The AI Governance Audit Checklist: Can Your Firm Pass an SEC Exam in 90 Days?
Dr. Leigh Coney
Founder, WorkWise Solutions
July 20, 2026
16 min read
TLDR: Most firms could not produce their AI governance documents fast if an SEC examiner asked. Grant Thornton's 2026 AI Impact Survey found that about 78 percent of leaders were not confident they could pass an AI governance audit within 90 days, a gap the survey named the AI proof gap. This is the checklist that closes it. It maps the six control areas an examiner tests, the Rule 206(4)-7 compliance program, the Marketing Rule, Rule 204-2 books and records, the Regulation S-P amendments effective June 3 2026, vendor and model risk, and the NIST AI RMF Govern function, to what an examiner expects and the exact document that proves it. Score each area green, yellow, or red, fix the reds first, and you can answer the request instead of scrambling.
Table of Contents
1. The Proof Gap: Why 90 Days Is the Test
Ask most investment firms whether their AI use is governed and they will say yes. Ask them to produce the documents that prove it, on a 90-day clock, and the confidence drops.
Grant Thornton's 2026 AI Impact Survey put a number on the gap: about 78 percent of leaders were not confident they could pass an AI governance audit within 90 days. The survey called it the AI proof gap, and the same research found firms with integrated AI were roughly four times more likely to report revenue growth. So the firms most exposed to a proof request are often the ones getting the most from AI.
Ninety days matters because that is roughly the window an SEC exam gives you between the document request and the interviews. Whether your firm uses AI responsibly matters less, in that window, than whether you can show it on paper. This checklist is built to produce that paper from what you already have or can assemble fast.
2. What This Checklist Covers, and Where the Exam Story Lives
This page is the actionable list. It names six control areas, tells you what an examiner expects in each, and points to the single document that proves it. You score yourself, find the gaps, and fix them in order of exposure.
If you want the narrative behind an exam, how the request arrives, who examiners interview, and how the AI portions fit inside a routine adviser exam, that lives in our companion guide, AI governance for an SEC exam. Read that for the story. Use this for the scoring. The two are meant to sit side by side.
One caveat before the list. This is operational guidance rather than legal advice. It helps you assemble evidence and find holes; your counsel and compliance consultant own the legal interpretation and the final call on what your firm files. With that said, the six rows below are where an adviser exam actually goes when AI is on the table.
3. The Rules an Examiner Actually Applies to AI
Start by clearing up a common belief: there is no standalone SEC AI rule for advisers to comply with. The agency proposed one and then pulled it back.
In 2023 the SEC proposed the predictive data analytics rule, aimed at conflicts of interest in how advisers and brokers use analytics and AI with investors. It drew heavy comment, and the SEC formally withdrew the proposal in June 2025 (release 33-11377, sec.gov). It is not in force, and you should not build a program around it.
That withdrawal changes less than it sounds. The obligations an examiner tests come from rules that already existed, applied to how you use AI: the compliance program rule, the Marketing Rule, the books and records rule, and Regulation S-P. The SEC Division of Examinations also named AI directly in its 2025 examination priorities (press release 2024-172, sec.gov), so the subject is live even without a dedicated rule.
The practical takeaway: your job is to show that your existing compliance obligations extend to the AI your team uses, not to chase a new AI rulebook that does not exist. That is a documentation job, which is exactly what the rest of this checklist maps.
4. The AI Governance Checklist at a Glance
Here is the whole checklist on one screen. Each row is a control area, what an examiner expects to see, and the document that proves it. The sections after this take each row in turn.
| Control area | What an examiner expects | The document that proves it |
|---|---|---|
| Compliance program (Rule 206(4)-7) | Written policies covering how the firm uses AI, reviewed at least annually under a designated CCO | An AI use policy inside the compliance manual; the annual review record; a named owner |
| Marketing and AI claims (Marketing Rule 206(4)-1) | Every AI claim in advertising is accurate and can be substantiated | A substantiation file for each AI claim; the marketing review and approval log |
| Books and records (Rule 204-2) | AI-assisted advertisements and communications retained for the required period | A retention schedule that names the AI tools; archived AI outputs that qualify as records |
| Customer data (Reg S-P, June 3 2026) | An incident-response program and safeguards for customer data moving through AI tools | The incident-response plan; a data-flow map for each AI vendor; the safeguards policy |
| Vendor and model risk | Diligence on AI vendors' data handling and a record of model changes | Vendor diligence files; data processing terms; a model or version change log |
| Governance (NIST AI RMF Govern) | A named accountable owner, an inventory of AI systems, and risk decisions on record | An AI system inventory; roles and responsibilities; a risk register or decision log |
Six rows, six proving documents. If you can put your hand on all six today, you are close to ready. The value of the table is that it turns a vague worry into a short, concrete punch list.
5. Rule 206(4)-7: The Compliance Program
This is the anchor row, and it is the one examiners open first. Rule 206(4)-7 requires a registered adviser to adopt and implement written policies and procedures reasonably designed to prevent violations, to review them at least annually, and to designate a chief compliance officer to run them.
