UNUS London — Compliance Intelligence Division | blog.unuslondon.com | UNCLASSIFIED // REGULATED INDUSTRIES
Main Site All Articles UK Law Firms FCA-Regulated IT & Governance Academy Book Discovery Call UNUS Govern
UNUS Intelligence — Compliance Insight for Regulated Industries

Evidence over
assertion.
Infrastructure
over advice.

Technical guides, regulatory analysis, and build documentation for COLPs, MLROs, Practice Managers, and Compliance Officers. Written by the team that builds the systems.

27Articles Published
3Sectors Covered
9ISO 42001 Gaps Mapped
Search the Intelligence Library
§ SRA Code ISO 42001 £ FCA / SM&CR EU AI Act COLP SaaS / ITSM Evidence Risk Assessment
Showing 27 articles
Legal ComplianceMar 2026· 12 min

The Evidence Problem No Consultant Will Solve For You

Law firms don't fail SRA inspections because supervision didn't happen. They fail because they cannot prove it did. The SRA Supervision Register changes that - permanently.

SRA Code 7.1Jul 2026· 14 min

What the SRA Supervision Register Actually Is - And How to Build One

Most firms treat the SRA Supervision Register as a spreadsheet exercise. The register is in fact a live operational system - and the regulator is testing whether yours can answer questions in 30 seconds.

ISO 42001 Gap 1Jun 2026· 12 min

ISO 42001 Gap 1: AI Policy for UK Law Firms (SRA-Aligned)

ISO/IEC 42001:2023 Clause 5.2 requires every law firm deploying AI to establish a documented AI Policy.

ISO 42001 Gap 2Jun 2026· 12 min

The COLP Problem: ISO 42001 Clause 5.3 and AI Governance Roles in UK Law Firms

The SRA's December 2025 thematic review found only one COLP who could outline all their responsibilities. ISO 42001 Clause 5.3 requires assigned AI governance roles.

ISO 42001 Gap 3Jun 2026· 12 min

The Shadow AI Problem: ISO 42001 Clause 7.5 and the Law Firm AI System Register

Most law firms cannot list every AI tool in active use. ISO 42001 Clause 7.5 requires a version-controlled AI system register.

ISO 42001 Gap 4Jun 2026· 14 min

AI Risk Assessment for Law Firms: ISO 42001 Clause 6.1 Explained

ISO 42001 Clause 6.1 requires structured AI risk and impact assessment before deployment.

ISO 42001 Gap 5Jun 2026· 12 min

AI System Lifecycle Management for Law Firms: ISO 42001 Clause 8.2

ISO 42001 Clause 8.2 requires a documented lifecycle procedure for every AI system.

ISO 42001 Gap 6Jul 2026· 14 min

AI Data Governance for Law Firms: ISO 42001 Clause 8.3 and UK GDPR

When client data enters an AI system, two frameworks apply: ISO 42001 Clause 8.3 and UK GDPR.

ISO 42001 Gap 7Jul 2026· 12 min

AI Client Disclosure for Law Firms: ISO 42001 Annex A.2 and SRA Transparency Obligations

ISO 42001 Annex A.2 requires firms to disclose AI use to affected parties.

ISO 42001 Gap 8Jul 2026· 12 min

Human-in-the-Loop for Law Firms: ISO 42001 Clause 8.4 and AI Oversight

ISO 42001 Clause 8.4 requires human oversight of AI system outputs.

ISO 42001 Gap 9Jul 2026· 12 min

AI Supply Chain Governance for Law Firms: ISO 42001 Clause 8.5

ISO 42001 Clause 8.5 requires documented governance of every third-party AI component.

EU AI Act Art. 4Apr 2026· 10 min

The Training Record Your Law Firm Doesn't Have (And Why It's Already Costing You)

EU AI Act Article 4 has been in force since 2 February 2025. Every law firm using AI must hold per-person literacy training records.

EU AI Act Art. 50May 2026· 10 min

EU AI Act Article 50: The One Document That Closes the Compliance Gap

EU AI Act Article 50 applies from 2 December 2026. One compliance statement, linked to your existing HITL procedure, is all you need.

