Assess ▼
Enable ▼
Build ▼
Sustain ▼
Govern ▼
Research ▼
Resources ▼
About ▼
Contact
Buyer's Guide September 26, 2026

AI Governance Help for SEC-Registered Advisers: Law Firm, Compliance Consultant or Specialist?

Author

Dr. Leigh Coney

Founder, WorkWise Solutions

Published

September 26, 2026

Reading Time

13 min read

TLDR: Most SEC-registered advisers need two kinds of AI governance help, and they rarely come from the same place. Outside counsel interprets the rules and owns the legal calls. Someone else builds the documents an examiner will open: the AI use policy, the tool inventory, vendor files, evidence for every AI claim, and a Reg S-P incident plan that covers AI vendors. That builder can be a compliance consultancy such as ACA Group, a Big 4 risk practice, a specialist AI governance firm, or your own CCO. This guide compares the five by who each suits, typical cost, timeline and limits, then gives the questions to ask and the red flags to walk away from.

1. The Short Answer: Counsel Interprets, Someone Builds the File

If you run compliance at an SEC-registered adviser and want help with AI governance before an exam, you usually need two kinds of help. They rarely come from the same place.

The first kind interprets. Outside counsel tells you what the rules require of your firm, checks what you say about AI in Form ADV and your marketing, and handles anything that could turn into an enforcement matter. The second kind builds. Somebody has to produce the documents an examiner will actually open: an AI use policy, an inventory of the tools your people use, a diligence file on each AI vendor, the evidence behind every AI claim, and an incident-response plan that covers those vendors.

Trouble starts when one provider is asked to do both jobs. A law firm can write a fine policy, but paying legal rates for a tool inventory is an expensive way to get a spreadsheet. A consultant can build the file, but it cannot give you a legal opinion, and a good one will tell you so.

This guide compares the five places that help comes from, what each costs and where each falls short. One caveat runs through all of it: this is operational guidance. Your counsel owns the interpretation of the rules and the final call on what your firm says and files.

2. What an SEC Exam Tests on AI in 2026

Start with what any provider has to prepare you for. There is no standalone SEC rule on AI for advisers. The Commission proposed one in 2023, aimed at conflicts of interest in predictive data analytics, and formally withdrew it on June 12, 2025 along with other pending proposals. It is not in force, and a provider who builds your program around it is working from an old map.

AI stayed on the exam agenda anyway. The Division of Examinations' fiscal 2026 priorities, released in November 2025, say staff will review firms' representations about their AI capabilities for accuracy and assess whether firms have adequate policies and procedures to monitor and supervise their use of AI. The 2025 priorities named AI too.

The obligations behind those reviews come from rules you already live under:

  • Rule 206(4)-7, the compliance program rule. Written policies reasonably designed to prevent violations, reviewed at least annually and run by a chief compliance officer. If your people use AI, the policies have to cover it.
  • The Marketing Rule, Rule 206(4)-1. Every AI claim in an advertisement has to be true and supportable. The SEC's first AI-washing cases against advisers, Delphia and Global Predictions in March 2024, were settled with findings of Marketing Rule violations and $400,000 in combined civil penalties (press release 2024-36).
  • Rule 204-2, books and records. An AI-drafted advertisement or client communication can be a record, so retention has to reach the AI tools.
  • Regulation S-P, as amended in 2024. An incident-response program, oversight of service providers that touch customer information, notice from those providers within 72 hours of a breach, and, in most cases, notice to affected individuals within 30 days. Advisers with $1.5 billion or more in assets under management had to comply by December 3, 2025, and all other SEC-registered advisers by June 3, 2026 (SEC compliance guide and adopting release). Any AI vendor that touches customer data sits inside this.

Many firms give that work a shape with the NIST AI Risk Management Framework. It is voluntary, and its four functions (Govern, Map, Measure, Manage) give an examiner a structure they recognize. NIST's Generative AI Profile (NIST AI 600-1, July 2024) applies it to the chat assistants and copilots your team actually uses.

Two notes on scope. Single-family offices that qualify for the SEC's family office exclusion sit outside the exam half of this guide, though the policy advice is still worth taking. And for a request-by-request walk through what examiners are asking, see the author's SSRN paper, The RIA's AI Governance Playbook: What SEC Examiners Are Asking in 2026. The AI governance audit checklist turns the same rules into a self-score.

