4 minRIAIntelligence field notes

The RIA's AI cheat sheet

Ten practices for using AI well inside an advisory firm, from what never gets pasted to the four questions every vendor should answer.

This piece covers ten working practices: what never leaves the firm, how to check an answer, when a summary can be trusted, and what to ask any vendor selling you AI. · The questions buyers carry

Most of what goes wrong when an advisory firm uses AI is not exotic. It is a handful of ordinary mistakes, made casually, by good people trying to save an hour. The fixes are just as ordinary. Here are ten practices worth adopting today, whatever tools your firm runs.

The ten

  1. Never paste client-identifying information into a personal AI account. A name next to an account number next to a balance, typed into a consumer chat window, is client data leaving the firm under terms nobody at the firm has read. If the tool is not covered by a firm agreement, work with placeholders: “Client A, 72, $1.4M IRA” gets you the same drafting help without the exposure.
  2. Ask where every number came from. Make “what is that based on?” a reflex. A tool built for real work can point at its source: the statement, the row, the document. A number that arrives with no receipt is a draft of a number, and it gets verified before it gets used.
  3. Trust a summary exactly as far as you can check it. A summary of a document you possess is safe to lean on, because you can spot-check three claims against the original in two minutes. Do that, every time, before forwarding. A summary of something you cannot check, “the market this quarter,” “the new rule,” is an opinion wearing a summary’s clothes.
  4. Treat confidence as zero evidence. These tools write fluently when they are right and just as fluently when they are wrong. There is no tone of voice that signals error. The only tell is checking, so anything bound for a client, a file, or a regulator gets checked.
  5. Use AI for drafts, never for decisions. Let it produce the first version of the letter, the agenda, the meeting recap, the comparison table. The judgment about what to recommend, and the responsibility for it, stays with a person whose name is on the work. That line is also where a regulator will look.
  6. Write down where AI is allowed in your firm. One page is enough: which tools are approved, what data may go into each, who signs off on new ones. A firm with no written policy still has a policy; it is whatever each employee decides alone at their kitchen table at 9 p.m.
  7. Prefer rules that are settings over rules that are sentences. If a restriction exists only as an instruction someone typed, “don’t show other advisors’ clients,” it is a request the model usually honors. A restriction enforced outside the model, as a setting you can print and check, is a control. Compliance files are built from controls.
  8. Keep a person on everything outward. Nothing AI-drafted should reach a client, a custodian, or a regulator without a named person reading it and approving it. Approved sending is fine; unattended sending is how a small error becomes a firm-wide apology.
  9. Keep the work product. When AI materially helps produce something that touches a client matter, keep what was asked and what came back, the way you would keep any other working paper. If the answer is ever questioned, the record of how it was made is the difference between an explanation and a reconstruction.
  10. Ask every vendor the same four questions. What exactly does your AI see? What does it keep, and for how long? Is our data used to train models? And when it acts outward, an email, a filing, a message, who signs? Vendors with real answers give them in specifics: named systems, named settings, named people. Vendors without real answers give you adjectives.

What the list adds up to

Read back through the ten and a pattern shows: none of them require technical skill. They require the same habits the industry already has about client money, applied to client data: know where it goes, verify before you rely, keep the record, and make sure a person signs. Firms that bring those habits to AI get the hour back without buying a new problem. Firms that don’t are running an unwritten policy they have never read.

And the four vendor questions are fair to turn on anyone, including us. RIAI’s answers are the product: it sees the firm’s records in a database the firm owns, the record of what it saw and did is append-only, no client data trains anyone’s models, and a person approves what goes out, including email where a firm chooses to turn sending on. Any vendor selling into this industry should be able to answer that cleanly. Hold everyone to it.

The door

See it answer for yourself.

A live install on an invented firm. Ask it anything, watch the receipts land, then try to make it cross a line.

Open the demoNo form. Access code RIAI2026

Ask us about your firmhello@riaintelligence.ai