AI Risk Register and Governance Committee for an Advisor Practice
A CCO who can't produce a written AI risk register with named owners and named mitigations in under 15 minutes when an SEC examiner asks for it is the CCO of a practice that gets the next AWC. A practice owner who hasn't stood up an AI Governance Committee by mid-2026 is running a deployment with no organizational mechanism for the cross-functional decisions that AI strategy requires โ vendor approvals, agentic-action authorizations, incident response coordination, Marketing Rule audits, ADV amendment timing. This lesson installs the twelve top risks for a 2026 advisor practice (each with named mitigation and named owner), the AI Governance Committee charter (membership, decision rights, meeting cadence, relationship to existing compliance committee), and the operating rhythm that turns governance from a compliance theatre exercise into the load-bearing layer of the practice's AI strategy.
Why a Discrete AI Risk Register, Not a Footnote in the Existing Compliance Register
Most advisor practices already maintain a compliance risk register under SEC Compliance Rule 206(4)-7 and FINRA Rule 3110 reasonable design โ typically a spreadsheet listing the top operational, market, regulatory, and reputational risks with owner names and review cadence. The instinct in 2025 was to add a single line item "AI-related risk" to the existing register. By mid-2026 that approach has failed across enough practices that the trade press, the FINRA 2026 Annual Regulatory Oversight Report, and the practitioner literature (Smarsh, ACA Group, Debevoise, Sidley Austin, Snell & Wilmer, AdvisorEngine, Ncontracts) converge on a single recommendation: AI risk gets its own discrete register, owned by a discrete governance body, with a discrete operating rhythm.
Three reasons. First, the velocity is different โ vendor capabilities change quarterly, regulatory guidance changes (the January 2026 SEC staff FAQs on Marketing Rule, the FINRA 2026 Annual Regulatory Oversight Report's agentic-AI section, the Reg S-P 17 CFR Part 248 May 2024 amendments' compliance dates that wave through 2025-2026), and the practice's own AI footprint changes month-to-month. A risk surfaced and mitigated in March is replaced by a new risk in April. The existing compliance register's annual cadence doesn't keep up. Second, the cross-functional coordination is different โ AI risk touches CCO, CTO if the firm has one, COO, head of advisory, lead advisor, and outside counsel in ways the existing compliance committee isn't structured to handle. Third, the documentation requirements are different โ under FINRA Rule 4511 and SEC Rule 204-2, the supervisory artifacts associated with AI deployments (prompts, outputs, edits, signoffs, incident records) are a different category of record than the operational risk artifacts the compliance committee already manages.
The practical implication: stand up the AI risk register and the AI Governance Committee as a discrete structure with a defined relationship to the existing compliance committee (the AI Governance Committee reports up; the existing compliance committee does not duplicate the AI work). The L4 capstone deliverable explicitly requires this artifact set.
The Twelve Top Risks for an Advisor Practice in 2026
Each risk below names the mechanism, the operational signal that surfaces it, the regulatory anchor, the mitigation, and the named owner.
Risk 1 โ Hallucination
An LLM produces a confident, well-formed statement with no factual basis: invented account number, fabricated cost basis, wrong RMD age (SECURE 2.0 confusion between 70ยฝ, 72, 73, and the 75 step-up in 2033), made-up FINRA rule citation, plausible-sounding inaccurate Social Security PIA math, hallucinated trust language. Operational signal: NIGO rate worsening, principal review exception spike, advisor edit log showing high-volume corrections. Regulatory anchor: Reg BI Care Obligation ยง240.15l-1(a)(2)(ii) ("reasonable basis" requirement) and FINRA Rule 2210 on accuracy of communications. Mitigation: L1 Ch2 L3 Cardinal Rule three-tier verification (source-system, regulatory, client-fit) on every AI-touched artifact before signoff; principal review queue under Rule 2210; firm-approved prompt library that constrains output style and citation discipline. Named owner: CCO, with advisor-level execution.
