Claude for Financial Advisors Compliance: What the Plugin Checks and What Your Firm Still Owns
Dr. Leigh Coney
Founder, WorkWise Solutions
September 28, 2026
14 min read
TLDR: Claude for Financial Advisors compliance sits with your firm: no software can be compliant with SEC rules on its own, and Anthropic's plugin does not claim to be. Its /compliance skill pre-checks client-facing drafts against the Marketing Rule, antifraud duties, Rule 204-2 and, for dual registrants, Reg BI, then hands your CCO a draft review. Your firm still owns supervision, vendor oversight for Anthropic and each connector, accurate AI claims and records. Records are the biggest gap. The plugin has no archiving connector, and Claude's audit log exports hold events without chat content, so on Enterprise the Compliance API is the automated route from Claude to your archive.
Table of Contents
1. The Short Answer: Compliance Lives in Your Program
Anthropic launched Claude for Financial Advisors on September 14, 2026. No software can be compliant with SEC rules on its own, and this plugin does not claim to be.
Anthropic draws the line in its launch post: "Investment recommendations, client communications, compliance determinations, and other regulated activities remain subject to human review and approval." The plugin's README adds that the advisor must explicitly approve any action that writes back to an external system, such as a CRM update or a client draft.
So the plugin drafts, checks and waits for permission. Archiving, supervision, disclosure and every decision stay with your firm.
This guide goes rule by rule and ends with a go-live checklist for your CCO. It is operational guidance, and your counsel and CCO own the interpretation. The short FAQ answer has the one-paragraph version.
2. What the SEC Expects From Advisers Using AI
There is no standalone SEC rule on AI for advisers. The Commission proposed one in 2023, aimed at conflicts of interest in predictive data analytics, and formally withdrew it on June 12, 2025.
AI stayed on the exam agenda anyway. The Division of Examinations' fiscal 2026 priorities, released in November 2025, say staff will review firms' representations about their AI capabilities for accuracy and assess whether firms have adequate policies and procedures to monitor and supervise their use of AI.
So an examiner who finds this plugin would test it against rules you already follow: the compliance program rule, the Marketing Rule, the books and records rule and Regulation S-P, plus Reg BI and FINRA Rule 2210 for dual registrants.
The weak spot is testing. In the 2026 Investment Management Compliance Testing Survey from ACA Group, the Investment Adviser Association and Yuter Compliance Consulting, 86 percent of 411 firms had an AI acceptable use policy and only 37 percent had policies for testing and validating AI outputs. A plugin that drafts client material makes that gap this quarter's work.
3. Rule by Rule: What the Plugin Does and What You Own
Here is the whole guide in one table. Read the last column as your to-do list.
| Rule | What the plugin does | What your firm still has to do |
|---|---|---|
| Marketing Rule, Rule 206(4)-1 | /compliance tests client-facing drafts against the seven general prohibitions and the performance, testimonial and rating rules, suggests fixes, and flags performance and testimonials for the CCO every time | Approve before anything goes out; keep substantiation for every claim; add your own disclosures and review standards to the generic checklist |
| Antifraud and fiduciary duty, Section 206 | /compliance flags undisclosed conflicts, unclear fees and misstated scope of services; no skill recommends or places a trade | The advisor makes every recommendation; disclose conflicts; read what Claude drafts before relying on it |
| Books and records, Rule 204-2 | Keeps a scratch pad it says is not your books and records, reminds advisors of the five-year retention period, and has no archiving connector | On Enterprise, feed the Compliance API to your archive; keep records for the period the rule sets, generally five years in an easily accessible place, the first two in an appropriate office of the adviser |
| Regulation S-P, as amended in 2024 | Its files hold no client data; Claude pulls from connected systems when a skill runs, with each user's own permissions | Put Anthropic and every connector vendor under service-provider oversight, with 72-hour breach notice and a place in your incident response program |
| Compliance program, Rule 206(4)-7 | Pauses for approval before any write and routes client-facing output through /compliance; the README says some guardrails rely on the model following instructions | Written policies naming the plugin, approved skills and connectors; supervision, testing and the annual review |
| Reg BI and FINRA Rule 2210 (dual registrants) | /compliance adds Reg BI and FINRA 2210 checks when you say the firm is a dual registrant | Principal approval and filing where Rule 2210 requires them; broker-dealer supervision; Form CRS |
Look down the middle column: wherever the plugin does real work, the last step belongs to a person at your firm.
