- Enforcement
- Markets & Trading
- Governance & Accountability
Eight minutes, no investigation
A low-priced stock doubled in eight minutes before the open, through a single omnibus account, and the trades tripped the firm's own surveillance alerts. Nobody looked. FINRA fined the firm for written procedures that never described the very patterns they were meant to catch.

FINRA · Rules 3110 & 2010 · Manipulation Surveillance
Eight minutes, an alert, and no investigation
Source: FINRA Letter of Acceptance, Waiver, and Consent, TD Arranged Services LLC, formerly ATM Execution LLC; published 14 September 2026.
A low-priced security doubled over an eight-minute premarket window through one omnibus account. Some trades reached the firm's alerts, but the firm did not timely investigate or respond.
Overview
On 14 September 2026, FINRA published a settlement with ATM Execution LLC, an executing broker that primarily handled institutional order flow and has since been renamed TD Arranged Services. The firm was censured and fined $12,500 for a supervisory failure that is small in dollars and large in instruction: between December 2021 and December 2024, its written supervisory procedures were not reasonably designed to detect or investigate manipulative trading, and the specific example FINRA chose to include is hard to forget. On one day in the relevant period, a low-priced security traded through an omnibus account at the firm doubled in price over an eight-minute premarket window. That account was a significant portion of the total volume, and some of the trades appeared on the firm's own surveillance alerts. The firm did not timely investigate or respond.
The matter did not come from a customer complaint or an internal audit. It originated from FINRA's own surveillance, which is the quiet theme running under this whole case: the regulator's cross-market net caught what the firm's did not. What FINRA found was not the absence of a surveillance system but a system whose written procedures never described the patterns they were supposed to identify. The WSPs did not explain how prearranged or coordinated trading and momentum ignition would be spotted across different accounts, or, critically, within a single omnibus account. They defined spoofing and layering too narrowly. And their marking-the-close parameters were drawn so tight that they would miss activity occurring before the final minute of trading, or in smaller orders that nonetheless set a security's price.
Five distinct manipulative patterns, one underlying failure: procedures that named the risks without ever operationalising them. The firm consented without admitting or denying, and it has since transitioned its accounts to an affiliate with supervisory procedures that address manipulative trading and closed the omnibus accounts involved. The $12,500 penalty will not trouble anyone's budget. But this is a template case, one FINRA has been bringing against firm after firm, and its lessons about omnibus blind spots, over-narrow definitions, and alerts that fire into a void apply far beyond a single small broker.
ATM Execution: case facts
The central failure was the design of the written procedures: they did not operationalise detection, investigation, or escalation.
Source: FINRA Letter of Acceptance, Waiver, and Consent, TD Arranged Services LLC, formerly ATM Execution LLC; published 14 September 2026.
Infringements
The charge is a violation of FINRA Rules 3110(a) and (b), the supervision rule, and by extension Rule 2010, the requirement to observe high standards of commercial honour. FINRA found the firm failed to establish, maintain, and enforce a supervisory system, including written supervisory procedures, reasonably designed to achieve compliance with the rules and laws prohibiting manipulative trading. The finding spans a full menu of manipulation: prearranged and coordinated trading, momentum ignition, layering and spoofing, and marking the close. There was no allegation that the firm itself manipulated anything, and no proof that its customers did; the violation is the supervisory design, the failure to build procedures capable of catching the conduct.
The deficiencies are specific, and they cluster into two shapes. The first is a blind spot: the WSPs did not describe how patterns indicating prearranged or coordinated trading and momentum ignition would be identified between different accounts, or within a single omnibus account, or how such activity would be investigated once detected. Because an omnibus account aggregates many underlying traders behind one identifier, coordination among them is invisible unless the surveillance is deliberately built to look inside, and the firm's was not. The second shape is miscalibration: the WSPs defined spoofing and layering too narrowly, offered no clear guidance on what a reviewer should actually look for in the surveillance report, and set marking-the-close parameters that excluded activity before the last minute of trading and smaller orders that set a security's price.
