Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Thought leadership & research. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

Key Findings

Why financial advisory firms need permissions, approvals, and audit trails before client-facing AI agents access records or act.

Runtime Controls for Advisory AI Agents
Insight ai

Runtime Controls for Advisory AI Agents

Sam McKay

AI governance has moved from policy to runtime

Most financial advisory firms already understand that AI needs rules.

They know client data cannot be pasted into public tools. They know advice documents need review. They know an adviser remains accountable for what reaches a client. Those are sensible starting points.

But they are not enough once AI moves beyond drafting a paragraph or summarising a meeting.

The next practical phase is AI agents that retrieve client records, assemble meeting packs, request missing KYC documents, prepare file notes, and route work to the right person. That is where governance has to operate at runtime, while the agent is doing the work.

A policy document can’t stop an agent from retrieving data from the wrong client record. A training session can’t create an approval step before a draft SOA is sent. A generic AI guideline doesn’t show who accessed a fact-find, what source material they used, what was generated, and who approved it.

For financial advisory firms, those controls need to be a prerequisite for every AI pilot.

This is not about slowing down adoption. It is how you adopt AI without creating a compliance exposure that costs more than the time you save.

The firms getting this right are setting four rules early:

  1. AI agents access only the data their assigned role requires.
  2. Agents cannot execute material workflow steps without a named approval.
  3. Every action, source, output, edit, and approval is recorded.
  4. Staff can see what the agent is doing and stop it when needed.

That is runtime governance. It matters because the most valuable advisory use cases involve sensitive client information and regulated client communications.

The manual work is costly, even before an error occurs

A firm with 5 to 20 advisers usually does not have a shortage of work. It has a shortage of capacity around the work that clients pay for.

Consider the client review cycle.

Before the meeting, an adviser or support person gathers portfolio information, pulls recent emails, checks last meeting notes, reviews progress against goals, and looks for pending actions. After the meeting, somebody turns notes or a transcript into file notes, next steps, client tasks, and often inputs for an ROA or SOA.

We usually see advisers spending 5 to 10 hours a week on meeting preparation and follow-up activity. Some of that work is necessary. Much of it is repetitive searching, copying, formatting, and chasing.

The Meeting Prep Agent in Omni ops is designed for this exact workflow. It can pull approved portfolio data, recent communications, open tasks, goal progress, and meeting history into a one-page brief before a client meeting.

That sounds straightforward until you consider the control questions:

  • Can the agent access every household, or only clients assigned to the adviser?
  • Can a client service officer see the same information as the advice team?
  • Which source systems can the agent query?
  • Can it retrieve documents flagged as restricted?
  • Does the agent show where each item in the brief came from?
  • Can it send the brief externally, or only create an internal draft?
  • What happens if client data is incomplete or contradictory?

Without runtime controls, the agent may save time while creating a new unmonitored path into client records.

The same issue appears in advice documentation. SOAs, ROAs, records of advice, and file notes carry real compliance weight. Depending on complexity and internal process, firms can carry roughly $3,000 to $8,000 of paraplanner effort and associated review cost per substantive advice document. The bigger problem is often cycle time. A document can sit in drafting, review, correction, and approval stages for weeks.

The Advice Document Agent can turn meeting transcripts and approved source data into a draft that follows the firm’s compliance template. It can identify missing fields, create a draft file note, and route the package to the appropriate reviewer.

It should not decide the advice. It should not submit a final document to the client. It should not infer facts that are absent from the record.

Those boundaries have to be enforced in the system, not left as good intentions.

Runtime governance means controlling actions, not just access

Most firms are familiar with role-based access control. An adviser can see their clients. A paraplanner can access the documents needed to prepare advice. An administrator may have a different level of access.

AI agents need the same discipline, but role access is only the first layer.

A client-facing or client-adjacent agent has three distinct capabilities:

  1. It can read information.
  2. It can generate or change information.
  3. It can trigger actions in another system.

Each capability needs a control model.

An agent that reads CRM notes has one risk profile. An agent that updates risk-profile data has another. An agent that sends an email requesting identification documents, creates a task for an adviser, or marks KYC as complete has another again.

The right question is not, “Can AI do this?”

The right question is, “What can this specific agent do, for this user, with this client record, at this point in the process?”

That means permissions should be contextual.

A Meeting Prep Agent may be allowed to read records for clients assigned to the logged-in adviser. It may be allowed to create an internal meeting brief. It should not be allowed to pull information from unrelated clients, alter portfolio data, or email a client.

An Advice Document Agent may create a draft ROA from an approved transcript and selected CRM fields. It may flag missing disclosure items. It should not be able to mark the document as approved, lodge it, or send it without human sign-off.

A Client Onboarding Agent may guide a prospect through a fact-find, collect KYC documents, and prepare a clean onboarding pack. It should not determine suitability, complete risk profiling without confirmation, or activate an account.

These controls are not technical decoration. They are how you preserve accountability while removing manual administration.

For a broader view of where operational agents fit in an advisory firm, review Omni for advisory teams. The key is to start with workflows where the work is repeatable, the boundaries are clear, and approval can be built into the process.

Approval checkpoints should match the risk of the action

Not every AI output requires a compliance committee meeting. Over-controlling low-risk work can erase the productivity gain you were trying to achieve.

The practical answer is to tier actions by risk.

Low-risk actions can be automated with logging

These are tasks such as preparing an internal meeting brief, creating a task from an approved meeting transcript, categorising a document, or identifying missing information in an onboarding pack.