Applied to AI, that means your compliance manual has to address AI use directly. Not a slogan, a policy: which tools are approved, what data is allowed on them, what is off limits, who signs off on new tools, and how the firm supervises all of it. If the manual is silent on AI while the team pastes deal data into chatbots every day, the gap between the paper and the practice is the finding.
The proving documents are three. The AI use policy inside the manual. The record of the annual review that looked at it. And a named owner, a person accountable when an examiner asks who runs this. Firms miss the review record most often: they write a decent policy once and never document that anyone looked at it again. A policy nobody reviews reads, to an examiner, like a policy nobody follows.
6. The Marketing Rule: Substantiating AI Claims
The Marketing Rule, Rule 206(4)-1, prohibits false or misleading statements in advertising and requires a reasonable basis for the material claims you make. This is where AI washing becomes an exam problem rather than a branding one.
If your pitch deck, website, or DDQ answer calls the firm AI-driven, an examiner can ask you to substantiate it. The SEC has already shown it will. Its first AI-washing cases, against Delphia and Global Predictions in March 2024, were charged under the Marketing Rule and the compliance rule, with settlements of about $225,000 and $175,000 (press release 2024-36, sec.gov). The then-chair publicly warned advisers against AI washing. The takeaway is straightforward. Describe your AI use in language you can back, and the rule protects you as much as it constrains you.
The proving document is a substantiation file: for each AI claim in your marketing, the evidence that supports it, plus the review and approval log showing a human signed off before it went out. The deeper method, including a before-and-after rewrite of the phrases that draw scrutiny, is in our guide on AI washing in LP materials.
7. Rule 204-2: Books and Records
Rule 204-2, the books and records rule, requires advisers to keep records of advertisements and certain communications, and to retain them for the periods the rule specifies. What has to be kept stays the same when AI enters the picture. What changes is where the records now live.
If an AI tool drafts a client email, a marketing claim, or a piece of investor communication, that output can be a record. So your retention has to reach the AI tools, not stop at the email server. The common failure is a blind spot: the firm has a solid retention policy that predates the chatbots, and nobody updated it when the team started drafting in them.
The proving document is a retention schedule that names the AI tools in use and states how their outputs are captured and kept. Where prompts and outputs qualify as records, they belong in the archive on the same schedule as everything else. Examiners expect the records the rule already covers to survive the fact that AI helped write them, not a log of every keystroke.
8. Reg S-P: The June 3 2026 Deadline
This row has a date on it, which makes it the most time-sensitive item on the list. Amendments to Regulation S-P carry a compliance date of June 3 2026 for larger entities, with smaller firms following later. They require an incident-response program and safeguards for customer information.
AI pulls this row into scope in a way it was not before. Any AI vendor that touches customer data sits inside the safeguards requirement, and any incident involving that vendor sits inside your incident-response obligation. A model provider processing client information is a service provider you now have to account for, the same as any other.
Three proving documents. The incident-response plan, updated to cover an AI-vendor breach. A data-flow map showing what customer data reaches which AI tool and where it goes. And the safeguards policy that governs it. Because this row has a hard date, it belongs near the top of the fix list even if the exam is not scheduled: the deadline arrives whether or not an examiner does. The wider control set is in our guide to AI for PE compliance and regulatory reporting.
9. Vendor Risk, Model Risk, and the Govern Function
The last two rows trace to something broader than a single SEC rule: the general duty to run a reasonable compliance program, and the framework examiners increasingly recognize as a standard of care.
Vendor and model risk is the diligence you do on the AI tools themselves. Does the vendor train on your data? What is retained, and for how long? Who are the sub-processors? When the model changes under you, is there a record? The proving documents are your vendor diligence files, the data processing terms you agreed, and a change log that tracks model or version updates. Model changes matter more than firms expect: a tool that behaved one way in your testing can behave differently after a silent update, and the log is how you show you noticed.
The governance row is where you show a structure, not just a stack of tools. The NIST AI Risk Management Framework organizes AI risk into four functions, Govern, Map, Measure, and Manage, with Govern as the foundation that the other three sit on. In practice that means three artifacts: an inventory of the AI systems the firm runs, written roles and responsibilities, and a risk register or decision log that records the calls you made and why. NIST is voluntary, not law, but it gives an examiner a recognizable shape for a reasonable program, which is worth more than a folder of unstructured notes.
10. Score Yourself: Green, Yellow, Red
Now make it a score. For each of the six rows, mark one color and be honest, because an examiner will be.
Green. The proving document exists, it is current, and it has a named owner who could hand it over this week. Yellow. Something exists, but it is stale, partial, or nobody owns it. A policy last reviewed two years ago is yellow. Red. The document does not exist. Use one blunt test to sort yellow from red: if you cannot produce the proving document in an afternoon, treat it as red.
Then fix by exposure, not by ease. Reds in the compliance program, the Marketing Rule, and the Reg S-P rows come first, because those are the rows an examiner opens first and the ones with a rule and, for Reg S-P, a date behind them. Vendor risk and the Govern function can trail slightly, though a firm with reds across all six should assume it is not exam-ready and plan accordingly.
