← Blog

FINRA AI Compliance Checklist for Broker-Dealer Controls

Parminder Singh
Parminder Singh··6 min read
Summarize with AI

This FINRA AI compliance checklist gives broker-dealers seven gradable checks for use-case scope, written supervision, communications review, books and records, vendor oversight, access and routing, and evidence testing. Every check names an owner, pass condition, evidence, and remediation trigger while preserving the firm’s responsibility for each regulatory judgment.

Industry Verticalsai-complianceai-governancecomplianceregulationauditpolicy-enforcement
FINRA AI Compliance Checklist for Broker-Dealer Controls

A broker-dealer inventory row says marketing copilot. It has no business owner or communication class. It also lacks a retained-record link. That row fails this FINRA AI compliance checklist before the team reaches model testing. I want seven checks. Each should return pass or out of scope, unless it needs remediation. Attach an owner and dated evidence. A red cell beside a named workflow is more useful to the CCO than a 40-page policy that never touches production.

TL;DR

  • Grade seven checks. Record pass and out of scope as closed results; use remediate when action remains. Add the owner and date. Include the evidence link and open action.
  • Apply existing FINRA duties to the actual business use. FINRA's AI material creates no separate rulebook.
  • Test a real communication and a denial. Then test a vendor workflow and an old retained record.
  • Limit gateway credit to authenticated HTTP model traffic routed through the policy point.

Check 1: classify every business use

Owner: compliance with the business owner.

Pass condition: the inventory names the AI function, users, data classes, customer impact, provider and model destination, plus the deployment method and accountable owner. It identifies the FINRA rules and securities-law duties triggered by the actual use. Embedded AI capabilities are separate rows when they process firm or customer information.

Evidence: approved inventory and use-case assessment, plus the architecture diagram and data-flow record. Include the review date. FINRA's artificial intelligence topic page says existing technology-neutral rules apply to both proprietary and third-party AI, including embedded AI. The same page says its information creates no new legal requirements.

Remediate when: the use-case assessment says only vendor approved, or a moving model alias has no controlled resolution record.

Check 2: put the use into written supervision

Owner: the CCO with the designated supervisory principal.

Pass condition: written supervisory procedures name the permitted workflow and responsible principal, the review trigger and escalation route, plus the exception process and testing cadence. They also name the retained evidence. The procedure covers reliability and accuracy, plus data privacy and integrity. It covers change governance at a level matched to the use.

Evidence: approved procedure version and principal assignment, training record and test script, plus the completed review and exception register. Include the remediation ticket. FINRA Regulatory Notice 24-09 connects GenAI used in a supervisory system to Rule 3110 and identifies technology governance and model risk, privacy and integrity, plus reliability and accuracy as subjects for policies and procedures.

Remediate when: the procedure says only human review required. The reviewer and stopping condition remain undefined, along with the required evidence. I would fail that sentence on contact.

Check 3: control AI-assisted communications

Owner: communications compliance with the reviewing principal.

Pass condition: the firm classifies each communication under Rule 2210 and applies the required approval and review path. It preserves the exact version sent. The reviewer can connect an AI-produced draft to its edits and approval, plus the audience and channel. The record also includes the distribution timestamp.

Evidence: prompt or controlled source reference and model output, final communication and redline, approval event and communication class, plus the distribution record and content-test result. FINRA's Rule 2210 text supplies the governing categories and standards. Notice 24-09 confirms that content standards apply to communications generated by people and technology tools.

Remediate when: a principal approved a PDF, while the delivery platform sent a later AI-edited version. Use the per-decision audit record to join the model event to the approved artifact.

Check 4: preserve the required books and records

Owner: records management with legal and compliance.

Pass condition: each covered artifact has a documented record category and retention period, plus legal-hold treatment and storage method. It also has a production procedure. A selected record and its audit trail can be exported promptly in readable and usable electronic forms. The firm can recreate the original after a modification or deletion under the audit-trail option.

Evidence: retention schedule and storage design, audit-trail configuration and integrity result, backup or redundancy evidence and retrieval test, plus the export and production runbook. The SEC's Rule 17a-4 preserves business communications for at least three years, with the first two years readily accessible. Its electronic-recordkeeping provisions allow a complete time-stamped audit trail or records preserved exclusively in non-rewriteable, non-erasable form.

