Platform Why Features Security Score AI Engine AI Coding KYP Hub Pricing Company About Buckler News Contact Français Book Demo →
Part One

What Regulators Expect

No regulator has written a separate AI record keeping rule. They have said, clearly, that existing record keeping duties apply, and that AI tools need to be explainable enough to meet them.

1
Explainability in the Guidance
What Canadian and US regulators have said

The Canadian Securities Administrators tie explainability directly to records:

"AI systems used by registrants should provide an appropriate degree of explainability so that registered firms are able to meet applicable record keeping requirements."[1]

CSA staff describe a high level of explainability as meaning "an AI system's reasoning is clear and comprehensible," and favour "the highest degree of explainability that is feasible" for the type of system used.[1]

In their December 2025 review of KYP practices, the CSA and CIRO added two expectations that apply to automated tools: that firms' policies describe automated systems in detail, and that firms relying on algorithmic models keep evidence of ongoing oversight. The same review looked for approval records that show "meaningful consideration" of the elements assessed.[2] An approval that leaned on AI output is held to the same standard.

In the US, FINRA's 2026 Annual Regulatory Oversight Report describes firms "storing prompt and output logs for accountability and troubleshooting; tracking which model version was used and when."[3] On AI agents, it warns that "complicated, multi-step agent reasoning tasks can make outcomes difficult to trace or explain, complicating auditability," and lists "how to track agent actions and decisions" as a consideration for firms.[3]

2
Record Keeping Still Applies
The rules that already govern the trail
JurisdictionRuleWhat It Requires, in Brief
CanadaNational Instrument 31-103, ss.11.5 and 11.6[4]Registered firms keep records that accurately record their business and demonstrate the extent of their compliance with securities law, and retain them for a prescribed period in an accessible form
US (broker-dealers)SEC Rule 17a-4; FINRA Rule 4511[5]Preservation of required books and records, including business communications, for set periods and in accessible form
US (advisers)SEC Rule 204-2[6]Books and records requirements for registered investment advisers, including records supporting advice and written communications

None of these rules mentions AI, and none needs to. If a firm's KYP records must demonstrate its compliance, and an AI tool produced part of the analysis behind a product decision, the record has to capture that part. Which specific AI records fall within each rule is a question for the firm's own legal review; the practical approach is to keep the AI trail alongside the product record it supports, for the same period.

3
Two Kinds of Explainability
Explaining the tool, and explaining the decision
Model-LevelDecision-Level
Question it answersHow does this tool work?Why did the firm reach this conclusion about this product?
Who asksModel validators, auditors, examiners reviewing the programSupervisors, examiners reviewing a file, the firm itself later
What answers itPolicy description, validation record, known limitationsThe inputs, the output, its sources, and what the reviewer did
Achievable with modern AI?Partly; internal reasoning of large models is hard to inspectYes, if outputs are tied to sources and the review is recorded

For KYP, decision-level explainability is the one that matters most, and it is achievable. A firm may never be able to explain exactly how a large language model arrived at its wording. It can always show that the tool said a fund's management fee rose by 0.10%, that the statement came from page 3 of the amendment filed on a given date, and that an analyst checked it and recorded the decision. That is an explainable decision, even if the model inside is not fully explainable.

Part Two

The Audit Trail

An audit trail for AI-assisted decisions links four things: what went in, what came out, where it came from, and what a person did with it.

1
What to Record
The elements of a complete record for each AI output
ElementWhat to CaptureWhy
InputsThe documents and data the tool used, with their dates and a fixed copy or fingerprint of eachDocuments change; the record must show what the tool actually read
Tool and versionTool name, underlying model and version, prompt or configuration versionThe same input can produce different outputs under a different version
TimeWhen the output was producedPlaces the output against what the firm knew at the time
OutputThe output exactly as produced, before any editsShows what the tool said, separately from what the firm concluded
SourcesFor each statement or value, the document, page or data point it came fromMakes each output checkable
FlagsAny warnings the tool raised, such as low confidence, scanned input or missing dataShows whether known weaknesses were visible to the reviewer
ReviewWho reviewed it, when, and whether they accepted, edited or rejected it, with any edits capturedShows human judgment was applied, and where the tool was wrong
DecisionA link to the product decision the output informed, and the reasoning recorded by the decision-makerConnects the AI trail to the product record

Keep the tool's words and the person's words apart. If an AI-drafted summary is pasted into a product file and lightly edited, no one can later tell which parts were the firm's analysis. The original output, the edits and the final text should all be recoverable.

