AI Compliance Concerns Surge Among Investment Advisors

Artificial intelligence is top of mind for many advisors and firm leaders, and it’s no different when it comes to those overseeing compliance, according to a new survey from the ACA Group.

The compliance consulting firm’s 2026 “Investment Management Compliance Testing Report” indicated that AI was the top compliance concern among respondents at 85%, a whopping 50 percentage points above the second-place concern (cybersecurity).

The number was a 28-percentage-point increase from the previous year’s survey among respondents who marked AI as a chief concern. According to ACA Group President Carlo di Florio, the firm had never seen a single topic “command this kind of separation” from other concerns in 21 years of conducting the annual survey.

“What makes this year’s results particularly meaningful is that firms are no longer just naming AI as a concern; they are allocating compliance resources, standing up governance committees and increasing testing,” he said. “But the gaps in human oversight, output validation and third-party AI policies tell us the work is far from done.”

Related:Mercer Launches Second Generation of Aspen Unified Operating Platform

The ACA Group conducted the survey, along with the Investment Adviser Association and Yuter Compliance Consulting. The survey includes data from 411 firms collected through online surveys conducted in April and May 2026.

Most respondents reported assets under management of $1 billion to $10 billion, and firms were evenly split between advising private funds, institutional clients, and high-net-worth individuals (or some combination). About 34% of respondents reported working with retail clients (accounts under $1 million), while about 24% worked with family offices.

About 80% of respondents reported using AI tools, with 70% of total respondents claiming they’d restricted it to internal use cases (compared with 10% that use it internally and externally). Eighteen percent are exploring, but have not yet adopted tools, while 2% have banned or significantly restricted them.

According to the ACA Group, 86% of firms have established policies and procedures governing employee use of AI. In comparison, 59% have established AI governance committees and 72% have completed compliance testing for AI tools.

However, less than half (48%) reported having formal plans in place for “human-in-the-loop” oversight of AI outputs, while only 30% had policies addressing third-party AI use.

In particular, the ACA Group said firms could do more to develop policies governing the use of third-party AI, and that such oversight was a key concern for surveyors. According to the survey, six in 10 firms have made or are making “significant” changes to their third-party risk management programs, while 48% completed compliance testing on vendor due diligence.

Related:WealthStack Roundup: Zeplyn Launches AI Advisor Coaching Feature

Of those, 69% had updated third-party risk procedures, while 58% “introduced or revised vendor risk-tiering criteria” (for example, differentiating between “critical” vs. “non-critical” vendors). However, only 31% had improved internal tracking and 27% had “implemented or enhanced continuous or periodic vendor risk reviews.”

Other top concerns for firms included cybersecurity, privacy and Regulation S-P, and advertising and marketing, at 37%, 35% and 19% of respondents, respectively.

For cybersecurity, while 81% of firms are updating and reviewing their incident response plans and 88% are updating and reviewing business continuity plans annually, yearly testing happens less frequently (for business continuity plans, 77% of respondents reported doing so). Among the scenarios tested were cybersecurity incidents (62% of respondents), critical vendor or service outages (48%) and facility inaccessibility (46%).

While AI compliance oversight within firms is growing, the use of the tool within compliance and operations remains “mile wide and an inch deep,” according to comments from Joseph Kochansky, ACA’s head of product and engineering, in May.

Related:The WealthStack Podcast: Helping Advisors Serve Business Owners with RISR’s Jason Early

Kochansky was commenting on results from an ACA Group survey that found that while 84% of respondents reported using AI, “active AI use” occurred, on average, in only two of 20 compliance and operations sub-functions. Additionally, only 18% of firms reported using AI for compliance tasks.

The most common compliance use for AI in firms was the so-called “compliance program administration” sub-function, at 35%; according to the ACA Group, this included day-to-day tasks such as summarizing reports, preparing communication first drafts and reviewing policies and disclosures.

But this sub-function captured users working with desktop tools, such as Claude, Microsoft Copilot and ChatGPT. According to Kochansky, while desktop AI tools were easy for users, they could be cumbersome when applied to firms’ compliance management.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *