Free download · no email wall

Do you have an AI policy? Here's one. Free.

A sample AI Use Policy & Procedures for registered investment advisers — the minimum framework an examiner will expect a firm permitting AI to have adopted. Fourteen sections including AI accuracy and hallucination, a vendor-diligence checklist, a tool-inventory template, and the part most samples skip: the evidence checklist it will be examined against. Two editions: the clean one you can adopt, and the annotated one — marked up by the compliance seat that has to live with it, pricing every provision in traps, homework, and what dissolves under a governed layer.

purpose & scopeapproved toolsprohibited usesAI accuracy & hallucinationReg S-P safeguardsbooks & records (204-2)marketing & AI claimsvendor diligencemonitoring & testingtraining & attestationsincident responseannual reviewtool inventory templatethe evidence checklist
Read before adopting

The policy is the easy part. Every line you adopt is a record you owe.

And the standard defense — "our advisors attested to it" — has a failure mode every experienced CCO knows by heart:

"Our policy prohibits client PII in AI tools — and advisors acknowledge it on the annual compliance questionnaire."

"That's what they attest. How do you know?"

Then comes the request that ends the conversation: certify it yourself — that you're sure they aren't. Counsel won't let you sign, because you aren't sure; there's nothing behind the attestation but the attestation. The certification you couldn't sign becomes the finding.

That is the exact sequence that produced the off-channel fines: written policy, annual acknowledgment, no verification, nine-figure penalties. Ungoverned AI is the same pattern on the next channel. So here is the honest ledger — the same provisions, evidenced by hand, versus running on a governed layer where the evidence exists because the architecture produced it.

"No AI-generated figure may be used in Firm business until verified against the Firm's systems of record."
SAMPLE §6.2

By hand — the exam risk

Generative AI hallucinates fluently. Adopting §6.2 means a human traces every balance, return, and RMD in every AI draft to a source system — forever. Ship one invented number to a client, and this is the provision you're charged under.

On RIAGuardrAIls

The model never computes a figure. Numbers come only from governed tools reading the systems of record, provenance-tagged — an unverified figure structurally cannot appear. §6.2 is satisfied by architecture, not willpower.

figures: tool-computed · provenance-tagged
"Supervised persons may not enter client information into unapproved AI tools."
SAMPLE §5.1

By hand — the exam risk

An annual acknowledgment. When the examiner asks "how do you know?", the only honest answer is that you don't — and the certification you can't sign is the finding. The off-channel posture, next channel.

On RIAGuardrAIls

Client data connects server-side and accounts surface masked to last-4 — PII never transits the chat. The rule isn't policed; it's structurally impossible to break.

masking: last-4 · server-side
"The Firm preserves records of AI interactions relating to its advisory business."
SAMPLE §8.1

By hand — the exam risk

Which records? The conversations live in personal accounts on personal phones. Under Rule 204-2, records you cannot produce are the finding.

On RIAGuardrAIls

Every AI data request writes an audit entry — who asked, what was accessed, when, the outcome. Every tool call captured, on a record your firm owns.

audit: per-call · firm-owned
"Each person's AI access is limited to the client information appropriate to their role."
SAMPLE §7.3

By hand — the exam risk

Consumer AI tools have no concept of your org chart. There is nothing to scope and no way to test it — the provision is words.

On RIAGuardrAIls

Seats are scoped fail-closed: advisors see only their own book; principals see the firm, read-only, with attribution. Scoping is enforced on every payload — and testable on demand.

seat: scoped · fail-closed
"The CCO periodically reviews the Firm's AI use, using records the Firm actually possesses."
SAMPLE §11.1–11.2

By hand — the exam risk

The review has nothing to review — the data lives in apps you can't see. A monitoring program that quietly skips the exercise, or samples attestations instead of activity, is itself the deficiency.

On RIAGuardrAIls

"Show me every AI data request from last quarter — who asked, what was touched, what came back." Monitoring becomes a query; the completed review becomes a standing record.

audit_summary · one ask
"AI vendors receiving client information are overseen as Reg S-P service providers."
SAMPLE §10.2

By hand — the exam risk

A dozen point subscriptions — note-taker, transcriber, report writer — each one a diligence file, a DPA, and an incident-response seat in your perimeter.

On RIAGuardrAIls

One governed platform consolidates the pile. Each firm runs a dedicated instance — its own database, its own keys — and every vendor you retire exits your oversight perimeter.

your instance · your keys
Same policy. Two firms. One of them can produce the record.

Appendix B of the sample lists nine artifacts an examiner may request. Under a manual program, each is a project. Under a governed layer, the hard four are byproducts — the system evidences itself.

Seven minutes

Take the policy. Then see it enforce itself.

The demo starts from a blank screen: a governed workspace composes a compliance morning, every panel receipted as it lands. Bring the sample — we'll show you which sections stop being homework.

Request a demo

The sample policy is educational marketing material from RIAGuardrAIls, a technology vendor — not legal, compliance, or investment advice. Tailor with counsel before adoption. Regulatory references: Advisers Act Rules 206(4)-7 and 204-2; Regulation S-P as amended (2024); SEC off-channel communications sweep (2021–2024); In re Senvest Management LLC (2024); SEC 2025 Examination Priorities.