Enterprise DNA
Key Findings

How financial advisory firms can govern AI agents with access controls, approvals, logs, and monitoring before core system access.

Runtime Controls for AI Agents in Advice Firms
Insight ai

Runtime Controls for AI Agents in Advice Firms

Sam McKay

AI governance has to operate at runtime

A policy document doesn’t govern an AI agent once it starts working inside your business.

It might set the right intent. It may state that client data must remain confidential, advice must be reviewed, and records need to be retained. All sensible. But the real governance question is much more practical.

What can the agent access at 10:14 on a Tuesday morning?

Can it read a client record in your CRM? Can it retrieve portfolio data? Can it draft an ROA from a meeting transcript? Can it upload a document, send an email, update a task, or mark an onboarding requirement as complete?

For financial advisory firms, those questions cannot wait until after the first pilot succeeds. The work is too close to client records, personal information, advice documentation, and regulated workflows.

AI governance is moving from broad acceptable-use policies into runtime controls. Regulated industries are leading because they have to. They know that a static policy can’t prevent an agent from pulling the wrong client record, acting outside its role, or submitting an incomplete document into a core platform.

For an advice firm doing USD 1M to USD 25M in annual revenue, this isn’t a big-enterprise problem. It is a margin, capacity, and risk problem. The firms we speak with commonly have between $70K and $200K a year tied up in manual follow-up, rework, document preparation, delayed onboarding, and senior people checking work that should have been prepared properly in the first place.

The opportunity is real. So is the need for control.

You can see the broader operating model behind this approach through Omni for financial advisory firms. The point isn’t to put a chatbot in front of your team. It is to build agents that do defined work, inside clear boundaries, with a human responsible for the outcome.

The manual work agents can take off your team

Most advisory firms don’t need AI to “transform” every process. They need it to remove recurring work that drags advisers, paraplanners, and client service staff away from clients.

Three areas stand out.

Meeting preparation and post-meeting records

A typical adviser may spend five to 10 hours a week getting ready for client meetings and turning those meetings into useful records afterward.

Before a review, someone pulls recent emails, notes, portfolio changes, action items, goal progress, insurance information, and outstanding service requests. In smaller firms, that job often falls back to the adviser. In larger firms, it is distributed across adviser support and client service teams, which introduces handoffs and delay.

After the meeting, the same team faces another list. File notes need to be completed. Actions have to be assigned. The CRM needs updating. A follow-up email may need drafting. If advice was discussed, the relevant trail needs to be clear.

The Meeting Prep Agent in Omni ops can pull approved data sources into a one-page brief for the adviser before each meeting. It can also prepare a draft record afterward, including discussion topics, agreed actions, and items that require follow-up.

That doesn’t mean the agent gets free access to every client record in the firm. It means it receives access to the specific client, the specific meeting, and the specific source systems required for that task.

That distinction is where runtime governance begins.

Advice documents and compliance records

SOAs, ROAs, file notes, and supporting documentation create a large amount of structured work. A paraplanner is often reconstructing a discussion from notes, recordings, emails, and templates, then sending drafts back for review.

The direct paraplanner cost of an advice document can often sit in the $3K to $8K range once you factor in preparation, revision cycles, adviser input, compliance review, and the cost of waiting for missing information. The bigger issue is cycle time. A document that should move in days can stretch into weeks because someone needs a fact clarified or an adviser has not had time to review a draft.

The Advice Document Agent can take an approved meeting transcript, the relevant client facts, and your firm’s current compliance template to produce a structured first draft. It can identify gaps rather than filling them with assumptions. It can flag statements that require adviser confirmation. It can prepare a file note and a document checklist alongside the draft.

The agent should not have authority to issue advice. It should not publish an SOA, finalise an ROA, or represent that compliance review is complete.

Those are human decisions. Runtime controls make that separation enforceable rather than aspirational.

Client onboarding and KYC

New-client momentum is fragile. A prospect has agreed to proceed, but then the firm sends a broad document request, follows up two weeks later, and discovers key details are missing. A 30- to 60-day onboarding process is still normal in many firms.

