EPC Group - Enterprise Microsoft AI, SharePoint, Power BI, and Azure Consulting
G2 High Performer Summer 2025, Momentum Leader Spring 2025, Leader Winter 2025, Leader Spring 2026
BlogContact
Ready to transform your Microsoft environment?Get started today
(888) 381-9725Get Free Consultation
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌

EPC Group

Enterprise Microsoft consulting with 29 years serving Fortune 500 companies.

(888) 381-9725
contact@epcgroup.net
4900 Woodway Drive, Suite 830
Houston, TX 77056

Follow Us

Solutions

  • M&A Practices

    • M&A Tenant Migration
    • Carve-Out Migration
    • Private Equity Practice
    • Engagement Operating Model
  • All Services
  • Microsoft 365 Consulting
  • AI Governance
  • Azure AI Consulting
  • Cloud Migration
  • Microsoft Copilot
  • Data Governance
  • Microsoft Fabric
  • Dynamics 365
  • Power BI Consulting
  • SharePoint Consulting
  • Microsoft Teams
  • vCIO / vCAIO Services
  • Large-Scale Migrations
  • SharePoint Development

Industries

  • All Industries
  • Healthcare IT
  • Financial Services
  • Government
  • Education
  • Teams vs Slack

Power BI

  • Case Studies
  • 24/7 Emergency Support
  • Dashboard Guide
  • Gateway Setup
  • Premium Features
  • Lookup Functions
  • Power Pivot vs BI
  • Treemaps Guide
  • Dataverse
  • Power BI Consulting

Company

  • About Us
  • Our History
  • Microsoft Gold Partner
  • Case Studies
  • Testimonials
  • Fixed-Fee Accelerators
  • Blog
  • Resources
  • All Guides & Articles
  • Video Library
  • Client Reviews
  • Engagement Operating Model
  • FAQ
  • Contact
  • Schedule a consultation

Microsoft Teams

  • Teams Questions
  • Teams Healthcare
  • Task Management
  • PSTN Calling
  • Enable Dial Pad

Azure & SharePoint

  • Azure Databricks
  • Azure DevOps
  • Azure Synapse
  • SharePoint MySites
  • SharePoint ECM
  • SharePoint vs M-Files

Comparisons

  • M365 vs Google
  • Databricks vs Dataproc
  • Dynamics vs SAP
  • Intune vs SCCM
  • Power BI vs MicroStrategy

Legal

  • Sitemap
  • Privacy Policy
  • Terms
  • Cookies

About EPC Group

EPC Group is a Microsoft consulting firm founded in 1997 (originally Enterprise Project Consulting, renamed EPC Group in 2005). 29 years of enterprise Microsoft consulting experience. EPC Group historically held the distinction of being the oldest continuous Microsoft Gold Partner in North America from 2016 until the program's retirement. Because Microsoft officially deprecated the Gold/Silver tiering framework, EPC Group transitioned to the modern Microsoft Solutions Partner ecosystem and currently holds the core Microsoft Solutions Partner designations.

Headquartered at 4900 Woodway Drive, Suite 830, Houston, TX 77056. Public clients include NASA, FBI, Federal Reserve, Pentagon, United Airlines, PepsiCo, Nike, and Northrop Grumman. 6,500+ SharePoint implementations, 1,500+ Power BI deployments, 500+ Microsoft Fabric implementations, 70+ Fortune 500 organizations served, 11,000+ enterprise engagements, 200+ Microsoft Power BI and Microsoft 365 consultants on staff.

About Errin O'Connor

Errin O'Connor is the Founder, CEO, and Chief AI Architect of EPC Group. Microsoft MVP multiple years, first awarded 2003. 4× Microsoft Press bestselling author of Windows SharePoint Services 3.0 Inside Out (MS Press 2007), Microsoft SharePoint Foundation 2010 Inside Out (MS Press 2011), SharePoint 2013 Field Guide (Sams/Pearson 2014), and Microsoft Power BI Dashboards Step by Step (MS Press 2018).

