About a-team Marketing Services
The knowledge platform for the financial technology industry

A-Team Insight Blogs

AI Expands Buy-Side Compliance Remit as Resources Remain Flat

Subscribe to our newsletter

Four in five respondents to a survey of US investment advisers use artificial intelligence, but many have yet to put testing, validation and third-party oversight behind that adoption. Around 60% of chief compliance officers also hold another executive role, so the added AI duties sit alongside their existing responsibilities. Amended Regulation S-P also requires advisers to scrutinise how vendors protect customer information; 67% of respondents reported difficulty securing confirmation that service providers would notify them within 72 hours of a breach.

Together, these findings in the 21st annual Investment Management Compliance Testing Survey show that the buy-side compliance remit is growing faster than the resources assigned to it.

ACA Group, the Investment Adviser Association and Yuter Compliance Consulting surveyed 411 investment management firms during April and May 2026. Some 85% of respondents identified AI as the leading compliance issue, up 28 percentage points from 2025 and well ahead of cybersecurity at 37%.

In conversation with RegTech Insight, Aaron Pinnick, Senior Manager, Thought Leadership at ACA Group, said the findings show compliance teams taking on more responsibility for technology governance, enterprise risk and third-party oversight.

“The story I see is a story of a function whose resources may not be necessarily keeping pace with the continually expanding mandate of the compliance function,” he said.

AI Governance Moves into Testing

Investment advisers have adopted basic AI controls. Eighty-six per cent have policies governing employee use, and the same proportion maintain an inventory of approved AI tools. Fifty-nine per cent have established an AI governance committee, while 72% have updated employee training and increased AI-related compliance testing.

The report says firms still need to improve AI-output validation, oversight of third-party AI use and incident-response planning. Pinnick said AI matters to compliance teams because each new use creates additional oversight obligations.

“That sort of hot compliance topic comes with more work, it comes with more testing, it comes with more responsibility,” he said.

Compliance officers may not lead every AI project, but firms increasingly expect them to set policies, define acceptable use, train staff and test controls. They must also manage risks associated with non-deterministic systems, including unreliable outputs, model manipulation and operational disruption.

Pinnick said firms now need to test and validate AI systems and understand how service providers use AI on their behalf. That shifts the RegTech requirement from maintaining approved-tool lists to recording tests, validation results and third-party AI use.

A Wider Remit for Dual-Role CCOs

The broader remit is falling on compliance functions whose structure has changed little. Forty-five per cent of respondents employ between two and five compliance staff. Another 10% have no dedicated compliance employee or outsource the CCO role.

Only 40% reported that their CCO works solely in that position. Other firms combine the role with chief operating officer responsibilities at 19%, general counsel at 17% and chief financial officer at 12%.

Pinnick said staffing levels and budgets have remained broadly flat for five or six years, even as firms have assumed new obligations covering AI, privacy, cybersecurity and vendor risk.

“We are approaching the point where it’s becoming increasingly difficult for compliance programs to operate effectively, operating as lean as they are,” he said.

Pinnick said the resources needed for an effective compliance function depend on a firm’s size, business model, clients, activities and risk profile. He said the programme needs policies, training, controls, testing, regulatory readiness and documentation, backed by external or internal validation that the controls work.

“So just saying all of that out loud, that’s a lot of work for one person,” he said.

Pinnick expects firms either to add compliance resources or recast the role around broader governance, risk and compliance responsibilities.

Third-Party Due Diligence

The SEC’s recent amendments to customer data protection, Reg S-P, now requires covered institutions to maintain incident-response programmes and oversee service providers through due diligence and monitoring so affected customers receive the required notifications.

Eighty-three per cent of respondents had updated their policies and procedures, but only 53% had formalised an incident-response plan. Thirty-four per cent had mapped their non-public personal information, while 28% had conducted due diligence on vendors’ breach-notification policies and plans.

The survey ran during April and May, before the 3 June 2026 compliance deadline for smaller firms. ACA said that timing partly explains the remaining gaps.

The greatest implementation problem was securing confirmation that service providers would notify advisers within 72 hours of discovering a qualifying breach, cited by 67%. Forty-eight per cent had also encountered difficulties negotiating vendor-oversight arrangements.

Pinnick said the issue tends to arise in two circumstances. Smaller advisers may doubt their ability to obtain assurances from large technology providers. Other firms depend on transfer agents or specialist providers that would be difficult to replace. That dependence weakens their position in contract and oversight discussions.

Pinnick observed that regulators deliberately set a lower notification threshold for service providers in part, because one breach can affect many advisers and clients. As he put it: “If you breach one third party, you can breach an industry,” he said.

Subscribe to our newsletter

Related content

WEBINAR

Recorded Webinar: Sponsored by FundGuard: NAV Resilience Under DORA, A Year of Lessons Learned

The EU’s Digital Operational Resilience Act (DORA) came into force a year ago, and is reshaping how asset managers, asset owners and fund service providers think about operational risk. While DORA’s focus is squarely on ICT resilience and third-party dependencies, its implications extend deep into core operational processes that are critical to market integrity, investor...

BLOG

ISDA Taps Gentek AI for DRR Traceability Tool

The International Securities Swaps and Derivatives Association has selected Gentek AI to build a traceability tool for Digital Regulatory Reporting (DRR). Gentek will develop a tool designed to let users track the history of DRR decision-making and connect coding choices back to regulatory requirements. The story behind the announcement is that Gentek comes to the...

EVENT

Digital Assets & Tokenisation Summit, New York

A-Team Group’s Digital Assets & Tokenisation Summit spotlights how global financial leaders are rapidly embracing programmable tokenised assets and DLT networks to achieve real-time, 24/7 peer-to-peer transactions.

GUIDE

AI in Capital Markets Handbook 2026

AI adoption in capital markets has moved into a more disciplined phase. The priority is now controlled deployment: where AI can be used safely, where it can deliver measurable value, and how outputs can be governed, monitored and evidenced. The 2026 edition of the AI in Capital Markets Handbook examines how AI is being applied...