# AI Supervision Under FINRA and SEC Recordkeeping Rules

> Financial Services · AI Course · FIN-3
> Source: https://ibl.ai/solutions/financial-services/course/ai-supervision-finra-sec
> Last updated: 2026-08-25

**Supervise AI in a broker-dealer or RIA — communications review, books and records obligations, and what happens when an agent talks to a client.**

## The Short Answer

**Supervisory and recordkeeping rules apply to AI-generated client communications exactly as to human ones, and most firms have not extended retention to cover prompts. ibl.ai keeps prompts, outputs, and model versions inside firm-controlled retention where you own all the code and the data.**

On ibl.ai you own all the code and the data, run it model-agnostic across any LLM, and pay with no per-seat pricing — so you can deploy anywhere, from your own cloud to a fully air-gapped network.

[Request Access](https://ibl.ai/contact) · [Explore Financial Services](https://ibl.ai/solutions/financial-services)

## Course facts

- **Level:** Intermediate
- **Duration:** 5.5 hours across 8 modules
- **Format:** Cohort workshop with supervision labs
- **Modules:** 8
- **Catalog code:** FIN-3
- **Frameworks covered:** FINRA rules, SEC Marketing Rule, Books and records rules, Reg BI

## What is this course about?

Supervisory and recordkeeping obligations apply to AI-generated communications exactly as they do to human ones, and most firms have not extended their systems to cover them. This course covers retaining prompts and outputs, off-channel risk introduced by AI tools, advertising rule compliance, and examination readiness.

## Who is this course for?

- Chief compliance officers of broker-dealers and RIAs
- Supervisory principals
- Surveillance and communications review staff
- Internal audit covering supervision

### What do I need before starting?

- Broker-dealer or RIA compliance experience
- Familiarity with your supervisory system

## What will I be able to do afterwards?

- Extend supervisory procedures to AI-generated communications
- Retain prompts, outputs, and model versions as required records
- Manage off-channel risk introduced by AI tools
- Apply advertising and marketing rules to AI-generated material
- Prepare the artifacts an examination will request

## What does each module cover?

### Module 1 — What supervisory obligations attach to AI output?

Extending supervision to communications a system generated. _(45 min)_

**Objectives**

- Apply supervisory obligations to AI-generated communications
- Update written supervisory procedures
- Assign supervisory responsibility

**Topics:** Supervisory scope · WSP updates · Responsibility assignment · Review requirements

**Activity:** Update your WSPs to cover AI-generated communications.

### Module 2 — What has to be retained?

Books and records applied to prompts, outputs, model versions, and configuration. _(50 min)_

**Objectives**

- Determine what constitutes a required record
- Retain prompts, outputs, and model versions
- Meet format and accessibility requirements

**Topics:** Record scope · Prompt retention · Model version records · Format requirements

**Activity:** Map AI artifacts to your recordkeeping obligations and find the gaps.

### Module 3 — How do AI tools create off-channel risk?

Personal AI tool use as the newest off-channel communications problem. _(45 min)_

**Objectives**

- Identify off-channel risk created by AI tools
- Detect unapproved tool use
- Set and enforce policy

**Topics:** Off-channel risk · Personal tool use · Detection · Policy enforcement

**Activity:** Survey actual AI tool use and assess the off-channel exposure.

### Module 4 — How do advertising rules apply to generated material?

Marketing rule compliance when the content was drafted by a system. _(50 min)_

**Objectives**

- Apply advertising and marketing rules to AI content
- Handle performance and testimonial content
- Build the review workflow

**Topics:** Marketing rule · Performance claims · Testimonials · Review workflow

**Activity:** Review AI-generated marketing material against the marketing rule.

### Module 5 — What happens when AI informs a recommendation?

Suitability and fiduciary duty when analysis behind a recommendation came from a model. _(50 min)_

**Objectives**

- Apply suitability and fiduciary standards to AI-informed advice
- Document the basis for a recommendation
- Set boundaries on AI's role

**Topics:** Suitability · Fiduciary duty · Basis documentation · Role boundaries

**Activity:** Document the basis for an AI-informed recommendation to a supervisory standard.

### Module 6 — How do you surveil employee AI use?

Surveillance that meets supervisory obligations without becoming disproportionate. _(45 min)_

**Objectives**

- Design surveillance meeting supervisory duties
- Keep surveillance proportionate
- Escalate findings appropriately

**Topics:** Surveillance design · Proportionality · Escalation · Employee communication

**Activity:** Design the surveillance approach and its escalation path.

### Module 7 — What will an examination request?

Preparing the artifacts examiners are asking for on AI use. _(45 min)_

**Objectives**

- Anticipate examination requests on AI
- Prepare artifacts in advance
- Identify and remediate gaps before examination

**Topics:** Examination requests · Artifact preparation · Gap remediation · Response readiness

**Activity:** Complete a mock examination request list and identify what you cannot produce.

### Module 8 — Building the supervisory procedure

The workshop module: a written supervisory procedure for one client-facing AI workflow. _(50 min)_

**Objectives**

- Write the supervisory procedure
- Verify it is operationally executable
- Test it against a real workflow

**Topics:** Procedure writing · Executability · Testing · Principal sign-off

**Activity:** Write the procedure and have a principal execute it against real output.

## What is the capstone project?

**Supervisory procedure for a client-facing AI workflow.** Produce updated written supervisory procedures covering AI-generated communications, a records mapping with gaps remediated, off-channel policy, marketing review workflow, recommendation basis documentation, and an examination readiness assessment.

