AI Risk Matrix for Private Funds

June 12, 2023

Reading Time : 1 min

Numerous journalists have showcased their use of “deep-voice” and other Artificial Intelligence technologies to spoof electronic confirmation systems. Although these attempts to bypass security, so far, have largely been confined to retail banking and credit cards, private fund managers should focus on this new arrow in the scammer’s quiver.

All private fund managers, including managers that use third-party administrators to manage subscriptions, redemptions and investor information processes (e.g., wiring instructions), should assess their susceptibility to AI-fueled scams, such as combining a redemption or transfer request from a hacked or spoofed email account with a “live” verification by an AI-enabled voice or video impersonation tool.

While it is early days, and given that there is no one-size-fits-all solution, we would suggest that all managers review and stress test their verification processes and consider whether additional safeguards are appropriate. Compliance personnel should also review existing (albeit pre-AI) regulatory guidance and industry best practices for indicative guidance (e.g., the SEC’s Regulation S-ID Risk Alert).

One interim suggestion that we have is to implement a “2x2” requirement, i.e., requiring:

  • A bidirectional communication record
  • That occurs across two pre-approved media (e.g., “known” email accounts or telephone numbers)

for any investor-related change or transaction to occur.

For example, a voice request over a phone call originating from a pre-approved number must be validated by an email exchange with a pre-approved email address, or vice versa. We have distilled this suggestion into a (very simplified) matrix:

Obviously, this effort will require collaboration among legal, compliance, operations and other firm personnel. Outside counsel can assist in identifying state, federal and foreign privacy, data transfer and similar laws, in addition to traditional regulatory compliance advice.

Share This Insight

Attachments

© 2024 Akin Gump Strauss Hauer & Feld LLP. All rights reserved. Attorney advertising. This document is distributed for informational use only; it does not constitute legal advice and should not be used as such. Prior results do not guarantee a similar outcome. Akin is the practicing name of Akin Gump LLP, a New York limited liability partnership authorized and regulated by the Solicitors Regulation Authority under number 267321. A list of the partners is available for inspection at Eighth Floor, Ten Bishops Square, London E1 6EG. For more information about Akin Gump LLP, Akin Gump Strauss Hauer & Feld LLP and other associated entities under which the Akin Gump network operates worldwide, please see our Legal Notices page.