// analysis
After the fines: the black box inside JPMorgan market surveillance
Regulators required JPMorgan to conduct a retrospective review, hire an independent consultant, implement remediation and report progress. The contents remain absent from the public record. Part two explains sponsored access, the surveillance chain and the risk still open to measurement.
Part one established the sequence: manipulation admitted in 2020, surveillance gaps discovered in 2021 and coordinated sanctions in 2024. It also set a necessary limit. Billions of order messages missing from JPMorgan’s systems are not billions of abuses. They are billions of objects never tested by the scenarios intended to detect abuse.
Part two starts after the fine. Orders from the Federal Reserve, Office of the Comptroller of the Currency and Commodity Futures Trading Commission required a retrospective review, a full list of trading venues, independent assessment, a corrective plan, progress reports and, for the CFTC, a final certification. As of 31 July 2026, the public sources consulted for this investigation disclose the obligations but not the work produced under them.
The issue is larger than an IT fault. A global dealer buys software, combines feeds from many markets and allows algorithmic clients to reach venues through different contractual arrangements. Control works only if every expected message arrives, every venue appears in the inventory and each detection test covers the relevant behaviour. Risk grows at the junctions.
Sponsored access, delegated trading and retained control
On the venue called “DCM-1”, JPMorgan attributed most missing messages to sponsored access trading by three significant algorithmic firms. The CFTC records this explanation without identifying the venue or the firms.
Sponsored access lets a client or intermediary send orders to a venue through a market member’s access. Economically, the client originates the order. Routing, clearing, checks before trading and monitoring after trading can fall to different entities depending on the market and contract.
The rules reflect that detail. In securities markets overseen by the SEC, Rule 15c3-5 requires the broker with market access to maintain financial and regulatory controls under its direct and exclusive control, subject to limited exceptions. It must also review their effectiveness regularly.
Futures rules are different. In a 2013 interpretation, the CFTC said a futures broker providing sponsored access to an executing firm is not, solely because it provides access, required under Regulation 1.73(a)(2)(iv) to screen the executing firm’s customer orders. One shortcut therefore fails: sponsorship does not create universal responsibility for every control.
The distinction does not weaken the 2024 case. The CFTC sanctioned J.P. Morgan Securities under Regulation 166.3 for failing to supervise diligently. The proven failure involved ingesting and monitoring order messages. The client’s economic identity did not make the data feeding JPMorgan’s own surveillance optional.
Every alert needs a complete chain
Electronic market surveillance is a chain, not one piece of software:
- the venue creates messages for new orders, changes, cancellations and executions;
- connectors transport those messages and put them into a common format;
- an inventory links each venue, product, trading team and client to the correct control rules;
- reconciliation compares the amount expected with the amount received;
- detection tests search for suspicious patterns;
- analysts examine alerts and record their decisions;
- serious cases reach compliance staff, managers and, where appropriate, regulators.
In 2020, JPMorgan told the CFTC that it used three main alert types in the SMARTS software for spoofing and layering. Order 20-69 also describes quality checks and monthly reporting by trader, team, supervisor and region. Those controls came after data entry. A well-designed test never sees a message that failed to arrive.
The golden-source assumption
JPMorgan reconciled some data every quarter but excluded feeds received directly from venues. The firm assumed exchange data were a golden source and did not need the same test.
The assumption mixed up two properties:
- accuracy of the data produced by the venue;
- completeness of the data arriving in JPMorgan’s tool.
The first can be excellent while the second falls to zero. A wrong setting, an unrecognised product code, an incomplete connector or a rejected transformation can be enough. The CFTC identified feed-configuration problems as a cause of the gaps. It did not publish a breakdown of each type of failure.
Operational risk then becomes circular. The control system assumes its own input is complete. Without a separate test of that assumption, an empty alert dashboard looks reassuring. It can also mean no data arrived.