The eight-minute episode is where the two shapes met a live event. The omnibus account's premarket trading in one low-priced security doubled the price in eight minutes and made up a significant share of volume, and some of those trades did surface on the firm's surveillance alerts. Yet the firm failed to timely investigate or otherwise respond. Detection, at least partially, worked. The written procedures that should have told someone what the alert meant and what to do about it did not exist in usable form, so the alert died where it landed. That is the case in one sentence: the net had holes, and where it did catch something, no one had written down what to do next.
Analysis
The root failure is that the firm's procedures named the risks without describing them. It is one thing for a WSP to say the firm surveils for spoofing, layering, and marking the close; it is another for it to define each pattern accurately, tell a reviewer what a surveillance report would show when the pattern is present, and set thresholds calibrated to catch it. FINRA's finding is that ATM Execution did the first and not the second. A procedure that lists manipulative behaviours but cannot operationalise their detection is a compliance artefact, not a control, and it produces exactly this outcome: a system that looks supervised on paper and is not in practice.
The omnibus blind spot is the most consequential piece, because it is structural rather than incidental. Surveillance that scores activity at the account level treats an omnibus account as a single trader, when it is in fact a curtain in front of many. Prearranged and coordinated trading, and momentum ignition driven by a group acting together, live precisely in the relationships the omnibus hides. Catching them requires surveillance designed to look inside the omnibus, to ask who the underlying participants are and whether they are moving together. The firm's WSPs never contemplated that question, so the coordination was, by design, unseeable. The eight-minute doubling is what that blind spot looks like when it is exercised.
The miscalibration is the more familiar failure, and it is the one that recurs across the enforcement record. Defining spoofing and layering too narrowly, or setting a marking-the-close window that only looks at the final minute, quietly engineers a system that rarely fires on the real thing. Manipulation does not confine itself to the last sixty seconds, and a price-setting order need not be large; a threshold that assumes otherwise is tuned to miss. The same is true of the reviewer guidance gap: an alert is only useful if the person receiving it knows what they are looking at, and the WSPs offered no clear description of what should raise concern. A surveillance report with no interpretive guide is a spreadsheet nobody can act on.
Then there is the alert that fired and died. This is the most damning detail, because it separates a detection failure from a response failure. The firm was not entirely blind; the eight-minute activity reached its alerts. What was missing was any procedure for investigating and escalating what the alerts surfaced, so a genuine red flag, a security doubling premarket on concentrated omnibus volume, produced no timely response. An alert that no procedure tells anyone how to handle is worse than no alert, because it creates a record of a warning the firm received and did not act on. Detection without disposition is not surveillance; it is documentation of the thing you missed.
It is worth reading the proportionality honestly. This is a $12,500 case against a small executing broker that has since remediated, closed the omnibus accounts, and moved its business to an affiliate with proper procedures. The dollar figure reflects the firm's size and cooperation, not the seriousness of the control gap. The reason a case this small still merits attention is that the failure mode is universal, FINRA is pursuing it systematically across firms of every size, and the same omnibus and calibration gaps that produced a modest fine here have produced seven-figure ones elsewhere. The size of the penalty is a function of the firm; the lesson is not.
Five patterns, one gap
FINRA faulted the firm's procedures across five manipulative patterns at once. Each is a specific calibration or coverage failure, and together they map the anatomy of an under-designed surveillance program.
Prearranged / coordinated trading
The WSPs did not describe how to identify coordination across accounts, or within a single omnibus account, or how to investigate it.
Momentum ignition
The procedures did not describe the pattern or how to spot it; the eight-minute premarket doubling went uninvestigated.
Spoofing
Defined too narrowly, with no clear guidance on what a reviewer should look for in the surveillance report.
Layering
Defined too narrowly as well, limiting the scope of what the firm would even monitor.
Marking the close
Parameters excluded activity before the final minute of trading, and smaller orders that set a security's price.
The common thread
Procedures that named each risk but never operationalised its detection, investigation, or escalation.
Practical Insights
The controls that would have changed this outcome are well understood, and the FINRA order effectively names them by describing what was missing. Four belong on any surveillance program's agenda.
