Digital brain circuit design over colorful pixel grid representing artificial intelligence and technology.

AI Governance for RIAs: What Wealth Managers Should Govern First

October 09, 2026

An advisor records a client meeting with an AI note-taker. Another pastes a portfolio summary into a chatbot to draft a quarterly letter. Someone in operations uses AI to clean up a spreadsheet of account numbers. Each one saves time. Each one moves client data somewhere your compliance program may not reach.

That's the core of AI governance for RIAs: making sure the speed AI brings doesn't outrun the obligations you already have for client data, vendors, and records. The industry is moving fast. The ACA Group and NSCP 2025 AI Benchmarking Survey found that 71% of firms now formally use AI, up 26 points in a year.

This guide is for principals and COOs at registered investment advisers and wealth management firms, including the many Chicago-area firms we talk to. It covers how advisors already use AI, what your policy should cover first, how AI controls fit your compliance work, what a safe pilot looks like, and who should own AI decisions. (This is general information. Your chief compliance officer or counsel should review your approach.)

How are advisors already using AI with client data?

Advisors are already using AI to summarize meetings, draft client letters and emails, prepare reviews, research investments, and clean up data. Many of those uses touch nonpublic personal information. The risk comes from personal accounts, note-takers, and browser add-ons that nobody reviewed before client data went into them.

Common uses we see:

· Meeting notes: AI note-takers that record and summarize client meetings

· Client communications: first drafts of letters, emails, and review summaries

· Research: summarizing fund documents, market commentary, and filings

· Operations: reformatting spreadsheets, reconciling data, and drafting procedures

Most of these are reasonable uses. The questions are which tools, which accounts, and what data. A meeting note-taker on a firm-approved platform with retention settings is very different from the same feature on an advisor's personal account. So is a client letter drafted with account details versus one drafted from a generic template. Governance starts by mapping these uses so you know where client data actually flows.

What should an RIA's AI policy cover first?

An RIA's AI policy should first cover which tools are approved, what client data can never go into unapproved tools, how AI-generated client communications are reviewed, how AI vendors are vetted, and how AI use is recorded and retained. Start with those 5 and add detail as your use grows.

Govern these first:

1. Approved tools. A short list of reviewed, business-grade tools. Ban personal and free accounts for any firm or client data.

2. Client data rules. Account numbers, Social Security numbers, balances, and other nonpublic personal information stay out of unapproved tools.

3. Review of client-facing output. A person reviews AI-drafted letters, emails, and summaries before they go out.

4. Vendor due diligence. Treat AI tools like any vendor with access to customer information. The ACA survey found only 24% of firms have policies governing third-party AI use, so this is a common gap.

5. Recordkeeping. Decide how AI-assisted communications and meeting notes are captured and retained, in line with your existing books-and-records obligations.

The same survey found that 70% of firms already have employee AI-use policies, but only 28% test or validate AI outputs. A policy is the start. Testing and supervision make it real.

How does AI governance for RIAs fit with existing compliance work?

AI controls fit into the compliance program you already run: written policies and procedures, safeguarding customer information, overseeing service providers, incident response, and recordkeeping. The work is applying your existing obligations to the AI tools and vendors your team uses.

Regulation S-P is the clearest example. According to Davis Wright Tremaine's summary, the SEC's amended Reg S-P applies to registered investment advisers. Larger firms had to comply by December 3, 2025, and smaller entities by June 3, 2026. The amendments require:

· A written incident response program for unauthorized access to customer information

· Notice to affected individuals within 30 days for incidents involving sensitive customer information

· Oversight of service providers with access to customer information, including procedures so vendors notify you within 72 hours of a breach

· Records documenting compliance

The SEC has also named Reg S-P compliance an exam priority for fiscal year 2026. An AI vendor that touches client data is a service provider, so it belongs in that oversight.

For Illinois-based firms, there's a state angle too. The Illinois Personal Information Protection Act says a contract that discloses Illinois residents' personal information must require the recipient to implement and maintain reasonable security measures.

Where your IT partner fits

Your compliance officer interprets the rules. Your IT partner builds and documents the technology controls. At Framework IT, your virtual Chief Information Officer (vCIO) works directly with your compliance officer to implement controls, provide documentation for audits, help with risk assessments and security questionnaires, and coordinate on incident response. We provide technology controls. Legal and regulatory interpretation stays with your compliance officer or counsel, which is why a strong compliance officer on your side matters.

What does a safe AI pilot look like in an advisory firm?

A safe AI pilot in an advisory firm uses one approved platform, a small trained group, and tasks that start without client data, like research summaries and internal drafts. Compliance reviews the outputs, records are retained, and client data comes in only after vendor diligence, permissions, and review steps are settled.

A practical sequence:

6. Approve one platform after due diligence. Look for security certifications, written "no training on your data" terms, access controls, and audit logs.

7. Train the pilot group. Our AI Champion Certification takes about 90 minutes.

8. Start internal. Research summaries, procedure drafts, and marketing copy that compliance reviews anyway.

9. Add client workflows carefully. Meeting summaries and letter drafts, with human review and retention in place.

10. Review results monthly. Partners in our Managed Framework AI adoption program meet with us monthly for an AI Strategic Business Review, and every Managed Framework AI partner gets the Framework AI Resources Hub from day one, including industry playbooks for financial services firms.

