Practical Guide
Governing AI in Your Firm
Vendor types, risks, controls, and policy language you can adapt. AI has not created a new class of risk — it has concentrated the existing ones, and put them inside tools your users were already using.
By Brian Edelman, Founder & CEO, FCI Cyber · Last updated: May 2026
Governing AI in a firm means categorizing every AI tool in your environment — third-party, fourth-party, or AI solution integrator — containing the AI-specific risks each one carries, putting data, identity, evidence, and boundary controls in place, and folding AI policy into your Acceptable Use Policy with signed user acknowledgment.
Related: AI Regulatory Guidance · IT & Cyber Disciplines · Data Security · FCI & AI
Overview
Why This Matters
AI has not created a new class of risk. It has concentrated the existing ones — and put them inside tools your users were already using. The same Nonpublic Information (NPI) your firm has always had to protect now flows into chat windows, embedded features, and third-party integrators at machine speed.
The question is no longer whether AI is in your stack. It is whether your firm knows where it lives, who is accountable for it, and what evidence you can produce when a regulator asks.
This page gives you a working framework: how to categorize the AI in your environment, the risks specific to it, the controls that contain them, and example policy language you can adapt for your AUP.
The firm — not the vendor, not the AI provider — owns the decision about what data goes into AI tools and what evidence proves it.
Prerequisites
Two Foundations
Before talking about AI specifically, two things must already be in place.
Every cybersecurity regulation requires it, and AI sharpens the consequence: if your firm has not defined what information is sensitive, it cannot define what is safe to put into an AI tool. The scope is no longer just PII. Most regulators now require protection of all Nonpublic Information (NPI), which includes:
• Business Confidential Information (BCI)
• Personal Financial Information (PFI)
• Personally Identifiable Information (PII)
• Protected Health Information (PHI)
AI vendors clear the same annual due diligence package as every other vendor: a SOC 2 report or ISO certification, a management assertion confirming the vendor runs its own cyber program, proof of cyber insurance, and current network penetration test and vulnerability scan results. AI status does not lower the bar — it raises the stakes of meeting it.
The AI-specific items under Controls to Put in Place below are additions to this baseline, not substitutes for it.
Categorize
The Three Forms AI Shows Up in Your Stack
Most firms underestimate how much AI is already in their environment because they only count the tools they explicitly purchased. AI typically reaches your firm in one of three ways.
A standalone AI product or service your firm selected and contracted with directly. Your users interact with it knowingly, and your firm is fully accountable for the due diligence and ongoing oversight of the vendor.
AI functionality your existing vendor has added to a product you have already approved — an AI feature inside your CRM, your email platform, or your document system. Your vendor selected the AI component; your firm inherits it. The primary due diligence responsibility sits with your vendor, but your firm must verify they performed it.
In the last few years, a wave of new companies has approached financial services firms offering AI-built solutions layered on top of frontier models. They are often early-stage, lightly funded, and frequently lack the cyber maturity of the model providers they sit on. They will access extensive amounts of your private data.
Your firm has two ways to handle this kind of vendor — pick the one that matches the engagement.
Option 1 — Treat them as a third party. They must clear the full vendor due diligence package, and a third party with technical expertise should review their architecture before approval. Financial services firms often skip this step and miss serious risk, particularly when data is uploaded to another environment in the cloud.
Option 2 — For a solo consultant, treat them as an employee. Provide a corporate-owned computer carrying the same security tools your employees and affiliates use, and implement MFA that the firm controls. In this model the firm — not the consultant — is responsible for the protected device, the access controls, and the evidence that comes from them.
Contain
AI-Specific Risks
These are the risk classes your firm should track, separate from generic vendor risk.
Prompts, files, and outputs used to improve the vendor’s model — often by default, often reversible only by configuration.
NPI uploaded into a chat window, a summarizer, or an embedded feature without a record of what was sent or who saw it.
Employees signing up to AI tools with personal email addresses, bypassing every control the firm has put in place.
AI-generated content used in advice, communications, or documents without human review and without a paper trail.
Automated transcription joining calls by default, capturing client conversations before participants are told.
Particularly with AI integrators — companies that may disappear, change hands, or alter terms, leaving the data they held in uncertain custody.
NPI moving out of the firm via AI tools to personal accounts, removable media, or unmanaged cloud apps.
Controls
Controls to Put in Place
The controls below extend your standard vendor and endpoint controls. We group them in four categories so the picture is clear, not a checklist.
Data retention. The vendor must state whether your data is stored, for how long, and for what purpose.
Data anonymization. The process must be documented and verifiable, not asserted.
Training opt-out. The vendor must allow your prompts, files, and outputs to be excluded from model training — contractually and technically.
DLP (Data Leakage Protection). The firm must have a system that monitors, alerts, or blocks transfers of NPI to cloud apps, AI tools, and removable media.
Firm-managed business account. The firm holds the AI vendor relationship; personal accounts for firm use are not allowed.
User management. Provisioning, deprovisioning, and role-based access run through the firm, not the individual user.
Multi-factor authentication. MFA is required for every AI tool. No exceptions.
Logging and auditability. The vendor must maintain logs of data processing and administrative actions sufficient to support investigations, audits, and regulatory inquiries.
Log retention. Logs must be retained per your cyber program requirements and accessible to the firm.
Hardening evidence. Cybersecurity settings on the AI tool must be reviewed, documented, and produced on request.
Blocking unapproved AI tools. The firm must have a mechanism to block access to every AI tool that is not on the approved list.
Approved-list maintenance. The list is reviewed on a defined cadence as AI features and vendors change.
Adaptable Language
Example Policy Clauses
The clauses below are examples. Your firm should tailor them to its approved AI tools list, data classification standards, and supervisory procedures.
Next Steps
What to Do This Week
Three concrete next steps a firm can take immediately.
List every AI tool in use across the firm, including AI features that came embedded in vendors you have already approved.
Apply your annual vendor due diligence package to every AI vendor and integrator on that list.
Add the AI clauses, walk users through the changes, and re-collect signatures.
Put AI Governance in Place with FCI
FCI helps financial services firms govern AI — data classification, DLP, vendor due diligence, and the evidence trail that proves your controls are enforced.