Pitfall 1: WSPs that name a pattern without describing it Listing spoofing, layering, momentum ignition, and marking the close in a procedure is not the same as detecting them. Each pattern needs an accurate definition, a description of what the surveillance report shows when it is present, the specific factors a reviewer should weigh, and a defined threshold for concern. A procedure a reviewer cannot act from is not a control, and FINRA treats it as one that does not exist.
The second pitfall is the omnibus blind spot. Surveillance tuned to a single account cannot see coordination among the clients trading behind an omnibus identifier, which is exactly where prearranged and coordinated trading and group-driven momentum ignition hide. The control is surveillance and procedures deliberately designed to look inside omnibus flow: aggregating and disaggregating activity, testing for participants moving together, and defining when the firm must inquire into the underlying beneficial owners. If your surveillance treats an omnibus account as one trader, it is not surveilling the risk that account actually carries.
The third pitfall is parameters tuned to miss. A marking-the-close window that only examines the final minute, or a spoofing definition drawn too narrowly, quietly guarantees the alert rarely fires on the real thing. Parameters have to be calibrated to how manipulation actually occurs, before the last minute, in smaller price-setting orders, over longer sequences, and validated by running known manipulative patterns through the system to measure what it misses, not just what it flags. False negatives are the number that matters here, and they are the number firms least often measure.
The fourth pitfall is the alert with nowhere to go. The eight-minute doubling reached the firm's alerts and produced no response, because no procedure told anyone how to investigate or escalate it. Every alert type needs a defined disposition path: who reviews it, in what timeframe, what evidence they must capture, and when it escalates. An unactioned alert is not a near miss; it is a documented warning the firm chose not to pursue, and it is the first thing an examiner will pull. The question to run internally is simple: if that stock doubled through our omnibus account tomorrow, which procedure catches it, and who acts?
Parallels across the record
ATM Execution is not an outlier; it is a recent entry in a sustained FINRA campaign against surveillance programs that are deployed but not reasonably designed. The RegLabs record is full of the same shapes, at every size, and three cases show the range.
Mirae Asset Securities: the near-identical twin
Weeks before the ATM Execution order, FINRA settled with Mirae Asset Securities on almost the same facts: WSPs that failed to describe how prearranged or coordinated trading and momentum ignition would be identified within a single omnibus account, for foreign broker-dealer clients. Mirae's own tools generated 28 momentum-ignition alerts in one month on one omnibus account, including a day the account was over 6% of premarket volume as a security ran from $5.60 to $25.00. Same omnibus blind spot, same uninvestigated alerts, weeks apart.
Great Point Capital: the parameters tuned too narrow
Great Point ran a third-party surveillance system but set its parameters to exclude spoofing and layering where the non-bona-fide orders were entered more than one minute before the executed order, and only captured orders at or outside the NBBO, so the system failed to detect potentially manipulative activity throughout the period. Its WSPs also did not describe what a reviewer should evaluate or when to escalate, and provided no supervisory review of alerts closed without escalation. It was a repeat: FINRA had fined the firm $1.1 million for similar failures in 2015.
Velocity Clearing: the alerts nobody worked
Velocity is the alert-disposition failure at industrial scale. It left its prearranged-trading surveillance switched off for three years, even after other broker-dealers flagged more than 40 of its customers, then closed more than 147,000 manipulation alerts without investigation. A replacement system generated roughly 15.2 million alerts, of which millions went unreviewed. Where ATM Execution let one alert die, Velocity let them die by the million, and the underlying gap, procedures that never said how to work an alert, is identical.
Read together, and alongside larger data-layer cases like Credit Suisse (hundreds of millions of records omitted from surveillance) and Instinet (premarket and marking-the-close parameters found unreasonably narrow), these actions describe a category FINRA works methodically. The common finding is never that a firm lacked surveillance; it is that the surveillance was not reasonably designed, whether because the definitions were too narrow, the omnibus was a blind spot, or the alerts went unworked. ATM Execution is the small, clean illustration of the pattern.
