Public · ART-AIMS-G001 v1.0 · ISO/IEC 42001:2023 Cl. 5.2 · Gap Article 1 of 9 · unuslondon.com · 3 July 2026
Critical Gap 1 of 9 · ISO/IEC 42001:2023 · Cl. 5.2 / Annex A.2

ISO 42001 Gap 1:
AI Policy & Management Direction

UNUS London — Lead Compliance & Standards Architect
3 July 2026 · ART-AIMS-G001 v1.0
~1,400 words · 7 min read

Priya Anand opens Pemberton Capital's AI Governance Due Diligence Questionnaire. Question one: "Does the firm have a documented AI policy?" She cannot answer yes. This is the most foundational gap in ISO/IEC 42001:2023 — and the one that makes every other control ungoverned until it is closed.

What does ISO 42001 Clause 5.2 require a UK law firm to do?

ISO/IEC 42001:2023 Clause 5.2 requires that top management shall establish an AI policy. The policy shall be appropriate to the organisation's purpose, shall include a commitment to satisfy applicable requirements, and shall include a commitment to continual improvement of the AIMS. The policy shall be available as documented information, shall be communicated within the organisation, and shall be made available to interested parties as appropriate.

For an SRA-regulated law firm, this means the Managing Partner or senior leadership team — not the IT department, not the COLP acting alone — shall formally approve and communicate a written AI policy covering: acceptable AI use cases, prohibited uses, human oversight requirements, AI disclosure obligations, and the review cycle. Without this document, no other ISO 42001 control has a governance mandate to exist.

The morning Priya Anand could not answer question one

The Pemberton Capital AI Governance Due Diligence Questionnaire arrives by email on a Tuesday afternoon. Five questions. Thirty days to respond. Pemberton generates £620,000 per year in fees for Halstead & Cole LLP (fictional, SRA number 12345678) — it is the firm's largest single panel relationship.

Question 1: "Does the firm have a documented AI policy governing the use of AI systems in the delivery of legal services to Pemberton Capital?"

Priya Anand, Partner and COLP at Halstead & Cole, reads the question and opens the firm's document management system. She searches for "AI policy." No results. She searches for "artificial intelligence" and "AI governance." A single document appears: a two-paragraph note from the IT Director dated March 2025 suggesting that fee earners "exercise caution" when using AI tools. It has no signatory, no version number, no review date, and no definition of what "caution" means.

She cannot answer yes to question one. Which means she cannot answer yes to any of the five questions that follow it — because without a policy, there is no governance mandate for any of the controls that the subsequent questions ask about.

This scenario is fictional. The governance gap it describes is not. ISO/IEC 42001:2023 Clause 5.2 is the first control obligation that creates firm-wide AI governance, and it is the gap that makes every subsequent control ungoverned.

Clause 5.2: the prescriptive requirements

The following requirements shall apply. Per ISO/IEC Directives Part 2: shall denotes a requirement; should denotes a recommendation; may denotes a permission.

Obligation typeISO/IEC 42001:2023 Clause 5.2 requirement
SHALLTop management shall establish an AI policy.
SHALLThe AI policy shall be appropriate to the purpose of the organisation.
SHALLThe AI policy shall include a commitment to satisfy applicable requirements related to AI systems.
SHALLThe AI policy shall include a commitment to continual improvement of the AIMS.
SHALLThe AI policy shall be available as documented information.
SHALLThe AI policy shall be communicated within the organisation.
SHALLThe AI policy shall be made available to interested parties as appropriate.
SHOULDThe AI policy should address the organisation's approach to responsible AI use, including ethical principles relevant to the organisation's context.
SHOULDThe AI policy should define acceptable and prohibited AI use cases in terms the organisation's staff can apply in practice.
MAYThe AI policy may be integrated with the organisation's existing information security policy where appropriate, provided the AI-specific content is separately identifiable.
CAUTION

The obligation in Clause 5.2 is placed on top management — not on the COLP, IT Director, or Compliance team acting independently. An AI policy signed only by a compliance officer does not satisfy the standard. The signature authority shall be the Managing Partner or equivalent senior leadership body. This is not a bureaucratic formality — it establishes the governance mandate that authorises and requires every other AIMS control.

Annex A control A.2 supplements Clause 5.2 by requiring that the organisation shall ensure that information about AI system objectives, behaviour, and limitations shall be made available to relevant internal and external stakeholders. In a law firm context, this extends the policy obligation to client-facing transparency — which is addressed separately in Gap 7 (DOC-AIMS-DISC-001), but the policy itself shall acknowledge this obligation.

What the SRA requires — and how it maps to Clause 5.2

The SRA does not yet mandate ISO 42001 certification. But its existing Code obligations, interpreted in the context of its 9 February 2026 AI guidance, create a near-identical AI policy requirement through a different mechanism.

SRA regulatory instrument

SRA Compliance Tips for Solicitors Regarding the Use of AI and Technology, last updated 9 February 2026: firms shall ensure solicitors understand AI tools they use; it shall always be made clear to clients where they are interfacing with AI; solicitors remain responsible for work produced with AI assistance.

