AI Readiness Audit for an Advisor Practice
An AI strategy that isn't grounded in an honest read of where the practice actually is โ what data lives where, who owns which workflow, what the WSP says vs. what the team does, which custodian feeds are clean and which are duct-taped โ ages like milk. This lesson is the one-page readiness audit that grounds the rest of L4. Score the practice across six dimensions (people, process, technology, data, governance, culture), identify the three highest-leverage interventions, and walk out with a single-page report a managing partner can hand to a CFO, a CCO, or a private-equity diligence team without flinching. The audit takes 90 minutes to run, two hours to write up, and saves a year of misallocated AI investment.
Why a Readiness Audit Comes Before Vendor Selection
The most expensive AI mistake an advisor practice makes in 2026 is buying tools before scoring the practice's ability to absorb them. The pattern is consistent across the Schwab 2026 RIA Benchmarking Study, the Cerulli practice-management data, and the Kitces AdvisorTech adoption series: firms that buy Jump or Zocks or Holistiplan before they have a Reg S-P-compliant vendor due diligence process, an updated ADV Part 2A AI disclosure, a written WSP under SEC Rule 206(4)-7 that names acceptable tools, and a Smarsh / Global Relay archive integration end up with shelfware, shadow IT, or โ worst case โ a 2026-era Reg S-P breach notification under the May 2024 amendments and an SEC examination with a finding on inadequate vendor oversight.
The readiness audit reverses the order of operations. Score the practice first. Find the gaps. Sequence the interventions. Then โ and only then โ pull out the L4 Ch2 vendor scorecard and start selecting tools. The audit is not a vendor evaluation. It is a self-evaluation. It produces three deliverables: a scored one-page readiness report, a ranked list of the three highest-leverage interventions, and a remediation timeline that feeds the L4 Ch1 L3 three-year roadmap.
The discipline of running the audit before selecting tools also produces a defensible regulatory artifact. The SEC Division of Examinations has, since 2024, increasingly asked advisers what process they followed before deploying an AI tool. "We bought Jump because everyone bought Jump" is not a defensible answer. "We ran a written six-dimension readiness audit, identified our top three gaps, and selected vendors whose capabilities matched our gap profile, then ran a 60-day pilot under L4 Ch2 L3" is the answer that survives. The audit itself becomes part of the firm's compliance record under SEC Rule 204-2 and FINRA Rule 4511.
Dimension 1 โ People
The people score asks one question in five different ways: does the practice have the human capacity, skill, and motivation to operationalize AI without breaking the supervisory model? The five sub-scores:
Advisor AI literacy โ Can the producing advisors articulate the difference between an LLM and an extractor? Can they explain to a 70-year-old client what AI does and does not do in the practice (the L1 Ch1.1 client script)? Can they recognize a hallucinated RMD age, a fabricated cost basis, an invented IRC citation (the L1 Ch2.2 hallucination gallery)? Score 1-5 by surveying the advisor team โ five questions from L1, scored objectively. A practice with 80%+ of advisors scoring 4 or 5 is "ready"; under 50% is "rebuild from L1 before tool deployment."
Compliance / CCO capacity โ Does the practice have a CCO (in-house or outsourced) who has read the FINRA 2026 Annual Regulatory Oversight Report's GenAI section, the SEC Division of Examinations Risk Alerts on AI-washing, the January 2026 staff FAQs on Marketing Rule, and the May 2024 Reg S-P amendments? Does the CCO have the bandwidth to add an AI workstream โ or is the CCO already at capacity on the existing program? A solo's CCO score is their own self-assessment.
Operations / paraplanner capacity โ Who actually runs the workflows? In most ensemble RIAs, the paraplanners and CSAs absorb 70% of the operational load. Their AI fluency, their workflow muscle memory, and their willingness to redesign the workflow around new tools determine whether the tool deploys or shelves.
IT / technical capacity โ Is there someone who can integrate Jump to Wealthbox to Smarsh, configure Microsoft Defender for Cloud Apps to block shadow LLM access, set up SSO for the enterprise LLM, and audit data flows for Reg S-P compliance? Solo and small ensemble practices typically score low here; the remediation is an outsourced IT/MSP relationship.
