Back to Insights
  • Enforcement
  • Markets & Trading
  • Governance & Accountability

Too blunt, then too narrow

A proprietary firm's spoofing surveillance was mis-tuned twice: first a monthly ratio too crude to see the pattern, then vendor parameters so tight an alert would fire only if a trader cancelled within one second. Both missed spoofing, layering, and disruptive quoting and trading activity. Calibration, not the absence of a system, is where trade surveillance quietly fails.

A blue adjustable aperture between coarse and fine meshes, crossed by a cyan beam

NASDAQ PHLX · Spoofing & Layering Surveillance · Rule General 9

The calibration a firm has to hit

too blunt: monthly cancel-to-fill ratio
fires
too narrow: cancel within 1 second
2020 to 2023: missedthe reasonable window2023 to 2026: missed
$100,000
PHLX fine + censure
6+ years
of unreasonable surveillance
Both ends
too crude, then too tight

A calibration band showing a firm swinging from too-blunt to too-narrow, missing the detection window on both sides

Source: NASDAQ PHLX LLC Letter of Acceptance, Waiver, and Consent, Avatar Securities, LLC; accepted 4 September 2026.

01

Overview

On 4 September 2026, NASDAQ PHLX accepted a settlement from Avatar Securities, a New York proprietary trading firm, censuring it and imposing a $100,000 fine. The finding was not that Avatar had no surveillance for spoofing and layering. It had a report, and later a vendor system, and at times someone watching screens. The finding was that none of it was calibrated to actually catch the conduct it was built to catch. From at least March 2020 through July 2026, PHLX concluded, Avatar's supervisory system was not reasonably designed to prevent and detect potential spoofing, layering, or disruptive quoting and trading activity.

What makes the case a clean teaching example is that the miscalibration ran in two opposite directions over time. In the first phase, from 2020 to early 2023, Avatar leaned on a monthly Spoofing and Layering Report that flagged any symbol where cancels outnumbered fills by ten to one over a month. That is far too blunt an instrument: an aggregated monthly ratio says nothing about whether orders sat at or inside the national best bid and offer, or whether executions came on the opposite side of the market, which are the actual fingerprints of layering. In the second phase, from February 2023, Avatar bought a vendor surveillance system and then set its parameters so tight that they would rarely fire at all: an alert required, among other things, that the trader cancel each suspect order within one second of an opposite-side execution, that at least five opposite-side orders be placed within thirty seconds, and that at least four remain live at execution. For a desk that traded manually, those thresholds were, in PHLX's word, unreasonably narrow.

So the firm managed to be wrong in both directions: a net with holes too big to catch anything, then replaced by a net with a mesh so fine it never opened. Layered on top was a specific supervisory failure. Avatar had a trader it knew warranted heightened supervision because of a prior FINRA disciplinary history for disruptive activity, recognised that, and then failed to implement or document it, relying on the same reports and occasional screen-watching that were not designed to catch the behaviour. The case is small in dollars but unusually instructive, because calibration is where trade surveillance most often fails, and the parallels across the enforcement record are striking.

Avatar Securities: case facts

Fine
$100,000plus censure
Failure
Calibrationnot a missing system
Both ends
Blunt then narrow2020 to 2026
Schemes
Spoofinglayering, disruptive quoting & trading

Calibration, not a missing system: blunt then narrow, 2020 to 2026.

Source: NASDAQ PHLX LLC Letter of Acceptance, Waiver, and Consent, Avatar Securities, LLC; accepted 4 September 2026.

02

Infringements

The AWC cites failures under Phlx Rule General 9, Section 53, which prohibits disruptive quoting and trading, and Section 20(h), which requires a supervisory system and written procedures reasonably designed to detect and prevent violations. The first deficiency is the monthly report. Its single lens was an aggregation unit's cancel-to-fill ratio, symbol by symbol, over a month, with review focused on symbols where cancellations ran at least ten times fills. That metric was not reasonably designed to detect the patterns Avatar intended it to catch, because it ignored the factors that actually distinguish layering from ordinary high-cancellation market making, most importantly whether displayed orders sat at or inside the NBBO on one side while executions printed on the other.

