Advisor Insights topic

Technology governance

Due diligence, privacy, security, and risk questions for advisory technology.

Nine Questions to Send Any AI Vendor Before You Sign

Most vendor security questionnaires are long, generic, and produce answers nobody reads. These nine questions are shorter and harder, because each one has an answer that would change whether you sign. They cover the breach-notification clock, where your client data physically goes, whether it trains a model, what you can export, whether the vendor's records satisfy your recordkeeping rule, and who carries the loss. Each question is paired with what a usable answer looks like.

If Your AI Vendor Is Breached, You Have Thirty Days to Tell Your Clients

The duty to notify clients after a vendor breach sits with the advisory firm, not the vendor. Of nineteen AI vendors serving wealth management whose public documents we reviewed, ten publish a notification deadline, and eight of those ten put it in a data processing agreement, the terms of service, or a subscription agreement rather than the privacy policy. Two name Regulation S-P. Three of the ten deadlines carry qualifiers that change what they mean. The article closes with nine questions a firm can send any vendor.

A Policy Without a Record Is a Promise Without Receipts

An AI policy states what the firm intends. Exams, arbitrations, and client disputes are settled by evidence of what actually happened. AI work leaves no record unless the workflow is designed to produce one, so the gap between a firm's policy and its receipts is wider than most firms realize.