โ†
AI for Financial Advisors & Wealth Managers
Aware ยท M12 ยท lesson 12 of 17 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
The Cardinal Rule: Verify Every Number, Every Citation, Every Recommendation
๐Ÿ“–
now learning

The Cardinal Rule: Verify Every Number, Every Citation, Every Recommendation

15 min

Every advisor who survives 2026 with their registration intact will have one habit in common: a fixed, repeated, almost mechanical verification pass run on every AI-touched artifact before it leaves their screen. The previous lesson cataloged sixteen wealth-specific hallucination patterns; this lesson installs the protocol that catches them โ€” three tiers, three minutes per artifact, run on every memo, every email, every Reg BI file, every tax projection, every IPS draft, every prompt the firm produces. This is the Cardinal Rule. The chapters that follow this one โ€” the Marketing Rule defense in L1 Ch4.1, the Roth conversion screen across fifty households in L3 Ch2, the rollover Reg BI memo workflow in L2 Ch7.2, the agentic-AI WSPs in L4 Ch3.3 โ€” all assume an advisor who runs this protocol without thinking about it. The protocol is short, dull, and absolute: source-system check, regulatory check, client-specific check. Build it once, use it forever. The Hendersons' 9:30 review meeting from L1 Ch1 ends with a queued Roth conversion memo; the only thing standing between that memo and the next FINRA AWC headline is the three-tier verification pass you are about to learn.

Why a Protocol Instead of Vigilance

Every advisor who has used AI for more than a quarter has experienced the same temptation: "I've reviewed enough AI output to spot the obvious errors. I'll catch hallucinations as I read." The temptation is wrong, and the wrongness is structural โ€” not a reflection on the advisor's intelligence or attention. Hallucinations are fluent. Hallucinated IRC sections look like real IRC sections. Hallucinated account numbers look like real account numbers. Hallucinated trust language reads like the trust the client actually signed in 2014. Vigilance fails because the cognitive load of reading an AI-drafted Reg BI memo is dominated by the substantive question the memo is trying to answer ("should this client roll the 401(k)?"); the verification task gets buffered to the same attention bucket and quietly loses. The 2025-2026 FINRA AWC pattern on inadequate rollover Reg BI files is the precise enforcement artifact this failure mode produces โ€” competent registered persons who signed memos that were 95% accurate and 5% structurally wrong because the structurally-wrong 5% looked exactly like the structurally-right 95%.

The fix is to externalize verification from attention into a checklist that runs whether the advisor "feels" alert or not. The Cardinal Rule is a three-tier checklist. Tier one is the source-system check โ€” "did this number, this account, this allocation, this transaction actually come from the custodian / planning / tax / CRM system, or did the model interpolate it?" Tier two is the regulatory check โ€” "is the rule cited correctly to the SEC, FINRA, IRS, DOL, or state DOI, and does the cited subsection actually say what the model claims?" Tier three is the client-specific check โ€” "does the recommendation actually fit this household given the IPS, the risk tolerance, the documented prior decisions, the family structure, and the regulatory profile?" Each tier takes roughly a minute. Three minutes per artifact. Applied to every artifact. The downstream cost of skipping it is a multiple of the AWC settlement, the reputational hit, the client churn, and the E&O renewal premium.

This is the lesson the program assumes. Every later lesson โ€” every workflow, every prompt template, every supervisory procedure โ€” bakes the three-tier check into the operational design. Build the reflex here. Make it routine before you touch a 50-household Roth conversion screen or a 500-account beneficiary audit.

Tier One โ€” Source-System Check

The first tier asks one question: did the numbers and identifiers in the AI output come from a verified source system, or did the model generate them from local pattern? "Source system" in a 2026 wealth practice means one of the named systems of record: the custodian (Schwab, Fidelity, Pershing, BNY Mellon, TD legacy / Schwab-Advisor) for positions, balances, account numbers, and cost basis; the portfolio accounting system (Orion, Tamarac, Black Diamond, Addepar) for performance, allocation, and reconciled basis; the planning system (RightCapital, eMoney, MoneyGuidePro) for plan assumptions, Monte Carlo position, projected cash flows, and drawdown narratives; the tax-extraction system (Holistiplan) for 1040 line items, K-1 distributions, MAGI, AGI, and bracket position; the estate-extraction system (Wealth.com, FP Alpha) for trustees, agents, beneficiaries, distribution mechanics, GST provisions, and digital-asset clauses; the CRM (Wealthbox, Redtail, Salesforce Financial Services Cloud + Einstein, Practifi) for client biographical data, prior meeting notes, action items, and disclosed conflicts; the meeting AI archive (Jump, Zocks, FinMate AI, Sybill, Zeplyn) for transcripts, summaries, and action items; the archive (Smarsh, Global Relay) for retained communications under FINRA Rule 4511 and SEC Rule 204-2.

