Financial Services AI Governance

Financial Advisor AI Policy Generator

Walk through ten guided decisions — approved uses, client confidentiality, human review, vendor approval, recordkeeping, and more — and assemble a written AI policy starter for your advisory firm.

No login requiredNo data stored — everything stays in your browserFixed, reviewed templates — not an AI chatbot

1. Select your approach

Each section offers a few reviewed approaches. Pick the one closest to how your firm wants to operate.

2. Review the draft

Your selections assemble a complete policy starter, live. Copy it or download it as a file.

3. Hand it to your team

The draft is a starting point for your legal, compliance, and leadership teams to review and approve.

Step 1 of 10: Approved and Prohibited AI Uses

Section 1 of 10

10%

Approved and Prohibited AI Uses

Choose the base level of AI use your firm is prepared to support today.

Choose an approach for Approved and Prohibited AI Uses

Live Draft Preview

# AI Acceptable Use Policy — [Firm Name]
*DRAFT — STARTING POINT. This document was generated from ZYNAGI educational templates and is provided as a starting point only. It is not legal advice and does not become a usable firm policy until it has been reviewed and approved by the firm’s legal, compliance, and leadership teams.*

## Purpose and Scope
This policy defines how [Firm Name] may use artificial intelligence tools in firm work. It applies to all employees, contractors, and affiliated advisors of the firm, and to all AI tools used for firm purposes, whether provided by the firm or accessed personally. This starter draft is organized into sections; each section reflects decisions the firm has selected for review.

## Approved and Prohibited AI Uses
Approved AI use includes internal drafting support and the preparation of marketing and educational content, provided a qualified person reviews and approves the final text before publication. AI must not be used to generate investment recommendations or client-specific advice. Any use beyond this section requires written approval from the policy owner.

## Client Confidential Information
Client-identifiable information — including names, account numbers, Social Security numbers, holdings, financial plans, and any information that could identify a client — must not be entered into any AI tool that has not been approved for such data. Employees must assume a tool is not approved unless it appears on the approved-tool list. Suspected violations must be reported under the incident escalation section of this policy.

## Public and Private AI Tools
Public or consumer AI tools may be used only for content that contains no client-identifiable or confidential information — for example, general industry research or formatting. Any content touching client matters must use tools from the approved list. Employees remain responsible for confirming that nothing confidential is entered.

## Human Review Requirements
Every AI-assisted item that will be seen by a client — including emails, letters, reports, and presentations — must be reviewed and approved by a qualified person before delivery. The reviewing person is accountable for accuracy, tone, and appropriateness, and may not rely on the AI output as a substitute for professional judgment.

## AI Vendor Approval
No AI tool may be adopted, trialed, or expanded in scope without documented review and written sign-off from the policy owner. Reviews cover data handling, retention, security posture, subcontractors, and contractual data-use terms, and the outcome — approved, approved with conditions, or declined — is recorded.

## Recordkeeping
The firm maintains records of AI tool approvals, vendor reviews, policy versions, employee acknowledgments, and incidents. Records are kept in a form that can be retrieved on request and are retained according to the firm’s general record retention practices.

## Employee Responsibilities
Every employee must complete firm-provided training on AI risks — including confidentiality, accuracy, and disclosure — before using AI tools, and must acknowledge this policy annually. Managers are responsible for confirming their teams understand and follow the policy.

## Incident Escalation
Any suspected AI incident must be reported to the policy owner within 24 hours of discovery. The report should describe what was entered or sent, which tool was involved, when the incident occurred, and who is affected. The policy owner records the incident and directs containment.

## Policy Ownership
A named individual is designated as the AI governance owner, with documented authority to approve tools, grant exceptions, and update this policy. A deputy is named to cover absences, and ownership is reviewed annually.

## Review Frequency
This policy and the approved-tool list are reviewed at least annually. Each new tool approval triggers a focused review of the sections of this policy it affects, so the policy remains current as adoption expands.

## Review and Approval
Prepared by: ____________________  Date: ____________
Reviewed by (Compliance): ____________________  Date: ____________
Reviewed by (Legal): ____________________  Date: ____________
Approved by (Leadership): ____________________  Date: ____________

## Important Notice
This document is a starting point generated from ZYNAGI educational templates. It is not legal advice and is not a legally sufficient policy until it has been reviewed and approved by the firm’s legal, compliance, and leadership teams. Firms should adapt this draft to their specific business, regulatory context, and obligations with the support of qualified advisors.

The generated draft is a starting point. It is not legal advice, is not a legally sufficient policy, and does not create a legally sufficient policy until it has been reviewed and approved by your firm's legal, compliance, and leadership teams. Nothing here collects client data: selections are processed entirely in your browser, never stored, and never sent to a backend function or external AI model.