An AI Use Policy for RIAs
The full policy structure is on this page, in text, free to adapt. It is written against the control areas the 2026 compliance survey found least covered — starting with the 70% of firms that have no policy for third-party AI.
Why this policy exists
Most advisers have adopted AI faster than they have governed it, and the least-covered control is the one covering AI a firm did not choose to buy. In the 2026 Investment Management Compliance Testing Survey reported by InvestmentNews, 80% of firms had formally adopted AI tools while 30% had policies addressing third-party AI use.
A policy is also the first artefact an examiner asks for. Per Goodwin's summary of the SEC's 2026 priorities, examiners will test the policies and procedures firms have for supervising AI. An absent policy is not a neutral state.
Section 1 · Scope and inventory
The policy covers every system that generates, summarises, classifies or recommends using a model — including AI features inside tools adopted for another purpose.
Maintain a written inventory with, for each entry: the tool, the business purpose, the categories of client data it can access, the vendor, whether outputs reach clients, and the date of last review. The inventory is the document that makes the rest of the policy enforceable; without it, every other section applies to an undefined set.
A practical test for completeness: walk the firm's existing vendor list and ask, for each, whether that vendor shipped an AI feature in the last two years. The inventory that results is usually longer than the one built by asking staff what AI they use.
Section 2 · Permitted and prohibited use
State which data categories may be entered into which tools, and name the prohibited uses explicitly.
Recommended prohibitions to state in writing: entering client personally identifiable information into a consumer AI product not on the inventory; relying on AI output as the sole basis for a recommendation without documented human review; using AI to generate client-facing marketing claims about the firm's own AI capability without compliance review.
That last one is unusual in template policies and belongs in this one. The SEC's AI washing priority makes the firm's own marketing an examinable surface.
Section 3 · Human review before client delivery
No AI-generated output reaches a client without a named human reviewing it, and the review must leave a trace.
Only 37% of surveyed firms had procedures to test or validate AI outputs before client delivery, and 48% had human-in-the-loop oversight policies. The gap between a policy that says a human reviews and a record showing a named human did review is the gap an examination tests.
Specify: who may review, what they are attesting to, how the attestation is recorded, and what happens when the reviewer disagrees with the output.
Section 4 · Records and retention
Treat AI-generated transcripts, summaries and drafts as records unless a documented analysis says otherwise.
Cooley's analysis of Rule 204-2 concludes that the rule's definition of a record captures AI-generated transcripts whether firms realise it or not. A policy that stays silent on retention is making a retention decision by default, and it is the decision hardest to defend.
Address: what is retained, for how long, where, in what format, and how it is produced on request.
Section 5 · Model version and prompt logging
Record which model version produced which output, and when.
The FINRA 2026 Annual Regulatory Oversight Report describes storing prompt and output logs for accountability and troubleshooting, and tracking which model version was used and when. Most firms cannot do this today because most vendors do not expose it. Where a vendor cannot supply model version metadata, record that limitation in the inventory rather than leaving the field blank — an examiner reading a blank cannot distinguish an unasked question from an unanswerable one.
Section 6 · Vendor diligence
Before adoption and annually after, test whether the vendor can meet the recordkeeping obligations the firm carries.
The FINRA report describes simulated regulatory examinations as the mechanism for testing third-party vendors against Rules 17a-3 and 17a-4. A fuller question set is set out in our note on third-party AI vendor due diligence.
Section 7 · Incident response
Define what counts as an AI incident and who is called.
14% of surveyed firms had incident response plans updated for AI — the lowest-covered control measured. AI incidents do not look like security incidents: a model that produces a confidently wrong figure in a client summary is an incident with no breach, no alert and no log entry unless the firm has defined one.
Name the triggers: material factual error in client-facing output, client data entered into a non-approved tool, vendor model change without notice, output that cannot be reproduced.
Section 8 · Review cadence
Review the inventory quarterly and the policy annually, and record the date. Vendor AI features ship faster than annual policy cycles. A quarterly inventory review is the minimum that keeps Section 1 true.
Common questions
What should an RIA's AI use policy cover?
At minimum: an inventory of approved tools including AI embedded in existing vendors, rules for what client data may be entered, a human review requirement before AI output reaches a client, output validation procedures, retention treatment for AI-generated records, model version and prompt logging, vendor diligence, and an incident response path for AI-specific failures.
Do we need a policy for AI inside tools we already use?
That is the largest gap in the market. Only 30% of firms have policies addressing third-party AI use while 80% have adopted AI tools. AI switched on inside an existing CRM or meeting platform is third-party AI use, and it is usually the AI a firm has never formally reviewed.
Sources
- InvestmentNews — AI compliance testing surges as SEC steps up scrutiny of advisers
- NAPA — AI emerges as top compliance priority among RIA firms
- FINRA 2026 Annual Regulatory Oversight Report
- Goodwin — SEC 2026 Examination Priorities for Registered Investment Advisers
- Cooley — AI Notetakers and the Books and Records Rule
This page is published for information. It is not legal advice, and it does not establish an adviser-client or attorney-client relationship. Regulatory obligations turn on a firm's own facts — take any question that matters to your compliance counsel. Where a claim here comes from a secondary analysis rather than a regulator's own words, we have said so in the text.