Original SharePoint Beta Team member (Project Tahoe). Original Power BI Beta Team member (Project Crescent). FedRAMP framework contributor. Worked with U.S. CIO Vivek Kundra on the Obama administration's 25-Point Plan to reform federal IT, and with NASA CIO Chris Kemp as Lead Architect on the NASA Nebula Cloud project. Speaker at Microsoft Ignite, SharePoint Conference, KMWorld, and DATAVERSITY.

© 2026 EPC Group. All rights reserved. Microsoft, SharePoint, Power BI, Azure, Microsoft 365, Microsoft Copilot, Microsoft Fabric, and Microsoft Dynamics 365 are trademarks of the Microsoft group of companies.

‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
FINRA + SEC Microsoft Copilot Controls Checklist (2026) - EPC Group enterprise consulting

FINRA + SEC Microsoft Copilot Controls Checklist (2026)

The 38-control buyer's checklist for FINRA-regulated broker-dealers + SEC-registered RIAs deploying Microsoft 365 Copilot. SEC 17a-4, FINRA Rule 4511, Reg BI, NIST CSF mapping. Built from financial services Copilot rollouts.

HomeBlogAI Governance
Back to BlogAI Governance

FINRA + SEC Microsoft Copilot Controls Checklist (2026)

The 38-control buyer's checklist for FINRA-regulated broker-dealers + SEC-registered RIAs deploying Microsoft 365 Copilot. SEC 17a-4, FINRA Rule 4511, Reg BI, NIST CSF mapping. Built from financial services Copilot rollouts.

EO
Errin O'Connor
CEO & Chief AI Architect
•
May 20, 2026
•
11 min read
FINRASECMicrosoft 365 CopilotFinancial ServicesReg BIComplianceMNPICommunication CompliancePurview
FINRA + SEC Microsoft Copilot Controls Checklist (2026)
11 min readPublished May 20, 2026

Key Takeaways

  • The 38-control buyer's checklist for FINRA-regulated broker-dealers + SEC-registered RIAs deploying Microsoft 365 Copilot. SEC 17a-4, FINRA Rule 4511, Reg BI, NIST CSF mapping. Built from financial services Copilot rollouts.

FINRA + SEC Microsoft Copilot Controls Checklist

The 38-control checklist for FINRA-regulated broker-dealers + SEC-registered investment advisers (RIAs) deploying Microsoft 365 Copilot. Use as a procurement + readiness gating tool.

Scope reminder. This checklist applies to Microsoft 365 tenants where Copilot may be exposed to MNPI (material non-public information), client trading data, suitability records, communications with retail customers, or other FINRA/SEC-regulated content. Coordinate with your compliance officer + outside counsel.

Quick Answer

FINRA + SEC Microsoft Copilot deployment requires controls across 8 families: communications surveillance (FINRA Rule 3110), books and records (SEC 17a-4 + FINRA 4511), supervision (FINRA 3110), customer best interest (Reg BI for broker-dealers; fiduciary duty for RIAs), cybersecurity (Reg S-P + Reg SCI), records retention (6-7 years), MNPI handling, and AML/KYC.

The 38-Control Checklist

Family 1: Communications Surveillance (FINRA Rule 3110, 3120) — 6 controls

  • ☐ 1. Microsoft Purview Communication Compliance policy: ALL Copilot prompts + responses scanned
  • ☐ 2. Policy: outbound customer communications (email, Teams chat) scanned for suitability red flags
  • ☐ 3. Policy: internal-only Copilot responses to customer-facing employees scanned
  • ☐ 4. Reviewer assignment: Chief Compliance Officer + named supervisor team
  • ☐ 5. Remediation SLA: 24 hours for surveillance hit
  • ☐ 6. Quarterly false-positive tuning + supervisor calibration session