Risk 2 โ Data Leakage / NPI Exposure
Client NPI lands in a non-approved tool โ free public ChatGPT, personal Microsoft Copilot, Claude Pro personal, an unvetted vendor's training pipeline, or a screenshot uploaded to a public service. Operational signal: incident reports from advisors, vendor audit findings, anomalous prompt patterns in approved-tool logs, monitoring alerts. Regulatory anchor: Reg S-P 17 CFR Part 248 May 2024 amendments (30-day breach notification, written incident response program, vendor oversight), GLBA Safeguards Rule, NY DFS 23 NYCRR 500 third-party-service-provider expectations, California CPRA, Texas DIR. Mitigation: written AI Use Policy (the L1 capstone), approved-tool list with prohibited-tool list, advisor training, vendor due-diligence file with SOC 2 Type II review (L4 Ch2 L2), incident response plan under Reg S-P. Named owner: CCO with CTO / IT lead support.
Risk 3 โ Prompt Injection
A malicious actor (or an unwitting client uploading a poisoned PDF) embeds instructions in input data that override the system prompt, exfiltrate data, or cause the AI to behave outside policy. The classic 2025-2026 examples include an estate document uploaded to Wealth.com or FP Alpha with hidden text that instructs the extractor to mis-classify the trustee, and a prospect's "LinkedIn profile" pasted into Catchlight that includes instructions to summarize as a fabricated UHNW profile. Operational signal: anomalous extraction output, unexplained context-window behavior, advisor-flagged inconsistencies. Regulatory anchor: Reg BI Care Obligation, FINRA Rule 3110 reasonable-design supervision, Reg S-P if data is exfiltrated. Mitigation: vendor-attested input-sanitization architecture, prompt-injection-resistant system prompts, output validation against expected schemas, advisor training to recognize anomalous output. Named owner: CTO or IT lead with CCO coordination.
Risk 4 โ Vendor Lock-In
The practice's workflow is so embedded in one vendor's API, data model, or proprietary archive integration that switching costs grow over time and the vendor's pricing power expands. The Holistiplan 10,000-firm install base, the Jump enterprise integration with Salesforce Financial Services Cloud + Einstein, and the Smarsh / Global Relay archive connectors are all 2026 examples of high-switching-cost dependencies. Operational signal: annual pricing increases, vendor reduced responsiveness, contract terms tightening at renewal, exit-path estimates rising. Regulatory anchor: FINRA Rule 3110 reasonable-design and Compliance Rule 206(4)-7 (the supervisory architecture must remain workable independent of any single vendor); ADV Part 2A disclosure if a switch materially changes data flows. Mitigation: contracted exit clauses, data-portability requirements in the master agreement, periodic alternative-vendor PoCs, parallel-tool experimentation per L5 Ch2 L2. Named owner: COO with practice owner coordination.
Risk 5 โ Regulatory Drift
The regulatory regime under which a tool was approved changes โ a new SEC Risk Alert, a new FINRA notice, a new state DOI bulletin, an NAIC AI Model Bulletin update, a new SEC Marketing Rule FAQ โ and the practice's WSPs, ADV disclosure, or tool usage falls out of compliance. The January 2026 SEC staff FAQs on third-party ratings and hypothetical performance, the FINRA 2026 Annual Regulatory Oversight Report's agentic-AI section under Rule 3110, and the rolling Reg S-P 17 CFR Part 248 compliance dates (December 2025 for large advisers, June 2026 for smaller) are the 2026 reference set. Operational signal: regulatory bulletin published, trade press coverage of new enforcement, peer firm AWC. Regulatory anchor: all of them. Mitigation: quarterly regulatory scan owned by CCO, outside counsel quarterly check, WSP refresh cycle, ADV Part 2A annual amendment with off-cycle trigger documented in L4 Ch7 L2. Named owner: CCO with outside counsel quarterly support.
