โ†
AI for Financial Advisors & Wealth Managers
Strategic ยท M21 ยท lesson 21 of 21 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
Written Supervisory Procedures (WSPs) for GenAI Use
๐Ÿ“–
now learning

Written Supervisory Procedures (WSPs) for GenAI Use

15 min

The single document an SEC examiner or FINRA examiner reads first when AI is on the practice's deployment list is the WSP โ€” Written Supervisory Procedures โ€” and specifically the section addressing GenAI use. A blank WSP, a generic WSP, or a WSP whose AI section is a single sentence ("we will use AI in accordance with regulatory requirements") is functionally equivalent to no supervisory architecture under FINRA Rule 3110 reasonable-design or SEC Compliance Rule 206(4)-7. This lesson installs the model WSP section for GenAI: six required components (acceptable tools, prohibited data categories, approval workflow, training requirements, incident response, supervisory log), the regulatory mapping that makes each component defensible, and the maintenance discipline that keeps the WSP from drifting into shelfware. The completed WSP section is the central deliverable of the L4 Ch3 chapter and the spine of the L4 Capstone.

Why WSPs and Not Just "Policy"

Many practices have "AI policy" documents that read more like marketing statements than supervisory documents. A WSP is different in three specific ways. First, it is supervisory โ€” it describes the controls the firm actually exercises over the conduct of its registered persons and associated personnel, not aspirations. Second, it is written โ€” formal, dated, version-controlled, signed by the CCO, and filed under the firm's compliance record. Third, it is procedural โ€” it describes who does what, in what order, with what evidence, on what cadence โ€” not abstract principles.

The regulatory basis for the WSP is layered. For broker-dealers, FINRA Rule 3110 requires a "system of supervision" reasonably designed to achieve compliance with applicable rules. For SEC-registered investment advisers, Compliance Rule 206(4)-7 requires written policies and procedures reasonably designed to prevent violations. For dually-registered firms, both apply concurrently. For state-registered advisers, state versions of 206(4)-7 typically mirror the SEC's requirements. The FINRA 2026 Annual Regulatory Oversight Report extended the Rule 3110 framing explicitly to GenAI use and agentic AI, making the WSP requirement no longer aspirational but operational. Regulatory Notice 24-09 on GenAI is the practitioner-level guidance the WSP should explicitly reference.

The practical test of a WSP's adequacy: can the firm hand it to a 2026 SEC or FINRA examiner and walk through specific advisor scenarios โ€” "Advisor A used Tool X to draft a Reg BI rollover memo on Tuesday at 2:14 PM; here's what happened next in the WSP-defined workflow" โ€” without flinching? If yes, the WSP is doing its job. If the answer is hand-waving, the WSP needs the components this lesson installs.

Component 1 โ€” Acceptable Tools

The acceptable-tools section is the WSP's named-vendor whitelist. It is the most operationally consequential component and the most-skipped in poorly drafted WSPs. Five required elements:

Approved tool list. Every AI tool the firm has approved for advisor use โ€” Jump or Zocks (for meeting AI), Holistiplan (tax), FP Alpha or Wealth.com (estate), the enterprise LLM (Microsoft Copilot or OpenAI Enterprise or Google Gemini Enterprise or Anthropic Claude for Work), the planning software's AI features (RightCapital, eMoney, MoneyGuidePro), the CRM (Wealthbox, Redtail, Salesforce FSC + Einstein, Practifi), the archive (Smarsh, Global Relay), and any other AI-enabled tool โ€” listed with vendor name, product tier, deployment date, scope, and L4 Ch2 vendor onboarding chain reference (scorecard + DD + pilot completion dates).

Tool retirement log. Vendors the firm has retired or declined, with the date and rationale. Demonstrates the L4 Ch1 L1 solo "ruthless consolidation" discipline and the L4 Ch2 L3 pilot kill-discipline.

Use case scope per tool. What each tool is approved for: Jump for meeting prep / notes / follow-up; Holistiplan for tax-return extraction; FP Alpha for estate document extraction; the LLM for general drafting, summarization, and structured extraction (with the L1 Ch5.2 NPI rules); Wealthbox for CRM, etc. Explicit scope prevents scope creep.

Prohibited tools. Free public LLMs (ChatGPT free tier, Claude.ai free, Gemini consumer), personal AI subscriptions on firm devices, and any AI tool not on the approved list. The list is the operational predicate for the L4 Ch1 L1 ensemble shadow-IT prevention framework.

Approval mechanism. The named process for adding a new tool โ€” typically: L4 Ch2 L1 scorecard โ†’ L4 Ch2 L2 DD questionnaire โ†’ L4 Ch2 L3 60-day pilot โ†’ CCO + managing partner signature โ†’ WSP amendment โ†’ ADV Part 2A assessment per L5 Ch7. New-tool requests bypassing this process are unauthorized and trigger the L4 Ch3 L4 IRP.

Component 2 โ€” Prohibited Data Categories

The prohibited-data section is the WSP's Reg S-P operating manual. Under the May 2024 Reg S-P amendments, NPI moves trigger vendor oversight obligations; mishandling triggers the 30-day customer breach clock and the 72-hour NY DFS notification. The section names what cannot go where.

