SEC examiners are already asking RIAs to produce their AI policies, their AI vendor due diligence files, and evidence that a human reviewed AI-generated output before it touched a client. If your firm uses AI anywhere — even one advisor pasting client questions into a chatbot — you should assume the question is coming, and "we're still figuring it out" is not an answer that survives an exam. SEC AI governance for RIAs is not a future problem tied to some pending rule. It's a current-exam problem tied to your existing compliance program.
Here's the uncomfortable reframe: the SEC does not need a new AI rule to examine your AI use. Most CCOs are waiting for AI-specific rulemaking before they build an AI governance program. Examiners aren't waiting. They're applying rules that have existed for decades — Rule 206(4)-7, the Marketing Rule, fiduciary duty, books-and-records — to a technology your advisors adopted last quarter.
That gap is the risk. Not the AI itself. The absence of documented governance around it.
The Division of Examinations made that explicit in its Fiscal Year 2026 Examination Priorities, released November 17, 2025 — the first under Chairman Paul Atkins — which name artificial intelligence as a focus area and state that examiners will assess advisers' policies for monitoring the use of AI technologies, including AI used for fraud prevention and detection, back-office operations, anti-money laundering, and trading functions. And the enforcement precedent already exists: in March 2024, the SEC charged two investment advisers, Delphia and Global Predictions, for making false and misleading statements about their use of artificial intelligence — announced in SEC press release 2024-36, with $400,000 in combined penalties. Notably, both firms were also charged under Rule 206(4)-7 itself, for failing to implement policies reasonably designed to prevent the violations. The SEC's first AI enforcement cases were, in part, compliance-program cases.
AI governance for an RIA is the documented framework of policies, approvals, supervision, and recordkeeping that controls how the firm and its personnel use artificial intelligence tools — covering which tools are approved, who may use them for what, how output is reviewed before it reaches clients or filings, and how all of it is evidenced for examiners.
Notice what that definition is really describing: a supervision problem, not a technology problem. Rule 206(4)-7 requires every registered investment adviser to adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act, and to review their adequacy annually — the rule's text is on SEC.gov. If AI now touches your advice, your marketing, your operations, or your client data, then your 206(4)-7 program has to cover it. Full stop.
Examiners are asking for artifacts — documents you can hand over — not philosophies. The pattern was set by the SEC's AI sweep of investment advisers that began in late 2023, and it now runs through the FY2026 priorities' focus on how firms monitor AI across fraud detection, back-office operations, AML, and trading. The questions cluster into six areas:
1. Inventory. "Provide a list of all AI tools used by the firm and its personnel, including use cases." If you can't produce an inventory, the exam starts from the assumption that you don't know what your people are doing. That's a supervision finding waiting to happen.
2. Policies. "Provide the firm's policies and procedures regarding the use of artificial intelligence." A generic technology policy from 2019 doesn't cover generative AI. Examiners want to see that your written program contemplates the tools your firm actually uses.
3. Marketing claims. "Provide all marketing materials referencing AI, and the substantiation for each claim." This is the AI-washing lane — the Delphia and Global Predictions cases were Marketing Rule and antifraud cases at their core. If your website says "AI-powered," you need to be able to show exactly what that means.
4. Vendor due diligence. "Describe the firm's due diligence and ongoing oversight of third-party AI vendors." What data does the vendor see? Where is it stored? Does the vendor train models on your client data? Who reviewed the contract, and when?
5. Human oversight. "Describe how AI-generated output is reviewed before use." Examiners want to see the human-in-the-loop, and they want to see it documented — not asserted.
6. Client data protection. "Describe controls preventing nonpublic client information from being entered into unapproved AI tools." This is where AI governance intersects Regulation S-P, and where most firms have their biggest blind spot.
Because the cost of a weak answer compounds. A single deficiency in AI oversight rarely stays a single deficiency.
Consider the chain. An advisor uses an unapproved AI tool to draft a client email — that's a supervision gap under 206(4)-7. The email included portfolio recommendations — now there's a question about whether the advice process was supervised. The tool retained the client's holdings data — now it's a Regulation S-P question. The firm's website meanwhile claims "rigorous AI oversight" — now it's a Marketing Rule question. One casual workflow, four exam findings.
There's also the cost nobody budgets for: exam response time. Firms that can't produce AI documentation quickly end up in extended exams, follow-up request lists, and remediation commitments. For a small compliance team, that's weeks of work that displaces everything else on the calendar. CCOs describe the feeling precisely: "I'm one exam away from a problem."
