
The Ncast · 2026-06-02 · 40 min
Key moments - from our scoring
Substance score
44 / 100
Five dimensions, 20 points each
Regulatory expectations around AI, cybersecurity, and vendor oversight are reshaping compliance priorities for wealth management firms, but regulators are largely applying existing rules rather than creating new AI-specific guidance. Holly Mason explains that the SEC and FINRA's approach to AI remains technology-neutral, relying on established frameworks around fiduciary duty, record-keeping, disclosures, and conflicts of interest - but enforcement actions and examinations will effectively set guardrails. The conversation addresses the practical reality of firms facing overlapping SEC and FINRA examinations, the critical gap in third-party vendor documentation and oversight, and the specific risks of deploying generative AI tools like hallucinations and bias. Mason emphasizes that defensible AI governance requires understanding technology capabilities, maintaining human oversight at critical escalation points, establishing clear policies about who can use which tools, and ensuring robust quality assurance around AI outputs. The episode reveals that firms remain underprepared on vendor management, client-facing AI disclosures, and the explainability requirements FINRA now demands - making this essential listening for compliance officers navigating the intersection of existing regulations and emerging technology risks.
No - regulators are taking a technology-neutral approach and applying existing rules around fiduciary duty, record-keeping, disclosures, and conflicts of interest to AI. Enforcement actions and examinations will establish guardrails, following a historical pattern established with email, Knight Capital, and other technology shifts.
Third-party vendor oversight, specifically the lack of documentation about why vendors were chosen, what capabilities they actually have, and confirmation that they're delivering the functions firms assume they are.
Firms must accurately describe how services incorporate AI technology, balance benefits with appropriate risk disclosure, and explain what AI is actually doing so clients can make informed decisions.
Establish policies defining who can use generative AI, require human oversight and quality assurance checks on all AI outputs, and avoid replacing human judgment with AI - especially for client-facing applications.
Yes, overlap is common in fraud, AML, and cybersecurity examinations; firms should proactively inform examiners of prior disclosures and documented steps rather than recreating work.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode offers some useful framing - particularly the historical technology-neutral regulatory approach and 'rule by examination' as the practical source of AI guardrails - but is heavily padded with generic compliance advice ('have a checklist,' 'have conversations,' 'document things'). Novel claims per minute are low.
it's not about the rule. Let's follow this rule. What ends up happening with this approach is that just like in you know the Nike case or all of these, you know notice to members, we started seeing sort um of rule by examination
what's their change management process, right? When they implement, they change things, right? They, they change how it, how it looks to a customer, how they process things, where they store their data
The most original contribution is grounding AI regulation in a decade-long historical arc (1998 email confirmations, Knight Capital 2013) to argue that 'rule by examination' is the real enforcement mechanism - a genuine insight. Everything else recycles standard compliance tropes without a contrarian angle.
if you go back to like for example like 1998 we had the. When everyone is sort of saying can you really send my statement via email? Can you really send my confirms via email?
we started seeing sort um of rule by examination and I know that there's been, that has also been a topic of conversation in other circles
Holly Mason has authentic multi-sided practitioner credentials - FINRA senior enforcement counsel, FINRA arbitrator for over a decade, in-house counsel at major institutions, and COO of an RIA - giving her legitimate standing to speak across regulatory, litigation, and operational dimensions. Not a pure thought-leader.
I did serve as chief um, operating officer for a smaller IRA which you know it had 12 to 15 investment advisors
she held uh, members accountable to finra. She's also a certified FINRA dispute resolutions arbitrator for more than a decade
The episode has a handful of specific anchors - Knight Capital (2013), FINRA's 2026 oversight report, cases in New York/Delaware/Minnesota - but no dollar figures, no named enforcement actions beyond passing references, no rule numbers cited, and advice stays largely at the level of principles rather than concrete metrics or timelines.
we had the Knight Capital case right with the SEC in 2013
FINRA's 2026 oversight report, they specifically call out hallucination bias and cybersecurity risk
The host brings a useful practitioner framing (banking vendor management parallel, minimum viable oversight program question) and occasionally sets up good topics, but reflexively calls every answer 'a great question,' never pushes back on vague claims, and frequently pivots to sharing his own views rather than extracting more from the guest.
That is a great question and I think it sort of starts in the Wayback Machine if you will
what is the minimum viable oversight program look like? And my theory is that this has really been shaped by a lot of class action lawsuits
Computed from the transcript - who did the talking, and the words that came up most.
