
An examiner asks your CCO a simple question: "Show me your firm's policy on artificial intelligence, and show me how you know people are following it." A cyber-insurance underwriter asks a version of the same thing on your renewal application. Most advisory firms can answer the first half — they have a document — and freeze on the second. That gap is the whole problem, and it's why so many AI use policies end up doing more harm than the risk they were meant to cover.
Here's the part that makes it urgent. You almost certainly already have AI running inside your firm. Someone is pasting meeting notes into a free chatbot to draft a client email. A planner is running an AI note-taker on Zoom calls. Your CRM quietly shipped an "AI assistant" in its last update. None of it went through compliance. A written AI use policy is how you find that activity, decide what's allowed, and — the part everyone skips — make it something you can prove at exam or on an insurance application.
What an AI use policy is (and the one principle that changes how you write it)
An AI use policy for a financial advisory firm is a written standard that defines which AI tools your people may use, what client and firm data those tools are allowed to touch, who reviews AI-assisted work before it reaches a client, and how you keep evidence that the rules are being followed. It sits alongside your existing compliance and information-security policies rather than replacing them.
The principle that separates a useful policy from a dangerous one: write it backward from the evidence you'll be asked to produce. A policy is not a statement of good intentions. Once it's written, it becomes a standard you're on record for. If your document says "all AI-generated client communications are reviewed by a licensed advisor" and you have no record showing that review happened, you haven't reduced your risk — you've written down a rule you can be shown to have broken. So before drafting a single "the firm shall" sentence, get honest about two things: what AI is actually in the building, and what you could hand an examiner tomorrow to show the rule is real. Those two questions — inventory and evidence — should drive every clause.
That maps to the four questions we use to frame any AI governance work: what AI is being used, what data is exposed to it, what controls exist, and what regulatory and business risk is left over. A good policy answers all four in a way you can back up with proof.
Step 1 — Inventory the AI already in your firm
You can't write a policy for tools you can't name. Start by finding the AI already in use, sanctioned or not. Ask every team what they use to draft, summarize, transcribe, research, or analyze — and check the features your existing vendors turned on without asking. The goal isn't to punish anyone for the note-taker they've been using since spring. It's to bring that activity back under the umbrella where you can govern it. Shadow AI you don't know about is the exposure; shadow AI you've inventoried is just a tool waiting for a rule.
Write down each tool, who uses it, and for what. This list becomes the backbone of the policy and the first thing you can show that proves the policy is grounded in reality rather than copied from a template.
Step 2 — Map what data each tool touches
For every tool on the inventory, ask what information goes into it. Client names, account numbers, Social Security numbers, portfolio holdings, and planning details are the categories that turn an everyday software tool into a data-handling and privacy question. Under current public guidance, safeguarding client information is governed by regimes such as SEC Regulation S-P and the FTC Safeguards Rule under the Gramm-Leach-Bliley Act (GLBA), and pasting nonpublic personal information into a consumer AI tool that trains on its inputs is exactly the kind of exposure those rules speak to. Verify how each tool handles, stores, and retains what you send it before you decide it's allowed — that's vendor due diligence, and it belongs in the record.
Step 3 — Decide the controls, in plain language
Now write the rules, and make each one specific enough to test. A workable AI use policy for a financial advisory firm usually covers:
- Approved and prohibited tools. Name what's allowed for what purpose, and state plainly what's off-limits — for example, no client nonpublic personal information in any tool that hasn't been reviewed and approved.
- Data handling. What may be entered, what must never be, and how outputs are stored and retained.
- Human review. Who checks AI-assisted client communications, marketing, and advice-adjacent content before it goes out, and how that sign-off is recorded. Framing AI output as final client-facing work without a human standard is where advice, marketing, and recordkeeping obligations collide.
- Recordkeeping. How AI-assisted communications and their review are captured, consistent with your books-and-records obligations.
- Roles and oversight. Who owns the policy, who approves new tools, and how exceptions get requested.
- Training and enforcement. How staff are trained on the rules and what happens when someone steps outside them.
Write each control as something a person could produce evidence for. "Advisors review AI-drafted emails" is aspirational. "AI-drafted client emails are routed through [the firm's review queue] and the reviewer is logged before send" is provable.
Step 4 — Build the evidence in, not on top
This is the step the ranking templates leave out. For every rule, decide up front how you'll show it's being followed: the tool inventory, the vendor due-diligence file, the review log, the training sign-offs, the record of exceptions granted. If a clause has no evidence attached to it, you have two choices — build a way to capture that evidence, or soften the clause to what you can actually demonstrate. A shorter policy you can prove beats a comprehensive one you can't. This is also what an underwriter is really probing on a cyber-insurance application: not whether you have a document, but whether the controls behind it are live.
What to do, in order
Inventory the AI in use first. Map the data each tool touches and run basic vendor due diligence. Draft the controls in plain, testable language. Decide the evidence for each control and set up how you'll capture it. Then socialize the policy, train the team, and put it on a real review cadence — quarterly is a reasonable starting point given how fast these tools change. Skipping straight to "draft the controls" from a template is how firms end up with a binder that reads well and proves nothing.
Frequently asked questions
Does every advisory firm need an AI use policy? If anyone at the firm uses AI in any form — and, after Step 1, most firms find they do — you need a written standard governing it. Even a firm that has decided to use no AI benefits from a short policy saying exactly that, because it turns an unmanaged risk into a documented decision.
Should we use a template or write our own? A template is a fine outline and a poor policy. The parts that carry weight — your specific tool inventory, your data map, your review workflow, your evidence — are unique to your firm and can't be copied in. Start from a structure, then make every clause reflect what you actually do.
What if we don't use AI yet? Write the policy anyway, and start it as a gate: no AI tool enters the firm until it's been inventoried, its data handling reviewed, and its use approved. It's far easier to hold a clean line than to claw back tools already in daily use.
Do we have to cover personal devices and free chatbots? Yes — that's usually where the real exposure lives. The policy should address AI used on personal accounts and devices for firm work, because a rule that only governs the tools you bought misses the ones people actually reach for.
How often should we review it? Often enough to keep pace with the tools and any regulatory developments. Many firms set a quarterly cadence and revisit sooner when a major tool or a new piece of guidance appears.
Where this leaves you
A strong AI use policy for a financial advisory firm isn't the longest one. It's the one built from the AI actually in your firm and backed by evidence you could hand an examiner or an underwriter without flinching. If you want a clear read on what AI is already in use, what data it touches, and where your policy would hold up or fall short, our AI Governance Assessment walks through exactly that — the four governance questions, applied to your firm, with a prioritized path to close the gaps. It's the difference between a document and a defensible position.

