Financial institutions are increasingly integrating artificial intelligence (AI) into compliance, communications and operational functions. As adoption expands, financial services organizations are also considering how existing regulatory requirements apply to technology that was not specifically contemplated when many of those rules were established.
During a panel hosted by technology firm Red Oak, securities lawyers, compliance executives and technology providers discussed regulatory considerations surrounding AI adoption. Panelists emphasized that the absence of AI-specific regulations does not eliminate existing compliance obligations. Current requirements related to supervision, communications, recordkeeping, conflicts of interest and fiduciary duties continue to apply whether a task is performed by a person or an automated system, according to reporting from PYMNTS.
Existing Rules Continue to Apply
Regulatory enforcement involving AI is already occurring under existing rules. Brian Rubin, a partner at Eversheds Sutherland and former Securities and Exchange Commission (SEC) enforcement attorney, highlighted recent SEC cases involving “AI washing,” a term used to describe situations in which companies make exaggerated or misleading claims about their AI capabilities.
Financial institutions may also be asked to provide documentation regarding their use of AI tools. This can include information about who approved a tool, what information or data the tool can access, how its outputs are reviewed or validated, and what level of human oversight is involved.
These considerations can become particularly relevant when AI is used to generate client communications, recommendations, marketing materials or other information subject to existing regulatory requirements.
AI and Recordkeeping Requirements
The use of AI also raises questions about how operational data should be retained. Panelists noted that there is not a single, standalone rule establishing a specific retention period for all operational AI data.
Instead, organizations may look to the existing requirements that apply to the activity in which AI is being used. For example, when an AI system generates a client communication, recommendation or marketing material, the applicable recordkeeping and retention requirements for those materials may continue to apply.
Jamie Hoyle, vice president of product at MirrorWeb, also discussed the importance of maintaining accountability when AI technology is provided by a third-party vendor. While vendors may provide technology and related compliance features, responsibility for regulatory obligations generally remains with the regulated organization.
Documentation and Human Oversight
AI systems can generate and process significant amounts of information, creating additional considerations for organizations developing recordkeeping and compliance procedures.
AI interactions may produce records such as:
- Prompts entered into an AI system
- AI-generated outputs
- Dates and timestamps
- User identifiers
- Client communications
- Recommendations or other generated content
- Records showing human review or approval
Depending on the circumstances and applicable requirements, these records may become relevant to regulatory examinations, litigation holds or discovery requests.
Organizations using AI may benefit from procedures that identify what records are created, where those records are stored, how long they may need to be retained, and who is responsible for maintaining them.
Applying Existing Compliance Frameworks to AI
The regulatory framework surrounding AI continues to develop, but financial institutions remain subject to existing laws and regulations while new guidance and rules are considered.
For organizations operating in regulated industries, AI compliance can involve evaluating existing requirements rather than relying solely on whether a specific AI regulation exists. Recordkeeping schedules, supervision procedures, data governance policies and human-review processes may be areas for organizations to consider as AI becomes more integrated into operations.
For collection agencies and other organizations subject to federal and state recordkeeping requirements, these considerations can also extend to AI-assisted consumer interactions. Regulation F provides a three-year federal record-retention baseline for certain records, while some states have longer requirements for collection records. Several states, including Alaska, Hawaii, Idaho, Nevada, Oregon, West Virginia and Wisconsin, have six-year retention periods.
State requirements referring broadly to communications with consumers may also be relevant when AI-assisted communications are involved. As a result, organizations operating across multiple states may consider whether AI-generated communications and related records fall within the longest applicable retention period.
Every AI interaction can create multiple records, including prompts, outputs, timestamps and user identifiers. These records may potentially become relevant to litigation holds or discovery requests. Having processes to identify where such information is stored and how it can be accessed may assist organizations in responding to these circumstances.
As AI adoption continues, existing compliance frameworks can provide a basis for evaluating how automated systems are incorporated into regulated activities.
Documentation, recordkeeping procedures and appropriate human oversight remain areas that organizations may consider when developing and updating their AI governance practices.
Author: Jennifer Evancic
Jennifer.Evancic@ResourceManagement.com
Jennifer Evancic is a third-party auditor valued by creditors and large organizations for her knowledge in call monitoring within the collections industry. With meticulous attention to detail and a firm grasp of regulatory requirements, she ensures compliance with clients’ criteria and state and federal regulations.
Jennifer audits collections calls, ensuring they meet client-specific criteria and comply with regulations, providing valuable insights and maintaining industry standards.
Beyond her auditing responsibilities, Jennifer takes the lead in organizing and facilitating monthly call calibrations. These sessions serve as a collaborative forum where clients and their vendors come together to discuss call monitoring results and address any findings or areas for improvement. Jennifer’s guidance fosters open communication and ensures alignment between clients and vendors, driving continuous improvement in collections practices.
Jennifer stays up-to-date with compliance and industry best practices by participating regularly in peer meetings, regulatory updates and industry webinars. This keeps her informed about emerging issues and ensures she remains a knowledgeable leader in collections compliance.
Third Party Auditing and Custom Consulting Available
With expertise and experience in collections, oversight and compliance, we understand the challenges faced by creditors in managing collections and recoveries while adhering to ever-evolving regulatory standards.
That’s why our team of seasoned experts is dedicated to providing tailor solutions that address your unique collection and compliance requirements.
From comprehensive consulting services
to specialized training programs
and meticulous oversight of third-party vendors,
we offer a comprehensive suite of services designed to empower your team and optimize your compliance strategies.
Contact our blog authors or Write to us at info@resourcemanagement.com for more information.
www.resourcemanagement.com
Sign Up for the Twice Monthly Complimentary Newsletter
Just enter your email address at the top orange bar at:
Collection Compliance Experts – “The Power of Expertise: Oversight Perfected”
It’s that easy! Twice a month – we provide blog updates and Resources for the Collection and Industry Professional.
Your email is just for this newsletter. We never sell your information. No fee. Opt-out at any time.



