An examiner sends the document request list. Somewhere between the code of ethics and the business continuity plan sits a line asking for your firm's policies and procedures governing artificial intelligence. At that point you either have a dated PDF or you have a very long weekend.
Most firms adopted the tools before they wrote anything down. Sixty-three percent of RIAs now use AI in some capacity, more than double the rate three years ago, according to the 2026 RIA and AI Research Study from Charles Schwab, which surveyed 533 advisory firms in October 2025. Roughly one in ten of those firms has integrated AI into business strategy. The rest are experimenting, which is fine, right up until someone asks who approved it.
What the SEC Says
The Division of Examinations published its 2026 examination priorities on November 17, 2025. Examiners will review "training and security controls that firms are employing to identify and mitigate new risks associated with artificial intelligence (AI) and polymorphic malware attacks." Separately, they will "review for accuracy registrant representations regarding their AI capabilities."
Those are two different exams inside one sentence. The first is a security question: does your staff recognize an AI-generated voice on a wire verification call. The second is a marketing question: does your Form ADV describe what your AI does today, or what you hope it will do by Q3.
The SEC has enforced the second one already. In March 2024 it charged Delphia and Global Predictions with making false and misleading statements about their use of AI, settling for $400,000 combined. "Investment advisers should not mislead the public by saying they are using an AI model when they are not," then-Chair Gary Gensler said in the announcement. "Such AI washing hurts investors."
The Hard Part Is There Is No AI Rule
Compliance officers are trained to wait for the rule. There is no AI-specific rule for investment advisers, and waiting for one is the wrong read of the situation.
AI governance gets enforced through instruments already binding on your firm. Advisers Act Rule 206(4)-7 requires written policies and procedures reasonably designed to prevent violations, reviewed at least annually. Once AI touches your investment process, your client communications, or your books and records, it is inside that perimeter. The Marketing Rule governs how you describe it. And Regulation S-P governs what happens when an AI vendor holding your client data gets breached.
That last one is settled. The amended Reg S-P compliance date for smaller entities, meaning advisers with $1.5 billion or less in regulatory assets under management, was June 3, 2026, and it has passed (Holland & Knight). Your written incident response program and your service provider oversight obligations are live requirements today, including the provision requiring providers to notify you within 72 hours of unauthorized access. The AI notetaker sitting in your client meetings is a service provider. It does not feel like one. It feels like a feature.
The Eight Sections of an AI Governance Policy
A policy that survives examination is short, dated, and accurate. Length is not the metric. A ten-page policy describing controls your staff ignored last Tuesday is worse than a three-page policy they follow, because the first one documents the gap in writing.
Here is the skeleton.
1. Scope and definitions. State what counts as AI at your firm. Generative assistants, meeting transcription, CRM enrichment, portfolio optimization, marketing copy tools, and anything embedded in software you already license. That last category is where firms get surprised, because vendors keep shipping AI features into products purchased before AI was a consideration.
2. Tool inventory. A living list of every approved AI tool, its owner, its business purpose, whether it touches client data, and its review date. This is the least interesting section in the document and the one most likely to be missing.
3. Approval gate. Name the person or committee who authorizes a new tool, and state that no tool touches client data before approval. Fifty-nine percent of firms have formed a formal AI governance committee, per the 2026 Investment Management Compliance Testing Survey of 411 adviser firms. A committee is optional at a twelve-person shop. A named decision-maker is not.
4. Permitted and prohibited uses. Write both columns. Permitted might include meeting summaries with client consent and internal research drafting. Prohibited should be specific enough to be enforceable: no client personally identifiable information in consumer chatbot accounts, no AI-generated performance claims, no trade recommendation reaching a client without an adviser reviewing it. Vague prohibitions produce vague compliance.
5. Human review requirements. Define which outputs require review, by whom, and what evidence of review looks like. Only 48 percent of surveyed firms have formal human-in-the-loop procedures, and only 37 percent have policies for testing and validating AI outputs. Examiners are asking about both.
6. Vendor diligence and data terms. For each tool: where the data is stored, how long it is retained, whether it trains models on your inputs, what security attestations exist, and what the breach notification clause says. Only 30 percent of firms have a policy addressing third-party AI use. This section is also how your AI program stays consistent with Reg S-P instead of quietly contradicting it.
