Artificial intelligence is rapidly reshaping the regulatory and operational landscape for investment advisers. This month, we’ve seen regulators move beyond broad discussions of AI and begin focusing on how firms govern, monitor, disclose, and oversee its use. At the same time, operational due diligence continues to evolve as investors place greater emphasis on governance, cybersecurity, vendor oversight, and operational resilience.
The broader theme is clear: firms are increasingly being evaluated not simply on whether policies exist, but on whether they can demonstrate that their controls operate effectively in practice. From SEC examinations and fiduciary obligations to frontier AI governance and operational due diligence, expectations continue to rise across the regulatory landscape.
In this month’s edition of The Salus GRC Brief, we’ve highlighted the latest developments and practical insights to help firms stay ahead of these evolving expectations.
AI Practices Now in the Crosshairs of SEC Exams
The SEC has begun requesting detailed information about firms’ AI governance, disclosures, vendor oversight, and compliance programs during examinations. Firms should prepare for deeper scrutiny into how AI is governed, monitored, and documented across the organization.
Operational Due Diligence: Building ODD-Ready Organizations for Investment Managers and Service Providers
Operational due diligence has become a continuous assessment of governance, cybersecurity, operational resilience, and vendor oversight. Investors increasingly expect documented evidence that operational controls function effectively—not simply that policies exist.
Frontier AI Intervention: When Model Access Becomes a Governance Issue
Government oversight of frontier AI models is introducing new considerations around vendor risk, business continuity, operational resilience, and model availability. Firms should begin evaluating AI providers as critical third-party vendors within their governance frameworks.
The Death of the DOL’s 2024 Retirement Security Rule: What It Means for Investment Advisers Providing Rollover Advice
Although the DOL’s 2024 Retirement Security Rule has been vacated, existing fiduciary obligations remain in place. Investment advisers should continue maintaining robust rollover documentation and compliance with PTE 2020-02 where applicable.
Regulatory Deadlines
- Quarterly Form 13H – July 10, 2026
- FOCUS Part II Quarterly Filing (FINRA) – July 24, 2026
- Form Custody (FINRA) – July 24, 2026
- Crypto Activities Information Request (FINRA) – July 24, 2026
- SSOI Quarterly Filing (FINRA) – July 29, 2026
- Distribute Pool Participant Statements (NFA/CFTC) – July 30, 2026
A Note from Bill Mulligan, CEO
Artificial intelligence continues to reshape the regulatory and operational landscape for investment advisers at a remarkable pace. Over the past several months, we have seen a clear evolution in regulatory expectations, from broad discussions about AI to detailed examination requests focused on how firms govern, monitor, disclose, oversee, and manage its use. The SEC is now requesting information on AI-related marketing, investment processes, vendor oversight, governance structures, and internal controls, reflecting the reality that AI has become a mainstream component of advisory operations rather than a future consideration. At the same time, recent developments involving the Department of Labor’s Retirement Security Rule provide an important reminder that changes to the regulatory framework do not necessarily lessen firms’ fiduciary obligations. While the 2024 rule has been vacated, advisers providing retirement advice remain subject to longstanding fiduciary standards and should continue to maintain robust documentation and best-interest processes. Across both technology and fiduciary compliance, firms are increasingly being measured not simply by whether controls exist, but by whether they are thoughtfully designed and consistently implemented.
Institutional investor expectations are evolving in much the same way. Operational due diligence has become far more than a regulatory compliance exercise. It is now an ongoing assessment of governance, operational resilience, cybersecurity, and oversight of critical third-party service providers. Increasingly, investors expect evidence, not simply policies; that key controls operate effectively in practice. AI governance has also become part of that review, with growing scrutiny of how firms approve AI tools, protect confidential information, oversee technology vendors, and monitor employee use. Strong governance, periodic testing, thoughtful vendor oversight, and well-documented operational controls are becoming meaningful differentiators for investment managers seeking to build confidence with both investors and regulators.
Looking ahead, the conversation is expanding beyond how firms use AI to include the resilience of the underlying technology itself. As governments take a more active role in overseeing frontier AI models, firms should begin viewing AI providers through the same lens as any other critical service provider. Questions surrounding model availability, vendor concentration, data governance, business continuity, and operational resilience are quickly becoming part of the AI governance framework. Together, these developments reinforce a broader theme that extends well beyond artificial intelligence: effective governance is increasingly defined by preparation, transparency, and the ability to demonstrate that risk management practices work in the real world. Our focus remains on helping clients navigate these evolving regulatory and operational challenges by integrating compliance, cybersecurity, operational due diligence, and AI governance into a practical, risk-based framework.
As always, we appreciate the confidence our clients place in us and look forward to continuing to support them in the months ahead.
Warm regards,
Bill Mulligan, CEO