What the Examiner Actually Asks: Who Approved This, and What Check Ran Before It Executed?

Blog · Wealthos

What the Examiner Actually Asks: Who Approved This, and What Check Ran Before It Executed?

By Rohit Gupta8 min read

Short answer

The stack's compliance story is evidence and audit-readiness — reconstructing proof, after the fact, of actions that ran across seams. But a books-and-records, fee-sweep, or suitability exam asks who was entitled to act, what check ran before execution, and who approved it — and a point-in-time archive was never built to answer that.

A regulatory exam does not open with your compliance philosophy. It opens with a specific fee, on a specific account, in a specific quarter — and three questions: who was entitled to take that action, what check ran before it executed, and who approved it? Most of the wealth stack was built to answer a different question entirely: what did we know, and what did we report. The distance between those two questions is where exams get uncomfortable.

Start with what the wealth stack got right, because it is substantial. Consolidating positions across custodians and fund portals rescued this industry from spreadsheets and monthly statements; the aggregation layer is real, hard engineering, and it earned its place. Performance calculation, billing computation, and proposal generation professionalized advisory operations. Document AI that extracts capital calls and K-1s removes genuinely brutal manual work, and KYC screening feeds surface risk that human review would miss. The posture the leading platforms describe — AI grounded in clean, governed, permission-aware data, with humans in the loop — is a responsible posture. Their thesis that AI is only as good as its data is correct as far as it goes.

The compliance modules deserve the same honesty. Centralized books-and-records archives, communication capture, timestamped marketing approvals, surveillance alerts routed to a review queue — all of it beats the shared-drive-and-prayer model of exam response by a wide margin. If your compliance team is still assembling evidence by hand, that tooling is worth having. Nothing that follows argues otherwise.

But read the category's compliance language closely and notice what it actually promises: evidence, organized. Readiness, meaning the proof of what happened can be produced quickly. That is a claim about the record. It is not a claim about the action.

Sit through a fee-billing sweep and the shape of the questioning becomes clear fast. The examiner does not ask for a philosophy. They pick accounts and trace fees: this advisory fee, this household, this quarter. When the applied rate and the client agreement diverge, the follow-up is never where is the document? The document is the easy part. The follow-up is: who changed the fee schedule, what validated the change against the agreement in force before the sweep executed, and who approved the exception.

Suitability obligations run the same way. The proposal that generated the allocation is background. The live question is what stood between recommendation and trade: what checked this rebalance against this client's profile and restrictions before the release went to trading — and if a human overrode a flag, whose name is on the override. Books-and-records is broader still: the obligation covers the business as transacted, which means the chain of authority behind the transaction, not merely the artifacts describing it.

Three exam formats, one grammar:

  • Entitlement. Was this person permitted to take this action, on this account, at that moment — and can you show the permission as it existed then, not as reconstructed now?
  • The gate. What control executed before the action committed — as distinct from what surveillance flagged after it settled?
  • The approval. Where judgment was required, who exercised it, and is that judgment recorded on the action itself?

Every one of these is a question about execution. None of them is a question about information.

Here is the structural problem, and it holds regardless of any vendor's roadmap. In the prevailing architecture, the consequential action executes downstream of the platform that holds the evidence. The fee change is keyed into a billing engine. The rebalance releases through a trading system. The account opens in a custodian portal. The distribution request crosses a service team and gets keyed again. The portfolio-aggregation platforms and advisor-tech suites read the results back across those seams and archive what they see.

That geometry dictates the compliance story. A system that learns about actions by ingesting their results can prove — sometimes beautifully — what happened. It cannot have run the check before the action, because before happened somewhere else, in a system it reads from but does not govern. So compliance becomes reconstruction: assemble proof, after the fact, that actions which ran across ungoverned seams were proper. Point-in-time archiving, genuinely valuable for what it does, answers what did the book look like on this date and what did we report. It audits the data. The decision-to-action chain — the thing the examiner is tracing — ran outside the frame.

Be fair to the thesis: governed data is the prerequisite, and the platforms that built it did the industry a service. But governed in that architecture means governed data — quality, permissions, traceability of what is known and reported. Governed action is a different claim, and it is the claim their own positioning does not make. The ground sits unclaimed because the architecture cannot stand on it.

THE WEALTH STACK Aggregation · Reporting Proposals · Evidence archive Operations action seams read path re-keyed handoff surveilled after Custodian A Custodian B Trading / billing evidence assembled after the fact ES FABRIC — ONE RUNTIME Operations action Inline gate before commit KYC · suitability · entitlement HITL step named approver Connector — sole egress Custodian / trading / billing emits Immutable per-action audit who initiated · gate disposition · approver · what egressed

Entroid's WealthOS starts from the other end: the operations action — not the report about it — is the governed unit. On the Composable Process Fabric, a fee change, an account opening, a rebalance release, a distribution request each execute as a Deterministic Workflow in one runtime. That single architectural decision changes what the audit record is.

  • The check runs inline, before commit. The KYC, suitability, or entitlement gate is a step inside the workflow, ahead of the commit — it cannot be skipped, because the gate is the execution path, not a monitor beside it.
  • Human judgment is a first-class step. Where policy requires review, the workflow pauses; a named, entitled approver acts; the disposition — passed, blocked, approved-by-whom — is recorded on the action.
  • Connectors are the sole egress. Nothing reaches a custodian, trading, or billing system except through a governed Connector. The seams still exist — ES runs over your existing estate, not instead of it — but crossing a seam becomes a governed, permissioned step rather than a re-keyed handoff.
  • The audit is a byproduct of execution. Every action emits an immutable per-action record: who initiated it, what gate ran, its disposition, who approved, what the Connector transmitted. The record is not assembled for the exam; it is emitted by the execution the exam is asking about.

Walk the fee-schedule example again — illustratively, as a description of the design, not a claimed deployment. An operations user initiates a fee change. The workflow checks entitlement at that moment, validates the new schedule against the agreement version in force, pauses for a supervisor where policy requires it, and only then applies the change through the Connector. When an examiner later asks the three questions, the answers are not a research project. They are fields on the record, because the record is the execution trace. That is what answered by construction means: the exam's grammar and the system's grammar are the same grammar.

One boundary, stated plainly: ES governs the operations process. It is a process platform, not an investment advisor — it makes no recommendations, holds no view on portfolios, and nothing here is a claim about investment outcomes. The governed unit is the action and its authority chain, full stop.

Fee billing, supervision, and books-and-records have recurred on published examination priorities for years running — directionally, that is where the questioning concentrates. So put this distinction to work in your next platform evaluation. Do not ask to see the archive; every serious vendor has one, and the demonstrations are polished. Pick one consequential action — a fee change, a rebalance release, a distribution — and ask two questions. Where does the compliance check run relative to the commit? And where does the approver's name land — on the action itself, or in a workflow tool beside it?

If the answer involves a downstream system, an overnight feed, and a surveillance report, you are looking at evidence tooling. It is worth having; it beats manual assembly decisively. But know what it is: proof, reconstructed, of actions that ran ungoverned. The alternative is an architecture where producing the proof and executing the action are the same event — where the examiner's three questions are answered before they are asked, because answering them is how the action ran in the first place.

The archive can prove what happened. Only the execution path can prove what was checked — and who said yes — before it happened.

See what this looks like for your enterprise.

Not a demo. A strategic conversation about how your enterprise could operate
when every process runs on one governed fabric.

Start the Conversation