What should an AI governance policy include for investment firms?
An AI governance policy for investment firms should include five core components: a model risk framework that classifies AI use cases by impact level, data handling rules that specify where deal-sensitive materials can be processed, human oversight requirements that define when AI output must be reviewed before action, vendor assessment criteria for evaluating third-party AI tools, and regulatory alignment provisions that map the policy to the firm's jurisdictional requirements under frameworks such as MAS Guidelines, DIFC rules, EU AI Act, or SEC expectations.
By Alexandre Klinkenberg,
Co-Founder & Data Protection Officer, DiligenceWorks
· Updated
Model risk classification
<p>Not all AI use cases carry the same risk. Summarising a public company's earnings call is different from generating a valuation assessment for an active deal. An effective governance policy classifies AI use cases into tiers based on the potential impact of an incorrect or misleading output — and applies proportional controls to each tier.</p>
<p>High-impact use cases, such as deal recommendation, counterparty assessment, and regulatory compliance checking, should require human review of all AI-generated output before it informs a decision. Lower-impact use cases, such as document extraction and scheduling, may operate with lighter oversight.</p>
Data handling and sovereignty requirements
<p>The policy must specify where different categories of data can be processed. Proprietary deal materials, LP information, and personally identifiable data typically require the highest level of protection — which may mean sovereign or single-tenant processing rather than cloud-based multi-tenant services.</p>
<p>For firms operating across jurisdictions, the policy should map data categories to specific regulatory frameworks: PDPA for Singapore, PDPL for the UAE, GDPR for European operations, and any fund-specific requirements from LP side letters or regulatory licenses.</p>
Human oversight and escalation
<p>The governance policy should define clear escalation paths: when an AI-generated output must be reviewed by a human before it is used, who is responsible for that review, and what constitutes a material discrepancy that requires escalation to senior decision-makers.</p>
<p>Research indicates that AI systems trained through standard methods are systematically poorly calibrated — their confidence does not reliably predict their accuracy. This makes human oversight not a bureaucratic safeguard but a structural requirement for any use case where the cost of an incorrect output is material.</p>
Vendor assessment for third-party AI tools
<p>Investment firms increasingly adopt third-party AI tools for research, screening, and analysis. The governance policy should include assessment criteria for these tools: where does the data go, what models are used, how is output quality measured, what audit trail exists, and can the firm exit the vendor without losing access to its own analysis history.</p>
<p>Particular attention should be paid to data retention and training provisions. Some AI vendors reserve the right to use customer interactions to improve their models — which means the firm's proprietary analysis could contribute to training data accessible to competitors using the same platform.</p>