How RIAs can build a practical AI compliance framework

How RIAs can build a practical AI compliance framework

Registered investment advisers (RIAs) adopting artificial intelligence face a defining question, according to MCO (MyComplianceOffice): can AI be trusted within a compliance programme, and can its use be effectively controlled?

In a recent discussion between MCO and Siepe MSP managing director Jilbert El-Zmetr, the two firms explored how RIAs can build a defensible framework for AI, spanning use case selection, controlled rollout and best practices that satisfy regulators and clients alike.

MCO stresses there is no AI-specific rulebook in financial services. Instead, long-standing frameworks for model risk management, recordkeeping and supervisory oversight apply directly to AI-driven RegTech tools. Firms must demonstrate the same control over AI as over any other system touching regulated activity.

Three sources of guidance shape RIA oversight, MCO explains. SR 11-7, the Federal Reserve’s model risk management guidance, is widely used as a governance baseline covering model inventories, ownership and validation. FINRA Regulatory Notice 24-09 makes firms responsible for AI-generated outputs in trade surveillance, communications drafting and investigation summaries. SEC Rule 206(4)-7, the Advisers Act compliance rule, extends to any AI tool touching conflicts of interest, disclosure or supervisory controls.

As noted in MCO’s recent webinar ‘‘AI and Compliance: A Practical Framework for RIAs’, ” regulators aren’t going to ask firms whether they have a named responsible AI framework in place. They’re going to ask whether the firm can evidence control, oversight, and accountability over the technology affecting its regulated activity.”

MCO points to two complementary frameworks. Model Risk Management (MRM) tests whether a model performs correctly, resting on documented methodology, independent validation and governance controls. Responsible AI (RAI) asks whether outcomes can be trusted, built on six principles including fairness, explainability, accountability, robustness, data governance and auditability. In practice, both demand the same evidence: what the tool did, who reviewed it, and what data informed the decision.

Human oversight remains non-negotiable. In e-comms surveillance, AI can flag likely spam to cut false positives, but a human must still disposition alerts. AI-generated trading signals flow to a portfolio manager or risk officer rather than executing autonomously, guarding against the “black box” problem.

On data governance, MCO advises firms to resolve data quality, tagging and ownership before AI touches a workflow, segregate or mask sensitive data, document lineage, and align retention with regulatory recordkeeping.

Smaller RIAs, MCO adds, need not replicate a global bank’s infrastructure. Regulators apply a proportionate, risk-based approach: a simple AI inventory, documented human review, vendor due diligence and periodic output checks generally suffice.

Firms that can inventory AI use, document review and produce an audit trail on demand are well placed to meet expectations today, MCO concludes.

For more insights, read the full story here.

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.