Agentic-AI WSPs Under FINRA Rule 3110 Reasonable Design
The moment AI stops drafting and starts acting โ placing a trade, sending a client email, initiating an ACATs, processing an RMD, filing a form โ the supervisory architecture under FINRA Rule 3110 reasonable-design changes structurally. The 2026 FINRA Annual Regulatory Oversight Report devoted a section to this transition, and the framing is now operational: an advisor practice deploying agentic AI without the supervisory layer this lesson installs is the named-respondent firm in the next AWC. This lesson installs the agentic-AI WSP under FINRA Rule 3110 โ the seven required components (pre-action compliance checks, post-action review, kill-switch design, supervisory log under Rule 4511, Reg BI documentation chain, Reg S-P data-flow review, client-facing disclosure) plus the governance committee oversight that makes agentic deployment defensible. Without it, action-taking AI is a liability accelerator. With it, agentic AI is the Year 3 differentiation lever per L4 Ch1 L3.
Why Agentic AI Changes the Supervisory Equation
A generative AI that drafts a client email lets the registered person decide whether to send it. The supervisor reviews drafts pre-delivery; the human is in the loop; the L4 Ch3 L2 principal review queue is the operational predicate. An agentic AI that sends the email autonomously moves the supervisor's checkpoint to after the action โ post-action review, sampling, exception handling โ because no human was in the pre-send loop. The risk asymmetry inverts: errors are now externalized to clients before they are caught.
The FINRA 2026 Annual Regulatory Oversight Report's GenAI section frames this explicitly: Rule 3110 requires a "system of supervision reasonably designed to achieve compliance," and when AI takes action, "reasonably designed" requires architectural changes โ pre-action compliance, kill-switch, post-action sampling, retention of the AI's decision trail under Rule 4511. The Snell & Wilmer / Debevoise / ACA Group / Smarsh teardowns of the 2026 Report all converge: action-taking AI is the supervisory frontier for 2026-2028 advisor practice deployment.
The cross-cutting implication: agentic AI is a Year 3 differentiation lever (L4 Ch1 L3) precisely because Year 1 productivity tools (drafting) and Year 2 integration tools (workflow automation) are foundational; action-taking AI requires the Year 1-2 foundation plus this WSP layer. Deploying agentic AI before completing Year 1-2 is the L4 Ch1 L3 "premature Year 3 ambition" failure mode.
Component 1 โ Pre-Action Compliance Checks
Pre-action compliance checks are the agentic equivalent of human pre-delivery review. Before the AI acts, the action is checked against firm-defined compliance rules. The check happens within the agentic AI's processing chain โ between decision and action โ and either allows, blocks, or routes to human review.
Rule definition. Each agentic action category (trade placement, email send, form filing, RMD processing, ACATs initiation, rebalance, beneficiary change) has documented compliance rules. Examples: trade placements above $50k flagged for human review; trades that change asset allocation beyond IPS bands blocked entirely; emails to clients flagged "do not contact" never sent; RMDs against atypical destinations (non-custodian, foreign, charitable) escalated.
Rule sources. Reg BI Care Obligation under ยง240.15l-1 (recommendation appropriateness), IPS limits (per L2 Ch5 IPS lessons), Marketing Rule 206(4)-1 (client-facing content), FINRA Rule 2210 (communications), NAIC Model #275 (annuity suitability), state DOI variations, the firm's WSP-defined prohibitions, the client's documented preferences and instructions.
Rule update cadence. Compliance rules updated as Reg BI / Marketing Rule guidance evolves (e.g., January 2026 SEC staff FAQs); ADV changes; new SEC Risk Alerts; FINRA Notices; State DOI guidance; SECURE 2.0 amendments; IRS publications; client-specific preference updates. Documented version control.
Check execution. Each pre-action check produces a structured output: allow, block, escalate-to-human, or pause-for-clarification. Reasoning captured. Timing measured. Failed checks documented.
Performance monitoring. False-positive rate (blocked actions that should have been allowed), false-negative rate (allowed actions that should have been blocked) โ measured through post-action sampling per Component 2.
Component 2 โ Post-Action Review
Post-action review samples completed agentic actions to validate the pre-action compliance checks worked. The L4 Ch3 L2 dual-sampling protocol applies here directly โ both blocked items (false-positive validation) and allowed items (false-negative validation) sampled.
Sampling strategy. Risk-tiered sampling โ higher tiers (trade execution, fund transfers, fiduciary transactions) sampled at higher rate (e.g., 25-50%); lower tiers (calendar confirmations, document deliveries) sampled at lower rate (e.g., 2-5%). Random within tier to prevent reviewer bias.
Reviewer authority. Registered principal with Rule 2210 / Rule 3110 supervisory authority. Different reviewers across sampling intervals (L4 Ch3 L2 reviewer rotation discipline).
Review timing. For irreversible actions (trade execution, fund transfers): post-action review within 1 business day for the highest tier, within 5 business days for medium tiers. For reversible actions: within 10 business days acceptable.
