AI Governance for Asset Management Firms: SEC Compliance Guide
A practical guide for asset management firms governing AI systems, AI agents, auditability, permissions, and runtime controls in a way that aligns AI use with existing adviser compliance obligations.
Why SEC AI compliance starts with existing adviser obligations
AI governance for asset management should be understood as part of the firm’s broader compliance operating model. The core task is to connect AI systems and AI agents to existing obligations for policy, supervision, records, disclosures, customer information protection, and annual compliance review.
This approach helps firms avoid treating AI as an isolated technology project. Instead, AI use cases can be reviewed according to their role in investor-facing, investment-related, operational, research, client communication, and supervisory workflows.
Core control domains for asset management AI governance
A practical AI governance program should clarify ownership, enforce controls during use, and retain audit evidence that connects user activity to policy decisions and outcomes.
Policy and ownership
AI use cases need named business owners, compliance oversight, risk classification, and written policies that define permitted and prohibited use.
Runtime enforcement
Controls should operate before sensitive actions occur, including retrieval, model invocation, tool calls, external communications, and workflow changes.
Auditability
Firms should retain evidence connecting users, prompts, data access, model versions, policy decisions, tool calls, outputs, approvals, and exceptions.
Governance architecture for AI systems and AI agents
A practical AI governance architecture for asset management should connect inventory, identity, policy enforcement, monitoring, and records. This is especially important for AI agents because agents may retrieve data, call tools, draft communications, update workflows, or initiate operational actions.
A chatbot that only drafts text creates one risk profile. An agent that can access research repositories, portfolio systems, customer information, or workflow tools creates a different profile and requires stronger control points.
-
Inventory and classify AI use cases
Identify the AI systems and AI agents in use, the business owner, the workflow supported, and the level of risk created by data access, outputs, and available actions.
-
Connect users, systems, permissions, and policy
AI governance should reflect who is using the system, what information it can access, which tools it can call, and which policies apply before sensitive activity occurs.
-
Monitor execution and retain records
Firms should preserve evidence that shows how an AI system or agent behaved, what policy decisions were made, whether exceptions occurred, and how approvals or escalations were handled.
Runtime controls for AI agent governance
Pre-deployment review is necessary, but it is not sufficient for live AI systems. Runtime governance is needed because the most important control decisions often happen during execution: what data the agent retrieves, whether a prompt attempts to override policy, whether sensitive information appears in the output, whether a tool call is allowed, and whether a human approval is required before action.
Runtime controls make governance operational
For AI agents, governance is strongest when policy enforcement occurs inside the live workflow, not only during intake or periodic review. This helps connect permissions, model use, retrieval, tool access, output handling, approvals, exceptions, and audit logging.
Audit evidence firms should retain
Auditability should allow a firm to reconstruct material AI activity and explain how the system was governed. Evidence should connect the user, the AI system or agent, the data accessed, the model or tool used, the policy decision, the output, and any human approval or exception.
| Evidence area | What it should show |
|---|---|
| User and identity context | Which user or service account initiated the AI activity, and what permissions applied at the time. |
| Prompts and inputs | The prompt or instruction given to the AI system, including whether policy-relevant information was included. |
| Data access | What repositories, documents, customer information, research materials, or other sources were retrieved or exposed. |
| Model and system context | The AI system, model version, agent configuration, or tool path involved in the workflow. |
| Policy decisions and exceptions | Whether activity was allowed, blocked, redacted, escalated, approved, or handled as an exception. |
| Outputs and tool calls | The generated output, external communication, workflow update, tool call, or operational action produced by the system or agent. |
Governance responsibilities across the firm
AI governance requires coordinated ownership. The program should define how compliance, legal, risk, security, technology, data teams, and business owners participate in approval, supervision, enforcement, monitoring, and evidence retention.
- Compliance: Maintain AI policy coverage, supervisory review procedures, exception handling, annual review inputs, and evidence requirements.
- Legal: Review AI-related disclosures, marketing statements, client-facing claims, vendor terms, and emerging regulatory developments.
- Risk: Define risk classification, approval thresholds, control expectations, risk acceptance, and periodic reassessment.
- Security: Enforce identity, permissions, least privilege, logging, data protection, incident response, and agent access controls.
- Technology and data: Implement model access, retrieval controls, tool-call constraints, monitoring, testing, and change management.
- Business owners: Document intended use, workflow impact, human oversight, escalation points, and operational accountability.
Evaluation criteria for AI governance platforms
When evaluating AI governance platforms, asset management firms should focus on whether the platform can support the controls and evidence needed for live AI systems and AI agents. The evaluation should consider how well the platform connects identity, permissions, policy, monitoring, and records.
| Criterion | Governance question |
|---|---|
| AI inventory | Can the firm identify approved AI systems and AI agents, their owners, risk classifications, and intended uses? |
| Access control | Can permissions and least-privilege expectations be applied to data retrieval, model use, and tool calls? |
| Runtime policy enforcement | Can policies be enforced before sensitive information is accessed, generated, communicated, or acted on? |
| Human oversight | Can the workflow require review, approval, escalation, or exception handling before higher-risk actions occur? |
| Audit logging | Can the firm retain records that connect users, prompts, data access, model versions, policy decisions, tool calls, outputs, approvals, and exceptions? |
Implementation considerations
AI governance should be implemented as a control system that supports both pre-use review and live oversight. Asset management firms should define where controls operate, which teams own each part of the process, and how evidence is retained for review.
- Map AI use cases to business workflows, data categories, and supervisory responsibilities.
- Define policy requirements for permitted use, prohibited use, approval thresholds, exception handling, and periodic reassessment.
- Apply identity and permissions to AI systems and AI agents so access reflects the user, the workflow, and the action being attempted.
- Use runtime controls where agents retrieve data, invoke models, call tools, draft external communications, or initiate workflow changes.
- Retain audit evidence that can support compliance review, supervision, incident response, and records obligations.
Frequently asked questions
Is AI governance separate from the firm’s existing compliance program?
No. For registered investment advisers, the practical obligation is to map AI use into existing adviser duties for written policies, annual compliance review, books-and-records retention, truthful disclosures, customer information protection, and supervision of technology used in investor-facing or investment-related workflows.
Why do AI agents require stronger controls than basic chatbots?
AI agents may retrieve data, call tools, draft communications, update workflows, or initiate operational actions. That creates a different risk profile than a chatbot that only drafts text, especially when the agent can access research repositories, portfolio systems, customer information, or workflow tools.
Why is runtime governance important?
Runtime governance is important because many key control decisions happen during execution, including what data the agent retrieves, whether a prompt attempts to override policy, whether sensitive information appears in the output, whether a tool call is allowed, and whether human approval is required before action.
Build AI governance that can be enforced and audited
Asset management firms need AI controls that operate at runtime, not only in policy documents. Trussed AI helps govern enterprise AI agents with identity, permissions, policy enforcement, monitoring, tool governance, and audit logging.
Talk to an Expert