The Next AI Governance Challenge for Investment Firms: What Happens After Approval?

Artificial intelligence is rapidly becoming part of the modern investment firm’s operating model.

Compliance teams are exploring AI to summarize regulatory updates, assist with marketing reviews, draft policies and procedures, organize due diligence, research regulatory guidance, and improve operational efficiency. Investment professionals are also using AI to accelerate research and synthesize information, while operations teams are finding new ways to automate repetitive work and streamline processes.

The opportunities are significant, but so are the governance challenges.

Many firms have focused their AI governance efforts on one critical milestone: approval.

Typically, a firm identifies a new AI tool, and compliance reviews the use case. Information security evaluates the vendor, while legal considers contractual terms. The appropriate teams assess risk, complete documentation, and ultimately approve the tool for use.

Then the process stops.

The assumption is understandable. If the firm evaluated the risks before implementation, the most important governance work may appear to be complete.

In reality, approval is only the beginning.

Unlike traditional software, AI systems can change quickly. Vendors update models and introduce new capabilities. At the same time, employees discover new use cases, business processes evolve, and regulatory expectations continue to develop.

As a result, the governance decision made on day one may no longer reflect how an AI tool is being used six or twelve months later.

For investment compliance professionals, that distinction matters.

Investment firms already operate within a culture of ongoing supervision, documentation, testing, recordkeeping, vendor oversight, and regulatory accountability. As AI becomes more deeply integrated into the firm’s operations, those same governance disciplines become increasingly important.

The next AI governance challenge isn’t simply deciding whether a tool should be approved.

It’s determining what happens after approval.

Why AI Is Different From Traditional Technology

Investment firms already have established processes for evaluating software, vendors, cybersecurity risk, and operational risk.

However, AI introduces a new variable: rapid and sometimes material change.

A generative AI platform approved today may operate differently months from now. For example, a vendor may introduce a more powerful model, new integrations, agentic capabilities, or functionality that allows the system to interact with additional data and applications.

Meanwhile, the firm’s own use can change just as quickly.

A tool initially approved to summarize internal meeting notes might eventually help teams research regulatory developments, review marketing materials, analyze due diligence materials, or draft client-facing content.

The platform may be the same, but the risk profile may not be.

This is one reason the NIST AI Risk Management Framework (AI RMF) takes a lifecycle approach to AI risk management. NIST’s framework organizes AI risk management around four functions: Govern, Map, Measure, and Manage. Its guidance specifically describes risk management as continuous and performed throughout the AI system lifecycle.

For compliance teams, that concept should feel familiar.

Compliance programs aren’t designed around a single moment of approval. Firms test policies, reassess vendors, monitor regulatory changes, review controls, and document exceptions.

AI governance should follow the same philosophy.

The Risks That Appear After Approval

Some of the most meaningful AI governance risks may not be visible when a tool first enters the organization.

Instead, they emerge through use.

Governance Drift

Consider an AI application originally approved for a narrow, low-risk use case.

Employees begin using it successfully, and adoption grows.

Over time, the compliance team may use it to summarize regulatory releases, while marketing begins using it to draft content. An investment team might experiment with the same tool for research. Eventually, another employee may upload a document containing information that wasn’t contemplated during the original review.

Individually, none of these decisions may feel significant.

Collectively, however, the organization may have moved well beyond the boundaries of the original approval.

This is the practical problem of governance drift: the documented state of AI governance begins to diverge from the actual state of AI use.

For investment compliance teams, that creates a familiar problem. A control may exist on paper, but does it still reflect what is happening in practice?

Lifecycle governance helps close that gap.

Vendor and Model Evolution

The tool itself can also change.

AI vendors are innovating at an extraordinary pace, upgrading models, introducing features, and expanding integrations. In addition, some platforms are moving beyond generating information toward AI agents capable of taking actions or completing multi-step workflows.

Those developments may introduce risks that weren’t part of the original vendor review.

Therefore, the firm’s governance process needs a way to distinguish routine product updates from changes that warrant reassessment.

That doesn’t mean compliance needs to review every software release. Instead, firms should define material-change triggers.

For example:

  • Has the underlying AI model materially changed?
  • Can the system now access new categories of firm data?
  • Has a new integration been enabled?
  • Can the AI take actions it couldn’t take previously?
  • Has the vendor materially changed how customer data is stored, retained, or used?
  • Has the firm’s approved use case expanded?

A “yes” to one of these questions may be a reason to revisit the original assessment.

Existing Regulatory Obligations Still Matter

One of the most important principles for investment compliance professionals is also one of the simplest:

AI may be new, but many of the underlying compliance responsibilities are not.