Risk 6 โ Model Bias
An AI tool produces systematically different output for similar clients based on protected-class proxies (ZIP code, name, gender markers in narrative, age in voice analysis). The wealth-specific examples include life-expectancy assumptions in retirement income modeling, ZIP-code-defaulted asset allocation, gendered Social Security claiming defaults, and credit-related referrals showing race-correlated patterns. Operational signal: advisor-flagged inconsistencies, sample audit findings, client complaints. Regulatory anchor: CFP Board Code and Standards, Investment Advisers Act fiduciary duty of care, NAIC AI Model Bulletin on unfair discrimination in insurance, ECOA-related concerns for credit-touching AI. Mitigation: quarterly bias audit on a representative client sample, system-prompt constraints removing protected-class inputs, vendor attestation on fairness testing in the SOC 2 file. Named owner: Head of advisory with CCO oversight.
Risk 7 โ M&A Integration Risk
The practice acquires a book or is acquired, and the AI stack mismatch produces gaps in archive coverage, supervisory continuity, prompt-library transfer, advisor adoption, or client communication standardization. The L4 Ch8 L3 lesson develops this in depth. Operational signal: M&A under consideration, LOI signed, integration kickoff. Regulatory anchor: FINRA Rule 3110, Rule 4511, ADV Part 2A amendment for material changes, Reg S-P vendor transition under 17 CFR Part 248. Mitigation: pre-close diligence pack covering AI maturity (L4 Ch8 L2), 90-day post-close integration plan (L4 Ch8 L3), parallel archiving during transition, advisor-comp redesign accounting for AI fluency. Named owner: COO with CCO coordination during transition.
Risk 8 โ Key-Person Risk on Internal Champion / Prompt Librarian
The internal champion (L4 Ch5 L1), the prompt librarian (L5 Ch4 L1), or the senior AI-fluent advisor leaves or becomes unavailable, and the practice's AI capability degrades because the institutional knowledge wasn't documented or distributed. Operational signal: single-point-of-failure mapping, talent-retention concerns, succession-plan gaps. Regulatory anchor: business continuity plan requirements under FINRA Rule 4370 and SEC Rule 206(4)-7 compliance program; ADV Part 2A disclosure on material changes. Mitigation: documented prompt library with version control, cross-trained backup champion, succession plan for key AI roles, retention packages with AI tool access (L4 Ch8 L3). Named owner: Practice owner with COO support.
Risk 9 โ Training Data Poisoning
A vendor's training pipeline (for fine-tuned models or RAG systems) is exposed to adversarial inputs that corrupt subsequent outputs โ particularly relevant for any RAG-to-firm-vault deployment (L3 Ch9 L2) where the firm's own documents feed the model. Operational signal: unexpected output patterns, retrieval anomalies, vendor security incidents. Regulatory anchor: Reg S-P 17 CFR Part 248 (data integrity component of vendor oversight), FINRA Rule 3110 reasonable design. Mitigation: documented training data sources, vendor SOC 2 Type II review with data-integrity controls, input-sanitization for RAG pipelines, regular output validation. Named owner: CTO with CCO coordination.
Risk 10 โ Agentic-Action Error
An AI agent (placing a trade, sending an email, filing a form, processing an RMD, initiating an ACAT) acts outside the authorized envelope. The FINRA 2026 Annual Regulatory Oversight Report's section on agentic AI under Rule 3110 reasonable design framed this explicitly. Operational signal: unauthorized actions, kill-switch activations, post-action review exceptions. Regulatory anchor: FINRA Rule 3110 reasonable design, Rule 4511 retention of action logs, Reg BI Care Obligation for recommendation-bearing actions under ยง240.15l-1, SEC Rule 206(4)-7 compliance procedures. Mitigation: agentic-AI WSPs (L4 Ch3 L3) โ pre-action approval thresholds, kill-switch design, post-action review, supervisory log under Rule 4511. Named owner: CCO with CTO and head of advisory.
