Enterprise DNA
Key Findings

How financial advisory firms can govern AI agents at runtime with approval gates, access limits, activity logs, and monitoring.

Runtime Controls for Financial Advice AI
Insight ai

Runtime Controls for Financial Advice AI

Sam McKay

AI governance doesn’t stop at launch

Many financial advisory firms treat AI governance as a launch checklist.

They review the vendor. They ask where client data is stored. They get a compliance sign-off. Then they turn the agent on and assume the governance work is done.

That approach doesn’t match how AI agents actually work.

An AI agent isn’t static software sitting quietly in the background. It receives new client information, accesses changing systems, interprets instructions, calls tools, produces outputs, and can trigger actions. The risks appear during operation, not only before deployment.

For a financial advisory or wealth management firm, that changes the question.

The question isn’t, “Did we approve this AI tool?”

It’s, “What can this agent do right now, with this client record, under these conditions, and who can see what it did?”

That is runtime governance. Regulated businesses are moving there early because they have to. The same controls that protect a client file, advice record, or portfolio instruction need to apply while an AI agent is working.

For firms doing between USD 1 million and USD 25 million in annual revenue, this isn’t enterprise bureaucracy. It’s a practical way to get value from automation without creating a new compliance headache.

The firms that get this right will move faster on meeting preparation, advice documentation, and onboarding. They won’t ask advisers to choose between efficiency and control.

The manual work is expensive before it becomes visible

Most advisory firms don’t have a single broken process. They have dozens of small manual steps that consume adviser, paraplanner, and client service capacity every week.

Meeting preparation is a good example.

Before a client review, an adviser or associate may open the CRM, portfolio platform, financial planning software, email history, prior meeting notes, task lists, and market commentary. They pull together the relevant story for the client.

What changed in their portfolio? What goals are on track? What documents are outstanding? What did they ask for in the last meeting? Is there a risk-profile review due?

Then, after the meeting, someone writes file notes, creates follow-up tasks, sends a summary, and begins the advice-document workflow if the discussion led to a recommendation.

We usually see advisers spending five to 10 hours a week across meeting preparation, follow-up, and note creation. Some firms hide that cost because it sits inside salaried time. It is still capacity that cannot be spent in client conversations, business development, or higher-value advice work.

Advice documentation creates an even more visible bottleneck. SOAs, ROAs, file notes, disclosures, and compliance checks often pass between an adviser, paraplanner, and reviewer. A document can take weeks to reach a point where it is ready for the client. Industry ranges for paraplanner cost per advice document commonly sit around USD 3,000 to USD 8,000 once rework and review time are included.

Onboarding brings the same issue to the front of the client relationship. Prospective clients are asked for identity documents, statements, goals, risk information, entity details, and consent forms. The firm follows up repeatedly. A client who was ready to move forward starts losing momentum.

A 30-to-60-day onboarding cycle is normal in many firms. It doesn’t have to be.

Across these workflows, a typical advisory firm can have USD 70,000 to USD 200,000 in annual leakage through manual handling, delays, rework, and underused adviser capacity. That figure isn’t one bill or one headcount. It is the accumulation of work that nobody designed as a system.

See Omni for financial advisory firms to see where that leakage typically sits and which workflows are realistic places to start.

What an agent should do, and what it should never do alone

The right AI agent is not a generic chatbot with access to every folder in the business.

It has a defined job, a limited data scope, clear operating rules, and a handoff point to a person. Think of it as a digital team member with narrow authority, not an extra adviser.

Take the Meeting Prep Agent in Omni ops.

Before a scheduled review, the agent can pull portfolio data, recent communications, prior action items, goal progress, and outstanding documents into a one-page brief. It can flag that a client has not completed an updated risk profile, that their cash allocation has moved outside an agreed range, or that a beneficiary nomination is due for review.

The adviser gets a concise briefing pack before the meeting. They still decide what matters, how to discuss it, and whether any advice is required.

The agent should not independently send a portfolio recommendation, make an investment decision, or present an unreviewed interpretation of client circumstances as advice.

