โ†
AI for Financial Advisors & Wealth Managers
Strategic ยท M8 ยท lesson 8 of 21 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
AI-Washing Risk Audit and Remediation
๐Ÿ“–
now learning

AI-Washing Risk Audit and Remediation

15 min

The 2024-2025 SEC AI-washing settlements (Delphia, Global Predictions, and the broader 2025 enforcement cluster), the SEC Division of Examinations Risk Alerts on Marketing Rule compliance, and the January 2026 SEC staff FAQs on third-party ratings, hypothetical performance, and testimonial mechanics together produce a single operating reality for the advisor practice in 2026: every place the practice has ever claimed "AI-powered," "machine-learning-driven," "algorithmic," "proprietary AI," "AI-augmented planning," or any kindred language is a Marketing Rule 206(4)-1 artifact that must survive substantiation, "clear and prominent" disclosure, and the cherry-picking / fair-and-balanced framework. This lesson installs the audit-and-remediation playbook a CCO runs to find every claim, evaluate it against the 2026 enforcement standard, fix it through a substantiation file, language rewrite, ADV update, and marketing-archive sweep, and stand up the ongoing discipline that prevents the next claim from drifting into AI-washing territory.

The 2024-2026 Enforcement Landscape โ€” What the Settlements Actually Held

The SEC's March 2024 Delphia and Global Predictions settlements turned on a single, recurring fact pattern: the firms marketed AI-based capability they did not actually have or did not actually use in the way marketing implied. Delphia represented that it used AI and machine learning to "predict which companies and trends are about to make it big and invest in them before they are mainstream"; the SEC found the firm did not in fact have or use such capability. Global Predictions claimed to use "the first regulated AI financial advisor" and "expert AI-driven forecasts"; the SEC found these statements false. Both firms settled and paid civil penalties.

The 2025 enforcement cluster extended the pattern across additional firms and across the testimonial / third-party-rating mechanics; the SEC Division of Examinations' published "Additional Observations Regarding Advisers' Compliance with the Marketing Rule" reinforced the focus. The January 2026 SEC staff FAQs clarified mechanics on third-party ratings (the "Catchlight referral" / "Barron's ranking" / "SmartAsset lead" category), hypothetical performance (the "AI-generated case study" or "what if you had invested" content category), and testimonial mechanics (the Google review / client video / podcast quote category).

The synthesized 2026 standard: an AI-related claim must (a) be substantiated by documented evidence the firm holds in its files; (b) be presented in fair and balanced fashion with material risks and limitations disclosed; (c) include the "clear and prominent" disclosure of any AI-related capability claimed (not buried, not micro-text, not on a separate page); (d) if performance-adjacent (close-rate, time-saved, accuracy-rate, prediction-quality), satisfy the hypothetical-performance rule's intended-audience, material-risk, assumptions, and methodology disclosure requirements; (e) if testimonial-shaped (client quote, Google review, third-party rating), satisfy the Marketing Rule 206(4)-1(b) testimonial / endorsement / rating mechanics; (f) if ADV-disclosure-bearing (the practice's AI tool usage, NPI handling, conflict-of-interest implications), be reflected in current ADV Part 2A. The L4 Ch7 L2 lesson develops the testimonial / third-party-rating / ADV / performance disclosure operations; this lesson develops the audit-and-remediation discipline.

Where AI Claims Actually Live in the Practice โ€” Twenty Locations to Audit

The audit starts with the inventory. The advisor practice's AI-related claims live in materially more places than the CCO typically expects. Twenty named locations form the audit checklist.

Practice-controlled content: (1) the firm's primary website (homepage, about page, services page, blog posts); (2) the engagement letter; (3) Form ADV Part 2A and Part 2B; (4) Form CRS; (5) the client onboarding packet; (6) email marketing campaigns (current and archived); (7) social media (LinkedIn firm and personal advisor profiles, X, Facebook, Instagram, YouTube); (8) webinar and event recordings; (9) printed marketing materials (brochures, one-pagers, pitchbooks); (10) the firm's podcast (host episodes, guest appearances); (11) prospect deck and sales materials; (12) press releases and earned-media coverage where the firm provided quotes.