_Deliverable:_ An executable supervisory procedure with an examination readiness gap list.

## How are learners assessed?

- Procedure executed by a principal against real output
- Records mapping tested — can you produce a prompt from six months ago?
- Mock examination request completed with gaps identified

## What ships with the course?

- **Facilitator guide.** Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
- **Learner workbook.** Exercises, checklists, and the templates each module's activity produces.
- **Hands-on lab environment.** A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
- **Assessment bank.** Scenario questions and rubric criteria mapped to each stated learning outcome.
- **Source bibliography.** Every primary regulation and standard cited on this page, linked and dated.

## Which AI agents does this course use?

- [Compliance Agent](https://ibl.ai/solutions/financial-services/agent/compliance-agent)
- [Regulatory Reporting Agent](https://ibl.ai/solutions/financial-services/agent/regulatory-reporting-agent)
- [Client Advisory Agent](https://ibl.ai/solutions/financial-services/agent/client-advisory-agent)
- [Knowledge Agent](https://ibl.ai/solutions/financial-services/agent/knowledge-agent)

## Where does the course material come from?

Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.

- [Artificial Intelligence](https://www.finra.org/rules-guidance/key-topics/artificial-intelligence) — FINRA. FINRA's guidance on AI use by member firms.
- [U.S. Securities and Exchange Commission](https://www.sec.gov/) — SEC. Marketing rule, recordkeeping, and examination priorities.
- [FFIEC](https://www.ffiec.gov/) — Federal Financial Institutions Examination Council. Technology risk expectations relevant to supervision systems.
- [AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework) — NIST. Governance structure supporting the supervisory design.

## Delivery notes

Binding guidance for anyone preparing and delivering this course:

- Module 2's prompt retention is the gap almost every firm has. Test it concretely — ask participants to produce a prompt from six months ago and watch the room.
- Off-channel enforcement has produced very large penalties. Module 3 should reference the enforcement pattern without naming firms gratuitously.
- Examination priorities change annually. Verify current AI-related priorities at each revision rather than citing a specific year's letter.
- Module 8's procedure must be operationally executable. Supervisory procedures that a principal cannot actually perform are a finding in themselves.
- Have a compliance officer with examination experience review the course. Examination expectations are set by practice, not by rule text.

## Why run AI training on a platform you own?

- **You own the course, not a licence to it.** Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
- **Model-agnostic delivery.** Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
- **No per-seat training licences.** Usage-based or self-hosted, so cost tracks actual use rather than headcount.
- **Deploy anywhere.** Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.

## Frequently asked questions

### What does the AI Supervision Under FINRA and SEC Recordkeeping Rules course cover?

Supervisory and recordkeeping obligations apply to AI-generated communications exactly as they do to human ones, and most firms have not extended their systems to cover them. This course covers retaining prompts and outputs, off-channel risk introduced by AI tools, advertising rule compliance, and examination readiness. It runs 5.5 hours across 8 modules across 8 modules, at intermediate level, and closes with a capstone: Supervisory procedure for a client-facing AI workflow.

### Who should take AI Supervision Under FINRA and SEC Recordkeeping Rules?

It is written for Chief compliance officers of broker-dealers and RIAs, Supervisory principals, Surveillance and communications review staff, Internal audit covering supervision. Prerequisites: Broker-dealer or RIA compliance experience; Familiarity with your supervisory system.

### Can we run this course on our own infrastructure?

Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for financial services teams that cannot send work to a public AI tool.

### How do we get access to AI Supervision Under FINRA and SEC Recordkeeping Rules?

Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.

### How much does AI training for financial services cost on ibl.ai?

There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

## More Financial Services courses

- [AI Model Risk Management for Financial Institutions](https://ibl.ai/solutions/financial-services/course/ai-model-risk-management): Extend model risk governance to generative AI — inventory, validation, challenger testing, and the documentation examiners expect for a non-deterministic model.
- [KYC and AML with AI: Screening, Alerts, and SAR Support](https://ibl.ai/solutions/financial-services/course/kyc-aml-with-ai): Apply AI across the BSA/AML program — name screening, alert triage, and narrative drafting — without weakening the audit trail a regulator will examine.
- [Fraud Detection with AI: Anomalies, Alerts, and False Positives](https://ibl.ai/solutions/financial-services/course/fraud-detection-with-ai): Build AI-assisted fraud detection where a false positive is a blocked customer — anomaly detection, adaptive fraud, and fair-lending exposure.
- [AI for Client Advisory Without the Compliance Risk](https://ibl.ai/solutions/financial-services/course/ai-client-advisory-compliance): Research and client content generation inside a regulated advisory business — sourcing, review workflow, disclosure, and the line before personalized advice.
- [Regulatory Reporting Automation: SOX, PCI DSS, and Audit Trails](https://ibl.ai/solutions/financial-services/course/regulatory-reporting-automation): Automate regulatory reporting and control testing with AI — evidence collection, narrative drafting, and a control environment that keeps the automation auditable.
- [Private LLMs in Finance: Keeping Client Data In-House](https://ibl.ai/solutions/financial-services/course/private-llms-in-finance): Deploy capable models inside your own network — open-weight selection, hardware sizing, GLBA and cross-border considerations, and the ownership question.
