← Blog

Wealth Management AI and FINRA Compliance

Broker-dealers and RIAs are wiring AI into research, client communications, and portfolio workflows, but FINRA supervision and books-and-records duties attach to the output. This walks through the obligations and the per-decision records that supply supervisory evidence.

ByParminder Singh· Founder & CEO, DeepInspect Inc.
Industry Verticalsai-compliancecomplianceregulationai-governanceauditai-security

A registered representative pastes a draft market commentary into a public chatbot and asks it to tighten the language for a client segment. The request leaves as an HTTPS POST to the model provider, and the edited text returns in a few seconds. FINRA Rule 2210 governs that text as a communication with the public the moment it reaches clients. FINRA Rule 3110 places the same output under the firm's supervisory system. SEC Rule 17a-4 makes it a record the firm has to preserve and produce when an examiner asks.

The AI call that produced the language usually leaves no independent trace of who asked, what went into the prompt, or what came back.

I want to walk through the three obligations that attach to AI-assisted output at a broker-dealer or RIA, why application-controlled logs fail a Rule 3110 review, and the record structure that supplies supervisory evidence.

FINRA rules attach to the AI-assisted output

FINRA supervises broker-dealers, and it has stated that its existing rules are technology-neutral and apply to a member's use of AI tools the same way they apply to any other tool. The guidance FINRA has published on artificial intelligence does not create a separate AI rulebook. The obligation attaches to what the representative sends, recommends, or files, regardless of how the draft was produced. Three rules carry most of the weight for a wealth management workflow.

Rule 3110 supervision

Rule 3110 requires each firm to establish and maintain a supervisory system, with written supervisory procedures, reasonably designed to achieve compliance. When a model drafts a client email or summarizes research, a principal still has to be able to review what was produced and show that the review happened.

Rule 2210 communications

Rule 2210 governs communications with the public. It sets content standards, principal approval, and recordkeeping for retail communications. An AI-assisted market commentary sent to clients is a retail communication and carries those approval and retention duties.

SEC Rule 17a-4 recordkeeping

SEC Rule 17a-4 sets the books-and-records retention regime for broker-dealers. Communications relating to the firm's business have to be preserved in a compliant format for the periods the rule specifies, and produced to SEC or FINRA examiners on request.

Supervision under Rule 3110 turns on evidence a reviewer can reconstruct

A supervisory system under Rule 3110 has to do more than exist on paper. When FINRA examines it, the firm shows how a principal reviewed specific communications and recommendations. For an AI-assisted workflow, that means answering concrete questions about a particular client email or portfolio note. Who prompted the model? What did the prompt contain? Which client or account context was in scope? What did the model return, and what did the representative change before it went out?

Authentication alone does not answer those questions. The representative logged into the firm's tools and into the AI application, so the identity of the human is known at login. The supervisory record still has to connect that identity to the specific AI call and its content. This is the post-authentication gap: the user is authenticated, but no record ties this authenticated person to this prompt, this response, and the policy in effect at that moment.

Application-controlled logs fail the supervision test

The common answer is to rely on the logs the AI application writes. That reproduces the self-attestation problem regulators reject in every other part of the business. The system that generates the output also writes the record of what it did, which means the record inherits three failure modes. The application can log the clean cases and skip the edge cases. The log can be edited or purged by the same system that produced it. The application can crash after the model responds but before the record commits, so the communication went to the client and the evidence never landed.

There is a second gap. When a research analyst uses a personal chatbot account instead of a sanctioned tool, the firm's supervisory system never sees the call at all. IBM's Cost of a Data Breach research reports that one in five breached organizations traced the incident to shadow AI, and that shadow AI breaches cost $670,000 more on average than standard breaches. Vendor tools that embed model calls create the same blind spot. I covered who owns that exposure in You Own the AI Liability, Not the Vendor.

SEC Rule 17a-4 sets the retention and integrity bar

Retention is where format matters. SEC Rule 17a-4 has long required that covered records be kept in a non-rewriteable, non-erasable form, or under an arrangement that preserves a complete audit trail of any change, so that a record cannot be altered after the fact without evidence of the alteration. A log the application can quietly overwrite does not meet that bar, and an examiner who suspects gaps will treat a mutable log as unreliable.

For AI-assisted communications, this means the record of the call needs the same integrity properties the firm already applies to email and order records. The evidence has to survive for the multi-year periods 17a-4 assigns by record category and stay producible to SEC and FINRA examiners. Audit-log integrity is the property that separates a system of record from a convenience log. A record that the producing application can edit reads as a convenience artifact rather than evidence.

Identity-aware policy and a per-decision record supply the evidence

The evidence a Rule 3110 review needs has a specific shape. For every AI call tied to client-facing work, the firm should be able to produce a record that carries a verified identity for the representative or agent behind the request, the role and authorization in effect, the data classification of the prompt content, the policy version that governed the call, the model and endpoint used, the decision outcome, and a precise timestamp. That record has to be written by something other than the application under review, and committed before the response returns.

That structure also answers Regulation Best Interest. When a recommendation is AI-assisted, Reg BI still requires the firm to show the basis for the recommendation, and the per-decision audit record captures the inputs and policy at the moment of the call. The same record satisfies parallel regimes. EU AI Act Article 12 requires automatic recording of events over the system lifetime, including timestamps, input data, and identification of the natural persons involved. I walked through the financial-sector version of this in AI compliance in banking.