3. Five Types of AI Governance Help at a Glance

Each type below can do part of the job. None does all of it well, so read the last column first.

Type of help Best for Typical cost Typical timeline Where it falls short
Outside counsel Interpreting the rules, reviewing ADV and marketing language, exam letters, enforcement risk, privileged advice Usually hourly; a scoped review commonly runs five figures, and exam or enforcement work more Days for one question, weeks for a full review An expensive way to build inventories and vendor files; policies can read like memos
Compliance consultancy (ACA Group and similar) Mock exams, compliance manual updates, testing, outsourced CCO support Fixed-fee projects, commonly five figures; ongoing support on retainer A few weeks per project Depth on specific AI tools varies by team; no legal advice
Big 4 risk practice Large and multi-entity managers; independent assurance over AI controls Enterprise pricing, commonly six figures and up Months Staffed and priced for large institutions; independence limits for audit clients
Specialist AI governance firm Small and mid-size advisers that want AI-specific documents on a fixed fee Fixed-fee packages, commonly five figures Two to six weeks for a document set Small benches and key-person risk; no legal advice; less exam history
In-house, led by the CCO A small, stable AI footprint and a CCO with time Staff time, plus any training and tools Often a quarter or more beside the day job No outside eyes; blind spots in tool settings and vendor terms

Many advisers end up combining two rows: counsel plus one builder. The next five sections take each type in turn.

4. Outside Counsel

Counsel is the only provider here that can tell you what the law requires of your firm and stand behind the answer. That matters most in three places: the words you use about AI in Form ADV, marketing and LP materials; any question that could become an enforcement matter; and advice you want protected by privilege.

The investment management and securities enforcement practices at large law firms see many exams and enforcement matters at once, which gives them a view of patterns no single adviser can see. Smaller securities law firms do similar work at lower rates, and many advisers already have one on call.

The limits are cost and form. Legal work is usually billed by the hour, so counsel is an expensive way to build a tool inventory or chase vendor contracts. And a policy written like a legal memo tends to sit in a drawer while the team keeps working the old way.

Best fit: every adviser, for interpretation. If you have an exam letter, a deficiency letter or a worry that something you said about AI was misleading, call counsel first.

5. Compliance Consultancies

Compliance consultancies are where many advisers already go for exam preparation, and AI is now part of the work. ACA Group is one example. It runs compliance reviews and mock exams with a team that includes former regulators, and it offers investment advisers AI risk assessments, governance design and AI-specific policies and procedures.

ACA also runs the annual Investment Management Compliance Testing Survey with the Investment Adviser Association and Yuter Compliance Consulting. In the 2026 edition, 85 percent of 411 responding firms named AI the hottest compliance topic of the year. Most had an AI acceptable use policy (86 percent), fewer had a formal AI governance committee (59 percent), and only 37 percent had policies governing how AI outputs are tested and validated. That gap is the work. Most advisers have written a policy, and far fewer can show how they check what the tools produce.

Best fit: advisers that want a mock exam and a compliance manual update from people who prepare firms for exams for a living, often inside a compliance relationship they already have.

Limits: depth on specific AI tools varies by team, so ask who on the engagement has configured the tools your people use and read their vendors' data terms. A consultancy also cannot give legal advice. Counsel still owns interpretation.

6. Big 4 Risk Practices

Each of the Big 4 has a named AI governance offering: Deloitte's Trustworthy AI, EY's Responsible AI framework, KPMG's Trusted AI framework and AI Trust services, and PwC's Assurance for AI, launched in June 2025 to give independent assurance over AI systems.

Their strength is scale and independence. A manager with several registered entities, operations in more than one country, or institutional investors who want a third party to test its AI controls is the client these practices are built for.

Best fit: large and multi-entity managers, and any firm that needs assurance over its AI controls from a name its investors already accept.

Limits: price and fit. The teams are staffed for large institutions, and a single-entity adviser with a dozen AI tools rarely needs an enterprise program. Independence cuts the other way too. If the same firm audits your funds, auditor independence rules can limit the non-audit work it may take on, so check before you scope anything.