Vendor-and-channel content: (13) third-party advisor directories (NAPFA, Garrett, XY Planning Network, Wealthramp, Catchlight profile, SmartAsset profile); (14) custodian-published profiles (Schwab Advisor Services, Fidelity Advisor Network, Pershing Advisor Network); (15) Google Business Profile and Google reviews; (16) Yelp / Bing / other review platforms; (17) industry rankings (Barron's, Forbes, Financial Advisor, Investment News, AdvisorHub); (18) podcast guest appearances on other shows; (19) co-branded content with vendors (Holistiplan case study, FP Alpha customer feature, Jump / Zocks customer quote); (20) any AI-tool vendor's website featuring the practice as a customer.

Each location gets cataloged in a single spreadsheet: location, URL or location identifier, capture date, AI-related claim language, substantiation file reference, remediation status, owner, completion date. The CCO owns the catalog; the head of advisory provides content access; outside counsel reviews the highest-risk items (any quantitative claim, any forward-looking statement, any "first" / "only" / "exclusive" claim). The L4 Ch6 L1 AI Governance Committee reviews the catalog at the meeting following kickoff.

Building the Substantiation File for Each Claim

The Marketing Rule under 206(4)-1(d) prohibits any material claim of fact that the advisor cannot substantiate upon SEC demand. The substantiation file is the practice's documented evidence supporting each claim โ€” not the claim itself, but the underlying basis. For each AI-related claim identified in the audit, the substantiation file contains: the documented source of the data behind the claim (vendor white paper, internal usage metrics, a peer-reviewed study, the practice's own measured outcomes); the methodology the underlying data uses; the time period the data covers; the population the data covers (the practice's whole book, a subset, a vendor's broader user base); the assumptions baked into the data; the material risks and limitations not captured by the headline number; and the documented basis for any forward-looking statement made.

The substantiation file is not the dashboard (L4 Ch5 L2) โ€” the dashboard is the data layer, the substantiation file is the documented basis the practice cites when an examiner asks "where did this number come from?" The two are linked: the dashboard's "hours recovered" figure for the practice's internal use is operational; if the practice cites the figure externally ("our advisors save 10 hours a week using AI"), the dashboard data plus the methodology documentation plus the disclosure language plus the source attribution becomes the substantiation file for that claim. The L4 Ch7 L2 lesson develops the testimonial / rating / ADV / performance disclosure mechanics; this lesson installs the substantiation discipline that feeds them.

Claim Categories and Their Substantiation Templates

Five claim categories cover most AI-related content. Capability claims ("we use AI to draft Reg BI rollover memos") โ€” substantiated by the workflow documentation, the vendor reference, the actual usage data, the prompt library version. Performance claims ("our advisors save 10 hours per week with AI") โ€” substantiated by the L4 Ch5 L2 dashboard methodology + measured data + time-period scope + advisor cohort scope. Accuracy claims ("our AI extracts 1040 line items with 99% accuracy") โ€” substantiated by the vendor's accuracy attestation, the practice's verification sampling, the time period, the document subset. Outcome claims ("clients see X benefit from our AI workflow") โ€” substantiated by the workflow documentation, the client-outcome data, the cohort identification, and the disclosure that the outcome is not guaranteed. Comparative claims ("most advanced AI in advisor tech") โ€” almost always unsupportable; the audit's standard recommendation is to rewrite into a substantiated alternative or remove entirely.

The Language Rewrite Playbook

Once cataloged and substantiated, each claim either survives the audit, gets rewritten, or gets removed. The decision tree: (1) Is the claim substantiated by documented evidence? If no, rewrite or remove. (2) Is the claim fair and balanced under 206(4)-1(d)(2)? If no, add the disclosure of material risks and limitations, then re-evaluate. (3) Is the claim presented with "clear and prominent" disclosure of AI-related capability? If no, restructure the page or restate the claim. (4) If performance-adjacent, does it satisfy the hypothetical-performance rule? If no, restructure or remove. (5) If testimonial-shaped, does it satisfy 206(4)-1(b) mechanics? If no, restructure or remove.

The rewrite patterns: capability with restraint โ€” "we use AI tools to support our advisors" (substantiated, accurate, fair-and-balanced); performance with disclosure โ€” "our advisors report time savings using AI workflows (based on [methodology], measured over [time period], not a guaranteed outcome)"; accuracy with limitation โ€” "AI extraction accuracy varies by document type; we apply human verification on every output (see our verification protocol [link])"; outcome with caveat โ€” "some clients have experienced [benefit]; outcomes vary; AI is not a substitute for advisor judgment and not a guarantee of future results"; removal of comparatives โ€” rewrite "most advanced" to "the workflow we use" or remove entirely.

