AI Governance for Investment Advisers: Summary and Takeaways

 

Executive Summary

The discussion focused on a central reality: AI tools are often adopted faster than firms establish the governance, configuration, records, and oversight controls needed to manage them. For investment advisers, the challenge is not simply deciding whether to permit AI. It is determining which tools and use cases are approved, how information flows through them, where outputs are stored, who can access them, how long they are retained, and how the firm can demonstrate that its written policy matches actual practice. Xantrion’s AI resources for business leaders offer additional guidance on AI strategy, implementation, security, and compliance.

Two Real World Cases

The speakers used two scenarios to illustrate the problem.

Example 1: Uncontrolled AI note-taking. An adviser adopted an AI note-taker that saved about 20 minutes per client meeting, and colleagues quickly followed. Fourteen months later, the firm had accumulated transcripts and summaries across multiple locations without clear decisions about retention, surveillance, privilege, access, or deletion. The example shows how a useful tool can create significant records and compliance exposure when adoption moves faster than governance.

Example 2: Policy and configuration misalignment. Another firm had a well-designed AI policy, but the approved tool’s settings did not actually enforce its requirements. Sharing, access, or data-use controls remained inconsistent with what the policy promised. The lesson was that a policy is only defensible when technical configurations, training, monitoring, and documented decisions make it operational.

Key Takeaways

  1. Governance must precede or quickly catch up with adoption. Firms should maintain an inventory of approved tools and use cases, assign ownership, and evaluate technology from legal, compliance, cybersecurity, privacy, contractual-rights, and data-usage perspectives.
  2. A prohibition alone can create shadow AI. Employees often adopt consumer tools to improve efficiency rather than to evade controls. Providing an approved team or enterprise option, combined with training, is generally more effective than relying on a broad ban. Xantrion’s AI Enablement Sprint helps organizations turn scattered experimentation into a safer, repeatable way of working.
  3. Recording creates a new information asset that must be managed. A transcript or summary may have implications for discovery, regulatory requests, surveillance, privilege, and retention even where its status as a required books-and-records item is uncertain.
  4. Storage location is a governance decision. Email delivery may place transcripts into long-term compliance archives and make them easier to surveil. A controlled portal may support shorter retention and centralized deletion. Either approach should be intentional and documented.
  5. Policies should be practical and technically enforceable. Firms should avoid detailed rules they cannot monitor. Tool configurations should enforce as much of the policy as possible, reducing dependence on users remembering nuanced requirements.
  6. Human accountability remains unchanged. The employee who delivers a work product remains responsible for its accuracy, quality, appropriateness, and compliance, regardless of whether AI helped create it.
  7. AI expands the consequence of weak permissions. A user might overlook a file they should not access; an AI assistant connected to a broad repository can retrieve and synthesize it immediately. Least-privilege access and clear data boundaries therefore become more important.
  8. Exam readiness depends on evidence, not effort alone. Firms should be able to produce policies, training records, vendor diligence, committee minutes, risk decisions, configurations, and examples showing that practice aligns with policy.

Key Points and Examples

AI Note-Takers: Productivity Versus Record Risk

An adviser adopted an AI note-taker that saved roughly 20 minutes per meeting. Three colleagues then began using it without a formal request. The productivity gain was real, but the firm had not decided where transcripts would reside, whether they would be archived, who would review them, or when they would be deleted. When a document request arrived, records were spread across shared folders and other repositories. The example demonstrates why firms should define the full information lifecycle before allowing broad deployment.

Retention and Surveillance Require Deliberate Choices

The speakers contrasted two workable models. Some firms allow email delivery so AI outputs automatically enter existing archives and surveillance systems; this limits retention uncertainty but can preserve large volumes of unreviewed material. Other firms deliver transcripts to a controlled portal, treat them as temporary backstop notes, and delete them after a defined period. The important point is consistency among the firm’s rationale, technology, retention schedule, and review process.

