Industries / Financial services
AI answers a supervisor can check.
You are putting AI in front of people, under SEC and FINRA rules. Every answer it gives names who approved the source, and when.
The problem
Nobody can see what happened.
“There are no controls over where our information is, who has access to it, or when access should be revoked.”
Before an AI assistant is allowed to go live, a review board asks two things: where the answers came from, and who was allowed to see them.
Two business units have already bought their own AI tools. Each one reads a different pile of files, under different permissions.
Supervision asks whether your written procedures cover what an assistant tells a registered representative. Books and records asks whether you can produce what was said, and what it rested on.
An answer assembled on the spot from files that have since moved cannot be rebuilt later. So the assistant does not ship, and the budget sits.
Why this industry
What the rules actually ask.
Three things decide whether an assistant survives review at a firm like yours. Each turns on the same question: can you produce the record behind the answer?
None of the three is about how good the answer sounds. They are about whether anyone can show, afterwards, what it was built from.
- Books and records, SEC Rule 17a-4. You have to keep what was said and be able to produce it. An answer built from files that later changed cannot be rebuilt. Here every answer comes from a numbered version, so the record exists from the start.
- Supervision, FINRA Rule 3110. Your written procedures have to cover what your people are told. You cannot review an answer that does not exist until somebody asks for it. Approval happens once, before use, and the assistant serves only what passed it.
- Model risk. Your validation team needs to know what the model reads. A live index of everything the firm has ever written is not a bounded input. A set of approved, numbered entries is.
What we will not claim
None of this makes your firm compliant with SEC or FINRA rules, and we will not tell you it does. Rules and examinations assess firms, not software.
What Cognatum supplies is evidence toward duties your firm already carries: the named approver, the date, the version history, and the source behind every answer the AI serves.
What it does here
Five things that need approving.
The knowledge behind an assistant at your firm is not one kind of thing. Five classes carry approval duties at almost any broker-dealer or adviser.
Suitability
What may be said, and to whom
A representative quoting the assistant is quoting the firm. The entry carries the current guidance, its approver, and the date it took effect.
Disclosure
Approved wording, word for word
Approved language is approved as written. A language model rephrases by default. Here the wording comes back exactly, from the current revision.
Product terms
Rates and fees that moved
Approve the new terms and the old entry is archived with the dates it applied. The assistant stops serving it everywhere at once.
Procedures
The revision in force
Ask what to do and the answer comes from the revision in force, with a named approver on it, not from whichever copy ranked first.
Due diligence
What you told the last one
Questionnaires, bids and tenders ask the same questions every quarter. Answering from the approved entries means the answer you send is the one legal and security signed.
Returned word for word
“Past performance is no guarantee of future results. The value of an investment may fall as well as rise, and you may get back less than you invested.”
D-214 ยท v6
- Adviser portal Unchanged
- Client letter Unchanged
- AI assistant Refused
What was refused
Asked to send “can go down too” in place of “may fall as well as rise”. Rewording approved text is refused, not corrected.
Verbatim enforcement
Approved wording, returned as written
A language model rephrases by default. Tighten a sentence in a disclosure and you have changed the disclosure. It reads well enough that nobody notices until somebody reads the transcript.
So disclosure language is marked as fixed. Cognatum returns it word for word from the current revision, in full, or not at all. It is never summarised, and the loop's wording step skips it.
Conflict surfacing
When two approved sources disagree
Your procedures live on a shared drive and more than one person edits them. Terms change midstream. Sooner or later two approved answers to the same question are both live.
Cognatum holds them apart. Where a date settles it, the resolution is drafted and queued for approval. Where it is a real disagreement, both go to a named person, and neither is served as approved until that is closed.
Averaging two approved answers produces one nobody approved. That is worse than no answer, because it is confident and has no author.
Frameworks
What each framework asks.
Written as pairs, because a list of framework names is one screenshot away from reading as a claim to hold them.
| Instrument | What it asks of you | What we supply toward it |
|---|---|---|
| SEC Rule 17a-4 | That records are retained in a specified form and produced on request within a set time. | Each entry keeps its versions and its approvals, so producing the version that was live on a given date is a lookup. |
| FINRA supervision obligations | Written supervisory procedures and a designated principal accountable for review. | A named person approves each entry before it can be served, and the name travels with every answer built on it. |
| Gramm-Leach-Bliley | That customer information is safeguarded and that the safeguards are documented. | Retrieval and answers are gated by clearance at the AI layer, not only at the document store. |
| Model risk governance | That any system shaping a decision is controlled, validated, and monitored. | The knowledge an assistant answers from is versioned and approved, which is the input side of that control. |
This table describes obligations that fall on your organization, and the evidence Cognatum produces toward them. It is not a claim of certification or conformity, ours or yours.
Why not search
Search cannot sign anything.
Search points at a file wherever it happens to sit. It can rank that file. It cannot number it, approve it, or say who stood behind it.
A system of record is the other thing: it stores the approved answer itself. The version, the approver, and the date belong to the answer and travel with it.
That is why an examiner question has an answer here. You produce a record instead of reconstructing one.
Use disclosure D-214 rev 6. It supersedes rev 5 for all retail communications and carries the current market-risk language. SOP-4471 v3
In practice
Can the assistant see that?
One security review, before a sales assistant goes anywhere near restricted data.
Security is asked whether an AI assistant used by your sales teams can reach restricted customer and product information.
They check the role mappings and the sensitivity labels, then run the same prompts as people with different clearances and read what comes back.
What is restricted does not appear, and a refusal is recorded with who asked and when, so a denial is explainable rather than mysterious.
They export that record for the review. Nobody reconstructs it afterwards from memory.
Common questions
What firms ask first.
What do we show an examiner who asks how we supervise AI answers?
The record. Every entry the assistant answers from carries a named approver, an approval date, a version history, and a source. You produce the entry, who approved it, when it changed, and what it said on any given date. How that fits your supervisory system is a decision for compliance and counsel.
Our written procedures live on a shared drive and three people edit them. What changes?
Each procedure becomes a numbered entry with one revision in force and a named approver on every change. Ask the assistant a procedures question and the answer comes from that revision, cites it, and stops being served the moment a new one is approved. Every superseded version is kept.
How does this sit with our books and records duties under 17a-4?
Retention is your program, and we do not claim this makes you compliant with SEC Rule 17a-4. What you get is the producible record: approved entries, superseded versions, approval events, and dates, exportable to your retention systems and for examiner requests.
Our model risk team wants to add the assistant to the model inventory. Does this help?
It separates two problems that usually get tangled. However your framework classifies the assistant, the knowledge it reads is a separate input. An open index makes that input unbounded. Approved, numbered entries give validation a defined object to point at.
Product terms changed mid-quarter. How does the wrong answer stop?
The moment the new entry is approved it is what the assistant serves, on every channel at once. The old version is archived rather than deleted, with the dates it applied. An index waits for someone to find and fix every stale copy.
Who holds the approval, compliance or the business?
Your firm decides, per type of entry. What does not vary is the mechanism: every approval is a named person and a date, and the assistant serves nothing that has not passed one.
Knowledge governed. Intelligence everywhere.
See it on your own content, in your own environment.