An advisor records a client meeting with an AI note-taker.
Another pastes a portfolio summary into a chatbot to draft a quarterly letter.
Someone in operations uses AI to clean up a spreadsheet of account numbers.
Each one saves time. Each one moves client data somewhere your compliance
program may not reach.
That's the core of AI governance for RIAs: making sure the
speed AI brings doesn't outrun the obligations you already have for client
data, vendors, and records. The industry is moving fast. The ACA Group and NSCP 2025 AI Benchmarking Survey
found that 71% of firms now formally use AI, up 26 points in a year.
This guide is for principals and COOs at registered
investment advisers and wealth management firms, including the many
Chicago-area firms we talk to. It covers how advisors already use AI, what your
policy should cover first, how AI controls fit your compliance work, what a
safe pilot looks like, and who should own AI decisions. (This is general
information. Your chief compliance officer or counsel should review your
approach.)
How are advisors already using AI with client data?
Advisors are already using AI to summarize meetings, draft
client letters and emails, prepare reviews, research investments, and clean up
data. Many of those uses touch nonpublic personal information. The risk comes
from personal accounts, note-takers, and browser add-ons that nobody reviewed
before client data went into them.
Common uses we see:
·
Meeting
notes: AI note-takers that record and summarize client meetings
·
Client
communications: first drafts of letters, emails, and review summaries
·
Research:
summarizing fund documents, market commentary, and filings
·
Operations:
reformatting spreadsheets, reconciling data, and drafting procedures
Most of these are reasonable uses. The questions are which
tools, which accounts, and what data. A meeting note-taker on a firm-approved
platform with retention settings is very different from the same feature on an
advisor's personal account. So is a client letter drafted with account details
versus one drafted from a generic template. Governance starts by mapping these
uses so you know where client data actually flows.
What should an RIA's AI policy cover first?
An RIA's AI policy should first cover which tools are
approved, what client data can never go into unapproved tools, how AI-generated
client communications are reviewed, how AI vendors are vetted, and how AI use
is recorded and retained. Start with those 5 and add detail as your use grows.
Govern these first:
1. Approved tools. A short list of
reviewed, business-grade tools. Ban personal and free accounts for any firm or
client data.
2. Client data rules. Account numbers,
Social Security numbers, balances, and other nonpublic personal information
stay out of unapproved tools.
3. Review of client-facing output. A
person reviews AI-drafted letters, emails, and summaries before they go out.
4. Vendor due diligence. Treat AI tools
like any vendor with access to customer information. The ACA survey found only
24% of firms have policies governing third-party AI use, so this is a common
gap.
5. Recordkeeping. Decide how AI-assisted
communications and meeting notes are captured and retained, in line with your
existing books-and-records obligations.
The same survey found that 70% of firms already have
employee AI-use policies, but only 28% test or validate AI outputs. A policy is
the start. Testing and supervision make it real.
How does AI governance for RIAs fit with existing compliance work?
AI controls fit into the compliance program you already run:
written policies and procedures, safeguarding customer information, overseeing
service providers, incident response, and recordkeeping. The work is applying
your existing obligations to the AI tools and vendors your team uses.
Regulation S-P is the clearest example. According to Davis Wright Tremaine's summary, the SEC's
amended Reg S-P applies to registered investment advisers. Larger firms had to
comply by December 3, 2025, and smaller entities by June 3, 2026. The
amendments require:
·
A written incident response program for
unauthorized access to customer information
·
Notice to affected individuals within 30 days
for incidents involving sensitive customer information
·
Oversight of service providers with access to
customer information, including procedures so vendors notify you within 72
hours of a breach
·
Records documenting compliance
The SEC has also named Reg S-P compliance an exam priority
for fiscal year 2026. An AI vendor that touches client data is a service
provider, so it belongs in that oversight.
For Illinois-based firms, there's a state angle too. The
Illinois Personal Information Protection Act says a contract that discloses
Illinois residents' personal information must require the recipient to implement and maintain reasonable security measures.
Where your IT partner fits
Your compliance officer interprets the rules. Your IT
partner builds and documents the technology controls. At Framework IT, your
virtual Chief Information Officer (vCIO) works directly with your compliance
officer to implement controls, provide documentation for audits, help with risk
assessments and security questionnaires, and coordinate on incident response.
We provide technology controls. Legal and regulatory interpretation stays with
your compliance officer or counsel, which is why a strong compliance officer on
your side matters.
What does a safe AI pilot look like in an advisory firm?
A safe AI pilot in an advisory firm uses one approved
platform, a small trained group, and tasks that start without client data, like
research summaries and internal drafts. Compliance reviews the outputs, records
are retained, and client data comes in only after vendor diligence,
permissions, and review steps are settled.
A practical sequence:
6. Approve one platform after due diligence.
Look for security certifications, written "no training on your data"
terms, access controls, and audit logs.
7. Train the pilot group. Our AI Champion
Certification takes about 90 minutes.
8. Start internal. Research summaries,
procedure drafts, and marketing copy that compliance reviews anyway.
9. Add client workflows carefully. Meeting
summaries and letter drafts, with human review and retention in place.
10. Review results monthly. Partners in our
Managed Framework AI adoption program meet with us monthly for an AI Strategic
Business Review, and every Managed Framework AI partner gets the Framework AI
Resources Hub from day one, including industry playbooks for financial services
firms.
