How Banks Use AI to Detect Rogue Traders: A Control Benchmark
A primary-source control benchmark for rogue-trading surveillance: what the Kerviel and Adoboli cases reveal, where analytics helps, and which decisions must remain human.
In this research
"AI detects rogue traders" is an attractive headline, but it starts in the wrong place. Unauthorised trading is first a control failure: mandates, position limits, independent valuation, confirmations, access rights or escalation did not work together. Analytics can connect weak signals and prioritise cases; it cannot repair missing segregation of duties or decide that a person committed misconduct.
This guide uses two documented loss events, European market-abuse rules and prudential control guidance to build a testable surveillance benchmark. It deliberately avoids vendor performance claims because there is no public, like-for-like dataset proving that one model or platform prevents rogue trading better than another.
What the Kerviel and Adoboli cases actually show
In Société Générale's published account of the Jérôme Kerviel case, the bank says an alert on 18 January 2008 led to an internal investigation, the discovery of concealed positions of about €50 billion and a final loss of €4.9 billion after the positions were unwound. The bank says fictitious trades, deletions, replacements and false explanations allowed separate alerts to be handled without an aggregated picture of the exposure. Société Générale's Kerviel case record[1]
The UK regulator's final notice on UBS is more useful as control evidence. It records that Kweku Adoboli's unauthorised trading produced a $2.3 billion loss and that the FSA fined UBS £29.7 million for breaches of its principles on skill, care, diligence and adequate risk-management systems. The notice describes weaknesses involving risk limits, supervisory challenge, front-to-back information and the handling of warning signals. FSA final notice to UBS AG[2]
These cases do not prove that a modern machine-learning system would have prevented either loss. They do establish a more defensible design requirement: surveillance must combine position, booking, valuation, confirmation, access and behavioural evidence, and it must route exceptions to people who are independent of the revenue-producing desk.
The control stack comes before the model
The Basel Committee's current operational-risk guidance says strong internal controls require clear accountability, separation of duties, regular testing and an independent second-line view of control effectiveness. It also names returns that appear inconsistent with a supposedly low-risk, low-margin activity as a signal of a possible internal-control breach. Basel Committee operational-risk guidance[3]
Earlier CEBS guidance, now hosted by the European Banking Authority, gives concrete trading-floor examples: independent post-trade processes, monitoring cancellations and amendments, and a minimum continuous absence during which a trader cannot access trading systems or mark their own book. These are governance and internal-control measures, not decisions that can be delegated to a model. CEBS guidelines on operational risk in market-related activities[4]
A credible programme therefore begins with hard controls: authorised products and limits, independent price verification, daily profit-and-loss explanation, confirmation and settlement breaks, access recertification, mandatory leave, and documented escalation. AI belongs above this foundation as a correlation and prioritisation layer.
The CloudFintech rogue-trading surveillance benchmark
The benchmark below separates prevention, detection, escalation and assurance. It is intended for control-design workshops and vendor evaluations: a bank can mark whether each evidence stream exists, how quickly it arrives, who owns the decision and whether an alert can be reconstructed later.
Methodology: CloudFintech mapped documented control failures from the Société Générale and UBS cases against Basel operational-risk principles, CEBS/EBA trading-control guidance and the EU MAR/STOR framework. Detection horizons and automation roles are qualitative editorial classifications for control-design workshops; they are not measured vendor performance or legal advice.
Primary sources: FSA final notice to UBS AG; Société Générale Kerviel case record; Basel Committee operational-risk guidance; CEBS/EBA market-activity control guidelines; EU Market Abuse Regulation; EU STOR delegated regulation
Download underlying datasetThe downloadable dataset is not a regulatory checklist and does not assign numerical scores. Its purpose is to expose gaps that a glossy "AI surveillance" label can hide. A platform that analyses communications but cannot join an alert to position limits and independent P&L is not an end-to-end rogue-trading control.
Where machine learning adds defensible value
Cross-system correlation. One cancelled trade may be routine. A repeated cancel-and-rebook pattern combined with unexplained profit, limit exceptions and unusual privileged access is more informative. Entity resolution can join the trader, desk, account, instrument and communication channel into one case without pretending that correlation proves intent.
Peer-aware anomaly ranking. Fixed thresholds remain appropriate for hard limits. Models can supplement them by comparing activity with the trader's mandate, the desk's history and relevant market conditions. The output should be a ranked exception with contributing features, not an opaque verdict that someone is a rogue trader.
Sequence analysis. Concealment may appear as a lifecycle: book a position, add an offsetting entry, cancel it before confirmation, then replace it. Sequence models can surface recurring patterns across order, trade and operations data that separate systems would treat as unrelated.
Case triage. Surveillance teams must assess alerts rather than maximise alert volume. A model can prioritise cases by the number and independence of corroborating signals, the size and speed of exposure growth, and whether a control override occurred. Analysts still need access to the raw evidence and a reason for the ranking.
