ValaisOS publication

Advisor Insights

Practical guidance for financial advisors on responsible AI, firm-governed workflows, knowledge continuity, and technology stewardship.

Technology governance

The Vendors Behind Your Vendor: What Nineteen Subprocessor Lists Do Not Name

Regulation S-P makes the advisory firm responsible for overseeing its service providers through due diligence and monitoring, but a firm cannot diligence a party it does not know exists. Of nineteen AI vendors serving financial advisors and RIAs whose public documents we reviewed, eight publish a subprocessor list we could read. Six name a model provider and two name a transcription provider. None names a vector store, the system holding a derived copy of client documents. The one vector database we found named is on Anthropic's own subprocessor list, filed under web search, and three of the nineteen vendors now appear as connectors in Claude for Financial Advisors.

Technology governance

The Plugin Is a First Draft. The Firm Is the Author.

Claude for Financial Advisors, released by Anthropic on September 14, 2026, is an openly licensed plugin of eight skills and a twelve-system connector list. The skills are Markdown instructions, the plugin holds no client data, and the repository's own README states that most of its guardrails, including advisor approval before any write to a client system, are enforced by the model following them rather than by the runtime. That makes the plugin a well-written first draft of a firm's AI operating procedures. The controls that hold on a bad day, the record of what happened, and where client documents go when a connector is missing are the firm's to write.

Technology governance

Your AI Approved Nothing. You Did. Where Is That Written Down?

Every AI product sold to advisory firms promises that a person approves the work before it counts. Claude for Financial Advisors gates its CRM writes behind a single batch confirmation, and its repository's design rules require a pause before anything leaves the session. The approval happens. The question a firm has to answer is where it was written down. Anthropic's Enterprise audit log records conversations, projects, and file uploads by identifier, and excludes chat content. The closest thing to a recorded approval event is Cowork telemetry an administrator has to configure. Until the firm makes approval an artifact in its own system, the evidence of review is a chat turn.

Technology governance

Which AI-Generated Work Product Is a Required Record Under Rule 204-2?

Rule 204-2 (17 CFR 275.204-2) does not mention AI. It lists categories of records an SEC-registered adviser must keep, and an AI-generated document falls into a category, or does not, on the same terms as a human-written one. A sent client email relating to advice is a required record whoever drafted it. An unsent draft usually is not. What AI changes is how much of the work now exists only as unsent drafts and vendor logs, and whether the firm can reconstruct what was sent from what it kept.

Technology governance

Is My Vendor a Regulation S-P Service Provider? The Test Is Whether Client Information Flows

Under Regulation S-P, a service provider is any entity that "receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a covered institution" (17 CFR 248.30(d)(10)). The test is whether records about clients flow to the vendor or are accessible by it, not what the vendor is called, how big it is, or whether it uses AI. Since June 3, 2026, every SEC-registered adviser owes each service provider due diligence, monitoring, and written policies reasonably designed to secure a 72-hour breach notification, and the firm keeps the duty to notify clients itself.

Technology governance

Regulation S-P Now Applies to Every SEC-Registered Adviser. Here Is What Changed for a Small Firm.

Yes, it applies to you. Since June 3, 2026, amended Regulation S-P (17 CFR 248.30) has applied to every SEC-registered investment adviser regardless of size. A firm must maintain written safeguards for customer information, run a written incident response program, notify affected individuals within 30 days of becoming aware of a breach of sensitive customer information, oversee service providers with due diligence and monitoring, and keep records of all of it under Rule 204-2(a)(25). This article walks the rule paragraph by paragraph and ends with what a small firm should do this quarter and what the file should contain.

Knowledge continuity

The Firm Remembers What It Can Reconstruct

Advisory work is starting to be done with a system in the middle of it. The finished note, email, or plan looks the same either way, and that is the problem. Institutional memory used to live in people who could be asked. When part of the work comes from a system, memory depends on three things captured at the time: what the system saw, what it produced, and what the person decided. A firm that keeps those can hand work forward. A firm that keeps only the finished artifact has a record it cannot retrace.