7. Training and attestation. The SEC named training explicitly. Document what you taught, when, to whom, and get an annual attestation. A training record with dates and names is one of the cheapest artifacts to produce and one of the most persuasive in an exam.
8. Logging, testing, and disclosure. Keep records of AI use in client-facing work, test the controls during your annual 206(4)-7 review, and reconcile your Form ADV and marketing language against what the tools do. If the website says proprietary AI, someone should be able to point to it.
If you want an external framework to anchor the policy, the NIST AI Risk Management Framework (AI 100-1) and its Generative AI Profile (AI 600-1) map cleanly onto these sections and cost nothing.
What Examiners Ask For That Firms Cannot Produce
Four requests come up repeatedly: the written acceptable use policy, vendor evaluation documentation for every third-party AI tool, evidence that AI-assisted recommendations received human supervisory review before reaching clients, and staff training records with completion dates.
Firms are moving. Eighty-five percent named AI their top compliance priority for 2026, up 28 points in a single year, and 86 percent report having an acceptable use policy and a tool inventory. The gap sits downstream, in review procedures, output testing, and vendor policy, where the numbers fall to 48, 37, and 30 percent. Having a policy and having a policy that answers the four requests above are separate accomplishments.
Why This Lands Differently in DFW
North Texas is absorbing a lot of new financial firms at once. The New York Stock Exchange announced in February 2025 that it would move its fully electronic Chicago exchange to Dallas, and Texas already carries the largest number of NYSE listings of any state at $3.7 trillion in market value. Nationally, the RIA count set a record at 16,544 firms after 674 new registrations in a single year.
A firm in year two has a compliance manual assembled from a template, a founder doing three jobs, and a staff that discovered Copilot on its own. That is the profile the AI governance section was written for. Our IT readiness playbook for Texas wealth management firms covers the surrounding infrastructure, and why a fractional vCISO is the right first security hire for a growing RIA covers who owns this work when nobody has the title yet.
Start With the Inventory
Do not start with the policy document. Start with the list of tools your firm is already using, including the ones nobody approved. Every other section depends on that list being honest.
Techvera builds AI governance programs for financial services firms through Managed AI, Compliance Readiness, and vCIO Services, covering the tool inventory, the vendor diligence file, and the training records examiners ask for. For more context on the exam cycle, read what the SEC's 2026 examination priorities mean for your RIA's IT program and the AI risk question every RIA CCO will face in 2026.
Feeling overwhelmed and not sure where to start? Let’s chat.
Frequently Asked Questions About RIA AI Governance Policy
Does the SEC require RIAs to have a written AI governance policy?
There is no AI-specific SEC rule requiring one. The obligation comes from Advisers Act Rule 206(4)-7, which requires written policies and procedures reasonably designed to prevent violations of the Advisers Act, reviewed annually. Once AI touches investment decisions, client communications, or required records, examiners expect written policies covering it. The SEC's 2026 examination priorities name AI training and security controls as a review area, so exam-stage document requests for an AI policy are now routine even though no standalone rule exists.
What should an RIA AI governance policy include?
Eight components: a definition of what counts as AI at the firm, an inventory of approved tools, a named approval authority for new tools, explicit lists of permitted and prohibited uses, human review requirements for AI outputs that reach clients, vendor diligence and data handling terms for every AI provider, documented staff training with attestations, and logging plus annual testing tied to the Rule 206(4)-7 review. The policy should also reconcile with Form ADV and marketing language so that stated AI capabilities match actual practice.
Is an AI notetaker a Regulation S-P issue for an RIA?
Yes, if it processes or stores customer information. An AI transcription or notetaking tool that records client meetings is a service provider under the amended Regulation S-P, which required smaller advisers, meaning those with $1.5 billion or less in regulatory assets under management, to comply by June 3, 2026. The rule requires written policies for overseeing service providers, including a provision that the provider notify the adviser within 72 hours of unauthorized access to customer information, plus a written incident response program and customer notification within 30 days of a qualifying breach.
About the Author
Team Techvera
Techvera Team
Articles written collaboratively by the Techvera team, combining expertise across cybersecurity, managed services, and digital transformation.
