I appreciate the opportunity to comment on FINRA's proposed amendments to Rule 2210.
My perspective comes from several years working in compliance technology at a broker-dealer, where I was directly responsible for building, operating, and maintaining the infrastructure used to capture, archive, supervise, and produce electronic data for regulatory oversight. That operational background gives me a grounded, technical vantage point on this proposal. I lived the daily realities of trying to satisfy regulatory expectations across evolving communication channels, shifting third-party vendor capabilities, and expanding supervisory demands.
I strongly support FINRA's effort to modernize Rule 2210 and move toward a risk-based supervisory framework. However, the proposal as written underestimates where firms experience the greatest operational risk and cost, while providing insufficient guidance on how to govern the technologies doing the work.
1. Capture Is the Foundation of Supervision (Not AI Review)
Much of the discussion in the Notice focuses on reviewing retail communications after they exist. In practice, supervision begins much earlier: a communication cannot be reviewed, archived, searched, or produced during an examination unless it is successfully captured first.
Capturing data across an ever-expanding ecosystem whether Microsoft Teams, Zoom, WhatsApp, CellTrust, Bloomberg, Threads, Bluesky, Substack, RedNote, Lemon8, or whatever platform emerges tomorrow requires continuous integration, testing, and capital expenditure.
The Reality of AI Review: AI cannot review, score, or audit data that was never captured.
Understated Economic Impact: FINRA's preliminary economic assessment focuses heavily on principal review time, significantly understating the total cost of compliance. In compliance IT, data capture and ingestion not review, represent the highest operational expense and regulatory risk.
2. The Dependency on Third-Party Vendors Creates a Regulatory Trap
Broker-dealers are almost entirely reliant on third-party archiving vendors to build capture tools for new communication platforms. This creates a severe structural issue:
Every time a new platform emerges, firms must wait for vendors to build capture capabilities, test the APIs, validate data integrity, and integrate the feed into archival systems.
Unfair Liability: If a platform alters its API or a vendor's capture mechanism fails, the regulatory liability and resulting fines fall entirely on the member firm, not the vendor.
Recommendation: FINRA should establish minimum technical expectations for platform capture or provide a good-faith safe harbor for member firms that demonstrate robust vendor due diligence, validation, and ongoing monitoring.
3. "Reasonably Designed" Requires Clearer Guidelines and Safe Harbors
While moving to a risk-based model is directionally correct, the proposal repeatedly relies on firms establishing procedures that are "reasonably designed" without defining the baseline.
Reasonable according to whom? An examiner, a firm's CCO, outside counsel, or a software vendor? Without concrete guidance, firms acting in good faith will develop vastly different supervisory models, only to learn FINRA's preferred interpretation during an enforcement audit.
Recommendation: FINRA should publish practical implementation guidance, supervisory scenarios, and worked examples illustrating what a "reasonably designed" risk-based program looks like in practice.
4. AI Governance Must Extend to the "AI Reviewer," Not Just AI-Generated Content
The Notice discusses AI primarily as a tool for generating communications, with brief mention of using AI to supervise content. These represent fundamentally different control challenges. When a firm deploys AI to review or approve communications, the AI tool itself becomes part of the firm's supervisory control environment.
Through my work developing AI governance framework, I have found that governing the AI performing supervisory activities requires explicit operational controls, including:
Documented model validation and prompt oversight.
Audit trails showing which model version evaluated a specific communication.
Systemic monitoring for model drift, false positives, and false negatives.
Clear human escalation thresholds and assigned human accountability.
Without explicit guidance on governing the "AI Reviewer," firms risk deploying opaque automation that fails quietly while technically fulfilling the rule on paper.
5. Human Judgment Must Remain the Final Supervisory Authority for Complex Language
Large language models (LLMs) are valuable for prioritizing and flagging high-risk text, but current AI architectures cannot reliably evaluate idiomatic language, regional dialects, sarcasm, slang, or context-heavy trader colloquialisms.
Phrases like "we killed that trade," "I got murdered on that position," "she has mad skills," or "he had Nostradamus like insight" carry potential regulatory risk (e.g., exaggerated claims or implied guarantees), but literal or automated evaluation routinely misinterprets their intent.
Recommendation: FINRA should explicitly clarify that AI tools should augment supervisory professionals not replace them and that ambiguous, slang-heavy, or context-dependent communications must route to qualified human review by default.
Conclusion
FINRA is right to modernize Rule 2210. However, true modernization requires recognizing where operational risk actually sits: in the data capture layer, in the third-party vendor pipeline, and in the governance of AI oversight tools.
Accompanying any final rule with explicit guidance on communications capture standards, AI reviewer governance, and practical supervisory examples will protect investors while giving firms a clear, defensible path to compliance.
FINRA Utility Menu
For the Public
FINRA DATA
FINRA Data provides non-commercial use of data, specifically the ability to save data views and create and manage a Bond Watchlist.
For Industry Professionals
FINPRO GATEWAY
Registered representatives can fulfill Continuing Education requirements, view their industry CRD record and perform other compliance tasks.
For Member Firms
FINRA GATEWAY
Firm compliance professionals can access filings and requests, run reports and submit support tickets.
