ISO 42001 × SRA Standards & Regulations › Legal Series › Gap Severity Matrix — £19
Also in this series: Free Guide · £47 Guide · £167 Guide
ISO 42001 × SRA Standards & Regulations · Gap Severity Matrix · Legal Edition · £19

All 9 ISO 42001 Gaps.
Every SRA Obligation.
One Reference Page.

Your compliance committee needs to know where the AI governance risks are — not read a report to find out. The Gap Severity Matrix puts all nine gaps, their SRA obligation mapping, severity ratings, and EU AI Act cross-references on a single, high-resolution reference sheet.

Designed for COLP-led compliance agendas, internal audit dashboards, and SRA investigation preparation. Pin it. Project it. Print it. The complete ISO 42001 × SRA picture in one place, in the format legal compliance professionals actually use.

One-time purchase · No subscription · Instant download · Print-ready PDF + high-res PNG

All 9 ISO 42001 Gaps SRA Obligations Mapped 4 Critical · 3 High · 2 Medium EU AI Act Articles ITIL 4 Practice Column Print-Ready A3 Landscape
Live Preview

The Complete Matrix — 9 Gaps, All Frameworks, One View

The first three rows are shown in full below. Rows 4–9 are available on purchase. Each row contains the gap, its ISO 42001 clause, the SRA obligation mapped, severity rating, EU AI Act article, and consolidated artefact.

MAT-AIMS-LG-001 v1.0 · ISO 42001 × SRA Standards & Regulations Gap Severity Matrix · Legal Edition

ISO 42001 × SRA Standards & Regulations: Gap Severity Matrix

Rows 4–9 visible on purchase
#
Gap
SRA Obligation
EU AI Act Cross-Reference
Severity
Consolidated Artefact
G1
AI Policy & Governance FrameworkClause 5.2 — AI Policy
Code 2.1 — GovernanceAbsence of documented AI policy means the firm cannot demonstrate systemic governance to SRA reviewers.
Art. 9 — Risk Management System
Risk management commensurate with AI system risk profile
Medium
AI Governance Policy (COLP/MP sign-off, annual review)
G2
Governance Structure & AccountabilityClause 5.3 — Roles, Responsibilities & Authorities
Code 2.1 — AccountabilityUndocumented AI accountability means no clear line of responsibility if AI causes client harm or SRA concern.
Art. 26 — Deployer Obligations
Appropriate technical & organisational measures for deployers
High
AI Governance Structure doc (named COLP lead, escalation path)
G3
AI System Register & TransparencyClause 6.1.2 / 8.4 — AI System Inventory
Code 1.4 · 2.1 · 6.3Firm cannot evidence competent oversight of AI or confidentiality controls without knowing what AI systems are in use.
Art. 11 — Technical Documentation
System documentation for high-risk AI applications
High
AI System Register (live; quarterly COLP review)
G4
Risk Assessment & CompetenceClause 6.1 / 6.1.3
Code 1.4 · 3.1 · 6.3Unassessed AI risk — hallucination, data breach, bias — directly threatens client outcomes
Art. 9 / Art. 10
Critical
AI Risk Register
G5
AI Lifecycle & Matter ManagementClause 8.4 / 8.5–8.6
Code 1.4 · 2.1 · 3.1
Art. 9 — Lifecycle obligations
Medium
Per-system lifecycle records
Gaps 5–9 · Severity ratings · EU AI Act articles · Consolidated artefacts — Unlock for £19 →
The Deliverable

One Document. Everything Your Compliance Committee Needs to See.

A single-page reference document engineered for governance use — not reading. Designed to be printed at A3, projected in a committee meeting, or used as a dashboard anchor for your COLP-led AI governance review.

📊 Complete Coverage

All 9 ISO 42001 Gaps — Including the Four Not in the Free Guide

Every gap in the ISO 42001 Nine-Gap Audit framework is mapped. Including the four not covered in the free lead magnet — AI Policy (G1), Risk Assessment (G4), AI Lifecycle Management (G5), and Data Governance (G6). The free guide shows where your highest SRA risks are. The matrix shows the complete picture, with severity ratings across all nine.

⚖️ SRA Mapping

SRA Obligation for Every Gap — Code and Principle References

Each gap is mapped to the SRA Standards and Regulations obligation it directly implicates — Code of Conduct section, Principle reference, and a one-line exposure description. This is the column that converts the matrix from an ISO compliance tool into an SRA regulatory risk document that a COLP can present to the management board.

🔴 Severity Ratings

4 Critical · 3 High · 2 Medium — SRA Risk Calibrated

Severity is calibrated to SRA regulatory exposure and client harm risk, not abstract ISO compliance score. A Critical gap is one where the absence of governance evidence is most likely to constitute a professional conduct issue under the Standards and Regulations. Gaps 4, 6, 7, and 8 are rated Critical. Use severity to prioritise your remediation roadmap and COLP compliance committee agenda.

🇪🇺 EU AI Act

EU AI Act Article Cross-Reference for Each Gap

The EU AI Act creates obligations that run parallel to ISO 42001 requirements. For law firms advising clients on AI matters, or using AI tools that meet the high-risk classification threshold, these obligations may apply directly. Each gap includes the relevant EU AI Act article — allowing your compliance committee to see where ISO 42001 compliance simultaneously closes EU AI Act exposure.

📋 Consolidated Artefact

The Document Each Gap Requires — Named and Defined

Each gap row identifies the consolidated artefact that closes it — the specific document or record the gap requires. This is the column that converts the matrix from a gap identification tool into a remediation action list. For each gap, you know not just that the gap exists, but what you need to produce to close it. Named, defined, and owner-assignable.

