Breaking Regulatory Compliance
SEC Billimek-Williams Front-Running Settlement: The Surveillance Pattern Firms Should Test
The SEC Billimek-Williams front-running settlement shows how order, account, and communications data can expose insider trading controls that failed.
Table of Contents
TL;DR
- The SEC’s proposed Billimek-Williams front-running settlement would resolve a 2022 civil case involving approximately $47.3 million in alleged illegal trading profits.
- The alleged pattern was measurable: 1,697 intraday trade overlaps, a 97% win rate, and communications immediately before trades.
- A code of ethics existed. The harder control question is whether the firm joined order data, employee access, outside-account activity, and communications metadata quickly enough to detect the pattern.
- Advisers should run a targeted lookback now, with Compliance owning the investigation and Trading, Legal, HR, and Data supporting it.
A six-year front-running scheme should not look invisible in hindsight. According to the SEC, it looked like 1,697 same-day overlaps, repeated communications before trades, and a 97% win rate.
The SEC’s September 22, 2026 litigation release announced proposed final judgments against Lawrence Billimek and Alan Williams. The agency did not announce a new complaint. It moved to settle the civil case it filed in December 2022, subject to court approval.
That distinction matters. So does the compliance lesson: written prohibitions on front-running and misuse of material nonpublic information are only the first layer. The case shows what happens when access, trading, and communications data are not turned into a joined surveillance view.
What the SEC Billimek-Williams front-running case alleged
The SEC’s 19-page complaint alleged that Billimek worked as an equity trader for a major U.S. asset manager. His role gave him access to planned orders for client funds—orders large enough to move market prices.
The complaint says Billimek provided that information to Williams. Williams then allegedly opened positions in the same securities before, or while, the asset manager executed its orders. Once the institution’s trading moved the price in the anticipated direction, Williams closed his position.
The alleged scheme ran from at least September 2016 through August 15, 2022 and covered hundreds of public companies.
| Case element | SEC allegation or proposed result |
|---|---|
| Conduct | Trading ahead of a large asset manager’s nonpublic orders |
| Period | September 2016 through August 15, 2022 |
| Trading pattern | 1,697 intraday round trips overlapping the funds’ trades |
| Alleged profit | At least $47.3 million |
| Williams win rate on overlapping trades | 97% |
| Billimek disgorgement | $12,684,000 |
| Williams disgorgement | $34,627,659 |
| Williams prejudgment interest | $12,027,557.75 |
| Status | Proposed final judgments, subject to court approval |
The proposed judgments permanently enjoin both defendants from violations of Securities Act Section 17(a), Exchange Act Section 10(b), and Rule 10b-5. Billimek would also be enjoined from violations of Investment Company Act Section 17(j) and Rules 17j-1(b)(1) and (3). The monetary amounts are deemed satisfied by forfeiture ordered in the parallel criminal case.
Calling the $47 million a “fine” would be wrong. It was the approximate illegal profit alleged by the SEC. The proposed civil resolution specifies disgorgement and prejudgment interest, with satisfaction through criminal forfeiture.
The sequence was detectable, not merely suspicious
The complaint’s examples read like surveillance specifications.
On July 8, 2022, for example, the SEC alleged that Williams exchanged texts with a prepaid phone, bought 69,000 shares of “Company A,” and sold those shares immediately after the asset manager bought at least 64,343 shares. The complaint describes two more similar sequences in the same security later that day. The alleged profit from that day’s activity was approximately $169,900.
The SEC said the pattern extended far beyond one example:
- The outside accounts initiated 1,697 unique intraday round-trip combinations where the funds traded the same symbol, on the same date, and in the same direction.
- The outside positions opened before the funds’ large trades and closed after those trades could affect the market.
- The alleged overlap had odds of less than one in a trillion of occurring by random chance.
- More than 99% of 1,465 outgoing texts from one prepaid phone during a five-month period went to Williams.
- Williams allegedly transferred at least $540,000 to Billimek’s bank account.
Those are allegations from the complaint, not independent findings by RiskTemplates. But they expose the data relationships a surveillance program should be capable of testing.
Why a code of ethics was not enough
The asset manager allegedly classified Billimek as an “Access Person.” Its code of ethics prohibited front-running and disclosure of fund or client transaction information outside the firm.
That is necessary under the access-person framework reflected in Investment Company Act Rule 17j-1. It did not, by itself, stop the alleged conduct.
The practical failure mode is familiar: the policy team owns attestations, the trading desk owns order data, a vendor receives employee brokerage feeds, Information Security owns messaging telemetry, and nobody is accountable for joining the datasets. Every control can appear “green” while the pattern between systems goes untested.
The case is different from a conventional employee-personal-account exception. Williams’ accounts were not alleged to be accounts held in Billimek’s name. A surveillance design limited to disclosed employee accounts could therefore miss the core pattern.
That is why the useful question is not merely, “Did the employee preclear the trade?” It is, “Which external accounts repeatedly trade ahead of orders visible to this employee?”
