ValaisOS tool · runs in your browser

AI use policy builder

How do I write an AI use policy for my advisory firm that maps to the rules an examiner will cite?

An advisory firm's AI policy has to do three things an examiner will look for: say which systems and uses are approved, say how client information is handled and how output is reviewed, and produce a record that shows the policy is implemented and enforced. This page turns ten answers about the firm's actual practice into a policy draft with those parts, each section carrying the rule it answers to: Rule 206(4)-7 for the compliance program and annual review, Rule 204-2 for the records, and Regulation S-P for the vendors that receive client information. The draft is built in your browser and can be copied or printed; nothing you enter is stored or sent.

Key facts

  • Advisers Act Rule 206(4)-7 requires an SEC-registered adviser to adopt written policies and procedures reasonably designed to prevent violations of the Act, to review them at least annually, and to designate a chief compliance officer; it does not name AI, and it does not need to.
  • The SEC Division of Examinations' fiscal year 2026 priorities say examiners will assess whether firms have policies and procedures to monitor and supervise their use of AI, and evaluate compliance programs on whether policies are implemented and enforced.
  • Rule 204-2(a)(7) makes a sent communication relating to advice a required record whoever drafted it, and Rule 204-2(a)(17) requires a copy of the compliance policies and the records documenting each annual review.
  • Any AI vendor that receives client information is a Regulation S-P service provider for an SEC-registered adviser (17 CFR 248.30(d)(10)), owed due diligence, monitoring, and a 72-hour breach-notification standard; for a state-registered adviser the FTC Safeguards Rule (16 CFR 314.4(f)) requires contractual oversight of the same vendors.

Describe how the firm uses AI

Ten questions. The draft rewrites itself as you answer. Everything happens in your browser; nothing is stored or sent.

Optional. Leave blank for "the Firm".

Sets the rule references in the records and vendor sections.

2. Which uses of AI does the firm permit?
3. May client information be entered into AI systems?
5. Is human review required before AI-assisted output reaches a client?
6. What does the firm keep for AI-assisted client work?
7. Do the AI vendors that receive client information have written 72-hour breach-notification commitments on file?
8. Do personnel acknowledge the policy in writing?
9. How often is the policy reviewed?
10. May personnel use personal AI accounts for firm work?

The draft

What to do with the draft

  • Read it against what the firm actually does. A policy that describes a review step nobody performs is worse than no policy, because it documents a control that the record will show was not applied.
  • Have counsel and the compliance lead review the rule references for the firm's registration and state. The draft cites federal rules as of September 2026 and does not cover state-specific requirements.
  • Adopt it as part of the compliance manual, date it, and keep the adopted copy; for an SEC-registered adviser Rule 204-2(a)(17)(i) requires a copy of the policies in effect at any time in the last five years.
  • Put the review cadence on the calendar and keep the record of each review; Rule 204-2(a)(17)(ii) requires the records documenting the annual review.
  • Use the service-provider inventory to sort the vendors the vendor section refers to, and the diligence letter to obtain the commitments it assumes.

Questions

Does an SEC-registered adviser have to have an AI policy?

Rule 206(4)-7 requires written policies and procedures reasonably designed to prevent violations of the Advisers Act, reviewed at least annually. It does not name AI. The SEC Division of Examinations' fiscal year 2026 priorities say examiners will assess whether firms have policies and procedures to monitor and supervise their use of AI, so a firm that uses AI in client work needs its policies to cover it.

What makes an AI policy defensible in an exam?

Evidence that it is implemented and enforced. A policy that names approved systems, requires human review before AI-assisted output reaches a client, keeps the sent version and the review record, and is checked at the annual review can be demonstrated. A policy that only states intentions cannot.

Does this page store my answers or the draft?

No. The answers are used only in your browser to assemble the text. Nothing is transmitted, saved, or measured. Copy or print the draft before leaving the page.

Does the draft cover a state-registered adviser?

Yes, with different rule references. Choose the state-registered option and the vendor and records sections cite the FTC Safeguards Rule and state recordkeeping rules instead of Regulation S-P and Rule 204-2. Confirm the state's own requirements with counsel.

Primary sources

General information from ValaisOS LLC, not legal, compliance, tax, or investment advice. Confirm requirements for your firm with counsel. See Terms of Use.

ValaisOS is building a more enduring operating foundation for private-wealth professionals.

Request early access