01
Control what can be said
Disposition control determines whether a response can be delivered, qualified, or escalated.
AI governance for wealth management determines what AI may say to clients, how responses are evaluated, and whether past interactions can be reconstructed and explained.
Interaction-level evidence
Evidence chain · NV-0714-104218
01
Client question
Why did my portfolio fall today?
02
Answer
Technology exposure explains most of the move.
03
Controls applied
Contextual · advice boundary clear
04
Sources + context
Portfolio · house view · market data
05
Evaluation
Grounding · disclosure · disposition passed
06
Replay record
Response · state · versions · timestamp
The evidential gap
Traditional governance establishes policies, controls, and accountability at the system level. Client-facing AI also requires interaction-level evidence: what information was used, which controls applied, how the response was evaluated, and what was ultimately delivered.
Five questions determine whether a client-facing AI interaction can be reconstructed and defended after the fact:
01
What exactly did the system say, and to whom?
02
What information did it rely on — portfolio state, market data, house views, client profile — as of that moment?
03
Why was the response permitted? Which disposition did it receive — factual, contextual, or handoff to the relationship manager — and which controls evaluated it?
04
What was the system's configuration — model version, rules version, knowledge sources — at the time?
05
Can the interaction be reconstructed from preserved evidence?
This is a practical five-question framework for regulator-defensible AI.
Event logging versus reconstruction
Application logs can show that an output was produced, timestamped, and stored. They often do not preserve the full historical context required to explain why it happened: the model and rules versions, retrieved sources, client and portfolio context, disposition decision, evaluation evidence, and final response.
Logs may form part of the evidence. Interaction-level reconstruction requires the relevant response, context, controls, versions, and evaluation evidence to be preserved together.
Evidential architecture
Moving from governance principles to interaction-level evidence requires three connected controls:
01
Disposition control determines whether a response can be delivered, qualified, or escalated.
02
Responses are assessed for grounding, policy alignment, disclosure completeness and accuracy.
03
The interaction record retains the context required to reconstruct and explain what happened.
Interaction-level reconstruction
Verifiable replay is the reconstruction of a historical AI-client interaction from preserved evidence: the delivered response, inputs, client and portfolio context, retrieved sources, disposition, model and rules versions, and evaluation results.
Replay does not mean rerunning a probabilistic model and promising an identical new output. It means presenting the original interaction and the state and controls that produced and permitted it, as they existed at the time.
Illustrative replay record
Interaction NV-0714-104218
Client question
10:42:18 SGTWhy did my portfolio fall today?
Delivered response
ContextualYour technology allocation explains most of today's move. The portfolio remains within its target range; this is context, not a personal recommendation.
Control outcomes
Retrieved sources
Historical state
Replay record assembled
Original response, historical state, sources, controls, versions, and evaluation evidence presented together. No deterministic rerun implied.
Regulatory landscape
Formal requirements, supervisory direction, and industry frameworks differ by market.
Supervisory direction
In the United States, SR 26-2 excludes generative and agentic AI from its model-risk guidance while directing banks to govern tools outside its scope through broader risk-management practices. This makes demonstrable governance and evidence around AI outputs increasingly important.
Formal requirements
In the European Union, the AI Act emphasizes traceability for high-risk systems, while DORA strengthens operational controls, logging, and record protection. Together with existing conduct obligations, these requirements increase the need for reliable records around client-facing AI activity.
Accountable AI + SAFR
In Singapore, accountable AI principles emphasize governance, transparency, and human oversight. SAFR, developed under MAS's BuildFin.ai initiative, adds a supporting industry framework for runtime controls and recordability; it is not regulatory guidance or a statement of supervisory expectations.
Taken together, these developments point toward stronger runtime controls, preserved records, and inspectable evidence.
Demonstration, not attestation
A board, compliance, architecture, or security team evaluating client-facing AI should require demonstration — not attestation:
Ask us to demonstrate all five against a real interaction.
FAQ
AI governance in wealth management is the set of controls that determine what a firm's AI may say to clients, how responses are evaluated, and what evidence is preserved for later supervision, review, or dispute resolution.
Verifiable replay is the reconstruction of a historical AI-client interaction from the preserved response, inputs, context, sources, controls, versions, and evaluation evidence. It does not mean rerunning a probabilistic model and promising an identical new output.
Ordinary application logs often record outputs and events but not the complete historical state needed to explain them. A replayable record preserves the model and rules versions, retrieved sources, client and portfolio context, disposition, evaluation evidence, and final response together.
Client-facing AI in a regulated institution should not give personal financial advice unless the full suitability, disclosure, and recordkeeping obligations that apply to human advice are met. Nextvestment's architecture classifies every response as factual information, contextual explanation, or a matter for the relationship manager — and routes anything approaching personal advice to a human, with the classification itself recorded.
SAFR — Safeguards for Agentic Finance at Runtime — is an industry reference framework published under MAS's BuildFin.ai initiative in July 2026. It is not regulatory guidance or a statement of supervisory expectations. It is one signal in the broader direction toward runtime controls and inspectable evidence; the five-question framework on this page is a practical test for client-facing AI, not part of SAFR.
In production, no. POEMSGPT, the AI assistant inside Phillip Securities' POEMS platform, operates under full disposition control and evaluation in a MAS-regulated brokerage — and AI conversations convert to investment actions month after month. The governance is what makes deploying AI in front of regulated clients possible at all.
Responsible AI frameworks define principles such as fairness, transparency, and accountability. The five-question framework focuses on the interaction evidence a regulated wealth institution should be able to produce after the fact.
For boards, compliance, and digital wealth leaders
Nextvestment is the AI engagement and intelligence layer for wealth management, live inside regulated institutions across three regulatory regimes. Ask us to replay an interaction.