The Numeric and Identifier Sweep

Read the AI output and mentally highlight every number and every identifier. Account numbers (e.g., "client's Schwab IRA xxxx-1147"). Cost basis figures ("the XYZ lot acquired 2018-03-14 has basis $42,317.81"). Position quantities ("12,400 shares of XYZ"). Distribution amounts ("the QCD election will distribute $42,500"). Tax-return line items ("line 11 AGI of $187,400"). Plan numbers ("RightCapital Monte Carlo 91% success"). Beneficiary names and percentages ("Roth IRA: primary 100% spouse; contingent 50/50 child A and child B"). Trust quotations ("Article 4.2(b) authorizes principal distributions for HEMS"). Social Security PIA figures ("client's PIA at FRA is $3,427"). RMD amounts ("2026 RMD is $42,109"). Each of these is a source-system question. For each, the verification step is: open the source system, find the value, confirm the match. If the AI value doesn't appear in any source system, the value is interpolated and must be struck or corrected.

The Document-and-Quote Sweep

If the AI output quotes a client document โ€” trust, will, POA, healthcare directive, IPS, prior meeting note, beneficiary form, custodian agreement, plan document, attorney memo โ€” the quote goes to the source document. Open the document. Find the cited Section / Article / paragraph. Match the quoted language word-for-word. Context-window truncation is a common silent failure: the AI was given a 95-page trust binder, the model only processed the first 40 pages, and the model confabulated language consistent with standard trust patterns for the parts it did not see. The advisor's verification reflex must include the source-document match for every quotation, including the section reference.

The Source-System Cheat Card

The mature firm laminates a card for the advisor desk that names the source system for each data class. Positions and balances โ†’ custodian. Cost basis โ†’ custodian + portfolio accounting system (whichever is the reconciled ground truth at the firm). Allocation โ†’ portfolio accounting system. Plan assumptions and Monte Carlo โ†’ planning software. Tax return โ†’ Holistiplan extraction or the actual return PDF. Estate documents โ†’ Wealth.com / FP Alpha extraction or the executed document. Client biographical and prior decisions โ†’ CRM. Meeting content โ†’ Jump / Zocks transcript and summary. The cheat card removes the "where do I check?" cognitive load and makes the tier-one sweep a 60-second reflex.

Tier Two โ€” Regulatory Check

The second tier asks: is every rule, statute, regulation, case, or publication citation in the AI output correct, and does the cited subsection actually say what the model claims? Hallucinated citations are the most under-detected category of AI failure in wealth, because the citations look exactly like real citations and most readers do not open the underlying rule. The 2026 enforcement landscape is unforgiving on this point โ€” an AI-drafted Reg BI memo that miscites Reg BI is itself a Reg BI Compliance Obligation failure under ยง240.15l-1(a)(2)(iv); an AI-drafted Marketing Rule disclosure that miscites Rule 206(4)-1 walks straight into the 2024-2025 AI-washing enforcement pattern; an AI-drafted tax memo that miscites IRC ยง408(d)(6) when it means ยง408(d)(2) read with ยง72(e)(8) puts the advisor's whole backdoor-Roth practice into the exam crosshairs.

