Free Self-Assessment Tool

Your AI Governance Self-Audit

There's no SEC or NASAA rule that spells out exactly what an "AI policy" must contain. This walks you through the questions examiners are actually asking under existing rules — so you can see where your real exposure sits before someone else finds it for you.

5
Sections
~5
Minutes
14
Questions
Progress
0%

Ready to find your real exposure?

A plain-language walk-through of the same five areas the SEC's Division of Examinations has said it's actually looking at in 2026 — even though no AI-specific rule exists. Every answer, including the good ones, comes back with an explanation of why it matters.

🔍
Shadow AI Detection
Surface tools staff may be using that you don't know about.
🔒
Data Privacy Exposure
Flag Reg S-P risk from client data going into the wrong tools.
📋
Policy & Marketing Gaps
Spot supervision, disclosure, and "AI-washing" exposure.

Your AI Governance Self-Audit Results

Based on your answers, here's where your firm's AI use may create exposure — organized around the same areas examiners are asking about, with an explanation for every answer, not just the risky ones.

This is education, not compliance advice. This self-audit is a starting point to help you think through AI-related risk — it is not a substitute for review by your firm's compliance officer, outside compliance consultant, or securities counsel, and it does not guarantee examination readiness or regulatory compliance. There is no SEC or NASAA rule specific to AI; the findings below are organized around how AI use intersects with existing federal obligations (Reg S-P, the Marketing Rule, Rule 206(4)-7 / written supervisory procedures, Form ADV disclosure, and recordkeeping requirements).

A note for state-registered advisers: NASAA has published its own general compliance guidance on AI use, and it lines up with much of what's covered here — human review of AI-generated content, staff training, and vendor due diligence. But NASAA is an association that coordinates state securities regulators; it doesn't have independent rulemaking authority the way the SEC does. What's actually required depends on your specific state's own securities regulator, which this self-audit does not research state by state. Confirm your state's current requirements with your compliance officer or counsel rather than assuming NASAA's general guidance is binding as written.

Want help implementing your policies?

This self-audit identifies potential gaps in your firm's AI governance. Your next step is to review these results with your Chief Compliance Officer to address any vulnerabilities in a formal, written policy.

Once that policy is in place, Coellaborate can help you operationalize it. I can help you embed these new instructions into your day-to-day workflows, build the necessary supporting templates, and create custom training videos for your staff.

Don't let a well-crafted policy gather dust on a shared drive—ensure your compliance guidance becomes an active, seamless part of your firm's daily operations.

Let's collaborate