DeepInspect

This is the record DeepInspect produces. DeepInspect is a stateless proxy that sits between authenticated users or agents and the LLM endpoints they call. For every request and response, it evaluates identity, role, data classification, model authorization, and firm policy, makes a pass or block decision inline, and commits a signed, tamper-evident record before the model's output reaches the application.

For a broker-dealer or RIA, that record is the supervisory evidence Rule 3110 review and 17a-4 retention depend on. It shows which representative prompted the model, what classification applied to the content, which policy governed the call, and what came back, in a form the producing application cannot alter after the fact. DeepInspect is model-agnostic, so the same record covers OpenAI, Anthropic, Azure OpenAI, Bedrock, and self-hosted endpoints behind one policy.

The gateway sits on the AI request path, which makes the record a structural product of every call rather than a feature the application has to remember to write. Book a demo today.

Frequently asked questions

Does FINRA regulate the AI tool or the output it produces?

FINRA regulates the member firm's conduct, and the obligation attaches to the output and the recommendation, not to the software that drafted them. FINRA has said its existing rules are technology-neutral, so a client email drafted with a model is governed by Rule 2210, a recommendation informed by a model is governed by Regulation Best Interest, and the supervisory duty under Rule 3110 covers both. The practical consequence is that a firm cannot point to a vendor's model card or SOC 2 report as the answer to a supervision question. The examiner asks what the firm did with the tool: how it reviewed the output, what policy governed the use, and what record it kept. A firm that treats the model as the regulated object misreads where the duty sits. The duty sits with the firm and its supervisory system, and the record has to reflect that.

Which FINRA rule covers AI-generated client communications?

Communications with the public fall under FINRA Rule 2210. It classifies communications into retail communications, correspondence, and institutional communications, and it sets content standards, principal approval requirements, and recordkeeping for each. An AI-assisted market commentary or newsletter sent to more than 25 retail investors within a 30-day period is a retail communication, which generally requires principal approval before use and preservation under the rule. The fact that a model produced the first draft does not change the classification or the approval duty. Rule 2210 also prohibits false, exaggerated, or misleading claims, which is a live concern when a model can produce fluent text that overstates performance or omits risk. The reviewing principal has to catch that before it reaches clients, and the firm has to keep the record showing the review. SEC Rule 17a-4 then governs how long that record is retained.

Do our application logs satisfy SEC Rule 17a-4?

Usually not on their own. SEC Rule 17a-4 expects covered records to be preserved in a non-rewriteable, non-erasable format, or under an audit-trail arrangement that captures any change to a record. A standard application log stored in a database the same application controls fails that expectation, because the system that wrote the log can also modify or delete it. The log also tends to miss the fields an examiner needs for an AI call: the verified identity behind the prompt, the data classification, and the policy in effect. The retention duty runs for the multi-year periods 17a-4 assigns by record type, and the records have to be producible to SEC and FINRA examiners on request. A record produced and held by an independent layer, committed before the response returns and preserved in tamper-evident form, meets the integrity and retention requirements that an application log alone does not.

How does Regulation Best Interest apply to AI-assisted recommendations?

Regulation Best Interest requires a broker-dealer to have a reasonable basis for a recommendation and to act in the retail customer's best interest at the time it is made. When a model helps generate or screen a recommendation, Reg BI does not shift because a machine was involved. The firm still has to show the basis: the inputs considered, the account context, and the reasoning that supported the recommendation. That is difficult to reconstruct after the fact if the AI call left no record of what data went into the prompt or what the model returned. A per-decision record that captures the identity, the prompt classification, the policy, and the outcome at the moment of the call gives the firm the contemporaneous evidence a Reg BI review depends on. Absent that record, the firm is reconstructing intent from memory months later, which is a weak position in an examination or an arbitration.

What does a firm need to produce if FINRA examines an AI-assisted communication?

An examiner reviewing an AI-assisted communication asks a specific set of questions. Which representative or agent initiated the request? What was in the prompt, and what client or account context applied? What did the model return, and what was changed before the communication went out? Which principal approved it under Rule 2210, and when? Under what policy was the AI use permitted? The firm answers with records, not recollection. That means a contemporaneous, tamper-evident record of the AI call tied to a verified identity, plus the supervisory review record and the retained communication under SEC Rule 17a-4. If the only artifact is an application log the firm cannot prove is complete or unaltered, the examiner is likely to record a finding rather than a clean review. The record structure has to exist before the examination, because it holds no credibility if it is recreated afterward.

Does this apply to an RIA, or only to a FINRA member broker-dealer?

The specific rule citations differ by registration, but the underlying duty is the same. FINRA Rules 3110 and 2210 and SEC Rule 17a-4 apply to broker-dealers that are FINRA members. A registered investment adviser reports to the SEC or a state under the Investment Advisers Act and faces parallel obligations: a recordkeeping duty for communications and recommendations, an advertising and marketing standard, and a general duty to supervise its personnel and service providers. Dually registered firms are common in wealth management, so both regimes apply to the same advisor depending on the capacity in which the advisor is acting. In every version, the supervisory and recordkeeping duty attaches to the AI-assisted output, and the firm needs a contemporaneous record of the AI call tied to a verified identity. The registration category changes which rule number the examiner cites. The evidence the firm has to produce stays the same.