That lag costs more than admin time. It can reduce conversion, create a poor first impression, and leave your advisers chasing documents instead of building trust.

The Client Onboarding Agent can guide a client through fact-finding, request KYC documents in the right sequence, check for missing fields, and prepare a clean onboarding pack for the adviser. It can also route exceptions to the right person when information does not match or documents are incomplete.

This is valuable work. It is also an area where an agent may touch identification documents, financial information, risk-profile inputs, and client contact details. You cannot treat it as a basic workflow automation job.

If you are mapping where these processes sit across the wider business, the practical examples in Omni ops are a useful starting point.

What runtime controls look like in an advisory firm

Runtime controls are the rules and checks applied while an agent is operating. They determine what it can see, what it can do, what requires approval, and how the firm can review its actions later.

The controls do not need to make the workflow slow. They need to match the risk of the action.

A draft meeting brief is lower risk than a CRM data change. A request for a missing KYC document is different from marking KYC as complete. A draft ROA is not the same thing as issuing a final document to a client.

Here is the control model I would expect before an agent connects to client records or core systems.

Role-based access tied to the job

Don’t give an agent a generic account with broad permissions because it is convenient.

Give it a role that maps to its assigned work.

A Meeting Prep Agent may be allowed to read the selected client’s recent communications, meeting history, portfolio summary, and outstanding tasks. It should not be able to search the entire client database, access unrelated households, alter investment settings, or download every record in bulk.

An Advice Document Agent may be allowed to access approved transcripts, fact-find data, existing document templates, and adviser notes for a named case. It should not be able to submit the document, change compliance status, or access a different adviser’s active files without a valid assignment.

This is least-privilege access applied in a form that suits agents. The permission should be limited by role, client relationship, system, data type, and time window.

Access also needs to expire. If the agent was given permission to prepare materials for a 2:00 pm client review, it does not need indefinite access to the client record afterward.

Approval steps before meaningful actions

An agent can prepare. A person should approve anything that changes a client-facing record, creates a regulated document, sends sensitive communication, or closes a control step.

Use clear approval gates.

For example, the Client Onboarding Agent can create a draft onboarding pack and identify missing documents. A client service team member can review the pack before it is added to the CRM. If identity verification raises an exception, the agent should route it to the nominated human owner rather than trying to interpret or override the issue.

The Advice Document Agent can draft an SOA section using your template. The adviser and compliance reviewer remain responsible for checking suitability, factual accuracy, disclosure requirements, and final approval.

Approvals should be built into the process, not handled through a vague instruction like “please check the output.” The system should know who must review, what they are reviewing, what source information was used, and what happens if they reject it.

Activity logs that answer practical questions

You need to be able to answer five questions quickly.

  1. Which client record did the agent access?
  2. What data did it retrieve?
  3. What instruction or workflow triggered the action?
  4. What output did it generate or change?
  5. Who approved the next step?

That is the operating record. It matters when a compliance manager reviews a file, when a client asks about a communication, or when the firm needs to understand why an agent produced a particular draft.

Logs should capture the agent identity, human owner, timestamp, source systems, permissions used, workflow state, outputs, approvals, and exceptions. You do not need a complex dashboard on day one. You do need enough evidence to reconstruct an action without relying on someone’s memory.

This is also why a pilot should not live entirely in disconnected personal AI accounts. If the work is important enough to use in the client process, it is important enough to make observable.

Ongoing monitoring and exception handling

Controls at launch are not enough. Agents change as prompts, source systems, templates, and business processes change.

Monitor the work in production.

Review exceptions weekly in the first phase. Track rejected drafts, missing source data, incorrect client matching, approval delays, and actions that were blocked by policy. Look for repeated patterns. If the same issue occurs across six onboarding files, it probably isn’t a one-off user error. It may be a process gap or a control that needs redesigning.

You should also review access regularly. People change roles. Advisers leave. Client relationships move. Systems are replaced. An agent’s permissions cannot be set once and forgotten.

