Governed AI for registered investment advisers

Your AI. Your Data. Your Rules.

Your advisors are already using AI. The only question is whether your firm can prove it's governed. What RIAGuardrAIls supplies is the guardrails: a governed tool layer between the model and your book — every seat scoped, every account masked to last-4, every request memorialized on a record you own.

RIAGuardrAIls — gold shield emblem with railway signal, over the wordmark and the line: Stay on track. Your AI, your data, your rules.

Built and operated by a sitting Chief Compliance Officer of an SEC-registered investment adviser — running in production, on the record, every day.

The people building AI tools and the people who answer to examiners for them are usually different people. Here, they're the same person. That changes what gets built — and what would never be allowed to ship.

The exposure today

Shadow AI is already inside your firm

Generic AI tools don't know your book — so advisors paste client names, accounts, and holdings into chat windows by hand. That workaround is the violation: unlogged, unscoped, unretained.

Prohibition doesn't work

Regulators fined firms over $2 billion for business communications on unapproved channels employees used anyway. Ungoverned AI is the same pattern on the next channel — and examiners are already asking about AI use.

Client PII in the prompt

Amended Reg S-P requires safeguarding customer information and notifying clients of compromise. PII pasted into a consumer AI tool sits outside your safeguards, your vendor diligence, and your incident response.

No books, no records

Advisers must preserve required business records under Rule 204-2. AI conversations that shape advice, held in personal accounts, are records you cannot produce.

How the exam goes
EXAMINER
"What is your firm's AI policy?"
YOU
"We permit AI tools — but no client PII goes in. It's in our compliance manual."
EXAMINER
"How do you verify that? Produce your monitoring records and any violations you've found."
YOU
There are no records to produce. The tools are consumer apps on personal phones — you have a policy, and no way to evidence it.
A policy you can't evidence is a liability, not a defense.

This posture has already been charged: in the off-channel sweep, an adviser whose own senior officers violated its written prohibition — never verified — was charged for the policy failure itself. $6.5 million, required admissions, an imposed consultant.

SEC off-channel communications sweep, 2021–2024 · In re Senvest Management LLC (2024) · Reg S-P amendments (2024) · Advisers Act Rule 204-2 · SEC 2025 Examination Priorities (AI use). Examination dialogue is an illustrative scenario.

Free download · no email wall

Don't have the policy yet? Take ours — a sample minimum framework, free, in Word and PDF.

Fourteen sections — including AI accuracy and hallucination — the tool-inventory template, and the evidence checklist your examiner will read it against.

Get the free policy
What RIAGuardrAIls changes

The AI becomes useful. The record becomes yours.

PII never transits the chat

Data connects server-side. Account numbers surface masked to last-4; client identifiers stay in your database. Advisors get answers without ever handling raw PII in a prompt.

Every interaction memorialized

Each AI data request writes an audit entry — who asked, what was accessed, when, and the outcome. When the examiner asks for your AI records, you produce a log, not a shrug.

Advisor-level walls, fail-closed

Each advisor's AI sees only that advisor's book. No entitlement means access to nothing — never everything. Executives and compliance get the firm-wide view by role, on the record.

Your instance. Your keys.

Each firm runs a dedicated deployment — its own database, its own encryption keys, its own domain. Client data never commingles with another firm's, never gets copied into a vendor's cloud to build someone else's "canonical record," and the instance is yours.

AI can hallucinate. Your numbers can't.

Generative models produce fluent, plausible, wrong figures — the single risk every compliance officer names first. Here, the model never computes a number: every figure on screen is calculated by a governed tool reading your systems of record, and carries its provenance. An invented balance, return, or RMD structurally cannot appear — accuracy by architecture, not by hoping someone catches it in review.

The next surface · in live development

A workspace the AI composes. An operating system you can live in.

The canvas opens blank. Ask for your morning, and watch the AI assemble it — book summary, risk overview, review queue — each panel placed and sized by what matters most today, each one receipted as it lands.

Say a household's name, and the entire canvas becomes them. Release, and the firm view returns exactly as you left it. Not a dashboard with a chat bolted on — a governed surface that arranges itself around the work.