Regulators aren't waiting for new rules before they start examining for compliance failures - they're applying existing frameworks to AI and vendor oversight right now, and wealth management firms that aren't prepared are already behind. Hollie Mason, Managing Director at Stout and former FINRA senior enforcement counsel, joins Rafael DeLeon to break down what the SEC and FINRA are prioritizing in 2026 exams, where the vendor oversight documentation gaps are showing up, and what defensible AI governance looks like for RIAs and broker-dealers.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Foreign.
Speaker B: Welcome to the ncas, the podcast where we bring you the sharpest minds in compliance, risk and regulation and make sense of what it all means for financial organizations navigating today's environment. I'm Rafael deleon, um, the senior vice president of industry relations and contracts. Having spent decades as a bank examiner and watching regulatory expectations evolve in real time, I can tell you the conversations I find most valuable are the ones that don't just explain what the rules say, but what it actually looks like when institutions are getting it right and wrong. Today's conversation is going to be one of those. My guest is Holly Mason, managing director with Stout and their financial services area and Stout is a global advisory firm. Holly brings a wealth of experience and something that's genuinely rare to this conversation. She has sat on every side of the table. Holly is a financial services expert with an advisor with Stout. She has spent her career at the intersection of securities regulation, enforcement and litigation. Presenting cases before arbitration panels, courts and regulatory bodies, conducting regulatory investigations and advising on rulemaking enforcement matters. Before her consulting work, Holly served as a senior enforcement counsel at uh, the Financial Industry Regulatory Authority FINRA where she held uh, members accountable to finra. She's also a certified FINRA dispute resolutions arbitrator for more than a decade and spent years as an in house legal counsel for major financial institutions handling complex brokerage clearing and investment advisor matters. In short, uh, Holly's done a lot of these things and she's either enforced it, arbitrated, litigated it or advised on it. Holly, welcome to the nclass. We're really glad to have you.
Speaker A: Yeah, thank you. Good morning. It's great to be here and great to have these conversations because typically they're very structured and uh, court related so it's nice to be able just to chat.
Speaker B: Is there anything I missed in your bio that you want to bring to uh, our listeners attention?
Speaker A: Um, it was pretty comprehensive. Um, the only thing I would say is that on the RA side since that's what we're talking about today, um, um, I did serve as chief um, operating officer for a smaller IRA which you know it had 12 to 15 investment advisors. Um, you know those that were state licensed as well as registered with the sec, they did insurance products, estate planning, you know, the regular, you know, securities trading as well. So that's another sort of perspective that I bring to this which I think your description was pretty good in terms of sort of that 360 view uh, of the industry.
Speaker B: So I appreciate it having like as I said for myself Been on both sides, having started off working at uh, banks, uh then working as an examiner and now on the board of directors. So really seeing it, you know, from all perspectives as well. But I'm really glad to have you because we've got a focus on wealth management and registered investment advisors, wealth, you know, managers and what's going on. Can you give our listeners a quick snapshot of what you're seeing on the ground right now and what's keeping those compliance officers up at night?
Speaker A: So I think we're um. It's no surprise, I think that most uh, folks in the industry, um, wherever you're seated are you know, keeping a close watch on you know, fraud related um, fraud related, uh, issues and um, you know, risk management in general. And I think you know, we're seeing those where you know, if they're shifting from you know, your retail client to maybe your relationships with vendors. So um, I think this administration as well as um, you know, sort of the messages that they've been uh, putting out, everyone is sort of focused in on you know, those, those fraud related um, issues as well as you know, customer harm and all of those which we, which sort of plays into standards of care. Um, the other thing, um, I think, you know I've been um, hearing about is the SEC's task force on um, you know, sort of RIA sweeps that have this insurance arm, um, and they're looking at it and the SEC is always looking at conflicts of interest. But I think this one is, has a little bit different twist to it um, in terms of conflicts of interest. And so that's another one that I um, think people are um, keeping their eye on. And again conflicts of interest is always, you know, something we're um, focused on. And anytime you're a dual registrant or you know, you have another business arm or even in the instance where you have maybe your CCO is also your CEO, uh, or plays dual roles and you know, and a lot of the middle, you know, the mid sized firms as well as you know, some of the smaller firms, you know that dual hat is necessary and um, but it just requires a little bit more um, thought and planning in the risk management area.