It looks boring, documented, and proportionate. You do not need a 60-page framework. You need five things that exist in writing and generate evidence as they operate:
| Component | What it is | What the examiner sees |
|---|---|---|
| AI inventory | Living list of approved tools and use cases | You know what's in use |
| Acceptable-use policy | What personnel may and may not do with AI, including client data rules | Your program contemplates AI |
| Approval workflow | How a new AI tool gets vetted and approved | Vendor due diligence exists |
| Review & documentation standard | Who reviews AI output, when, and how it's logged | Human oversight is real, not asserted |
| Annual review integration | AI risks assessed in your 206(4)-7 annual review | Governance is ongoing, not one-time |
One more distinction pays off in exams: classify your AI by function. Generative assistants that draft text, extraction models that read documents, analytics that score or rank portfolios, and AI features embedded inside vendor software each carry different data flows, different failure modes, and different review requirements. A single "AI policy" that treats a chatbot and a document-extraction pipeline identically reads as boilerplate; a shorter policy that distinguishes them reads as governance.
Two principles matter more than any template. First, the program has to match reality — a policy that bans tools your advisors demonstrably use is worse than no policy, because it proves the supervision failure. Second, the program has to generate its own evidence. If demonstrating oversight requires reconstructing what happened from memory and email threads, you don't have oversight; you have a story.
This is where the tooling question becomes unavoidable. A governance program run on spreadsheets and good intentions produces no audit trail. StratiFi's ComplianceIQ was built on the opposite premise: supervision activity — reviews, exceptions, approvals, resolutions — creates an audit trail automatically, as a byproduct of the work rather than a separate documentation chore. When the exam request asks you to "describe how AI-generated output is reviewed," the answer is a report, not a scramble. And because ComplianceIQ sits downstream of AdvisorIQ and OperationsIQ in one data flow, the oversight evidence lives in the same system as the activity it supervises — which is exactly the connectedness examiners probe for when they ask how compliance actually sees what advisors do.
The clearest precedent remains the March 2024 AI-washing cases. The SEC charged Delphia (USA) Inc. and Global Predictions Inc. with making false and misleading statements about their purported use of AI, resulting in $400,000 in combined civil penalties, per SEC press release 2024-36. The lesson generalizes: the SEC treated AI claims as it treats performance claims — say it, prove it, or pay for it.
Beyond enforcement, the Division of Examinations has now flagged AI across consecutive priority cycles, and the FY2026 priorities go furthest: examiners will assess advisers' policies for monitoring AI technologies across use cases from trading to back-office automation, alongside the training and security controls firms use to identify and mitigate new AI-related risks. The through-line is supervision of the technology, not the technology itself. For a full breakdown of the current cycle, see our analysis of the SEC's 2026 exam priorities, and for the supervision architecture underneath all of this, the RIA Portfolio Supervision Rulebook covers the 206(4)-7 obligations in depth.
No. As of mid-2026, there is no adopted SEC rule specific to advisers' use of AI. Examiners instead apply existing obligations — Rule 206(4)-7 compliance programs, the Marketing Rule, fiduciary duty, and books-and-records requirements — to AI use. That means AI governance is already required in substance, even without an AI-specific rule.
What documents should an RIA prepare for AI questions in an exam?At minimum: an inventory of AI tools in use, a written AI acceptable-use policy, vendor due diligence files for AI providers, samples of documented human review of AI output, and evidence that AI risk was covered in the most recent annual compliance review.
Is it enough to ban AI tools at the firm?No. A ban is a policy, and policies require enforcement evidence. If personnel use AI tools despite the ban — which is common — the ban becomes proof of a supervision gap rather than protection. A realistic approved-tools approach with monitoring is more defensible than an unenforced prohibition.
Does using AI change an adviser's fiduciary duty?No. The fiduciary duty is unchanged: advice must be in the client's best interest regardless of how it was produced. An adviser cannot attribute an unsuitable recommendation to a tool. Responsibility for AI-assisted output stays with the adviser and the firm.
How often should an RIA review its AI governance program?At least annually, as part of the Rule 206(4)-7 annual review, and additionally whenever the firm adopts a new AI tool or materially changes how an existing one is used.
If you'd rather walk into your next exam with the AI oversight evidence already assembled — reviews logged, exceptions documented, audit trail generated automatically — book a demo and we'll show you how ComplianceIQ makes AI governance something your firm can prove, not just describe.