Managed Framework AI runs on an enterprise platform that's SOC 2 Type I, SOC 2 Type II, and SOC 3 certified. Client data is encrypted, isolated from other organizations, and never used to train AI models. Administrators control which roles can use which models and features, with full audit trails, and data processing agreements are available on request.

Who should own AI decisions at a small RIA?

At a small RIA, a principal or the COO should own AI decisions, the chief compliance officer should own the policy and supervision, and your IT partner should vet tools and run the technical controls. An AI champion on the advisory team helps colleagues use approved tools well and spots problems early.

A workable model:

· Principal or COO: sets risk tolerance and approves tools and budget

· Chief compliance officer: owns the AI policy, review procedures, and recordkeeping

· IT partner or vCIO: vets vendors' security, configures access, and documents controls

· AI champion: 1 advisor or operations lead who answers questions and shares what works

IT support for Chicago RIAs

Key Framework IT staff, including your vCIO, have direct RIA experience, and responsible AI guidance is part of every managed services engagement. We also commit to helping each partner identify at least 1 real-world AI use case. That work is backed by a local team: about 85% of our service delivery staff are in the Chicagoland area.

For the general version of this guide, see writing an AI policy for a small business. You can also learn about our AI services and how we support RIAs and wealth management firms in Chicago.

Frequently Asked Questions

Do RIAs need an AI policy?

There's no standalone AI rule for advisers, but existing obligations for safeguarding client information, supervising communications, overseeing vendors, and keeping records apply to AI tools. A written AI policy is the simplest way to show how you meet them.

Does Regulation S-P apply to AI vendors?

If an AI vendor receives or has access to customer information, it's a service provider for Reg S-P purposes, and the amended rule requires oversight through due diligence and monitoring. Your compliance officer should confirm how it applies to each tool.

Can advisors use AI note-takers in client meetings?

Many firms do, with guardrails: an approved tool, client notice or consent where required, human review of summaries, and retention that matches your recordkeeping obligations.

What AI uses are lowest risk for an RIA to start with?

Start with work that doesn't involve client data: summarizing public research, drafting internal procedures, and preparing marketing copy that compliance already reviews. Move to client-facing workflows once vendor diligence, review steps, and recordkeeping are in place.

Does FINRA apply to RIAs?

FINRA rules apply to broker-dealers. RIAs are generally regulated by the SEC or state securities regulators. Firms that are dually registered or affiliated with a broker-dealer may need to consider both.

The Bottom Line

Advisors will keep using AI because it saves real time. AI governance for RIAs makes sure that time savings don't come at the cost of client data, vendor oversight, or books and records.

We help Chicago-area advisory firms put the policy in place, secure the tools, and work alongside your compliance officer so the controls are documented and ready for an exam.

Book an AI readiness conversation to see what your firm should govern first.

Framework IT | 700 N. Sacramento Blvd., Suite 101, Chicago, IL 60612 | (312) 564-5446

About the Author

Adam Barney is President and Managing Partner of Framework IT, a premier managed IT and telecommunications firm based in Chicago. With more than 15 years of executive experience in managed services and telecommunications, Adam leads with a core philosophy that technology should be user-friendly and approachable, empowering businesses to thrive in their respective industries.

Since assuming the presidency in January 2020, Adam has led a team of over 40 professionals spanning sales, information technology, operations, marketing, human resources, and fulfillment. Under his leadership, Framework IT remains committed to its unique inverted-pyramid approach, which ensures clients' needs and aspirations are always the company's top priority.

Founded in 2008, Framework IT specializes in IT support, strategy, and cybersecurity for small and mid-sized businesses nationwide. The company's 30+ engineers act as an extension of client businesses, proactively preventing IT issues so teams have more time to focus on what truly matters. During his career, Adam has consulted over 1,000 companies, helping them transform and streamline their technology infrastructure.

In recent years, Adam has spearheaded the adoption of artificial intelligence in Framework's internal operations and service delivery, positioning the company at the forefront of AI-driven IT management. He has pioneered the launch of a new service offering to help clients implement AI and AI-based automation in their own businesses, enabling organizations to unlock new levels of efficiency and competitive advantage. Adam is also a founding member of The Forge AI Alliance of MSPs, an alliance of managed service providers working to accelerate the adoption of AI and automation in their own companies and those of their clients.

Under Adam's leadership, Framework IT has been named to the Inc. 500 Fastest Growing Private Companies in America twice and the Inc. 5000 list at least five times over the past decade. The company has been ranked one of the Best & Brightest Places to Work in Chicago for five consecutive years and one of the Best & Brightest Places to Work in the Nation twice in the last five years. Framework IT has maintained a BBB complaint-free record since 2008.

Adam's expertise has positioned him as a sought-after voice in managed services and business technology. His insights have been featured in the Harvard Business Review, the Washington Post, and Fox 32 Chicago. Adam has also served as a speaker and panelist at the Chicago Bar Association AI Symposium, sharing practical guidance on AI adoption with the legal community.

Adam holds a Bachelor of Science in Finance and Business Administration from the University of Illinois Urbana-Champaign, where he graduated Summa Cum Laude. He maintains numerous industry certifications, including ITIL Foundations and multiple AI and cybersecurity certifications.

Outside of work, Adam is a husband and father of two daughters, as well as an avid reader with interests spanning leadership, management, psychology, and technology.