Speaker B: Um, well, I agree with you. I think a lot of these issues and one that you know, I also want to talk about is here is what we're seeing around AI, uh, what we're seeing uh, with vendors, uh, in particular. Um, so there's uh, really a phrase that's really kind of floating around in regulatory circles that the existing Rules already cover it and regulators seem to be saying they don't need new AI specific rules. Do you buy that? What do you think of that? What does that actually mean for some of these RIAs and broker dealers that are trying to figure out where the guardrails are?
Speaker A: That is a great question and I think it sort of starts in the Wayback Machine if you will. Um, it's not that I don't buy the regulator's approach to this. I think that um, it's one that has historically been taken and um, it's technology neutral. We've heard it out of regulators mouths for a decade and while the SEC had a little um, rulemaking, um, proposed rule concerning conflicts and AI I think you know, generally you know they are this technology neutral and I'm sort of dating myself maybe. But if you go back to like for example like 1998 we had the. When everyone is sort of saying can you really send my statement via email? Can you really send my confirms via email? And so you know those things we had you know notice to members and uh, we had you know the, and then if you go forward we had the Knight Capital case right with the SEC in 2013. So all of these are technology updates. We're not strangers to technology updates in this industry and I think it's a position they've taken. And I think the important part here is to say that it's not about the rule. Let's follow this rule. What ends up happening with this approach is that um, just like in you know the Nike case or all of these, you know notice to members, we started seeing sort um of rule by examination and I know that there's been, that has also been a topic of conversation in other circles that you know the SEC says they're not going to do that anymore. There's going to be some cooperation. But for in this instance I think with AI and technology I think that's, that's what I think we can expect with these examinations. And maybe it's just a heads up to begin with but you know enforcement and these things were really, really going to get the guardrails from those activities. And that's not just me saying that's a decade of historical data on the various different steps we've taken in this technology universe.
Speaker B: Right. Well again I think it's, it's great to frame it just, even in just technology because what the spillover has been and where I see uh, some parallels, uh, albeit a little bit different but is around vendors, uh, and vendors use of Technology and on the banking side I've seen and watched the evolution of kind of these rules with vendors, vendor management come into place. But for at least um, banks um, and credit unions. Following that we've moved into more of a plug and play dynamic and area. Whereas before everybody was tied to a core so you weren't really having to manage multiple risk. And now with a lot of different companies coming on and they're having access or may access customer data and how that impacts uh, those crown jewels of the organization, uh, I see that uh, again with banks and credit unions that they've had 20 years to kind of learn this and get up to speed and kick and scream the whole way like we don't really need to do this. And yet we've seen with breaches and other attacks that really you have to know who you're dealing with uh, and uh, in the same area. So I do see those parallels. Uh, and then now with technology we're also talking about cybersecurity issues and how they impact whether the institution itself or through uh, the vendor. That goes back even to the target data breach that we saw. Uh, and then with AI, so you layer on these complexities that a lot of vendors and companies are taking on and it does create some concerns. So if you had to point an RIA compliance officer um, to the three rules they should be watching most closely as they evaluate or implement AI tools right now, record keeping disclosures, uh, conflicts, which ones rise to the top and why?
Speaker A: Well I think all of those are at the top of the list and just because that's what we're seeing um, and not necessarily in enforcement necessarily but we're seeing it in uh, notices and um, um guidance from our um, applicable regulators. And so I think they're seeing things that they don't um, like or repeated issues in these areas. And so they have said that this is what we should pay attention to. And I think you know, in rule based with AI is again back to there's you know, this technology neutral, all the rules you know, apply and they apply just fine to this new technology. But I think you know there's some um, principles here that we can you know, take away and I think that's where firms are focused is these principles. And you know we've been helping firms with checklists and things and you know, prioritizing um, but as you know I think we're going to talk somewhat later about third party vendors but being aware of technology limits, um, establishing an AI governance and not replacing vendors for um in house sort of knowledge you have to have some in house knowledge to be able to function and, and identify those risks and you know, knowing where your data is just like the record keeping and you know having a strategy I guess is you know, sort of these principles that um, sort of all encompass these, these rules and these um, points of interest you pointed out.