Findings discipline. Errors surfaced through post-action review trigger: (1) client remediation if material (e.g., trade unwind, fee reversal, client communication); (2) pre-action rule update; (3) L4 Ch3 L4 IRP activation if customer NPI or significant impact involved; (4) governance committee notification per L4 Ch6 L1; (5) supervisory log entry under Rule 4511.
Component 3 โ Kill-Switch Design
The kill-switch is the WSP's emergency-stop mechanism. The agentic AI can be paused or terminated mid-execution if anomalous behavior is detected. Without a kill-switch, agentic AI runaway is not just operationally dangerous but a Rule 3110 reasonable-design failure.
Activation criteria. Specific conditions that trigger kill-switch activation โ agentic error rate spike, unauthorized data access pattern, repeated rule violations within a window, customer complaint pattern, regulator notification thresholds. Documented in the WSP.
Activation authority. Named individuals with authority to activate (CCO, managing partner, designated operations lead, vendor support); 24x7 availability if production agentic; documented response time SLA.
Activation procedure. Step-by-step: (1) recognize anomaly via post-action review or alerting; (2) verify with second person; (3) activate kill-switch via documented mechanism; (4) verify pause confirmed by vendor; (5) initiate L4 Ch3 L4 IRP if applicable; (6) communicate to affected stakeholders; (7) post-activation review and root cause analysis.
Post-activation procedure. Documented re-enablement criteria โ agentic AI cannot restart without (a) root cause identified, (b) remediation applied, (c) governance committee approval, (d) WSP update if architectural change, (e) ADV assessment per L5 Ch7 if material.
Kill-switch testing. Quarterly tabletop or live test of kill-switch activation; documented findings; remediation if test reveals procedural gaps.
Component 4 โ Supervisory Log Under FINRA Rule 4511
The supervisory log captures the entire agentic AI decision and action trail. Under Rule 4511, the log is retained and available for examination. The L4 Ch3 L1 WSP supervisory log component is the conceptual predicate; this lesson extends to agentic-specific metadata.
Pre-action metadata. Decision inputs (trigger, client/account context, applicable rules), agentic processing chain (reasoning steps if available), pre-action compliance check results, decision outcome (act / escalate / block), timing.
Action metadata. Action taken, action target (account, custodian, client), action parameters, action timestamp, action confirmation (successful execution).
Post-action metadata. Sampling status (sampled or not), reviewer if sampled, review findings, remediation if needed, archive timestamp per L3 Ch10 archive pipeline.
Retention. Per Rule 4511 (typically 3-6 years from action) plus practice retention policy. Tamper-evident format. Retrievable on demand for examination.
Examination posture. The log enables specific examiner scenarios: "Show me the agentic AI's decision and action chain for Client B's RMD on Q4 Tuesday at 10:23 AM." The chain is complete from decision through action through post-action review.
Component 5 โ Reg BI Documentation Chain
For agentic actions that constitute recommendations under Reg BI ยง240.15l-1 (e.g., AI-driven rebalance that changes asset allocation, AI-initiated RMD destination recommendation, AI-driven beneficiary change recommendation), the Reg BI documentation discipline applies. The registered person remains accountable even when AI executes.
Care Obligation documentation. The four-alternative documentation pattern under the 2025-2026 FINRA AWC framework โ even when AI executes, the registered person's pre-deployment review of the agentic AI's recommendation logic and the documented consideration of alternatives must be retained.
Conflict Obligation. If agentic AI's behavior creates new conflicts (e.g., AI optimizing for firm metrics that conflict with client interest), the conflict is disclosed and (where required) mitigated. The L4 Ch7 L2 conflict-disclosure framework applies.
Disclosure Obligation. ADV Part 2A reflects the agentic deployment scope; engagement letter language addresses automated processing; client communication explains when AI acts vs. human acts. The L5 Ch7 off-cycle ADV amendment workflow handles material changes.
Compliance Obligation. The firm's compliance program under SEC Rule 206(4)-7 incorporates the agentic AI architecture; the L4 Ch3 L1 WSP includes the agentic section; training per L4 Ch5 addresses the registered person's role.
Component 6 โ Reg S-P Data Flow Review
Agentic AI involves data flows that may differ from generative AI's drafting workflows. The Reg S-P data flow review documents what NPI moves where, supports the May 2024 Reg S-P vendor oversight obligation, and informs the L4 Ch3 L4 IRP design.
NPI mapping. What client data the agentic AI accesses to decide and act โ account data, transaction history, beneficiary information, custodian-specific identifiers, IPS / planning data.
Vendor inventory. The agentic AI vendor's sub-processors (cloud, foundation model, analytics) โ each part of the practice's L4 Ch4 L1 vendor inventory.
Cross-border flow. Is any data processed outside US? Documented controls; ADV disclosure; California CPRA cross-border transfer notice if applicable.
Breach scenario planning. What is the breach surface if the agentic AI vendor experiences an incident? IRP coordination per L4 Ch3 L4; 30-day customer notification under May 2024 Reg S-P; 72-hour NY DFS notification.
Component 7 โ Client-Facing Disclosure
When an AI acts on behalf of the firm, the client deserves to know. The disclosure framework spans ADV, engagement letter, and direct client communication.