EU AI Act Annex IIIMay 2026· 12 min

The EU AI Act Classification Your Firm Has Never Done (And Why It Is the Most Important One)

EU AI Act Annex III classification determines whether Arts. 9-15 and Art. 26 apply to each AI system your firm uses.

EU AI Act Art. 27May 2026· 10 min

The FRIA Your Law Firm Does Not Need Right Now (And the Template for When That Changes)

EU AI Act Article 27 FRIA applies only to High-Risk AI. If your tools are Not High-Risk, you do not need a FRIA yet - but you need a record.

EU AI Act Art. 26(5)Jun 2026· 10 min

The AI Incident That Triggers a Regulatory Notification (And How to Know Which One)

EU AI Act Article 26(5) requires law firms to notify AI providers of serious incidents. Most AI failures are not serious incidents.

EU AI Act Arts. 25 & 53Jun 2026· 12 min

Every AI Tool Your Law Firm Uses Is Built on a GPAI Model. Here Is What That Means.

EU AI Act Articles 25 and 53 impose obligations on deployers of GPAI models. GPT-4o, M365 Copilot and LEAP AI all qualify.

FCA-Regulated Firms · SM&CR · ISO 42001
9 articles
ISO 42001 Gap F-G1May 2026· 10 min

Your FCA Firm Has No AI Policy. That Is Gap One.

ISO/IEC 42001 Gap F-G1 for FCA-regulated firms: no AI Policy under SM&CR. How to fix it in 14 days.

ISO 42001 Gap F-G2May 2026· 10 min

Your AI Policy Names You. Your Statement of Responsibilities Doesn't.

ISO/IEC 42001 Gap F-G2: no AI accountability in Statements of Responsibilities under SM&CR.

ISO 42001 Gap F-G3May 2026· 12 min

You Can't Govern an AI System You Don't Know Exists

ISO/IEC 42001 Gap F-G3: No AI System Register at FCA-regulated firms. Shadow AI is a governance and GDPR crisis.

ISO 42001 Gap F-G4May 2026· 12 min

Your AML AI Has Never Been Risk-Assessed. That Is Gap Four.

ISO/IEC 42001 Gap F-G4: No AI Risk Assessment for FCA-regulated firms. Model bias, hallucination, and drift.

ISO 42001 Gap F-G5Jun 2026· 12 min

When the AI Is Wrong, Who Is Harmed? That Is Gap Five.

ISO/IEC 42001 Gap F-G5: No AI Impact Assessment for FCA-regulated firms.

ISO 42001 Gap F-G6Jun 2026· 12 min

The Data You Send to AI Has Rules. Do You Know What They Are?

ISO/IEC 42001 Gap F-G6: No AI data governance for FCA-regulated firms.

ISO 42001 Gap F-G7Jun 2026· 10 min

The Report That Said Nothing

Gap 7 of 9: When AI writes client reports but no one tells the client. ISO 42001 Annex A.2 disclosure requirement.

ISO 42001 Gap F-G8Jun 2026· 10 min

Reading It Once Is Not a Review

Gap 8 of 9: When 'a human reviewed it' means nothing. Documented human oversight of AI outputs.

ISO 42001 Gap F-G9Jun 2026· 12 min

What They Never Thought to Ask For

Gap 9 of 9 - the series finale. AI supplier governance framework for FCA-regulated firms.

IT & Governance · Infrastructure
1 article
IT GovernanceMar 2026· 18-22 min

The SaaS Trap: Why Thousands of Organisations Are Paying a Fortune for IT Systems They Don't Own

SaaS ITSM platforms are structured to increase your switching costs, charge you for unused features, and make your historical data difficult to extract. UNUS London shows you the way out.

Regulatory insight.
Every week. No noise.

One email per week. A technical analysis, a regulatory update, or a build guide relevant to your industry. Written for compliance professionals who prefer evidence to opinion.

Trusted by COLPs, MLROs, Practice Managers and Compliance Officers across regulated UK industries