FINRA AI Controls Mapping for Broker-Dealer Supervision
This FINRA AI controls mapping connects supervisory, communications, recordkeeping, vendor, and routed-request objectives to accountable owners, control points, repeatable tests, retained evidence, and explicit gaps. It separates FINRA source language from implementation choices and gives an HTTP gateway credit only for decision evidence on traffic that actually traverses it.

A control map row labelled FINRA compliance: covered tells a CCO nothing about the Bloomberg commentary drafted by an LLM at 09:17 UTC. A useful FINRA AI controls mapping names the obligation and owner, then records the decision point and test, along with the evidence and boundary. It also leaves a red gap where the firm's architecture misses a route or a supervisory join. I prefer an honest partial row to a green square that collapses during the first sample request.
TL;DR
- Map the source anchor and objective, then name the owner and control point. Record the test and evidence, along with the boundary.
- Keep AI guidance in its stated role; FINRA applies existing technology-neutral rules to each business use.
- Split supervisory-system control, communication approval, electronic-record integrity, and request-route enforcement.
- Mark gateway coverage partial unless authenticated HTTP traffic is routed through the control and joined to firm records.
Map source status before product coverage
FINRA's artificial intelligence topic page states that existing FINRA rules and securities laws continue to apply when members use GenAI, including internally developed systems and third-party tools where AI is embedded. It also states that the page is informational and creates no new legal requirements. Put those two facts at the top of the map.
Regulatory Notice 24-09 uses the same technology-neutral frame. It connects GenAI business use to existing obligations and explains that applicable rules depend on deployment. The notice names Rule 3110 for supervision and Rule 2210 for communications, while noting that GenAI could implicate nearly every area of a member's duties.
Each map row should therefore contain an exact source anchor and scoped objective. Add the accountable owner and operational control point. Record the repeatable test and retained evidence, then the known bypass and remediation status. A product capability is in the implementation field. It never replaces the source or owner.
Rule 3110 supervisory-system control
Objective: place each material AI business use inside a reasonably designed supervisory system and written procedures tailored to the firm's business under FINRA Rule 3110.
Owner and control point: final responsibility for proper supervision rests with the member. The firm should designate appropriately registered principals with authority for the relevant supervisory responsibilities. Its governance may also assign administrative or compliance responsibilities to the CCO. The use-case approval gate, written procedure, and supervisory review workflow are operational control points.
Test and evidence: select one AI-assisted supervisory alert or customer-facing work item. Trace it to the approved use case and current procedure; the reviewer assignment and source records; the AI output and human disposition; and the escalation. Retain the procedure version and training record; the review event; the exception and finding; and the retest.
Boundary and gap: the request layer can preserve what a routed model call contained and which policy applied. It cannot judge the adequacy of written procedures or perform a principal's supervisory review. AI embedded in a vendor tool is a gap when it has no event export, even after procurement approves the vendor.
Rule 2210 communications control
Objective: classify AI-assisted communications and apply the firm's content, approval, review, and recordkeeping process to the exact version used.
Owner and control point: communications compliance owns classification and standards. The registered principal owns approval where required. The publishing or delivery release gate prevents an unapproved artifact from reaching its audience.
Test and evidence: choose one sent retail communication and retrieve the source prompt reference and model output; the edits and final approved version; the reviewer, approval timestamp, audience, and channel; and the send event. Confirm the delivered content matches the approved hash or version. Repeat with a rejected draft containing an unsupported performance statement.
Boundary and gap: FINRA's Rule 2210 page is the source anchor. An HTTP policy can detect or route content for review, while final classification and principal approval are the firm's responsibility. The wealth management FINRA article covers the broader business context; this row turns one communication into a runnable control test.
Rule 4511 and SEC recordkeeping control
Objective: preserve books and records required under FINRA and Exchange Act rules, along with the firm's record schedule, in an approved medium for the applicable period, then produce them promptly.
Owner and control point: records management owns classification; retention and legal hold; indexing; and production. Compliance and legal approve the schedule. The electronic recordkeeping system controls custody and retrieval.
Test and evidence: select an old AI-assisted communication. Retrieve the original and approval; the AI event; the audit trail and index; and the policy record. Export the package in human-readable and usable electronic forms. Modify a staged copy and verify that the audit trail preserves the original plus the actor and timestamp. Test redundancy separately.
