Advisor Insights topic
Technology governance
Due diligence, privacy, security, and risk questions for advisory technology.
Most vendor security questionnaires are long, generic, and produce answers nobody reads. These nine questions are shorter and harder, because each one has an answer that would change whether you sign. They cover the breach-notification clock, where your client data physically goes, whether it trains a model, what you can export, whether the vendor's records satisfy your recordkeeping rule, and who carries the loss. Each question is paired with what a usable answer looks like.
August 12, 2026
The duty to notify clients after a vendor breach sits with the advisory firm, not the vendor. Of nineteen AI vendors serving wealth management whose public documents we reviewed, ten publish a notification deadline, and eight of those ten put it in a data processing agreement, the terms of service, or a subscription agreement rather than the privacy policy. Two name Regulation S-P. Three of the ten deadlines carry qualifiers that change what they mean. The article closes with nine questions a firm can send any vendor.
August 12, 2026
An AI policy states what the firm intends. Exams, arbitrations, and client disputes are settled by evidence of what actually happened. AI work leaves no record unless the workflow is designed to produce one, so the gap between a firm's policy and its receipts is wider than most firms realize.
August 5, 2026