UNUS London  —  Compliance Architecture Division  |  UNCLASSIFIED // REGULATED INDUSTRIES
Home Solutions Industries Standards Academy Blogs Ebooks About Book Discovery Call UNUS Govern
Compliance Architecture — Production Ready

The Self-Driving
Enterprise Architecture
for Regulated Industries

Database-first governance infrastructure that makes compliance evidence retrievable in under 30 seconds. Not a consultant. Not a SaaS subscription. A system you own — live in 14 days.

0 Days to Production
0s Evidence Retrieval
£13,397 Starting Price
sra_compliance_audit.sql — PostgreSQL 17.4 (Supabase UK)
ISO/IEC 42001 EU AI Act ISO/IEC 27001 SRA Code 2019 ITIL 4 MLR 2017 ISO 9001:2015 IEC 80000 Series

Regulated Firms Are Already
Using AI. Few Can Evidence It.

Case triage, knowledge-base search, compliance drafting, clinical documentation — AI has entered day-to-day operations across law firms, financial services, manufacturers and healthcare providers faster than governance has caught up. Our own ISO/IEC 42001 gap analysis of AI-integrated systems found the same pattern holds almost everywhere we look.

Critical ISO/IEC 42001 Cl. 4.3–4.4

No AI Management System

Infrastructure controls exist — audit logs, access controls — but they are rarely constituted as a governing AIMS. Without one, there is no defensible answer when a regulator or client due-diligence questionnaire asks how AI use is controlled.

Critical ISO/IEC 42001 Cl. 6.1

No AI Risk Register

Hallucination in regulatory advice, vendor model outage, data leakage via API, biased outputs affecting protected groups — these risks are rarely identified, assessed or owned by anyone in particular.

Evidenced Gap ISO/IEC 42001 Cl. 5.2 / 5.3

No Policy, No Named Owner

No signed AI policy, no acceptable-use definitions, no individual designated as AI Risk Owner or AI System Owner. When something goes wrong, there is no documented chain of accountability to point to.

This is the same evidence gap our Governance Academy and ISO/IEC 42001 nine-gap audit content is built to close — see the free resources below.

The Deadlines and Expectations
Already Applying to Your Sector

None of this is hypothetical. Each of these obligations is either already in force or has a defined compliance date. Here's what's expected in your sector — and what a gap costs.

⚖️ Legal & Professional

SRA Accountability for AI-Assisted Decisions

The SRA expects COLPs and MLROs to explain and evidence how AI is used in regulated activity — not just that it's used. Client panel reviews increasingly ask for it directly.

Risk: panel review failure · SRA supervision findings

Legal & Professional →
🏦 Financial Services

Consumer Duty Meets Algorithmic Accountability

Consumer Duty requires AI-assisted decisions to produce good outcomes and be explainable. Under SM&CR, a named Senior Manager is accountable for those outcomes — even when the model itself isn't directly regulated.

Risk: Consumer Duty enforcement · personal SMF liability

Financial Services →
🏭 Manufacturing

ISO 9001 Audits Now Probe AI-Assisted QA

Predictive maintenance and AI-assisted defect detection fall inside your quality management system. Surveillance and recertification audits increasingly ask for documented control of these tools, not just the machines.

Risk: recertification non-conformance · lost supplier status

Manufacturing →
🏥 Healthcare

CQC Well-Led & DSPT Now Cover AI Tools

AI-assisted triage, documentation and clinical decision support sit inside CQC Well-Led evidence and the Data Security & Protection Toolkit. Automated decisions affecting patients also engage UK GDPR Article 22.

Risk: "Requires Improvement" rating · DSPT non-compliance

Healthcare →

EU AI Act — Cross-Sector

Prohibited-practice obligations (Feb 2025) and general-purpose AI model obligations (Aug 2025) are already in force. High-risk system obligations, originally due August 2026, are proposed for delay to December 2027 under the EU's 2026 Digital Omnibus — organisations building AI-assisted systems now should design to the original timeline, not assume the delay finalises as proposed.