7. Specialist AI Governance Consultants

A newer category of small firms works only, or mostly, on AI governance for investment firms. They write AI use policies, build tool inventories and vendor files, match AI claims in marketing to evidence, and run AI-focused mock exam sessions, usually for a fixed fee.

Their advantage is knowing the tools. A vendor file has to record how Microsoft 365 Copilot, ChatGPT Enterprise, Claude or Gemini handles your data under the plan you pay for, and that is where generic policies go wrong. A policy that says a tool keeps nothing, when your plan retains chat history, is a misstatement waiting for an examiner.

Best fit: small and mid-size advisers that use a handful of AI tools and want the documents built quickly by people who know those tools.

Limits: small teams, so ask who does the work and what happens if that person leaves. They are not law firms and should say so plainly. And most have less history with the exam process than a large compliance consultancy, so pair them with counsel.

8. Building It In-House Under the CCO

Plenty of advisers can do this themselves, especially when the AI footprint is one enterprise assistant and a note-taker. The CCO writes the policy, IT exports the tool list from the admin console, and someone reads each vendor's data terms and files them.

The cost is time, and time is the scarce thing in a compliance function. The survey numbers above show where the work tends to stall: the policy gets written, while testing, vendor files and marketing evidence wait for a quiet quarter that never comes.

Best fit: firms with a small, stable AI footprint and a CCO with real hours to give it.

Limits: no outside eyes before the examiner's, and blind spots in tool settings nobody at the firm configured. A short review by counsel or a consultant at the end is cheap insurance. Read the shadow AI guide first, because an inventory built from the approved list misses the tools people use anyway.

9. How to Choose AI Governance Help for an SEC Exam

Pick by the question you need answered. Brand size is a weak guide.

  • "What do the rules require of us, and is what we say about AI accurate?" Counsel.
  • "Would we get through an exam next month?" A mock exam from a compliance consultancy, or an AI-focused one from a specialist.
  • "Do we have the documents for the tools we actually use?" A specialist or your own CCO, with counsel reviewing.
  • "Can a third party vouch for our AI controls to investors?" A Big 4 assurance practice.
  • "We have an exam letter." Counsel first, then whoever can build the missing documents fastest.

A mid-size adviser usually lands on counsel plus one builder. Large multi-entity managers often pair a Big 4 practice for assurance with a compliance consultancy for exam preparation. A small adviser with a simple setup can build in-house and buy a review.

Where WorkWise fits

WorkWise Solutions, which publishes this guide, is in the specialist category: it builds the documents and works alongside your counsel, who owns the legal interpretation. Its AI Governance framework is $9,500 and covers an AI use policy, a supervision approach, a vendor diligence method, an LP DDQ answer bank and a disclosure review. The SEC Exam-Ready package is $17,500 for single-entity firms up to roughly 150 people and adds Reg S-P incident-response alignment, an examination file for each AI tool and a mock-exam walkthrough with the CCO. With an exam letter in hand, Exam Response runs that package on a two-week clock for $25,000, and a Governance Refresh keeps it current for $2,500 per quarter.

Not a fit if you need a legal opinion or representation in an enforcement matter (hire counsel), an outsourced CCO (a compliance consultancy does that), or independent assurance for a multi-entity global manager (a Big 4 practice). The rules this guide follows when it names providers are in how we evaluate tools.

10. Questions to Ask and Red Flags

Whichever type you hire, put these questions to them before you sign:

  • Who on the team has been through an SEC exam, from either side of the table?
  • Can you name the AI tools we use and say how each handles our data under the plan we pay for?
  • How does your work map to the fiscal 2026 exam priorities, the Marketing Rule, Rule 204-2 and Reg S-P?
  • What do we own at the end, and can our own staff keep it current?
  • Is the fee fixed or hourly, and what is excluded?
  • How will you work with our counsel, and where does your advice stop?

And walk away from any of these:

  • A promise of an "SEC-approved" or "fully compliant" AI program. The SEC does not approve programs, and nobody can promise an exam outcome.
  • A program built around the predictive data analytics rule, which was withdrawn in June 2025.
  • Legal conclusions from someone who is not your lawyer.
  • A policy template with no inventory of your actual tools behind it.
  • A claim that an AI vendor stores nothing, without the contract and plan terms to show it.
  • A software subscription sold as the whole answer. Tools can track controls, but someone still has to write the policy and sit with the examiner.