2
An Example Record
One AI-detected change, from filing to decision

An illustrative audit record for a hypothetical fund:

AI-Assisted Decision Record: Example
Hypothetical
Product
Example Global Income Fund, Series A and F.
Inputs
Amendment to simplified prospectus dated March 4, 2026 (fixed copy stored); prior prospectus dated June 30, 2025 (fixed copy stored).
Tool
Filing change detection tool v3.1; underlying model version recorded; prompt configuration v22. Run March 5, 2026, 06:12.
Output
Three changes detected: (1) Series A management fee increased from 1.60% to 1.70%, effective May 1; (2) investment strategy now permits up to 20% in below-investment-grade debt, previously 10%; (3) auditor name updated. Stored as produced.
Sources
(1) Amendment, p.2, fee table; (2) amendment, p.3, "Investment Strategies"; (3) amendment, p.4.
Flags
None. All inputs machine-readable.
Review
Product analyst, March 5. Changes (1) and (2) confirmed against source. Change (3) edited: the tool reported a new auditor; the amendment shows the same firm under a new legal name. Edit and reason recorded.
Decision
Product committee, March 9: maintain with watch. Rationale recorded by the committee: higher credit risk and cost reviewed against the fund's mandate and approved alternatives. Product file and advisor summary updated.

This record answers every question a reviewer is likely to ask: what the tool saw, what it said, where each statement came from, where it was wrong, who checked it and who decided. The error on the auditor is as useful as the correct findings: it is evidence that review was real, and a data point for monitoring the tool.

3
The Reconstruction Test
Can the firm rebuild a decision from its records alone?

Pick an AI-assisted product decision from six to twelve months ago and try to answer these questions using only the records, without asking anyone who was involved:

QuestionRecord That Answers It
What documents and data did the tool use?Inputs, with fixed copies
Which tool and version produced the output?Tool and version
What exactly did it produce?Output, unedited
Where did each statement come from?Sources
Did it warn about anything?Flags
Who checked it, and what did they change?Review
Who made the decision, and why?Decision
Was the tool validated and approved for this use at the time?Model inventory and validation record

Any question that can't be answered from the records is a gap. Running this test on a small sample each year, and after any change to an AI tool, shows whether the trail works before an examiner tests it.

Part Three

Designing for Explainability

Explainability is far easier to build in than to add later. Most of it comes down to a few design choices made when a tool is selected or configured.

1
Design Principles
Choices that make AI outputs explainable by default
Source Every Output
Every value or statement carries a link to the page or data point it came from. Outputs without a source are flagged, not used.
Prefer Structure
Structured outputs (a fee, a date, a barrier level) are easier to check and compare than free text. Use free text where it adds value, not by default.
Version Everything
Model, prompts, configuration and input documents are all versioned, and the version is stamped on every output.
Keep Logs Fixed
Records can't be altered after the fact, are held by the firm rather than only by a vendor, and are retained as long as the product record they support.
  • Capture the review, not just the result. Accept, edit and reject should be actions in the system, with edits stored, rather than something that happens in a copy of the text.
  • Let the decision-maker write the reasoning. The rationale for a product decision should be in the decision-maker's own words, even when AI drafted the analysis behind it.
  • Log agent actions step by step. Where an AI agent takes several steps, each step, and any record it changed, should be logged, and agents should not be able to change product status or approvals.
2
Common Gaps
Where AI audit trails usually break, and how to fix them
GapConsequenceFix
AI summary pasted into the product file without markingThe firm can't show which analysis was its ownStore the original output separately; mark AI-drafted text
No record of model or prompt versionThe output can't be reproduced or explained after a vendor updateStamp versions on every output
Reviewer overwrites the AI outputEvidence of review, and of the tool's errors, is lostKeep original, edits and final text
Logs held only in the vendor's system, deleted after a short periodRecords gone before the retention period endsContractual retention, or export to firm records
Source document not keptCan't show what the tool read if the issuer later changes the online versionStore a fixed copy of each input
Agent actions summarized, not loggedCan't trace what an agent did or whyStep-level action log
Research assistant answers used without recordAn input to a decision disappearsSave answers that inform a product decision to the product file, with sources
Part Four

Responsibilities

The firm designs the trail. Everyone who uses AI output in product work adds to it.