The second deficiency is the vendor parameters. Avatar did the thing regulators encourage, replacing a home-grown report with a dedicated surveillance system, but then tuned it into uselessness. PHLX singled out a requirement that a potential spoofing or layering order be cancelled within one second of an opposite-side execution as too narrow given that the firm's traders traded manually, and flagged the layering logic's compound conditions, five opposite-side orders within thirty seconds, four still live at execution and cancelled within one second, as unreasonably restrictive. Real-time screen monitoring did not fill the gap either, because spoofing and layering, which involve many simultaneous orders and rapid placement and cancellation, are precisely the patterns a human cannot reliably catch by watching a screen.

The third finding is the supervisory lapse. From March 2020 through October 2021, Avatar failed to reasonably supervise a trader it had itself identified as warranting heightened supervision on account of a prior FINRA disciplinary history for disruptive activity. It never implemented or documented that heightened supervision, relying instead on the same deficient report and occasional screen-watching. The trader left voluntarily in October 2021. Avatar consented to the censure and $100,000 fine without admitting or denying the findings, and the matter, tellingly, originated from FINRA's cross-market surveillance, the regulator's own calibrated net catching what the firm's did not.

03

The calibration trap

Trade surveillance is not a binary of present or absent; it is a dial, and both extremes fail. Turn it too far toward simplicity and you get Avatar's first phase: a metric so aggregated it cannot distinguish manipulation from legitimate activity. A monthly cancel-to-fill ratio treats a market maker who quotes and cancels thousands of times a day, entirely legitimately, the same as a spoofer, because it never looks at the one thing that separates them, the relationship between where orders are displayed and where executions occur. A blunt metric does not just miss cases; it generates noise that buries the real ones, and it gives a firm the false comfort of a report that runs every month and finds nothing.

Turn the dial too far toward specificity and you get Avatar's second phase, which is subtler and more common than it looks. Vendor systems ship with configurable parameters, and it is genuinely difficult to set them well. Set them too loose and analysts drown in false positives; tighten them to cut the noise and you can quietly engineer a system that almost never alerts. Avatar's one-second cancellation window is the perfect illustration: it may catch a fully automated spoofer, but a human trader placing and pulling orders operates on a scale of seconds to tens of seconds, so the parameter excluded exactly the population the firm was supervising. Each individual threshold looked defensible; stacked together, with compound AND conditions, they made the alert almost impossible to trigger. Over-tightening is often invisible precisely because a quiet alert queue looks like a clean book.

The reasonable window sits between those failures, and finding it is the whole discipline. It requires knowing your own traders and instruments, because the right parameters for a manual options desk are not the right parameters for an automated equities engine. It requires testing, because the only way to know whether a threshold catches manipulation is to run known patterns through it. And it requires periodic recalibration, because markets, strategies and the traders themselves change. Avatar's failure was not a single bad number; it was the absence of that discipline, first accepting a crude report as adequate, then accepting vendor defaults and tightening them without asking whether anything would ever fire.

There is a governance lesson braided through this, too. The heightened-supervision failure and the calibration failure are the same failure seen twice. Avatar identified a specific, elevated risk, a trader with a disruptive-trading history, and then supervised him with tools it had never confirmed could see disruptive quoting and trading activity. Recognising a risk and calibrating a control to it are different acts, and the gap between them is where this case lives. A surveillance program is only as good as the match between what it is tuned to detect and what the firm actually needs it to detect, and that match has to be demonstrated, not assumed.

04

Parallels across the record

Avatar is not an outlier. Miscalibrated surveillance is one of the most consistent findings in market-conduct enforcement, and the same shapes recur across the RegLabs record: a system that never received the data, a system that generated alerts nobody worked, and an alert design so cluttered the signal was overridden. Three cases, none of them small, make the pattern concrete.

J.P. Morgan Securities: the surveillance that never saw the data

CFTC · 2024 · $200 million

The CFTC fined J.P. Morgan Securities $200 million after finding that, from 2014 through 2021, its trade-surveillance systems failed to ingest billions of order messages from more than 30 venues, so on one designated contract market it surveilled less than 1% of order messages. The gaps stemmed from configuration issues and an erroneous assumption that direct-from-exchange data was inherently reliable. The remedy is the tell: the order expressly requires automated data reconciliation and measures to ensure surveillance scenarios and parameters are reasonably designed and calibrated, and monitored and tested routinely. A calibration failure at the data layer, upstream even of Avatar's, and the same fix.