🖨️ Format

High-Res PDF · Print-Ready A3 · Committee-Ready

Delivered as a high-resolution PDF at A3 landscape — the format compliance committees and governance teams use for reference documents. Print and laminate for your compliance office. Project from a laptop in a committee meeting. Use as a standing agenda item backdrop. The design is engineered for these use cases, not general reading.

9 ISO 42001 Gaps
All Covered
4 Critical Gaps
SRA Rated
A3 Print Format
High-Res PDF
Who It's For

Built for the People Who Run the Compliance Committee, Not the People Who Brief It.

The matrix is a working document, not a reading document. It's for the people who need a complete picture of AI governance risk at a glance — and who need to produce that picture for the management board and the SRA quickly.

Primary

COLPs & Heads of Compliance

✓Use as the standing AI governance agenda item in COLP compliance committee meetings
✓Show which gaps are remediated, in-progress, and open — update quarterly as evidence is built
✓Demonstrate to the SRA that AI governance is monitored systematically, not reactively
✓Use severity ratings to build the remediation priority order for the management board
Primary

Managing Partners & Senior Leadership

✓Incorporate into the management board pack as the firm's AI governance risk dashboard
✓Use the SRA obligation column to understand personal exposure — not just institutional risk
✓Commission firm-wide AI governance remediation using severity ratings as the priority framework
✓Share with the firm's professional indemnity insurer to demonstrate systematic AI risk management
ISO 42001 × SRA Standards & Regulations · Legal Edition · MAT-AIMS-LG-001 v1.0

ISO 42001 × SRA Standards & Regulations: Gap Severity Matrix

Single-page high-res reference PDF. Instant download. One-time purchase.

£19
One-time purchase
No subscription
Instant access
VAT may apply
✓All 9 ISO 42001 gaps mapped — no gaps omitted
✓SRA Standards & Regulations obligation for each gap — Code and Principle references
✓Severity ratings: Critical (4) / High (3) / Medium (2) — SRA risk calibrated
✓EU AI Act article cross-reference for every gap
✓Consolidated artefact column — the named document each gap requires
✓High-res PDF at A3 landscape — print-ready for compliance committee use
✓UNUS London design system — consistent with the full legal series
Purchase & Download — £19 →

Processed by Stripe · Secure checkout · 60-day money-back guarantee · Instant download after purchase

Instant download 60-day guarantee One-time purchase No subscription
ISO 42001 × SRA Standards & Regulations — Legal Series

Complete the Series

Free 5 SRA Risk Gaps
Lead magnet — 5 gaps, SRA investigation scenarios, Warning boxes, First Fix actions. 16pp.
Download Free →
You are here £19 Gap Severity Matrix
All 9 gaps · SRA mapping · severity · EU AI Act. Single-page A3 PDF.
£47 Vendor Due Diligence Guide
Clause 6.6 in depth · SRA Code 6.3 · 3-tier risk model · 7-week plan. 14pp.
Learn More →
£167 Integration Guide + Calendar
Full dual-framework mapping · 8 chapters · 27-activity compliance calendar. 28pp + A2.
Learn More →
Questions

Frequently Asked Questions

The matrix is delivered as a high-resolution PDF file formatted at A3 landscape (420 × 297 mm / 16.5 × 11.7 inches). It is print-colour-adjusted to reproduce correctly on both colour and mono printers. A high-resolution PNG is also included in the download package for digital use — presentations, intranets, screen projection, and Teams/Zoom sharing.

The free guide covers five gaps (G2, G7, G8, G9, G3) in long-form — with SRA investigation scenarios, Warning boxes, and First Fix actions. It is designed for reading and self-assessment. The matrix covers all nine gaps in a single-page reference format — designed for compliance committee use, management board presentation, and SRA investigation preparation. They serve different purposes and different audiences. The matrix is the logical second step after the free guide: you know what your highest SRA risks are, now you need the complete governance picture in committee-ready format.

Severity ratings are calibrated against SRA Standards and Regulations obligations and published enforcement guidance — specifically the SRA's enforcement strategy, Code of Conduct provisions, and published investigation and adjudication decisions. They reflect SRA regulatory risk — the likelihood that absence of governance evidence for a given gap will constitute a professional conduct issue under the Standards and Regulations. Critical gaps (G4, G6, G7, G8) are those where absence most directly implicates client harm obligations or personal COLP accountability. They are governance judgements, not statistical measures based on enforcement data.

EU AI Act references are current to Regulation (EU) 2024/1689 as enacted. The matrix includes article references and brief descriptions of the parallel obligation. For full EU AI Act compliance assessment — particularly for law firms advising clients on high-risk AI deployments — the matrix is a cross-reference tool, not a compliance programme. Firms with EU AI Act client advice obligations should take qualified legal advice on the regulation's application to their specific circumstances.

Yes. The purchase licence permits internal firm use — printing, projection, sharing with compliance committee members, management board, and practice group heads within the purchasing firm. It does not permit resale, redistribution to third parties, or use as a deliverable in consulting or legal advisory engagements. Multi-firm licences and consultant licences are available — contact support@unuslondon.com.

ISO 42001 × SRA Standards & Regulations · All 9 Gaps · One Page

Your compliance committee can't manage what it can't see. Give it the complete SRA risk picture.

Nine gaps. Every SRA obligation. Severity ratings. EU AI Act references. Consolidated artefacts. One reference document your COLP can present to the board. £19.

Get the Matrix — £19 →

One-time · Instant download · A3 high-res PDF · 60-day guarantee