Market-abuse surveillance and rogue-trading controls overlap, but are not identical
Rogue trading means activity outside an authorised mandate; market abuse concerns conduct such as insider dealing or manipulation. An unauthorised position is not automatically market abuse, and a fully authorised trader can still manipulate a market. The data can overlap, but the legal tests and escalation routes differ.
Article 16 of the EU Market Abuse Regulation requires relevant market operators, investment firms and persons professionally arranging or executing transactions to maintain effective arrangements, systems and procedures for detecting and reporting suspicious orders and transactions.Regulation (EU) No 596/2014, Article 16[5] The accompanying delegated regulation says an assessment should rest on facts rather than speculation and that a suspicious transaction and order report should be submitted without delay once reasonable suspicion has formed.Commission Delegated Regulation (EU) 2016/957[6]
Neither instrument requires "AI". The defensible claim is narrower: analytics may help firms examine more orders, connect related activity and assemble evidence quickly, provided a qualified person determines whether the facts meet the reporting threshold.
Governance questions for an AI-assisted surveillance system
Can every alert be reproduced? Store the model or scenario version, source-data timestamps, contributing features, threshold, case actions and final disposition. Without lineage, the firm cannot explain why a case was prioritised or test whether a later model change altered coverage.
Who can suppress or close an alert? Overrides should require a reason, an accountable owner and review outside the desk. Repeated suppression by the same person or for the same book is itself a control signal.
How is drift measured? Alert volumes alone are weak evidence. Monitor changes in input coverage, missing feeds, feature distributions, unresolved control breaks, time to disposition and outcomes from investigations or regulatory feedback.
What is excluded? A model trained on executed trades may miss cancelled orders; a communications model may exclude voice; a position engine may not see manual journals. The control inventory should name these boundaries rather than imply complete coverage.
Are privacy and employment constraints designed in? Communication and behavioural surveillance needs documented purpose, access restrictions, retention controls and jurisdiction-specific review. More employee data is not automatically better risk detection.
A practical 90-day implementation sequence
Days 1–30: prove the evidence chain. Select one desk and trace orders, executions, positions, confirmations, P&L, limits, access events and cases. Reconcile identifiers and timestamps. Record missing or delayed feeds before selecting a model.
Days 31–60: back-test scenarios and anomalies. Use known control breaks and synthetic test cases to compare deterministic rules with anomaly ranking. Measure whether alerts show the underlying evidence, whether obvious events are missed and how many cases an analyst can review properly. Do not present synthetic detection rates as real-world loss-prevention results.
Days 61–90: run in shadow mode. Generate alerts without automating disciplinary, trading or regulatory decisions. Compare model-ranked cases with existing surveillance, document disagreements, test access and override controls, and obtain sign-off from surveillance, operational risk, model risk, legal/privacy and internal audit.
The outcome should be a controlled evidence system, not an "AI detector". That distinction makes the programme easier to test, explain to regulators and transfer to a future owner or operating team.
Sources
Numbered references are anchored to the specific claims they support. Primary documents are preferred wherever available.
- Société Générale's Kerviel case record societegenerale.com ↩
- FSA final notice to UBS AG fca.org.uk ↩
- Basel Committee operational-risk guidance bis.org ↩
- CEBS guidelines on operational risk in market-related activities eba.europa.eu ↩
- Regulation (EU) No 596/2014, Article 16 eur-lex.europa.eu ↩
- Commission Delegated Regulation (EU) 2016/957 eur-lex.europa.eu ↩
Frequently asked questions
Can AI prove that a trader is acting without authorisation?
No. Analytics can surface unusual positions, bookings, access patterns or communications and show why a case was prioritised. Mandate records, control evidence and a properly authorised human investigation determine whether activity was unauthorised or misconduct occurred.
Which controls matter before machine learning is introduced?
Core controls include trader mandates and limits, segregation of duties, independent valuation and P&L explanation, confirmation and lifecycle reconciliation, access review, mandatory absence, documented escalation and independent testing. Models should augment this foundation rather than substitute for it.
Does EU market-abuse law require banks to use AI surveillance?
No. MAR Article 16 requires effective arrangements, systems and procedures for detecting and reporting suspicious orders and transactions, but it does not prescribe AI. A firm may use analytics as part of a proportionate control framework while retaining accountable human assessment.
What should a surveillance model record for each alert?
Record the model or scenario version, source-data timestamps, contributing features, threshold, linked control breaks, case owner, overrides, investigation actions and final disposition. This supports reproducibility, validation and regulatory explanation.
How should a bank benchmark a rogue-trading surveillance platform?
Test evidence coverage and decision workflow rather than relying on a vendor accuracy percentage. Check whether the platform joins orders, trades, positions, P&L, limits, confirmations, access and cases; exposes missing feeds; reproduces alerts; governs overrides; and keeps regulatory decisions human.
Update history
- Preserved CEBS/EBA trading-control guidance from the stronger live version; clarified the control examples and citation anchors.
- Rebuilt around the Kerviel and Adoboli control evidence; removed unsupported claims about detection speed and false-positive reductions; added MAR Article 16 analysis, a reproducible control benchmark, primary-source claim anchors and a downloadable dataset.