For Case Participants
DR PORTAL
Arbitration and mediation case participants and FINRA neutrals can view case information and submit documents through this Dispute Resolution Portal.
Need Help? | Check System Status
Log In to other FINRA systems
Jaime Arroyave Comment On Regulatory Notice 26-14
Dear Jennifer Mitchell,
I appreciate the opportunity to comment on FINRA's proposed amendments to Rule 2210.
My perspective comes from several years working in compliance technology at a broker-dealer, where I was directly responsible for building, operating, and maintaining the infrastructure used to capture, archive, supervise, and produce electronic data for regulatory oversight. That operational background gives me a grounded, technical vantage point on this proposal. I lived the daily realities of trying to satisfy regulatory expectations across evolving communication channels, shifting third-party vendor capabilities, and expanding supervisory demands.
I strongly support FINRA's effort to modernize Rule 2210 and move toward a risk-based supervisory framework. However, the proposal as written underestimates where firms experience the greatest operational risk and cost, while providing insufficient guidance on how to govern the technologies doing the work.
1. Capture Is the Foundation of Supervision (Not AI Review)
Much of the discussion in the Notice focuses on reviewing retail communications after they exist. In practice, supervision begins much earlier: a communication cannot be reviewed, archived, searched, or produced during an examination unless it is successfully captured first.
Capturing data across an ever-expanding ecosystem whether Microsoft Teams, Zoom, WhatsApp, CellTrust, Bloomberg, Threads, Bluesky, Substack, RedNote, Lemon8, or whatever platform emerges tomorrow requires continuous integration, testing, and capital expenditure.
The Reality of AI Review: AI cannot review, score, or audit data that was never captured.
Understated Economic Impact: FINRA's preliminary economic assessment focuses heavily on principal review time, significantly understating the total cost of compliance. In compliance IT, data capture and ingestion not review, represent the highest operational expense and regulatory risk.
2. The Dependency on Third-Party Vendors Creates a Regulatory Trap
Broker-dealers are almost entirely reliant on third-party archiving vendors to build capture tools for new communication platforms. This creates a severe structural issue:
Every time a new platform emerges, firms must wait for vendors to build capture capabilities, test the APIs, validate data integrity, and integrate the feed into archival systems.
Unfair Liability: If a platform alters its API or a vendor's capture mechanism fails, the regulatory liability and resulting fines fall entirely on the member firm, not the vendor.
Recommendation: FINRA should establish minimum technical expectations for platform capture or provide a good-faith safe harbor for member firms that demonstrate robust vendor due diligence, validation, and ongoing monitoring.
3. "Reasonably Designed" Requires Clearer Guidelines and Safe Harbors
While moving to a risk-based model is directionally correct, the proposal repeatedly relies on firms establishing procedures that are "reasonably designed" without defining the baseline.
Reasonable according to whom? An examiner, a firm's CCO, outside counsel, or a software vendor? Without concrete guidance, firms acting in good faith will develop vastly different supervisory models, only to learn FINRA's preferred interpretation during an enforcement audit.
Recommendation: FINRA should publish practical implementation guidance, supervisory scenarios, and worked examples illustrating what a "reasonably designed" risk-based program looks like in practice.
4. AI Governance Must Extend to the "AI Reviewer," Not Just AI-Generated Content
The Notice discusses AI primarily as a tool for generating communications, with brief mention of using AI to supervise content. These represent fundamentally different control challenges. When a firm deploys AI to review or approve communications, the AI tool itself becomes part of the firm's supervisory control environment.
Through my work developing AI governance framework, I have found that governing the AI performing supervisory activities requires explicit operational controls, including:
Documented model validation and prompt oversight.
Audit trails showing which model version evaluated a specific communication.
Systemic monitoring for model drift, false positives, and false negatives.
Clear human escalation thresholds and assigned human accountability.
Without explicit guidance on governing the "AI Reviewer," firms risk deploying opaque automation that fails quietly while technically fulfilling the rule on paper.
5. Human Judgment Must Remain the Final Supervisory Authority for Complex Language
Large language models (LLMs) are valuable for prioritizing and flagging high-risk text, but current AI architectures cannot reliably evaluate idiomatic language, regional dialects, sarcasm, slang, or context-heavy trader colloquialisms.
Phrases like "we killed that trade," "I got murdered on that position," "she has mad skills," or "he had Nostradamus like insight" carry potential regulatory risk (e.g., exaggerated claims or implied guarantees), but literal or automated evaluation routinely misinterprets their intent.
Recommendation: FINRA should explicitly clarify that AI tools should augment supervisory professionals not replace them and that ambiguous, slang-heavy, or context-dependent communications must route to qualified human review by default.
Conclusion
FINRA is right to modernize Rule 2210. However, true modernization requires recognizing where operational risk actually sits: in the data capture layer, in the third-party vendor pipeline, and in the governance of AI oversight tools.
Accompanying any final rule with explicit guidance on communications capture standards, AI reviewer governance, and practical supervisory examples will protect investors while giving firms a clear, defensible path to compliance.
Thank you for the opportunity to comment.
Jaime Arroyave Founder, 2120 Stumpf Consulting