The Citation Sweep

Read the AI output and mentally highlight every citation. SEC rules (Marketing Rule 206(4)-1 with its lettered subparts and the January 2026 staff FAQs; Compliance Rule 206(4)-7; Custody Rule 206(4)-2; Rule 204-2 recordkeeping; Reg S-P 17 CFR Part 248 with the May 2024 amendments). FINRA rules (Rule 2210 Communications, Rule 3110 Supervision, Rule 4511 Recordkeeping, Rule 4530 Reporting, Rule 1240 Firm Element CE, Regulatory Notice 24-09 on GenAI, the 2026 Annual Regulatory Oversight Report). Reg BI under ยง240.15l-1 with its four obligations (Disclosure, Care, Conflict, Compliance) and the lettered subparagraphs. IRC sections (the high-traffic backdoor-Roth bundle is ยง408(d)(2) read with ยง72(e)(8) reported on Form 8606 โ€” never ยง408(d)(6), which governs IRA transfers incident to divorce; the SECURE 2.0 RMD age at ยง401(a)(9); QCD at ยง408(d)(8); NUA at ยง402(e)(4); 72(t) substantially equal periodic payments; 1202 QSBS under the dual regime post-OBBBA July 2025 with legacy $10M/10x and post-OBBBA $15M/10x and the $75M gross-asset threshold; 83(b) elections; 529(c)(2)(B) five-year superfund election; 663(b) 65-day election for trust distributions; 1400Z-2 opportunity zones; 691(c) IRD deduction; 453 installment sale). DOL regulations (the rollover landscape under PTE 2020-02 and the Reg BI parallel). State frameworks (NY DFS 23 NYCRR 500 cybersecurity; California CPRA; Texas DIR; NAIC Model #275 annuity suitability; the NAIC AI Model Bulletin). E&O / professional standards (CFP Board Code and Standards; AICPA SSTS for the CPA-collaborator).

The Verification Source Card

Each citation has one canonical verification source: sec.gov for SEC rules and staff guidance; finra.org/rules-guidance/rulebooks for FINRA rules; irs.gov and the Bloomberg Tax / Thomson Reuters Checkpoint code text for IRC sections; ssa.gov for Social Security regulation and PIA mechanics; cms.gov for IRMAA and Medicare; the home state DOI for state insurance rules; naic.org for NAIC model laws and bulletins; dfs.ny.gov for NY DFS Part 500; oag.ca.gov for CPRA; the CFP Board Code and Standards for CFP professional rules. The mature firm maintains a single internal wiki page with the link to each source, the canonical citation format, and any "watch out for this miscitation" annotation (e.g., "AI commonly cites ยง408(d)(6) for the backdoor-Roth pro-rata rule โ€” that subsection governs IRA transfers incident to divorce; the correct cite is ยง408(d)(2) read with ยง72(e)(8) and reported on Form 8606").

The Subsection-Match Test

The most common citation hallucination is the right rule with the wrong subsection โ€” "FINRA Rule 2210(d)(4)(B)" where the rule exists but the subsection either does not exist or says something different than the model claims. The verification step opens the rule and reads the cited subsection. If the cited language does not match the model's claim, the cite is hallucinated and must be corrected or struck. This is the failure mode the principal review under FINRA Rule 2210 most directly catches when the principal is paying attention; the Cardinal Rule installs the same discipline at the advisor's desk so the issue never reaches the principal queue.

Tier Three โ€” Client-Specific Check

The third tier asks: does this recommendation actually fit this household? Tier one confirms the inputs were real. Tier two confirms the rules were cited right. Tier three confirms the answer is the right answer for this client. A Roth conversion that bracket-fills to the top of 24% is the right answer for a 63-year-old pre-RMD client with a low-income year and a charitable bunching plan; the same conversion is wrong for a 71-year-old client who is one year from IRMAA and who has dependent grandchildren on a 529-Roth glide path. AI does not know the difference unless the prompt and the source systems told it the difference. The client-specific check makes the advisor confirm the fit explicitly.

The IPS and Prior-Decision Match

Open the client's IPS. Does the recommendation align with the documented allocation policy, the risk tolerance language, the documented liquidity needs, the ESG / values constraints, the prohibited holdings list, and the rebalancing thresholds? Does the recommendation conflict with a prior documented decision (e.g., "client elected in 2024 not to convert above the 22% bracket for IRMAA reasons" โ€” the AI doesn't know this unless the CRM and Wealthbox prior-meeting notes told it). The 2026 mature practice runs the IPS as a structured document that the AI prompt can ingest; the verification step still requires the human to confirm the match because AI's understanding of "alignment" is interpolative.

The Family-Structure and Life-Event Match

Does the recommendation account for the household's actual structure? A married couple, with or without a SLAT in place. A blended family with a prior-marriage child whose contingent beneficiary status was renegotiated post-divorce. A special-needs grandchild whose SNT funding triggers Medicaid means-test issues. A surviving spouse whose stepped-up basis under ยง1014 changes the tax-loss harvest landscape. A small-business owner mid-exit with QSBS Section 1202 stock issued under both legacy and post-OBBBA regimes. AI may produce a generic-looking memo that does not absorb these facts; the client-specific check is the moment the advisor confirms the recommendation is tailored to the household, not the persona.

