FINANCE, POLICY & MARKETSPublished by Paul Ivinskas
fc.The Financial CurrentDAILY INTELLIGENCEWhat matters across finance
Deep-dive library

OCC / JPMorgan: trade-surveillance coverage and confidence in market operations

4 min read · estimatedAI-generated analysis · Methodology
Historical version · 2 versions · Publication details

First published . This version published .

Version history

About this historical version

Initial publication.

Related research, policy & entities ↓

At a glance

Excerpts from this version
What it covers
The March 2026 termination changes the legal status; the underlying case remains useful for understanding why sophisticated surveillance fails without complete data.
The mechanism: coverage before sophistication
The broader analytical point is simple: a surveillance model cannot flag a transaction it never receives. Model accuracy measured only on loaded records does not measure coverage of the complete trading population. A system can score very well on an internal test while an omitted venue, product or transaction type creates a large blind spot. Data completeness is therefore a control objective in its own right.Read in context
0% through article

Tap a dotted-underlined term for a definition; terms are highlighted once per section. Use Aa in the navigation for reading preferences.

In this article

Status: terminated, with a dated history

The OCC’s March 14, 2024 against JPMorgan Chase Bank, N.A., docket AA-EC-2023-50, addressed its trade-surveillance program. The OCC terminated that order on March 30, 2026 through AA-ENF-2026-17, announced in its April 16, 2026 enforcement release. The case should therefore be presented as a terminated action, not an outstanding restriction.

Termination of this specific order does not establish that every separate action involving the bank or its affiliates ended. The original order and the termination are separate documents with different functions. The former describes required corrections; the latter establishes the changed legal status. This article uses both and does not infer confidential ratings or current misconduct.

The mechanism: coverage before sophistication

The 2024 order required a review of data deficiencies affecting surveillance and a lookback for previously unidentified misconduct. Its independent assessment requirements covered venue inventories, data reconciliation, legal obligations, scenarios, parameters, alert handling and audit. The OCC’s associated March 2024 announcement separately described a $250 million civil money penalty.

The broader analytical point is simple: a surveillance model cannot flag a transaction it never receives. Model accuracy measured only on loaded records does not measure coverage of the complete trading population. A system can score very well on an internal test while an omitted venue, product or transaction type creates a large blind spot. Data completeness is therefore a control objective in its own right.

Three different reconciliations

A strong design reconciles the business inventory to the surveillance inventory, the upstream transaction population to received data and received data to successfully processed records. Each comparison answers a different question. A file arriving on time does not establish that every expected transaction was in it; a full file does not establish that parsing and enrichment succeeded.

Reconciliation should include cancellations, amendments, identifiers and timestamps where those fields determine how activity is linked. Simple record counts can conceal offsetting errors or duplicate records. Control owners should understand which differences are harmless and which invalidate a surveillance scenario, with thresholds grounded in the actual use of the data rather than a generic tolerance.

A hypothetical surveillance gap

Assume a bank executes one million trades across ten venues. Its surveillance engine receives 950,000 records and detects all seeded test cases within that subset. Calling the engine fully effective would ignore the 50,000 omitted trades. If those trades are concentrated in a new venue with a different risk profile, the missing 5% may matter more than a random sample of that size.

In this hypothetical, the bank first identifies the missing population, reconstructs reliable historical data and determines which scenarios can be rerun. It then documents records that cannot be recovered and considers compensating investigation. The example does not describe JPMorgan’s actual volumes. It shows why a lookback requires a defensible population and cannot be reduced to pressing rerun on an existing model.

Validation should challenge the whole chain

commonly focuses on thresholds, detection quality and . Those are useful, but they should connect to an explicit statement of coverage. An independent reviewer needs to know which businesses and behaviors the model is intended to address, what data it requires and how the organization detects departures from those assumptions.

Testing can deliberately remove a field, introduce a new venue or delay a feed to see whether the system raises a control exception. This is different from testing whether a misconduct scenario generates an alert. Both tests matter: one evaluates the detection rule, while the other evaluates whether the conditions required for the rule to operate remain intact.

Costs and organizational tradeoffs

Comprehensive surveillance can produce substantial processing, storage and investigation costs. Extending coverage without improving prioritization may overwhelm analysts and slow escalation. The response should be explicit capacity planning and defensible scenario design, not an undocumented decision to exclude difficult data. Management needs visibility into the operational consequences of each coverage choice.

A common tension exists between central surveillance teams and businesses that introduce new venues or products. Launch approval should include data readiness and ongoing ownership. Otherwise the surveillance function discovers changes after transactions have accumulated. The control is most effective when it is part of product onboarding, with a clear escalation path for exceptions and a defined owner for historical remediation.

These controls should survive personnel and platform changes. A named owner, documented reconciliation logic and retained test evidence make the coverage assessment reproducible when the team or technology changes.

Reading the termination carefully

The OCC explains that it can terminate actions for several reasons, including compliance, changed circumstances or incorporation into a replacement. Readers should avoid adding a more specific conclusion than the termination record supports. Here, the verified point is that this March 2024 order was terminated on March 30, 2026. That should remain visible beside the historical findings.

Evidence that would change the operational assessment includes a new public action, a documented recurrence or public validation results showing sustained improvements. In their absence, the case remains a historical illustration of a durable control principle: surveillance performance is conditional on knowing what activity should be present, proving that it arrived and preserving evidence that it was actually evaluated.

Sources

  1. OCC JPMorgan consent order AA-EC-2023-50; March 14, 2024Official source · PDF
  2. OCC March enforcement announcement; March 20, 2024Official release
  3. OCC termination AA-ENF-2026-17; March 30, 2026Official source · PDF
  4. OCC April enforcement announcement; April 16, 2026Official release

Flag an error or suggest a correction →Public corrections log →