How Serra governs AI: our approach to responsible, compliant AI in wealth management
Serra runs its own operations on a fleet of specialised, governed AI agents, and one rule sits above all of them: a human owns every decision. Agents draft, prepare, and execute inside guardrails, but a hard human gate stands in front of every irreversible action, moving money, sending or publishing anything external. We write this from doing it, not predicting it.
Most published thinking on "responsible AI" in wealth management is written by firms describing what they might do. Serra's is written from a live system we operate every day. This article sets out the doctrine behind that system, the five load-bearing principles, so you can judge whether a firm's AI is actually governed or merely described. It sits within our broader AI for Wealth resource, and it builds on our argument that the real AI gap in wealth is governance, not adoption.
How does Serra govern its AI agents?
Serra governs AI through five binding principles: a human owns every decision, a hard gate guards every irreversible action, the guardrail binds the outgoing action rather than filtering the input, identity is the root of every gate, and a dedicated compliance agent reviews every client-facing deliverable. Together they make governance a property of the system, not a policy on paper.
Each principle below is something the fleet enforces mechanically. None of them depends on an agent "choosing" to behave, which is the difference between governance and a good intention.
Who is accountable when an AI agent acts at Serra?
A named human is accountable for every decision, always. Serra's agents are scoped to a role, marketing, research, compliance, portfolio, finance, engineering, operations, and each one drafts, prepares, or executes within its guardrail. But the decision, and the accountability for it, never leaves a human. The agent is a capable instrument; it is not the principal.
This matters because "the AI did it" is not a defence a regulated firm can offer. At Serra, an action is always traceable to the person who owns it. The fleet extends what our people can do; it does not dilute who answers for it.
What is the hard human gate, and when does it apply?
The hard human gate is a mandatory human approval that applies only to irreversible actions: moving money, and any external send or publication. Everything else, drafting a report, preparing a reconciliation, running research, runs unattended inside its guardrail. We gate what cannot be taken back, and we let the reversible work flow.
The design point is proportionality. Gating everything would make the fleet useless; gating nothing would make it dangerous. So the gate falls precisely on the class of actions where a mistake cannot be undone, money out the door, or a statement into the world.
What does it mean that the guardrail binds the action, not the input?
It means the guardrail checks the outgoing action against approved scope, rather than merely filtering what goes in. A content step must match the approved content. A payment step must match an authorised instruction. The system is fail-closed by mechanism: if the outgoing action does not match what was approved, it does not happen.
This is the distinction most "AI safety" policies miss. Filtering inputs is easy to defeat and easy to drift from. Binding the outgoing action means the guardrail is evaluated at the moment of consequence, the send, the transfer, the publish, where it actually protects the client.
How does identity underpin Serra's AI governance?
Identity is the root of every gate. Each agent authenticates as itself, holds least-privilege access scoped to its role, and every action it takes is attributable and logged. The result is a full audit trail of every action, every check, and every refusal, so any step can be reconstructed and any actor can be named.
Least privilege is deliberate: an agent can reach only what its role requires and nothing more. Combined with attribution and logging, it means the fleet is not a black box. It is a system where "who did what, under what authority, and what did it decline to do" always has an answer.
How does compliance review work in Serra's AI system?
A dedicated compliance agent, in a Chief Compliance Officer role, reviews every client-facing and outbound deliverable to a MiFID-grade standard before it ships. For published content, a multi-station content committee gates the work: sourcing, structure, craft, and compliance each clear it in turn. Nothing reaches a client or the public without passing that review. This is also why we hold a firm line on where AI may touch client information, set out in what the FCA's rules on AI mean for UK wealth firms.
Building compliance into the pipeline, rather than bolting it on afterwards, is the point. Review is not a favour a busy human might get to; it is a station every deliverable must pass. That is how a firm keeps standards constant even as output scales.
A real example: the guardrail that held
We are building family-office operating layers, reporting, administration, coordination, for a client, with a live compliance guardrail in place. In one instance an agent was asked to write a credential where the approval had been relayed second-hand rather than given directly by the principal. The agent refused. The guardrail required the principal's direct authorisation, the relayed approval did not satisfy it, and the fail-closed mechanism held rather than proceeding on a convenient assumption.
That refusal is the doctrine working as designed. A governed agent that declines an under-authorised action is worth more than a compliant-sounding policy that never faces a real test. The client stays anonymous; the lesson does not.
FAQ
Does a human really approve every irreversible action at Serra?
Yes. Moving money and any external send or publication require a hard human gate, mandatory human approval, before they can proceed. Reversible work runs unattended inside its guardrail, but nothing that cannot be undone happens without a named human signing off.
Is Serra's AI making investment decisions?
No. Investment decisions belong to Serra's people. The agent fleet handles preparation, research, drafting, coordination, and back-office execution within guardrails. Note that Serra Education, which covers Serra's process and tooling, is distinct from Serra Wealth investment advice, and this article describes how Serra operates its systems, not investment guidance.
What happens if an AI agent is asked to do something outside its scope?
The guardrail is fail-closed: the outgoing action is checked against approved scope, and if it does not match, it does not execute. In a real case an agent refused to write a credential because approval had been relayed rather than given directly by the principal. The system declines rather than assumes.
How does Serra keep an audit trail of what its AI does?
Every agent authenticates as itself with least-privilege access, and every action, check, and refusal is attributable and logged. That produces a full audit trail, so any step can be reconstructed and any actor named. Identity is the root of the whole model.
Why should a client trust a firm that uses AI this heavily?
Because the governance is mechanical, not aspirational. A human owns every decision, irreversible actions are hard-gated, guardrails bind the outgoing action and fail closed, identity underpins every gate, and a compliance agent reviews every outbound deliverable. Serra writes this from operating the system, not from predicting one.
This article describes how Serra Wealth governs and operates its internal AI systems (Serra Education: process and tooling). It is not investment advice and does not constitute a recommendation. Serra Wealth uses AI tools in its operations under human oversight.