Managed Framework AI runs on an enterprise platform that's
SOC 2 Type I, SOC 2 Type II, and SOC 3 certified. Client data is encrypted,
isolated from other organizations, and never used to train AI models.
Administrators control which roles can use which models and features, with full
audit trails, and data processing agreements are available on request.
Who should own AI decisions at a small RIA?
At a small RIA, a principal or the COO should own AI
decisions, the chief compliance officer should own the policy and supervision,
and your IT partner should vet tools and run the technical controls. An AI
champion on the advisory team helps colleagues use approved tools well and
spots problems early.
A workable model:
·
Principal
or COO: sets risk tolerance and approves tools and budget
·
Chief
compliance officer: owns the AI policy, review procedures, and
recordkeeping
·
IT
partner or vCIO: vets vendors' security, configures access, and documents
controls
·
AI
champion: 1 advisor or operations lead who answers questions and shares
what works
IT support for Chicago RIAs
Key Framework IT staff, including your vCIO, have direct RIA
experience, and responsible AI guidance is part of every managed services
engagement. We also commit to helping each partner identify at least 1
real-world AI use case. That work is backed by a local team: about 85% of our
service delivery staff are in the Chicagoland area.
For the general version of this guide, see writing an AI policy for a small business. You
can also learn about our AI services and how we support RIAs and wealth management firms in Chicago.
Frequently Asked Questions
Do RIAs need an AI policy?
There's no standalone AI rule for advisers, but existing
obligations for safeguarding client information, supervising communications,
overseeing vendors, and keeping records apply to AI tools. A written AI policy
is the simplest way to show how you meet them.
Does Regulation S-P apply to AI vendors?
If an AI vendor receives or has access to customer
information, it's a service provider for Reg S-P purposes, and the amended rule
requires oversight through due diligence and monitoring. Your compliance
officer should confirm how it applies to each tool.
Can advisors use AI note-takers in client meetings?
Many firms do, with guardrails: an approved tool, client
notice or consent where required, human review of summaries, and retention that
matches your recordkeeping obligations.
What AI uses are lowest risk for an RIA to start with?
Start with work that doesn't involve client data:
summarizing public research, drafting internal procedures, and preparing
marketing copy that compliance already reviews. Move to client-facing workflows
once vendor diligence, review steps, and recordkeeping are in place.
Does FINRA apply to RIAs?
FINRA rules apply to broker-dealers. RIAs are generally
regulated by the SEC or state securities regulators. Firms that are dually
registered or affiliated with a broker-dealer may need to consider both.
The Bottom Line
Advisors will keep using AI because it saves real time. AI
governance for RIAs makes sure that time savings don't come at the cost of
client data, vendor oversight, or books and records.
We help Chicago-area advisory firms put the policy in place,
secure the tools, and work alongside your compliance officer so the controls
are documented and ready for an exam.
Book an AI readiness conversation to
see what your firm should govern first.
Framework IT | 700 N. Sacramento Blvd., Suite 101, Chicago,
IL 60612 | (312) 564-5446
About the Author
Adam Barney is President and Managing Partner of Framework
IT, a premier managed IT and telecommunications firm based in Chicago. With
more than 15 years of executive experience in managed services and
telecommunications, Adam leads with a core philosophy that technology should be
user-friendly and approachable, empowering businesses to thrive in their
respective industries.
Since assuming the presidency in January 2020, Adam has led
a team of over 40 professionals spanning sales, information technology,
operations, marketing, human resources, and fulfillment. Under his leadership,
Framework IT remains committed to its unique inverted-pyramid approach, which
ensures clients' needs and aspirations are always the company's top priority.
Founded in 2008, Framework IT specializes in IT support,
strategy, and cybersecurity for small and mid-sized businesses nationwide. The
company's 30+ engineers act as an extension of client businesses, proactively
preventing IT issues so teams have more time to focus on what truly matters.
During his career, Adam has consulted over 1,000 companies, helping them
transform and streamline their technology infrastructure.
In recent years, Adam has spearheaded the adoption of
artificial intelligence in Framework's internal operations and service
delivery, positioning the company at the forefront of AI-driven IT management.
He has pioneered the launch of a new service offering to help clients implement
AI and AI-based automation in their own businesses, enabling organizations to
unlock new levels of efficiency and competitive advantage. Adam is also a
founding member of The Forge AI Alliance of MSPs, an alliance of managed service
providers working to accelerate the adoption of AI and automation in their own
companies and those of their clients.
Under Adam's leadership, Framework IT has been named to the
Inc. 500 Fastest Growing Private Companies in America twice and the Inc. 5000
list at least five times over the past decade. The company has been ranked one
of the Best & Brightest Places to Work in Chicago for five consecutive
years and one of the Best & Brightest Places to Work in the Nation twice in
the last five years. Framework IT has maintained a BBB complaint-free record
since 2008.
Adam's expertise has positioned him as a sought-after voice
in managed services and business technology. His insights have been featured in
the Harvard Business Review, the Washington Post, and Fox 32 Chicago. Adam has
also served as a speaker and panelist at the Chicago Bar Association AI
Symposium, sharing practical guidance on AI adoption with the legal community.
Adam holds a Bachelor of Science in Finance and Business
Administration from the University of Illinois Urbana-Champaign, where he
graduated Summa Cum Laude. He maintains numerous industry certifications,
including ITIL Foundations and multiple AI and cybersecurity certifications.
Outside of work, Adam is a husband and father of two
daughters, as well as an avid reader with interests spanning leadership,
management, psychology, and technology.