Family 2: Books and Records (SEC 17a-4 + FINRA Rule 4511) — 6 controls

  • ☐ 7. Microsoft Purview Audit (Premium) enabled with 10-year retention
  • ☐ 8. Audit log streaming to WORM-compliant storage (Azure Immutable Storage or 3rd-party)
  • ☐ 9. Microsoft 365 Copilot interaction audit: prompts, responses, grounding sources
  • ☐ 10. Retention label R-7 applied to all customer-facing Copilot outputs
  • ☐ 11. Litigation hold capability for customer-specific data
  • ☐ 12. Annual records retention attestation by named officer

Family 3: Supervision Framework (FINRA Rule 3110) — 5 controls

  • ☐ 13. Written supervisory procedures (WSP) updated to reference Microsoft Copilot
  • ☐ 14. Designated principal for Copilot oversight (registered + named)
  • ☐ 15. Annual Copilot supervision certification by CCO
  • ☐ 16. Branch office supervision policy includes Copilot use cases
  • ☐ 17. Heightened supervision for high-risk personas (registered reps, traders)

Family 4: Best Interest / Fiduciary (Reg BI for BDs; Investment Advisers Act for RIAs) — 4 controls

  • ☐ 18. Copilot use case approval list (which personas use Copilot for which workflows)
  • ☐ 19. Suitability decision documentation: Copilot must not be the sole basis for recommendation
  • ☐ 20. Customer disclosure: AI assistance used in operations (if material)
  • ☐ 21. Conflict of interest review: Copilot prompts not steered toward proprietary product

Family 5: Cybersecurity (Reg S-P + Reg SCI for SROs) — 6 controls

  • ☐ 22. Conditional Access: Copilot access requires phishing-resistant MFA
  • ☐ 23. Microsoft Defender for Cloud Apps anomaly alerts
  • ☐ 24. Information Barrier policy: research vs investment banking (where applicable)
  • ☐ 25. Microsoft Sentinel financial-services analytics rules
  • ☐ 26. Annual penetration test scope includes Copilot
  • ☐ 27. Incident response playbook updated for Copilot-specific scenarios

Family 6: MNPI Handling — 4 controls

  • ☐ 28. Sensitivity label "MNPI-Restricted" with encryption + do-not-forward
  • ☐ 29. Restricted SharePoint Search excludes MNPI sites from Copilot grounding
  • ☐ 30. DLP for Copilot: blocks MNPI keywords + ticker symbols in M&A pipeline
  • ☐ 31. Quarterly MNPI exposure review with named reviewers

Family 7: AML / KYC / Suspicious Activity (BSA + FinCEN) — 4 controls

  • ☐ 32. Copilot prompts on customer accounts scanned for SAR indicators
  • ☐ 33. Customer due diligence documents flagged for retention
  • ☐ 34. OFAC sanctions screening integrated with Copilot grounding
  • ☐ 35. Annual BSA/AML attestation by BSA officer

Family 8: Governance + Vendor Management — 3 controls

  • ☐ 36. Microsoft BAA + DPA + standard contractual clauses verified
  • ☐ 37. Third-party Copilot Studio agents reviewed via vendor management process
  • ☐ 38. Annual third-party audit (SOC 2 + customized) includes Copilot scope

Reg BI vs Investment Advisers Act Differences

Broker-Dealer (Reg BI): Customer-specific best interest standard. Disclosure of material conflicts. Reasonable basis for recommendation. Compliance with Form CRS.

Investment Adviser (Advisers Act): Fiduciary duty of care + loyalty. Mid-contract disclosure obligations. Form ADV updates.

Both: Copilot recommendations cannot be the SOLE basis for customer-facing recommendation. Human-in-the-loop required.

