Two files are included in your purchase. Download both below. Print the PDF at A3 for compliance committee use. Use the high-res PNG for digital presentations, board packs, and intranet display.
Each link is valid for 1 hour. Bookmark this page to re-download any time within 30 days.
Print the matrix and use it as the standing reference document for your COLP compliance committee agenda item. Each quarter, mark which gaps are remediated (✓), in progress (~), or open (✗). Over time this produces a documented, dated compliance committee record showing systematic AI governance improvement — exactly the evidence the SRA looks for when investigating whether a firm has adequate compliance arrangements in place.
Use the matrix as the AI governance risk dashboard in your management board pack. The severity column (Critical / High / Medium) gives leadership the prioritised risk picture without requiring them to understand ISO 42001. The SRA obligation column translates each gap into the regulatory language the board will recognise. The consolidated artefact column converts the board presentation into a remediation action list with named outputs.
If your firm receives an SRA request for information or a formal investigation involving AI use, use the matrix to structure your evidence response. For each gap, the SRA obligation column identifies the specific Standards and Regulations provision your evidence must address. The consolidated artefact column identifies the document the SRA will look for. Annotate the printed matrix with your evidence references — it becomes the investigation-ready evidence map you can share with the SRA directly.
Use the severity column to build your remediation roadmap in the correct regulatory priority order: Critical gaps (G4 Risk Assessment, G6 Data Governance, G7 Client Disclosure, G8 Human Oversight) must be addressed before High gaps, and High gaps before Medium. Assign a named owner and target date to each gap using the consolidated artefact column to define the deliverable. Present the roadmap to the board with the matrix as the evidence that the prioritisation is risk-based, not arbitrary.
Use the EU AI Act article cross-reference column when assessing AI vendors under SRA Code 6.3 outsourcing obligations. For each gap, the EU AI Act article identifies the regulatory obligation your vendor assessment should address — particularly relevant for firms using AI tools that may meet the high-risk classification threshold. This gives your vendor evaluation framework a dual regulatory anchor: SRA outsourcing obligation and EU AI Act supply chain requirement in one reference document.
The full matrix is in your downloaded files. This summary confirms all nine gaps, their severity ratings, and SRA obligation mapping for your records.
Summary only. Full SRA exposure descriptions, EU AI Act articles, ISO clauses, and consolidated artefacts are in your downloaded matrix files.
You now have the complete picture of where your ISO 42001 gaps are and how they map to SRA obligations. The next step is the AI Vendor Due Diligence Pocket Guide — the £47 deep-dive on Gap 9, the gap that carries direct SRA Code 6.3 outsourcing exposure and is the one most firms discover only when an SRA investigation begins.
For questions about interpreting severity ratings, applying the SRA obligation mapping, or using the matrix in a compliance committee or board context, post in the Governance Academy community.
Governance Academy Community →Email your Stripe order reference to our support address with "MAT-AIMS-LG-001 resend" in the subject line. We resend access within one business day.
support@unuslondon.com →Refund requests are handled through Stripe's 60-day guarantee — contact support@unuslondon.com with your order reference.