Skip to content

NISM-Series-VII: Securities Operations and Risk Management · Risk Management

Surveillance and Operational Risk Controls for NISM Series VII

Updated 11 October 2026 · Fact-checked

Surveillance is the monitoring of trading to detect unusual or manipulative activity. Operational risk is the risk of loss from failed people, processes, systems or external events. Controls such as checks, segregation of duties, audit, and business continuity and disaster recovery plans reduce it. Match each question to the control that fixes the stated cause.

Understand Surveillance and Operational Risk Controls

Markets can be abused. Someone may move a price with a few trades, trade on secret information, or trade with themselves to fake volume. Market surveillance is the watching of trades, orders and positions to spot such behaviour early. Stock exchanges, clearing corporations and depositories run surveillance systems, and SEBI supervises the whole structure. Brokers and depository participants must also watch their own clients.

Surveillance works on alerts. Software compares activity against set patterns, such as a sudden jump in price or volume in a stock, heavy trading by a few accounts, or repeated trades between the same parties. An alert is not proof of wrongdoing. It starts a review. The exchange may seek explanations, then escalate to SEBI, or apply measures such as closer monitoring or restrictions. Check your workbook for the exact named measures, as you must not guess them.

Operational risk is the risk of loss from inadequate or failed internal processes, people, systems, or external events. Typical causes are human error (wrong order entry, wrong client code), system failure, fraud, weak controls, and external events such as fire, floods or cyber attacks. It is different from market risk (price moves) and credit risk (counterparty not paying).

Internal controls reduce operational risk. Key ones are written procedures, segregation of duties (the person who initiates a transaction is not the one who approves or reconciles it), maker-checker, access limits, regular reconciliation, internal audit, and clear escalation. Controls are preventive (stop errors), detective (find them) or corrective (fix them).

A business continuity plan (BCP) keeps critical operations running during a disruption. Disaster recovery (DR) is the technical part: restoring systems and data, usually from a backup site in a different location. Plans must be documented and tested regularly, otherwise they fail when needed.

Key formulas to remember

Operational risk definition
Operational risk = loss from failed processes, people, systems or external events
It excludes pure price risk (market) and counterparty default (credit).
Segregation of duties
Initiator ≠ Approver ≠ Reconciler
Core internal control against error and fraud.
Control types
Preventive | Detective | Corrective
Prevent errors, find them, fix them. Classify the control in a question by its purpose.
BCP versus DR
BCP = whole-business continuity; DR = IT recovery of systems and data
DR is a part of BCP, not the other way round.
Surveillance alert
Alert → review → explanation sought → escalation
An alert is a trigger for enquiry, not proof of manipulation.

How to solve Surveillance and Operational Risk Controls questions

Use this order for any scenario or definition question on surveillance or operational risk.

  1. 1Read the last line first to see what is asked: a cause, a control, a definition or a next action.
  2. 2Identify the risk type: market, credit, liquidity or operational. If the loss comes from a failed process, person, system or event, it is operational.
  3. 3For surveillance questions, ask who monitors (exchange, clearing corporation, depository, broker) and what pattern is unusual.
  4. 4For control questions, pick the control that directly addresses the stated cause, for example segregation of duties for fraud, reconciliation for mismatches, backup site for system loss.
  5. 5Eliminate options that overstate, such as 'eliminates all risk' or 'proves manipulation'.
  6. 6Check for absolute words like always and only; these are usually traps.
  7. 7Choose the answer, then re-check that it answers the exact question asked.

Quickest way: Cause-to-control matching

When to use it: When the question names a failure and asks for the fix, or names a control and asks what it addresses.

  1. Underline the cause in the question: error, fraud, system, external event, or unusual trading.
  2. Map it: error → checks and maker-checker; fraud → segregation of duties and audit; system or disaster → BCP and DR; unusual trading → surveillance alert and review.
  3. Pick the option matching that map and drop the rest.

Common mistakes in Surveillance and Operational Risk Controls

  • Treating a surveillance alert as proof of manipulation

    The word alert sounds like a finding.

    Fix: Remember alert → review. Proof comes only after enquiry.

  • Classifying a wrong order entry as market risk

    The loss shows up as a price difference.

    Fix: Look at the cause. A human or process error is operational risk.

  • Confusing BCP with DR

    Both deal with disruption.

    Fix: BCP covers the whole business and people; DR is restoring IT systems and data.

  • Thinking one person can handle a whole transaction if trusted

    Trust seems to replace controls.

    Fix: Segregation of duties is required regardless of trust.

  • Believing a plan on paper is enough

    Documentation looks like compliance.

    Fix: Plans must be tested periodically and updated.

  • Choosing options saying controls eliminate risk

    Controls sound complete.

    Fix: Controls reduce risk; they do not remove it.

Worked examples

Example 1

A dealer at a broking firm enters a buy order and also approves and reconciles the same trade, and a fraud goes unnoticed. Which control was missing?
A. Higher margins
B. Segregation of duties
C. Wider circuit filters
D. Lower exposure limits

Show the solution
  1. The cause is fraud going undetected, which is a failure of internal process.
  2. One person initiated, approved and reconciled, so no independent check existed.
  3. Margins, circuit filters and exposure limits address market or credit risk, not this.
  4. The control that separates initiator, approver and reconciler is segregation of duties.

Answer: B. Segregation of duties

Example 2

A broker's main data centre is lost in a flood. Which arrangement allows it to restore systems and data from a separate location?
A. Disaster recovery site
B. Circuit filter
C. Surveillance alert
D. Position limit

Show the solution
  1. The cause is an external event destroying IT systems.
  2. The risk is operational, so the fix is a continuity arrangement.
  3. Restoring systems and data from another location is disaster recovery.
  4. Circuit filters, position limits and surveillance alerts do not restore operations.

Answer: A. Disaster recovery site

Exam tips

  • Match the cause to the control. Most questions test exactly this link.
  • Reject absolute options such as 'eliminates' or 'proves'.
  • Know which body does what in surveillance, and use your workbook for exact named measures rather than guessing.
  • Under negative marking, skip a question only if you cannot narrow to two options; otherwise decide by elimination.

Practice questions from Risk Management

Surveillance and Operational Risk Controls in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Surveillance and Operational Risk Controls: frequently asked questions

What is market surveillance in securities markets?

It is the monitoring of orders and trades to detect unusual or manipulative activity. Exchanges, clearing corporations and depositories run it, and SEBI oversees the system.

What causes operational risk in securities operations?

Failed processes, human error, fraud, system failures and external events such as fires or cyber attacks. It is separate from price and counterparty risk.

How is operational risk in settlement reduced?

Through written procedures, segregation of duties, maker-checker, regular reconciliation, audit and tested continuity plans.

What is the difference between BCP and DR?

BCP keeps the whole business running during a disruption. DR is the IT part, restoring systems and data, often from a backup site.