The ADV Part 2A Update Discipline

If the practice has been using AI tools without explicit ADV Part 2A disclosure, the audit triggers an amendment. The ADV Part 2A items that touch AI use include: Item 4 (Advisory Business) โ€” disclose the use of AI tools in the advisory process; Item 5 (Fees and Compensation) โ€” disclose any AI-related conflicts (vendor revenue sharing, AI cost-to-serve changes that affect fee schedule); Item 8 (Methods of Analysis, Investment Strategies, Risk of Loss) โ€” disclose AI's role in investment research or recommendation generation if applicable; Item 14 (Client Referrals and Other Compensation) โ€” disclose any Catchlight / SmartAsset / similar AI-driven referral arrangements with the required disclosures; Item 17 (Voting Client Securities) โ€” disclose any AI role in proxy voting; Brochure Supplement (2B) โ€” disclose the AI tools the supervised person uses.

The L4 Ch7 L2 lesson develops the off-cycle amendment trigger; the audit's role is to surface any disclosure gaps and queue them for the next amendment (annual or off-cycle as material). The 2025-2026 SEC examination focus on Marketing Rule compliance is increasingly cross-referenced with ADV disclosure completeness โ€” what the firm says publicly must match what the firm discloses in ADV, and both must match what the firm actually does. The audit produces the cross-reference.

The Marketing Archive Sweep

Under FINRA Rule 4511 + SEC Rule 204-2, the practice's archive captures every marketing communication and recordable communication. The Smarsh or Global Relay archive contains the historical record. The marketing-archive sweep reviews the archived content for AI-related claims that may have run in prior periods โ€” particularly relevant if the practice has changed AI tool usage or reduced claims in current marketing but the archive contains a year-old website page, a 6-month-old podcast episode, or an 18-month-old printed brochure circulating in the field.

The sweep produces three outputs: (1) the catalog of historical claims with their archive timestamps; (2) the remediation log showing which historical claims have been retracted, corrected, or are no longer in circulation; (3) the documented basis for any historical claim that remains relevant (the substantiation file for the still-in-effect content). The sweep is not a one-time event โ€” the L4 Ch6 L1 AI Governance Committee maintains a standing register entry to refresh the sweep quarterly. Any AI-related content that drops out of current marketing must still be reconciled with the archive.

The Ongoing Discipline That Prevents Drift

The audit is the recovery action. The discipline that prevents the next drift has four elements. First, the firm-approved prompt library (L2 Ch8 L1 / L4 Ch5 L1) encodes the substantiated, fair-and-balanced, clear-and-prominent disclosure language for any AI-related claim the practice routinely produces. Marketing content generated through the prompt library inherits the discipline. Second, the principal review queue under FINRA Rule 2210 and Marketing Rule 206(4)-1 โ€” staffed by the CCO or designated principal, supported by AI-to-AI red-team first-pass screening โ€” catches AI-related claims before they ship. The review queue covers any client-facing AI-related communication; the sampling rate (set by the AI Governance Committee per L4 Ch6 L1) typically covers 100% of Reg BI-recommendation-bearing content and 25-50% of other AI-mentioning content. Third, the CCO's quarterly regulatory scan โ€” covering SEC Risk Alerts, FINRA notices, state DOI bulletins, and the Marketing Rule staff FAQs โ€” surfaces any change to the standard that requires the substantiation file or language to be refreshed. Fourth, the AI Governance Committee's monthly meeting includes a standing register entry for Marketing Rule audit status and any new claims or revisions.

The four elements operationalize the audit's discipline into the practice's standard workflow. The L4 Ch5 L1 90-day adoption curve installs the prompt library and the principal review queue; the L4 Ch5 L2 ROI dashboard surfaces operational health items; the L4 Ch6 L1 AI Risk Register tracks regulatory drift and Marketing Rule audit status; the L4 Ch7 L2 testimonial / rating / ADV / performance lesson operationalizes the specific disclosure mechanics. This L4 Ch7 L1 lesson is the recovery + ongoing-discipline installation that bridges them.

