MCIT has expanded, bigger team, broader capabilities, same trusted service.Learn more about the merger

Regulated Financial Services

Build one compliance operating plane. Preserve firm independence.

MCIT helps broker-dealers, RIAs, hybrid firms, and independent practices standardize Microsoft 365 security operations, delegated access, and reviewable evidence across separate tenants—with Microsoft 365 Lighthouse at the core.

The Executive Question

How do you standardize control across independent firms without centralizing every tenant, decision, or workflow?

A compliance operating plane answers with a shared governance model, scoped technical delegation, and evidence-ready operations while preserving separate firm environments.

Distributed firms, shared accountability

Independent offices need local control. Enterprise leadership still needs a reliable way to see material posture, exceptions, and follow-through across the network.

2026 raises the operating bar

Cybersecurity, third-party oversight, customer-information safeguards, communications, and evidence production all depend on technology that can be governed and demonstrated.

AI expands faster than policy

AI use cases can touch supervision, communications, recordkeeping, privacy, and fair dealing. Firms need an approval and monitoring model before agents gain sensitive data or authority.

Reference Architecture

Centralized visibility. Delegated operations. Firm-owned environments.

Microsoft 365 Lighthouse anchors the multi-tenant control plane. MCIT surrounds it with responsibility mapping, service operations, evidence discipline, recordkeeping boundaries, and AI governance.

MCIT lighthouse operating planeA lighthouse projects a shared control beam while three independently owned firm environments remain connected through scoped operating paths.FIRM 01FIRM 02FIRM 03

MCIT

Global operating visibility
01

Enterprise / home office

Governance and oversight

Define the control baseline, supervisory boundary, exception process, reporting cadence, vendor requirements, and scale gates.

  • Policy and risk ownership
  • Portfolio posture and exception review
  • Incident and vendor governance
02

MCIT-operated layer

Microsoft 365 control plane

Use Microsoft 365 Lighthouse, scoped GDAP, security tooling, service management, and evidence workflows to turn standards into repeatable operations.

  • Multi-tenant posture and baselines
  • Identity, device, email, and threat signals
  • Remediation, change, and evidence workflow
03

Independent firm

Firm-owned tenant and decisions

Each firm keeps its tenant, users, data, business workflows, local ownership, and approved exceptions. Delegated access remains explicit, scoped, and revocable.

  • Separate tenant and data boundary
  • Local owners and approved workflows
  • Transparent access and change history

Lighthouse baselines, audit logs, and posture views support operations; they do not replace compliant communications archiving, regulatory record production, supervisory review systems, or legal advice.

Six Connected Capabilities

A control plane is only useful when signals become owned work and reviewable evidence.

MCIT connects the Microsoft layer to the operating disciplines a regulated firm needs to make decisions, manage exceptions, and prove follow-through.

01

Identity & delegated access

Map roles, MFA, privileged access, GDAP relationships, support groups, expiration, and offboarding to least-privilege operating tasks.

02

Baseline & configuration posture

Establish repeatable Microsoft 365 security baselines, deployment journeys, exception ownership, and reviewable drift follow-through.

03

Security signals & incident readiness

Coordinate device, user, email, vulnerability, service-health, escalation, containment, recovery, and evidence workflows.

04

Records & evidence boundary

Inventory regulated channels, connect the approved archive and retention architecture, test production, and keep Lighthouse logs in their proper supporting role.

05

Third-party governance

Operationalize vendor inventory, access reviews, contractual control evidence, incident exercises, contingency planning, and secure termination.

06

Governed AI adoption

Gate use cases through data classification, approval, testing, model and action traceability, human review, monitoring, and retirement.

Responsibility by Design

Oversight works when every decision and operating task has an owner.

This responsibility map is a starting point for the pilot charter. Final allocation must reflect the firm’s legal structure, supervisory system, agreements, policies, and actual services.

Regulated firm leadership

Owns accountability

  • Rule interpretation and legal advice
  • Supervisory procedures and risk decisions
  • Recordkeeping architecture and customer notices
  • Approval of access, exceptions, and AI use cases

Enterprise / home office

Owns the shared model

  • Control baseline and responsibility map
  • Cross-firm posture and exception governance
  • Vendor requirements and escalation paths
  • Pilot measures, wave gates, and executive reporting

MCIT

Operates the technology plane

  • Lighthouse, GDAP, identity, and baseline implementation
  • Monitoring, triage, remediation, and change records
  • Evidence packages and control-operation reporting
  • Technical testing, tabletop support, and improvement backlog

FINRA & SEC Alignment

Map obligations to operating evidence without confusing a tool with compliance.

The architecture supports technical control operation and evidence. Each firm must determine which rules apply and whether its full supervisory, privacy, communications, and recordkeeping program meets them.

FINRA Rule 3110 and 2026 GenAI themes

Supervision & governance

Support a reasonably designed supervisory system with named ownership, approved use cases, documented controls, testing, monitoring, and human review. Technology remains subject to the firm’s supervisory procedures.