Risk 11 โ Supervisory Gap
The practice's WSPs under FINRA Rule 3110 reasonable design don't cover a specific AI use case the advisors are actually running โ typically because the use case emerged after the last WSP refresh. Operational signal: advisor-reported "I started using X but it isn't in the policy," exception in principal review, audit finding. Regulatory anchor: FINRA Rule 3110, SEC Compliance Rule 206(4)-7. Mitigation: WSP quarterly refresh cycle, advisor self-reporting of new tool use, AI Governance Committee approval gate for any new tool or use case. Named owner: CCO.
Risk 12 โ Client Perception / Trust Erosion
A client perceives the practice's AI usage as substituting for advisor judgment, or learns the practice uses AI in a way the client didn't expect, or reads a public AI-washing enforcement headline and assumes the practice is implicated. Operational signal: client complaint, prospect drop-off citing AI concerns, social media mention. Regulatory anchor: SEC Marketing Rule 206(4)-1 ("clear and prominent" disclosure), ADV Part 2A disclosure obligations, CFP Board Code and Standards transparency duty. Mitigation: client disclosure language in engagement letter and ADV Part 2A, the 90-second client script (L1 Ch1 L1 Key Takeaway), proactive transparency in quarterly client communication. Named owner: Head of advisory with CCO oversight on disclosure language.
The AI Governance Committee Charter
The committee is a discrete body, chartered by the practice owner or partner group, with a written charter signed at standup and reviewed annually. The charter has six elements.
Purpose and Scope
The committee owns the AI risk register, the WSPs governing AI under FINRA Rule 3110 (or the practice-level equivalent for an RIA-only firm under SEC Compliance Rule 206(4)-7), the approved-tool list, the prohibited-data-category list, the principal-review-queue design under Rule 2210 and Marketing Rule 206(4)-1, the incident response procedures under Reg S-P 17 CFR Part 248, the vendor due-diligence process (L4 Ch2 L2), the training program (L4 Ch5 L1), and the ROI dashboard (L4 Ch5 L2). The committee does not own day-to-day vendor management, day-to-day advisor adoption support, or day-to-day client communication โ those remain operational and report into the committee monthly.
Membership
The committee has six core members. CCO (chair) โ owns the regulatory framing, the WSPs, the incident response coordination, and the books-and-records integration with the AI Governance Committee minutes under Rule 4511 and SEC Rule 204-2. CTO or IT lead โ owns vendor due diligence (SOC 2 Type II review, encryption, MFA, NY DFS Part 500 third-party service provider attestation), integration architecture, and prompt-injection / data-poisoning technical controls. Head of advisory โ owns advisor-facing adoption, the prompt library content, training design, and head-of-advisory-level escalations. Lead advisor (or in a solo practice, the producing advisor) โ owns the producing-advisor perspective and represents the workflow reality of AI usage. Ops lead โ owns integration friction, archive coverage under Smarsh / Global Relay, NIGO trend ownership at the operational layer, and dashboard production. Outside counsel (attending as needed, not as a permanent member) โ owns the regulatory-drift quarterly scan, Reg S-P / Marketing Rule / Reg BI interpretation, ADV amendment review, and any enforcement-related advice. For practices with fewer than six suitable staff, the same person may hold two roles (CCO + outside counsel coordination is the most common dual-hat); the committee minutes document the dual-hat arrangement explicitly.
Meeting Cadence
Monthly is the standard cadence. The agenda has a fixed structure: (1) dashboard review (L4 Ch5 L2); (2) risk register review with any new entries, status changes, or closures; (3) approval queue for new tools, new use cases, or new agentic-action authorizations; (4) incident review for any month-over-month incidents under Reg S-P or principal review exception clusters under Rule 2210; (5) regulatory scan covering any new SEC, FINRA, state DOI, or NAIC bulletin in the prior month; (6) action items with named owners and due dates. The meeting produces minutes that become books-and-records under Rule 4511 + SEC Rule 204-2. Quarterly, the committee adds a deep-dive on one risk area; annually, the committee runs a full WSP refresh cycle and an annual charter review.
