The AI Evidence Assessment
Twelve questions. Three minutes. Answer for what you could actually put your hands on today, not for what the policy says. This is not regulatory advice and nothing here assesses your compliance program — we do not do that, and we are not your compliance consultant.
Your result is on screen. Forward it if it is useful.
The three artifacts you scored lowest: .
Scoring zero today: .
A risk assessment dated after go-live is the one artifact that cannot be produced retroactively.
Here is what to make of that.
Across the industry, 86% of adviser firms have an AI acceptable use policy and 86% maintain an inventory of AI tools. Then it falls away: 48% have human-in-the-loop oversight procedures, 37% have output testing or validation policies, 30% have third-party AI use policies, and 14% have updated their incident response plans for AI disruption (2026 Investment Management Compliance Testing Survey — Investment Adviser Association with ACA Group and Yuter Compliance Consulting; 411 adviser firms, fielded April–May 2026, published July 29, 2026). That respondent base skews larger and better-resourced than a $250M–$5B firm, so read those as an upper bound rather than a par score.
If you scored in the middle band, you are where most of this market is. The policy layer is saturated because it is a deliverable somebody could sell. The evidence layer is an operating rhythm, and nobody sold you one.
Why these six and not others
They are the artifacts three different parties ask for, for three different reasons. The Division of Examinations said in its FY2026 priorities, announced November 17, 2025, that it will assess whether firms have implemented adequate policies to monitor and supervise their use of AI technologies. Cyber insurers have begun asking financial services firms to evidence AI governance at renewal — tool inventory, risk assessments completed before deployment, and where human oversight sits (ACA Group, July 23, 2026; a consultancy that sells governance services, so directional). And an acquirer’s diligence list is close to the same list.
What this result is not
It is not an assessment of your compliance program, and it is not regulatory advice. Whether a given transcript is a required record, or whether a given incident triggered a notification obligation, is your compliance consultant’s judgment. We do the other half: build the register, capture the record, configure the tenant, and keep producing the file.