Leadership commitment โ Has the managing partner / firm owner publicly committed to AI as a multi-year investment, with budget, time, and patience for failed pilots? Or is the AI initiative someone's side project that loses to the next CRM migration?
The people score is the most under-weighted dimension in most firm audits and the most determinative of actual AI ROI. A firm with strong tools and weak people produces shelfware. A firm with weak tools and strong people compounds capability quarter over quarter. The L4 Ch5 90-day adoption curve lesson is the operational follow-up for any practice scoring under 3.5 on people.
Dimension 2 โ Process
Process asks whether the practice's workflows are documented, repeatable, and instrumented enough that AI can meaningfully plug into them. Five sub-scores:
Workflow documentation โ Are the practice's core motions (annual review, quarterly meeting, onboarding, Reg BI rollover memo, IPS update, beneficiary audit, Roth conversion, RMD calendar, year-end tax-loss harvest) written down? Or do they live in the head of the senior advisor? Undocumented workflows cannot be AI-augmented systematically; they get one-off prompts that the team forgets in three weeks. The L3 capstone deliverable (the practice playbook with 10 named workflows) is the target state.
Reg BI documentation discipline โ Does every recommendation have a documented file: recommendation memo, documented consideration of reasonably available alternatives, costs comparison, client-specific rationale, reviewer signoff? The 2025-2026 FINRA AWC pattern on inadequate rollover Reg BI documentation is the canonical enforcement reference. A practice with weak Reg BI documentation hygiene cannot safely deploy AI drafting of Reg BI memos โ the AI will produce more memos, faster, with the same documentation gap, and the volume will accelerate exam exposure.
Marketing Rule pre-use review โ Is there a documented pre-use review process for client-facing content under SEC Marketing Rule 206(4)-1? Does the firm maintain a substantiation file for any AI-related capability claim? The 2024-2025 AI-washing settlements (Delphia, Global Predictions, the broader 2025 enforcement cluster) and the SEC Division of Examinations Risk Alerts make this a non-optional process layer.
Archive and retention pipeline โ Is Smarsh or Global Relay (or ACA / NRS for smaller scale) integrated with the meeting AI, the CRM, the planning software, and the LLM under FINRA Rule 4511 and SEC Rule 204-2? The L3 Ch10 Zocks-to-Wealthbox-to-Smarsh pipeline lesson is the operational target.
NIGO and follow-up SLA โ Does the practice measure NIGO (Not In Good Order) rate at the custodian, time-to-follow-up after meetings, and percentage of action items closed on time? These are the leading indicators of operational AI maturity (L4 Ch5 L2 dashboard) โ and the cleanest places to demonstrate ROI to a CFO or a buyer.
Process scoring is mechanical: each sub-score gets a 1-5. The mode is typically 2-3 for mid-sized RIAs entering L4 โ workflows exist informally, Reg BI documentation has gaps, Marketing Rule pre-use review is ad hoc, the archive is in place but not integrated to AI outputs, and NIGO/SLA are not measured. The remediation sequence is the next chapter's content.
Dimension 3 โ Technology
Technology asks whether the existing stack can absorb AI without rebuild, and whether the firm has the procurement and vendor-management muscle to add tools defensibly. Five sub-scores:
CRM maturity โ Wealthbox, Redtail, Salesforce FSC, or Practifi at a configured state with custom fields, activity tracking, and the ability to ingest structured AI output? Or a stale CRM that captures barely 60% of activity? The CRM is the system of record for everything downstream of an AI workflow; an immature CRM caps AI ROI hard.
Planning software depth โ RightCapital, eMoney, or MoneyGuidePro with the household actually modeled to current facts, not a 2022 vintage plan? AI extraction (Holistiplan, FP Alpha, Wealth.com) downstream-syncs into planning software; stale plans poison the AI's contextual usefulness.
Custodian integration cleanliness โ Schwab, Fidelity, Pershing, BNY Mellon feeds reconciled cleanly, with daily position and transaction data flowing into the portfolio system (Orion, Tamarac, Black Diamond) without manual re-keying? Multi-custodian RIAs (L4 Ch1 L1 archetype 3) score this dimension hardest and most consequentially.
Archive integration โ Smarsh / Global Relay capturing email, IM, voice, and (critically) Zoom / Teams / Webex meeting recordings? AI-aware archive search enabled? L3 Ch10 L1 pipeline operational?
Identity / access management โ SSO across the major tools, MFA enforced under NY DFS 23 NYCRR 500 expectations, role-based access controls aligned to the WSP, and an audit log for who accessed which client data when? This is the most-skipped dimension at firms scoring low overall and the one Reg S-P May 2024 amendments most directly require.
Dimension 4 โ Data
Data is the dimension that most often produces a surprise score. The firm believes it has good data because Schwab statements arrive monthly. The audit finds that 18% of households have stale beneficiary designations in the CRM, 23% of plans were last updated in 2022 or earlier, and the household-to-account-to-position graph is reconciled only at the custodian level, not at the practice level. Five sub-scores:
Data classification โ Has the firm classified its data into NPI / non-NPI buckets, with retention schedules and access controls per bucket? The May 2024 Reg S-P amendments and the NIST AI RMF both anchor here.
Data freshness โ How current are the household facts in the CRM, the plans in the planning software, the beneficiary designations in the file? AI on stale data produces stale recommendations. The remediation is the L2 Ch3 quarterly SLA audit operationalized.
Data accuracy / reconciliation โ Do the custodian feeds reconcile to the CRM, the planning software, and the billing system? Multi-custodian RIAs score this dimension as a make-or-break.
Data integration โ Can data flow from the meeting AI to the CRM to the planning software to the archive without manual re-keying? Integration debt (L4 Ch1 L1 multi-custodian failure mode) lives here.
Data lineage โ Can the practice trace a specific number on a client's plan back to its source system, the date pulled, and the version used? Essential for the Cardinal Rule (L1 Ch2.3) source-system verification step.
Dimension 5 โ Governance
Governance asks whether the firm has the policy infrastructure to deploy, supervise, and disclose AI defensibly. Five sub-scores:
WSP coverage โ Does the WSP have a discrete section on AI use, naming acceptable tools, prohibited data categories, approval workflow for new use cases, training requirements, and incident response? The L4 Ch3 L1 model WSP is the target. Mapped to FINRA Rule 3110 reasonable design and SEC Compliance Rule 206(4)-7.
Vendor due diligence process โ Is there a documented 40-question vendor DD process (L4 Ch2 L2) covering SOC 2 Type II, Reg S-P May 2024 amendments, GLBA Safeguards, NY DFS 500, and FINRA 2026 cyber expectations? Does the firm complete and retain DD before any new vendor touches NPI?
ADV Part 2A AI disclosure โ Is the ADV Part 2A current on AI tool use? Does the firm have an off-cycle amendment process for material AI tool changes (L5 Ch7 cross-reference)? Is the engagement letter language coordinated?
Incident response program (IRP) โ Is there a written IRP per the May 2024 Reg S-P amendments โ naming roles, escalation paths, the 30-day customer notification clock, the 72-hour NY DFS notification clock, and E&O carrier reporting? Tested annually?
Marketing Rule audit posture โ Has the firm scrubbed every AI-related capability claim in marketing materials, the website, the ADV, and the engagement letter? Maintained a substantiation file? Run the L4 Ch7 L1 AI-washing risk audit at least annually?
Dimension 6 โ Culture
Culture is the dimension that decides whether the other five turn into outcomes. Five sub-scores:
Curiosity / learning posture โ Do advisors actually try new tools, share findings in team meetings, and read the FINRA / SEC / NAIC updates? Or does new technology arrive as a top-down mandate and die in shadow IT?
Tolerance for documented failure โ Will the firm publicly retire a pilot that didn't work, document the lesson, and move on? Or is every tool decision treated as permanent commitment? The L4 Ch2 L3 pilot framework requires explicit kill-criteria; a culture that cannot kill pilots cannot run them.
Compliance posture โ Is the CCO seen as a partner in deployment or as a roadblock? The L4 Ch3 L1 WSP design lesson is the operational predicate; a culture that treats compliance as adversarial cannot land defensible AI.
