Compliance

What Do SEC Examiners Ask Financial Advisors About AI? (An Exam-Prep Guide)

Sam Farrington, CFP®·July 29, 2026

SEC examiners are now asking registered investment advisors about AI as part of routine examinations, and they expect to see answers on paper. The questions come down to five things. What AI tools you use, whether you have a written AI use policy, how you vetted your vendors, who reviews AI output before it reaches clients, and how you've trained your team.

If your stomach dropped a little reading that list, keep going. Getting ready is closer to a weekend project than a compliance overhaul, and you probably have more of the pieces in place than you think.

Is AI Really Part of Standard SEC Exams Now?

Yes. The SEC's 2026 examination priorities, published in November 2025, name AI as a focus area for adviser exams, and examiners are applying it to firms of every size, whether or not you market AI to clients.

The Division of Examinations says it will look at whether your Form ADV and marketing accurately describe how you actually use AI, whether you have policies and procedures for supervising it, and whether a human stays involved in the decisions that matter.

This has teeth. In March 2024 the SEC brought its first enforcement actions for what it calls AI washing, charging two investment advisers that claimed AI capabilities they didn't have. The firms paid $400,000 in combined penalties.

Here's why this matters for you. The typical advisor's exposure has little to do with exaggerating AI capabilities. The bigger risk is using AI tools every day and having nothing on paper about how.

What Documents Do Examiners Actually Ask For?

Examiners are requesting five things, according to reporting from WealthManagement.com this spring. An inventory of the AI tools your firm uses, a written AI acceptable use policy, vendor due diligence records, supervisory procedures showing that a human reviews AI-assisted work, and staff training records.

None of these require a six-month project, and the inventory is the natural place to start because everything else builds on it.

Sit down and list every AI tool that touches your practice, including the ones running on personal devices and personal browser accounts. Meeting notetakers count, and so does the ChatGPT or Claude account you use for first drafts. If notetakers are on your list, I've written about whether AI meeting notetakers are compliant for financial advisors and the consent questions that come with them.

Once the list exists, the rest of the documents describe how you manage what's on it. That's a much easier writing assignment than it sounds.

What Does the Regulation S-P Deadline Have to Do With AI?

The amended Regulation S-P is now in effect for firms of every size, and it changes how examiners look at client data flowing through AI tools. Larger firms had a December 3, 2025 compliance date, and smaller firms had until June 3, 2026, which has already passed.

The amendments require a written incident response program and notification to affected clients within 30 days of learning that customer information was accessed without authorization. When client names or account details end up in an AI tool, that tool sits inside your data safeguarding perimeter whether you meant it to or not.

The good news is that the fix lives upstream of the tools. What you feed them matters more than which ones you pick, and what advisors need to know about PII, NPI, and AI tools covers how to anonymize client information before you prompt.

I teach financial advisors how to use AI for content, communication, and client attraction. New frameworks and prompts every Tuesday and Friday. Subscribe free or get full access for $20/month at amplifyforadvisors.substack.com.

What Is Shadow AI and Why Do Examiners Care?

Shadow AI is the industry's name for tools your team uses that compliance never signed off on, and it's the pattern examiners are most likely to find at small firms. The personal ChatGPT Plus subscription, the free notetaker someone installed last spring, the browser extension that summarizes client emails.

Firms routinely have AI touching client data with no record of it anywhere, and that visibility problem is exactly what the exam questions are designed to surface.

At a solo or two-person firm, shadow AI is a short list, and turning it into an approved list mostly means writing down what you already use and deciding what's allowed to touch client information. I've covered whether financial advisors can use ChatGPT from the compliance side before, and the answer holds. You can use these tools, as long as you can show how.

How Do You Write an AI Use Policy Without Hiring a Consultant?

A workable AI use policy for a small RIA fits on a few pages and answers four questions. Which tools are approved, what client information can and can't go into them, who reviews AI-assisted output before it reaches a client, and what happens when someone wants to add a new tool.

Write it to match what you actually do, because examiners compare the policy against practice. A borrowed enterprise policy that promises a governance committee you don't have creates a bigger problem than a short, honest document ever could.

This is the same thinking behind the compliance-first approach to AI content I've written about before. The guardrails come first, and then the tools get useful fast.

If you want to go deeper on this, the Compliance-Safe AI Playbook includes a sample AI use policy you can adapt to your firm, plus language swap tables and a pre-publish checklist. Between the policy and the checklist, it covers most of what the five-document list asks for.

And if the part you're unsure about is the language in your client-facing content, the Outcome-Focused Compliance Language System walks through writing about results in words a compliance officer can approve.

What Should a Solo Advisor Do First?

Start with the inventory this week, because every other document flows from it. Then draft the use policy, save a short note on each vendor covering what data it stores and where, and build a habit of spot-checking AI output the way you'd review work from a new associate.

Training records sound corporate, but at a small firm a dated note confirming you walked through the policy with your team counts. Keep it in the same folder as the policy so everything is ready if an exam letter shows up.

If you're earlier in the process and still setting up your AI system, the AI Setup Sprint builds these guardrails in from day one, which beats retrofitting them after the tools are already woven into your week.

Worth noting. What examiners want from a two-person RIA is evidence you thought about this before they asked, and that bar is lower than you might expect.

The Bottom Line for Financial Advisors

SEC examiners are treating AI the way they treat every other part of your practice. They expect you to know what you're using, have rules for it, and be able to show your work. For a small firm that means an inventory, a short policy, vendor notes, a review habit, and a training note, and you can build the whole set in a weekend.

The advisors who handle this well will be the ones whose paper matches their practice, and that has nothing to do with how thick the binder is.

Get it on paper before someone asks you for it.

Sam Farrington, CFP®

Sam Farrington is a Certified Financial Planner and the creator of Amplify for Advisors. He teaches financial advisors how to use AI to communicate authentically, stay compliant, and build a practice that attracts the right clients. He publishes twice weekly on Substack and is building the first suite of AI Skills designed specifically for financial advisors.

Subscribe at amplifyforadvisors.substack.com or explore more at amplifyforadvisors.ai.

Your voice. Amplified.

New frameworks every Tuesday and Friday, and the free AI Cheat Sheet every Sunday.

Subscribe free