Categorical NPI definition. SSN, full account numbers, dates of birth, addresses linked to client identity, financial-account balance and transaction history when associated with identifiable client, beneficiary identifying information, healthcare directive content with identifying information, U4 Form-disclosure content (DRPs), and any combination that allows re-identification of an individual client.

Tool-specific allowed/prohibited matrix. Per-tool table mapping NPI categories to allow/prohibit, e.g., Jump = allows meeting transcripts with client first name only; Holistiplan = allows tax-return extraction including SSN under SOC 2 Type II + signed DD + WSP; free public LLMs = prohibits all NPI categories without exception. Cross-reference L1 Ch5.2.

De-identification standards. "I just removed the name" is not de-identification under Reg S-P. Acceptable de-identification: structured anonymization with documented technique (k-anonymity, differential privacy, tokenization), independent audit verification, and re-identification risk assessment. Most advisor use cases do not require de-identification because the firm's enterprise tools support direct NPI handling under SOC 2 Type II contracts โ€” but if de-identification is attempted, the WSP names the standard.

Cross-border restrictions. Data residency requirements per L4 Ch2 L1: US-only by default; cross-border flow requires named jurisdiction, additional controls (SCCs, technical safeguards), ADV Part 2A disclosure, and (for California clients) CPRA cross-border transfer notice.

Confidential firm data. Firm-internal NPI (own employees' compensation, firm financials, M&A discussions, regulatory filings under embargo) โ€” separate prohibition aligned to the firm's confidentiality obligations.

Component 3 โ€” Approval Workflow for New Use Cases

The approval-workflow section is the WSP's change-management discipline. New use cases โ€” an advisor wanting to apply the LLM to a new workflow, a vendor adding a new feature that affects data handling, a new client communication pattern using AI โ€” must be approved before deployment.

Use case request submission. Named form or workflow tool where the requesting advisor submits the use case: description, AI tool used, data categories involved, expected output, supervisory implications.

Review chain. CCO reviews for regulatory implications (Marketing Rule, Reg BI, Reg S-P, Rule 4511, NAIC if annuity-licensed); IT/MSP reviews for technical/cyber implications; head of advisory reviews for operational fit. Each documents the review and concurs or escalates.

Decision and documentation. Approved (with documented rationale and any caveats), Conditionally Approved (with required modifications), or Declined (with documented rationale). Approval triggers WSP amendment, training updates, and L4 Ch5 90-day adoption guidance if the use case is new firmwide.

Cadence. Routine new use cases reviewed monthly; urgent cases reviewed within 5 business days. The cadence prevents both overwhelm (queueing) and operational paralysis.

Audit. Quarterly review of the use case log: which were approved, declined, conditionally approved; aggregate patterns informing the broader L4 Ch6 L1 governance committee discussion.

Component 4 โ€” Training Requirements

The training section is the WSP's adoption operationalization. FINRA Rule 1240 (Firm Element CE) for BD-side firms and the SEC's training expectations under 206(4)-7 for IA-side both anchor here.

Initial training. Every advisor and associated person must complete documented initial training on the firm's AI use, the Cardinal Rule (L1 Ch2.3), the prohibited-data categories, the Marketing Rule and Reg BI implications (L1 Ch4), and the Cyber / Reg S-P obligations (L1 Ch5). Completion documented per individual with date, content, and acknowledgement.

Ongoing training. Annual refresh aligned with FINRA Rule 1240 Firm Element CE for BD-registered persons; calendar-cycle alignment for IA-side personnel. Annual training updates with new regulatory developments (SEC Risk Alerts, FINRA Annual Regulatory Oversight Reports, Marketing Rule FAQs, NAIC AI Model Bulletin updates).

Just-in-time training. New tool added, new use case approved, new regulatory development โ€” targeted training for the affected personnel within 30 days.

Skills certification. For advisors using AI for material client-facing work (drafting Reg BI memos, IPS updates, Marketing Rule pre-use review), the firm may require role-specific certification โ€” e.g., the skill.re wealth track L1-L4 progression โ€” or equivalent demonstrated competency.

Documentation. Training records retained per FINRA Rule 4511 / SEC Rule 204-2; presented during examinations as evidence of supervisory diligence.

Component 5 โ€” Incident Response

The incident-response section is the WSP's connection to the L4 Ch3 L4 IRP. The WSP names the trigger conditions, the escalation chain, and the documentation requirements; the L4 Ch3 L4 lesson installs the operational IRP itself.

Incident definitions. Hallucination producing client-facing impact, data leak via AI tool, prompt injection compromising session, output compromise, agentic action error (per L4 Ch3 L3), vendor breach affecting firm data, shadow-IT incident with NPI exposure.

Initial response. Within 1 hour of discovery: containment (suspend affected tool, isolate affected data, preserve evidence), CCO notification, initial classification.

Escalation chain. CCO โ†’ managing partner โ†’ outside counsel if material โ†’ E&O carrier per L4 Ch4 L2 โ†’ regulator notification thresholds per Reg S-P May 2024 (30-day customer / 72-hour DFS) and NY DFS 23 NYCRR 500.

