An examiner asks one question: who holds administrative access to the system where client data moves between the CRM and the portfolio accounting platform, and when was that access last reviewed. The answer takes four days, three vendors, and a partner's weekend to assemble. Nothing was breached. No one was negligent. The firm genuinely performs the review — it simply could not prove the review was operating on the day in question.
That gap, between doing the thing and demonstrating the thing, is where compliance actually lives for a Los Angeles advisory firm in 2026. It is also where the standard checklist article fails its reader. A list of controls tells you what to have. It does not tell you what you will be asked to show, or which demonstrations have quietly become harder in the last two years.
The binder stopped being the artifact. The log became the artifact.
Written information security programs, incident response plans, vendor due diligence files — all still necessary. Registered advisers operate under long-standing obligations to safeguard client information and retain the records of their business, and documents satisfy the first half of that. They do not satisfy the second.
What has shifted — this is analysis rather than a finding — is that three different parties now ask the same question in three dialects. The regulator asks whether the program is reasonably designed and actually followed. The insurer asks which controls are enforced everywhere, without exception. The institutional client's operational due diligence team asks for the artifacts by name.
Each of those is an evidence request. A policy stating that access reviews occur quarterly is a sentence. An exportable record showing which accounts were reviewed, by whom, and what was revoked is an artifact. Firms that treat IT security as a documentation exercise produce sentences. Operating discipline produces artifacts, and produces them in an afternoon.
Retention follows the same logic. Immutable, tested data backup is interesting less as a best practice than as the only mechanism that converts "we can recover client records" into a demonstrable fact with a restore log behind it. Backup that has never been restored is a theory.
Identity is the only control surface an examiner can test
For a twenty-to-eighty person wealth management firm, there is no meaningful network perimeter left. Custody sits at the custodian. Portfolio accounting is a SaaS platform. Email, documents and chat live in Microsoft 365. Planning software, CRM, e-signature and the client portal are four more vendors. The attack surface is not an office in Century City or Pasadena. It is a set of identities.
Business email compromise persists for structural reasons rather than exotic ones. An attacker holding a legitimate session token needs no malware. They need patience, a mailbox rule that routes anything containing the word "wire" into a folder nobody opens, and a plausible moment to intervene in a payment that was already going to happen.
Controls that address this are unglamorous and testable. Conditional Access that gates sign-in on device compliance and location rather than merely prompting for a code. Phishing-resistant authentication — passkeys or hardware keys — for anyone holding administrative rights or payment authority. Administrative accounts kept separate from daily-use accounts. Alerting on mailbox forwarding rules, one of the few detections that maps to a fraud pattern rather than to a generic threat category.
Every one of those produces a log. Logs are what the examiner, the underwriter and the forensic investigator all want, and they want them from the same place. A firm that has consolidated identity has one answer. Eleven disconnected logins produce eleven partial answers and no timeline.
Advice is migrating into tools your archive has never seen
The exposure most firms have not yet priced is simpler than it sounds. An adviser pastes a portfolio summary into a consumer AI assistant to draft a rebalancing rationale. A junior analyst asks a chatbot to summarize a prospect's estate documents. A partner runs an AI notetaker that joins client calls, transcribes them, and stores the transcript in a vendor cloud nobody evaluated.
Two problems compound. Data is the first: client financial detail leaving a governed environment for a system with its own retention and training terms. Records are the second. If a conversation materially shapes a recommendation, recordkeeping obligations do not pause because it happened in a chat window instead of an email thread. An archive that captures email and Teams but not the tools where drafting actually occurs has a hole in the middle of it.
Prohibition is the wrong response, and usually an unenforceable one. Substitution works better: provide a governed AI capability inside the tenant where data boundaries, retention and audit logging already apply, then make the sanctioned path the easier one. Copilot governance is not a licensing decision. It is a question of whether permissions and sensitivity labels are accurate enough that an assistant summarizing "everything I have access to" does not surface the compensation spreadsheet.
The familiar voice on the phone is no longer evidence
Synthetic voice has become an ordinary product feature rather than a research demonstration. That change retires a verification method many firms still rely on informally — a recognizable voice on the line requesting a distribution, with urgency and a plausible story attached.
The control is old and now non-negotiable. Out-of-band callback to a number already on file, never a number supplied in the request, for every disbursement change and every first-time payee, with no exception for the client of twenty years who finds the question tedious. Document the callback. That documentation is simultaneously the fraud control and the evidence of the fraud control.
An opinion, offered as one: the firms most exposed here are those whose service culture treats friction as failure. Verification applied uniformly is a client protection, and saying so out loud converts an irritation into a demonstration of competence.
Four questions that do the work of a fifty-item checklist
The useful self-assessment for an advisory firm is not fifty controls. It is four questions, each of which should be answerable inside a day.
- Can we produce, this week, a current inventory of every system holding client data and who has administrative access to each?
- Can we show that a restore from backup was tested, by whom, and on what date?
- Do we know which AI tools our people actually use, and are the records they generate inside our retention boundary?
- Is callback verification performed and documented for every money movement, without exception?
A firm answering all four cleanly is in better condition than one with a thicker binder and no artifacts. Firms that cannot answer them have not uncovered a security problem. They have discovered that their evidence lives in individual people's memories — the one storage medium no examiner, underwriter, or institutional allocator accepts.
Pro Link Systems has supported Los Angeles businesses from Woodland Hills since 1999, and our 24/7 in-house, US-based help desk answers the phone live. If you want the evidence to exist before the request does, start a conversation with our managed IT services team.
Ready to talk to a real IT engineer?
Pro Link Systems has been protecting and managing IT for Los Angeles businesses since 1999. Book a free 15-minute discovery call — no pressure, no obligation, no scripts.