Blog Post

AI Governance Where the Regulator Also Runs the Market

October 7, 2026

Table of Contents

AI governance evidence is usually prepared for a neutral reader. A regulator with no stake in the market, an auditor with no competing product, an examiner who gains nothing from what the documentation contains.

‍

In securities and derivatives markets that assumption does not hold. Exchanges and clearing organizations register as self-regulatory organizations, and most of them operate the market while regulating its participants. The reader of your evidence is also an operator.

‍

Is the Structure Really Like That?

‍

It is codified, and the supervising agency has named the conflict explicitly in its own concept release on the model.

‍

Broker-dealers are required to belong to a self-regulatory organization that sets standards, conducts examinations and enforces rules over its members. Most such organizations also operate and regulate markets or clearing services. The agency's own language describes an inherent conflict where a body both serves the commercial interests of its members and regulates them.

‍

The Conflict Was Noted as Increasing

‍

The same release observes that conversion of some of these organizations to publicly traded, for-profit status may increase the conflicts inherent in the model. So the reader of your governance evidence may be a listed company with shareholders, competing for the order flow your systems generate.

‍

Which Reader Are You Writing For?

‍

Three at once, and they want different things from the same document.

‍

Control panel showing the fields transmitted from a device beside a separate list of content types never transmitted
An explicit list of what is disclosed and what is withheld is the shape a disclosure decision needs, whoever the recipient turns out to be.

An assessor establishing whether your system meets the rules. An operator whose venue your system trades on. Frequently a peer deployer too, since the same organization runs its own AI for surveillance and market monitoring. A detailed account of how your model works serves the first reader and informs the other two.

‍

Which Splits the Evidence in Two

‍

Outcome evidence describes what the system does and how well, covering error rates, oversight records, exception handling and the decisions it produced. Design evidence describes how it works, covering features, weightings, architecture and training approach. An assessment needs the first. A competitor would want the second.

‍

What Should Be Provided?

‍

Outcome evidence in full, and design evidence only where specifically required rather than by default.

‍

Most firms hand over both, because nobody separated them and a request for documentation reads as a request for everything. Preparing the two as distinct packages costs one afternoon and changes what leaves the building, and the distinction survives whoever the recipient is, which records that hold more than the current state makes easier because outcome evidence is mostly automatic.

‍

What If Design Detail Is Demanded?

‍

Provide it and record the demand. A documented request from a named party on a stated date is a materially different position from voluntary disclosure, and the record matters if the information later appears to have informed a competing product.

‍

Does a Non-Neutral Assessor Go Easier?

‍

Frequently harder, which is the finding that inverts the expected conclusion.

‍

Compliance readiness scored separately across several frameworks and regimes, each with its own assessment result
A per-regime position is what an assessment by a participant requires, since the standard being applied may be the assessor's own practice rather than a published one.

The assessing organization is itself supervised. In 2013 an options exchange paid a six million dollar penalty in what the agency described as the first financial penalty against an exchange for regulatory oversight failures, following systemic breakdowns in its regulatory and compliance functions.

‍

Which Creates an Incentive to Over-Assess

‍

An organization that has been penalized for insufficient rigor has a reason to demonstrate rigor. So the expectation of leniency from a commercially interested assessor is the wrong way round, and the realistic expectation is a demanding assessment conducted by somebody who also benefits from what they learn.

‍

What Is the Appeal Route?

‍

Available, and knowing it exists changes how a disagreement is handled.

‍

The supervising agency requires approval for rule changes and permits review of disciplinary actions taken by these organizations, so a determination is not final in the way a government regulator's finding would be. The agency rarely reverses disciplinary actions, so the route is a constraint on the assessor's conduct rather than a likely remedy.

‍

What Does That Change Practically?

‍

How a disagreement is documented rather than whether it is pursued. A position recorded at the time, with the reasoning and the standard being applied, is what a review would examine, and it cannot be assembled afterward, which producing evidence on somebody else's timeline covers as a general capability.

‍

Where Else Does This Structure Appear?

‍

In payment networks above all, where the same three roles sit in one organization.

‍

Card networks write the operating rules, run the network those rules govern, and levy assessments for breaches of them. The enforcement runs through an acquiring bank rather than directly, which adds a layer without changing the structure, and losing the right to process sets out the exposure that follows.

‍

What Do the Two Cases Share?

‍

A rule-maker with commercial interests in the conduct being regulated, and a remedy that is commercial rather than statutory. In both, the practical position depends on the relationship as much as on the rules, which is uncomfortable and worth planning around rather than resenting.

‍

Does the Assessor's Own System Set the Standard?

‍

In practice frequently, and knowing that is worth more than reading the published rules.

‍

Where the assessing organization runs its own AI for market monitoring or surveillance, whatever that system does becomes the working benchmark for what adequate looks like. A firm whose oversight arrangement is less rigorous than the assessor's own has a harder conversation regardless of what the rulebook requires, and one whose arrangement is more rigorous has an easier one.

‍

How Would You Know What It Does?

‍

Public material, mostly. These organizations publish descriptions of their surveillance capability because it is a selling point for market quality, so the general shape is available without asking. Reading it before an assessment is cheap preparation nobody does.

‍

Which Cuts the Other Way Too

‍

An assessor running its own AI for the same function has direct operational experience of the failure modes, which makes it a more informed reader than a government examiner would be. The result is a harder audience and a better one, since an argument that survives it is likely to survive anything, and a reviewer who can genuinely evaluate the work is rarer than the alternative.

‍

What Should Be Established?

‍

Three things, and the first is a document split rather than an analysis.

‍

Which of your AI governance evidence is outcome evidence and which is design evidence, prepared as two packages. Whether the assessing organization operates its own AI system for the same function, since that establishes the standard being applied in practice. Then whether any design disclosure to date was requested or volunteered, because the record differs. AI compliance readiness assessed per requirement is what shows which package a given request calls for, and a defensible framework for regulated industries assumes a neutral reader that this sector does not have.

‍

Write for a Reader With a Stake

‍

Exchanges and clearing organizations register as self-regulatory bodies and most of them operate the market while regulating its participants, a conflict the supervising agency names in its own concept release and notes as increasing where those bodies became publicly traded. So governance evidence is read by an assessor, an operator and frequently a peer deployer at once. Outcome evidence and design evidence separate cleanly, an assessment needs the first, and most firms provide both because nobody distinguished them. The expectation of leniency is the wrong way round, since one exchange has paid a penalty for insufficient regulatory rigor and now has reason to demonstrate it. Kovrr's AI Security and Governance Platform produces the outcome evidence an assessment needs without exposing the design.

‍

To see outcome evidence produced from observed activity rather than from design documentation, book a demo mapped to your own estate.

Yakir Golan

CEO

Self-Regulatory Assessment FAQs

Speak to an Expert

What is a self-regulatory organization in securities markets?

What is the conflict of interest in the SRO model?

Does a commercially interested assessor go easier on an assessment?

What AI governance evidence should be disclosed to a market operator?

Can an SRO disciplinary action be appealed?

Which other sectors have a regulator that also operates the market?