Technical guides, regulatory analysis, and build documentation for COLPs, MLROs, Practice Managers, and Compliance Officers. Written by the team that builds the systems.
Law firms don't fail SRA inspections because supervision didn't happen. They fail because they cannot prove it did. The SRA Supervision Register changes that - permanently.
Most firms treat the SRA Supervision Register as a spreadsheet exercise. The register is in fact a live operational system - and the regulator is testing whether yours can answer questions in 30 seconds.
ISO/IEC 42001:2023 Clause 5.2 requires every law firm deploying AI to establish a documented AI Policy.
The SRA's December 2025 thematic review found only one COLP who could outline all their responsibilities. ISO 42001 Clause 5.3 requires assigned AI governance roles.
Most law firms cannot list every AI tool in active use. ISO 42001 Clause 7.5 requires a version-controlled AI system register.
ISO 42001 Clause 6.1 requires structured AI risk and impact assessment before deployment.
ISO 42001 Clause 8.2 requires a documented lifecycle procedure for every AI system.
When client data enters an AI system, two frameworks apply: ISO 42001 Clause 8.3 and UK GDPR.
ISO 42001 Annex A.2 requires firms to disclose AI use to affected parties.
ISO 42001 Clause 8.4 requires human oversight of AI system outputs.
ISO 42001 Clause 8.5 requires documented governance of every third-party AI component.
EU AI Act Article 4 has been in force since 2 February 2025. Every law firm using AI must hold per-person literacy training records.
EU AI Act Article 50 applies from 2 December 2026. One compliance statement, linked to your existing HITL procedure, is all you need.
EU AI Act Annex III classification determines whether Arts. 9-15 and Art. 26 apply to each AI system your firm uses.
EU AI Act Article 27 FRIA applies only to High-Risk AI. If your tools are Not High-Risk, you do not need a FRIA yet - but you need a record.
EU AI Act Article 26(5) requires law firms to notify AI providers of serious incidents. Most AI failures are not serious incidents.
EU AI Act Articles 25 and 53 impose obligations on deployers of GPAI models. GPT-4o, M365 Copilot and LEAP AI all qualify.
ISO/IEC 42001 Gap F-G1 for FCA-regulated firms: no AI Policy under SM&CR. How to fix it in 14 days.
ISO/IEC 42001 Gap F-G2: no AI accountability in Statements of Responsibilities under SM&CR.
ISO/IEC 42001 Gap F-G3: No AI System Register at FCA-regulated firms. Shadow AI is a governance and GDPR crisis.
ISO/IEC 42001 Gap F-G4: No AI Risk Assessment for FCA-regulated firms. Model bias, hallucination, and drift.
ISO/IEC 42001 Gap F-G5: No AI Impact Assessment for FCA-regulated firms.
ISO/IEC 42001 Gap F-G6: No AI data governance for FCA-regulated firms.
Gap 7 of 9: When AI writes client reports but no one tells the client. ISO 42001 Annex A.2 disclosure requirement.
Gap 8 of 9: When 'a human reviewed it' means nothing. Documented human oversight of AI outputs.
Gap 9 of 9 - the series finale. AI supplier governance framework for FCA-regulated firms.