1
Firm and Advisor Duties
Who does what
What the Firm Needs to Do
  • Define the record. Set the elements captured for every AI output used in product work.
  • Require sources. Choose and configure tools that link each output to its source.
  • Version and stamp. Record model, prompt and configuration versions on every output.
  • Keep inputs fixed. Store copies of the documents and data each output relied on.
  • Capture review. Store the original output, edits and final text, with reviewer and date.
  • Own the records. Keep AI records in firm systems or under contract, for the same period as the product record.
  • Describe it in policy. Describe each tool, and what it records, in enough detail to test.
  • Test reconstruction. Rebuild a sample of decisions from records each year.
What the Individual Advisor Needs to Do
  • Use firm tools for product work. So that outputs are recorded; not personal or public tools outside the firm's records.
  • Check before relying. Confirm AI summaries against their sources.
  • Write their own notes. Product notes in the advisor's own words, not pasted AI text.
  • Report errors. So they are recorded and the tool can be corrected.
2
Example Written Process
What the firm writes down, as numbered clauses
Example: Records for AI-Assisted Product Decisions
Illustrative
1
Scope. This process applies to every output of an AI tool that is used in assessing, approving, reviewing or monitoring a product.
2
Record. For each such output the firm records the inputs, the tool and its model, prompt and configuration versions, the time, the output as produced, the sources for each statement or value, any flags raised, the review and the decision it informed.
3
Sources. AI outputs without sources are not used in a product decision unless the reviewer verifies them independently and records how.
4
Review. Reviewers accept, edit or reject each output within the system. The original output, any edits with reasons, and the final text are retained.
5
Decisions. Product decisions are made by named individuals, who record their rationale in their own words. AI-drafted text in product files is marked as such.
6
Retention. AI records are held in firm systems, or by vendors under contract, in a form that cannot be altered, and retained for the same period as the product records they support.
7
Agents. AI agents log each action they take. Agents may not change product status or approvals.
8
Testing. Each year, Compliance selects a sample of AI-assisted product decisions and confirms each can be reconstructed from records alone. Gaps are reported and remediated.
Five Questions to Test an AI Audit Trail
  1. For a product decision made last year, can the firm show exactly what the AI tool produced, before anyone edited it?
  2. Does every AI output in a product file cite its source?
  3. Would the firm know which model version produced a given output?
  4. If the vendor deleted its logs tomorrow, would the firm still have its records?
  5. Can the firm tell which parts of a product file were written by a person and which by AI?
A note on scope: This article describes practical approaches to explainability and record keeping for AI used in product due diligence, approval and monitoring, based on publicly available guidance as of its date. Which records fall within specific record keeping rules depends on the firm's registration and its own legal review. It is general information, not legal or compliance advice. The record elements, example record, tests, design principles and written process are illustrations, not prescribed requirements; the fund and details are hypothetical.
References
  1. Canadian Securities Administrators. CSA Staff Notice and Consultation 11-348, Applicability of Canadian Securities Laws and the use of Artificial Intelligence Systems in Capital Markets, December 5, 2024. Source document (PDF)
  2. Joint CSA/CIRO Staff Notice 31-368, Client Focused Reforms: Review of Registrants' Know Your Client, Know Your Product and Suitability Determination Practices and Additional Guidance, December 10, 2025. Approval and oversight of algorithmic models, pp.15-16; policies describing automated systems, p.34. Source document (PDF)
  3. FINRA. 2026 Annual Regulatory Oversight Report, December 2025. Generative AI, pp.26-27. Source document (PDF)
  4. National Instrument 31-103 Registration Requirements, Exemptions and Ongoing Registrant Obligations, s.11.5 (general requirements for records) and s.11.6 (form, accessibility and retention of records). Source document
  5. 17 CFR 240.17a-4, Records to be preserved by certain exchange members, brokers and dealers; FINRA Rule 4511 (General Requirements). Source document
  6. 17 CFR 275.204-2, Books and records to be maintained by investment advisers. Source document