Now consider the Advice Document Agent in Omni ops. It can take a meeting transcript, approved templates, relevant client facts, and the adviser’s structured instructions to draft an SOA, ROA, or file note. It can identify missing fields, insert standard disclosures, and prepare a reviewer checklist.

That can remove hours of formatting, copy-pasting, and first-draft work. Yet the final document still needs a qualified review and approval process. The agent should not be allowed to finalize advice documents, alter approved language without a review flag, or send a document to a client automatically.

The Client Onboarding Agent follows the same pattern. It guides a prospective client through fact-finding, requests KYC documents, checks for incomplete submissions, and assembles a clean onboarding pack. It can chase missing documents with approved reminders. It should not override a failed identity check, decide that a risk profile is suitable, or create an account instruction without an authorised person approving it.

This is the operating model we build around with Omni ops. Agents do the repeatable work. People retain judgment, authority, and accountability.

Runtime controls are the guardrails during the work

A pre-launch risk review is useful, but it can’t tell you how an agent will behave after 400 meetings, 200 document drafts, and dozens of unusual client requests.

Runtime controls govern the agent while it works.

For an advisory firm, the core controls are straightforward.

Approval gates for material actions

Start by listing actions that must never happen without human approval.

That list usually includes sending advice documents to clients, updating a risk profile, submitting account-opening paperwork, changing client records, issuing recommendations, transferring data outside approved systems, and publishing communications under an adviser’s name.

An agent can prepare these actions. It can queue them. It can explain what inputs it used. It should stop at the approval gate.

Approval gates need to match the risk. A draft internal meeting summary may only require adviser review before it enters the CRM. An ROA draft might require both adviser and compliance review. A KYC exception should go directly to the right human queue.

Don’t make every task require three approvals. That recreates the manual process you are trying to improve. Apply friction where it protects a client, the firm, or a regulatory obligation.

Access limits based on job and client relationship

An agent needs access to do its work, not access to everything.

The Meeting Prep Agent may need read access to a client’s CRM record, portfolio data, prior meeting notes, and approved communications. It does not need access to payroll files, other advisers’ client books, or unrestricted shared drives.

The Advice Document Agent may access the source meeting transcript, the current client record, approved templates, and the relevant advice workflow. It should not retrieve unrelated client records because a prompt happened to mention another name.

Use role-based access at a minimum. Better still, use client and workflow context. The agent should only access information connected to the specific task, adviser, and client relationship it has been assigned.

That protects client confidentiality and makes the agent easier to audit. It also limits the damage if a user gives a poor instruction or an outside email tries to manipulate the workflow.

Activity logs that can answer real questions

When compliance asks, “How did this document get created?” the answer can’t be, “The AI did it.”

You need an activity record that shows:

  • Who initiated the task
  • Which client and workflow were involved
  • What systems and documents the agent accessed
  • What instructions it received
  • Which model or workflow version was used
  • What output it produced
  • What it tried to do next
  • Who reviewed, changed, approved, or rejected the output

This doesn’t mean storing every stray thought an AI model may generate. It means retaining enough evidence to reconstruct the business process.

For a drafted ROA, the record should show the meeting transcript used, the approved template version, the data sources retrieved, the draft generated, the review comments, and the final approver. For onboarding, it should show document requests, submissions, failed checks, escalations, and the staff member who cleared exceptions.

A strong log is not only for a regulator. It helps you fix process issues quickly. If advisers keep rewriting the same section of an advice draft, the issue may be the template, the workflow rules, or the input quality.

Ongoing monitoring, not a quarterly surprise

Monitoring is where governance becomes operational.

Set alerts for unusual agent behaviour. Examples include a sudden jump in document retrievals, repeated failed KYC checks, attempts to access records outside a user’s client book, unusually high volumes of outbound reminders, or an advice-drafting workflow that is producing too many missing-data flags.

You should also review output quality over time. If a Meeting Prep Agent starts including stale portfolio data or a document agent begins missing mandatory wording after a template update, you want to catch it in days, not at the next annual compliance review.

A practical review rhythm for many firms is weekly operational checks for workflow exceptions, monthly quality sampling, and a formal quarterly review of access permissions, policy changes, and agent performance.

