A framing I hear often about AI governance is a fear that it may stand in the way of actually using AI. Legal must approve it. Compliance needs to review it. Security has to sign off. By the time those conversations can be had, the momentum is gone and the tools — or the nature of what the firm is trying to accomplish — have already changed.

I understand why firms and operators may see governance this way. In some cases, that experience may have been true. But it's the wrong way to think about what governance actually does when it's built correctly.

After two years of helping to craft Orion's own AI governance program, I see governance differently: it is not a constraint on momentum or adoption. It is the operating model that helps teams adopt AI in a way that they can explain, monitor, and improve. It gives teams a clear path to move forward with confidence.
 

 

The Questions Haven't Changed

Advisory firms have always managed data security, client privacy, and supervision. AI did not create those responsibilities. AI, though, raises the stakes because the tools are more powerful, the risk surface is broader, and adoption can happen quickly. The core questions, though, are familiar.

When I think about what AI governance means at Orion, I come back to this framing: we're answering old questions in new ways. Data security, proprietary information, client privacy — these have long been hallmarks of what financial advisors have cared about and focused on in order to be responsible stewards and advisors to their own clients. AI doesn't change what we're protecting. It changes how we think about protecting it, and what it takes to do that well at scale.

When a firm approaches governance from that standpoint, it changes what the firm is actually building. Instead of a list of restrictions, the firm builds a framework that tells employees what they can do — and why they can trust it. When people understand that a tool has been vetted, that someone has defined what data goes in and what doesn't, and that the firm stands behind the environment, they use it more, not less, and are empowered to review and understand the outputs the tools are generating. That's where the efficiency comes from. Not from removing governance, but from getting it right.

 

Who Owns This?

One of the most common mistakes I see is treating AI governance as a single function's problem to solve for. Legal owns it, or IT owns it, or compliance owns it. What happens is that the policy ends up reflecting one function's concerns while ignoring the rest.

What I’ve found works in practice is bringing diverse stakeholders to the table before you finalize anything. Legal, compliance, security, product, and operations each bring something the others don't have, and the governance framework that emerges from that conversation is more durable than anything built in isolation. The point isn't design-by-committee. It's that if you understand everyone's needs before you write the rules, the rules are more likely to enable the work rather than obstruct it.

This requires real leadership buy-in. A governance program that lives only at the operational level is fragile. If leadership isn't leaning in — setting the expectation that the firm will adopt AI thoughtfully, investing in the process, removing blockers when they emerge — the program stalls. Governance becomes an enabler only when leadership treats it as an opportunity to apply thoughtful strategy, not as an exercise in compliance. At its core, the technology has the potential to rewrite aspects of a firm's operations, and it should be treated accordingly in terms of strategic oversight.

Financial decision making
AI Resources for Advisory Firms

Start Building the Framework

Orion's AI Resource Hub brings together practical tools, frameworks, and perspective for firm leaders building their AI governance programs.

Starting Before You Have Everything Figured Out

From time to time I hear feedback such as "we're too small," "we don't have the resources," or "we are still trying to figure out what AI to use" — and I get it, the topic seems boundless. The time to start is now, though, as chances are the technology is already being used in your firm.

At Orion, when we started building our AI governance program, we didn't have everything figured out either. Instead, we started by identifying two or three safe use cases that we thought would be meaningful and impactful to Orion that we could learn from — tools we wanted to get into people's hands, evaluate, and understand before rolling out policy at scale. We built the policy framework in parallel with that learning, so that by the time we were ready to expand, the framework reflected real experience.

The lesson for firms of any size: this process is iterative and the technology moves fast. Start now by adopting a policy and program that allows you to effectively document and track your firm's AI usage. Build a framework that is repeatable and allows you to continue planning for additional use cases. Choose two or three use cases your team wants to evaluate, identify the stakeholders who need to review them, and document what you learn. That gives you a practical foundation you can build on as new tools and use cases emerge.

 

The Foundation for What Comes Next

The reason I describe governance as a foundation is that it compounds. When a firm has a governance program in place — even a basic one — it has a framework in place for how it can start to evaluate new AI platforms, tools, and features. The team knows what questions to ask, what data boundaries to apply, and how to educate and monitor usage. They are not starting from scratch each time.

That's what I mean when I say governance is the on-ramp, not the speed bump. The firms that build it early are positioned to move when the next wave of capability arrives. Their employees are less worried about what they cannot do with AI and more empowered to confidently use the tools that have been configured for them. Skip the governance step and you risk being left answering these important questions in real time without a roadmap, under the pressure of unmet expectations.

Treat governance as the starting point for responsible AI adoption. Put a basic program in place now, learn from real use cases, and improve it over time. Your firm will be better positioned to adopt new tools with confidence.

Go Deeper on AI Governance

Governance Is What Lets You Move Fast

If your firm is still figuring out where to start on AI, the AI Resource Hub has what you need — compliance, security, and product perspectives, in one place.

John Lawless is SVP, Legal and Risk Management at Orion, a premier provider of transformative wealthtech solutions for financial advisors and the enterprise firms that serve them.

This article is for educational and informational purposes only, is not intended and should not be construed as legal advice, and does not establish an attorney-client relationship in any form.