The best available list of what a supervisor will ask about AI was written by supervisors, for supervisors, and published. Almost nobody in this industry has read it, which makes exam preparation unusually tractable for something that feels unknowable.
The checklist
1. Read the question bank. IOSCO’s 2026 supervisory toolkit was built by a working group that includes the SEC, the FCA, ESMA, MAS and a dozen other authorities, off a 21-member survey. It sets out question banks across governance and risk management, third-party and outsourcing, disclosure, and recordkeeping and reporting. IOSCO also published a companion standalone extract of those tables, consolidated as “a hands-on resource that supervisors can refer to” during “on-site examinations and inspections.” A published list of the questions the examiner is being handed is a rare advantage. It is non-binding and it comes from IOSCO rather than the SEC, but as a rehearsal set it has no competitor.
2. Build the mapping table, because that is the deliverable. Two independent sources land on the same artifact: compliance programmes “should document each AI use case and map associated controls to the applicable requirements,” and counsel separately advise mapping AI usage across departments. Use case → control → rule is a crosswalk, and this wiki already generates one. Treat the crosswalk as the thing to hand over rather than internal scaffolding, and add the rule column for the firm’s own regime.
3. Rehearse the four demonstrations. Firms should be prepared to show how they evaluate AI tools before deployment, monitor outputs for accuracy and compliance, maintain human oversight of material AI-driven decisions, and address bias. Note that “material AI-driven decision” is undefined by the SEC, so each firm draws and defends that boundary itself, which argues for a written tiering rubric rather than a case-by-case answer under pressure.
4. Practise the version-as-of-date question. Records kept electronically must be produced to staff in electronic format on request, and the Commission’s expectation is that a firm can indicate which version of its policies and procedures was in effect as of a given date. That is a specific, testable drill and most firms fail it for AI policies, because the policy has been edited in place with no version history. Pair it with the four-month reconstruction drill in recordkeeping and compliance gaps.
5. Run the exam against the vendor before the regulator runs it against the firm. FINRA’s cleanest effective practice is testing a recordkeeping vendor’s capability “by, for example, simulating a regulator’s examination by requesting records to confirm compliance.” Applied to an AI platform: ask the vendor, in writing, to produce the prompts, outputs and model versions for a named agent over a named month, in an exportable format, and time it; what comes back is the firm’s actual capability, regardless of what the contract says.
6. Do the gap analysis in the form the regulator uses. This is cheap and nobody does it. FINRA’s published operating model is to compare current programmes and procedures against the questions in supervisory publications and determine whether gaps exist that could produce the findings described. Counsel give advisers the same advice against the FY2026 priorities.
7. Document the reasoning, not just the decision. The documentation examiners want strengthened includes the rationale for AI tool selection and for ongoing supervision. A decision record without reasoning is indistinguishable from a decision made without reasoning, and the reasoning is unrecoverable eighteen months later.
8. Know whether the firm is in the priority population. Never-examined and recently registered advisers are prioritised, and firms that grew fast, acquired, or changed business model should expect heightened interest. A firm-wide agent rollout is a business-model change by any reasonable reading.
Two things worth knowing about how this actually runs
Supervisors collect through examination and inspection data requests, structured outreach, and occasional sector-wide surveys, and IOSCO notes members “may require expert specialists and additional technical tools” to review AI records. The person reading a firm’s trace store may not be the person who wrote the request.
Individual examination findings are kept confidential by many authorities, with SEC Risk Alerts as the public channel. So the population of what has actually been found about AI at other firms is invisible from outside, and the absence of public findings is not evidence of an absence of findings.
One asymmetry worth using at a member firm: FINRA names three ways to ask before being asked.
The interpretive-request process handles genuine ambiguity about how a rule applies to a specific
Gen AI use; the Risk Monitoring Analyst already assigned to the firm is the standing channel for
raising an AI change in the business; and written feedback on rule modernisation goes to
pubcom@finra.org with “Gen AI” in the subject line (Regulatory Notice 24-09, 2024-06-27). The SEC
offers this audience no comparable named counterpart, which is part of why adviser-only firms find
exam preparation lonelier than broker-dealers do.
How you’d know it’s working
IOSCO’s lifecycle question for the firm’s highest-impact agent, ideation to retirement, can be answered in one sitting, from documents rather than from memory.
Someone has timed a vendor record-production request. If nobody has, production capability is a contractual claim rather than a measured one.
Someone can state which version of the AI policy was in force on a date twelve months ago, and produce it.
The human-oversight questions have numeric answers: who can intervene, how quickly, how often overrides actually happen, and whether anyone back-tests whether the overrides were right. Most firms have the first two and not the second two.
What this doesn’t solve
This is preparation rather than the controls being examined. Passing an exam and being safe are different achievements, and the gap is widest exactly where the regulator’s threat model trails the field: the SEC’s named AI attack vectors are malware and deepfakes, not prompt injection. FINRA is further along, having published an explainer on prompt injection in March 2026, so treat this as an SEC gap rather than a regulatory one.
IOSCO binds nobody. It is an international standard-setter and its toolkit is explicitly “non-binding, non-prescriptive.” Using it as a rehearsal set is sound; citing it as an obligation is unsound, and its question banks differ from the SEC’s question banks.
Nothing here describes SEC examination mechanics: cycle length, request-list format, scope negotiation, or what a deficiency letter looks like. That is a genuine hole in this page. The corpus behind it contains no exam manual, and we did not find a public one worth citing.
The FINRA material is broker-dealer practice. Advisers have no Risk Monitoring Analyst, no CORE programme, no branch exam programme, and no Firm Element training obligation. The techniques transfer; the infrastructure does not.
See also
- Regulatory exposure — what is at stake in the exam, and why the compliance-program charge is available without any predicate failure.
- Crosswalk — the mapping table two independent sources say is the deliverable.
- Supervisory review — the programme whose evidence will be produced.
- Registry review cadence — the recurring review that keeps the inventory answerable.
- When to involve legal and compliance — what happens when a request arrives rather than a scheduled exam.
- Templates and checklists — the printable artifacts, including the ones that can be forwarded to compliance.