4. What the /compliance Skill Checks, in Its Own Words
The /compliance skill is the part of the plugin a CCO should read first, and all of it is public: the skill file and its SEC checklist.
It first pins down the audience, channel and firm type, asking when any is unclear and assuming an SEC-registered RIA unless told otherwise. Then it works in passes:
- Scope. Is the piece an advertisement under the Marketing Rule? Antifraud duties apply either way.
- The seven general prohibitions. Untrue or unsubstantiated claims, misleading implications, benefits without balanced risks, cherry-picked advice, unfair treatment of performance, and anything otherwise materially misleading.
- Specific content. Net performance as prominent as gross, 1-, 5- and 10-year periods, testimonial and rating disclosures, and promissory words such as "no risk" or "will outperform".
- Dual registrants. Reg BI and FINRA Rule 2210 on top.
The output is two Markdown files: a verdict table rating each flagged passage Fail, Flag or Note, with rewording and disclosure language ready to paste, and a clean redraft. Performance, hypothetical performance and testimonials go to the CCO whatever their rating.
The skill is candid about its limits. It calls its output "a draft review for the firm's CCO/compliance officer, not a legal determination or an approval," never calls a redraft compliant, and describes its checklist as "a static snapshot, not a live firm-rules feed."
That checklist is generic. It knows nothing about your approved disclosures, banned phrases or past rulings until someone writes them in, and the customization guide shows how, in a private copy of the plugin.
Other skills route client-facing drafts here, including /post-meeting for follow-up emails. Treat a clean result as a draft with fewer problems left for your CCO to find, which is exactly what the skill says it is.
5. The Recordkeeping Gap: Audit Log, Compliance API, Archive
Three things here sound like records, and only one of them is an archive.
- The audit log. Enterprise only. Each export covers the past 180 days of events such as sign-ins, file uploads, and chat creation and deletion, and the help page is explicit: "Title and content of chats and projects are not available to be exported in audit logs."
- The Compliance API. On Enterprise, not Team. It pulls activity feed events, chat data and file content, and it covers Cowork, where this plugin runs, in Claude, Claude Desktop and Claude Mobile. Only the Primary Owner can switch it on, under Organization settings, API (Anthropic Help Center).
- Your archive. The system that keeps records for the period Rule 204-2 sets: generally five years in an easily accessible place, the first two in an appropriate office of the adviser.
Anthropic recommends Enterprise for RIAs "because it includes the audit logs that support recordkeeping." Support is the right word: an event log can show that an advisor opened a conversation, and nothing about what it said.
Content reaches your archive through the Compliance API. Smarsh launched Smarsh Capture for Claude Enterprise on that API on May 21, 2026, and it ingests conversations, prompts, files and activity logs, including deleted and archived conversations and Claude-generated artifacts. Ask your own archiving vendor whether it does the same.
The /compliance skill says the rest plainly: "There is no archiving connector yet." It names Smarsh, Global Relay, Proofpoint and RIA in a Box as examples of the firm's archive, and it describes its own compliance-review-scratchpad.md file as a staging note, never the firm's books and records.
Which prompts and outputs count as required records is a call for your CCO and counsel. Capturing everything the API exposes and applying retention rules inside the archive is usually simpler to supervise than deciding conversation by conversation.
The Team plan has neither the audit log export nor the Compliance API, so records depend on people filing final outputs by procedure, which is weaker. The small-RIA guide weighs that trade.