Privilege, Consent, and Sensitive Meetings Need Special Treatment

Default sharing can create a strong argument that privilege was waived, and automatic recording can capture meetings that should not be transcribed. Firms may use red-line categories that are never recorded, a whitelist of permissible meeting types, or a manual recording control. Consent should be built into the workflow where possible. Any policy distinguishing recordable and non-recordable calls must also explain how the distinction will be enforced.

Policy Should Be Simple for Users and Detailed Behind the Scenes

The panel described a useful division of labor: governance teams perform the complex work, while users receive a smaller set of clear rules. A standalone AI policy can be updated more easily than a full compliance manual as technology evolves. Attestations and recurring training reinforce the policy, while technical controls—approved accounts, single sign-on, restricted sharing, data-loss prevention, and centrally managed settings—reduce reliance on memory and judgment. Organizations that need broader technical ownership can reinforce these controls through managed IT services.

Tool Tier and Configuration Matter

A team plan may provide core protections at a lower cost, while an enterprise plan may add granular security and policy controls. The discussion used Claude as an example: a team offering can include useful cybersecurity features such as single sign-on, but the enterprise tier offers more detailed configuration. If a firm selects a lower tier, it should document why the available controls are sufficient and identify compensating controls such as training, monitoring, or tighter permissions.

Connected AI Makes Permission Problems Immediate

An AI system connected to SharePoint, Box, Dropbox, or another large repository may search an organization’s entire data corpus. The panel highlighted the risk that confidential information from one private investment could influence analysis of another, violating an NDA or internal information boundary. Firms should map what each AI system can access and apply least-privilege permissions to tools as well as people. Internal teams that need additional security expertise or implementation capacity can use supplemental IT services to close those gaps without surrendering control of their IT strategy.

AI-Assisted Work Product Still Requires Human Review

The speakers rejected the idea that a poor result can be excused because an AI system produced it. The person sending a client report, visualization, meeting summary, or analysis remains accountable. Universal “generated by AI” labels may be impractical because AI assistance can range from minor editing to full drafting. A more useful practice is to flag material AI involvement, known limitations, and areas requiring heightened review. This is especially true for client-facing analysis and visualizations.

Training Should Create Feedback, Not Merely Document Completion

Interactive training helps firms uncover where policy language, workflows, or configurations are failing. Employees often recognize practical AI risks and can identify emerging issues. Normalizing transparent discussion of AI use reduces the likelihood that staff will hide usage because they fear appearing lazy or unskilled. The panel noted that standalone AI training, or AI combined with cybersecurity training, is more effective than briefly embedding the topic in a broad annual compliance session.

Practical Action Checklist

  • Inventory approved and detected AI tools, owners, users, integrations, use cases, and data sources.
  • Form a cross-functional governance group with legal/compliance and technical representation.
  • Define recording, consent, retention, deletion, sharing, surveillance, and privilege rules for AI note-taking.
  • Use team or enterprise accounts where they provide necessary control over data, access, training, and configuration.
  • Align actual settings with written policy and document any gap, rationale, and compensating control.
  • Apply least-privilege access to repositories connected to AI systems.
  • Perform and retain vendor diligence for tools handling sensitive information or important business processes.
  • Specify human review and accountability requirements for AI-assisted client work.
  • Collect attestations and conduct recurring, interactive AI training.
  • Centralize committee minutes, risk decisions, configurations, training evidence, and testing results for examination readiness.
  • Test whether the firm can promptly identify and produce a defined period of AI-assisted client documents.
  • Use existing data-loss prevention and security monitoring to detect sensitive uploads and unapproved AI use.

Conclusion: Turn AI Governance into an Operating Discipline

A defensible AI program depends on more than a written policy. Approved use cases, technical controls, employee behavior, records practices, and documentation must work together around clear, repeatable decisions. Xantrion’s AI Steering Committee Charter provides a practical starting point for defining decision authority, approval criteria, risk escalation, and ongoing oversight.

Download the AI Steering Committee Charter to establish a clear governance structure before AI adoption outpaces your controls.

Ready to learn more? Get the latest Xantrion news and IT tips.

Menu
dialpad