Key facts
- Advisers Act Rule 206(4)-7 requires an SEC-registered adviser to adopt written policies and procedures reasonably designed to prevent violations of the Act, to review them at least annually, and to designate a chief compliance officer; it does not name AI, and it does not need to.
- The SEC Division of Examinations' fiscal year 2026 priorities say examiners will assess whether firms have policies and procedures to monitor and supervise their use of AI, and evaluate compliance programs on whether policies are implemented and enforced.
- Rule 204-2(a)(7) makes a sent communication relating to advice a required record whoever drafted it, and Rule 204-2(a)(17) requires a copy of the compliance policies and the records documenting each annual review.
- Any AI vendor that receives client information is a Regulation S-P service provider for an SEC-registered adviser (17 CFR 248.30(d)(10)), owed due diligence, monitoring, and a 72-hour breach-notification standard; for a state-registered adviser the FTC Safeguards Rule (16 CFR 314.4(f)) requires contractual oversight of the same vendors.
Describe how the firm uses AI
Ten questions. The draft rewrites itself as you answer. Everything happens in your browser; nothing is stored or sent.
The draft
What to do with the draft
- Read it against what the firm actually does. A policy that describes a review step nobody performs is worse than no policy, because it documents a control that the record will show was not applied.
- Have counsel and the compliance lead review the rule references for the firm's registration and state. The draft cites federal rules as of September 2026 and does not cover state-specific requirements.
- Adopt it as part of the compliance manual, date it, and keep the adopted copy; for an SEC-registered adviser Rule 204-2(a)(17)(i) requires a copy of the policies in effect at any time in the last five years.
- Put the review cadence on the calendar and keep the record of each review; Rule 204-2(a)(17)(ii) requires the records documenting the annual review.
- Use the service-provider inventory to sort the vendors the vendor section refers to, and the diligence letter to obtain the commitments it assumes.
Questions
Does an SEC-registered adviser have to have an AI policy?
Rule 206(4)-7 requires written policies and procedures reasonably designed to prevent violations of the Advisers Act, reviewed at least annually. It does not name AI. The SEC Division of Examinations' fiscal year 2026 priorities say examiners will assess whether firms have policies and procedures to monitor and supervise their use of AI, so a firm that uses AI in client work needs its policies to cover it.
What makes an AI policy defensible in an exam?
Evidence that it is implemented and enforced. A policy that names approved systems, requires human review before AI-assisted output reaches a client, keeps the sent version and the review record, and is checked at the annual review can be demonstrated. A policy that only states intentions cannot.
Does this page store my answers or the draft?
No. The answers are used only in your browser to assemble the text. Nothing is transmitted, saved, or measured. Copy or print the draft before leaving the page.
Does the draft cover a state-registered adviser?
Yes, with different rule references. Choose the state-registered option and the vendor and records sections cite the FTC Safeguards Rule and state recordkeeping rules instead of Regulation S-P and Rule 204-2. Confirm the state's own requirements with counsel.
Primary sources
General information from ValaisOS LLC, not legal, compliance, tax, or investment advice. Confirm requirements for your firm with counsel. See Terms of Use.