Source: Solicitors Regulation Authority, February 2026
SRA Code — competence

SRA Code of Conduct for Solicitors 2019, Rules 3.2 and 3.3: a solicitor shall maintain the level of competence and legal knowledge needed to practise effectively. The SRA has confirmed that this obligation extends to AI tools used in practice — a solicitor using an AI tool for legal research shall understand the tool's limitations, including its propensity for hallucination.

Source: SRA Code of Conduct for Solicitors 2019 (effective October 2019)
SRA Code — COLP duty

SRA Code of Conduct for Firms 2019, Rule 8.1(a): the COLP shall take all reasonable steps to ensure the firm, its managers, employees, and interest holders comply with their obligations under the SRA's regulatory arrangements. In the absence of a documented AI policy, the COLP cannot demonstrate they have taken reasonable steps to govern AI use — a critical gap in COLP accountability evidenced by the SRA's own thematic review (December 2025), which found that only one COLP audited could outline all their responsibilities.

Source: SRA Code of Conduct for Firms 2019 (effective October 2019); SRA Compliance Officers: A Thematic Review, December 2025

The mapping is direct: ISO 42001 Clause 5.2 and SRA Rules 3.2/3.3/8.1 both require the firm to establish a documented governance position on AI use, signed at leadership level, communicated to all who need it. The ISO 42001 AI Policy is the single document that simultaneously satisfies both obligations.

GAP-01 assessed: Critical severity, Internal issue

This is GAP-01 in the Halstead & Cole audit register (REG-AIMS-GAP-001), rated Critical. It is classified as an INT (internal) issue — meaning the primary driver is an organisational governance deficiency that the firm has created through inaction, rather than an external regulatory change imposed from outside.

WARNING

A Critical severity gap indicates that ISO/IEC 42001:2023 certification cannot proceed without closure, and that immediate regulatory exposure is possible under existing SRA Code obligations. At Halstead & Cole, GAP-01 means that every AI system currently in use — GPT-4o, Microsoft Copilot, LEAP AI — operates with no governance mandate whatsoever. There is no documented position on acceptable use, prohibited use, human review requirements, or liability allocation. If Sophie Chen's AI-assisted research note contains a fabricated citation (the Ayinde [2025] EWHC 1383 scenario), the firm has no documented framework within which that failure was foreseeable, forewarned, or governed.

The specific consequences for Halstead & Cole of the absent AI policy:

ITIL NOTE

In ITIL 4 terms, GAP-01 is a P1 incident in the firm's governance service. The AI Policy is the foundational policy document that functions as the ITIL "Policy Management" practice anchor for all AI-related service assets. Without it, no downstream AI governance controls have an authorised policy mandate — exactly as ITIL requires all service management practices to operate within an approved policy framework.

POL-AIMS-001: the AI Policy that closes GAP-01

The controlled document that closes this gap is POL-AIMS-001 — AI Policy. The document-control block below shows the mandatory metadata fields. All UNUS London controlled documents shall carry this block as the first structured element, before any content.

CONTROLLED DOCUMENT — POL-AIMS-001 v1.0 ● ACTIVE
Document IDPOL-AIMS-001
Version1.0
TitleAI Policy — Artificial Intelligence Management System Policy
StatusACTIVE
Standard refsISO/IEC 42001:2023 Cl. 5.2; Annex A.2; ISO/IEC Directives Part 2; ISO 9001:2015 Cl. 5.2; SRA Code of Conduct for Firms 2019 Rule 8.1
OwnerManaging Partner / Senior Leadership (signatory); COLP (maintenance and review)
ClassificationInternal — Controlled. Available to interested parties on request.
Date of issue[Date of Managing Partner signature]
Next reviewAnnual minimum; immediate review triggered by: material regulatory change, significant new AI system deployment, AI incident classified as High or Critical
Retention7 years from date of supersession (UK Companies Act 2006)
Related docsRACI-AIMS-001 (roles); REG-AIMS-SYS-001 (AI system register); DOC-AIMS-DISC-001 (client transparency disclosure); REG-AIMS-RISK-001 (risk register)

What POL-AIMS-001 shall contain — the six mandatory sections

The policy shall contain the following six sections. Each maps to one or more Clause 5.2 requirements and SRA Code obligations. The prescriptive language per section is specified below.

Section 1

Commitment to responsible AI use

[Firm name] shall use AI systems in the delivery of legal services only in a manner that is responsible, transparent, and auditable. The firm shall maintain appropriate human oversight of all AI-generated work product used in legal services. The firm is committed to the continual improvement of its AI governance framework.