Deutsche Bank Securities: the alerts nobody worked

CFTC · 2018 · $30 million

Deutsche Bank Securities did have a surveillance system tuned to catch spoofing in precious-metals futures, and it worked: it flagged several hundred instances of potential spoofing by the firm's own traders. The firm then did not review them. The CFTC found the firm failed to supervise diligently because it was aware of potential misconduct through its own alerts and took no steps to address it. This is the alert-disposition failure in its purest form, the mirror image of Avatar's too-narrow parameters. One firm tuned the system so it never fired; the other let it fire and ignored the output. Both are calibration of the whole detection-to-action loop, not just the threshold.

Citigroup Global Markets: the alert buried in the pop-up

UK PRA · 2024 · £33.88 million

When a Citigroup trader fat-fingered a US$444 billion basket, the firm's controls did generate warnings, 711 alerts in a single pop-up, of which only 18 were visible without scrolling, and a soft block the trader could override without reading them all. Downstream, teams did not escalate hundreds of information alerts, and the real-time control escalated the incident twenty minutes after the order had already been cancelled. The PRA fined the firm £33.88 million. Alert design is calibration too: a control that surfaces 711 warnings at once has, in practical terms, surfaced none, exactly the false comfort Avatar took from a quiet monthly report.

Put together, these cases describe a category, not a coincidence, and they map the full width of the calibration problem: too little data reaching the system (J.P. Morgan), a system tuned so tight it never alerts or so ignored its alerts go unworked (Deutsche Bank, and Avatar's own too-narrow parameters), and an alert design so cluttered the signal is lost (Citigroup). Regulators are increasingly examining not whether a firm has surveillance but whether the entire loop, data in, parameters, alerts, disposition, is calibrated to the firm's own trading, and they are finding, again and again, that a system can be fully deployed, fully documented, and still unreasonable. The fines range from a $100,000 exchange censure to a $200 million civil penalty; the finding, that the net was the wrong size or pointed the wrong way, is the one that keeps recurring.

05

Practical Insights

Calibration failures are fixable, and the controls that prevent them are well understood. Drawing on the control design RegLabs derives from this case, four discipline points matter most.

Pitfall 1: parameters set once, never validated The core failure is a threshold nobody tested against reality. The control is formal parameter tuning and validation: benchmark every scenario's logic and thresholds against known manipulative patterns, run historical and simulated spoofing and layering through the system, measure both false positives and false negatives, and document why each parameter is set where it is. A one-second cancellation window survives that process only if the desk actually trades that fast.

A second discipline point is matching the model to the trader. Avatar supervised a manual desk with parameters built for machine-speed behaviour. Surveillance has to be calibrated to how the firm actually trades: manual versus automated, options versus equities, market making versus directional, because a threshold that is reasonable for one is meaningless for another. The right question is never "is this a standard parameter?" but "would this catch our traders doing the thing we are worried about?"

Third is surveilling the right unit and the right factors. A monthly, symbol-level cancel-to-fill ratio was the wrong unit and the wrong factor. Effective spoofing and layering detection has to work at the order-and-execution level and incorporate the features that define the abuse, whether displayed orders sat at or inside the NBBO, whether executions came on the opposite side, the timing and sequencing of placements and cancellations. If a metric cannot separate a legitimate market maker from a spoofer, it is not a surveillance metric.

The fourth point ties calibration to governance: heightened risk demands a control proven to see it. When a firm identifies an elevated risk, a trader with a disciplinary history, a new strategy, a volatile product, it has to supervise that risk with a control confirmed to detect the relevant behaviour, and document that it did. Recognising a risk and then watching it with a tool you have never validated is the gap this case punishes. Periodic recalibration closes it, because a control that was reasonable last year may not be reasonable after the traders, the products or the strategies have changed.

06

Thematic Review

The Avatar finding sits inside one of the largest conduct-enforcement themes there is. Across the RegLabs record, surveillance-and-monitoring failures tied to spoofing and layering account for more than 700 catalogued actions, and the enforcers are led by FINRA and, overwhelmingly, the exchanges that examine market-conduct surveillance on their own venues, from the Nasdaq and Cboe families to NYSE, ICE and CME. Avatar's home venue, PHLX, alone accounts for more than twenty such actions. This is not a rare failure; it is a category regulators work systematically.

