The Morning the Inspector Arrived
It is 9:47 on a Tuesday morning. The SRA Inspector is already seated in your meeting room. She has a printed copy of your firm's risk profile, a notepad, and a question she is about to ask that will make the next four hours the longest of your professional career.
"Can you show me your supervision records for the last twelve months? I'd like to see the fee-earner, the matter, the date of review, the outcome, and who conducted it."
You say: "Of course. Give me a moment."
And then you go looking.
You check your emails. Then a shared folder on the server. Then a spreadsheet that Sarah from the compliance team was maintaining — until Sarah left in October. Then a Word document that the previous COLP had started in 2022 and hadn't been updated since. Then your inbox again, because surely there's something in there from the supervisors confirming they'd done their reviews.
Forty-five minutes later, you return to the meeting room with a collection of fragments. An email here. A file note there. A supervision log that covers three months out of twelve, for two fee-earners out of nine.
The inspector writes something in her notepad.
You know what that means.
The Problem Was Never Supervision. It Was Evidence.
Here is the part that nobody talks about openly at Law Society events or in the SRA's own guidance documents, even though it is the most important thing you need to understand about regulatory risk in your firm:
And in the eyes of the SRA, an undocumented supervision event is not a supervision event. The obligation under SRA Code of Conduct for Firms 2019 §7.1 is not simply to supervise. It is to ensure that supervision is genuine, timely, and — critically — evidenced. The word "evidence" carries the full weight of regulatory consequence.
This is the distinction that most compliance approaches get completely wrong. They focus on the activity of compliance and ignore the infrastructure of proof.
Firms shall ensure that the work of managers and employees is properly supervised. Evidence of supervision shall be producible on request. The absence of an evidence trail is treated, for inspection purposes, as the absence of supervision — regardless of what actually occurred.
This is why firms with good intentions and diligent partners receive the same inspection outcome as firms that never thought about supervision at all. The regulatory system does not reward effort. It rewards evidence.
What You Did Next — and Why It Didn't Work
After a difficult inspection, or after reading a file note from your SRA supervisor, or after attending a compliance seminar where someone mentioned that "supervision records" are a common gap, you did one of two things.
Either you hired a consultant.
Or you subscribed to a compliance SaaS platform.
Both are understandable decisions. Neither of them solved the problem.
The SaaS platforms are closer in spirit — at least they are operational. But they introduce a different set of problems. Your compliance data lives on someone else's infrastructure. Your audit trail is subject to another company's data retention policies. Your fee-earner records are in a third-party database that you cannot directly query, cannot customise, and cannot control. And every month, you pay a subscription fee for the privilege.
There is a question that very few compliance officers ask before signing the contract:
"Before I hand my firm's most sensitive regulatory evidence to an external vendor — does anything in our existing technology stack mean we could build this ourselves?"
The answer, for most SRA-regulated firms, is yes. And that realisation changes everything.
Look Inward Before You Look Outward
This is the mindset shift that this article asks you to make. It is not dramatic. It does not require you to become a technologist. It simply requires you to ask one question before your next purchase decision:
so that the evidence never leaves our control?"
Most UK law firms already have the foundational components. A database, or access to one. An email system. A practice management tool. The data about your fee-earners, your matters, and your supervisors already exists somewhere in your firm. It is fragmented, unstructured, and unqueryable — but it exists.
The compliance problem is not a data shortage. It is an architecture problem. You have the raw material. What you are missing is the structure that transforms that raw material into evidence.
Governance is not a product you buy. It is infrastructure you build. The distinction matters because infrastructure compounds — it gets more valuable over time, serves more purposes than it was originally designed for, and belongs entirely to you. A product subscription depreciates the moment you stop paying for it.
This principle is the foundation of everything UNUS London builds. Not SaaS. Not consultancy. Database-first compliance infrastructure — deployed on your own stack, owned by your firm, queryable by your team, and producing evidence that belongs entirely to you.
What the SRA Supervision Register Actually Is
The UNUS SRA Supervision Register is the first system in the legal compliance stack. It is not a form. It is not a policy template. It is not a guide to supervision best practice. It is a production-grade PostgreSQL database system that you deploy once and that runs continuously, recording every supervision event for every fee-earner in your firm from the moment it goes live.
When the SRA inspector asks for your supervision records, you do not go looking. You run a query. In under 30 seconds, you produce a complete, timestamped, immutable record of every supervision event — the fee-earner, the matter, the supervisor, the date, the outcome, the actions required, and whether those actions were completed.
