
This blog is part of our Defensible AI series for RIAs, focused on how existing compliance obligations apply to artificial intelligence use.
This article explains why AI governance is already a compliance priority across supervision, privacy, fiduciary duty, records, and investor protection.
We also look at why vendor oversight is now central to AI governance as third-party platforms add AI features that impact firm data and workflows.
Read Chapter: 1 | 2 | 3 | 4 | 5
For many RIAs, AI adoption is already happening through existing vendors. CRM systems, compliance platforms, investment portfolio tools, cybersecurity providers, and communication platforms are rapidly adding AI capabilities into their products which firms already use every day.
Others implement AI through software upgrades, vendor platforms, browser extensions, personal subscriptions, or employee workarounds. For RIAs and broker-dealers, this creates a difficult operating reality.
AI governance starts with visibility.
Before your firm can supervise AI use, it needs to know where AI exists, what data it touches, and which workflows may create regulatory exposure.
See how SurgeONE helps RIAs build defensible AI oversight.
The challenge is that these AI-centric updates can introduce new compliance, privacy, supervision, and recordkeeping risks without firms fully understanding how the AI works, what data it can access, or how outputs are generated. As a result, vendor oversight is no longer just an IT or procurement exercise, it is now a core part of AI governance.
Many RIAs will not build their own AI systems. They will adopt AI through vendors. That may include compliance platforms, CRM systems, portfolio tools, cybersecurity tools, surveillance systems, marketing platforms, document systems, research tools, meeting tools, and workflow automation systems.
This creates a major governance issue: the firm may rely on AI functionality embedded in vendor platforms without fully understanding how it works, what data it uses, or what risks it introduces.
A vendor may have been in place for many years under a contract that never contemplated AI. But that same vendor may now have AI tools embedded in its system.
This is a practical and immediate concern. AI functionality can be introduced through product updates, feature releases, integrations, or optional modules. The firm may not view this as a new vendor relationship, but the risk profile may have changed.
Traditional vendor agreements may not adequately address AI. They may include confidentiality, data protection, service levels, and limitation of liability language, but not the specific issues created by AI models, prompts, outputs, training data, hallucinations, explainability, data retention, or human review.
Vendor contracts are becoming an active area of liability and negotiation. Vendors may try to tighten contract language to limit responsibility, while firms may demand more clarity about how the tool works and how risk is controlled.
RIAs should review vendor contracts with AI-specific questions in mind:
These questions should be part of vendor due diligence and ongoing vendor oversight.
Regulators tend to pursue the regulated entity when vendor systems fail in ways that affect regulated obligations. The same principle should guide AI oversight. A firm cannot assume that vendor use of AI shifts responsibility away from the firm.
If the vendor’s AI tool causes a supervisory failure, inaccurate output, data breach, or recordkeeping deficiency, the firm may still be asked why it approved the vendor, how it reviewed the tool, what controls it required, and how it monitored performance.
Vendor due diligence should therefore be risk-based. High-risk AI vendors should receive deeper review. A vendor that uses AI to summarize public content is not the same as a vendor that has access to client data, communications, compliance records, trading information, or supervisory workflows.
A risk-tiering model might consider:
AI vendors may promise to reduce headcount, streamline operations, and allow a smaller team to do the work of a larger one. But if vendors are asked to accept more liability for AI-driven errors, pricing and contract terms may change.
This matters for firm leadership. AI should not be evaluated only as a cost-saving tool. It should be evaluated as a risk-transfer and control issue. If a vendor promises major efficiency gains, the firm should ask what risk remains with the firm and what controls are necessary to make the workflow defensible.
In practice, firms should avoid replacing human judgment in high-risk functions without carefully assessing whether the AI system can be supervised, tested, explained, and documented.
AI vendor review should not be a one-time procurement exercise. AI systems change frequently. Software updates, model changes, new features, new data flows, and new integrations can alter risk.
AI is not a plug-and-play investment. For RIAs, ongoing due diligence should include periodic vendor reviews, contract updates, control testing, incident tracking, feature review, and confirmation that approved use remains consistent with the firm’s policy.
The firm should also require vendors to notify it of material AI-related changes. These may include:
The goal is to avoid a situation where a vendor relationship originally approved for one risk profile quietly evolves into something materially different.
AI may save time. But without governance, today’s efficiency can become tomorrow’s examination issue. Most RIAs will encounter AI through vendors before they ever deploy their own AI systems. That means firms need to understand not only which vendors use AI, but also how those tools impact client data, supervision, compliance processes, and operational risk.
Contracts should address data use, model training, retention, logs, security, liability, incident notification, and the firm’s ability to supervise and preserve records. Firms and RIAs need to verify whether vendor contracts have been reviewed for AI functionality, data use, liability, retention, and incident notification.
Vendor AI oversight cannot be treated as a one-time review. AI tools evolve constantly through updates, integrations, and new features that can materially change a platform’s risk profile over time. AI vendor due diligence should be risk-based and a continuous, ongoing process.