Microsoft 365 E7 vs E5 for FINRA/SEC Copilot

Capability E5 + Copilot M365 E7
Microsoft 365 Copilot Add-on ($30/user/mo) Bundled
Communication Compliance E5 included E7 included
Information Barriers E5 included E7 included
Purview Audit Premium E5 included E7 included
Microsoft Agent 365 Add-on $45/user/mo Bundled
Per user/month $90+ $99 ($84.15 CSP promo through Dec 31 2026)

E7 wins for any broker-dealer or RIA running 200+ Copilot licenses (Agent 365 governance becomes operational at scale).

Implementation Sequence

Phase 1 (Weeks 1-4): Foundation — Identity (C22), Audit Premium (C7), Communication Compliance policy authoring (C1-5).

Phase 2 (Weeks 5-12): Data Classification — sensitivity label taxonomy + MNPI controls (C28-31) + Information Barriers (C24).

Phase 3 (Weeks 13-20): Supervision Framework — WSP update (C13), designated principal (C14), branch office training (C16).

Phase 4 (Weeks 21-26): Validation — quarterly tuning (C6), penetration test (C26), CCO attestation (C15).

Total: 26 weeks (6 months) to fully-controlled state. Pilot can begin at end of Phase 1.

Bottom Line

Use this 38-control checklist as a procurement + readiness gate before Copilot rollout. Map each control to a named owner. EPC Group ships a tailored version of this checklist with every financial services Copilot governance engagement.

Frequently Asked Questions

Q: Is Microsoft 365 Copilot FINRA-compliant out of the box?
A: No. Microsoft provides the platform + audit + Communication Compliance capabilities. Customer must configure + supervise per FINRA + SEC requirements.

Q: How long until Copilot is FINRA-safe to roll out?
A: 12-16 weeks for pilot with disciplined execution; 24-26 weeks for enterprise rollout with EPC Group support.

Q: What about Microsoft Copilot Studio agents in BD/RIA environments?
A: Each agent must go through vendor management + governance review. Treat as a third-party AI system. Document agent purpose, data path, retention, supervision.

Q: Does Copilot replace human supervision under FINRA Rule 3110?
A: No. Copilot is a tool. Supervision remains a human registered principal responsibility. Document the supervision-Copilot interaction model.

Q: What about state-registered investment advisers?
A: Apply state-specific overlays (e.g., NY BitLicense, California SB 327 IoT, etc) on top of this federal baseline.

Q: Why EPC Group?
A: 29 years Microsoft + financial services consulting. Errin O'Connor previously held a Lead Architect role at the Federal Reserve Bank of New York. Microsoft Solutions Partner with all six designations. See /reviews.

Next Steps

  • Schedule a FINRA/SEC Copilot Discovery: /contact
  • Productized readiness assessment: /services/microsoft-365-copilot-readiness-assessment
  • Ongoing engagement: /services/copilot-governance-consulting
  • Call (888) 381-9725
Share this article:
EO

Errin O'Connor

CEO & Chief AI Architect

Microsoft Press bestselling author with 29 years of enterprise consulting experience.

View Full Profile

Related Articles

AI Governance

Microsoft 365 Copilot HIPAA Governance Blueprint (2026)

Microsoft 365 Copilot HIPAA blueprint: 47-control governance framework, BAA scope, ePHI sensitivity labels, Communication Compliance for Copilot, audit trail, breach response. Built from Fortune 500 healthcare Copilot rollouts.

AI Governance

SharePoint Retention + Purview Label Mapping: Enterprise Reference (2026)

Complete reference mapping between SharePoint content types and Microsoft Purview retention labels. Per content category, jurisdiction, regulatory framework. Includes autolabeling rules and Copilot-impact analysis.

AI Governance

EU AI Act Enforcement August 2026: Enterprise Compliance Checklist

The EU AI Act high-risk system requirements enforce August 2, 2026. Article 6 + Annex III high-risk classification, AI literacy obligations (Article 4), data governance, technical documentation. 12-week enterprise compliance checklist.

Need Help with AI Governance?

Our team of experts can help you implement enterprise-grade ai governance solutions tailored to your organization's needs.

AI Governance Consulting ServicesSchedule a Consultation