Skip to content

AI Governance and Safeguards at Gen II

Portrait image of Raj Gidvani

Authored by:

Raj Gidvani, Chief Technology Officer

Published on: September 30, 2026

As artificial intelligence becomes increasingly embedded in financial services, Gen II recognizes the critical importance of communicating how we govern and protect the AI tools and processes that may access client data. The trust that our clients place in us — with their capital and their investor relationships — demands nothing less than the same rigorous oversight we apply to every other dimension of our operations.

At Gen II, AI is not a shortcut. We treat it as a managed business system — subject to formal governance, enterprise-grade security controls, and continuous human oversight. The following outlines the specific commitments and safeguards we have put in place to protect client data and maintain the standard of care expected from a leading fund administrator.

Governance and Executive Oversight

Our AI program is built around ISO 42001, the international standard for AI management systems — reflecting our commitment to world-class operational discipline. External certification is scheduled for September 2026, and our most recent internal audit completed with no major or minor findings.

An executive AI Committee — chaired by our Chief Transformation Officer, with representation from our Chief Technology Officer, Chief Information Security Officer, and Chief Legal Officer — reviews and approves every AI use case before it goes into production. No AI system touches client data without passing a formal impact assessment that documents how it works, what data it accesses, and what risks it presents. This is not simply a checklist exercise; it is the same disciplined governance that underlies everything we do.

Approved Tools and Strict Access Controls

Only AI tools that have been formally reviewed and approved are permitted at Gen II. Employee devices are centrally managed; unauthorized AI applications are blocked at the device and network level before they can reach our systems.

Access to approved AI tools requires multi-factor authentication on a compliant, monitored device. Privileged access is granted only when needed and only after explicit approval — there are no standing administrative rights. These controls reflect the same investment in people and process that has defined Gen II's operations since our founding: the right people, with the right access, doing the right work.

Secure Development and Integration

AI configurations are version-controlled and peer-reviewed before deployment. Every code change passes through automated security scanning — covering vulnerabilities, software supply chain risk, and runtime behavior — before reaching any production environment. External connectors are blocked by default and enabled only through a formal, ISMS-approved list.

Continuous Monitoring and Detection

Activity from every approved AI tool is streamed in real time to our security monitoring platform, where it is analyzed continuously for unusual behavior, data exfiltration attempts, and potential abuse. Our 24×7 Security Operations Center reviews alerts as they occur, correlating AI activity with identity and endpoint signals across the firm.

Configuration files and policy settings are monitored for unauthorized changes. We do not wait for problems to surface; we build systems designed to catch them before they become consequential.

Vendor and Supply Chain Oversight

Every AI vendor is assessed through our third-party risk management program before onboarding. Dedicated tooling actively discovers any unsanctioned AI use across the firm, and our web filtering blocks unapproved generative AI sites at the network edge. All employees attest to our Generative AI Acceptable Use Policy as part of onboarding and annual security training. Building a responsible AI culture requires investment in our people — in their awareness, their judgment, and their accountability. That investment is ongoing.

AI Use Case: Gen II's Verifii™ Platform

Accuracy at scale has always been central to how Gen II serves clients — and Verifii is the expression of that commitment in the AI era. Built from the ground up as part of our broader technology ecosystem, Verifii is our proprietary AI-driven quality control engine, purpose-built to automate the high-volume review tasks at the heart of fund administration: financial statement consistency checks, identification of missing schedules, and structural validation across complex fund documents. It has demonstrated 98% QC accuracy to date. Our roadmap runs from financial statement reviews today through automated PCAP and ILPA validation, footnote analysis, and ultimately near-real-time review of capital call notices and distributions in the future — every phase designed to compress cycle times and deliver greater confidence in the accuracy of what reaches clients and their limited partners.

Verifii is live today with select clients and regions, with a phased global rollout extending into early 2027.

Our Commitment to Client Data Protection

Protecting the data clients entrust to Gen II is a core obligation. Our controls reflect a deliberate choice: to invest in the people, processes, and technology required to maintain the highest standard of care.

We are committed to transparency as our AI capabilities evolve. Clients with questions about our AI security posture or the specific controls described herein are encouraged to reach out to their Gen II service team.

This article contains forward-looking statements regarding Gen II Fund Services LLC's strategic initiatives and technology development plans. Actual product availability, timelines, and capabilities may vary.

Insights

Explore other insights