Tool Gate · How it works
How the Advisory-Firm AI Exam Defensibility Audit gate works
How the Advisory-Firm AI Exam Defensibility Audit scores a firm's exam-readiness across weighted evidence domains — then a fatal-domain gate forces NOT DEFENSIBLE when any core domain (like books & records) sits at zero, so a respectable overall score still fails if one dispositive domain is empty.
How the gate works
This tool grades one advisory firm's AI use against the six exam-surface domains an SEC or state examiner probes. Each control is marked from your own evidence and weighted into a 0–100 score — and then the score is run past a gate that can only make the verdict worse.
The 6 weighted controls
| Signal | Weight |
|---|---|
| AI in marketing & advertising | 20 |
| Books & records for AI outputs | 20 |
| Supervision & written policies | 18 |
| Third-party / vendor AI oversight | 16 |
| Client disclosure & Form ADV | 14 |
| AI communications capture | 12 |
| Total | 100 |
The verdict bands
Three of the six domains are load-bearing — AI in marketing, books & records for AI outputs, and supervision & written policies. A zero on any one of them forces NOT DEFENSIBLE regardless of the score, because each is a finding that draws a deficiency letter on its own. A strong file elsewhere can't cure a missing load-bearing control; clear the zero and the gate releases.
In the worked sample it scores 73 out of 100 and still reads NOT DEFENSIBLE — The Northgate branch scores 73 on strong marketing, supervision, vendor, and comms controls — on the number alone it reads OPEN FINDINGS. But its books-and-records domain, a fatal exam domain, is at zero: AI summaries and AI-drafted client comms aren't retained where they function as records. The fatal-domain gate fires, so the verdict is NOT DEFENSIBLE, not OPEN FINDINGS — a polished file elsewhere can't cure a missing load-bearing control. The one thing to fix first: Books & records for AI outputs — the fatal domain sitting at zero. Retain AI summaries and AI-drafted client comms where they function as records; clearing that one domain releases the gate and moves the verdict off NOT DEFENSIBLE..
Common questions
Can something score well on the How the Advisory-Firm AI Exam Defensibility Audit works and still fail?
Yes. The weighted score is run past a worsen-only gate — the Fatal-domain gate — that can only make the verdict worse. In the worked sample it scores 73 out of 100 and still reads NOT DEFENSIBLE, because the Northgate branch scores 73 on strong marketing, supervision, vendor, and comms controls — on the number alone it reads OPEN FINDINGS. But its books-and-records domain, a fatal exam domain, is at zero: AI summaries and AI-drafted client comms aren't retained where they function as records. The fatal-domain gate fires, so the verdict is NOT DEFENSIBLE, not OPEN FINDINGS — a polished file elsewhere can't cure a missing load-bearing control.
What is a worsen-only gate?
A dispositive rule that can only lower a verdict, never raise it. One fatal flaw overrides an otherwise-good score, because a single disqualifying gap shouldn't hide behind a high average. The tool also names the one thing to fix first — here, "Books & records for AI outputs — the fatal domain sitting at zero. Retain AI summaries and AI-drafted client comms where they function as records; clearing that one domain releases the gate and moves the verdict off NOT DEFENSIBLE.".
Not legal advice. This is a readiness self-assessment that grades a firm's evidence from your own marks — not a compliance audit, a mock exam, a certification, or an opinion of counsel. It renders no legal ruling, confirms no obligation, and scores no person. Confirm which rules apply to your firm, and every date, with your CCO or a qualified securities attorney.
Embed this diagram
Free to share and embed with attribution (CC BY 4.0) — keep the link to redhub.ai.
Interactive — renders the live diagram
<iframe src="https://redhub.ai/visuals/tool/advisory-firm-ai-exam-defensibility-audit.html" title="How the Advisory-Firm AI Exam Defensibility Audit gate works — RedHub AI" width="760" height="1892" loading="lazy" style="border:0;width:100%;max-width:760px"></iframe>
<p style="font:14px/1.5 system-ui,sans-serif"><a href="https://redhub.ai/visuals/tool/advisory-firm-ai-exam-defensibility-audit">How the Advisory-Firm AI Exam Defensibility Audit gate works</a> — by <a href="https://redhub.ai">RedHub AI</a>, the AI that tells you when to doubt it.</p>Image + link — a static picture for any blog
<a href="https://redhub.ai/visuals/tool/advisory-firm-ai-exam-defensibility-audit"><img src="https://redhub.ai/visuals/tool/advisory-firm-ai-exam-defensibility-audit-share.png" alt="Diagram of the Advisory-Firm AI Exam Defensibility Audit: weighted evidence domains scored to 0-100 and a fatal-domain gate forcing NOT DEFENSIBLE when a core domain is at zero." width="760" loading="lazy" style="max-width:100%;height:auto;border-radius:16px"></a>
<p style="font:14px/1.5 system-ui,sans-serif"><a href="https://redhub.ai">RedHub AI</a> — the AI that tells you when to doubt it.</p>This is how Advisory-Firm AI Exam Defensibility Audit works. More diagrams in the Visual Field Guide.