If you take one step from this guide, switch on the Compliance API and test the archive feed before the pilot starts. A record you never captured cannot be produced later.
6. Supervision: What to Add to Your Policies
Rule 206(4)-7 requires written policies and procedures reasonably designed to prevent violations, reviewed at least annually, and once advisors use this plugin those policies have to cover it. Dual registrants should check the same points against their written supervisory procedures (WSPs).
A short addendum should answer six questions:
- Who uses what. Which people may use the plugin, and which of the eight skills.
- Which connectors. Each approved system, its access level and who approves new ones. Start read-only where the vendor offers it.
- Who approves writes. The plugin pauses before any CRM update or client draft; your procedure says what the advisor checks before saying yes.
- The review path. Client-facing drafts go through
/compliance, then your normal review, and performance and testimonials always reach the CCO. - Where firm rules live. In the firm's copy of the plugin, where the CCO can see them, rather than in each advisor's Instructions for Claude, which apply to every conversation.
- How you test. Who samples outputs, how often, and where the results are logged.
One passage in the README belongs in your risk assessment. Some guardrails are structural, such as read-only tools for the subagents that parse files. Others, including "advisor approval before any write," are, in the README's words, "enforced by the model following them, not by the runtime."
Anthropic states that plainly, and it tells you what to supervise. Test the approval step in the pilot, prefer read-only access, and take the README's advice on the statements, emails and CRM notes that skills read: "Treat that content as untrusted."
7. Reg S-P: Anthropic and Every Connector in Vendor Oversight
Regulation S-P, as amended in 2024, requires an incident response program, oversight of service providers that touch customer information, notice from those providers within 72 hours of a breach and, in most cases, notice to affected individuals within 30 days. Every SEC-registered adviser is past its compliance date: December 3, 2025 at $1.5 billion or more in AUM, and June 3, 2026 for the rest (SEC compliance guide).
When a skill runs, Claude sends a structured query to each connected system and gets back only what it asked for, while the records stay at the source (TechTimes). What comes back enters the Claude conversation and is kept under your firm's retention settings.
So treat Anthropic as a service provider, and reopen the file on every vendor whose connector you switch on. Record for each:
- Anthropic. Your plan, retention settings and commercial terms. On Team and Enterprise, those terms do not use your inputs to train models (more on training).
- Each connector vendor. Whether it needs a separate subscription or API key, as Anthropic's install tutorial warns it may; what it can read and write; and whether read-only access exists. Connectors inherit each user's permissions, so a loose permission in your CRM becomes a loose permission in Claude.
- Schwab, when its connector goes live. Financial Planning reported that RIAs activate it at the firm level and choose the users, that account numbers, Social Security numbers and clients' dates of birth are masked, and that Schwab's agreement prohibits training models on client data.
- Breach notice. Who at each vendor tells you within 72 hours, and how.
On Enterprise, admins can also restrict which plugins members install and disable local MCP servers. Anthropic's help center puts the reason bluntly: "Only install plugins from sources you trust."
8. What to Say About AI in Form ADV and Marketing
The fastest way to turn a useful tool into an exam finding is to describe it badly. The SEC's first AI-washing cases against advisers, Delphia and Global Predictions in March 2024, were settled with findings of Marketing Rule violations and $400,000 in combined civil penalties (press release 2024-36).
With the fiscal 2026 priorities promising scrutiny of AI claims, describe the plugin as it works:
- What Claude does. Prepares meeting briefs, drafts CRM notes and client communications, and organizes data from the firm's systems.
- What people do. Advisors review every output, approve every write and make every recommendation.
- What to leave out. AI-driven investment decisions, compliance built in, claims that client data never leaves your systems, and time savings you have not measured.
Whether your Form ADV brochure should mention the plugin is a question for counsel. If it does, the wording faces the same test as your marketing: accurate, specific and supportable.
You can also run the announcement itself through /compliance, since unsupported claims are what its second pass hunts for. AI washing in LP materials shows how to word AI claims you can back up.
