AI Governance for Broker-Dealers: What Examiners Expect Now
FINRA and the SEC already apply existing rules to AI. So, here's the fast, visual breakdown of what your broker-dealer needs today, not someday.
Meanwhile, most approval chains and patch cycles are still built for the slower, two-year world. Consequently, the gap between a vulnerability and an actual attack keeps shrinking, while your controls stay the same speed.
AI Governance for Broker-Dealers: You're Already Covered
So, is a new AI rule coming? Actually, no. Instead, FINRA and the SEC simply apply the rules you already have.
AI-assisted supervision still needs written procedures.
AI-drafted content still needs a factual, sound basis.
A model can't replace documented human review.
AI access to customer data must be controlled.
Outsourced AI still falls under vendor-oversight rules.
Enforcement is being tested, not just paperwork.
Note: the SEC withdrew its AI-specific conflicts proposal in 2025. As a result, Rule 3110, Reg BI, Reg S-P, and Notice 24-09 remain the real baseline, so verify current requirements against FINRA.org and SEC.gov before finalizing policy.
8 Controls That Actually Hold Up to Review
Now, here's the governance structure regulators want to see, built for broker-dealer compliance in 2026 and beyond.
What the Data Says
Meanwhile, the numbers back this up. NAVEX's 2026 survey of nearly 1,200 compliance executives shows adoption and the stakes are both rising fast.
Of compliance teams are now meaningfully involved in AI decisions, up from 65% last year.
Breach rate when leadership tolerates AI risk-taking, versus firms where it doesn't.
In short, structure alone doesn't prevent problems. Rather, it's leadership follow-through, actually enforcing the confirmation gates and vendor checks, that moves the needle most.
Ultimately, the safest path is simple: treat AI like any other high-access system. Inventory it, permission it, supervise it, and audit it, with a human always positioned between the model and anything consequential.
Is Your AI Governance Exam-Ready?
MCG Consulting builds supervisory frameworks, including AI governance, that are reasonably designed and demonstrably enforced for broker-dealers.
- → Broker-Dealer Compliance Solutions
- → Full Compliance Services Overview
- → Risk Management Advisory
- → Related read: FINRA Rule 2210 Overhaul
This post summarizes public regulatory guidance and general practices. It isn't legal advice. Therefore, confirm current requirements directly with FINRA.org, SEC.gov, and counsel before finalizing policy language.
Sources:
- FINRA Regulatory Notice 24-09: Regulatory Obligations When Using Generative AI and Large Language Models
- FINRA Rule 3110 (Supervision)
- FINRA Regulatory Notice 21-29 (Outsourcing to Third-Party Vendors)
- NIST AI Risk Management Framework (AI RMF 1.0)
- SEC Division of Examinations, 2026 Examination Priorities
- ACA Group, "The AI Security Inflection Point" (2026)
- NAVEX, "2026 State of Risk & Compliance Report", ~1,179 executives, January to February 2026, iResearch Consulting Group