Speaker B: No, I agree with you. It is, it, it really always goes back to strategy. In any case, what do we do? What are we going to do in this situation and what are we going to do if. And that gets right back to business continuity planning and it's easy to sit
Speaker A: here and say yes, have a checklist and y. I do say that they start conversations and since these things are very um, business tailored or um, offering specific then you really just do have to have those conversations with the right people in the room and creating your own risk profile. Again, we start those conversations with firms we may see something they don't or you know, just from an outside perspective but having the conversations is a really good place to start and keeping an eye on where regulators are, you know, seeing issues.
Speaker B: So you know, on that where regulators are seeing issues. Both the SEC and FINRA have flagged fiduciary duty, cybersecurity and AI as top examination priorities. And there's real overlap between the two regulations in the space for an ria. What does that coordination actually mean in practice? And are firms looking at a double barrel examination risk?
Speaker A: So, and that's another great question and another very way back machine historical sort of complaint in the industry. And even when I was at finra, that's um, that's something you know, firms identified as a real sore spot and I think there's been some really good developments um, on that front. But you know, you said looking at FINRA's priorities and the SEC's priorities and even state priorities right now because you know, some of that, you know, um, enforcement and various different topics have sort of fallen to states just because of the SEC has other priorities or other things. So again we're dealing with a lot of you know, folks that have overlap and in terms of you know, the SEC and finra, I think the SEC has come out and said they're going to try to avoid this overlap. But you know I, I think you're right. I think firms are still going to see some, some overlap and just based on my experience as a regulator, you know, call it out like say, you know, because you know, as much as we um, as ah, a regulator, you know, try to stay Connected sometimes that's just not, you know, possible and you know, saying, look, we've done this before, we' this now, we just disclosed this, here's our production for this is very helpful and is not going to, you know, give anyone pause on, on, on that side. I would say that's just my experience. But you know, call it out and, and just don't, you know, recreate the wheel if there is some overlap there. And you know, with Regbi we've seen overlap and I think fraud, we're going to see an overlap. Aml, we're going to see an overlap and, and whether it's policies and procedures or it's um, you know, processes or um, those types of things, I think truly, you know, as much as we avoid it, um, and we think everyone plays in their own space and in these, you know, I'm going to enforce this side and you enforce that side. You know, industries are enterprise and you're talking about banks and owning broker dealers and you're talking about broker dealers, um, having RAs and you know, um, so there is a lot of overlap and in terms of even just the corporate structure and who um, is, you know, related to who. And so I think we're still going to see some of that, you know,
Speaker B: and that really gets to managing these risks because they're important to you. Not trying to play to what the regulators are going to be looking for and asking, because I know from my vantage point, and I'm just seeing this again, uh, uh, recently is in the absence of regulation, you have different examiners, different people from different sides where there is overlap, asking different questions based on. There may be some synergy there, but each one has a bias and uh, thinks uh, that certain things are important. So if you're trying to play for that, you're going to be getting a lot of different questions depending on who is asking the question and you can't always assume it's going to be the same person.
Speaker A: And that's a great point because, you know, it's like chasing your tail almost in terms of that. So, you know, we always help clients sort of have a basis, an explanation, um, you know, to say and to understand the reason behind the decision and the person sitting in the seat, whether it's compliance or otherwise understanding I'm pushing this button for this reason. And you know, most of the time that thoughtful process and you know, those documented decision points and those things are more important than trying to predict with a crystal ball, you know, who's going to ask what question on what topic? I do know, um, you know, again, sitting in the seat inside firms, they do, you know, look at those very carefully. Just because it's a conversation, again internal, to say, hey, we should maybe take a look to see if any of these things pop up for us. And that's, you know, that establishes sort of those customary practices, those you know, standards talking to your industry folks to say, how are you handling this? And um, so it starts good conversations. And um, it also flags things that may not have been on their radar because of interpretations or before, um, things they're seeing. So.
Speaker B: Well, financial services firms like yours with Stout really uh, end up being a good kind of clearinghouse because you've got a lot of customers, they're sharing with you what they're hearing from exams, um, and uh, so you have a better understanding to share with more of your clients across the board. And really in terms of that, uh, and these areas of overlap, um, where do you think firms are most underprepared right now?