The Regulatory-Profile Match

Does the recommendation account for the client's regulatory profile? A senior client over age 65 in a state with elder-financial-abuse statutes (FINRA Rule 2165 trusted contact, the state APS reporting obligation). A client with a ยง409A deferred-comp election in place that constrains income-smoothing flexibility. A client with a Form 4 insider-filing obligation that constrains transaction timing (10b5-1 windows). A client whose annuity holdings put the recommendation inside NAIC Model #275 best-interest territory for the dually-licensed advisor. The client-specific check catches the regulatory profile mismatch the AI cannot see.

The Protocol in Practice โ€” A Worked Example

The Hendersons' 9:30 review (introduced in L1 Ch1) ended with Jump capturing the meeting and an AI draft of a Roth conversion recommendation memo. The memo says: "Recommend a $96,000 partial Roth conversion in tax year 2026 from the client's Schwab traditional IRA (account 8475-021-3398) to the client's Schwab Roth IRA. This fills the 24% bracket through the projected $244,000 MAGI ceiling under the 2026 schedule. Pro-rata rule under IRC ยง408(d)(6) does not apply because all pre-tax IRA balances are aggregated. Five-year clock starts 1/1/2026 for the converted amount. Recommended documentation: Form 8606 lines 6-15 at year-end."

Tier one (source-system, 60 seconds). Open Schwab โ€” the client's traditional IRA account number is xxxx-1147 (not 8475-021-3398, which the model invented). Strike the AI account number; insert the verified xxxx-1147. Open Holistiplan โ€” prior-year AGI was $148,000, not the model's implied $148,400. Open RightCapital โ€” the bracket-fill calculation in the model produces $96,000; the planning software produces $94,200 because the model did not account for the qualified dividend stacking. Correct the conversion amount.

Tier two (regulatory, 60 seconds). The memo cites IRC ยง408(d)(6) for the pro-rata rule. Open the IRC โ€” ยง408(d)(6) governs IRA transfers incident to divorce; the pro-rata aggregation rule lives at ยง408(d)(2) read with ยง72(e)(8), reported on Form 8606. Correct the citation. The memo asserts "five-year clock starts 1/1/2026 for the converted amount" โ€” verify against IRS Publication 590-B (the conversion five-year clock for under-59ยฝ withdrawals starts January 1 of the year of conversion, so the wording is correct, but the lesson here is the contribution five-year clock and the conversion five-year clock are different clocks and the AI is one prompt away from confusing them). The memo references "the 2026 schedule" โ€” verify the 24% bracket top against the current IRS Revenue Procedure for 2026.

Tier three (client-specific, 60 seconds). Open the Hendersons' IPS โ€” last updated 2022, allocation policy intact, no prohibited holdings issue. Open Wealthbox prior notes โ€” the Hendersons elected in their 2024 review to stay below the second IRMAA tier; the recommended conversion to $244,000 MAGI crosses that tier. Strike the $94,200 figure; reduce to $74,000 to preserve the IRMAA election OR document the explicit client decision to override the prior election. Confirm the higher earner's Social Security delay-to-70 plan is unchanged. Confirm the trust funding line item from the 2022 IPS is queued for the November meeting (not this memo).

Three minutes. The corrected memo is now compliant: the right account number, the right citation, the right amount, and the IRMAA-aware client-specific framing. The Reg BI file documents the alternatives considered (no conversion, $74,000 partial preserving IRMAA, $94,200 partial filling 24% bracket but crossing IRMAA, full conversion), the client-specific reason for the recommendation, the source-system verifications, and the Marketing Rule-compliant client-facing language. This is what the 2026 SEC and FINRA exam staff are looking for. This is what the protocol produces.

Archiving the Verification โ€” Rule 4511 and the Audit Trail

The Cardinal Rule produces an artifact: the verified version of the AI output, the verifier's initials, the date and time of verification, and the source-system references used. FINRA Rule 4511 and SEC Rule 204-2 retention obligations extend to this verification artifact, not just the final memo. The 2026 mature practice archives the chain in Smarsh or Global Relay: original AI output โ†’ verification annotations โ†’ corrected version โ†’ signoff. The FINRA 2026 Regulatory Oversight Report's framing of agentic AI under Rule 3110 reasonable design makes this explicit โ€” when AI takes any role in producing a recordable communication, the supervisory architecture must capture the human verification step, not just the final output. The L4 Ch3 chapter develops the WSP language; the L3 Ch10 lessons build the archive pipeline; the operational reflex starts here.