Read the official source
SEA Rules 17a-3/17a-4 and FINRA recordkeeping

Books & records

Inventory business communications, define approved channels, connect compliant retention, and test production. Lighthouse is not a regulatory archive and does not replace WORM or audit-trail requirements.

Read the official source
Amended SEC Regulation S-P

Customer-information safeguards

Support written incident-readiness, access control, service-provider oversight, response evidence, and recovery operations. The covered institution retains notification and compliance responsibility.

Read the official source
FINRA 2026 third-party risk landscape

Third-party risk

Make vendor ownership, access, contracts, monitoring, incident coordination, continuity, and offboarding visible. MCIT is also a third party and should be governed through the same diligence.

Read the official source

AI-Ready by Control, Not by Hype

Give every AI use case a governed path from idea to retirement.

FINRA’s 2026 report emphasizes that existing obligations remain technology-neutral and highlights governance, testing, monitoring, data sensitivity, model and action traceability, and human oversight.

  1. 01

    Inventory

    Name the use case, owner, users, data, model, vendor, decision impact, and recordkeeping implications.

  2. 02

    Classify

    Apply data tiers, access boundaries, prohibited uses, required retention, and human-review thresholds.

  3. 03

    Test

    Evaluate privacy, integrity, reliability, accuracy, bias, failure modes, and escalation behavior before release.

  4. 04

    Operate

    Track model versions, prompts or actions where required, approvals, exceptions, and human intervention.

  5. 05

    Review

    Monitor performance and access, re-approve material change, and retire workflows that no longer meet the control case.

Review FINRA’s 2026 GenAI considerations

Pilot Before Portfolio

Start with representative firms. Scale only after the evidence holds.

A bounded two-to-five-firm pilot makes differences visible early, validates the operating model, and gives executive leadership a real scale decision rather than a platform demo.

  1. 01

    Charter

    Before access

    Agree on authority and evidence

    Name the executive sponsor, compliance and supervision owners, representative firms, data boundary, delegated roles, success measures, and stop conditions.

  2. 02

    Baseline

    Pilot setup

    Observe before standardizing

    Inventory tenants, licenses, identities, devices, security controls, communications, archives, vendors, exceptions, and existing procedures.

  3. 03

    Operate

    Controlled pilot

    Run the workflow end to end

    Deploy approved baselines, exercise access and remediation, build evidence packages, test incident escalation, and capture firm feedback.

  4. 04

    Scale gate

    Executive review

    Prove the model before the next wave

    Review coverage, unresolved exceptions, evidence quality, operating load, user impact, costs, and responsibility gaps before approving expansion.

Executive Measures

Measure control operation, evidence readiness, firm impact, and cost to serve.

Baseline coverage

Eligible tenants and required tasks in an approved state

Access hygiene

Delegated roles, MFA, expirations, reviews, and removals

Exception velocity

Age, owner, risk decision, remediation, and repeat drift

Evidence readiness

Time to produce a complete, reviewed control-operation package

AI governance

Inventoried, approved, tested, monitored, and retired use cases

Operating load

Remediation volume, escalation quality, firm impact, and cost to serve

Decision FAQ

Questions Regulated Leaders Ask Before a Pilot

Clear boundaries make the pilot safer, faster, and easier to evaluate.

What is a global compliance operating plane?

It is a shared technology-governance and evidence model that connects an enterprise control baseline to separately owned firm environments. It gives leadership consistent visibility and operating discipline while preserving each firm’s tenant, data, local decisions, and approved exceptions.

Does Microsoft 365 Lighthouse make a broker-dealer FINRA or SEC compliant?

No. Lighthouse can support standardized configuration, multi-tenant visibility, scoped delegated administration, and operational evidence. Compliance depends on the firm’s facts, supervisory system, policies, recordkeeping architecture, implementation, testing, and legal and compliance advice.

Can independent firms keep control of their own Microsoft 365 tenants?

Yes. The intended model keeps each customer tenant separate. MCIT operates through explicitly approved and scoped delegated relationships, subject to Microsoft eligibility and licensing requirements. The customer controls the relationship and can remove delegated access.

Does Lighthouse replace our electronic communications archive?

No. Lighthouse audit and operational data can support evidence, but it is not a FINRA Rule 4511 or SEC Rule 17a-4 archive. Regulated records need a separately designed retention, immutability or audit-trail, accessibility, and production architecture.

How does the operating plane prepare us for AI?

It creates the prerequisites AI governance depends on: identity, data classification, approved tools, responsibility, testing, logging and traceability, monitoring, human review, exception handling, and a controlled path to retire or expand a use case.

What is the safest way to begin?

Start with a bounded pilot across two to five representative firms after agreeing on scope, responsibility, access, evidence, success measures, and stop conditions. Use a formal scale-gate review before adding the next wave.

Primary Sources

Read the authorities behind the architecture.

These official sources informed the public operating model. They are not an exhaustive statement of any firm’s obligations.

Executive Readiness Workshop

Define the Operating Model Before You Buy More Tools

Bring your technology, cybersecurity, compliance, supervision, records, and AI stakeholders together. MCIT will help map the boundary, pilot candidates, required evidence, measures, and scale gates.