Speaker A: That is a great question. And I think, you know, I think generally, um, I'm seeing sort of this gap in third party vendor oversight. And I know that we're, you know again talking about that in the context of AI, we're talking that um, in the context of um, um, other things too. But I, I really do um, see that and whether it's um, you know, lately I've been seeing with um, on the litigation side that you know, a lack of sort of documentation about oversight of that um, third party vendor for whatever reason you have them. And I'm seeing you know, some pain points there with you know, documenting for example choice. Right. Um, or understanding the capabilities or um. Again you think your third party vendor or your third party relationship is doing this function and it ends up that they're not or you know, so all of those clarity issues that come with um, working with other industry partners or third parties, um, I am seeing that come up over and over again.
Speaker B: Yeah, I'll come back, we'll come back to that when we talk about some of these third parties. But I have my own theories on, on really what starts to shape that. Um, FINRA has flagged that AI driven communication needs to be accurately described. Needs uh, to accurately describe how services incorporate AI technology and balance benefits with appropriate risk disclosure. That's a pretty high bar. How should RIS be thinking about that? Explainability.
Speaker A: Yeah. And I think um, that goes back to you know, knowing your technology and understanding where that sits and what it actually, how it functions and um, and sitting down and really thinking about, you know, things like conflict and conflicts and um, also then I guess most of, you know, disclosure, um, you know, we're talking about, you know, again, conflicts of interest or, um, you know, communicating with folks about, you know, what you're really offering. And so I think, you know, some of those things to say, you know, what you're representing to your clients. Always client facing, we know that that's at the highest risk. Right. Anything client facing in terms of AI functionality is always going to be under a microscope and at the highest risk of possible. So just, just being aware of where your, um, technology fits in that scale of risk and then, you know, making sure that again, you're aware of those functions and making those proper disclosures to your clients so they can make a decision and understand, you know, what's happening if they, they use that or how you're using it. Um, and so it is really just about those conversations, um, internally and thinking about it from whether it's the client perspective or conflicts perspective. Um, but yeah, I think just even
Speaker B: addressing it, um, well, in FINRA's 2026 oversight report, they specifically call out hallucination bias and cybersecurity risk, uh, as control areas firms need to address when deploying generative AI. And we're seeing that, we're all seeing that. And I think people in the market are excited and fearful at the same time. They're excited because it looks like a fantasy. It's going to help me with a lot and concern because we don't really know all of these concerns. I think again, we've been talking about hallucinations for the last past year. We've seen that ourselves if we're user of that technology. Um, so what does that look like in terms of defensible AI governance look like, uh, for wealth management firms?
Speaker A: Yeah. And so the, I know it's a, it's a, it's a really great tagline, hallucinations. Um, and I, I kind of like it because it, it sort of says, it makes it exciting to talk about and you know, being in this industry, compliance risk, it's so, you know, boring sometimes, whether you're at the dinner table or at work or whatever. But, um, to make it exciting, hallucinations. Um, so hallucinations for, you know, RA firms and those things. Um, and folks, you know, on that level, it's really about, um, again, back to understanding your technology. And it's, again, it's the learning part. If you're not, if you're not using Genai and Learning applications, that's, you know, that's different. Um, but most firms we're talking to and assisting, we're saying, you know, look, having a policy and explaining what technologies are available and how that information is, um, you know, processed and um, how it's used is pretty important. And controls who needs to use it, who doesn't, you know, and those types of things are important. Hallucinations really just means that your technology is taking in information and learning from various sources. And so, uh, again, it's creating information from the information that you're inputting. And so again, that's a check and balance to say, is that really accurate? And I think FINRA and the SEC have also said that, look, you're not going to replace human oversight and interaction, which is again, conversations that need to happen to say, at what point do we need somebody looking at this? What is, you know, what is this technology creating? And when do we need that oversight? Um, and that person sort of at that escalation point.
Speaker B: And we're still seeing these issues pop up in the news with larger firms, how they've been impacted by data that was incorrect or that had been, you know, there were hallucinations in there. I do like the term. I didn't ever think we would be talking about hallucinations exactly. But, uh, what does this mean? But I think it really, bottom line for our listeners is this just said this is a tool and how does this tool perform? And we have to constantly calibrate it, check it to make sure it's working for us and giving us the responses we need. And so it kind of puts the onus back on us. And what type of QA are we doing around any outputs from AI?