What the System Contains
Six Regulatory Tables
Firm profile, fee-earner register, supervisor register, supervision assignment log, client matter register, and the supervision event table — the immutable core of your §7.1 evidence.
Immutable Event Log with Timestamps
Every supervision event is written with a PostgreSQL audit trigger. Records cannot be altered after creation. The timestamp is set by the database server — not the user submitting the form.
n8n Workflow: Overdue Alerts
A production-ready n8n workflow runs daily. Any fee-earner whose supervision review is overdue generates an automatic escalation notification to the COLP before the gap becomes a gap of record.
Regulatory Readiness Score
A live compliance health view calculates your firm's score across four dimensions: supervision coverage, review timeliness, mandatory notes completion, and acknowledgement rates. You know your position before the inspector does.
Pre-Built Compliance Views
Views designed specifically for SRA inspection: fee-earner supervision history, matter-level supervision coverage, overdue review register, and supervisor workload analysis — all queryable in seconds.
Row-Level Security Policies
Aligned with ISO/IEC 27001:2022 Annex A controls. Each role in the system — fee-earner, supervisor, COLP — accesses only the records appropriate to their function. Access is enforced at the database layer, not the application layer.
The Infrastructure Belongs to You
This is the part that matters most, and it is the part that is most different from every other compliance solution you have been offered.
The SRA Supervision Register is not a platform. There is no login portal managed by UNUS London. There is no monthly fee gating your access to your own compliance data. There are no data retention clauses in a vendor's terms and conditions that govern what happens to your audit trail.
You deploy this system into your own Supabase project — which is your own PostgreSQL database instance, running on infrastructure you control. Your firm's data never leaves your environment. Your audit trail is yours. Your evidence is yours.
The system is designed as a governed service asset. The schema is version-controlled. The automation is documented. The compliance views are named and referenced in the setup guide. Every component is traceable back to its regulatory obligation — §7.1, ISO 9001 Clause 8.1, ISO/IEC 27001 Annex A.12.4. You can show an auditor exactly why each element exists and what it evidences.
When an SRA inspection team arrives next year, you will not be calling your SaaS vendor's support line asking for an export of your data. You will not be explaining to the inspector that the consultant who built your supervision framework left the industry. You will open a dashboard on your own system, run a query against your own database, and produce evidence that your firm created, your firm owns, and your firm controls.
That is what compliance infrastructure means. And it is built once.
The System in Practice: A Different Tuesday Morning
It is 9:47 on a Tuesday morning. The SRA Inspector is seated in your meeting room. She asks to see your supervision records for the last twelve months.
You open your browser. You navigate to your firm's compliance dashboard. You run the fee-earner supervision history view. You run the regulatory readiness report. You print two pages.
You return to the meeting room at 9:51.
"Every supervision event," you say, "timestamped, with the matter reference, the supervisor, the outcome, and the next review date. The system also flags any overdue reviews automatically — we had none outstanding at the end of last month."
The inspector writes something in her notepad.
This time, you know what that means too.
That four-minute difference is not magic. It is architecture. It is the product of a decision you made — to treat compliance as infrastructure, not as a service you buy from someone else. To look inward at what you already had, and to build the one thing that was missing: structure.
This Is Not a Technology Project. It Is a Governance Decision.
If you are a COLP, an MLRO, or a Practice Manager reading this, you are not being asked to become a database administrator. The SRA Supervision Register is designed to be deployed by a compliance professional working with a basic understanding of database tools — or with minimal IT support. The setup guide maps every step. The workflow is pre-built. The schema is documented against every regulatory obligation it satisfies.
What you are being asked to do is make a governance decision before your next budget sign-off: to ask whether the solution to your evidence problem already exists within your firm's infrastructure, and whether the money you are about to spend on a consultant or a SaaS subscription could instead be invested in building something permanent.
It is "Can we afford another inspection without it?"
The SRA Supervision Register is Mini Solution 1 in the UNUS London legal compliance stack. It integrates directly with Mini Solution 2 — the Client Matter Checklist Engine — and Mini Solution 3, the SRA Regulatory Readiness Report Generator, which produces a weekly signed-off governance report for the principal solicitor. Together, the three systems give you a compliance infrastructure that most SRA-regulated firms in the UK do not have.
Watch the System in Action
The full demonstration of the SRA Supervision Register — schema walkthrough, n8n workflow, compliance views, and live regulatory readiness score — is now live on the UNUS London YouTube channel.
Watch the Demonstration Book a Discovery Call