The point of the color pass is speed. It converts a fog of worry into a ranked list of documents to write, and it tells you, roughly, how far from 90-day ready you actually are. Most firms find they are greener than they feared on two rows and redder than they hoped on two others. That is a good outcome: it is a plan.
11. Where to Start
Do the color pass this week. It takes an hour and tells you where you stand. Then write the reds in exposure order, starting with the AI use policy inside the compliance manual, because it anchors everything else and it is the document an examiner asks for first.
Work one row at a time. A firm that assembles all six proving documents, gives each a named owner, and runs one honest annual review has done most of what an adviser exam on AI actually tests. When LPs ask the same questions during diligence, and they increasingly do, the same file answers them; our guide on what to tell LPs about AI covers that side.
If you would rather have the file built with you than assemble it alone, our SEC Exam-Ready AI Governance package assembles all six rows into the evidence set an examiner expects, plus a mock exam, for $17,500. If an exam letter is already in hand, the Exam Response track runs it on a compressed clock for $25,000, and a Governance Refresh keeps the file current at $2,500 per quarter as rules and tools change. The paper is the point. Build it before you need it, and the 90-day clock stops being a threat.
"The AI Risk Management Framework is intended for voluntary use and to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems."
NIST, AI Risk Management Framework (AI 100-1)
- •Grant Thornton's 2026 survey found about 78 percent of leaders were not confident they could pass an AI governance audit within 90 days. This checklist exists to close that proof gap before an exam does.
- •There is no standalone SEC AI rule for advisers. The proposed predictive data analytics rule was withdrawn in June 2025, so examiners apply existing rules to how you use AI.
- •Rule 206(4)-7 is the anchor: your written compliance policies have to say how the firm uses AI, who owns it, and what is off limits, reviewed at least annually.
- •The Marketing Rule is where AI washing lives. Any AI claim in a deck or on the website has to be substantiated, and the SEC's first AI-washing cases were charged under it.
- •Reg S-P amendments carry a June 3 2026 compliance date for larger entities, pulling every AI vendor that touches customer data into an incident-response and safeguards requirement.
- •The NIST AI RMF Govern function gives you the structure examiners recognize: a named owner, an inventory of AI systems, and risk decisions on record.
- •Score each row green, yellow, or red. If you cannot produce the proving document in an afternoon it is red, and reds in the compliance program, Marketing Rule, and Reg S-P rows get fixed first.
Frequently Asked Questions
Can an investment firm pass an SEC AI audit?
Yes, if it can produce the documents that prove its AI use is governed. There is no separate AI exam; examiners apply existing rules, so passing means showing an AI use policy inside your compliance manual (Rule 206(4)-7), substantiation for any AI marketing claim (the Marketing Rule), retained AI-assisted records (Rule 204-2), and Reg S-P safeguards for customer data. Grant Thornton found about 78 percent of leaders were not confident they could do this within 90 days, which makes it a documentation gap more than a technology one.
What do SEC examiners ask about AI?
They ask how the firm uses AI, who is accountable for it, and whether the claims the firm makes about AI are true. In practice that becomes requests for your AI use policy and its annual review, an inventory of the AI tools in use, the substantiation behind any AI-driven marketing language, your books-and-records retention covering AI outputs, and your Reg S-P incident-response plan. The 2025 examination priorities from the SEC Division of Examinations name AI directly (press release 2024-172), so the questions are current.
What documents prove AI governance to the SEC?
Six documents carry most of the weight: an AI use policy inside the compliance manual with its annual review record, a substantiation file for each AI marketing claim, a retention schedule that reaches your AI tools, a Reg S-P incident-response plan and vendor data-flow map, AI vendor diligence files, and an AI system inventory with a named owner and a risk register. Our SEC Exam-Ready AI Governance package assembles these into the evidence file an examiner expects for $17,500.
Related Guides & Articles
AI Governance for an SEC Exam
The companion narrative: how the request arrives, who examiners interview, and how the AI portions fit inside a routine adviser exam.
AI for PE Compliance and Regulatory Reporting
The wider control set the Reg S-P and books-and-records rows plug into: compliance workflows, reporting, and where AI fits under supervision.
AI Washing in LP Materials
The Marketing Rule row in depth: the phrasing that draws scrutiny and how to reword it into substantiated language, with a before-and-after table.
What to Tell LPs About AI
The same governance file, turned toward LP diligence: what investors ask about your AI use and how to answer it straight.
Can you produce the file in 90 days?
Run the color pass, then close the reds. Our SEC Exam-Ready AI Governance package assembles all six control rows into the evidence set an examiner expects, plus a mock exam, for $17,500. If an exam letter is already in hand, the Exam Response track runs it on a compressed clock for $25,000, and a Governance Refresh keeps the file current at $2,500 per quarter. This is operational documentation built alongside your counsel, who owns the legal interpretation.
Book a Call