All guides AI Governance for RIAs 4 min read

Do RIAs Need a Written AI Policy? (And What It Must Include)

Most RIAs have no written AI policy heading into 2026, right as the SEC names AI an exam focus and the Reg S-P deadline lands. Here's the 8-section policy your firm actually needs.

If you run a registered investment adviser and you've let your team use ChatGPT, an AI note-taker, or Microsoft Copilot without a written policy governing it, you're in the majority, and that's exactly the problem.

Per the ISS Market Intelligence Advisor Pulse survey (n=466, June 2025), 78% of RIAs said their firm did not have written policies on the use of AI, compared to just 35% of regional, independent, and bank advisors. RIAs are simultaneously the highest adopters of AI and the least governed. That gap is what an examiner sees first.

Is an AI policy legally required?

There is no rule titled "you must have an AI policy." But Rule 206(4)-7 (the Compliance Rule) requires every RIA to adopt written policies and procedures reasonably designed to prevent violations of the Advisers Act, and the SEC has made clear it views AI through that existing, technology-neutral lens.

For 2026, the SEC Division of Examinations named AI an explicit focus under its "Emerging Financial Technology" examination section. Examiners are directed to assess whether: (1) a firm's representations about its AI use are fair and accurate; (2) controls are consistent with disclosures made to investors; (3) AI-assisted advice stays consistent with each investor's profile; and (4) controls confirm that advice produced by automated tools meets the firm's regulatory obligations.

In plain terms: the absence of a written policy isn't a standalone violation, but it's the fastest way to fail every one of those four assessments at once.

What your AI policy must include (8 sections)

A defensible RIA AI policy maps directly to Rule 206(4)-7 and amended Regulation S-P. At minimum:

  1. Scope & approved tools: an inventory of which AI tools are sanctioned, for which tasks, and an explicit ban on entering client NPI into unapproved consumer tools.
  2. Data handling & Reg S-P: what categories of client data may touch which tools, and the vendor-oversight requirements behind each.
  3. Permitted vs prohibited use cases: note-taking and back-office drafting versus unsupervised investment advice.
  4. Human review & supervision: who reviews AI output before it reaches a client, and how that review is evidenced.
  5. Recordkeeping under Rule 204-2: retention of both AI outputs and underlying source material for five years.
  6. Disclosure: where AI use is reflected in Form ADV and client agreements, without overstating capabilities (AI-washing).
  7. Vendor due diligence: the file you keep on each AI vendor, covering training-on-your-data terms, prompt retention, subprocessors, and breach notification.
  8. Review cadence & ownership: who owns the policy and how often it's reviewed.

If you'd rather start from a structured draft than a blank page, the RIA AI Policy Starter Template maps all eight of these sections to Rule 206(4)-7 and Reg S-P.

Why now: the Reg S-P deadline

Amended Regulation S-P sets a compliance deadline of June 3, 2026 for smaller advisers (under $1.5B AUM); larger firms ($1.5B+) were on the hook by December 3, 2025. The amended rule expands obligations around incident response and third-party vendor oversight, which is precisely where unsanctioned AI tools create exposure. A written AI policy is the natural home for the vendor-oversight documentation the deadline now demands.

Frequently Asked Questions

Does a solo or small RIA still need a written AI policy?

Yes. Rule 206(4)-7 applies regardless of headcount, and the SEC's 2026 exam focus on AI does not carve out small firms. A solo RIA's policy can be far shorter, but the same eight elements apply, and the vendor-oversight piece tied to the June 3, 2026 Reg S-P deadline applies to smaller advisers specifically.

What happens at an SEC exam if we have no AI policy?

Examiners will ask what AI tools the firm uses, how client data flows through them, and what controls govern that use. With no written policy, you can't evidence supervision, disclosure, or recordkeeping, which are the four areas the 2026 Emerging Financial Technology exam section explicitly assesses. The absence becomes a finding that cascades across multiple rule areas.

Is using ChatGPT with client data against the rules?

It depends on the tier. Consumer and free tiers may retain inputs and train on them, creating Reg S-P exposure for any client NPI. Enterprise tiers with a data processing agreement that contractually excludes training are a different posture. Your policy should name which tools are approved for which data.

How often should we review and update the policy?

At least annually, alongside your Rule 206(4)-7 compliance review, and whenever you adopt a materially new AI tool. The AI tool market moves faster than most policies, so an annual cadence with event-driven updates is the practical standard.

Who should own the AI policy inside the firm?

The CCO owns it, but it should be built with whoever actually selects and deploys tools. A policy written in isolation from the people using AI day-to-day tends to miss the shadow-AI usage that creates the real risk.