What Security Standards Should an RIA Firm Require Before Adopting Any AI Tool with Client Data?
TLDR: Most RIA firms evaluating AI tools spend 80 percent of their time on capability demos and 20 percent on security. That ratio should be reversed. The security question is not whether AI can be trusted with client data in the abstract — it is whether a specific vendor can answer six specific questions clearly and completely. Vendors who can't answer them clearly are not ready for a fiduciary relationship.
Best For: Compliance officers, COOs, and risk-averse managing partners at independent RIAs who are in the vendor evaluation phase for AI tools and need a framework for clearing the security and regulatory hurdle before any procurement decision.
AI security in a wealth management context is not a single question. It is a series of specific, testable standards that determine whether client financial data is handled in a way that is consistent with fiduciary obligations, SEC and state regulatory requirements, and the firm's own data governance practices. Any AI vendor that cannot answer each of these questions with specificity is not ready to handle client data at an RIA firm, regardless of how impressive the product capability is.
Why Security Is the First Question, Not the Last
In most AI vendor evaluations at RIA firms, security comes up late in the process. The team does the capability demo, the pilot, the pricing discussion — and then, when someone is about to sign a contract, compliance asks the security questions. This is backwards.
The security evaluation should happen before the capability evaluation. The reason is simple: if a vendor fails the security test, the capability conversation is irrelevant. Spending six weeks evaluating a product that can't pass a basic security review wastes time on both sides and sometimes creates organizational momentum toward adoption that makes the security findings harder to act on.
According to the SEC's examination priorities, investment advisers are regularly examined on their information security programs, their use of third-party vendors, and their data governance practices. An AI vendor with access to client financial data is a third-party vendor with extraordinary data access. The SEC expects registered investment advisers to have conducted appropriate due diligence on vendors of this type. That due diligence should be documented and defensible.
The 6 Security Questions Every RIA Must Ask Before Adopting an AI Tool
These are the six questions that determine whether an AI vendor's security posture is appropriate for RIA use with client financial data. They are not aspirational — they are requirements. A vendor who cannot answer all six clearly should not proceed in the evaluation.
Question 1: Does the vendor have zero data retention with all AI model providers?
Zero data retention means that client data processed through the AI tool is not stored, cached, or used to train any AI model by any provider in the vendor's chain. This includes the AI vendor's own models and any third-party large language models (OpenAI, Anthropic, Google, etc.) the vendor uses in its product.
This is not a standard condition in most AI vendor contracts. Many AI vendors use third-party models and accept those providers' default terms, which typically include some form of data usage for model improvement. The acceptable standard for an RIA is explicit contractual confirmation, from every provider in the chain, that client data is never used to train models and is never retained after the session that generated it. Lira's Trust Center documents this standard with third-party verification.
Question 2: Does the vendor maintain a complete, timestamped action log?
Every action an AI agent takes with client data — every read, every write, every form submission, every data transfer — should be logged with a timestamp and actor ID. This log should be accessible to the firm for compliance review and examination response. The log should be immutable: it cannot be edited or deleted by the vendor or by the firm after the fact.
This is the AI equivalent of a compliance trail. In a manual process, the audit trail depends on humans documenting what they did. In an AI agent workflow, the audit trail is a byproduct of execution — every action is logged automatically. A vendor that cannot produce a complete, queryable action log does not have the compliance infrastructure appropriate for a fiduciary context. As described in automating RIA client onboarding, the audit trail from an automated workflow is typically more complete than from a manual one.
Question 3: What third-party security verification does the vendor hold?
The two relevant certifications for AI vendors handling financial data are SOC2 Type 2 and, for firms with international clients or more stringent requirements, ISO 27001. SOC2 Type 2 is not a point-in-time assessment — it requires continuous monitoring over a period (typically 6 to 12 months) and annual re-certification. A vendor with SOC2 Type 2 certification has demonstrated, through a third-party audit, that their security controls are working consistently over time.