The principal-review queue under FINRA Rule 2210 changes shape too. The first-pass principal review at scale is no longer "did the advisor write something problematic?" โ€” it is "did the advisor run the three-tier check, and does the audit trail show it?" A signed memo without a documented verification chain is an exception; an exception triggers the deeper review. This is the supervisory architecture that lets a $500M RIA process 200+ AI-drafted client artifacts a week without the CCO becoming the bottleneck.

When to Skip the Protocol โ€” Never

The advisor question that comes up after the first month of running the Cardinal Rule is: "is there a class of artifact where I can skip the tier-three client-specific check because the artifact is generic?" The answer is no, and the reason is structural. The class of artifact that looks generic โ€” a quarterly commentary, a market drawdown email, a SECURE 2.0 explainer โ€” is exactly the artifact category the Marketing Rule treats as a communication subject to "clear and prominent" disclosure under Rule 206(4)-1(d)(6) and which FINRA Rule 2210 treats as a recordable communication. The "generic" artifact also gets the IRMAA / IRC / RMD-age verification under tier two. The "generic" artifact also gets the source-system check under tier one if it contains any client-specific or market-specific numbers. The protocol applies to every artifact. The three minutes are not optional. The class of advisor who skips the protocol on the "easy" artifacts is the class of advisor whose name appears in the next AWC.

The corollary: AI productivity is only real productivity if the verification reflex is built in. An advisor who skips verification has not saved time โ€” they have moved the time cost from before-the-fact verification (three minutes) to after-the-fact remediation (the AWC, the client recovery, the E&O claim, the ADV amendment, the personal U4 DRP narrative drafting workflow in L5 Ch7.4). The math is decisively in favor of the three-minute protocol. The Cardinal Rule is not a tax on AI productivity โ€” it is the precondition of AI productivity.

Key Takeaways

  • The Cardinal Rule is a three-tier verification protocol โ€” source-system check, regulatory check, client-specific check โ€” run on every AI-touched artifact before it leaves the advisor's screen. Roughly three minutes per artifact, applied to every artifact.
  • Tier one (source-system) checks every number and identifier against the named system of record: custodian (Schwab / Fidelity / Pershing / BNY Mellon) for accounts, positions, and basis; Orion / Tamarac / Black Diamond / Addepar for allocation and reconciled basis; Holistiplan for tax-return data; Wealth.com / FP Alpha for estate documents; RightCapital / eMoney / MoneyGuidePro for plan assumptions; Wealthbox / Redtail / Salesforce FSC for client biographical and prior decisions; Jump / Zocks / FinMate / Sybill / Zeplyn for meeting content.
  • Tier two (regulatory) verifies every rule, statute, and case citation against the canonical source โ€” sec.gov for SEC rules and the January 2026 Marketing Rule staff FAQs, finra.org for FINRA rules, irs.gov for IRC sections. The high-frequency miscitation to watch: IRC ยง408(d)(6) (divorce IRA transfers) where the model means ยง408(d)(2) read with ยง72(e)(8) reported on Form 8606 (backdoor-Roth pro-rata).
  • Tier three (client-specific) confirms the recommendation fits THIS household โ€” IPS alignment, prior-decision conflicts, family structure, life events, regulatory profile (FINRA Rule 2165 trusted contact for seniors, ยง409A constraints, 10b5-1 windows, NAIC Model #275 for the dually-licensed annuity advisor, the dual-regime QSBS ยง1202 issuance-date classification).
  • The verification artifact is itself a record under FINRA Rule 4511 and SEC Rule 204-2 โ€” original AI output, verification annotations, corrected version, and signoff archived in Smarsh or Global Relay. The principal-review queue under FINRA Rule 2210 looks for the audit trail; an unverified memo is an exception that triggers the deeper review.
  • The protocol applies to every artifact, including the artifacts that look generic (quarterly commentary, market drawdown email, SECURE 2.0 explainer). Marketing Rule 206(4)-1(d) "clear and prominent" disclosure attaches to the generic artifact too. The three minutes are not optional.
  • The Cardinal Rule is the precondition of AI productivity, not a tax on it โ€” the three minutes upstream replace the multi-week downstream cost of an AWC, a client recovery, an E&O claim, and an ADV amendment. Every later lesson in this program (L2 Ch7.2 rollover Reg BI memo, L3 Ch2 Roth conversion screen, L4 Ch3.3 agentic-AI WSPs, L5 Ch7.4 Form U4 DRP drafting) assumes the Cardinal Rule reflex is in place.