Compliance decisions
FINRA: oversee staff use of AI
FINRA’s technology-neutral rules continue to apply when member firms use generative AI, including third-party features. Evaluate the actual use before deployment and connect it to a reasonably designed supervisory system. Input protection, output review and business-record handling are separate responsibilities.
For Broker-dealer compliance supervisors, technology risk and security teams
A third-party AI feature does not remove the firm’s supervisory responsibilities.
Synthetic firm, uses and procedures. No FINRA approval, executed test, communication release or supervisor sign-off is represented.01
Define the use before selecting the controls
FINRA Regulatory Notice 24-09 explains that existing FINRA rules and securities laws continue to apply to generative AI. The applicable duties depend on how the member firm uses the technology. It is a reminder about existing obligations, not a new universal AI rule.
Describe the task, users, information and output destination. Internal policy lookup, a draft customer communication and a tool used in supervisory review have different consequences. Include AI embedded in an existing vendor product rather than limiting the inventory to tools purchased under an AI label.
Source context: FINRA Regulatory Notice 24-09
02
Evaluate the proposed use before deployment
The notice says firms should evaluate generative AI tools before deploying them and ensure continued compliance with rules applicable to the business use. Identify the test cases, source information and failure conditions that matter to that use, rather than relying on a generic demonstration.
For an internal policy assistant, check whether answers reflect the current procedure and identify their source. For a communication draft, assess unsupported factual claims and the required review process. Use public or synthetic information when evaluating controls; do not expose customer data simply to build a test set.
Source context: FINRA Regulatory Notice 24-09
03
Connect the task to the supervisory system
Rule 3110 requires a supervisory system reasonably designed for the firm’s business and written supervisory procedures addressing the applicable activities. Assign responsibility for the AI use, its permitted scope, exceptions and evidence. Purchasing a vendor feature does not appoint the supervisor or implement the firm’s procedures.
Where AI itself supports supervisory review, Notice 24-09 highlights technology governance considerations including model risk, data privacy and integrity, reliability and accuracy. An AI-generated surveillance summary should not silently replace the substantive review or escalation the firm’s system requires.
Source context: FINRA Regulatory Notice 24-09 · FINRA Rule 3110: Supervision
04
Apply communications rules to the actual output
The content standards of Rule 2210 apply whether a communication is generated by a person or a technology tool, as the notice explains. Classify the communication and follow the applicable review and approval requirements. Do not infer that every draft has the same mandatory pre-approval route.
Keep the final communication and material review evidence in the appropriate process. An input-control block addresses the data sent to a tool; it does not prove that an unblocked output is accurate, balanced or suitable for its intended audience.
Source context: FINRA Regulatory Notice 24-09
05
Make exceptions and changes reviewable
Define what staff do when an output lacks a source, includes an unsupported claim or requires data outside the approved task. Record the exception, the responsible reviewer and the action taken. Reassess when the model, feature, source data or business use changes.
The fictional worksheet below assigns role-level responsibilities and expected checks. It does not claim that a supervisor has performed them. Hand record classification and retention to the relevant records process rather than treating every conversation as an automatically compliant archive.
Source context: FINRA Regulatory Notice 24-09 · FINRA Rule 3110: Supervision
Put it into practice
Generative AI supervision map
Three fictional member-firm uses illustrate distinct pre-use evaluation and supervisory evidence. Roles are examples, not actual appointments.
Synthetic firm, uses and procedures. No FINRA approval, executed test, communication release or supervisor sign-off is represented.
Define
Task, user, data and destination
Evaluate
Relevant correct and failure cases
Supervise
Named procedure and responsible role
Retain
Required record and review evidence
| Use | Pre-use check | Supervision and escalation |
|---|---|---|
| Internal policy lookup | Compare an answer with the current procedure and its source. | Policy owner resolves contradictions; staff do not rely on unsupported answers. |
| Draft customer email | Identify factual claims, audience and the applicable communications process. | Assigned reviewer applies the required procedure before any real use or sending. |
| AI surveillance summary | Assess source completeness, missed issues, accuracy and limitations. | Supervisory owner retains substantive review and escalates material findings. |
| Sensitive input in any use | Check permitted data and the exact supported input path. | Security investigates exposure; a passed input check is not approval of the output. |
| Feature or model change | Identify what changed and which evaluations may be affected. | Use owner reassesses risk and updates procedures where necessary. |
| Records handoff | Classify the final output and material review evidence. | Records owner assigns applicable retention and archive requirements. |
Work through your review
Use the checks to organise the evidence you need. Your selections stay in this tab.
