Why AI recordkeeping is becoming a compliance risk

Why AI recordkeeping is becoming a compliance risk

Financial firms are making decisions about artificial intelligence before regulators have established an AI-specific rulebook. But according to Red Oak Analysis, the absence of dedicated AI rules does not mean firms are operating without regulatory obligations.

The analysis, based on a 16 July Red Oak Insights webinar, brings together perspectives from Brian Rubin, partner and co-head of the Securities Enforcement Group at Eversheds Sutherland and former SEC and NASD enforcement attorney, Derek Stern, head of global distribution compliance at Manulife Wealth & Asset Management, and Jamie Hoyle, VP of product at MirrorWeb. Red Oak chief supervision evangelist James Cella moderated the discussion.

Rubin put the regulatory position simply: “There are no existing AI rules.” However, he argued that regulators are not waiting for new legislation or dedicated AI requirements before examining firms or bringing enforcement actions.

Existing requirements around supervision, communications, recordkeeping, conflicts of interest, Reg BI and fiduciary obligations can already apply when firms introduce AI into financial services.

FINRA’s Regulatory Notice 24-09 provides an example of how existing requirements can apply to AI. The notice states: “If a firm is using Gen AI tools as part of its supervisory system—for the review of electronic correspondence, for instance—its policies and procedures should address technology governance, including model risk management, data privacy and integrity, reliability and accuracy of the AI model.”

The issue is no longer theoretical. The SEC has charged firms over claims about their AI capabilities, while FINRA has brought an anti-money laundering case involving an automated identity-verification process. Neither case depended on the introduction of a new AI-specific rule.

For Rubin, the message for firms is increasingly about being able to demonstrate how technology is being used and controlled. He described this as a “show your work” environment, where regulators can look beyond written policies to examine who approved a system, what data it uses, how its outputs are validated and where human accountability remains.

The challenge is familiar to financial services firms. Rubin compared the current situation with the evolution of electronic communications. Rules originally developed around paper records were later applied to email and then to communications through channels such as WhatsApp and personal devices. The underlying regulatory framework did not necessarily change each time a new communication channel emerged.

AI creates a similar recordkeeping question. Employees using unapproved AI platforms for client-related work could create records outside the firm’s control, echoing the problems firms have already faced with off-channel communications.

There is also uncertainty over exactly which AI records firms should retain and for how long. Rubin noted that there are no AI-specific retention periods and that not every output generated by an AI system will necessarily carry the same regulatory significance.

The question becomes more straightforward when AI-generated material is used for an existing regulated purpose. If an output is sent to a client, incorporated into a recommendation or used in marketing, existing retention requirements can apply regardless of whether the content was produced by a person or a model.

Explainability creates another challenge. Firms need to be able to reconstruct how a decision was reached, what role AI played and where human oversight was involved. Rubin also highlighted model versioning, particularly where a model has been updated or retired between the original decision and a later regulatory examination.

His recommendation is to test that process before a regulator does. Firms should take a decision made six or 12 months earlier and attempt to reconstruct how it was reached. If they cannot, the exercise could expose a gap in their controls.

The discussion also highlighted a changing role for compliance teams. Stern said the adoption of AI at Manulife Wealth & Asset Management is being driven from the top of the organisation, with compliance involved early alongside technology, legal and marketing teams.

That represents a shift from treating compliance as a final checkpoint to involving it while systems are still being developed. Stern said compliance is no longer the “department of no” or “sales prevention”, but instead is increasingly viewed as a partner in the development and deployment of technology.

Stern outlined several considerations for assessing an AI system before it enters a compliance workflow. These include how data is handled and stored, who can access it, whether the system’s conclusions can be explained, how vendors manage model updates and how the technology performs against human review.

Hoyle added a warning about claims that compliance can simply be automated. He said, “you’ll hear [vendors] talk about putting compliance on autopilot and you should run for the hills.”

For Hoyle, one area where technology is changing compliance is communications surveillance. Traditional approaches based on keywords and lexicons can produce large numbers of false positives, while newer systems can use a firm’s own supervisory policies to assess communications in context.

The difference is between identifying a word and understanding why something may represent a risk. Hoyle gave the example of a firm’s $250 gift limit. Rather than requiring a specific keyword for every potentially relevant restaurant, a contextual system could recognise that a dinner at a three-Michelin-star restaurant may exceed the firm’s policy.

That shift also creates another requirement: firms need to understand why a system has raised a particular flag. For compliance teams, the ability to explain the reasoning behind an alert can be just as important as generating the alert itself.

The takeaway from Red Oak Analysis is that financial firms cannot wait for an AI-specific rulebook before addressing governance. The technology may be new, but the underlying expectations around documentation, explainability and human accountability are not. As AI becomes more embedded in financial services, firms will need to demonstrate that the technology they rely on is properly governed and that they remain accountable for its outcomes.

Read the full RedOak analysis.

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.