The relevant question is not, “Did the agent make an error?” Every team and every system produces exceptions. The better question is, “Did our controls catch the issue before it affected a client or a regulated record?”

A controlled workflow from start to finish

Consider a client review scheduled for next week.

The adviser’s calendar triggers the Meeting Prep Agent 48 hours before the meeting. The agent receives a job identifier, client identifier, adviser identifier, and a time-limited permission set. It pulls the approved portfolio summary, recent correspondence, prior meeting actions, current goals, and known service issues.

It produces a one-page briefing pack. It highlights missing data or a question that needs human input. It does not invent a view on investment suitability or recommend a product. The adviser reviews the brief before the meeting.

After the meeting, the approved transcript enters the workflow. The agent drafts meeting notes and proposes action items. It can classify tasks such as “send updated contribution forms” or “book insurance review,” but it cannot send instructions automatically or close tasks on its own.

If advice discussion took place, the Advice Document Agent prepares a draft file note or ROA section using the transcript and approved firm template. Any factual gaps are marked for review. The adviser verifies the draft. Compliance completes its review where required. Only then can a human approve the document for the next stage.

Every access event, generated draft, exception, and approval is retained in the activity log.

That is an agent doing real work. It also remains a controlled part of your business process.

If you want to identify which workflows are suitable for this level of control, Book a call with Sam. We will focus on the work creating delay today, the data involved, and the controls needed before you automate it.

Start narrow before connecting core systems

The temptation is to connect an agent to every system because the potential time savings look compelling. Resist that.

Start with one workflow where the inputs are reasonably structured, the output is clear, and a human already reviews the work. Meeting preparation is often a good first use case. Draft file notes can also work well when the firm has stable templates and an existing review process.

Avoid starting with workflows that give an agent authority to transfer funds, alter investment instructions, issue final advice documents, or make suitability decisions. Those may become possible to support with agent-assisted processes later, but they are not where you prove the model.

For each pilot, define four things before development starts:

  • The exact job the agent performs
  • The systems and records it can access
  • The actions it is blocked from taking
  • The human owner who reviews exceptions and approvals

Then measure the outcome. Look at preparation time per meeting, document turnaround time, number of revisions, onboarding completion rate, and time spent chasing missing information. You are looking for capacity released without a decline in file quality or control.

You can find more practical operating ideas in the Enterprise DNA insights library, including how firms use AI around service delivery rather than as an isolated experiment. For workflows that cross phone calls, notes, and follow-up tasks, Omni Voice can also form part of the controlled workflow.

The dollar case is about released capacity and avoided rework

The $70K to $200K annual leakage band is not usually sitting in one line item. It is spread across an adviser doing after-hours preparation, paraplanners chasing inputs, client service staff rekeying information, and compliance reviewers receiving incomplete drafts.

A firm with six advisers can quickly accumulate hundreds of hours each quarter in meeting preparation and notes alone. Add slow advice-document cycles and onboarding that drifts past a month, and the economic cost becomes obvious.

You do not need to claim every saved hour as direct profit. Some of it will become better service, faster turnaround, and less pressure on good people. That still matters. It can allow advisers to handle more client conversations, help the firm grow without adding support headcount at the same rate, and reduce the error-prone work that creates remediation later.

The strongest business case is not “AI will replace the team.” It is “the team will stop spending its best hours on work that can be prepared, checked, and routed with controls.”

Make controls part of the design

The firms that get value from agents will not be the ones that move fastest with no guardrails. They will be the ones that choose the right use case, define the human role, and make the control model visible from the start.

Role-based access. Time-limited permissions. Approval gates. Activity logs. Monitoring. Clear exception owners.

Those are not obstacles to adoption. They are what let you use AI in the workflows that actually matter.

The first practical step is a 60-minute Omni Audit. You will leave with three outputs, a map of the manual work creating the most drag, a short list of agent opportunities, and a view of the controls required to put the best option into production. There is no slide deck and no generic AI roadmap.

You can review the AI audit for financial advisory firms first, then Book a call with Sam when you are ready to work through the numbers and the workflow.