Technology governance

A Policy Without a Record Is a Promise Without Receipts

An AI policy states what the firm intends. Exams, arbitrations, and client disputes are settled by evidence of what actually happened. AI work leaves no record unless the workflow is designed to produce one, so the gap between a firm's policy and its receipts is wider than most firms realize.

Advisory firms are writing AI policies right now, many for the first time, some frankly from templates. That instinct is correct. Jon Cook's recent Advisor Perspectives piece describes compliance officers at large RIAs fielding exam findings about their technology and searching for somewhere to start, and his advice to start with a working policy is sound. The SEC's Fiscal Year 2026 examination priorities put the question squarely in scope: the Division of Examinations says it will assess whether firms have implemented adequate policies and procedures to monitor and supervise their use of AI technologies, and will review registrant representations about AI for accuracy.

But there is a phrase inside those priorities that deserves more attention than the AI language does. In describing how it evaluates compliance programs generally, the Division says examinations focus on whether policies and procedures are implemented and enforced. Not written. Not adopted. Implemented and enforced.

That distinction is the whole subject of this article. The first request in an exam is the policy. The second request is never the policy. It is some version of show me.

What a receipt is

A receipt has three properties that make it trustworthy. It is produced at the moment of the transaction, it is produced by the system that executed the transaction, and it exists whether or not anyone expected to need it. A record written later, from memory, in response to a request, has none of those properties. It is a reconstruction, and everyone evaluating it knows it is a reconstruction.

The compliance architecture of an advisory firm already runs on receipts, and has for decades. The email archive captures the message when it is sent. The order ticket exists because the trade could not happen without it. The custodian's statement is generated by the system that holds the assets. Rule 204-2's books and records requirements work in practice because the ordinary operation of the firm produces most of the required records as a byproduct. The record and the work come from the same act.

This is worth stating plainly because it explains something firms feel but rarely name: compliance evidence has historically been cheap, because the systems that did the work created it automatically. Nobody wrote down their trades from memory at year end.

AI work does not leave receipts on its own

Now consider where AI-assisted work actually happens. A conversation window. A draft that gets regenerated four times, each version overwriting the last. A prompt that an associate quietly improves on a Tuesday because the output got better, which means the firm's de facto procedure changed with no review and no record that it changed. An output that, once pasted into an email or a plan document, is indistinguishable from work a human did unaided.

None of that produces a receipt. The tools were not built to. Most of them are conversational by design, and conversation is the least self-documenting form of work ever invented.

So a gap opens that did not exist before. The policy can be excellent. The daily work can even comply with it. And the firm can still be unable to demonstrate either fact, because the layer where AI work happens generates no contemporaneous evidence unless someone deliberately designed it to. The policy operates on trust in exactly the place where the exam will ask for proof.

This is also why the annual review required by Rule 206(4)-7 gets harder in an AI-assisted firm, not easier. The rule asks advisers to review the adequacy and effectiveness of their policies and procedures. Effectiveness is an evidence question. A review of an AI policy with no underlying record can evaluate the prose, and nothing else.

What the receipt for AI-assisted work contains

For any consequential AI-assisted work product, a usable record answers a short list of questions. Which tool, and was it firm-approved. What client information went in. What came out. What the human changed. Who approved it going out the door. And which version of the firm's policy and prompts applied at the time.

The properties matter as much as the contents. The record has to be contemporaneous, created when the work happened. Attributable, tied to a person. Durable, surviving the tool, the chat session, and the employee. And retrievable, findable by someone other than the person who created it, years later.

Three tests

A firm can measure the distance between its policy and its receipts in an afternoon.

The sample test. Pick one AI-assisted client deliverable from last month, at random, and try to produce its full record within fifteen minutes: inputs, tool, human review, approval. If the answer is a shrug or an archaeology project, the policy is operating on trust.

The rule test. Pick one concrete rule from the policy, for example that client information goes only into approved systems. Ask what evidence exists that this rule was followed last week. Not whether anyone believes it was followed. What evidence.

The departure test. Imagine the firm's most AI-fluent advisor resigns tomorrow. Does the record of how their AI-assisted work was produced, reviewed, and approved survive them, or did it live in their chat history and their head?

Firms that pass all three are rare, and the ones that do share a trait: they stopped treating the record as documentation to be written and started treating it as an output the workflow produces, the way the order ticket is an output of trading.

Proportion, and an honest caveat

Not everything needs a receipt. A model brainstorming blog topics is not a compliance event, and a firm that tries to log everything will drown in its own evidence while the consequential records get lost in the noise. The record should scale with the consequence of the work, and deciding where that line sits is a judgment each firm makes in light of its own registrations, obligations, and counsel. Nothing here is individualized compliance advice, and the exam priorities themselves are staff views rather than rules.

The policy still matters, and this article is not an argument against writing one. The policy is what defines what the receipts should show. But the order of operations most firms are following right now, which is write the policy this quarter and think about evidence when someone asks, has the risk exactly backwards. The moment someone asks is the moment reconstruction stops being credible.

The policy is the promise. The record is the receipt. Exams, arbitrations, and client disputes are settled by receipts, and the firms that will be comfortable in that conversation are the ones whose daily work leaves them behind as a matter of course. That was true of trading thirty years ago. It is about to be true of everything.

Advisor Insights provides general professional information, not individualized investment, legal, or compliance advice. Supervision, records, and compliance conclusions are specific to each firm, its registrations, and its approved systems. Regulatory references are U.S. and current as of August 2026; the SEC examination priorities cited are Division of Examinations staff views, not Commission rules.

Primary sources

ValaisOS is building a more enduring operating foundation for private-wealth professionals.

Request early access