Decision Rights
The committee has decision authority over: approving new AI tools for use on NPI; approving new use cases requiring WSP updates; authorizing agentic-action thresholds; approving the principal review sampling rate under Rule 2210; approving the budget allocation across tool categories. The committee has recommendation authority (with the practice owner / partner group as decision-maker) over: budget growth above a threshold (typically 20% YoY or a named dollar figure); new vendor categories; M&A-AI-integration strategy. Major Marketing Rule decisions (any AI-washing-adjacent claim, any close-rate or households-per-advisor performance claim used externally, any testimonial / third-party-rating mechanic involving AI) escalate to outside counsel as a permanent gate โ operationalized in L4 Ch7 L2.
Relationship to the Existing Compliance Committee
The AI Governance Committee reports up to the existing compliance committee or the partner group monthly. The two committees do not duplicate work โ the existing compliance committee continues to own operational risk, market risk, custodian relationships, fee schedule, custody compliance, the broader Compliance Rule 206(4)-7 written supervisory procedures, and the FINRA Rule 3110 supervisory architecture at the non-AI layer. The AI Governance Committee owns the AI-specific layer of each. The escalation path is documented in the charter: incidents above a defined threshold, regulatory developments above a defined materiality, or budget items above a defined dollar threshold escalate from the AI Governance Committee to the existing compliance committee with named timelines.
Quorum, Minutes, and Meeting Discipline
Quorum is typically four of six core members. Minutes are produced by the CCO or designated secretary, circulated within 5 business days, and stored in the books-and-records archive under FINRA Rule 4511 and SEC Rule 204-2. Decisions are recorded with attendance, vote (when applicable), and rationale. The minutes are exhibit-grade โ the practice's supervisory architecture defense in any SEC exam or FINRA cycle is the 12-24 month rolling set of monthly minutes plus the supporting dashboards and WSPs.
How the Register and the Committee Work Together Monthly
The risk register is a living document, updated by the CCO between meetings and reviewed by the committee at every meeting. The flow each month: (1) any advisor or staff member can submit a risk observation via a documented channel (typically a Wealthbox / Redtail / Salesforce FSC custom form or a Slack channel logged into the archive); (2) the CCO triages observations into existing register entries or new entries; (3) the committee reviews each open entry monthly, validates the mitigation, checks the owner's progress, and either closes, extends, or escalates; (4) new risks (regulatory, operational, vendor) get added; (5) the dashboard's threshold breaches (L4 Ch5 L2) auto-generate register entries.
The pattern that works: roughly 5-8 new register entries per month, 60-80% close within one quarter, 15-25% become standing risks with ongoing monitoring, 5-10% escalate to the existing compliance committee or outside counsel. A register that produces zero new entries in a month is a register that isn't being looked at; a register that produces 20+ is a deployment in distress. Practice owners should expect the steady-state to land in the 5-8 range.
Three Named 2026 Scenarios the Committee Will Handle
Scenario A โ A new SEC Marketing Rule FAQ drops in January 2026 clarifying third-party rating mechanics. The CCO's quarterly regulatory scan flags it; the committee's monthly meeting reviews the implication; outside counsel attends to interpret; the practice's Catchlight / SmartAsset / Barron's / Forbes-ranking content is audited within 30 days; the ADV Part 2A and the marketing-archive sweep are completed by month 60; the L4 Ch7 L2 lesson framework governs the operational response. Register entry opened and closed within 60 days.
Scenario B โ A pilot advisor in week 4 of a new deployment accidentally pastes a client's SSN into personal Microsoft Copilot. Incident reported within hours by the advisor (the L1 Ch5 L2 training paid for itself); CCO activates the Reg S-P 17 CFR Part 248 IRP; the 30-day breach clock starts; affected client notified per the IRP; vendor (Microsoft) contacted; outside counsel reviews the notification obligations to the SEC and any applicable state regulators; NY DFS 72-hour rule check; E&O carrier notified; the AI Use Policy refreshed with the specific failure example; the prohibited-tool list expanded; advisor retraining scheduled. Register entry opened and closed within 90 days with a standing entry to track recurrence.