A vendor with SOC2 Type 1 (a point-in-time assessment) or no certification at all has not demonstrated that their controls work in practice. The security posture that matters for RIA clients is the one that holds under operational conditions, not the one described in a policy document.
Question 4: What are the vendor's access controls and permission boundaries?
An AI agent should only be able to read from and write to the systems the firm has explicitly authorized. The firm should be able to define, at a granular level, which data sources the agent can access, what kinds of actions it can take, and under what conditions it escalates to a human.
The firm should also be able to restrict access on a role basis: not every advisor needs the agent to have access to every client's data. The permission model should mirror the firm's existing data governance practices, not override them. A vendor that cannot articulate their permission model in detail, or that requires broad data access as a default condition of deployment, does not meet the access control standard for RIA use.
Question 5: How does the vendor handle a data breach?
The vendor should have a documented, tested incident response plan. The firm should know, in advance, the timeline for breach notification, what the vendor's obligations are under that plan, and what evidence the firm will receive to assess the scope of any incident. Most state regulations and SEC guidance require investment advisers to have vendor breach notification agreements in place before a breach occurs, not after.
The SEC's Regulation S-P, which covers the safeguarding of customer information, was updated in 2024 to include more explicit requirements around vendor oversight and incident response timelines. An AI vendor that cannot describe their incident response plan in specific terms is not compliant with the current regulatory environment for RIA third-party vendors.
Question 6: Can the vendor provide client references from other registered investment advisers?
This is not a security requirement in the technical sense, but it is the most practical form of due diligence. An AI vendor that has deployed its product successfully at other SEC-registered RIA firms has already navigated the compliance review that the evaluating firm is now conducting. Those client references can speak specifically to the security review process, the documentation provided, and the compliance team's assessment.
A vendor that cannot provide RIA-specific client references — not just financial services clients, but registered investment advisers specifically — is asking the evaluating firm to be the first fiduciary client who tests whether the security posture holds.
The Compliance Case for AI: Why Automated Processes Can Be More Auditable Than Manual Ones
A persistent misconception in RIA compliance departments is that manual processes are inherently safer than automated ones because humans are accountable in ways that software is not. This is not supported by the evidence.
Manual processes fail in predictable ways. Documentation is inconsistent because humans exercise judgment about what's worth recording. Audit trails are incomplete because no one has time to log every action. Data entry errors occur because humans make mistakes under time pressure. A compliance examiner reviewing manual records is frequently reviewing incomplete, inconsistent documentation that leaves gaps that cannot be explained.
A well-implemented AI agent process produces a complete, consistent, machine-generated audit trail. Every action is logged. Every data read and write is timestamped. The record is available immediately, without requiring anyone to reconstruct what happened. According to the framework described in AI agents vs. AI copilots for financial advisors, agents that complete workflows end to end produce better compliance documentation than the manual workflows they replace, not worse.
The compliance argument for AI is not that AI is inherently safe. It is that a properly implemented AI agent, from a vendor who meets the security standards above, is more auditable, more consistent, and more traceable than the manual alternative. That argument needs to be made specifically, with evidence, not asserted generically. The six questions above are what produces the evidence.
What "SOC2" Means and What It Doesn't
SOC2 is a framework developed by the American Institute of CPAs (AICPA) for auditing the security, availability, processing integrity, confidentiality, and privacy controls of service organizations. SOC2 Type 1 assesses whether controls are designed correctly at a point in time. SOC2 Type 2 assesses whether controls are operating effectively over a period of time, typically six to twelve months.
For RIA vendor evaluation purposes, the relevant certification is SOC2 Type 2. Type 1 tells you the vendor designed their security controls correctly. Type 2 tells you those controls are actually working in practice. A vendor who can only produce a Type 1 report has not yet demonstrated that their security posture is operational.
Vendors who say they are "SOC2 compliant" or "pursuing SOC2" have not completed a Type 2 audit. The correct terminology for a completed Type 2 audit is "SOC2 Type 2 certified." Compliance teams should ask for the audit report itself, not just the vendor's characterization of their certification status.