The AI decides what deserves the screenThe panel with a real finding takes the hero position. Quiet context shrinks to a glance. Why something was big is on the record too.
Every pixel traces to a governed tool callThe AI arranges the screen freely — but may only populate it from audited tools. A number with no provenance simply cannot appear.
It surfaces the numbers that disagreeComposing the morning, it computes the same control two ways — the exec email said zero money-movement alerts; the dashboard fired three. It places the two answers side by side, where a false all-clear can't hide. The most dangerous control is the one that looks like it's working.
The session is a recordEvery composition serializes. "Show me everything on screen when that decision was made" becomes a file you can produce for an examiner.
Firm risk overviewfirm_risk_overview
$12.4Bvalue-weighted · hero
placed hero — largest overnight move
Review queuereceipted
12due
3 past window
Advisors rankedreceipted
68reps
by value-weighted risk
⚠ Same control, two answerscontradiction
0 email · 3 dashboard
money-movement alerts — placed adjacent, can't be missed
A-2compose · blank spawn → morning loadout · receipted
A-9subject bind · "show me the Hendersons" → scene becomes household

Illustrative composition of the governed canvas, sample data.

What it feels like

Gorgeous is easy now. Gorgeous, scoped, masked, and logged is the product.

AI has reset the bar on client deliverables — firms are shipping polished, personal, media-rich work, and clients notice who isn't. Every example below is one ask, answered from your firm's own CRM, custodial, and document data — scoped to the asker, masked, and logged.

The Monday morning brief

"What changed in my book last week?"

Accounts gone inactive, cash past your threshold, meaningful value swings, households untouched in ninety days — a triage list before your first coffee, scoped to your book alone.

The client review, assembled

"Build my review pack: how the year went, where they stand, how they're tracking against the plan."

Year-over-year trend, current allocation and cash, last review's commitments from the CRM, progress against the plan document. An afternoon of prep becomes one question.

The opportunity dig

"Dig through my book for revenue hiding in plain sight."

Idle cash, concentrated positions, households that outgrew their service tier, follow-ups promised in the CRM and never made. An entire startup category sells this as a subscription; here it's one ask.

The client podcast

"Create a five-minute podcast ahead of Thursday's review — recap, transactions, progress toward the goal."

Built from custodial and CRM data, scoped to the advisor, reviewed before it ships. Meeting prep becomes a listen on the drive in.

The illiquid holdings report

"Assemble the performance report on their private funds."

Alternatives don't show up in custodial feeds — their story lives in PDF statements. Captured, parsed, advisor-confirmed; the data your reporting stack can't see becomes your best deliverable.

The CCO's sample

"Show me every AI data request from last quarter — who asked, what was touched, what came back."

Exam prep flips from dread to a query. The audit trail your policy promises becomes a standing record you produce on demand — the exact evidence the swept firms couldn't.

How it works

The governed loop

Three disciplines, enforced in code on every request — not policed after the fact.

I  ·  SCOPE

Every seat sees its own book

Advisors see their clients — never each other's. Principals see the firm, with attribution. Isolation is enforced on every payload element before the first question is answered.

seat: advisor · scope: book:read
II  ·  ACT

Capabilities, not credentials

The AI works through governed tools — book intelligence, supervision screens, risk analytics, review documents. Writes are dark by default, and confirm-gated when a firm turns them on.

writes: confirm-gated · dark by default
III  ·  LOG

Everything on the record

Every tool call lands in an audit trail your firm owns — who asked, what ran, what returned, when. A session can be reconstructed for examination. That isn't a feature; it's the shape of the system.

audit: per-call · session: serialized
Security & data protection

Handing an AI your clients' information is a real decision

So here is exactly how that information is protected, where it goes, where it does not, and how anyone would know if something went wrong. Every line describes a shipped control — what it claims, it can show.

