The ISO 42001 and SRA Standards Integration Guide for Law Firms
The challenge for COLPs is not a shortage of AI guidance — it is the absence of a method for treating SRA obligations and ISO 42001 requirements as a single governance exercise rather than two parallel compliance programmes. This guide provides that method.
Eight intersection chapters. Each gap mapped between both frameworks. A consolidated evidence table per chapter showing where one document satisfies both simultaneously. An 11-step implementation sequence. A 27-activity A2 Unified Compliance Calendar. The complete dual-framework programme, in one place.
One-time purchase · No subscription · Instant download · 28pp integration guide + A2 compliance calendar
SRA-ready governance and ISO 42001 audit readiness are not two separate programmes. They require the same underlying activities — documenting accountability, assessing risk, reviewing vendors, evidencing oversight. The question is whether you do those activities once and satisfy both, or twice and satisfy neither properly.
Every chapter in this guide ends with a Consolidated Evidence Table — a single-row-per-artefact view of what to produce, what frequency it requires, who owns it, and which obligation in each framework it satisfies. The consolidation principle means that by the end of the 11-step implementation sequence, a COLP has one coherent evidence set that answers both an SRA regulatory review and an ISO 42001 assessment.
Evidence that professional obligations are met
Accountability records, supervision logs, disclosure policies, vendor contracts — in the language of the Standards and Regulations
One Document
Both Satisfied
Systematic, documented, auditable governance
Management system artefacts, risk registers, lifecycle records, supplier assessments — in the language of the international standard
Each chapter maps one ISO 42001 gap against the SRA obligations it intersects — identifying where the frameworks converge, where one is more demanding, and what a single artefact looks like that closes both simultaneously.
Who is accountable for AI governance at your firm — and is that accountability documented or merely assumed? The chapter maps Clause 5.3 role assignment against Code 2.1 governance arrangements, identifies the most common failure mode (accountability assumed, not assigned), and defines the minimum viable AI Governance Structure document.
High SeverityThe AI register is the foundational transparency tool. A firm that cannot list its AI systems at a regulatory review cannot demonstrate it has assessed their risks, supervised their use, or ensured client data is handled appropriately. The chapter defines the minimum field structure for a law firm AI register and explains why the register makes all other controls provable.
High SeverityAI risk in legal practice is concrete: hallucinated case citations, confidential documents transmitted to an unsecured vendor, AI-drafted letters creating unintended contractual obligations. The chapter provides a risk category table mapping each risk type to its SRA obligation, its ISO 42001 dimension, and the control that closes it. Includes the EU AI Act risk classification alignment.
Critical SeverityAI governance does not end at adoption. The risk profile of an AI system changes as it is updated, as new practice areas adopt it, and as vendor relationships evolve. The chapter maps five lifecycle stages (Selection, Adoption, Operation, Change, Decommission) against their ISO and SRA obligations, with the per-system lifecycle record structure that closes the gap.
Medium SeverityThe solicitor who pastes a client's privileged instructions into a general-purpose AI tool has made a confidentiality decision — whether or not they recognised it. The chapter maps five data governance controls against their SRA and ISO obligations, addresses the high-risk scenario of consumer AI tools and client privilege, and defines the three-artefact evidence set that closes Gap 6.
Critical SeverityThe gap where SRA professional conduct obligations and ISO 42001 transparency requirements are most tightly aligned — and where failure is most directly felt by clients. Extended chapter covering: the materiality threshold framework (three tests), a five-decision disclosure protocol, EU AI Act Article 50 obligations, and the engagement letter priority action that provides baseline SRA compliance for most firms immediately.
Critical · Extended TreatmentBoth frameworks require that a human professional remains accountable for AI-influenced work. The question is not whether oversight is required — it is what oversight looks like in practice and how it is evidenced. Extended chapter covering the four-level oversight model (Administrative AI through Client-Facing Output), the supervision obligation for trainee AI use, and the quarterly COLP spot-check that validates operational compliance.
Critical · Extended TreatmentVendor due diligence is the gap most consistently underdeveloped across firms of every size. The chapter maps seven due diligence areas against their SRA obligation, ISO 42001 Clause 6.6 requirement, and the specific document to request from the vendor. Includes the proportionate approach note and the practical guidance on developing firm-standard AI vendor contractual clauses.
High SeveritySingle-page reference for all nine ISO 42001 gaps mapped against primary SRA obligation, severity rating, and consolidated evidence artefact — the at-a-glance regulatory picture for the full programme.
The master evidence set in full — 11 documents, their frequency, owner, and which SRA and ISO 42001 obligations each satisfies. Plus the 11-step implementation sequence from Week 1 to Month 6 sign-off.
The quarterly structure summary — Q1 through Q4 activities mapped across both frameworks, with combined outputs. The full A2 Unified Compliance Calendar is included as a separate file in the download.
Chapters 6 and 7 receive extended treatment because disclosure practice across the legal sector is currently inconsistent and the regulatory risk is real — and because human oversight is the gap where the SRA's supervision obligations and ISO 42001 most directly mirror each other.
The SRA Principles and Code do not contain an explicit AI disclosure rule — but they contain a framework of honesty, client communication, and informed consent obligations that collectively require disclosure in materially AI-influenced matters. The chapter provides a working definition of the materiality threshold (three tests), a five-decision-point disclosure protocol with matter-file evidence requirements, the EU AI Act Article 50 transparency obligation for EU clients, and a single engagement letter update that provides baseline compliance for most firms immediately.
