Your AI use is on theexam surface now.
Would it survive one? Mark the six domains an SEC or state examiner probes when an adviser uses AI — marketing, books & records, supervision, vendor oversight, Form ADV disclosure, communications capture — and get a defensibility verdict per firm, from your own evidence.
Not legal advice. This is a readiness self-assessment that grades a firm's evidence from your own marks — not a compliance audit, a mock exam, a certification, or an opinion of counsel. It renders no legal ruling, confirms no obligation, and scores no person. Confirm which rules apply to your firm, and every date, with your CCO or a qualified securities attorney.
Examiners stopped treating AI as a novelty. The controls it needs are the ones you already owe.
AI is in your marketing
AI-drafted posts, emails, and testimonials fall under the Marketing Rule like any other advertisement — and a lighter review path 'because AI wrote it' is a finding waiting to happen.
AI outputs are records — or should be
AI notetaker summaries and AI-drafted client comms function as records. Whether they're retained is the single most live books-and-records question an adviser faces right now.
A high score can hide a gate-triggering gap
A firm can look strong on paper and still contain a material evidence gap if one load-bearing control is simply absent. An overall percentage won't tell you which; a gate will.
Mark six domains per firm. The evidence gate does the rest.
Mark each exam-surface domain 0/1/2 on evidence. The verdict falls out.
Fix first: Books & records for AI outputs — the weakest exam-surface domain across the portfolio.
The Northgate branch scores 73 on points yet reads EVIDENCE GAP — its books-and-records domain (dotted, a gate domain) is at zero, and a strong file elsewhere can't cure a missing load-bearing control. Set that domain to 1 and it clears. The verdict comes from your own evidence marks; it grades a firm's exam evidence, renders no legal ruling, and scores no person. Not legal advice.


How the gate works, in one image
How the Advisory-Firm AI Exam Defensibility Audit scores exam-readiness and forces EVIDENCE GAP when a core evidence domain is empty — the same math the demo runs, as a diagram you can share or embed anywhere.
View & embed the full diagramThe same verdict from the command line.
The workbook and a zero-dependency Python engine produce identical results. Point the engine at a firms file and it prints the exam-surface read — verbatim below, from the shipped sample.
==============================================================================
ADVISORY-FIRM AI EXAM DEFENSIBILITY AUDIT
Exam-surface read - as of 2026-07-05
==============================================================================
PORTFOLIO VERDICT ..... DEFICIENCY LIKELY
Firms graded .......... 5
2 exam-ready - 1 open findings - 2 at evidence gap
Fix first ............. Books & records for AI outputs
------------------------------------------------------------------------------
FIRM / BRANCH MAR REC SUP VEN DIS COM SCORE VERDICT
------------------------------------------------------------------------------
Main RIA (HQ) 2 2 2 2 2 1 94 EXAM-READY
Northgate Branch 2 0 2 2 1 2 73 EVIDENCE GAP
Lakeside Advisors 1 1 1 1 1 1 50 OPEN FINDINGS
Summit Wealth (new) 1 0 0 1 0 1 24 EVIDENCE GAP
Harbor Point LLC 2 2 2 1 2 2 92 EXAM-READY
------------------------------------------------------------------------------
! Northgate Branch scores 73 on points yet reads EVIDENCE GAP:
a gate domain is at zero - Books & records for AI outputs.
A strong file elsewhere cannot cure a missing load-bearing control.
KEY: MAR=AI in marketing & advertising | REC=Books & records for AI outputs | SUP=Supervision & written policies | VEN=Third-party / vendor AI oversight | DIS=Client disclosure & Form ADV | COM=AI communications capture
The verdict comes from your own evidence marks - no benchmark. It
grades a firm's exam evidence, renders no legal ruling, and scores
no person. Not legal advice - confirm every rule and date with counsel.
==============================================================================Six weighted domains, three of them gate domains.
AI in marketing
Marketing Rule review, testimonial disclosure, substantiated claims.
Books & records for AI
AI summaries and AI-drafted comms retained where they function as records.
Supervision & policies
AI named in the written compliance program, with an owner.
Vendor AI oversight
Due diligence, contracts, and data-flow records for AI vendors.
Disclosure & Form ADV
Material AI use disclosed; no overstated capability claims.
AI comms capture
AI-assisted client communications captured and reviewable.
Each domain is marked 0/1/2 on evidence; the weights sum to 100 for a 0–100 score, banded EXAM-READY (75+) / OPEN FINDINGS (50–74) / EVIDENCE GAP (under 50). The gate is dispositive: a zero on any gate domain forces EVIDENCE GAP regardless of the score. The user's mark triggers this instrument's evidence gate. That does not establish that the control is legally required or that the firm violates applicable law. SEC examination priorities commonly cover these three areas; the audit does not predict what an examiner will find.
A way to find the gate-triggering gaps in your AI controls before an exam. Not an opinion of counsel.
What it is
- A readiness self-assessment for an adviser using AI
- Six exam-surface domains mapped to the Advisers Act frame
- A per-firm defensibility verdict with a domain evidence gate
- A portfolio rollup across branches, with the domain to fix first where a domain is short
What it isn't
- Not a compliance audit, mock exam, or certification
- Not an opinion of counsel and not a legal ruling
- Not tied to a statutory date — it grades process, not a deadline
- Not a score of any person — it grades a firm's evidence file
Not legal advice. This is a readiness self-assessment that grades a firm's evidence from your own marks — not a compliance audit, a mock exam, a certification, or an opinion of counsel. It renders no legal ruling, confirms no obligation, and scores no person. Confirm which rules apply to your firm, and every date, with your CCO or a qualified securities attorney.
Anyone who owns an adviser's exam readiness.
RIA principals & CCOs
Find the gate-triggering gap in your AI controls before an exam — and know which branch is the weakest link.
Compliance consultants
Run a consistent, evidence-based read across every client firm, and hand each one a prioritized remediation list.
Multi-branch & roll-up firms
Grade every office on the same six domains; the portfolio verdict follows the weakest branch, so you know where to look.
Firms adopting AI notetakers
The books-and-records domain is where notetaker adopters quietly fail. See whether your summaries are actually retained.
Triage the broad gap; deepen the domains this audit flags.
Pass a 90-Day AI Audit? Readiness Triage
The generic, cross-industry front door — seven governance domains and, where anything is short, which broad gap to close first. This audit is its adviser-specific counterpart.
ViewAI Output Audit-Trail & Record-Keeping Kit
If books-and-records is your gate-triggering gap, this grades whether each retained AI entry is actually complete — who, what tool, when, reviewed by whom.
ViewAI Vendor & Sub-Processor Data-Flow Register
Builds the vendor-oversight artifact this audit's fourth domain asks for — what each AI vendor touches, and whether it's governed.
ViewBefore you buy.
Find the gate-triggering gap first.
Before the examiner does.
One purchase, lifetime access, 12 months of updates. $99, once.
Not legal advice. This is a readiness self-assessment that grades a firm's evidence from your own marks — not a compliance audit, a mock exam, a certification, or an opinion of counsel. It renders no legal ruling, confirms no obligation, and scores no person. Confirm which rules apply to your firm, and every date, with your CCO or a qualified securities attorney.
Sold by RedHub AI LLC · Secured by Stripe · redhub.ai