Five CFTC reports and steps
The 23 May 2024 CFTC order did more than impose a penalty. It required a precise sequence:
- a JPMorgan report listing each affected venue and activity, the period, the volume not surveilled and any related market misconduct;
- an independent consultant’s report on policies, the venue inventory, reconciliation, detection tests, testing and previously unsurveilled activity;
- a remediation plan responding to the consultant’s findings and recommendations;
- quarterly progress reports describing work completed, status and timing;
- a completion certification signed by the chief compliance officer and another senior business executive.
The Commission may extend deadlines for good cause. Quarterly reporting ends only after the certification is submitted and accepted by the Division of Enforcement.
The Fed order follows a similar structure: an internal report, an independent party, a report to the board and Federal Reserve Bank of New York, an approved plan and quarterly updates. The review must cover the firm’s own trading and client activity, board oversight, the venue inventory, automated reconciliation, detection tests and periodic testing.
The OCC order also requires a lookback, a retrospective search through previously unsurveilled activity for misconduct not identified earlier. Its penalty order expressly preserves the possibility of an additional penalty based on the lookback results.
JPMorgan’s conclusion and no public audit
In its second-quarter 2024 Form 10-Q, JPMorgan said it had completed improvements to its venue inventory and data-completeness controls. Other remediation remained underway. The firm had retained the required independent consultant and paid approximately $450 million in coordinated penalties.
The filing also says its review of previously unsurveilled data identified no employee misconduct, no harm to clients and no harm to the market. The wording matters and should remain intact. It is JPMorgan’s published conclusion.
It is not a published retrospective report or independent assessment. As of 31 July 2026, our searches of public CFTC, Fed and OCC pages and JPMorgan’s SEC reports did not locate the content of those documents. The public therefore cannot compare:
- the method applied to billions of messages;
- the detailed venues, products and periods;
- the thresholds used to rebuild alerts;
- the consultant’s recommendations;
- exceptions, limitations and validation tests;
- the status of any final certification accepted by the CFTC.
Non-publication does not mean the reports were not delivered to regulators. The orders require delivery. It means JPMorgan’s conclusion cannot be reproduced from public material.
DCM-1 remains unnamed
The CFTC uses “DCM-1”, shorthand for designated contract market, a regulated US futures venue. No exchange name appears in the order. Assigning one would be speculation.
The anonymity blocks several external checks. Without the venue, readers cannot compare the period with its rules, technical notices, feed incidents or disciplinary data. Without the products, concentration by asset class remains unknown. Without the algorithmic firms, their regulatory histories cannot be checked.
Silence may protect commercial information, clients or investigations. The order gives no specific public explanation. This investigation therefore retains DCM-1 and refuses to guess.
Three unnamed algorithmic firms
JPMorgan described three “significant” algorithmic firms behind most sponsored activity on DCM-1. The adjective gives no volume, market share or risk measure.
Concentration among three clients nevertheless creates a clear mechanism. A misconfigured feed for a few very active producers can generate billions of missing messages. Automation explains the scale. It proves neither fraud nor loss, but makes a retrospective reconstruction harder and magnifies mistakes in the control perimeter.
Monitoring bank employees can also differ from monitoring high-frequency clients. Detection tests, identifiers, noise thresholds and referral methods need not be the same. The independent review was supposed to assess both proprietary and client trading, as well as detection thresholds. Its absence from public material prevents an external assessment of this distinction.
No alert is not proof of no abuse
The teaching point has three parts:
- a complete system can generate no alerts because no suspicious behaviour exists;
- an incomplete system can generate no alerts because the necessary messages are missing;
- alert counts become meaningful only after data completeness has been established.
This logic does not turn an unknown into suspicion. It fixes the order of proof. Completeness comes first, then threshold settings, human review and attribution of intent.
A 2025 thematic review by the International Organization of Securities Commissions states the principle for market authorities: access to orders, trades and cancellations is necessary for effective surveillance and market reconstruction. The report is not about JPMorgan. It confirms the general control logic.