Boundary and gap: FINRA Rule 4511 is the FINRA books-and-records anchor. The SEC's Rule 17a-4 electronic recordkeeping provisions allow either a complete time-stamped audit trail or records preserved exclusively in non-rewriteable, non-erasable form. A signed request event can support the package. Records counsel decides its category and retention.
Third-party and embedded-AI control
Objective: keep vendor and embedded AI uses inside the same supervisory system, with evidence rights plus change governance matched to the business activity.
Owner and control point: vendor management runs diligence and monitoring. Legal controls contract terms. Compliance and the business owner approve the use. Change intake is the decision point when a provider changes a model, data practice, subprocessor, or AI capability embedded in the tool.
Test and evidence: select a vendor workflow. Produce the data flow and model destination; the approved use and diligence; the contract responsibilities, record-access clause, change notice, and latest review; and the incident path and exit plan. Request event evidence for one sample and preserve the vendor's response.
Boundary and gap: Notice 24-09 expressly includes third parties and AI embedded in other tools. A provider assurance report supports diligence but leaves transaction-level supervision unanswered. AI vendor risk management can carry the procurement evidence, while this map requires a join back to the FINRA-governed workflow.
Routed-request policy and evidence control
Objective: make an identity-aware decision before approved applications send content to an external LLM, then retain a trustworthy event for the routed call.
Owner and control point: IAM owns identity proofing and role lifecycle. The application owner supplies the user or agent identity and business-purpose context. Security engineering owns route completeness and the HTTP policy point. Records management owns downstream retention when the event enters a required record set.
Test and evidence: send declared synthetic inputs through an approved application. Cover an approved and disallowed model; sensitive content and missing identity; a policy exception; and a service error. Retain the application and principal; the model endpoint and content classification; the policy version, action, timestamp, and response disposition; and the integrity result and correlation identifier. Then attempt a direct provider call and record the expected block or documented bypass.
Boundary and gap: this row covers authenticated HTTP traffic that traverses the policy point. Direct browser sessions, local inference, stolen credentials, and opaque vendor-managed model calls are outside this control. The tamper-evident audit log guide explains the independent custody test.
Review status and open gaps
A map is operational when a reviewer can rerun every test. Record the environment and declared inputs; the expected outcome and evidence location; the last execution date and result; and the owner and next review. Mark partial coverage as partial. Give each gap an interim measure and due date, plus a closure test.
Avoid aggregate percentages. A slide reporting 92% compliant can hide the one client-communication route that bypasses approval. Put that route in red, with its owner and traffic volume beside it. Also keep the supervisory join visible. A technically complete model event still needs the communication record and principal disposition before the FINRA row closes.
The map should show shared evidence without merging responsibilities. One timestamped model event may support supervision; communications testing and an investigation. Each row retains its own objective, owner, pass condition, and legal scope.
DeepInspect
DeepInspect is a stateless proxy for authenticated HTTP traffic routed to LLM endpoints. It evaluates application-supplied identity and workflow context; classifies content; enforces destination and policy rules; and inspects responses before writing a signed, tamper-evident decision record.
In this map, DeepInspect contributes to the routed-request control and supplies event evidence that can join supervisory and communications samples. The firm keeps responsibility for route completeness and identity proofing; principal review; record classification and retention; and vendor oversight and regulatory production. Book a technical deep dive at deepinspect.ai.
Frequently asked questions
- Can one control map to several FINRA rules?
Yes. Keep separate source anchors and objectives within the map. Shared evidence can appear in several rows, but a request event supporting supervision does not automatically prove communication approval or compliant retention.
- What belongs in the boundary field?
Name the applications, routes, data, and period the control can observe. State required identity and workflow inputs. List bypasses and decisions owned elsewhere. A precise exclusion makes the remaining coverage testable.
- Who owns the model provider's version change?
The provider may issue the notice. The member firm owns the effect on its approved use and testing; its procedure; its communication process and records; and its customer impact. Assign that assessment before the provider changes production behavior.
- Can a signed gateway record close the Rule 3110 row?
It can prove bounded facts about a routed call and policy decision. The Rule 3110 row also needs the approved use and written procedure; the qualified reviewer; the supervisory outcome and exception treatment; and the testing evidence.
- How should a missing join appear?
Mark the row partial or failed and name the two records that cannot be connected. Assign an owner, interim measure, target date, and retest. A blank cell should never inherit green from an adjacent technical control.