For registered advisers
Eighty-six percent of you wrote the policy. Fourteen percent have an incident response plan that mentions AI.
Both numbers come from the same survey, and the distance between them is the next two years of work at most adviser firms. It is not a drafting distance. Writing a policy is a deliverable somebody can sell you; producing the evidence that the policy was implemented is an operating rhythm, and nobody sold you one. Rule 206(4)-7 requires an adviser to adopt and implement written policies, and to review annually both their adequacy and the effectiveness of their implementation. Adequacy is answered by a document. Effectiveness of implementation is answered only by artifacts — a dated inventory, a completed test, an incident record, a written determination, a review that left a trace. If you already have an acceptable use policy, buying a second one moves nothing, and arguably makes things worse.
What the survey actually found
The 2026 Investment Management Compliance Testing Survey — the Investment Adviser Association with ACA Group and Yuter Compliance Consulting, 411 adviser firms, fielded April–May 2026, published July 29, 2026 — contains a sequence worth reading in order.
Eighty-five percent of firms named AI their number one compliance topic for the year, up 28 points and the most dominant single response in the survey's twenty-one-year history. Eighty percent have formally adopted AI tools. Eighty-six percent have an AI acceptable use policy. Eighty-six percent maintain an inventory of AI tools. Fifty-nine percent have a formal AI governance committee.
Then the floor gives way. Forty-eight percent have human-in-the-loop oversight procedures. Thirty-seven percent have output testing or validation policies. Thirty percent have third-party AI use policies. Fourteen percent have updated their incident response plans for AI disruption.
One caveat before anyone puts these in a board memo: the respondents skew larger and more institutional than a $250 million to $5 billion firm. Treat them as an upper bound on maturity, not a median. If you run a twenty-five-person adviser on the Main Line, the honest assumption is that your gap is wider than the survey's.
The saturation at the top is a professional service line doing its job
It is not a failure. AI arrived; 206(4)-7 requires written policies; compliance consultants across this market drafted acceptable use policies, stood up governance committees and got them adopted. Eighty-six percent is what competence looks like.
The problem is the second half of the same rule, and it is a different kind of work. Nobody's engagement letter says and then somebody here will run an Entra ID report on consented applications every quarter.
A policy statement and an artifact are not the same object
Compare two sentences.
"The firm maintains an inventory of AI tools in use."
"Here is the inventory, dated the fourteenth, owned by the COO, listing eleven tools, four of which surfaced through a shadow-IT report rather than through procurement, with the reconciliation attached."
The first takes four minutes to write. The second requires somebody to have pulled the consented-applications report, checked which AI features the tenant has switched on by default, gone through the recurring card charges in the accounting system, asked every adviser in writing what they use, and reconciled the four lists. Two afternoons the first time. About an hour a quarter after that.
Nothing in the second sentence is a legal judgment. It is administration — and it is what the FY2026 examination priorities, announced November 17, 2025, are pointed at. The Division said it "will assess whether firms have implemented adequate policies and procedures to monitor and/or supervise their use of AI technologies," and "will review for accuracy registrant representations regarding their AI capabilities."
One correction, in the other direction
Rule 206(4)-7 does not require a written report of the annual review. That is industry practice, driven by examination expectations and by Rule 204-2, not by the text of the rule. Any vendor telling you the rule requires the report has read a summary.
In practice the staff treat an undocumented review as no review. Which is a statement about evidence rather than about the rule — and it is the same point this whole article is making, arriving from the opposite side.
The one artifact you cannot produce later
Most of the evidence layer can be assembled retroactively by a competent person working hard for a fortnight. One item cannot: the risk assessment dated before a tool went live. It is also the item cyber insurers ask for by name at renewal, alongside the tool inventory and a clear explanation of where human oversight sits (ACA Group, July 23, 2026 — a consultancy that sells governance services, so read it as directional rather than as a carrier survey, and check with your own broker).
Which means the cost of waiting is not spread evenly. It lands entirely on the tools you deploy between now and the day you start.
What to do Monday
- Pull three lists: consented applications in Entra ID, AI features enabled by default in the Microsoft 365 admin center, and recurring card charges under $200 a month in the accounting system.
- Email every adviser one question: what AI tools do you use for firm work, including anything you pay for yourself?
- Reconcile the four lists into one dated table with a named owner. That table is artifact one.
- For any tool going live from here, write the risk assessment before the go-live date. Two pages is enough.
- Read your incident response plan and find the sentence that contemplates an AI failure. If there isn't one, you are in the 14% — or, more likely, the 86%.
Where we stop
We do not give regulatory advice and we are not your compliance consultant. Whether a particular transcript is a required record, whether a particular incident triggered a notification obligation, whether your policy is adequate — those belong to your consultant or your counsel, and we will say so in the meeting rather than guess. We also build nothing that produces an investment recommendation, a suitability determination, a portfolio decision or a security selection. What we do is the other half: run the inventory, build the register, capture the record, configure the retention, and keep producing the file after the engagement ends.
Signet, a division of Circle Square Consulting. Radnor, Pennsylvania. — signetattest.com/evidence-file