Speaker A: And from our perspective as experts and consultants and myself as a lawyer, you know, we're looking at it too from that perspective. And I think you're right. And you know, some of the, you know, first cases or slaps on the hand we're seeing, and you know, whether you consider them slots on the hand or not, but, you know, lawyers are, are being sanctioned and experts, um, reports are being thrown out and it's because of the way that they have implemented, relied on or cantic explain their use of, of AI. And in our universe of litigation, you know, we're looking at, you know, rules of evidence and those types of things and you know, reliability of, um, you know, findings and data. And so all of those things are the reason we're seeing these outcomes. And it is really about, you know, we have, I mean, cases in New York and Delaware and you know, um, Minnesota talking about, you know, chatbots and experts testifying that I'm not sure how, how we got there. And so again it is um, a lot of clients and we're actually, you know, as a firm, you know, talking about how we're using AI and you know, I've had, I've had clients say we were not in a position for you to use it. So, so you can't use it at all because we don't want to go down that road. And I think you're going to see that for a while until we see the impact in our federal rules as well as seeing maybe some best practices that give us a little more guardrails in our universe. So you're right, we are seeing some repercussions in other areas, um, outside the regulatory world, um, where folks are not quite grasping um, the implications of using it.
Speaker B: Well, I think in any tool that we're using we really need to, especially in the financial services space, need to be able to defend our position. Is it auditable, is it accurate? And when you were talking about compliance and again how that kind of can get boring at times, the problem is you can't be only 80% right, because over time that just creates more and more problems for you. And you were basing something on an answer that was 80% right. So where do we go to find that information? And I don't think as generative AI is still new, people are not understanding these questions to really understand.
Speaker A: Yeah. And I think you know, FINRA does a really good job of defining um, in their, you know, their materials, each, what they consider the, each type of AI. Right. And I think you know, so firms, you know, can you know, have good reference points. And I think you know, again the SEC has, you know, just formed you know, um, a group and you know, talking to the industry about you know, AI usage and at least our, you know, our surveillance of the industry is that most folks are really dipping their toe into it for whether it's you know, reviewing, reviewing documents or maybe advertising or you know, just small snippets in the process of other, other functions. And you know, I think you know, the regulators are interested in, you know, how this is going to develop, how firms see, you know, themselves using it, who's spending the money on um, developing their own versus third party vendors. But all these conversations are happening and um, so, but it's developing quickly. So even our conversation here, um, on this recording will be outdated next year because firms will be using it differently and there will be different issues. And so yeah, these conversations are really important and I um, think you know, having, having assistance or getting assistance if you don't have the expertise in house or you know, seeking that um, you know, view of what other people are running into, whether it's industry, um, committees or whether it's talking to, you know, similar um, folks at firms that look like you, or if it's you know, hiring consultants because they see other, you know, um, have other clients and they're, they kind of have a handle on, you know, the issue from various different vantage points. Whatever it is for you, that's it. It's important to stay engaged.
Speaker B: Right. So when um, as we kind of switch over and wind down around third party risk management, uh, FINRA has really called out third party riskman as a, another return priority for 2026, you know, indicating that a single incident at a critical service provider can affect large segments of the industry. And so for a lot of AIs, as you mentioned a minute ago, they're either going through the spend of, you know, building their own, but the majority are buying tools from vendors rather than building in house. So as you know, from your legal kind of uh, point of view, what type of due diligence questions should they be asking before they sign that contract?
