For SEC-registered RIAs using AI · 5-day fixed scope

RIA AI Practice Audit — The SEC Exam Question Your AI Adoption Isn't Answering

SEC's 2026 exam priorities explicitly name AI governance, vendor oversight, and supervision procedures. Sophisticated clients are asking about AI use in outside-consultant guidelines. E&O carriers are adding AI addenda to renewals. Your tools don't answer these questions. This audit does.

$2,500 USD · boutique RIA tier · 5 days
Start the audit What's included

Independent by design

Every AI vendor your firm uses has a story about their SEC-friendly posture. Some are good. Most are marketing. A firm relying on the vendor's own account is in the same trap as a CCO relying on a self-graded model — the vendor cannot, structurally, produce the third-party attestation your SEC examiner, E&O carrier, or sophisticated client wants. Same reason firms hire outside counsel for supervision-procedure review: independence is the value.

What you get

Six deliverables. Five business days from data handoff.

The audit

  • AI-use inventory — every AI tool the firm uses (Jump, Zocks, FP Alpha, Holistiplan, Wealthbox AI, Practifi, MoneyGuide Pro AI, etc.), mapped to every advisor and function
  • Reproducibility posture per tool — model versioning, output-of-record, cache determinism, audit trail availability
  • SEC 206(4)-7 written-policy compliance map — where the firm's AI use satisfies or gaps supervision, custody, marketing, testimonial, and advertising rules
  • Client-facing defensibility statement — drop-in language for Form ADV 2A addenda + outside-consultant guideline responses + client engagement letters
  • E&O carrier answer sheet — drop-in for annual renewal AI-use questionnaires
  • 30 / 60 / 90-day roadmap — specific closes for identified gaps, ranked by SEC-exam exposure

You provide

  • List of AI tools the firm currently uses (best guess is fine; we'll surface gaps)
  • Advisor + function map (planning / portfolio / comms / meeting notes / tax / retirement)
  • Any active SEC exam letter, E&O carrier question, or sophisticated-client outside-consultant AI-use question that triggered the engagement (if any)
  • 30-minute kickoff call w/ CCO OR managing partner OR CTO

The three surfaces where RIA AI-use goes wrong

Cross-tool drift
Most RIAs use 3-6 AI tools (Jump, Zocks, FP Alpha, Holistiplan, Wealthbox AI, plus a proprietary CRM extension). Each has its own versioning, log format, audit trail (usually poor), and retention posture. When SEC examines "the AI record" for a specific client interaction, the record is fragmented across vendors that don't coordinate.
Silent version drift across client interactions
Zocks meeting notes in March run on one underlying model. Same client, same advisor, September meeting = different model, different failure modes. Two meeting notes side-by-side in an SEC exam show different-shape AI reasoning that the firm can't easily reconstruct.
Confident-but-wrong that survives advisor review
Not the obvious hallucination. The subtle client-goal misinterpretation in a planning summary. The advisor-summary that reads confident but drops the most important tax-year deadline. Advisor reviewing 40 AI-drafted comms at end of day doesn't spot the pattern in note #23. SEC finds it in retrospect during an exam.

Pricing tiers

Fixed-scope, fixed-price. No hourly billing.

Small RIA (2-15 advisors)
$500-$2,500
Focused audit · 2-5 days · core deliverables
Platform / PE-backed roll-up
$15K-$25K
Multi-firm + platform-level audit · 2-4 weeks · per-firm brief

Start the audit

Mid RIA tier ($7,500) or boutique ($2,500) - depending on advisor count. If your firm has an active SEC exam letter, upcoming E&O renewal w/ AI addenda, or a sophisticated-client AI-use question in flight, say so on the kickoff call — I'll compress the timeline if possible.

Buy the audit — $2,500

Prefer a 15-minute qualification call first? Email luddy.kevin@gmail.com.

Why me

Kevin Luddy. 35 years shipping production software. 24-year CTO at Oculearn. Not a fiduciary or CCO — a technologist auditing the AI your compliance program depends on.

The audit surface is technical (model versioning, output retention, log-of-record, cache determinism, tool traces) crossed w/ regulatory (SEC 206(4)-7 written policies, marketing / testimonial / advertising rules, custody rules, E&O carrier language, sophisticated-client outside-consultant guidelines). Neither pure compliance consultant nor pure engineer produces a defensible cross-disciplinary artifact. contrarianAI does — independent, technical, and calibrated to the specific questions your firm's examiner, carrier, and sophisticated clients will ask.