratives
- Reproducible logic
- Drill-down to source events
- Full audit trail for every disposition and comment
5) Investigations workflow matters as much as detection
A platform should reduce investigator time, not just generate alerts.
Key workflow features:
- Case management
- Alert triage and deduplication
- Linking of related alerts into one case
- Watchlists and entity profiles
- Notes, tasks, approvals, escalation
- Evidence packaging and export
- Regulatory reporting support
For OTC, flexible case linkage is especially important because suspicious activity often spans trades, chats, calls, and multiple desks.
6) Consider scalability and performance
Exchange surveillance often means:
- Massive message volumes
- Real-time or near-real-time requirements
- Multi-venue normalization
- Historical replay for backtesting and investigations
OTC surveillance often means:
- Fewer messages, but more complexity per case
- Unstructured or semi-structured data
- Need for long retention and rich search
Make sure the vendor can prove:
- Throughput at your peak volumes
- Low alert generation latency where needed
- Long-term storage and fast retrieval
- Backtesting over historical periods
7) Review configurability vs vendor dependency
You want enough configurability to adapt rules without waiting on the vendor, but not so much complexity that the platform becomes fragile.
Ask:
- Can compliance users tune thresholds and lists?
- Can you build new typologies without code changes?
- How are model updates governed?
- Can you version-control scenarios and parameters?
For OTC, strong configuration is particularly valuable because products and trading behavior can vary a lot by desk and counterparty.
8) Data quality and enrichment capabilities
Good surveillance depends on good reference data.
Evaluate:
- LEI/UTI/UPI support
- Counterparty and beneficial owner resolution
- Instrument master quality
- Time synchronization and clock normalization
- Corporate actions and benchmark data
- Communications tagging and metadata capture
Poor enrichment can create false positives, missed links, and weak investigations.
9) Integration with your broader controls stack
A platform should fit into your broader compliance architecture:
- KYC/AML systems
- Trade surveillance
- E-comms surveillance
- Order management and execution systems
- Case management/GRC tools
- Data lake / warehouse
- SIEM or security tools where relevant
The best platforms have open APIs and robust export capabilities, so you are not locked into one workflow.
10) Vendor governance and regulatory credibility
Look for:
- Proven deployments in your asset classes and regions
- References from firms with similar business models
- Coverage of relevant regulations and typologies
- Model governance documentation
- Upgrade and validation process
- Support responsiveness and incident handling
Ask how they handle:
- New typologies or regulatory updates
- Model drift and tuning
- False positive reduction
- Independent validation
11) Total cost of ownership
Don’t compare license fees alone. Include:
- Data feeds and normalization costs
- Storage and infrastructure
- Professional services and implementation
- Ongoing scenario tuning
- Investigator training
- Support and maintenance
- Custom development and integration
Sometimes the “cheaper” platform costs more once you add data engineering and manual review overhead.
12) Practical selection framework
Use a scorecard with weights across:
- Market/venue coverage
- OTC data support
- Detection quality
- Explainability
- Workflow/case management
- Scalability/performance
- Configurability
- Integration/API maturity
- Regulatory credibility
- Total cost of ownership
Then run a proof of concept with your own data:
- Pick a representative period
- Include known suspicious cases if available
- Measure alert precision/recall
- Measure investigator time saved
- Test replay, search, and export
- Validate performance on peak volumes
Rule of thumb
- Choose an exchange-focused platform if your primary need is high-volume, structured, real-time detection on standard market data and order lifecycles.
- Choose an OTC-capable platform if you need to connect trades, quotes, communications, voice, and entity relationships across less standardized workflows.
- Choose a hybrid platform if you need both, but only if it handles both well; otherwise you may be better with best-of-breed tools integrated into a common case management layer.
If you want, I can also give you:
- a vendor evaluation checklist,
- a requirements template for RFPs, or
- a weighted scoring matrix you can use to compare platforms.