9. Off-Channel Risk Starts at the Copy Button
Claude drafts on the advisor's desktop, and the risk starts after that. An advisor who pastes a Claude draft into a personal text message has moved a business communication outside your archive, where no plugin setting can see it.
The /compliance skill watches for this. When the channel is text, WhatsApp or personal email, it warns that off-channel communications have drawn major SEC enforcement sweeps and that the message must go through an archived, firm-approved channel.
The same logic applies to Claude itself. A personal Claude account sits outside your archive and vendor program, so keep client work inside the firm's Claude organization and let your shadow AI checks look for the rest.
Off-channel risk used to live on the phone. Now it also sits one copy and paste away from every draft.
10. State-Registered Advisers and Dual Registrants
State-registered advisers, generally those under $100 million in assets under management, answer to their state securities regulator. Many state rules track the SEC's, so the plugin's SEC-based checklist is a reasonable start, but confirm the details with your state and tell /compliance the firm is state-registered when it asks.
Dual registrants carry both rulebooks. Tell the skill the firm is a dual registrant and it adds Reg BI and FINRA Rule 2210: fair and balanced retail communications, no exaggerated claims, and principal approval and filing for certain categories. The skill flags those points, and a registered principal still approves.
InvestmentNews reported that the product is initially focused on RIAs, with plans to expand to broker-dealers, wirehouses and private banks. Until then, your broker-dealer supervision applies in full to anything a registered representative sends.
11. A CCO Checklist Before Go-Live
Work through this list before the first advisor runs a skill on a real household.
- Choose the plan in writing. Enterprise for the audit log and the Compliance API; on Team, write down how records will be captured instead.
- Switch on the Compliance API (Primary Owner only), connect your archiving vendor, and confirm a test Cowork conversation lands in the archive.
- Control distribution. Push the plugin through your organization, restrict other plugins and local MCP servers, and keep client work off personal accounts.
- Approve each connector with a vendor file, an access level (read-only first) and a named list of users.
- Write the policy addendum covering the six questions in section 6.
- Load firm rules into your copy of /compliance: approved disclosures, banned phrases and review standards, each version signed off by the CCO.
- Update Reg S-P incident response and vendor lists for Anthropic and every connector.
- Review your AI language in Form ADV, on the website and in client letters, with counsel.
- Pilot for a week with two or three advisors on real households, then check the archive, the approvals and every escalation.
- Schedule the review. Add the plugin to the annual review and name who keeps the checklist current, since the plugin's copy is a static snapshot.
The AI governance audit checklist scores the same controls firm-wide, and the SEC exam readiness guide covers the exam itself.
WorkWise Solutions, which publishes this guide, runs most of this checklist as a fixed-price project. The Claude for Financial Advisors Setup is $10,000 for firms of 1 to 10 people and $20,000 for 11 to 25 (larger firms by proposal), runs two to four weeks, and includes the Compliance API handed to your archiving vendor, a policy addendum, supervision steps, vendor files for Anthropic and each connector, and your review standards and disclosures written into your copy of /compliance. For the firm-wide file an examiner opens, SEC-Exam-Ready AI Governance is $17,500.
Not a fit if you need a legal opinion (hire counsel), an outsourced CCO (a compliance consultancy does that), or if your CCO has the hours to run this list in-house. WorkWise sells no Claude licenses and takes no referral fees, and this comparison covers the other kinds of help.
"The Division will assess whether firms have implemented adequate policies and procedures to monitor and/or supervise their use of AI technologies, including for tasks related to fraud prevention and detection, back-office operations, anti-money laundering (AML), and trading functions, as applicable."
U.S. SEC Division of Examinations, Fiscal Year 2026 Examination Priorities (November 2025)
- •No AI tool can meet SEC rules on its own: Claude for Financial Advisors drafts, checks and waits for approval, while your firm keeps supervision, records, disclosure and every decision.