AI also has an enforcement home. In February 2025 the SEC set up a Cyber and Emerging Technologies Unit whose remit includes fraud committed using emerging technologies such as AI, so claims about AI remain an enforcement topic as well as an exam one.

11. Where to Start

Before you call anyone, list every AI tool your people use, approved or not, with an owner for each. That one page tells a provider more than an hour of discovery calls, and it tightens every quote you get.

Then split the questions into the ones that need counsel and the ones that need a builder, and put a date on both. The Reg S-P compliance dates have passed for every SEC-registered adviser, so an incident plan that ignores your AI vendors is already a gap.

If the exam letter arrives first, the SEC exam readiness guide explains how the request usually unfolds, and AI washing in LP materials covers the marketing claims examiners test.

"The Division will assess whether firms have implemented adequate policies and procedures to monitor and/or supervise their use of AI technologies, including for tasks related to fraud prevention and detection, back-office operations, anti-money laundering (AML), and trading functions, as applicable."

U.S. SEC Division of Examinations, Fiscal Year 2026 Examination Priorities (November 2025)

Key Takeaways
  • •Most SEC-registered advisers need two kinds of help: counsel to interpret the rules and own the legal calls, and a builder to produce the documents an examiner opens.
  • •There is no standalone SEC AI rule. The predictive data analytics proposal was withdrawn on June 12, 2025, so examiners apply the compliance program rule, the Marketing Rule, Rule 204-2 and Reg S-P to how you use AI.
  • •The fiscal 2026 exam priorities commit staff to checking the accuracy of AI claims and whether firms have adequate policies to supervise their AI use.
  • •Reg S-P compliance dates have passed for every SEC-registered adviser (December 3, 2025 at $1.5 billion or more in AUM, June 3, 2026 for the rest), which pulls AI vendors that touch customer data into incident response and service-provider oversight.
  • •Compliance consultancies such as ACA Group lead on mock exams, Big 4 practices on independent assurance at scale, specialists on AI-specific documents, and an in-house build suits a small, stable AI footprint.
  • •Ask every provider who on the team has been through an SEC exam and how your specific AI tools handle data under the plan you pay for.
  • •Walk away from promises of an SEC-approved program, anything built on the withdrawn rule, and legal conclusions from someone who is not your lawyer.

Frequently Asked Questions

Do I need an AI governance consultant for an SEC exam?

Not always. There is no standalone SEC AI rule, so an exam tests whether your existing compliance program, marketing claims, records and Reg S-P controls cover how you use AI. A firm with one enterprise assistant and a CCO who has time can build that file in-house and buy a review. Firms with several AI tools, AI claims in their marketing, or an exam letter in hand usually save time with outside help: counsel for interpretation, and a compliance consultancy or specialist to build the documents.

Should an RIA hire a law firm or a compliance consultant for AI governance?

Usually both, for different jobs. Counsel interprets the rules, reviews what you say about AI in Form ADV and marketing, and handles anything that could become an enforcement matter. A compliance consultant or specialist builds the documents an examiner opens: the AI use policy, tool inventory, vendor files, evidence for AI claims and a Reg S-P incident plan that covers AI vendors. Paying legal rates for the building work is expensive, and a consultant cannot give legal advice.

How much does AI governance help cost for an investment adviser?

It depends on the type of provider. Outside counsel usually bills by the hour, and a scoped review commonly runs five figures. Compliance consultancies and specialist firms tend to quote fixed fees, commonly five figures per project, and Big 4 programs are priced for large institutions, commonly six figures and up. An in-house build costs staff time. As one published example, WorkWise Solutions, which publishes this guide, charges $9,500 for its AI governance framework and $17,500 for its SEC exam-ready package.

Related Guides & Articles

Want the file built before the exam?

The SEC Exam-Ready AI Governance package builds the documents an examiner opens, with a mock-exam walkthrough, for $17,500. With an exam letter in hand, Exam Response runs it in two weeks for $25,000. It is operational documentation built alongside your counsel, who owns the legal interpretation.

Book a Call
Schedule Consultation