Speaker A: Yeah, and I think, you know, it starts with your initial research as well because I don't know about you, but you know, I, I get emails with you know, vendors that can do this with AI or can do that with AI and it's very um, it's, it bombards me in terms of how many firms are out there doing, you know, things with AI or can help you with, you know, these things. And um, and so doing that up front, you know, sort of taking a look at, you know, vendors that are established and they have the security protocols and you know, so it starts with that sort of due diligence and asking those questions about you know, their use of data, their you know, privacy policies, their um, again the um, cyber, cyber, you know, structure. So um, and then you know, talking, having everyone at the table. I know, um, when I, when I was in house, nobody wanted to come to legal but you know, involve them and compliance and risk and sit down and you know, and business partners too and say, you know, let's, let's vet these and see do they have the functionality, do they have you know, uh, the security we need and sort of go through that process in selecting them and select somebody that has a reputation and has worked out the kinks. Um, and then you kind of get a sense too of um, oversight and how that works and what you're going to have access to. And um, when you're asking those questions and sitting in a room and deciding on vendors to say, you know, how are we going to do this process? We have this process for oversight, how does that fit in to our relationship with unstructure? And contracts are important in identifying access and parameters and what they will be doing versus what you'll be doing. It also helps um, understand when you're telling regulators, look, we've hired this third party, um, we understand what they do, they understand what we do. And um, this is what we're using it for and how we've implemented it. So um, I, I think all of those questions are important, um, and particularly in identifying um, what type of vendor, who, who to go with. And um, you know, sometimes that depends on what AI function you're going to be utilizing them for. Some are very specialized and some are more general. And um, that's a conversation, you know, from a business strategy standpoint or you know, do you want five different vendors or do you want one that can do everything? You know, so those are the types of considerations, um, that conversations that are being had. And you know, I think people who are considering it in terms of third party vendors,
Speaker B: I think one of the, you know, one of my last questions here is, you know, we're talking about vendor oversight, but you know, what is the minimum viable oversight program look like? And my theory is that this has really been shaped by a lot of class action lawsuits that have been out there because every data breach that has happened or breach, there's a class action lawsuit. And I keep advising customers that I'm dealing with is like, it's not the regulators, it's your practices. And you just touched on that a minute ago. Do you have a process for looking at your vendors? So give uh, me your take on that.
Speaker A: Yeah, I think documentation about that is key. And you know, even, even statements, I've worked with firms that don't even have a statement in their policies that say we rely on this vendor for this function or we've, we've um, delegated that to um, you know, the over. We've, we've delegated that process to this vendor. And so it's important to identify who is doing what, make sure that you can delegate that and also then you know, identify that and how you're, you're overseeing it. And again being clear and documenting the fact that that's what's happening. I, I agree with you on the class actions for sure. I think they are sort of, um, and that's on you know, the retail civil side, of course. And like you said, the regulator side is, you know, I've seen when not too long ago we were asking the question, you know, when do we report? Like 45, 30, you know, there was some, you know, issues there with gosh, you're going to get reports every five minutes if this is the standard. So there were conversations around that too. Um, but I think in when do we disclose, when do we have to put that incident, you know, in our, you know, public 10Ks or you know, or when do we have to do a special filing? So the conversations are happening on um, the regulatory side with that and like you mentioned earlier, even with AI and disclosures, um, those conversations are happening. But I, I um, want to, I want to close with one thing that I think, um, you know, from a third party vendor selection and whether it's AI or anything else, because I know that that's a focus right now for everyone. Um, I think you know, you asked about questions that they should ask and I wrote down some things that I'm seeing and wrote down, you know, some um, things that I think um, are important. And when you're considering vendors or even you have a vendor, um, even just doing, you know, a revisit of these, um, you know, what's their change management process, right? When they implement, they change things, right? They, they change how it, how it looks to a customer, how they process things, where they store their data, um, they add, they add things. How do they communicate that to you? Because they may not necessarily know how that impacts you from a disclosure or regulatory standpoint. So having that conversation with those vendors is important. Um, technology support expertise, right? If you're relying on their expertise, what does that look like? Um, and um, if you're relying on them for technical support, say you do have a cyber incident or you do have a down function, um, that clients can't use or hey, look, we have to do this, you know, supervisory process and this thing isn't working or whatever it is, um, just, you know, what, understanding what kind of technology support and expertise that they have that you can lean on because that will shape what you need and um, in terms of expertise as well as um, how you communicate and how you sort of your uh, business continuity, planning, all of those things are sort of interrelated. And then, you know, I think when I was you know, looking at vendors in house. You know, it's always that relationship or ecosystem or how are they going to connect with your firm? Is it, you know, behind the firewall? Is it just clearly a, um, third party? Or how is that, how is that going to fit into your processes generally? And, um, it's always good to have a vendor that is willing because our industry changes so often. You know, this, like, regulations change all the time. And so to work with a vendor that understands that and, you know, flexibility and, um, has some capabilities to build out things that may, um, may be required because things change or even, you know, industry things on your side, like change in product or change in client focus or, you know, all of those things. You want, you want to have those conversations to, you know, vet and see what that looks like, right?
Speaker B: Well, Holly, this has been exactly the conversation that I wanted to have, and I think it is helpful for our listeners. Very direct, practical, and grounded in what's actually happening on the ground. So, um, thank you for your time today. Thank you for sharing your expertise. And until next time, stay engaged and stay proactive. Thank you.
Speaker A: Thanks, everyone.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.