Section 2

Acceptable AI use cases

AI systems may be used for the following purposes, subject to the human oversight requirements in Section 4 and the disclosure requirements in Section 5:

  • Legal research assistance — where outputs are verified by a qualified solicitor before use
  • Document drafting assistance — where all AI-generated content is reviewed and edited by the responsible fee earner
  • Document summarisation for internal review purposes
  • Administrative tasks including billing narrative drafting, scheduling, and internal correspondence
  • Client communication drafting — where outputs are reviewed by the responsible fee earner before sending
Section 3

Prohibited AI uses

The following AI uses are prohibited under this policy:

  • Submitting AI-generated legal research to a court, tribunal, or regulatory body without independent verification by a qualified solicitor
  • Using AI systems to conduct client due diligence, AML risk assessment, or GDPR compliance activities as a substitute for qualified human assessment
  • Uploading client documents or client personal data to AI systems not listed in the firm's AI System Register (REG-AIMS-SYS-001) and approved under the firm's data governance controls
  • Using AI systems to provide autonomous legal advice to clients without qualified solicitor review and sign-off
  • Using personal or consumer-grade AI accounts (e.g., free-tier ChatGPT) for any matter-related work
Section 4

Human oversight — non-negotiable requirement

Human oversight of AI outputs is a non-negotiable requirement of this policy. No AI-generated output shall be submitted to a client, filed with a court or tribunal, or used as the sole basis for a legal decision without review and sign-off by the responsible qualified solicitor. The sign-off shall be documented in the firm's matter management system. The firm's Human Oversight Procedure (PROC-AIMS-HITL-001) defines minimum review requirements by output type and risk level.

Section 5

AI disclosure to clients

The firm shall make clear to clients where AI systems are involved in the delivery of legal services, in accordance with the SRA's AI guidance (February 2026) and the firm's AI Transparency Disclosure Statement (DOC-AIMS-DISC-001). The disclosure shall be provided at matter opening and whenever a materially new AI system is introduced to the delivery of the client's work.

Section 6

Review cycle and ownership

This policy shall be reviewed annually as a minimum by the COLP, with the outcome of the review presented to senior leadership for approval. An immediate review shall be triggered by: a material change to applicable regulatory requirements; the deployment of a significant new AI system; or any AI-related incident classified as High or Critical. The COLP shall maintain the policy as a controlled document in the firm's document management system.

CAUTION

The policy template in Section 5 above represents the minimum content required to satisfy Clause 5.2. Firms shall adapt the acceptable use list (Section 2) and prohibited use list (Section 3) to reflect their actual AI deployment — a firm using only Microsoft Copilot will have different acceptable use cases than one using a bespoke API-connected LLM. The template is a starting point, not a finalised document. Review by a qualified solicitor or compliance professional is required before adoption.

Once POL-AIMS-001 is approved and communicated, Halstead & Cole shall satisfy the requirements of ISO/IEC 42001:2023 Clause 5.2 in full, and shall be able to answer Pemberton Capital's questionnaire question 1 affirmatively. It does not, by itself, close Gaps 2–9 — but it is the governance mandate that authorises every subsequent control to exist.

Download POL-AIMS-001 — the free, ungated AI Policy template

📋

AI Policy Template for UK Law Firms (SRA-aligned)

The full POL-AIMS-001 template includes: a complete document-control block; all six mandatory policy sections as drafted above; an SRA-aligned acceptable use schedule; a prohibited use schedule; a review log; and a sign-off page ready for Managing Partner approval. Available as a Word document (.docx) with document-control fields pre-populated.

Download POL-AIMS-001 (.docx) →
Document ID: POL-AIMS-001 Format: .docx No email required Matched video: Video 3 — "Building a Law Firm AI Policy from Scratch"

Watch the screen-recorded walkthrough of this template on the UNUS London YouTube channel — playlist: ISO 42001 for UK Law Firms, Video 3.

NOTICE

Limitations disclaimer. This template is published for educational purposes only and does not constitute legal advice or compliance advice. It is a starting point requiring adaptation and review by a qualified solicitor or compliance professional before adoption. Regulatory requirements, SRA guidance, and ISO standards are subject to change; the template shall be reviewed at each annual policy review cycle or on material regulatory change.

Gap 1 closes the policy gap. Eight gaps remain.

POL-AIMS-001 is the foundation. The AIMS policy establishes the governance mandate — but Halstead & Cole still cannot answer questions 2 through 5 of Pemberton's questionnaire. The remaining eight gaps each require their own controlled document and control implementation. The recommended next steps:

Quality gate record — ART-AIMS-G001 v1.0

The following gates were checked before publication. All 10 gates pass. This record is maintained as evidence of the pre-publication compliance audit.

The UK Law Firm's Guide to ISO 42001
← All 9 gaps
Internal organisation, roles & the COLP problem
Governance Academy · UNUS London

Work through this with a peer group

The UNUS London Governance Academy runs live sessions where COLPs and compliance leads walk through each gap together — getting templates reviewed and questions answered in real time. No email gate. No upsell.

This article is published for educational purposes only and does not constitute legal advice or advice on compliance with ISO/IEC 42001:2023 or any other standard. Halstead & Cole LLP, Priya Anand, Pemberton Capital LLP, Sophie Chen, and all associated names are fictional constructs. Any resemblance to real persons or firms is coincidental. All templates and controlled document examples require adaptation and qualified review before use. · Document ref: ART-AIMS-G001 v1.0 · Published 3 July 2026 · Next review: 3 October 2026 · Retention: 7 years · UNUS London Ltd. · unuslondon.com/legal/iso-42001-gap-1-ai-policy