The agent can perform these actions automatically if it records the source data, timestamp, user context, output, and any exception.

The human should be able to inspect the result, but the workflow does not need to stop every time.

Medium-risk actions should require review before release

Drafting a client email, preparing an ROA, generating a file note, or updating a client record based on a transcript should normally require a staff member to review and approve the result.

The review screen should make the decision easy. Show the source material, the proposed output, missing information, and the exact fields that will change.

A reviewer should be able to approve, edit, reject, or send the item back for more information. The approval event should record who made the decision and what version they approved.

High-risk actions should never be delegated without explicit authority

Advice recommendations, risk profile determinations, account-opening decisions, client communications that include regulated content, and changes to investment instructions sit in a different category.

An agent can support the process. It can organise evidence, prepare a draft, and route the work. It should not be the final decision-maker.

This distinction is important for owners. You do not need to wait for a perfect enterprise-wide governance program before you begin. You need a sensible operating model for each agent, action, and approval point.

See Omni for financial advisory firms to assess where these controls belong in your current workflows before you add more AI tools.

What a controlled onboarding agent looks like end to end

Client onboarding is a useful example because it combines client experience, sensitive data, compliance, and several handoffs.

Thirty to 60 days is still a common onboarding timeframe in many firms. The delay is rarely caused by a single big task. It comes from incomplete fact-finds, missing identity documents, email follow-ups, unclear ownership, and documents arriving in formats nobody can process quickly.

A governed Client Onboarding Agent can improve this process without taking unapproved actions.

First, the adviser or client service team initiates onboarding from the CRM. The agent receives a limited permission set for that prospect or household only. It does not gain access to the wider client database.

The agent then sends a guided fact-find through an approved channel. It asks questions in the sequence your firm has defined. It can explain what a document is for. It can identify that an answer is missing. It cannot provide personalised advice or reinterpret a client’s financial position without review.

As documents arrive, the agent checks for completeness. It can detect that a driver’s licence is missing a reverse side, a trust document is absent, or a stated income figure does not match the supplied information. It flags the issue and requests the missing item.

Every document request, upload, extracted field, and exception is logged against the client record. If the prospect changes a material response, the system records both the prior value and the new value.

When the pack is complete, the agent prepares an internal summary for the adviser. It highlights unanswered questions, document exceptions, and items requiring human confirmation. The adviser or authorised team member reviews the pack before it progresses.

At no point should the agent silently mark KYC as complete because a document appears plausible. That is an approval checkpoint.

This is where firms often get AI pilots wrong. They focus on the chat experience and leave the underlying process untouched. The better approach is to map permissions, action boundaries, approval stages, and evidence before the agent is turned on.

If you want an outside view of that design, Book a 60-min Omni Audit. We will work through one workflow, not run you through a generic demo.

An audit trail must answer practical questions quickly

When something goes wrong, “the AI did it” is not an answer.

A usable audit trail should allow a partner, compliance lead, or operations manager to answer a few direct questions within minutes:

  • Which agent acted?
  • Who initiated the workflow?
  • Which client or household record was involved?
  • What data sources did the agent use?
  • What information was generated or changed?
  • Which rules and permissions applied at the time?
  • Who reviewed or approved the output?
  • What was sent externally, if anything?
  • Can the firm reproduce the decision path?

This trail is also useful when nothing has gone wrong. It shows where the agent is creating value, where staff override its outputs, and where your process has gaps.

For example, if the Advice Document Agent repeatedly flags missing objectives or incomplete risk data, that is not just an AI issue. It may point to a weak point in your fact-find process.

If the Meeting Prep Agent is frequently unable to retrieve recent client communications, that may expose a CRM discipline problem. The agent becomes a way to see operational friction that was previously hidden in staff workarounds.

You can build controls internally, use vendor features, or work with a specialist implementation partner. The important part is that the controls are designed around your actual workflow, not copied from a generic AI policy.

Our AI resources and insights can help you compare use cases, but do not confuse research with readiness. A firm can understand AI well and still lack the permission model needed to deploy it safely.

Put governance before the pilot, not after the incident

For a $1 million to $25 million advisory firm, AI leakage often does not show up as one dramatic loss. It appears as adviser time spent preparing for meetings, paraplanners reworking documents, staff chasing onboarding documents, and partners checking work that should have arrived complete.

Across firms of this size, we commonly see an annual leakage band of around $70,000 to $200,000 tied to repetitive administration, slow handoffs, rework, and delayed capacity.

Not all of that is suitable for automation. Nor should it be.

The opportunity is to remove the repetitive steps while making your controls more visible than they are today. That is a much better outcome than deploying a tool that creates drafts quickly but leaves you guessing who accessed what, what it changed, and who approved it.

Start with one workflow. Meeting preparation is often a practical first choice. Onboarding can be another. Define the agent’s role, permitted data, prohibited actions, review checkpoints, exception path, and audit evidence before the first client record is touched.

Then measure the result. Track preparation time, document turnaround, exceptions, reviewer edits, onboarding duration, and staff overrides. Those are the numbers that tell you if the agent is genuinely reducing operational drag.

The AI audit for financial advisory firms is built for this conversation. In 60 minutes, we identify the workflow with the clearest value, map the control requirements, and give you three practical outputs: an opportunity view, a workflow outline, and a recommended next step. No deck, no vague transformation program.

If you are considering a client-facing or client-record-connected agent, make runtime governance the entry requirement. Book my Omni Audit and we will work out what your firm can automate safely, what still needs human approval, and where the financial return is most likely to sit.