Scenario C โ The FINRA 2026 Annual Regulatory Oversight Report's agentic-AI section drives the practice to consider authorizing AI-initiated trade execution for narrow rebalance-only scenarios in Orion Eclipse. The committee runs a multi-meeting evaluation: the L4 Ch3 L3 agentic-AI WSP framework is drafted; pre-action approval thresholds set (no agentic action above $X, no agentic action on a Reg BI-bearing recommendation, no agentic action without prior client written consent); kill-switch architecture designed; post-action review sampling rate set under Rule 2210 / Rule 3110; books-and-records integration confirmed under Rule 4511; ADV Part 2A amendment drafted and filed; client communication drafted with Marketing Rule 206(4)-1 disclosure. The committee makes the authorization decision in month 4 of the evaluation. The standing register entry tracks the agentic deployment monthly thereafter.
The L4 Capstone Link
The L4 capstone deliverable is a 30-page strategic AI plan for the practice โ readiness audit, three-year roadmap, vendor selection rationale, WSPs (including agentic-AI WSPs), training plan, ROI dashboard, risk register, Marketing Rule audit, cybersecurity playbook, and M&A-defensibility memo, presentable to a board, a buyer, or an SEC examiner. The risk register and the AI Governance Committee charter are two of those ten artifacts. The L4 Ch5 lessons (90-day adoption curve, ROI dashboard) produce the data layer the register and committee operate on. The L4 Ch6 L2 lesson on State DOI / NAIC AI Model Bulletin / annuity suitability layers the regulatory complexity for the dually-licensed advisor. The L4 Ch7 lessons handle the Marketing Rule and ADV strategy layer. The L4 Ch8 lessons handle the M&A integration layer. All ten artifacts together produce the practice's defensible AI strategy.
Key Takeaways
- AI risk gets a discrete register and a discrete committee โ not a footnote in the existing compliance register. Velocity, cross-functional coordination, and documentation requirements differ from the existing compliance risk.
- Twelve top risks, each with named mechanism, signal, anchor, mitigation, owner. Hallucination, data leakage, prompt injection, vendor lock-in, regulatory drift, model bias, M&A integration, key-person on champion/prompt-librarian, training-data poisoning, agentic-action error, supervisory gap, client perception.
- AI Governance Committee membership: CCO (chair), CTO / IT lead, head of advisory, lead advisor, ops lead, outside counsel as needed. Quorum 4 of 6. Dual-hat arrangements documented explicitly in minutes.
- Monthly cadence with fixed agenda. Dashboard review (L4 Ch5 L2), risk register review, approval queue (tools / use cases / agentic actions), incident review under Reg S-P + Rule 2210 exceptions, regulatory scan (SEC, FINRA, state DOI, NAIC), action items with named owners.
- Decision rights: committee approves new tools on NPI, new use cases, agentic thresholds, principal review sampling rate (under Rule 2210), budget allocation across tool categories. Marketing Rule decisions escalate to outside counsel as a permanent gate.
- Minutes are exhibit-grade. 12-24 month rolling set + dashboards + WSPs = supervisory architecture defense under FINRA Rule 3110 reasonable design, FINRA Rule 4511, SEC Rule 204-2, and SEC Compliance Rule 206(4)-7.
- Healthy register cadence is 5-8 new entries per month with 60-80% closing within a quarter. Zero new = not being looked at. 20+ new = deployment in distress.
- The committee is the load-bearing layer. AI Use Policy + WSPs + risk register + dashboard + monthly minutes + WSPs + outside counsel quarterly + the L4 capstone artifact set together produce the practice's defensible AI strategy.
Skill.re