This isn’t about watching every action manually. It is about having enough visibility to spot a drift before it becomes a client issue.

For a broader view of how this approach connects across your business systems, review the Omni platform. The controls should follow the work, even when that work moves between CRM, portfolio, document, and communications systems.

A controlled workflow from meeting to advice document

Here is what an end-to-end workflow can look like in a properly controlled setup.

A client review is scheduled for Thursday morning. On Wednesday afternoon, the Meeting Prep Agent receives a task from the calendar workflow. It confirms the adviser-client relationship, then retrieves only the relevant client data from approved systems.

It creates a one-page brief. The brief includes goal progress, portfolio movements, prior meeting actions, recent client messages, and a list of missing documents. It flags source links so the adviser can verify any point quickly.

The agent records the data sources used and saves the brief to the client workflow. It doesn’t email the client or make a recommendation.

After the meeting, the approved meeting recording or transcript enters the workflow. The adviser checks the transcript for accuracy, then selects the required output. Perhaps it is a file note, perhaps a follow-up email draft, perhaps an ROA.

The Advice Document Agent creates the first draft using the approved template and the client’s relevant data. If key facts are missing, it does not guess. It flags the missing information and routes it back to the adviser or paraplanner.

Once a draft is ready, the workflow sends it to the right reviewer. The reviewer can see what source material was used, what fields were generated by the agent, and where the agent has raised uncertainty. Changes and approvals are logged. Only after the required approval is complete can the document move to client delivery.

That is not a slower process. In most cases it is faster because the people involved spend their time on judgment and exceptions, not assembly work.

The key is that the workflow controls are designed before the agent gets broad access.

If you want to map this against your own client-service process, Book a call with Sam. We will identify the workflow, the control points, and the capacity opportunity without turning the session into a software demo.

Don’t let vendor settings become your governance model

Many AI vendors offer useful security settings. They may support user permissions, data retention choices, and admin controls.

Use them. But don’t confuse vendor controls with your firm’s operating policy.

Your firm still needs to decide:

  • Which workflows are approved for agent use
  • Which data classes an agent can access
  • What counts as advice, an operational draft, or client communication
  • Which actions require approval
  • Who owns workflow exceptions
  • How long activity records are retained
  • What happens when a template, regulation, or internal policy changes
  • Who can alter the agent’s instructions and integrations

This is where business owners need to be involved. Compliance can set requirements. Operations can own the workflow. Technology can implement controls. But only leadership can decide where the firm wants to apply automation and where it won’t.

A sensible first step is to choose one contained workflow, not attempt firm-wide autonomy. Meeting preparation is often a strong starting point because the value is clear and the approval boundary is simple. Onboarding document collection can be another good candidate when the process is consistent.

Advice-document drafting can deliver major value, but it deserves tighter controls from day one because of its direct compliance impact.

You can find practical operating ideas in our AI insights library and broader implementation material in the Enterprise DNA learning resources. The important part is applying the thinking to the way your firm actually works.

What an Omni Audit gives your firm

An Omni Audit is a 60-minute working session for owners, partners, and operational leaders who want a clear view of where AI agents can help without opening a control gap.

We don’t arrive with a generic transformation deck. We work through your current workflow, the people involved, systems touched, delay points, and compliance boundaries.

You leave with three outputs:

  1. A ranked view of the workflow leakage and likely capacity opportunity
  2. A practical agent design, including where human approval gates belong
  3. A runtime control plan covering access, activity logs, monitoring, and ownership

For an advisory firm, this is the bridge between interest in AI and a deployment you can stand behind. It helps you identify where the USD 70,000 to USD 200,000 annual leakage is coming from, while making sure the remedy does not create a new risk exposure.

The AI audit for financial advisory firms explains the specific workflows we assess across meeting preparation, advice documentation, and client onboarding.

AI agents will become part of the operating model for advisory firms. The firms that benefit most won’t be the ones that give an agent the broadest access. They will be the ones that define authority, retain evidence, monitor performance, and improve the workflow as they learn.

Book a call with Sam if you want to identify the first controlled workflow your firm can put into production.