For FINRA member firms, FINRA Regulatory Notice 24-09 explicitly reminds firms that its rules and the securities laws generally continue to apply when firms use generative AI, just as they do when firms use other technologies. FINRA’s 2026 regulatory oversight guidance also highlights potential implications for supervision, communications, recordkeeping, and fair dealing when firms use GenAI.

That distinction matters.

Investment firms shouldn’t necessarily think about AI governance as an entirely separate compliance universe. Instead, compliance teams can begin by asking how AI intersects with the obligations and controls they already manage.

If AI assists with communications, for example, what review and recordkeeping requirements apply?

If AI becomes part of a supervisory process, how does the firm assess the system’s reliability and accuracy?

Similarly, if an employee enters sensitive information into a third-party AI platform, what privacy, cybersecurity, confidentiality, or vendor-management considerations are implicated?

Finally, if AI contributes to a regulated workflow, what evidence should the firm retain about its use and oversight?

These questions move AI governance away from the abstract and into the everyday responsibilities of investment compliance.

Continuous Governance Doesn’t Mean Constant Review

The phrase “continuous AI governance” can sound burdensome.

For compliance teams already managing substantial regulatory workloads, the last thing anyone needs is another process requiring constant manual review.

However, lifecycle governance shouldn’t mean continuously reapproving every AI tool.

Instead, it should mean creating a system capable of identifying meaningful changes.

A practical approach might combine scheduled reviews with event-based triggers.

For instance, a lower-risk internal productivity tool may require a lighter review cadence. By contrast, an AI application involved in communications, investment processes, supervisory activities, or sensitive data may warrant more frequent oversight.

Between scheduled reviews, material events can trigger reassessment.

Those events might include:

  • Major model changes
  • New functionality
  • Expanded use cases
  • New integrations
  • Changes in data access
  • Security incidents
  • Material vendor-policy changes
  • New regulatory guidance
  • Identified performance or accuracy concerns

Ultimately, the goal isn’t more governance for the sake of governance.

It’s governance that remains aligned with reality.

What an AI Governance Lifecycle Can Look Like

A mature AI governance lifecycle doesn’t need to replace the firm’s existing compliance infrastructure.

In many cases, firms can build on processes they already use for vendor management, policies and procedures, risk assessments, supervisory controls, and testing.

The lifecycle might include several stages.

1. Inventory

Start by knowing what AI the firm actually uses.

An AI inventory can capture the application, vendor, business owner, approved use cases, relevant data, risk classification, approval date, and current status.

In turn, the inventory becomes the foundation for ongoing oversight.

2. Risk Assessment

Not every AI use case carries the same level of risk.

For example, using generative AI to brainstorm internal meeting topics is fundamentally different from incorporating AI into a process involving client communications, investment recommendations, surveillance, or regulatory reporting.

A risk-based governance model allows compliance teams to concentrate resources where the consequences are greatest.

3. Approval and Controls

Before deployment, firms can document what the system may do, what remains outside its approved scope, who owns it, and which controls apply.

This documentation creates a baseline against which teams can evaluate future changes.

4. Ongoing Monitoring

After approval, firms can monitor for material changes in the tool, vendor, use case, regulatory environment, and associated risks.

The NIST AI RMF Playbook provides voluntary suggested actions organizations can consider when operationalizing governance across the Govern, Map, Measure, and Manage functions. Importantly, NIST describes the Playbook as adaptable rather than a one-size-fits-all checklist.

5. Reassessment

Material changes should lead to proportionate reassessment.

In some cases, the firm may simply confirm that existing controls remain appropriate.

In others, compliance teams may need to update the approved use case, introduce additional controls, provide new employee guidance, or reconsider whether the technology remains appropriate for its intended purpose.

6. Retirement

Lifecycle governance also needs an endpoint.

When a firm no longer needs or approves a tool, teams should consider what happens to access, integrations, stored information, documentation, and historical records.

In other words, governance shouldn’t disappear simply because the firm canceled the subscription.

Documentation Becomes the Through Line

For investment compliance professionals, perhaps the most important element of lifecycle governance is documentation.

Consider a future regulatory examination or internal audit.

An examiner asks about the firm’s use of artificial intelligence.

Could the firm readily explain:

  • Which AI systems are currently in use?
  • What are their approved business purposes?
  • Who owns each system?
  • When did the firm approve each tool?
  • What risks did the firm identify?
  • Which controls did the firm implement?
  • Has the tool or model materially changed since approval?
  • Has its use expanded?
  • When did the firm last reassess it?
  • Did the firm identify any exceptions or incidents?
  • What actions did the firm take in response?

A firm that can answer those questions from a centralized governance record is in a very different position from one that needs to reconstruct the story across email threads, spreadsheets, vendor documentation, and individual employee recollections.