Spoofing and layering surveillance failures are venue-led

Catalogued surveillance-adequacy actions tied to spoofing/layering, by regulator · 700+ total · source: RegLabs

FINRA92
DOJ58
India · SEBI48
ICE40
Cboe (BZX/EDGX/EDGA/BYX)92
CME18
NASDAQ PHLX23

Cboe's figure aggregates its BZX, EDGX, EDGA and BYX venues; the wider Nasdaq family (Nasdaq, BX, PHLX, NQ and others) adds dozens more. By penalty value the CFTC and DOJ dominate through large criminal and civil spoofing cases; the exchange actions, like Avatar's, are smaller and far more numerous.

Zoom into the specific defect and the pattern sharpens. RegLabs tags a distinct failure mode, default and fallback logic, settings and parameters, that captures exactly the calibration problem at the heart of the Avatar case, and it recurs across more than a dozen surveillance and trading matters. In other words, mis-set parameters are not an idiosyncrasy of one firm; they are a recognised, catalogued way that trade surveillance and automated controls break, spanning both the too-blunt reports and the too-narrow vendor configurations.

Calibration failures span the surveillance stack

Related failure modes co-occurring in spoofing/layering surveillance cases · case count · source: RegLabs

Surveillance & monitoring procedures728
Trade/market surveillance program526
Core supervision435
Alert disposition & handling92
Technology governance & change77
Default/fallback logic & parameters13

Cases carry multiple tags, so these overlap. The point is the stack: a calibration failure rarely stands alone, it shows up as a surveillance-design finding, a supervision finding, an alert-handling finding, and, at the root, a parameter-and-logic finding.

The strategic reading is that "we have a surveillance system" is no longer an answer, and has not been for some time. Regulators, running their own calibrated cross-market surveillance, are testing whether a firm's net is the right size, and both a mesh too coarse and a mesh too fine now draw findings. The firms that stay clear of an Avatar outcome are the ones that treat calibration as an ongoing, evidenced discipline: parameters validated against known patterns, tuned to their own traders and instruments, tested for false negatives as rigorously as false positives, and recalibrated as the market moves. A quiet alert queue is not proof the controls work. It may be proof they were tuned until they stopped working.

Find the mis-tuned parameter before the regulator's net does

Test whether your surveillance is calibrated, not just deployed

Avatar had a report, a vendor system and someone watching screens. None of it was tuned to catch the conduct it existed to catch, and the same calibration failure recurs across the enforcement record, too blunt at one firm, too narrow at the next. RegLabs turns that record into regulatory models and analytics you can point at your own surveillance, so the mis-set parameter surfaces in a test rather than in an examiner's findings.

  • Automate regulatory review across surveillance design, spoofing and layering detection, supervision and alert-handling obligations, mapping every rule and disciplinary decision to the controls and parameters it touches.
  • Systematise risk assessment by benchmarking your surveillance scenarios, thresholds and calibration against the precise failure modes regulators keep citing, from too-blunt metrics to too-narrow vendor parameters.
  • Simulate an examination on your trade surveillance for your own firm, using RegLabs models to surface the questions FINRA, PHLX, ICE or the SEC would ask, and to pressure-test your calibration before their net does.
Explore this case in RegLabs Studio

This article is an independent editorial analysis for information only and is not legal or compliance advice. Avatar Securities, LLC consented to the findings without admitting or denying them.

Sources

  1. NASDAQ PHLX LLC Letter of Acceptance, Waiver, and Consent, Avatar Securities, LLC (accepted 4 September 2026; censure and $100,000 fine), for violations of Phlx Rule General 9, Sections 53, 20(h) and 1(c), and PSX Rule 3503, in connection with surveillance for spoofing, layering and disruptive quoting and trading activity from March 2020 through July 2026. Parallels drawn from the RegLabs enforcement database (J.P. Morgan Securities, CFTC 2024, $200m; Deutsche Bank Securities, CFTC 2018, $30m; Citigroup Global Markets Limited, UK PRA 2024, £33.88m); all aggregate figures also drawn from RegLabs; counts and totals are cumulative and approximate, and categories overlap. Full case record: studio.reglabs.ai .
Anatomy of an Erroneous Order: A Risk-Controls Dissection for Control-Review SeasonAlways on, fully delegated: the risk map for agentic AI tradingTwenty seconds before the bell: how BMO Nesbitt Burns marked the close