Academic research reaches the same data requirement. Bao Linh Do and Tālis Putniņš identify order-book imbalances, order activity, abnormal cancellations and cyclical patterns among useful inputs in their study of spoofing detection. The paper proposes a method and makes no finding about DCM-1. Without complete order messages, those inputs cannot be reconstructed reliably.
Four layers of risk
The case presents four different risks. Combining them produces either an excessive allegation or false reassurance.
Conduct risk. Manipulative behaviour can escape detection when its messages never enter the system. The public record does not show such behaviour in the missing feeds.
Regulatory risk. The CFTC, Fed and OCC have already imposed sanctions. The OCC order allows another penalty based on the lookback. Any new action would depend on new facts or inadequate remediation, neither established here.
Operational risk. An inventory, connector or reconciliation error can neutralise sophisticated detection tools. The problem lies in the path taken by data, not only in the alert model.
Governance risk. In 2020, the board and regulators received a detailed description of improvements. In 2021, the firm discovered a massive missing perimeter. The governance test is independent validation of coverage, not the number of written procedures.
This risk does not appear in quarterly earnings like a loan-loss provision. It resembles the market plumbing in our analysis of repo and collateral: infrastructure looks secondary until a break exposes every connection. Our guide to bank earnings and risk likewise separates accounting performance, conduct and operational exposure.
Five markers for follow-up
A long-running investigation needs falsifiable updates. Five events would change the assessment:
- a public lifting of new-venue onboarding restrictions by the Fed or OCC;
- a completion certification accepted by the CFTC, if the agency publishes it;
- a new action based on the lookback, a possibility expressly preserved by the OCC;
- a more detailed JPMorgan disclosure on reconstruction methods, the consultant or remediation status;
- a court decision or regulatory case connecting specific conduct to an unsurveilled period and venue.
Until such evidence appears, only three conclusions are firm: the gap was massive, JPMorgan says it identified no harm, and the public lacks the reports needed to verify that conclusion independently.
Limits of the public record
This investigation does not identify DCM-1 or try to infer its identity. It names none of the three algorithmic firms. It does not treat every cancellation as fraud. It does not turn a surveillance failure into manipulation.
It also does not add coordinated penalties as independent payments. The effective $448.168 million paid in 2024 is separate from the coordinated $920.204 million resolution in 2020, but each group has its own credits between agencies.
Finally, reports produced for regulators and consultants may contain confidential information. Their non-public status does not necessarily violate the orders. It limits the ability of readers, investors and researchers to audit the published conclusion.
Primary sources
- CFTC, Order 24-07 on surveillance gaps, 23 May 2024.
- Federal Reserve, Orders 24-007-B-HC and 24-007-CMP-HC, 14 March 2024.
- OCC, Order AA-EC-2023-50, 14 March 2024.
- OCC, penalty Order AA-EC-2023-49, 14 March 2024.
- JPMorgan Chase, Form 10-Q for 30 June 2024, Trading Venues Investigations note.
- CFTC, Order 20-69 on surveillance and spoofing, 29 September 2020.
- SEC, Rule 15c3-5 on market access, 3 November 2010.
- CFTC, Interpretative Letter 13-27 on sponsored access and Regulation 1.73, 29 April 2013.
- IOSCO, Thematic Review on Technological Challenges to Effective Market Surveillance, 2025.
Additional academic source: Bao Linh Do and Tālis J. Putniņš, “Detecting Layering and Spoofing in Markets”, version dated 3 November 2023. The paper is used only to explain the data needed for detection. It does not study JPMorgan.
Method and limit: research closed on 31 July 2026 across public CFTC, Fed, OCC and SEC orders, releases and databases, then JPMorgan regulatory filings. “Not found” describes the public documents searched. It proves neither the absence of a confidentially submitted report nor a breach of an order.
This analysis is not investment advice.
// cite this analysis
l0g, “After the fines: the black box inside JPMorgan market surveillance”, l0g.fr, published July 31, 2026, updated July 31, 2026, https://l0g.fr/en/analysis/jpmorgan-market-surveillance-black-box/
$ cd ../analysis