ADV Part 2A. Disclosure of agentic deployment scope โ what categories of actions the AI may take, what supervisory architecture applies, what client controls exist. L5 Ch7 off-cycle amendment workflow handles the disclosure update.
Engagement letter. Updated language describing the AI's role in service delivery, the client's opt-in or opt-out where applicable, the firm's supervisory responsibility, the breach-notification commitment.
Client communication. Specific notifications to affected clients before initial deployment; periodic updates if material changes. The L4 Ch7 L2 testimonial / endorsement / third-party / disclosure strategy lesson informs the framework.
Opt-out mechanism. Where required by client preference or regulation, clients may opt out of agentic processing for their accounts; documented opt-out tracking; agentic AI honors opt-outs.
What an SEC Examiner Actually Asks About Agentic AI in 2026
The 2026 SEC Division of Examinations risk-priority publication and the first round of post-Report exams have produced a recurring question pattern that the CCO should drill the team on before the examination notice arrives. The questions move in a predictable sequence. "Walk me through every category of action your agentic AI is authorized to take." The CCO produces the WSP's action-category schedule (trade placement, email send, form filing, RMD processing, ACATs initiation, rebalance, beneficiary change, calendar confirmation, document delivery) with the authorization-tier mapping. "For each category, show me the pre-action compliance rules and how the agentic AI applies them." The CCO produces the rule documentation, the version control, and a recent log entry showing the rule evaluation. "Show me your kill-switch test from last quarter." The CCO produces the quarterly tabletop minutes, the activation timing measurement, and any procedural-gap remediation notes. "Pull me three random agentic actions from the past 30 days and walk me through the post-action review." The CCO retrieves the actions from the Rule 4511 archive, demonstrates the dual-sampling protocol, and shows the reviewer-rotation evidence. "What's your false-positive and false-negative rate from the last quarter, and how have they trended?" The CCO produces the post-action review dashboard with the trend. "Show me the ADV Part 2A disclosure and the engagement letter language describing agentic deployment." The CCO produces the L5 Ch7 off-cycle amendment evidence and the engagement-letter template version. "How does your agentic AI honor a client opt-out?" The CCO walks the opt-out tracking mechanism and produces a recent opt-out example showing the AI's altered behavior. The firm that can answer all eight questions with documented evidence within an hour is the firm whose agentic deployment survives examination. The firm that cannot is the firm whose deployment will be deficient-finding territory.
Governance and the L4 Ch6 L1 Committee
The agentic AI WSP is one of the most significant policy decisions a firm makes; the L4 Ch6 L1 governance committee oversight is mandatory. The committee reviews quarterly: post-action review findings, false-positive and false-negative rates, kill-switch tests, IRP testing, ADV / engagement letter currency. The committee ratifies material WSP changes. The committee's minutes are part of the L4 Capstone documentation.
The agentic AI WSP is examined in M&A diligence per L4 Ch8 L2 โ buyers look specifically for documented agentic deployment evidence as a top-quartile AI maturity signal. Per Mercer Capital / ECHELON Q3-Q4 2025 data, top-quartile RIAs trade at 8x-10x adjusted EBITDA with the AI maturity premium attribute adding 0.5-1.5x; documented agentic-AI WSP under Rule 3110 reasonable-design supports the premium-top valuation reaching ~11.6x.
Key Takeaways
- Agentic AI changes the supervisory equation: human checkpoint moves from pre-delivery to post-action; risk asymmetry inverts (errors externalized to clients before catching); requires architectural WSP changes under FINRA Rule 3110 reasonable-design.
- Seven required components: pre-action compliance checks, post-action review with dual-sampling, kill-switch design with quarterly testing, supervisory log per FINRA Rule 4511, Reg BI documentation chain, Reg S-P data flow review, client-facing disclosure (ADV + engagement letter + direct communication).
- Pre-action compliance rules sourced from Reg BI ยง240.15l-1, IPS limits, Marketing Rule 206(4)-1, FINRA Rule 2210, NAIC Model #275, state DOI variations, WSP prohibitions, client preferences.
- Post-action review applies dual-sampling protocol (L4 Ch3 L2): both blocked items (false-positive validation) and allowed items (false-negative validation) sampled with reviewer rotation.
- Kill-switch with documented activation criteria, named authority, 24x7 availability, quarterly testing, post-activation re-enablement criteria with governance approval.
- Supervisory log captures the full agentic chain from pre-action through action through post-action review; retained per Rule 4511 for examination defensibility.
- Reg BI documentation chain applies when agentic actions constitute recommendations under ยง240.15l-1 โ Care + Conflict + Disclosure + Compliance Obligations.
- L4 Ch6 L1 governance committee quarterly oversight + ADV Part 2A material amendment (L5 Ch7) + Marketing Rule audit (L4 Ch7 L1) + cyber inventory (L4 Ch4 L1) + IRP (L4 Ch3 L4) coordination = the agentic deployment is defensible under regulatory scrutiny and supports premium top-quartile M&A valuation.
Skill.re