Why advisor AI governance is a controls-before-capability discipline
Most advisory firms adopted AI in the order the tools arrived: a notetaker, then a drafting assistant, then features their existing software added through release notes. Governance came after, if at all, as a policy describing what staff should do. Advisor AI governance reverses the order. The firm decides the controls first, approved systems, information scope, provider list, review and approval, retention, and sign-off, and then permits capability inside them. For a compliance officer, this is the structure that survives an examination question about how AI use is supervised. For a small firm, it is a one-page decision made once: what may touch client information, who checks it, and what gets written down.
What advisor AI governance is not
Advisor AI governance is not an AI policy document; a policy is one input, and a policy without a record is a promise without receipts. It is not vendor due diligence alone; diligence is a control applied to one system at one time. It is not a ban, and it is not blanket permission. It is the ongoing set of decisions and records that let a firm say, for any AI-assisted piece of client work, which system did it, with what information, under whose approval, and where the result went.
Where advisor AI governance touches regulation
No SEC rule requires an AI policy by that name. Rule 206(4)-7 (17 CFR 275.206(4)-7) requires written compliance policies reasonably designed to prevent violations of the Advisers Act, and an annual review; AI use that touches client communications, records, marketing, or customer information falls inside that program. Regulation S-P applies wherever an AI system or its model provider receives customer information; 17 CFR 248.30(d)(10) defines a service provider as any entity that receives, maintains, processes, or is permitted access to customer information through services provided to the adviser. The Marketing Rule applies to AI-drafted advertisements as to any other. Advisor AI governance is the firm's way of mapping those existing obligations onto systems that did not exist when the rules were written. Regulatory descriptions are U.S. federal and current as of September 2026.
How the term is used on this site
The FAQ describes the ValaisOS design intent as turning a firm's written AI policy into operating behavior. That is advisor AI governance expressed as software. The nine questions to send any AI vendor are the diligence control; the Dropbox two-factor article is the endpoint control; proposed until approved is the review control.
Related terms
Articles that use this term
- The Vendors Behind Your Vendor: What Nineteen Subprocessor Lists Do Not Name
- The Dropbox Breach Skipped Every Account With Two-Factor On
- Your Clients Won't Remember the Rebalance
- Nine Questions to Send Any AI Vendor Before You Sign
- A Policy Without a Record Is a Promise Without Receipts
- When the Firm Arrives With a Product
- What to say when a client asks what you think about AI
Questions
Does the SEC require an AI policy?
No SEC rule requires an AI policy by that name. Rule 206(4)-7 requires written compliance policies reasonably designed to prevent violations of the Advisers Act and an annual review; AI use that touches client communications, records, marketing, or customer information falls inside that program.
Is advisor AI governance just vendor due diligence?
No. Diligence is one control applied to one system at one time. Advisor AI governance is the ongoing set of decisions and records that let a firm say, for any AI-assisted piece of client work, which system did it, with what information, under whose approval, and where the result went.
Can a two-person firm do advisor AI governance?
Yes. It is a one-page decision made once: what may touch client information, who checks it, and what gets written down. Supervision, recordkeeping, and fiduciary obligations apply to a two-person RIA as fully as to a national firm.