As the regulatory landscape continues to evolve, September's focus is on one consistent theme: governance. Whether it's artificial intelligence, cybersecurity, supervisory controls, or conflicts of interest, the SEC continues to emphasize that firms must demonstrate not only that policies exist, but that they are actively implemented, monitored, and documented.
This month's Round-Up highlights several areas receiving increased regulatory attention and provides practical steps your firm can take to strengthen its compliance program before year-end.
Artificial intelligence is no longer a future consideration for Registered Investment Advisers - it's here, and regulators are paying close attention.
The SEC recently reinforced its commitment to responsible AI adoption through its Artificial Intelligence Program, emphasizing innovation while maintaining strong governance and investor protection. As AI tools become increasingly integrated into business operations, firms are shifting away from asking whether AI should be used and instead asking how it can be governed responsibly.
While there are currently no AI-specific rules for RIAs, examiners are increasingly focused on how firms oversee AI technologies, including:
Firms should expect examiners to ask not only what AI tools are being used, but how they are supervised and controlled.
The strongest AI governance programs aren't built around restricting technology - they're built around managing risk.
Treat AI like any other critical vendor:
As with every compliance program, documentation is your best defense.
Cybersecurity incidents continue to increase across every industry.
Under the SEC's updated Regulation S-P requirements, once your firm becomes aware of unauthorized access to sensitive customer information, the notification timeline begins.
That means firms generally have 30 days to notify affected individuals when notification is required. Waiting until an investigation is complete can significantly reduce the time available to respond.
Before an incident occurs, every RIA should know:
Conduct an annual tabletop cybersecurity exercise.
Testing your incident response plan before a real event helps identify gaps, clarify responsibilities, and ensure your team understands regulatory expectations before the pressure of an actual breach.
Rule 206(4)-7 continues to serve as the foundation of every RIA compliance program.
The SEC expects firms to maintain written policies that are not only well designed but actively supervised, tested, and updated as risks evolve.
An effective compliance program includes:
Strong supervision supports your fiduciary obligations and helps build a culture of compliance throughout the organization.
Compliance is about building a stronger, more resilient firm, not just meeting regulatory expectations.
Whether you're reviewing AI governance, preparing for Regulation S-P requirements, strengthening supervisory controls, or conducting annual testing, True West partners with RIAs to simplify compliance so you can stay focused on serving your clients.
One Team. One Trail.
Questions? Contact the True West Compliance Team to discuss any of the topics covered in this month's Regulatory Round-Up.