Sooner or later, someone will ask a firm why it made a product decision: why a fund stayed on the shelf after its manager left, why a structured note was approved, why an alert was closed without action. If AI played a part in that decision, the answer has to include what the AI produced, what it was based on, and what a person did with it.
Most AI tools don't record that by default. They produce an output, someone uses it, and the trail ends. When the question comes a year later, the firm can show the decision but not how it was reached.
This article sets out what an AI-assisted product decision needs to show, and how to build the audit trail that shows it. It covers what regulators have said about explainability and records, the difference between explaining a model and explaining a decision, what to record for each AI output, an example record, a test for whether a decision can be reconstructed, design principles and common gaps, and responsibilities and an example written process.
It focuses on AI used in Know-Your-Product (KYP) work: product due diligence, approval and monitoring. It reflects publications available as of the date above.
No regulator has written a separate AI record keeping rule. They have said, clearly, that existing record keeping duties apply, and that AI tools need to be explainable enough to meet them.
The Canadian Securities Administrators tie explainability directly to records:
CSA staff describe a high level of explainability as meaning "an AI system's reasoning is clear and comprehensible," and favour "the highest degree of explainability that is feasible" for the type of system used.[1]
In their December 2025 review of KYP practices, the CSA and CIRO added two expectations that apply to automated tools: that firms' policies describe automated systems in detail, and that firms relying on algorithmic models keep evidence of ongoing oversight. The same review looked for approval records that show "meaningful consideration" of the elements assessed.[2] An approval that leaned on AI output is held to the same standard.
In the US, FINRA's 2026 Annual Regulatory Oversight Report describes firms "storing prompt and output logs for accountability and troubleshooting; tracking which model version was used and when."[3] On AI agents, it warns that "complicated, multi-step agent reasoning tasks can make outcomes difficult to trace or explain, complicating auditability," and lists "how to track agent actions and decisions" as a consideration for firms.[3]
| Jurisdiction | Rule | What It Requires, in Brief |
|---|---|---|
| Canada | National Instrument 31-103, ss.11.5 and 11.6[4] | Registered firms keep records that accurately record their business and demonstrate the extent of their compliance with securities law, and retain them for a prescribed period in an accessible form |
| US (broker-dealers) | SEC Rule 17a-4; FINRA Rule 4511[5] | Preservation of required books and records, including business communications, for set periods and in accessible form |
| US (advisers) | SEC Rule 204-2[6] | Books and records requirements for registered investment advisers, including records supporting advice and written communications |
None of these rules mentions AI, and none needs to. If a firm's KYP records must demonstrate its compliance, and an AI tool produced part of the analysis behind a product decision, the record has to capture that part. Which specific AI records fall within each rule is a question for the firm's own legal review; the practical approach is to keep the AI trail alongside the product record it supports, for the same period.
| Model-Level | Decision-Level | |
|---|---|---|
| Question it answers | How does this tool work? | Why did the firm reach this conclusion about this product? |
| Who asks | Model validators, auditors, examiners reviewing the program | Supervisors, examiners reviewing a file, the firm itself later |
| What answers it | Policy description, validation record, known limitations | The inputs, the output, its sources, and what the reviewer did |
| Achievable with modern AI? | Partly; internal reasoning of large models is hard to inspect | Yes, if outputs are tied to sources and the review is recorded |
For KYP, decision-level explainability is the one that matters most, and it is achievable. A firm may never be able to explain exactly how a large language model arrived at its wording. It can always show that the tool said a fund's management fee rose by 0.10%, that the statement came from page 3 of the amendment filed on a given date, and that an analyst checked it and recorded the decision. That is an explainable decision, even if the model inside is not fully explainable.
An audit trail for AI-assisted decisions links four things: what went in, what came out, where it came from, and what a person did with it.
| Element | What to Capture | Why |
|---|---|---|
| Inputs | The documents and data the tool used, with their dates and a fixed copy or fingerprint of each | Documents change; the record must show what the tool actually read |
| Tool and version | Tool name, underlying model and version, prompt or configuration version | The same input can produce different outputs under a different version |
| Time | When the output was produced | Places the output against what the firm knew at the time |
| Output | The output exactly as produced, before any edits | Shows what the tool said, separately from what the firm concluded |
| Sources | For each statement or value, the document, page or data point it came from | Makes each output checkable |
| Flags | Any warnings the tool raised, such as low confidence, scanned input or missing data | Shows whether known weaknesses were visible to the reviewer |
| Review | Who reviewed it, when, and whether they accepted, edited or rejected it, with any edits captured | Shows human judgment was applied, and where the tool was wrong |
| Decision | A link to the product decision the output informed, and the reasoning recorded by the decision-maker | Connects the AI trail to the product record |
Keep the tool's words and the person's words apart. If an AI-drafted summary is pasted into a product file and lightly edited, no one can later tell which parts were the firm's analysis. The original output, the edits and the final text should all be recoverable.
An illustrative audit record for a hypothetical fund:
This record answers every question a reviewer is likely to ask: what the tool saw, what it said, where each statement came from, where it was wrong, who checked it and who decided. The error on the auditor is as useful as the correct findings: it is evidence that review was real, and a data point for monitoring the tool.
Pick an AI-assisted product decision from six to twelve months ago and try to answer these questions using only the records, without asking anyone who was involved:
| Question | Record That Answers It |
|---|---|
| What documents and data did the tool use? | Inputs, with fixed copies |
| Which tool and version produced the output? | Tool and version |
| What exactly did it produce? | Output, unedited |
| Where did each statement come from? | Sources |
| Did it warn about anything? | Flags |
| Who checked it, and what did they change? | Review |
| Who made the decision, and why? | Decision |
| Was the tool validated and approved for this use at the time? | Model inventory and validation record |
Any question that can't be answered from the records is a gap. Running this test on a small sample each year, and after any change to an AI tool, shows whether the trail works before an examiner tests it.
Explainability is far easier to build in than to add later. Most of it comes down to a few design choices made when a tool is selected or configured.
| Gap | Consequence | Fix |
|---|---|---|
| AI summary pasted into the product file without marking | The firm can't show which analysis was its own | Store the original output separately; mark AI-drafted text |
| No record of model or prompt version | The output can't be reproduced or explained after a vendor update | Stamp versions on every output |
| Reviewer overwrites the AI output | Evidence of review, and of the tool's errors, is lost | Keep original, edits and final text |
| Logs held only in the vendor's system, deleted after a short period | Records gone before the retention period ends | Contractual retention, or export to firm records |
| Source document not kept | Can't show what the tool read if the issuer later changes the online version | Store a fixed copy of each input |
| Agent actions summarized, not logged | Can't trace what an agent did or why | Step-level action log |
| Research assistant answers used without record | An input to a decision disappears | Save answers that inform a product decision to the product file, with sources |
The firm designs the trail. Everyone who uses AI output in product work adds to it.