Scoped by role, on every request

An advisor's connection sees only that advisor's own households and clients; firm-wide visibility requires a firm-level role. The boundary is enforced on every single request — not just at login — and a request that isn't permitted returns nothing at all, without even revealing the thing exists.

fail-closed · enforced per request
Encrypted, isolated, single-key

Client data lives in a dedicated database only the service can reach, through one locked-down key, with row-level rules that keep every query inside firm and advisor boundaries. Stored credentials are held encrypted, and every connection is encrypted in transit — nothing is served in the clear.

dedicated DB · row-level rules · TLS
Watched from outside — alerts in minutes

Availability is monitored continuously from outside the firm's own infrastructure, so an outage — even one that takes the whole machine down — raises an alert within minutes. Repeated failed sign-ins on every login surface are detected and alert the firm's compliance and executive roles.

external monitor · intrusion alerting
Every privileged action attributed

Every privileged action and every write back to the CRM is tied to a named operator and logged — with no client data kept in that trail. Compliance can review the live evidence — failed-sign-in counts, alerting status, system health — in the admin console.

named operator · reviewable evidence
Where the data goes
  • To the frontier model, through the connector — under commercial terms where business content is not used to train models.
  • Back to the firm's own CRM — a round-trip into a system the firm already owns, not a handoff to a new party.
  • Into the firm's dedicated database — reachable only by the service, inside row-level boundaries.
Where it does not
  • No client information to any other AI provider.
  • None to advertisers or third-party analytics.
  • Market-data lookups carry only a ticker or a year — never a client's name or account.

Honest about the limits: this is proportionate, verifiable protection for a governed advisory tool. It is not a 24/7 security-operations center, and this page will never imply it is.

The capability surface

A full capability surface, shipped in scoped pairs

This is operational compliance, not process compliance — evidence computed from real custodial and CRM data, never self-reported. Every capability ships twice: an advisor version scoped to their own book, and a principal version scoped to the firm with attribution. Same math, different blast radius.

Book intelligence

Census, holdings, transactions, balance history, and true performance — market return separated from flows.

orion_book_summaryorion_performance

Supervision & reconciliation

CRM-vs-custodian conflicts, unbridged assets, householding drift, contribution stoppages, fee outliers.

crm_reconciliation_reportorion_insights

Risk intelligence

Firm value-weighted risk, per-advisor ranking, concentration-times-risk screens, single-ticker blast radius.

firm_risk_overviewblast_radius

Options oversight

Strategy mix, covered versus naked exposure, expiry calendars with assignment risk, market-vs-model divergence on live chains.

options_exposure_screenmarket_vs_model

Planning scenarios

Deterministic tax and retirement modeling — Social Security claiming, IRMAA tiers including Part D, the senior deduction. Every figure computed by the tool, never by the model, with primary-source provenance.

ss_timing_aftertaxfigures: provenance-tagged

Client deliverables

Meeting prep, annual-review briefs, and wealth progress reports an advisor is proud to hand across the table.

client_review_briefhousehold_brief

The record

Firm AI activity summarized from the audit trail itself — the layer that watches the layer.

audit_summarysession: serialized
The structural difference

Keep your firm. Keep your systems. Keep your economics.

Some platforms make advisors change firms to reach their AI. Here, adoption is a connector consent — your CRM, your custodian, your compliance archive, your comp structure, and your clients stay exactly where they are. What you pay for is the one thing you don't have and shouldn't build twice: the guardrails. The walls, the scoping, the record — that's the product.

YOUR CRM YOUR CUSTODIAN YOUR ARCHIVE YOUR COMP YOUR BRAND
Where the edges are

What this doesn't replace

Your communications archive. Your marketing-review workflow. Your personal-trading system. RIAGuardrAIls is the governed layer between your firm's AI and your firm's data — access, isolation, and the record. One governed platform can replace the pile of single-purpose AI subscriptions — and under amended Reg S-P, every vendor you retire exits your oversight, diligence, and incident-response perimeter. But we'd rather tell you where the edges are than let you find them.

A note on the category

"AI readiness" isn't AI

A well-funded vendor category now sells AI readiness — unifying your data so AI can use it someday, by copying your book into their cloud to build a "canonical record." Readiness is a roadmap; it ships no advisor-facing AI, no supervision surface, and no record of how AI touched client data. RIAGuardrAIls is the AI layer itself: governed tools in daily advisor use, a live supervision surface, and the one artifact no data layer produces — a supervisable record of every AI interaction. If your systems already talk to each other, you don't need a second foundation bought under the first.

Five gold shields on a rail: Governed, Secure, Documented, Auditable, Compliant.
Seven minutes

Watch a compliance morning
compose itself.

The demonstration starts from a blank screen. You watch the governed canvas assemble the morning — every panel receipted as it lands, one contradiction surfaced where you can't miss it. Before the examiner writes your AI policy for you — let's talk.

Request a demo