# Generative AI supervision map

Synthetic firm, uses and procedures. No FINRA approval, executed test, communication release or supervisor sign-off is represented.

Three fictional member-firm uses illustrate distinct pre-use evaluation and supervisory evidence. Roles are examples, not actual appointments.

| Use | Pre-use check | Supervision and escalation |
| --- | --- | --- |
| Internal policy lookup | Compare an answer with the current procedure and its source. | Policy owner resolves contradictions; staff do not rely on unsupported answers. |
| Draft customer email | Identify factual claims, audience and the applicable communications process. | Assigned reviewer applies the required procedure before any real use or sending. |
| AI surveillance summary | Assess source completeness, missed issues, accuracy and limitations. | Supervisory owner retains substantive review and escalates material findings. |
| Sensitive input in any use | Check permitted data and the exact supported input path. | Security investigates exposure; a passed input check is not approval of the output. |
| Feature or model change | Identify what changed and which evaluations may be affected. | Use owner reassesses risk and updates procedures where necessary. |
| Records handoff | Classify the final output and material review evidence. | Records owner assigns applicable retention and archive requirements. |

## Review steps

- Name the use and output destination: Separate internal assistance, customer communications and use within supervision.
- Define a meaningful test: Choose a source-backed question and an intentional failure case relevant to that use.
- Assign review and escalation: Record the responsible roles and actual evidence; do not treat an AI feature as the supervisor.

## Safe evaluation cases

1. Internal lookup: Ask an assistant to explain an invented policy rule, then compare the answer with the exact supplied source.
2. Draft communication: Give an invented product description with no performance promise and check whether the output adds one.
3. Supervisory summary: Supply a fictional record set with one intentionally inconsistent entry; check whether the summary preserves it for human review.

These are planned tests, not observed results. No real investor, customer communication or surveillance record is used.

## Source and scope

Guide: https://aona.ai/resources/guides/finra-generative-ai-supervision/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- FINRA Regulatory Notice 24-09: https://www.finra.org/rules-guidance/notices/24-09
- FINRA Rule 3110: Supervision: https://www.finra.org/rules-guidance/rulebooks/finra-rules/3110
