An AI-Assisted FINRA Communication Approval Queue
Broker-dealers can't use retail communications without principal approval, and the manual queue eats hours. An AI-assisted queue that pre-flags problems so the principal's time goes to the close calls.
FINRA Rule 2210 requires principal approval of broker-dealer retail communications before use. Many firms run this through a manual queue where a compliance officer reads every piece, marks it up, and approves or rejects.
The queue eats hours per week. AI doesn't replace the principal. It pre-flags problems so the principal can focus on the close calls.
The setup
Communications get submitted to a queue from anywhere they're created (advisor email tool, marketing platform, content management). Each submission gets:
- Pre-screened by AI for known violation patterns
- Scored on multiple FINRA-relevant dimensions
- Routed to the principal with a summary of issues
The principal reviews the AI's summary, then the piece itself, then approves/rejects.
What gets pre-flagged
Patterns the AI catches with high reliability:
1. Performance claims without required disclosure. Any mention of returns, performance, or growth without the standard "past performance does not guarantee future results" language.
2. Projections or predictions. "We expect 8% returns" or "this fund will outperform" type statements. FINRA prohibits these in retail communications.
3. Misleading comparisons. "Better than the S&P" claims without context, time period, or risk adjustment.
4. Implied promises. "Guaranteed income" or "risk-free" outside specifically defined products.
5. Banned terms. Each firm has a banned-terms list (specific products, specific phrasing). The AI checks each piece against the list.
6. Required disclaimers. Each communication type has required disclaimers (firm name, FINRA membership, SIPC, etc.). The AI verifies presence.
7. Personal endorsements / testimonials. New SEC marketing rule allows testimonials with disclosure. The AI flags any testimonial-shaped content for verification of disclosure compliance.
The prompt
Review this proposed retail communication for FINRA Rule 2210 compliance.
Content: {communication_text}
Type: {email | webinar_slide | social_post | newsletter | website_section}
Audience: {retail / accredited / institutional}
Flag each of:
1. Performance claims without required disclosure
2. Forward-looking statements (projections, predictions)
3. Misleading or unsubstantiated comparisons
4. Implied guarantees or promises
5. Banned terms: {firm_banned_terms_list}
6. Missing required disclaimers for this content type: {required_disclaimers}
7. Testimonial language without proper disclosure
8. Risk-balanced presentation (does the piece adequately disclose risk?)
For each flag, return:
- specific quote from the content
- which rule or principle is at issue
- severity: high / medium / low
- suggested fix
End with overall recommendation: "approve" | "approve_with_edits" | "reject"The queue UI
A simple internal tool (a Notion database works, or a custom admin panel):
- List view of pending communications
- Sort by submission time and AI-flagged severity
- Each row shows: submitter, type, AI summary (with color-coded severity), action buttons
Principal clicks into a piece, sees the AI's flagged issues at the top, then the full content. Approves, rejects with notes, or sends back for edits.
Each approval/rejection is logged with timestamp and decision rationale for audit trail.
What tends to break
Over-cautious flagging. A first prompt tends to flag almost everything, and compliance officers end up spending more time clearing flags than they spent on raw review. Tune the prompt against the principal's feedback until the flags are worth reading.
Firm-specific rules. Every firm has its own patterns to catch, such as any mention of crypto, or fund names the firm doesn't sell. Add firm-specific extension prompts that layer on top of the base prompt.
Principals who feel second-guessed. This is a cultural issue more than a technical one. Call the AI output "items to verify" rather than "flags," and make clear the AI is a triage tool, not a co-approver.
How to measure it
Record the principal's review time per piece for a few weeks before the AI layer goes in, and keep recording after. Track audit findings on approved communications too. The goal is faster review at the same quality, so a drop in review time alongside a rise in findings means the tool is costing you.
What this isn't
The AI does not approve communications. The principal approves. The AI surfaces issues for the principal's attention.
The AI does not create a defense in audit. The principal's documented review is the defense. The AI is a productivity tool inside that review.
What to build first
If you're a broker-dealer or RIA running a manual approval queue:
One, the banned-terms checker. Most-common, lowest-risk to automate. Start here.
Two, the disclaimer-presence checker. Mechanical. High value.
Three, the performance-claim flagger. Where many violations live.
Four, full prompt-based review at the end. Once the mechanical checks are working, layer on the broader review prompt.
Expect the prompt iteration with the compliance team to take longer than the build itself.
Get the next one.
Field notes from real deployments, written the way this one was. No schedule promised and nothing sold to you. Unsubscribe whenever.