Five AI controls advisors should adopt before SEC exam

Advisors should require human review, tighten cybersecurity and vendor rules, disclose AI use to clients and name an AI governance lead before SEC exams.

Compliance consultants and industry experts are urging investment advisers to adopt five specific controls for artificial intelligence before facing Securities and Exchange Commission examinations: require human review of outputs, strengthen cybersecurity, tighten vendor agreements, disclose AI use to clients and designate a person or team to govern AI use.

Compliance teams are advised to write policies that require a human to review AI-generated results where accuracy, bias or client suitability are at issue. A survey of 411 investment-adviser compliance officers by ACA Group found 48% had a formal human-in-the-loop policy, leaving a majority without a documented requirement for human checks. Firms are being told to test AI tools sufficiently to have a reasonable expectation they do not produce misleading answers, biased conclusions or other errors.

Advisers should review cybersecurity controls to prevent client data from being exposed when entered into large language models or other AI systems. Regulation S-P remains a primary legal standard requiring advisers to protect private customer information; recent amendments require firms that suffer security breaches to notify affected clients within 30 days. Consultants advise firms to ensure notes, meeting transcripts and other client data cannot leak into public model versions or be accessed by other users.

Third-party vendors are a compliance focus. Fewer than one in three ACA Group respondents reported having policies that govern outside service providers’ use of AI. Firms are advised to revise contracts to specify whether vendors may use AI, how they must secure data and the required steps if a breach occurs. SEC rules treat third parties the same as advisers for breach notification and data protection purposes.

Firms should review marketing materials and client agreements to state when AI assists in client-facing work, such as drafting reports, summarizing meetings or aiding recommendations. Regulators expect transparency so clients can know when AI played a role and whether a human reviewed the results.

Advisers are also encouraged to name one person or a team responsible for AI governance and compliance. Centralized oversight is intended to ensure consistent policies on vendor use, data handling, documentation and testing of model outputs. Examiners are expected to request records showing where and how AI is used, how decisions are reached and how firms verified AI reliability.

There is no single SEC rule that governs advisers’ use of AI. The agency previously considered a rule focused on AI conflicts and later dropped the proposal. Existing regulations, including books-and-records requirements, raise questions about whether AI-generated meeting summaries or transcripts must be retained and for how long. The SEC’s examination priorities now list AI as a key area of focus, and examiners will assess whether firms’ AI practices meet fiduciary and other obligations.

Some firms are already taking cautious steps. Adam Spiegelman, founder of Spiegelman Wealth Management, pays for enterprise versions of AI tools to protect privacy, avoids entering sensitive client data into public models and checks AI summaries against original transcripts before using them in client communications. ACA Group found 12% of surveyed firms were using AI in external, client-facing ways, up from the prior year. Carlo di Florio, president of ACA Group, warned regulators expect firms to test AI systems and keep records of testing, governance decisions and how human reviewers are applied so firms can demonstrate compliance with existing rules.

Articles by this author