Client-conversation comfort โ Can advisors explain AI use to a 70-year-old client, a CPA, a divorce attorney, and a 38-year-old equity-comp executive โ each in the right register? The L1 Ch1.1 90-second client script is the deliverable; the audit asks whether 80%+ of advisors can deliver it.
Cross-functional collaboration โ Do compliance, operations, advisor, and IT functions meet on AI as a single committee (L4 Ch6 L1 governance committee) โ or in separate, conflicting silos?
The One-Page Readiness Report and the Three Interventions
The output of the audit is a single page. Six dimensions, each scored 1-5 on five sub-dimensions, weighted equally, producing a 30-point dimension score and a 180-point overall. Reference bands:
0-60 โ Rebuild from L1. The practice cannot safely deploy AI tools. Spend the next quarter on L1 advisor literacy and L2 process documentation before any new tool purchase. Re-audit in 90 days.
61-110 โ Selective intervention. The practice can deploy specific AI tools in defined workflows where the score is highest. Focus on the three lowest-scoring sub-dimensions; do not buy across the board.
111-145 โ Ready for full deployment. The practice can execute the L4 Ch1 L3 three-year roadmap. Vendor scorecard (Ch2), WSPs (Ch3), cyber (Ch4), training (Ch5) all flow normally.
146-180 โ M&A-ready. The practice is a top-quartile AI-mature firm. The L4 Ch8 valuation chapter applies: top-quartile RIAs at 8x-10x adjusted EBITDA per Mercer Capital and ECHELON Q3-Q4 2025, with AI maturity adding 0.5-1.5x โ premium-top transactions reaching ~11.6x.
The three highest-leverage interventions are not the three lowest sub-scores. They are the three interventions where remediation unblocks the most downstream value. The interaction matters: fixing data freshness (dimension 4) before fixing CRM maturity (dimension 3) wastes effort because the freshening flows into a CRM that can't hold the data. Fixing WSP coverage (dimension 5) before fixing advisor AI literacy (dimension 1) produces a WSP no one understands. The audit's value is in the sequencing logic โ typically run as a 90-minute workshop with the managing partner, the CCO, the head of operations, and the lead advisor.
The deliverable is a one-page report. Top half: the six-dimension score wheel with the 180-point total. Bottom half: the three ranked interventions with named owner, 90-day milestone, success metric, and budget. Footer: the four-signature line (managing partner, CCO, operations, lead advisor) certifying the audit. Filed under the WSP. Re-run annually. Updated mid-year if a material event (new tool, new advisor, new custodian, M&A, examination) changes the score by more than 15 points.
Key Takeaways
- The readiness audit precedes vendor selection. Score the practice across six dimensions before pulling out the L4 Ch2 vendor scorecard. The audit itself becomes a regulatory artifact under SEC Rule 204-2 and FINRA Rule 4511.
- Six dimensions, five sub-scores each, 1-5 scale, 180-point total: people, process, technology, data, governance, culture.
- Reference bands: 0-60 rebuild from L1, 61-110 selective intervention, 111-145 ready for full deployment, 146-180 M&A-ready (top-quartile, 8x-10x adjusted EBITDA, AI maturity premium +0.5-1.5x per Mercer Capital / ECHELON Q3-Q4 2025).
- People is the most under-weighted and most determinative dimension โ advisor literacy, CCO capacity, operations bandwidth, IT capacity, leadership commitment.
- Process scoring catches Reg BI documentation hygiene, Marketing Rule pre-use review, archive integration (Smarsh / Global Relay), and NIGO/SLA measurement โ the operational predicates for safe AI deployment.
- Governance scoring covers WSP, vendor DD, ADV Part 2A AI disclosure, written IRP under May 2024 Reg S-P, and Marketing Rule audit posture.
- The three highest-leverage interventions are sequenced for downstream unlock, not picked by lowest individual sub-score. The audit's value is in the sequencing logic.
- One-page report, four signatures, annual re-run, mid-year update if scores move 15+ points โ feeds directly into the L4 Ch1 L3 three-year roadmap and budget.
Skill.re