A busy FINRA docket: recent manipulation-surveillance AWCs
FINRA fine per action for inadequately designed manipulation surveillance · Source: RegLabs
Fines are the FINRA AWC amounts as stated; for firms settling across multiple venues, the figure is the total AWC fine. The dollar range spans two orders of magnitude, but the finding is the same in every one: surveillance deployed, not reasonably designed.
Thematic Review
Zoom out and this small case sits inside one of FINRA's most active supervisory themes. Surveillance-adequacy failures tied to the manipulative patterns in the ATM Execution order recur across hundreds of catalogued actions, and while the broker-dealers pay through FINRA, the exchanges police the same conduct on their own venues. In the slice of the RegLabs record covering surveillance-and-monitoring failures for momentum ignition and marking the close alone, FINRA is the single largest enforcer, followed closely by the equity exchange families that run parallel programs.
Who enforces manipulation-surveillance adequacy
Catalogued surveillance-and-monitoring actions tied to momentum ignition and marking the close, by regulator · 322 total · Source: RegLabs
This slice totals 322 catalogued actions and roughly $197m in penalties; the wider spoofing-and-layering surveillance-adequacy theme runs to more than 700 actions. The many other Nasdaq and Cboe venues add dozens more. The point is breadth: this is a systematically examined obligation, not a rare finding.
The mechanism that makes it systematic is the one that caught ATM Execution: FINRA runs its own cross-market surveillance, and it originates these matters when a firm's flow trips the regulator's net and the firm's response, or lack of one, does not hold up. The eight-minute doubling is a case in point. FINRA did not need the firm to self-report; it saw the activity, looked at how the firm handled it, and found the procedures wanting. For a broker, that means the realistic risk is not a rare catastrophic fine but a near-certain finding if the surveillance is deployed without being designed, because the regulator is already watching the same tape.
The strategic reading is that "we have a surveillance system" has not been a sufficient answer for years, and the bar keeps rising toward demonstrable design. Regulators are testing whether the definitions are accurate, whether the omnibus is covered, whether the parameters catch manipulation as it actually occurs, and whether alerts are worked. A firm that can answer those questions with evidence, tested thresholds, documented omnibus coverage, a defined alert-disposition path, will pass. A firm relying on a procedure that names the risks and a system that fires into a void will, sooner or later, meet its own eight-minute doubling in an examiner's findings.
Find the gap before FINRA's net does
Test whether your surveillance is designed, not just deployed
ATM Execution had a surveillance system and alerts that fired. What it lacked were procedures that described the patterns, covered the omnibus, calibrated the parameters, and told anyone what to do when an alert lit up. Those gaps, and the far larger versions of them, are visible across the enforcement record. RegLabs turns that record into regulatory models and analytics you can point at your own program, so the missing definition, the omnibus blind spot, and the unworked alert surface in a review rather than in an AWC.
- Automate regulatory review across surveillance design, spoofing, layering, momentum ignition, marking-the-close and omnibus obligations, mapping every rule and disciplinary decision to the controls and parameters it touches.
- Systematise risk assessment by benchmarking your WSP definitions, omnibus coverage, surveillance thresholds and alert-disposition against the precise failure modes FINRA keeps citing.
- Simulate an examination on your trade surveillance for your own firm, using RegLabs models to surface the questions FINRA, the SEC or an exchange would ask, and to pressure-test your calibration before their net does.
This article is an independent editorial analysis for information only and is not legal or compliance advice. TD Arranged Services LLC consented to the findings without admitting or denying them.
Sources
- FINRA Letter of Acceptance, Waiver, and Consent, TD Arranged Services LLC, formerly ATM Execution LLC (executed 27 August 2026, published 14 September 2026; censure and $12,500 fine), for violations of FINRA Rules 3110(a), 3110(b) and 2010 in connection with supervision of manipulative trading from December 2021 to December 2024.
- Parallels drawn from the RegLabs enforcement database (Mirae Asset Securities, FINRA 2026, $18,550; Great Point Capital, FINRA 2026, $250,000; Velocity Clearing, FINRA 2025, $1,000,000; and Instinet, Blue Ocean ATS, TradingBlock and Credit Suisse). All aggregate figures also drawn from RegLabs and are cumulative and approximate.
- Full case record: studio.reglabs.ai.
