RegReview · Capability
AI Governance
Inventory every AI tool. Apply a firm-specific use policy. Produce the evidence regulators are asking for. Delivered inside RegReview, aligned to NIST AI RMF and SEC 2024–2026 exam priorities.
What's inside
AI vendor inventory
Every AI tool used by the firm — ChatGPT, Copilot, model providers, embedded features — logged with data-flow, purpose, and human-review posture.
AI use-policy + attestations
Firm-specific AI use policy generated for your registration type, plus staff acknowledgements and annual refreshers stored to the exam file.
Risk classification
Classify each AI use case by client-impact, data-sensitivity, and reviewability — aligned to NIST AI RMF and SEC risk-based examination priorities.
Model change tracking
Version and log model upgrades, prompt changes, and dataset updates so you can answer 'what changed and when' during an exam.
Marketing Rule guardrails
Any AI-drafted client communication routes through Marketing Review before it goes out — enforcing SEC 206(4)-1 and FINRA 2210 automatically.
Human-in-the-loop evidence
Every agent hand-off logs the licensed reviewer's sign-off — the auditable checkpoint regulators want to see for AI-assisted work.
Building with LLMs
Firms now use large language models — Claude, ChatGPT, Gemini, Copilot, or an internal model — to draft policies, procedures, WSPs, and disclosures, and to build internal tools on model APIs. That work creates books-and-records, supervision, and vendor obligations. AI Governance adds a human review gate before any AI-assisted document is adopted, retains the prompt, output, model version, and reviewer decision, and carries an AI section into your annual 206(4)-7 or 3120 review file.
Model-agnostic. Model names appear for identification only. FIN Group is not affiliated with, endorsed by, or certified by any AI model provider.
FAQ
What is AI Governance in RegReview?
AI Governance is the RegReview capability that inventories every AI tool your firm uses, applies a firm-specific AI use policy, and produces the evidence regulators are starting to ask for — vendor list, risk classification, human-in-the-loop sign-offs, and model change history.
Is this the same as the SEC's predictive-analytics proposal?
AI Governance is built to satisfy the SEC's expected AI-conflict-of-interest rulemaking, the SEC's 2024 exam priorities on AI, and NIST AI RMF. When the final rules land, AI Governance updates the policy templates and evidence register accordingly.
Does it govern our own use of ChatGPT and Copilot?
Yes — general-purpose tools (ChatGPT, Copilot, Gemini) are inventoried alongside compliance-specific AI. The use-policy sets guardrails on what data may be entered, which use cases require reviewer sign-off, and how outputs are logged.
Can we use Claude or ChatGPT to write our policies and procedures?
Yes — with a governed process. The model may draft; a licensed reviewer must adapt it to your business, approve it, and leave a record. AI Governance supplies the permitted-use map, the human review gate, and the retained prompt/output evidence, so an examiner can see how a procedure was produced and who owned the judgment. The service tier that operates this for you is Governed AI Development.
Does it cover internal apps and agents we build on a model API?
Yes. Model and prompt versions are logged, pre-deployment validation results are stored as testing evidence, and the model provider gets a vendor AI diligence file. We govern and document the build — we do not write your application code or administer your AI tenants.
How does it interact with the FIN Group AI agents?
Every FIN Group AI agent — Marketing Review, PST, Trade Surveillance, etc. — logs its outputs and reviewer sign-off into the AI Governance register. That means the same evidence file covers your firm's own AI usage and the AI agents doing your compliance work.