AI has moved from experimentation to early production across asset management. Most companies CrossCountry Consulting has worked with have embedded some form of AI into at least one investment process, and most of the rest are piloting one now.  

Governance has not kept pace compared to adoption. 

That gap is expensive in both directions: initiatives stall when approval paths are unclear, and ungoverned use creates regulatory, operational, and reputational exposure. 

AI governance is the set of policies, controls, and oversight processes that determine how AI tools are approved, monitored, and documented across an organization. Done poorly; it functions as a brake. Done well, it is what lets AI adoption scale safely in a market that shifts every quarter.  

Why has AI adoption outpaced governance in asset management? 

Most companies are deploying generative AI faster than they can build structured oversight around it. Investment teams reach for tools that were never formally approved, and few companies have centralized visibility into what their AI tools and agents are doing, returning, or getting wrong. 

The pressure this creates is concrete. An auditor wants the evidence chain behind a reported net asset value or a hard-to-value mark. A limited partner presses on how a fee or expense was allocated. An examiner asks for documented controls over any AI agent that touches a material process. Meanwhile, shadow AI carrying material nonpublic information seeps into the research and idea generation workflows where adoption is heaviest, often outside any information barrier. 

This is not a new enforcement territory. In March 2024, the Securities and Exchange Commission (SEC) brought its first “AI washing” cases against two investment advisers, for marketing AI capabilities they did not actually have. The companies paid a combined $400,000 in civil penalties.  

Separately, the SEC’s broader recordkeeping sweep has reached more than 100 companies and over 2 billion dollars in penalties since 2021, and its Asset Management Unit has charged advisers for misallocating fund expenses, from broken-deal costs to shared overhead. AI accelerates these exposures. The longer the governance gap persists, the harder it becomes to close. 

Companies that close this gap early see the opposite pattern. In our experience working with clients, companies that operate under a risk-tiered AI life cycle tend to move use cases through intake and approval more quickly, gain clearer visibility into risk and value across their AI portfolio, and stay audit-ready through a documented AI inventory. Governance, structured correctly, accelerates adoption instead of competing with it.

What should every AI use case answer before moving forward? 

Every AI use case should answer three questions before it scales: what the tool is doing, how much the company relies on it, and whether the work can be proven. These three questions turn governance from an abstract principle into a practical checkpoint. 

Infographic showing the three questions every AI use case must answer for asset management governance.

Agentic systems raise the same three questions one level down: what the agent is and how it authenticates, what it can access and execute, and who owns it through to decommissioning. Together, the answers define accountability from the individual use case to the underlying infrastructure. 

Where does AI risk actually live? 

AI risk is broader than security. Security dominates most conversations about AI risk, but it is one of three exposures that need active governance, alongside operational and data risk. 

A program built to address only one of these three exposures leaves the other two open. 

Diagram of a risk-tiered AI lifecycle framework for AI governance in asset management.

How do you build an AI governance program in phases? 

No company needs a complete governance program on day one, and the ones that try to build everything at once usually stall. A phased build works better than an all-at-once rollout. 

  1. Foundation. Build a use case inventory, a responsible AI policy, and review workflows that a person can keep up with. 
  1. Automation. Add tiered routing based on risk, a model registry, and command center visibility across the AI portfolio. 
  1. Optimization. Layer in real-time alerting, drift detection, and incident playbooks once the first two phases are running smoothly. 

Routing should be tiered by risk from the start. An internal productivity tool with a person reviewing every output can clear a fast track measured in weeks. Anything touching investor money, sensitive data, or a regulatory obligation earns testing, legal review, and audit documentation on a longer timeline. Approved use cases should accumulate into a pattern library, so the second valuation workflow does not repeat the full review of the first. 

This sequence is typically benchmarked against the NIST AI Risk Management Framework and COSO’s guidance on internal controls; two frameworks built specifically to make AI oversight defensible to auditors and regulators. 

How do you know an AI governance program is working? 

A working AI governance program can answer four questions: whether people are following the process, whether controls catch issues, whether the models are performing, and whether measurable value is showing up. Standard system and activity logging (who signed in, what data moved) is not enough on its own. 

Governing AI well requires a deeper record: what the model decided and why, what was performed across connected systems, and whether guardrails fired when they were supposed to. Across the asset managers we work with, gains so far sit mostly in operational efficiency. Few companies can yet tie AI directly to investment returns, and that is fine. A program that cannot answer all four questions above is still a pilot, no matter how long it has been running. 

For asset managers, the question is no longer whether to implement AI. It is whether every use case can answer what the AI is doing, how much the firm relies on it, and whether that work can be proven when someone asks. Companies that can answer all three moves faster, not slower than the ones still treating governance as an afterthought. 

Building this out often connects directly to broader AI Strategy & Transformation work, since the governance layer and the adoption roadmap need to be designed together, not in sequence. It also overlaps closely with Integrated Risk Management, particularly where AI touches controls that are already subject to audit or regulatory review. 

To fully capitalize on the value a well-governed AI program can bring to your organization, contact CrossCountry today.

Frequently asked questions 

What is AI governance in asset management? 

AI Governance is the set of policies, controls, and oversight processes that determine how AI tools are approved, monitored, and documented. For asset managers, it covers everything from intake and approval to ongoing monitoring of any AI tool touching investment decisions, financial and client data, or regulatory reporting. 

What are the regulatory risks of deploying AI without governance? 

Companies face SEC enforcement risk, including “AI washing” charges for misrepresenting AI capabilities, along with recordkeeping violations and expense misallocation of charges. Ungoverned AI also raises the risk of shadow AI exposing material nonpublic information outside proper information barriers. 

How does a risk-tiered AI life-cycle work in practice? 

Each AI use case moves through intake, approval, build, and monitoring, with a governance checkpoint at every stage. Low-risk tools clear a fast track in weeks, while anything touching investor money or regulatory obligations goes through testing, legal review, and audit documentation. 

What does an AI governance program look like in phases? 

Programs typically build in three phases: foundation (use case inventory, policy, review workflows), automation (tiered routing, model registry, command center visibility), and optimization (real-time alerting, drift detection, incident playbooks). 

How should asset managers document AI use for auditors and LPs? 

Documentation should trace what the AI was asked, what it produced, who reviewed it, and what decision resulted, generated automatically by the workflow rather than reconstructed after the fact. This creates an audit-ready inventory before an examiner or limited partner asks for one.

Connect with an expert

Tom Alexander

Head of AI Innovation & Transformation

See Bio

Contributing authors

Sean Sinclair

Ronel Vermeulen

Anjali Khullar

Joseph Denton