The framing I hear most often about AI governance is that it's the thing standing between a firm and actually using AI. Legal must approve it. Compliance needs to review it. Security has to sign off. By the time those conversations happen, the momentum is gone and the tools have changed.

I understand why firms have internalized this. In some cases, it's been true. But it's the wrong way to think about what governance actually does when it's built correctly.

I think, after spending the better part of two years building Orion's AI governance program, that governance isn't a constraint on adoption. It's the mechanism that makes adoption sustainable.

 

The Questions Haven't Changed

Advisory firms have always cared about data security, client privacy, and supervision. Those aren't problems AI created. AI has amplified them — the stakes are higher, the surfaces for risk are larger, the tools are more powerful. But the underlying questions are ones this industry has been answering for decades.

When I think about what AI governance means at Orion, I come back to this framing: we're answering old questions in new ways. Data security, proprietary information, client privacy — these have been the hallmarks of what it means to be a responsible financial services firm. AI doesn't change what we're protecting. It changes how we think about protecting it, and what it takes to do that well at scale.

And I think when a firm approaches governance from that standpoint, it changes what they're actually building. Instead of a list of restrictions, they build a framework that tells employees what they can do — and why they can trust it. When people understand that a tool has been vetted, that someone has defined what data goes in and what doesn't, that the firm stands behind the environment — they use it more, not less. That's where the efficiency comes from. Not from removing governance, but from getting it right.

 

Who Owns This?

One of the most common mistakes I see is treating AI governance as a single function's problem. Legal owns it, or IT owns it, or compliance owns it. What happens is that the policy ends up reflecting one function's concerns while ignoring the rest. Legal builds a framework that addresses liability but doesn't reflect what advisors actually do. IT builds a security policy that doesn't account for what compliance needs from a supervision standpoint.

And so, I think what really works is getting diverse stakeholders to the table before you finalize anything. Legal, compliance, security, product, operations — each of them brings something the others don't have, and the governance framework that emerges from that conversation is more durable than anything built in isolation. The point isn't design-by-committee. It's that if you understand everyone's needs before you write the rules, the rules are more likely to enable the work rather than obstruct it.

I'd also say this requires real leadership buy-in, and that's what I've seen make the difference. A governance program that lives only at the operational level is fragile. If leadership isn't leaning in — setting the expectation that the firm will adopt AI thoughtfully, investing in the process, removing blockers when they emerge — the program stalls. Governance becomes an enabler only when leadership treats it as a priority, not a compliance exercise.

Financial decision making
AI Resources for Advisory Firms

Start Building the Framework

Orion's AI Resource Hub brings together practical tools, frameworks, and perspective for firm leaders building their AI governance programs.

Starting Before You Have Everything Figured Out

I want to address the version of this conversation where firms say they'd love to do all of that, but they're too small, or don't have the resources, or are still figuring out which tools they want to use.

At Orion, when we started building our AI governance program, we didn't have everything figured out either. What we did was identify two or three use cases we could learn from — tools we wanted to get into people's hands, evaluate, and understand before rolling out policy at scale. We built the policy framework in parallel with that learning, so that by the time we were ready to expand, the framework reflected real experience.

The lesson for firms of any size: you don't have to wait until your governance program is complete before you start using AI. You must start somewhere. The policy that exists and is imperfect is far better than the policy you're still planning. Pick two or three things your team wants to try. Get the right stakeholders involved in evaluating them. Write down what you learn. Build from there.

The firms I've seen get stuck are the ones waiting to achieve full stakeholder alignment before doing anything. And what I'd say is that alignment comes through the process — you get there by going through work together, not by perfecting the design in advance.

 

The Foundation for What Comes Next

The reason I describe governance as a foundation is that it compounds. When a firm has a governance program in place — even a basic one — every time a new AI tool comes to market, they have a framework for evaluating it. They know what questions to ask. They know what data boundaries to apply. They're not starting from scratch.

That's what I mean when I say governance is the on-ramp, not the speed bump. The firms that build it early are positioned to move when the next wave of capability arrives. The firms that skip it will have to build it under pressure when something goes wrong.

Governance is an enabler in AI. Jump on it, put a policy in place, and I think you'll be well on your way to getting it started.

Go Deeper on AI Governance

Governance Is What Lets You Move Fast

If your firm is still figuring out where to start on AI, the AI Resource Hub has what you need — compliance, security, and product perspectives, in one place.