✓
Purchase Confirmed — Thank You

Your Gap Severity Matrix is ready to download.

Your high-res PDF and PNG files are available below. We've also sent the download links to your email.

MAT-AIMS-LG-001 v1.0
ISO 42001 × SRA Standards & Regulations
Legal Edition
Check Stripe receipt for order ref
unuslondon.com

ISO 42001 × SRA Standards & Regulations: Gap Severity Matrix

Two files are included in your purchase. Download both below. Print the PDF at A3 for compliance committee use. Use the high-res PNG for digital presentations, board packs, and intranet display.

Bookmark this page.  To re-download any time within 30 days, re-enter your email above. If you lose access, email support@unuslondon.com with your order reference and the relevant product code in the subject line.
Getting Value From the Matrix

Five Ways to Use the Gap Severity Matrix

01
COLP compliance committee agenda — standing AI governance item

Print the matrix and use it as the standing reference document for your COLP compliance committee agenda item. Each quarter, mark which gaps are remediated (✓), in progress (~), or open (✗). Over time this produces a documented, dated compliance committee record showing systematic AI governance improvement — exactly the evidence the SRA looks for when investigating whether a firm has adequate compliance arrangements in place.

02
Management board presentation — AI regulatory risk dashboard

Use the matrix as the AI governance risk dashboard in your management board pack. The severity column (Critical / High / Medium) gives leadership the prioritised risk picture without requiring them to understand ISO 42001. The SRA obligation column translates each gap into the regulatory language the board will recognise. The consolidated artefact column converts the board presentation into a remediation action list with named outputs.

03
SRA investigation preparation — evidence structure

If your firm receives an SRA request for information or a formal investigation involving AI use, use the matrix to structure your evidence response. For each gap, the SRA obligation column identifies the specific Standards and Regulations provision your evidence must address. The consolidated artefact column identifies the document the SRA will look for. Annotate the printed matrix with your evidence references — it becomes the investigation-ready evidence map you can share with the SRA directly.

04
Remediation roadmap — Critical gaps first

Use the severity column to build your remediation roadmap in the correct regulatory priority order: Critical gaps (G4 Risk Assessment, G6 Data Governance, G7 Client Disclosure, G8 Human Oversight) must be addressed before High gaps, and High gaps before Medium. Assign a named owner and target date to each gap using the consolidated artefact column to define the deliverable. Present the roadmap to the board with the matrix as the evidence that the prioritisation is risk-based, not arbitrary.

05
AI vendor assessment — EU AI Act and SRA Code 6.3 column

Use the EU AI Act article cross-reference column when assessing AI vendors under SRA Code 6.3 outsourcing obligations. For each gap, the EU AI Act article identifies the regulatory obligation your vendor assessment should address — particularly relevant for firms using AI tools that may meet the high-risk classification threshold. This gives your vendor evaluation framework a dual regulatory anchor: SRA outsourcing obligation and EU AI Act supply chain requirement in one reference document.

Quick Reference — All 9 Gaps at a Glance

The full matrix is in your downloaded files. This summary confirms all nine gaps, their severity ratings, and SRA obligation mapping for your records.

MAT-AIMS-LG-001 v1.0 · ISO 42001 × SRA Standards & Regulations Gap Severity Matrix · Legal Edition

Nine-Gap Summary Reference

#
Gap
Severity
SRA Obligation
G1
AI Policy & Governance Framework
Cl. 5.2
Medium
Code 2.1 — Governance
G2
Governance Structure & Accountability
Cl. 5.3
High
Code 2.1 — Accountability
G3
AI System Register & Transparency
Cl. 6.1.2 / 8.4
High
Code 1.4 · 2.1 · 6.3
G4
Risk Assessment & Competence
Cl. 6.1 / 6.1.3
Critical
Code 1.4 · 3.1 · 6.3
G5
AI Lifecycle & Matter Management
Cl. 8.4 / 8.5–8.6
Medium
Code 1.4 · 2.1 · 3.1
G6
Data Governance & Confidentiality
Cl. 6.2 / 8.3
Critical
Code 6.3 · 1.4
G7
Client Disclosure & AI Transparency
Cl. 8.2 / 8.7
Critical
P.2 · P.4 · Code 7.1
G8
Human Oversight & Supervision
Cl. 8.1 / 8
Critical
Code 3.1 · 1.4 · P.4
G9
Vendor Due Diligence & Supply Chain
Cl. 6.6
High
Code 6.3 · 1.4 · 2.1

Summary only. Full SRA exposure descriptions, EU AI Act articles, ISO clauses, and consolidated artefacts are in your downloaded matrix files.

ISO 42001 × SRA Standards & Regulations — Legal Series

The Matrix Identifies the Gaps. The Series Closes Them.

You now have the complete picture of where your ISO 42001 gaps are and how they map to SRA obligations. The next step is the AI Vendor Due Diligence Pocket Guide — the £47 deep-dive on Gap 9, the gap that carries direct SRA Code 6.3 outsourcing exposure and is the one most firms discover only when an SRA investigation begins.

Free ✓ 5 Gaps That Create SRA Risk — available at unuslondon.com/legal-sra-ai-gaps
£19 ✓ Gap Severity Matrix — you have this
£47 AI Vendor Due Diligence Pocket Guide — ISO 42001 Clause 6.6 in depth, SRA Code 6.3 alignment, three-tier vendor risk model, the six questions every AI vendor must answer in writing, and a seven-week zero-to-audit-ready implementation sequence. 14pp.
£167 Integration Guide + Compliance Calendar — Complete ISO 42001 × SRA dual-framework mapping across 8 intersection chapters. Evidence consolidation method. 27-activity A2 Unified Compliance Calendar. For COLPs and Managing Partners implementing full AI governance.
Get the AI Vendor Due Diligence Pocket Guide — £47 → Or explore the full series at the Governance Academy — £97/month · 7-day free trial
Support

Questions or Access Issues?

Using the Matrix

Questions about the content or how to use it

For questions about interpreting severity ratings, applying the SRA obligation mapping, or using the matrix in a compliance committee or board context, post in the Governance Academy community.

Governance Academy Community →
Download Access

Can't download or lost the link?

Email your Stripe order reference to our support address with "MAT-AIMS-LG-001 resend" in the subject line. We resend access within one business day.

support@unuslondon.com →

Refund requests are handled through Stripe's 60-day guarantee — contact support@unuslondon.com with your order reference.