Knowledge continuity

The Transcript Remembers Everything and Weighs Nothing

An advisor's handwritten meeting note was never a recording. It was a judgment about what mattered, and that judgment was the firm's memory. Automated notes invert this: the record becomes complete and unweighted, and the note the advisor used to write is the note that quietly stops being written. The transcript is a gain. The substitution is a loss. Firms that keep a short judgment layer beside the automated record get both.

Technology governance

The Dropbox Breach Skipped Every Account With Two-Factor On

Between August 4 and August 21, 2026, an attacker used a defect in Lenovo's ID registration to sign into roughly 5,000 Dropbox accounts with no password and no access to the victim's inbox. Dropbox says every affected account had two-factor authentication off. For advisory firms that had it on, there was no letter, no investigation, and no Regulation S-P clock. The article explains why a password was irrelevant and a second factor was not, what that one setting spared firms under the amended rule, which second factor to use, and how to require it across every cloud tool that touches client files.

Advisor operations

When a Client Arrives With Questions From AI

The first wave was clients arriving with AI-generated answers. The new wave is clients arriving with AI-generated question lists for their advisor. The list is usually reasonable. The prompt that produced it tells you what the client is actually concerned about, and that is where the real meeting starts.

Advisor operations

A Surprise Tax Bill Is a Data Problem Wearing a Tax Costume

A surprise tax bill is almost never a knowledge failure, because every advisor involved knows what brackets do. It is a timing failure. The information existed in March, sat unnoticed in a payroll system or a brokerage feed through the summer, and arrived at the advisor's desk as an April emergency. The gap between where the data lives and where the judgment lives is what manufactures the surprise, and closing that gap is the least glamorous and most valuable work in an advisory practice.

Responsible AI

Your Clients Won't Remember the Rebalance

Nobody calls their advisor in tears about tax-loss harvesting. The moments that make an advisory practice are human, being the first call after the promotion, the sale, the birth, the loss, and no machine can replace them. The honest question about AI in an advisory practice is not whether it can replace those moments. It is what it clears out of the way so there is room for them. The firms getting this right are deliberately deciding which work deserves a human and which work deserves an audit trail.

Technology governance

Nine Questions to Send Any AI Vendor Before You Sign

Most vendor security questionnaires are long, generic, and produce answers nobody reads. These nine questions are shorter and harder, because each one has an answer that would change whether you sign. They cover the breach-notification clock, where your client data physically goes, whether it trains a model, what you can export, whether the vendor's records satisfy your recordkeeping rule, and who carries the loss. Each question is paired with what a usable answer looks like.

Technology governance

If Your AI Vendor Is Breached, You Have Thirty Days to Tell Your Clients

The duty to notify clients after a vendor breach sits with the advisory firm, not the vendor. Of nineteen AI vendors serving wealth management whose public documents we reviewed, ten publish a notification deadline, and eight of those ten put it in a data processing agreement, the terms of service, or a subscription agreement rather than the privacy policy. Two name Regulation S-P. Three of the ten deadlines carry qualifiers that change what they mean. The article closes with nine questions a firm can send any vendor.

Responsible AI

The Engineer Signs the Drawings. Who Signs the Advice?

A production chain is only as strong as its weakest link, and automating most of a chain concentrates value and risk in whatever remains. In advisory work, what remains is judgment on one end and execution on the other. The overlooked part is the handoff between them, where a decision leaves the person who made it and enters the system that acts on it. Professions that automated safely, like structural engineering, survived because they had an artifact that made judgment attributable. Advisory work has no stamp, and that seam is where accountability is established or lost.

Technology governance

A Policy Without a Record Is a Promise Without Receipts

An AI policy states what the firm intends. Exams, arbitrations, and client disputes are settled by evidence of what actually happened. AI work leaves no record unless the workflow is designed to produce one, so the gap between a firm's policy and its receipts is wider than most firms realize.

