New York City and the Tri-State Area
AI and Technology Governance for New York Firms Under Two Regulators
Most financial firms answer to one regulator for technology. Many New York firms answer to two. Centience builds and operates the governance program that satisfies both, and keeps the evidence current between examinations.
What makes New York different
NYDFS Part 500 sits on top of everything else
If your firm holds a licence, registration or charter from the New York State Department of Financial Services — a bank, insurer, mortgage lender or servicer, money transmitter or virtual currency business — you are a Covered Entity under 23 NYCRR Part 500. That obligation runs alongside anything the SEC or FINRA already expects of you, and it is enforced separately.
Part 500 is also more prescriptive than most federal expectations. The amended rule phased in through 1 November 2025, when the final requirements took effect: multi-factor authentication for any individual accessing any information system unless a documented exception with compensating controls is approved, and written procedures for creating and maintaining an asset inventory.
The part that catches firms is the certification. Each year by 15 April, a Covered Entity files either a certification of material compliance or an acknowledgement of non-compliance with a remediation plan. It is signed by the highest-ranking executive and the CISO, and it must rest on documentation and data showing the controls actually operated — not on a policy binder assembled the week before.
That is a personal signature on an operational claim. It is a very different exercise from an annual review, and it is the reason New York firms need governance that runs continuously rather than governance that is assembled on demand.
Where dual regulation actually bites
The overlap is rarely a clean subset. SEC and FINRA recordkeeping asks what you retained and whether you can produce it. Part 500 asks whether a specific control was in place, who approved the exceptions, and whether your CISO will sign that it operated. A firm can satisfy one and fail the other.
AI makes the gap wider. An assistant introduced into a workflow creates records under Rule 17a-4 or Advisers Act Rule 204-2, and simultaneously becomes an information system that Part 500 expects to see in your asset inventory, behind MFA, and covered by your written program. Firms tend to solve one half and discover the other during certification season.
What we operate for New York firms
A single governance program that produces evidence for both regimes: technology asset inventory maintained rather than reconstructed, access and MFA enforcement monitored continuously with exceptions documented and owned, retention aligned to the applicable federal rule, and AI tools inventoried and governed as the information systems they are.
The output is a certification package your CISO can sign with a straight face — control-by-control evidence, dated, with the exceptions and compensating controls written down — plus the exam evidence your federal regulator asks for, drawn from the same underlying program instead of a second parallel effort.
Serving New York City and the Tri-State Area
Questions we get from New York firms
+Does NYDFS Part 500 apply to my firm if I am an SEC-registered investment adviser in New York?
Not by itself. Part 500 applies to entities operating under a licence, registration or charter from NYDFS. SEC registration alone does not make a firm a Covered Entity. Many New York firms do hold a NYDFS licence alongside their federal registration, and it is worth confirming which of your entities are in scope rather than assuming either way.
+When is the Part 500 certification due?
Annually by 15 April. The filing covers the prior calendar year and is signed by the highest-ranking executive and the CISO. A Covered Entity that cannot certify material compliance files an acknowledgement instead, together with a remediation plan.
+What changed on 1 November 2025?
The final phase of the amended rule took effect: multi-factor authentication extended to any individual accessing any information system, unless a documented exception approved by the CISO is in place with reasonably equivalent compensating controls, and written procedures for creating and maintaining an asset inventory.
+Do you work with firms outside New York City itself?
Yes. We serve Manhattan, Westchester, White Plains, Long Island and northern New Jersey. The regulatory picture is the same across the Tri-State area for firms holding New York licences.
Know where you stand before someone asks
The Governance Score is a free five-minute self-assessment across cybersecurity, data and records, supervision, infrastructure and AI governance. You get a 0–100 result and see which areas need attention. No call required.