SRA: Principle 4 (Honesty) · Principle 2 (Integrity) · Code 7.1 (Client Communication)
ISO 42001: Clause 8.2 (Transparency) · Clause 8.7 (Explainability)
A solicitor who signs off AI-drafted content without reading and understanding it has not supervised that work. The SRA's 2024 AI guidance makes this explicit: review of AI output must be substantive, not cursory. The chapter sets out the four-level oversight model — from Level 1 Administrative AI through to Level 4 Client-Facing Output — with the review requirement and evidence artefact for each level. Includes specific treatment of the trainee AI use scenario and the quarterly COLP spot-check as the validation control.
SRA: Code 3.1 (Supervision) · Code 1.4 (Competence) · Principle 4 (Integrity)
ISO 42001: Clause 8.1 (Operational Planning) · Clause 8 (Operations)
The consolidated evidence set a law firm needs to demonstrate dual-framework readiness — one document per governance activity, designed to satisfy both SRA and ISO 42001 requirements simultaneously.
The 11-step sequence in Appendix B builds the master evidence set in the correct dependency order — each document uses the previous one as input. Month 6 produces the first full evidence set with COLP sign-off across all eleven documents.
Inventory all AI tools currently in use. The register is the input to every subsequent step — nothing else can be completed without it.
Complete vendor DPA review for all high-risk systems in the register before the risk register is drafted.
Draft the risk register using the AI register and DPA review as inputs. Each system in the inventory shall have at least one risk entry.
Draft the policy and governance structure document. COLP sign-off. Managing Partner or Board approval for the policy.
Draft and review against current engagement letter wording. Priority action: update the standard engagement letter AI clause.
Map each AI system in the register to its oversight level using the four-level model. Identify the review requirement and evidence artefact for each.
Conduct staff AI training programme. Update training records for all fee earners. Retain sign-off records per person.
Embed oversight record requirements into the practice management system. Each matter using AI generates a review record.
First quarterly review of the AI register and risk register. COLP sign-off. Calibrate the review frequency based on the number of systems in use.
Compile the Vendor DD Record for every AI vendor in the register. COLP sign-off on risk decision per vendor.
COLP sign-off across all eleven documents in the master evidence set. The firm is dual-framework ready: SRA regulatory review and ISO 42001 assessment.
CAL-AIMS-LG-001 — the A2 landscape Unified Compliance Calendar — is included as a separate file in the download. It shows every dual-framework governance activity across 12 months, with owner, ISO clause or SRA code reference, colour coding by framework, and active-month indicators. Print at A2 for the compliance office. Use digitally for planning.
Six documents that form the foundation of a defensible AI governance position — pairable with IG-AIMS-LG-001 Appendix B:
The Integration Guide is the senior-level instrument for implementing dual-framework AI governance. It is not a reading exercise — it is a governance programme with a named owner at every step.
28pp integration guide + A2 compliance calendar. Instant download. One-time purchase.
Processed by Stripe · Secure checkout · 60-day money-back guarantee · Instant download after purchase · Two files: 28pp PDF + A2 PDF
No. The Integration Guide is a standalone programme — it contains everything needed to implement dual-framework AI governance from scratch, including the nine-gap reference matrix (Appendix A) and the full master evidence set (Appendix B). However, buyers who have worked through the free guide and the Gap Severity Matrix will find the chapter structure familiar — the same gap numbering and SRA obligation mapping is used consistently across the series. The Vendor Due Diligence Pocket Guide (£47) covers Gap 9 in more operational depth than Chapter 8 of this guide, and is a useful companion for firms with a large or complex AI vendor portfolio.
The guide's 11-step sequence is designed to take a COLP or Practice Manager from zero to first full evidence set sign-off in six months — approximately two to four hours of governance work per week, without requiring specialist legal technology resource. The most time-intensive steps are the AI system inventory (Week 1–2) and the Vendor DPA reviews (Week 2–3 and Month 4–6). Firms with fewer AI systems or existing vendor DPAs in place will complete the programme faster. Firms with large or complex AI portfolios may need additional time for the vendor due diligence steps.
The download includes: (1) IG-AIMS-LG-001_v1.0.pdf — the 28-page Integration Guide at A4 print-ready format, covering the regulatory context, all eight intersection chapters, and three appendices; and (2) CAL-AIMS-LG-001_v1.0.pdf — the A2 landscape Unified Compliance Calendar showing all 27 dual-framework governance activities across 12 months with owner assignments, framework colour-coding, and the COLP Minimum Evidence Set checklist. Print the calendar at A2 for the compliance office or governance meeting room; use the guide as the authority reference for each activity.
No. The Integration Guide is a governance education resource that maps ISO 42001 requirements against SRA Standards and Regulations obligations. It does not constitute legal advice, regulatory advice, or a guarantee of SRA compliance. Law firms with specific questions about their regulatory obligations, AI-related SRA exposure, or individual COLP liability should take qualified legal and regulatory advice. The guide is designed to inform governance decision-making and structure the evidence-building exercise, not to substitute for professional legal or regulatory counsel.
Yes. The purchase licence permits internal firm use — sharing with the COLP, Managing Partner, Legal Technology Lead, Practice Manager, and other governance roles within the purchasing firm. The calendar may be printed and displayed in the compliance office. Neither document may be resold, redistributed to third parties, or used as a deliverable in consulting or legal advisory engagements. Multi-firm licences and consultant licences are available — contact support@unuslondon.com.
Eight chapters. Eleven documents. Twenty-seven calendar activities. One coherent evidence set your COLP can stand behind. £167.
One-time · Instant download · 28pp Integration Guide + A2 Calendar · 60-day guarantee