Documentation. Incident log entry, root cause analysis, remediation, post-incident review with lessons-learned feeding back into the WSP's other components.

Customer notification. If NPI affected, the 30-day customer notification clock under May 2024 Reg S-P amendments runs; the WSP names the notification process and template.

Component 6 โ€” Supervisory Log Under Rule 4511

The supervisory-log section is the WSP's evidence-retention discipline. Under FINRA Rule 4511 and SEC Rule 204-2, the firm must retain documentation of supervisory activity for the prescribed period. For AI-supervised content (Marketing Rule pre-use review with AI first-pass per L4 Ch3 L2, Reg BI memo audit, agentic AI supervision per L4 Ch3 L3), the log captures the entire chain.

Per-artifact metadata. Each AI-touched artifact retained with: prompt text, model output, advisor edits, signoff identity, signoff timestamp, supervisor review status, supervisor identity if reviewed, archive timestamp, retention duration. Cross-reference L3 Ch10 L2 prompt-retention decision tree.

Sampling discipline. Documentation of the sampling protocol (random / risk-based / dual-sampling for false-negatives per L4 Ch3 L2), sample frequency, supervisor responsible, review findings.

Periodic certification. Quarterly CCO certification that the supervisory architecture is operating as designed; deficiencies documented and remediated.

Annual audit. Annual independent audit (internal or external) of the supervisory log integrity, sampling protocol fidelity, escalation handling โ€” findings reported to the L4 Ch6 L1 governance committee.

Examination posture. The log is retrievable on demand for SEC or FINRA examination; format defensible (tamper-evident, timestamped, signed signature chain); the L3 Ch10 archive pipeline is the operational foundation.

WSP Maintenance Discipline

The WSP without maintenance discipline is shelfware. Three operational disciplines:

Annual review. Comprehensive review aligned with the L4 Ch1 L2 readiness audit cycle. CCO leads, governance committee ratifies, version-controlled with date and version number. Comparison against year-over-year regulatory developments (SEC Risk Alerts, FINRA Annual Regulatory Oversight Report, Marketing Rule FAQs, Reg S-P amendments, NAIC updates).

Material-event update. New AI tool added, vendor breach event, examination finding, new regulation, M&A event โ€” trigger an off-cycle WSP amendment. Document the trigger, the change, the rationale.

Version control and audit trail. Every WSP version retained with date, signature, change log. Demonstrable evidence in examination that the WSP evolved with the firm's AI maturity and the regulatory landscape.

The completed WSP section becomes part of the firm's compliance record under SEC Rule 204-2 and FINRA Rule 4511. It is the central deliverable of the L4 Ch3 chapter and the foundation of the L4 Capstone's 30-page strategic AI plan. In M&A diligence (L4 Ch8 L2), the WSP is examined for adequacy as part of the AI maturity premium attribute assessment supporting top-quartile valuation (8x-10x adjusted EBITDA per Mercer Capital / ECHELON Q3-Q4 2025, with AI maturity adding 0.5-1.5x; premium-top reaching ~11.6x).

Key Takeaways

  • WSP, not "policy": supervisory, written, procedural; signed by CCO; filed under compliance record per SEC Rule 204-2 and FINRA Rule 4511.
  • Six required components: acceptable tools (named whitelist + retirement log + use case scope + prohibited tools + approval mechanism), prohibited data categories (categorical NPI definition + tool matrix + de-identification standards + cross-border + confidential firm data), approval workflow for new use cases (request submission + review chain + decision + cadence + audit), training requirements (initial + ongoing per FINRA Rule 1240 + just-in-time + certification + documentation), incident response (definitions + initial response + escalation chain + documentation + customer notification under May 2024 Reg S-P 30-day clock), supervisory log (per-artifact metadata + sampling + quarterly certification + annual audit + examination posture).
  • Regulatory mapping: FINRA Rule 3110 reasonable-design (BD), SEC Compliance Rule 206(4)-7 (IA), Rule 1240 Firm Element CE, Rule 4511 retention, SEC Rule 204-2, Reg S-P May 2024 amendments (30-day customer / 72-hour DFS clocks), NY DFS 23 NYCRR 500, NAIC AI Model Bulletin / Model #275, FINRA 2026 Annual Regulatory Oversight Report, Reg Notice 24-09, Marketing Rule 206(4)-1 + January 2026 staff FAQs, Reg BI ยง240.15l-1.
  • Test of adequacy: can the firm walk an examiner through specific advisor scenarios without hand-waving?
  • Approved tools list cross-references the L4 Ch2 vendor onboarding chain (scorecard + DD + pilot completion).
  • Prohibited data categories operationalize Reg S-P with tool-specific allow/prohibit matrix and de-identification standards.
  • Maintenance discipline: annual review aligned with L4 Ch1 L2 readiness audit, material-event off-cycle amendments, version control and audit trail.
  • WSP is the spine of the L4 Capstone and a major component of M&A defensibility per L4 Ch8 L2.