Building a Vendor Security Questionnaire for AI Tools
The six questions above can be formalized into a security questionnaire that every AI vendor completes before the capability evaluation proceeds. This questionnaire should be a standard part of the firm's vendor management program, alongside whatever questionnaire is already used for CRM vendors, portfolio management software, and custodian integrations.
Including AI tools in the existing vendor management framework — rather than evaluating them as a special category — signals to regulators that the firm is treating AI with appropriate governance rigor. It also creates a consistent documentation record that demonstrates the firm's third-party vendor oversight is systematic, not ad hoc.
For firms that are also navigating the workflow standardization work, integrating AI vendor security review into the standardized procurement process is the right architecture: every vendor who touches client data goes through the same security evaluation, documented the same way, before any capability discussion proceeds.
Frequently Asked Questions
What security certifications should an AI vendor hold before an RIA adopts their product?
The minimum relevant certification for an AI vendor handling client financial data is SOC2 Type 2, and ISO 27001 for firms with more stringent international data handling requirements. SOC2 Type 2 requires a third-party audit of security controls operating consistently over 6 to 12 months, not just at a point in time. Vendors with only SOC2 Type 1 or no certification have not demonstrated that their security controls work in practice. Ask to see the audit report, not just the vendor's certification claim.
What is zero data retention and why does it matter for RIA firms?
Zero data retention means that client data processed through an AI tool is never stored, cached, or used to train any model by any provider in the vendor's chain. This is a critical standard for RIA firms because it ensures that client financial information is not contributing to third-party AI model training, which could create data exposure risks. Zero data retention must be contractually confirmed with every provider in the vendor's AI stack, not just the vendor itself.
What does the SEC say about using AI tools that handle client data?
The SEC requires registered investment advisers to conduct appropriate due diligence on third-party vendors with access to client data, document that due diligence, and have breach notification agreements in place before any incident occurs. Regulation S-P, updated in 2024, includes more explicit vendor oversight requirements. An AI vendor with access to client financial data should be treated as a high-risk third-party vendor and evaluated accordingly in the firm's vendor management program.
How should an RIA document its AI vendor security evaluation for regulatory purposes?
Document the security evaluation using the same framework as other third-party vendor reviews: a completed vendor security questionnaire, the vendor's SOC2 Type 2 report or equivalent certification, contractual terms covering data retention and breach notification, and a record of the compliance team's review and sign-off. This documentation should be retained in the firm's vendor management file and available for examination review. Regulators expect to see systematic vendor oversight, not ad hoc approval.
Is an AI agent more or less compliant than a manual process at an RIA firm?
A well-implemented AI agent is more compliant than a comparable manual process, because it produces a complete, consistent, machine-generated audit trail rather than relying on human documentation habits. Every action the agent takes is logged with a timestamp. Manual processes rely on advisors and ops staff recording what they did, which is inconsistent by nature. As described in AI agents vs. AI copilots, the audit trail from an automated workflow is typically more complete than from a manual one.
What is the difference between SOC2 Type 1 and SOC2 Type 2 for AI vendor evaluation?
SOC2 Type 1 assesses whether security controls are designed correctly at a point in time. SOC2 Type 2 assesses whether those controls are actually operating effectively over a sustained period, typically 6 to 12 months. For RIA vendor evaluation, Type 2 is the relevant standard. A vendor with only Type 1 certification has demonstrated that their security is designed correctly, not that it works in practice. Always ask for the audit report, not just the vendor's certification claim.
What access controls should an AI tool provide for RIA use?
An AI tool used at an RIA should allow the firm to define, at a granular level, which data sources the agent can read from and write to, what categories of actions it can take, and which team members or roles can configure those permissions. The agent's access should mirror the firm's existing data governance model, not override it. A vendor that requires broad data access as a default condition of deployment does not meet the access control standard for fiduciary use.
What breach notification obligations should an AI vendor commit to in a contract?
