A compliance consultant retainer vs. a Discover scan
Author
Audrey
NobleCloak's AI Correspondent · AI-drafted, fact-checked against our sourced evidence before publishing.
Date Published
If you're an RIA, you probably already pay a compliance consultant. A typical retainer runs about $8,000–$15,000 a year, and for most firms it's money well spent: the consultant is your compliance calendar, your mock-exam partner, your Form ADV sanity check, and the person who picks up the phone when the SEC's Division of Examinations sends a document request. This post is not an argument to fire them. It's the opposite — the consultant is the relationship you keep. It's an argument about one specific line item that standard retainer scope almost never includes, and what to do about it.
Go read your engagement letter. Look for the words "AI vendor risk," or "AI due diligence," or even "artificial intelligence." For the large majority of RIA compliance retainers, they aren't there. That's not an oversight and it's not a knock on your consultant — it's a scope boundary, and understanding it precisely is how you close the gap without disrupting a relationship that's working.
What the retainer covers — and it's a lot
A good compliance consultant earns the fee. Standard scope typically includes:
- The annual compliance program review required under the Advisers Act, and the written policies and procedures that go with it.
- Form ADV drafting, updating, and consistency checks — making sure what you disclose matches what you do.
- Mock exams and exam support — dry-running the SEC's questions and standing beside you when the real request arrives.
- The compliance calendar — the deadlines, filings, and annual obligations that are easy to miss and expensive to blow.
- Reg S-P policy work — and this is where the seam shows, so hold it for a second.
This is the relationship layer. It's judgment, continuity, and someone who knows your firm. No report replaces it, and you shouldn't want one to.
The seam: Reg S-P now names vendor oversight, and AI is the hardest vendor
Here's the specific place the gap opens. The amended Reg Safeguards Rule is live for the entire covered market — larger firms since December 3, 2025, and all smaller RIAs and broker-dealers since June 3, 2026 (the SIFMA/IAA extension request was denied). The rule text (17 CFR 248.30(a)(5)) requires written policies mandating ongoing "oversight, including through due diligence and monitoring, of service providers," plus a 72-hour provider-to-firm breach-notice expectation and a written incident-response program. And Reg S-P compliance is a named SEC Division of Examinations FY2026 priority.
Your consultant will almost certainly help you write the policy that says you conduct service-provider oversight. That's squarely in scope. What standard retainer scope does not include is performing the AI-specific vendor diligence that the policy commits you to — sitting down with each AI vendor's data-handling terms, sub-processor list, retention policy, and training-on-your-data posture, and producing the documented findings that prove the oversight actually happened.
Writing "we oversee our service providers" is the policy. Having the file that shows what you found when you oversaw the AI ones is the evidence. The retainer typically buys the first. The exam increasingly asks for the second. (We walk through building that file by hand in The Reg S-P service-provider oversight file step by step.)
Why this gap is nobody's fault
It's worth being clear that this isn't a failure of your consultant. AI vendor risk is a young, fast-moving, technical diligence discipline — it means reading OAuth grants, parsing DPAs, tracking sub-processors that change quarterly, and knowing which "we don't train on your data" claims have an asterisk. That's a different muscle than Advisers Act compliance, and pricing it into a general retainer would balloon the fee for a capability most firms only recently needed. The standard scope reflects what the discipline was when the engagement was written. The AI line item is new because the exposure is new.
So the honest framing is complement, not replacement: the consultant is the relationship; the Discover scan is the AI-specific artifact they don't produce. The two sit in the same binder and answer to the same examiner.
Side by side
| Compliance consultant retainer | Discover scan |
|---|---|---|
What it is | The relationship — ongoing judgment and continuity | An artifact — the AI vendor-diligence file |
Typical cost | ~$8–15k/yr | Priced per assessment, small-firm friendly |
Form ADV, mock exams, calendar | Core scope | Not its job |
Reg S-P policy language | Yes — writes the policy | Not its job |
AI-specific vendor findings | Rarely in scope | The core deliverable |
AI inventory from your OAuth grants | Not typically performed | Read for you |
Relationship to the other | Keep it | Fills the one line the retainer leaves out |
When the consultant alone is enough
Because candor is the brand, here's when you may not need a separate AI artifact at all:
- Your consultant already scopes AI vendor diligence explicitly — and some of the larger, more technical firms are starting to. If "AI vendor risk assessment" is a named deliverable in your engagement and they produce documented, sourced findings, you're covered. Read your letter; don't assume the gap exists if it doesn't.
- Your firm uses essentially no AI. If your tech stack is deliberately AI-free and your vendors haven't slipped it in — check that second part, because Your vendors are adding AI without telling you is exactly how firms get surprised — there may be little to assess yet.
- You have the hours to build it in-house and want to. The Build vs buy — assembling the AI vendor binder yourself math applies to RIAs too.
If none of those hold — you use AI, your vendors are adding it, and your retainer doesn't name it — that's the gap, and it's the common case.
The bottom line
Your compliance consultant is the relationship, and you should keep it. But the standard $8–15k retainer buys the compliance program — Form ADV, mock exams, the calendar, the policies — and rarely buys the AI-specific vendor diligence that your own Reg S-P policy now commits you to and that the SEC has named an exam priority. That's not a reason to change consultants. It's a reason to hand them the one artifact they don't produce, so your file is complete when the request arrives.
Your Discover report is that artifact — produced by the AI Discover scan, run with you, with the vendor findings backed by NobleCloak Vendor Intelligence, the research library behind every report, and mapped to the Reg S-P oversight language your examiner uses. **Get your Reg S-P AI vendor file** and give your consultant the evidence to sit alongside the policy they wrote.
New to the Reg S-P vendor-oversight obligation? Start with Reg S-P is live — the AI vendor file your examiner expects, and see the industry page at RIA and Reg S-P AI vendor oversight for the fast-lane overview.