Turn the allegations into surveillance tests
A defensible program needs multiple tests because no single alert proves misconduct.
| Test | Data required | Starter trigger to investigate | Evidence owner |
|---|---|---|---|
| Order-ahead correlation | Parent orders, child fills, external-account executions | Same symbol and direction; external entry before institutional execution; exit shortly after | Trade Surveillance |
| Repeated win-rate anomaly | P&L and overlap population | Statistically unusual success over a meaningful sample, compared with account history and peers | Surveillance Analytics |
| Access-to-order linkage | OMS access logs, desk assignments, order timestamps | Employee viewed or handled the order before correlated external trading | Trading Operations / InfoSec |
| Communications proximity | Call and message metadata, approved-channel records | Contact immediately before recurring correlated trades | Compliance / Legal |
| Beneficial relationship review | Disclosures, payments, HR records, investigation results | Unexplained payment or relationship connecting an employee to an external account | Compliance Investigations |
| Control-evasion signal | Device inventory, approved communications, metadata | Repeated contact through undisclosed devices or channels near alerts | InfoSec / Compliance |
These are starter triggers, not universal thresholds. Calibrate lookback windows and alert cutoffs against at least three to six months of the firm’s own order duration, liquidity, strategy, and false-positive history. A five-minute window may work for one desk and be useless for a multi-hour execution strategy.
Anti-gaming matters too. Reconcile every alert to a case ticket, preserve query versions, and track reopened cases. If an analyst can clear a high-confidence alert with “no employee account match,” the procedure has embedded the wrong assumption.
This enforcement theme also connects to the broader SEC focus on MNPI controls and insider trading and the control weaknesses discussed in the Doximity executive trading case. The common thread is access plus timing—not job title.
Five things to check Monday morning
1. Rebuild the access-person population
The CCO should reconcile the access-person list to HR job codes, order-management permissions, desk rosters, shared-drive groups, and temporary assignments. Sample terminated and transferred employees. The evidence artifact is a dated reconciliation with exceptions and owners, not an annual certification spreadsheet.
2. Test whether outside-account feeds are complete
Compare employee attestations with duplicate confirmations, automated broker feeds, preclearance records, and known financial relationships. Escalate stale feeds and unsupported “no reportable account” certifications. Compliance Operations should document the source, last successful load, and exception status for each covered person.
3. Run an external-account correlation lookback
Trade Surveillance should query accounts already known through investigations, counterparties, referrals, or relationship disclosures—not only employee-named accounts. Rank repeated same-symbol, same-direction intraday overlaps ahead of institutional orders. Start with employees who can see parent orders or portfolio-manager intent.
4. Join communications metadata after a trading alert
Do not conduct indiscriminate monitoring. Once trading data establishes a risk-based alert, Legal and Compliance should use an approved investigation protocol to compare communication timestamps, device identifiers, and relevant contacts. Document legal basis, scope, retention, and access controls.
5. Fix closure logic
A reviewer should not close an alert merely because the employee did not trade personally. Require the disposition to address access, timing, relationship, communications, trading outcome, and repeat behavior. High-confidence or repeated alerts should receive independent second-level approval.
If the lookback produces gaps, record them as owned remediation—not email promises. The Issues Management Tracker & Template gives Compliance a clean way to assign owners, evidence, due dates, and validation for the fixes.
A 30/60/90-day response plan
Days 1–30 — define exposure. The CCO names one accountable lead. Compliance, Trading, HR, Legal, and Data inventory available fields and reconcile the access-person population. Surveillance documents current alert logic and known blind spots. Open issues for missing feeds, stale entitlements, and closure standards.
Days 31–60 — test the pattern. Analytics runs a risk-based lookback on employees with order visibility, using same-security timing, direction, holding period, profitability, and repeat frequency. Investigators review high-confidence results with communications and access metadata under Legal-approved procedures.
Days 61–90 — prove sustainability. Model or surveillance validation challenges thresholds and false-negative scenarios. Compliance samples closed alerts, verifies evidence, and reports overdue remediation to the appropriate risk committee. Internal Audit or an independent testing team confirms that resolved issues actually changed production logic.
The real takeaway from the SEC front-running settlement
The policy in the SEC complaint already prohibited the conduct. The signal came from relationships among data: who knew about the order, who communicated, who traded, when they traded, and whether the outcome was implausibly successful.
That is the control test worth carrying into the next surveillance review. If those fields cannot be joined, the firm does not yet have a surveillance conclusion. It has separate systems and a policy.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the SEC allege Lawrence Billimek and Alan Williams did?
How much did the proposed SEC settlement require?
What surveillance pattern did the SEC identify?
Which controls should investment advisers test after this case?
Was the September 2026 SEC action a new complaint?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
● Don't wait for your own enforcement action
Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Regulatory Compliance
OFAC Just Codified Its Penalty Playbook. What 31 CFR Part 505 Means for Your Sanctions Compliance Program.
On September 25, 2026, OFAC's new Sanctions Penalties Regulations (31 CFR Part 505) took effect — the first time OFAC has consolidated its civil and criminal penalty procedures into formal regulations. Here's what changed and what your compliance program needs to account for.
Sep 27, 2026
Regulatory Compliance
Nano Banc Failed at 0.82% Capital: The Enforcement Timeline Risk Teams Should Read
The Nano Banc failure followed years of governance orders and a missed 9.5% capital mandate. Here is the control breakdown and response checklist.
Sep 26, 2026
Regulatory Compliance
Federal Reserve Stablecoin Rules: The Capital Math and Application Binder Banks Need Now
Federal Reserve stablecoin rules propose capital, reserve, reporting, custody, and application standards under the GENIUS Act.
Sep 25, 2026