0 of 3 reviewed
Example files for this task
Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.
finra-ai-supervision-map.mdInspect
# Generative AI supervision map
Synthetic firm, uses and procedures. No FINRA approval, executed test, communication release or supervisor sign-off is represented.
Three fictional member-firm uses illustrate distinct pre-use evaluation and supervisory evidence. Roles are examples, not actual appointments.
| Use | Pre-use check | Supervision and escalation |
| --- | --- | --- |
| Internal policy lookup | Compare an answer with the current procedure and its source. | Policy owner resolves contradictions; staff do not rely on unsupported answers. |
| Draft customer email | Identify factual claims, audience and the applicable communications process. | Assigned reviewer applies the required procedure before any real use or sending. |
| AI surveillance summary | Assess source completeness, missed issues, accuracy and limitations. | Supervisory owner retains substantive review and escalates material findings. |
| Sensitive input in any use | Check permitted data and the exact supported input path. | Security investigates exposure; a passed input check is not approval of the output. |
| Feature or model change | Identify what changed and which evaluations may be affected. | Use owner reassesses risk and updates procedures where necessary. |
| Records handoff | Classify the final output and material review evidence. | Records owner assigns applicable retention and archive requirements. |
## Review steps
- Name the use and output destination: Separate internal assistance, customer communications and use within supervision.
- Define a meaningful test: Choose a source-backed question and an intentional failure case relevant to that use.
- Assign review and escalation: Record the responsible roles and actual evidence; do not treat an AI feature as the supervisor.
## Safe evaluation cases
1. Internal lookup: Ask an assistant to explain an invented policy rule, then compare the answer with the exact supplied source.
2. Draft communication: Give an invented product description with no performance promise and check whether the output adds one.
3. Supervisory summary: Supply a fictional record set with one intentionally inconsistent entry; check whether the summary preserves it for human review.
These are planned tests, not observed results. No real investor, customer communication or surveillance record is used.
## Source and scope
Guide: https://aona.ai/resources/guides/finra-generative-ai-supervision/
Source check: 21 September 2026. General information, not professional approval or a completed control test.
- FINRA Regulatory Notice 24-09: https://www.finra.org/rules-guidance/notices/24-09
- FINRA Rule 3110: Supervision: https://www.finra.org/rules-guidance/rulebooks/finra-rules/3110
Download finra-ai-supervision-map.mdfinra-ai-supervision-map.csvInspect
Use,Pre-use check,Supervision and escalation
Internal policy lookup,Compare an answer with the current procedure and its source.,Policy owner resolves contradictions; staff do not rely on unsupported answers.
Draft customer email,"Identify factual claims, audience and the applicable communications process.",Assigned reviewer applies the required procedure before any real use or sending.
AI surveillance summary,"Assess source completeness, missed issues, accuracy and limitations.",Supervisory owner retains substantive review and escalates material findings.
Sensitive input in any use,Check permitted data and the exact supported input path.,Security investigates exposure; a passed input check is not approval of the output.
Feature or model change,Identify what changed and which evaluations may be affected.,Use owner reassesses risk and updates procedures where necessary.
Records handoff,Classify the final output and material review evidence.,Records owner assigns applicable retention and archive requirements.
Download finra-ai-supervision-map.csvBefore you proceed
Keep these distinctions clear
- Embedded AI is still a business use
- A feature inside an existing product still needs assessment for its actual use.
- Input protection is not output approval
- Communications and substantive supervisory checks remain separate.
Apply it to employee AI use
Bring your actual data path.
Aona can support visibility and sensitive-input policy evaluation on supported employee AI paths.
It does not approve FINRA communications, act as the firm’s supervisor or validate the accuracy of AI outputs.
Use one invented communication scenario to assess the selected data-input boundary and available event evidence.
Review your use caseFAQ
Questions for this decision
Did Notice 24-09 create a separate AI rulebook?
Does third-party or embedded AI avoid the review?
Must every AI draft follow the same approval process?
Can an AI summary replace supervisory judgment?
Evidence behind the guide
Sources and scope
Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.
- FINRA Regulatory Notice 24-09
Technology-neutral duties, pre-deployment evaluation, supervision and communications standards for generative AI use.
regulator · checked 2026-09-21 - FINRA Rule 3110: Supervision
Reasonably designed supervisory systems, written procedures and assigned supervisory responsibilities.
standard · checked 2026-09-21