Responsible AI

When the Firm Arrives With a Product

Personalized product outreach used to be expensive, and the expense was an accidental control. AI removes the cost but not the obligation. A generated reason a product fits a client is a hypothesis, not evidence of fit, and the firm now owns every tailored message it sends.

Advisor operations

When a Client Arrives With a Headline

When a client calls about a market headline, they are rarely asking what the market will do. They are asking whether the news applies to them. Headlines describe aggregates; clients live in particulars, and the advisor's work is translating one into the other with specifics: what you hold, what the plan assumed, what would change it. Morningstar and Vanguard research put a measurable cost on acting without that translation, and the firm's systems should already know which households a headline touches.

Advisor operations

The $140,000 Nobody Was Looking At

A client with strong income, maxed retirement accounts, and no debt had $140,000 sitting in a checking account for years, visible on every statement and seen by no one. Idle cash is a background condition of most books: as of July 2026 the FDIC's national average interest checking rate was 0.07%. Software is well suited to noticing across every account at once; deciding what the money is for remains human work, and the system that notices must be governed.

Responsible AI

What to say when a client asks what you think about AI

When a client asks what you think about AI, a credible answer does three things: acknowledges what the technology does well, names precisely what it cannot know, and connects that limit to the judgment and accountability an advisor provides. Dismissal and breathless enthusiasm both close the conversation. The article gives a version an advisor can say out loud, the research behind the limit, and the prerequisite: firsthand evaluation inside firm-approved systems.

Responsible AI

When a client arrives with an answer from AI

When a client brings an AI-generated financial conclusion into a meeting, the useful first move is to ask to see the prompt, because the answer depends on what the system was told and what it was never told. A 2026 working paper by Choukhmane, de Silva, Lin, and Akuzawa found AI financial guidance was often directionally sound yet leaned on round-number heuristics and varied with the inputs. The article gives five questions an advisor can ask and explains how to preserve the reasoning that follows.

Knowledge continuity

Your Firm Has More Client Information Than Client Context

Advisory firms rarely lack information. Account records, plans, CRM notes, and emails record what happened. What they often fail to preserve is why: what prompted a decision, what the client cared about, which alternatives were considered, and what remains open. Client context is that reasoning, and it is what lets another authorized professional continue the work without guessing. The article gives five warning signs, a continuity test, and four practical improvements.

Beyond the articles

Series to read in order, and tools that run in your browser.

Series

What the Documents Say

A recurring review of what AI vendors serving wealth management commit to in their public documents, one clause at a time, recorded by document and section.

Series

When a Client Arrives With...

Clients now walk into meetings with an AI answer, an AI question list, a headline, or a product pitch from the firm itself. Each piece works out what the advisor should do with it.

Tool

AI use policy builder

Ten answers about how your firm uses AI become a policy draft, each section mapped to Rule 206(4)-7, Rule 204-2, or Regulation S-P. Built in your browser; nothing is stored.

Tool

The reconstruction test

Take one piece of AI-assisted client work and answer nine questions about what your firm's record can show. A scored, printable read of the firm's memory, done in your browser.

Tool

Regulation S-P clock

Enter when your firm became aware of unauthorized access to client information and see the 72-hour and 30-day Regulation S-P deadlines, notice contents, and records to keep.

Tool

Service-provider inventory

List the systems that touch client information, answer three questions about each, and get a printable inventory that says which ones are Regulation S-P service providers and why.

Tool

Vendor diligence letter

Turn the nine questions to send any AI vendor into a letter addressed to your vendor, with the rule behind each question. Copy or print it. Nothing you type leaves your browser.

Editorial standard

Useful before promotional.

Every article is written for a professional audience, reviewed for claims and sources, and maintained as an updateable resource on ValaisOS.com. Read our editorial policy.