Remediate when: the only evidence is a screenshot of a retention setting. The firm must provide a retrieved historical record and its audit trail.

Check 5: supervise vendors and embedded AI

Owner: vendor management with compliance and legal, plus the business owner.

Pass condition: diligence covers the actual AI function and data use, subprocessors and change notices, security and continuity, plus evidence access and retention. It also covers deletion and incident support. The contract identifies responsibilities and gives the firm access to records needed for supervision and regulatory production. The inventory is updated when a vendor turns on an embedded AI capability.

Evidence: diligence file and contract clauses, data-flow review and provider and model register, change notification and test results, plus the exception decision and exit plan. FINRA makes the scope explicit in Notice 24-09: existing rules apply to third-party technology and embedded AI capabilities. Vendor procurement supports supervision; the member firm is responsible.

Remediate when: the vendor supplies a SOC 2 report but cannot identify the model endpoint or return event records for a selected transaction.

Check 6: enforce identity and route policy

Owner: application engineering and IAM, with security engineering responsible for the HTTP policy point.

Pass condition: the route diagram shows traffic moving from an authenticated application through the policy point to an approved LLM endpoint. The application supplies a stable user or agent identity and business-purpose context. Tests cover an approved destination and blocked destination, plus sensitive content and missing identity. They also cover a policy error. Bypass paths are blocked or documented with separate controls.

Evidence: route inventory and identity schema, policy version and declared test inputs, expected results and event records, plus the bypass test and exception ticket. The zero trust guide for AI systems explains the per-request authorization pattern after login.

Remediate when: the gateway sees only one shared relay account, or an application can call the provider around the policy point.

Check 7: prove the controls with selected samples

Owner: compliance testing or internal audit.

Pass condition: the reviewer freezes the population and selects both successful and unsuccessful events. One sample traces through identity and input, model destination and output, policy decision and principal review, plus the final communication and retained record. A second sample proves denial or exception handling. An old record proves retrieval and integrity.

Evidence: frozen manifest and selection method, completed trace and missing-join register, integrity test and historical export, plus findings and remediation owner. Include the target date and retest result. The AI audit log chain of custody guide provides the custody test for the event layer.

Remediate when: owners replace a failed selection with a cleaner row, or the trace depends on undocumented knowledge held by one engineer.

DeepInspect

DeepInspect evaluates authenticated HTTP traffic routed by the firm to LLM endpoints. It uses the identity and workflow context supplied by the calling application, then applies content and destination rules. It inspects the response. A signed, tamper-evident event records the policy version and decision.

That event supports Check 6 and the request-level portion of Check 7. The firm keeps responsibility for use-case scope and principal review, communication classification and record retention, plus vendor supervision and regulatory production. Direct browser sessions and local inference require separate controls. So does opaque embedded processing. Book a technical deep dive at deepinspect.ai.

Frequently asked questions

Is FINRA Regulatory Notice 24-09 a new AI rule?

FINRA states that the notice creates no new requirements or interpretations. It reminds firms that existing rules apply to GenAI uses. The checklist records that status and maps each workflow to the rules already governing the business activity.

Should every failed check stop production?

The accountable owner should define severity and interim measures before testing. A missing principal approval or uncontrolled customer communication normally demands immediate containment. A documentation gap may receive a dated remediation plan if the underlying control still operates and compliance approves the treatment.

Does a vendor approval pass Check 5?

Vendor approval is one part of the evidence. The firm also needs use-specific scope, responsibilities, data handling, change governance, record access, incident support, and an exit path. Testing should confirm the contract's evidence route works for a selected event.

Can an AI gateway approve retail communications?

A gateway can apply request and response policy to routed HTTP traffic. The registered principal and the firm's Rule 2210 process own communication approval. Preserve both records and join them with a stable identifier.

How often should the checklist run?

Set cadence by risk and written procedure. Run it again after a material model or provider change. A route or data-use change also triggers a run, as does a business-purpose change. Also rerun the affected checks after an incident or supervisory finding. Do the same after failed evidence retrieval.