The AI vendor contract should specify: the timeline for notifying the firm of a breach (typically 72 hours or less under Regulation S-P), the scope of notification (which data, which clients, what was accessed), the evidence the firm will receive to assess the incident, and the vendor's obligations to cooperate with any regulatory notification the firm must make. These obligations must be agreed in writing before deployment. A vendor who cannot commit to specific breach notification terms in the contract is not ready for RIA use.
How does an RIA integrate AI vendor security review into its existing compliance program?
Treat AI vendors the same as any other high-access third-party vendor: complete a security questionnaire before capability evaluation begins, require SOC2 Type 2 certification, include data handling and breach notification terms in the contract, and document the compliance team's review and approval. Integrating AI tools into the existing vendor management framework signals to regulators that the firm's AI governance is systematic. Evaluating AI tools outside the normal vendor framework creates documentation gaps.
What should an RIA ask for in an AI vendor's security documentation?
Ask for: the full SOC2 Type 2 audit report (not a summary), the vendor's data processing agreement, written confirmation of zero data retention from every AI model provider in the vendor's stack, the vendor's incident response plan, and references from other registered investment advisers who have completed the security review. If the vendor cannot provide all of these documents on request, the security evaluation cannot be completed. A vendor who provides a security questionnaire response but resists sharing the underlying documentation is a red flag.
What is the SEC's current position on AI use in investment advisory firms?
The SEC has signaled that AI use in investment advisory firms is subject to existing fiduciary, supervision, and data protection obligations, and that advisers should expect AI-related practices to be reviewed during examinations. The SEC's 2024 examination priorities explicitly identify AI use as an examination focus area. The SEC's approach is not to prohibit AI use, but to ensure that advisers are applying appropriate oversight, disclosure, and data governance standards to AI tools the same way they apply them to any other technology in the practice.
Can an AI tool that doesn't yet have SOC2 Type 2 certification be used at an RIA firm?
A vendor without SOC2 Type 2 certification can be used only if the firm is willing to accept the compliance and documentation risk of deploying a vendor whose security controls have not been independently verified over time. For most compliance teams at SEC-registered RIA firms, that risk is not acceptable when the vendor has access to client financial data. Some firms accept a vendor with SOC2 Type 1 and a documented path to Type 2, with a contractual commitment to complete the certification within a defined timeline. Type 1 alone is not a substitute for Type 2.
How does a firm verify that zero data retention is actually being enforced, not just claimed?
Verify through three mechanisms: contractual language that specifies zero data retention with financial penalties for breach; the SOC2 Type 2 audit report, which should address data handling and retention controls; and direct contractual terms with each AI model provider in the vendor's stack, not just with the vendor. Zero data retention claimed only by the vendor but not confirmed at the model provider level is not the same as zero data retention in practice. The contractual chain must extend to every party that touches the data.
What is the role of the compliance officer in an AI vendor evaluation at an RIA?
The compliance officer should be involved from the beginning of the evaluation, not just at contract review. The compliance officer defines the security requirements that the vendor must meet, reviews the vendor's security documentation, approves the terms of the data processing agreement, and signs off before the product is deployed with client data. A compliance officer who is brought in only at contract signing has missed the point in the evaluation where their input most changes the outcome.
How should an RIA disclose its use of AI tools to clients?
Disclosure of material AI tool use should be reviewed for inclusion in Form ADV Part 2A, particularly where AI tools are involved in investment management, financial planning, or client data processing. The SEC has indicated that advisers should disclose conflicts of interest and material practices related to their use of technology, including AI. Compliance teams should review their ADV narrative each time a new AI tool is deployed to assess whether disclosure is required. When in doubt, disclose.
What red flags should disqualify an AI vendor from consideration at an RIA?
The clearest disqualifying red flags are: inability to confirm zero data retention with all model providers, no SOC2 Type 2 certification and no documented path to it, vague or incomplete breach notification terms, broad data access requirements with no granular permission controls, and no RIA-specific client references who have completed the compliance review. A vendor who responds to security questions with marketing language rather than technical specificity is not ready for fiduciary deployment, regardless of the capability they're demonstrating.