- •The /compliance skill pre-checks client-facing drafts against the Marketing Rule, Section 206, Rule 204-2 and, for dual registrants, Reg BI and FINRA 2210, and calls its own output a draft review for the CCO rather than a legal determination or an approval.
- •The plugin has no archiving connector and Claude's audit log exports hold events without chat content, so on Enterprise the Compliance API is how content reaches the archive that Rule 204-2 generally requires you to keep for five years.
- •Some guardrails, including advisor approval before any write, are enforced by the model following its instructions rather than by the software, so test and supervise them.
- •Reg S-P reaches Anthropic and every connector vendor, so each needs a vendor file with its access level, training terms and 72-hour breach notice.
- •Describe your AI use in Form ADV and marketing in words you can substantiate, because the fiscal 2026 exam priorities commit examiners to checking AI claims for accuracy.
- •State-registered advisers should confirm their state's rules, and dual registrants still need principal approval and broker-dealer supervision for communications under FINRA Rule 2210.
Frequently Asked Questions
Is Claude for Financial Advisors compliant with SEC rules?
No software is compliant with SEC rules on its own, and Anthropic does not claim this plugin is. It helps: the /compliance skill pre-checks client-facing drafts against the Marketing Rule, antifraud duties, Rule 204-2 and, for dual registrants, Reg BI, and every write to a CRM or client draft waits for the advisor's approval. Your firm still owns the compliance program, supervision, vendor oversight under Reg S-P, accurate AI disclosures and a five-year archive. Anthropic itself says regulated activities remain subject to human review and approval.
How do you archive Claude for Financial Advisors conversations for Rule 204-2?
Through the Compliance API on the Enterprise plan. The plugin has no archiving connector, and Claude's audit log exports record events such as sign-ins and chat creation without chat content, 180 days at a time. The Compliance API pulls chat data and file content, covers Cowork, and is switched on by the Primary Owner. Archiving vendors build on it: Smarsh launched Smarsh Capture for Claude Enterprise in May 2026. Rule 204-2 generally requires five years of retention in an easily accessible place, the first two in an appropriate office of the adviser. The Team plan offers neither feature.
What does the /compliance skill in Claude for Financial Advisors check?
It pre-checks client-facing drafts such as emails, newsletters, social posts and presentations. It asks for the audience, channel and firm type, decides whether the piece is an advertisement under the Marketing Rule, then tests it against the rule's seven general prohibitions, the performance and testimonial requirements, Section 206 antifraud duties and, for dual registrants, Reg BI and FINRA 2210. It returns a Fail, Flag or Note verdict table, disclosure language and a redraft. Performance and testimonials always go to the CCO, and the skill calls its output a draft review, not an approval.
Related Guides & Articles
Claude for Financial Advisors Setup
Plan, connectors, firm rules in /compliance, the Compliance API wired to your archive and a one-week pilot. From $10,000, two to four weeks.
Claude for Financial Advisors
What the plugin is, what each of the eight skills does and does not do, what it costs, and who should wait.
How to Customize Claude for Financial Advisors
Put your disclosures, banned phrases and review standards into a private copy of the plugin, with CCO sign-off on every version.
Claude for Financial Advisors for Small RIAs
Team or Enterprise under 20 people, and what the recordkeeping workaround on Team really costs you.
AI Governance Help for SEC-Registered Advisers
Counsel, compliance consultancies, Big 4, specialists or your own CCO, compared by cost, timeline and limits.
AI Governance and SEC Exam Readiness
How an exam request arrives, who examiners interview, and how the AI questions fit inside a routine adviser exam.
Want the plugin live with records and supervision already in place?
The Claude for Financial Advisors Setup switches on the Compliance API and hands it to your archiving vendor, writes the policy addendum and vendor files, and puts your review standards into your firm's copy of /compliance. It costs $10,000 for firms of 1 to 10 people and $20,000 for 11 to 25, over two to four weeks. Legal interpretation stays with your counsel.
Book a Setup Call