This is where AI governance becomes less about having a policy and more about maintaining evidence of governance.

Building Governance That Can Evolve

Investment firms don’t need to invent AI governance from scratch.

Several established frameworks can provide useful reference points.

ISO/IEC 42001, the international standard for AI management systems, is built around establishing, implementing, maintaining, and continually improving an AI management system. ISO describes the standard as a structured approach to managing AI risks and opportunities, including traceability, transparency, and reliability.

Similarly, NIST emphasizes continuous risk management across the AI lifecycle.

These frameworks aren’t substitutes for securities laws, SEC rules, FINRA requirements, or a firm’s own legal and compliance analysis. However, they can provide useful structure as investment firms determine how to operationalize AI oversight.

For compliance leaders, the opportunity is to connect these emerging AI governance practices to familiar disciplines:

Inventory. Ownership. Risk assessment. Policies. Controls. Monitoring. Testing. Documentation. Escalation. Reassessment.

The technology is new.

The fundamentals of good governance are not.

Preparing for the Question: “Show Me How You Govern AI”

Investment compliance teams have spent years preparing for questions about cybersecurity, electronic communications, vendor oversight, books and records, marketing, conflicts, and supervisory processes.

Increasingly, AI is becoming another layer across many of those same areas.

That makes a future question increasingly plausible:

“Show me how your firm governs AI.”

A policy alone may not provide a complete answer.

A stronger response includes an operational record showing what the firm uses, why it approved each tool, which controls apply, who owns it, how it has changed, and how the firm continues to evaluate its risks.

This is ultimately the value of lifecycle governance.

It turns AI oversight from a point-in-time decision into a defensible, repeatable compliance process.

Approval Is the Starting Point

AI adoption within investment firms is unlikely to slow.

The tools will become more capable, while use cases will become more sophisticated. Employees will continue finding new ways to incorporate AI into everyday work. Meanwhile, regulators will continue evaluating how existing requirements apply to emerging technologies.

Therefore, the governance model has to evolve too.

Approving an AI tool matters. So does documenting the initial risk assessment and creating an AI policy.

However, none of those activities, individually, answers the larger question of what happens next.

Investment firms need a way to maintain visibility as AI changes after approval. In particular, they need to know when use cases expand, when risks change, when reassessment is warranted, and whether the governance record still reflects what is happening across the organization.

The firms best positioned for the next phase of AI adoption won’t necessarily be those with the longest AI policies or the most restrictive approval processes.

Instead, they’ll be the firms that can demonstrate that governance continues long after approval.

Because when it comes to AI, approval isn’t the finish line.

It’s the starting point.

Frequently Asked Questions

What is AI governance for investment firms?

AI governance for investment firms is the framework of policies, processes, controls, ownership, documentation, and oversight used to manage how artificial intelligence is evaluated, approved, used, monitored, and retired across the organization. Effective governance should account for both AI-specific risks and the firm’s existing regulatory obligations.

Why should AI be monitored after approval?

AI tools, underlying models, vendor capabilities, integrations, and business use cases can change after the initial approval. Therefore, ongoing oversight helps firms identify when those changes materially affect the original risk assessment or require new controls.

How often should an investment firm review approved AI tools?

There is no universal review cadence appropriate for every AI application. Instead, firms can take a risk-based approach, with higher-risk applications receiving more frequent review and material changes triggering reassessment between scheduled reviews.

Does using AI change a firm’s existing regulatory obligations?

AI does not automatically replace or eliminate existing regulatory requirements. For example, FINRA has stated that its technology-neutral rules and securities laws continue to apply when member firms use generative AI, including requirements that may relate to supervision, communications, and recordkeeping. Therefore, firms should evaluate each AI use case in the context of the specific laws, rules, and obligations applicable to their business.

What should firms document as part of AI governance?

Depending on the use case and risk level, documentation may include the AI system and vendor, business owner, intended and approved uses, risk assessment, applicable controls, approval history, material changes, periodic reviews, incidents, exceptions, and eventual retirement. Ultimately, the goal is to maintain a governance record that reflects how the AI system is actually being used over time.

What is the biggest post-approval AI governance risk?

There isn’t one universal risk, but governance drift is particularly important. A tool may remain “approved” while its capabilities, use cases, data access, or underlying model change significantly. Without lifecycle oversight, the firm’s documented governance can gradually stop reflecting operational reality.

AI Governance Shouldn’t Stop at Approval

TillieStar helps investment firms build a more structured, defensible approach to AI governance, from initial assessment and approval through ongoing monitoring, documentation, and reassessment.

Ready to strengthen your AI governance lifecycle? Contact us at sales@tilliestar.com or (617) 865-3550 to start the conversation.

Leave a comment

Your email address will not be published. Required fields are marked *