Three Named 2026 Scenarios the Audit Encounters

Scenario A โ€” Website "AI-powered planning" claim. The homepage says "AI-powered comprehensive planning that anticipates client needs." Substantiation: workflow documentation showing AI tool use in planning workflows (Holistiplan, FP Alpha, RightCapital, eMoney). The phrase "anticipates client needs" is the AI-washing risk โ€” it implies prediction-quality the practice does not have or has not substantiated. Remediation: rewrite to "We use AI tools to support our planning process and apply advisor judgment to every recommendation"; substantiate the AI tool use in the file; update ADV Part 2A Item 4 to reflect the AI tool inventory; mark website page as updated; archive prior page in Smarsh; standing register entry tracks the new page for any drift.

Scenario B โ€” Email signature "machine-learning-driven analysis." Advisor email signature includes "Powered by machine-learning-driven portfolio analysis." Substantiation: the practice uses Orion Eclipse rebalancing tools that include ML-based optimization. The phrase "machine-learning-driven analysis" overstates โ€” the ML is one component of the rebalancing engine, not the analytical layer the advisor applies. Remediation: rewrite to "Portfolio rebalancing supported by AI optimization tools (Orion Eclipse) with advisor review and IPS-aligned constraints"; if the rewrite exceeds email signature length, remove the AI claim from signature entirely and disclose AI use through the engagement letter and ADV. Marketing Rule audit register entry closes; standing entry tracks future signature drift.

Scenario C โ€” Catchlight referral page rating language. The practice's Catchlight profile says "Top 1% AI-rated advisor for tech executives." Substantiation: the Catchlight platform's algorithmic rating methodology. The "Top 1% AI-rated" framing intersects with Marketing Rule 206(4)-1(b) testimonial / third-party-rating mechanics and the January 2026 staff FAQs. Remediation: outside counsel reviews the Catchlight rating mechanics and confirms the practice's qualification; the page's disclosure language is updated to satisfy the third-party-rating disclosure requirements (rating provider, methodology summary, time period, the practice's payment to the provider if any); ADV Part 2A Item 14 disclosure refreshed; the L4 Ch7 L2 lesson framework specifically operationalizes this.

Key Takeaways

  • The 2024-2026 enforcement landscape: Delphia + Global Predictions (March 2024) AI-washing settlements, the 2025 enforcement cluster, the SEC Division of Examinations Risk Alerts, the January 2026 SEC staff FAQs on third-party ratings + hypothetical performance + testimonial mechanics. Every AI-related claim is a Marketing Rule 206(4)-1 artifact.
  • Twenty audit locations: practice-controlled content (website, ADV, engagement letter, social, podcast, deck, etc.) + vendor-and-channel content (directories, custodian profiles, Google reviews, industry rankings, podcast guest appearances, vendor co-branded content). Cataloged in a single spreadsheet owned by the CCO.
  • Substantiation file under 206(4)-1(d) is the documented basis. Five claim categories: capability, performance, accuracy, outcome, comparative. Comparatives ("most advanced") are almost always unsupportable; rewrite or remove.
  • Five rewrite patterns: capability with restraint, performance with disclosure, accuracy with limitation, outcome with caveat, removal of comparatives. Each presented with "clear and prominent" disclosure under Rule 206(4)-1.
  • ADV Part 2A update touches Items 4, 5, 8, 14, 17, and the Brochure Supplement 2B. The 2025-2026 SEC examination focus increasingly cross-references Marketing Rule with ADV completeness โ€” public claims must match ADV disclosure must match actual practice.
  • Marketing archive sweep under FINRA Rule 4511 + SEC Rule 204-2: Smarsh / Global Relay catalog of historical claims, remediation log, documented basis for still-in-circulation content. Quarterly refresh via the L4 Ch6 L1 AI Governance Committee standing entry.
  • Four ongoing-discipline elements prevent drift: firm-approved prompt library encoding compliant language; principal review queue under Rule 2210 + Marketing Rule with AI-to-AI red-team screening; CCO quarterly regulatory scan; AI Governance Committee monthly meeting standing entry.
  • The L4 Ch7 L1 audit-and-remediation lesson bridges L4 Ch5 (adoption + ROI dashboard) and L4 Ch7 L2 (testimonial / rating / ADV / performance disclosure operations). The L4 capstone Marketing Rule audit deliverable is this lesson's output.