Three Ways to Deploy
UNUS Governance Infrastructure

Build it yourself with UNUS Govern Asset Monitor, buy a fully-deployed compliance system from us, or let us run the whole thing for you. Same architecture. Same evidence layer. Different commercial shapes.

Option 01
Build It Yourself
Govern Full Stack + Asset Monitor on your infrastructure
£449/mo
UNUS Govern Full Stack · self-managed

Provision UNUS Govern on your own infrastructure. Asset Monitor continuously tracks every component, every schema, every workflow — surfacing drift, expiry, and audit gaps before the regulator sees them. For teams with the engineering capacity to operate it.

  • Full PostgreSQL schema (audit, asset, evidence tables)
  • Asset Monitor (drift, expiry, configuration state)
  • n8n workflow library (read-only by default)
  • SQL evidence layer (live, <30s retrieval)
  • Source code ownership, full transparency
  • You operate. We don't see your data.
Explore Govern Full Stack →
Option 03
Run It as a Service
Govern Governance Engine — managed continuous compliance
£299/mo
UNUS Govern Engine · managed service

We operate the evidence layer for you. The Governance Engine runs scheduled readiness sweeps, asset drift checks, and audit-pack generation on a continuous cadence — so the next regulator visit, ISO surveillance audit, or FCA supervisory dialogue lands on an already- prepared system. You see the dashboard. We do the work behind it.

  • Continuous readiness score (0–100, live)
  • Weekly evidence pack generation
  • Quarterly regulatory landscape review
  • Dedicated compliance architect on call
  • Incident response within 4 business hours
  • Includes 1 industry add-on of your choice
  • Cancel anytime — your data exports clean
See the Engine →

Why Regulated Firms
Are Switching to UNUS

The traditional choice was expensive consultants or locked-in SaaS. Neither leaves you owning the outcome. UNUS London changes that equation permanently.

Evaluation Criteria Traditional SaaS Big 4 Consultancy UNUS London
3-Year Total Cost £936,000+ £450,000+ £77,000
Time to Production 2 weeks (then perpetual dependency) 12–18 months 14 days
Code Ownership ✗ Never ~ After final payment ✓ Day 1
Audit Evidence Retrieval ~ Manual exports ✗ PDF documents ✓ <30 seconds, live
Immutable Audit Trail ✗ Logs only ✗ Not standard ✓ Database-layer triggers
Regulatory Compliance Mapping ~ Generic templates ~ Framework docs ✓ Hard-coded in schema
Live Readiness Score (0–100) ✗ Not available ~ Qualitative only ✓ Live dashboard
Monthly Subscription Required ✗ Forever ✗ Ongoing retainer ✓ One-time fee option
Open Source Stack ✗ Proprietary ✗ Vendor-tied ✓ PostgreSQL + n8n
Infrastructure Ownership ✗ Cloud vendor ✗ Consultant holds keys ✓ Your servers
Verdict Perpetual cost centre Expensive, slow delivery The Asset You Own

Standards-Aligned By Design,
Not By Retrofit

Every UNUS London system is architected against named clauses in these frameworks from the schema up — not mapped to them afterward in a spreadsheet.

ISO/IEC 42001:2023

AI management systems — policy, risk, human oversight and continual improvement for organisations that develop, provide or use AI.

Explore →

EU AI Act

Risk-tiered obligations for AI systems placed on or used in the EU market — prohibited practices, GPAI transparency, high-risk conformity.

Explore →

ISO/IEC 27001:2022

Information security management — the ISMS backbone most regulated firms already hold, and the natural integration point for an AIMS.

Explore →

ITIL 4

Service value system for change management, service transition and standard operating procedures — how governance becomes repeatable practice.

Explore →

ISO/IEC 19770-1:2017

IT asset management — the software and hardware inventory discipline underneath every audit-ready evidence trail.

Explore →

IEC 80000 Series

Quantities and units — correct electrotechnical notation for manufacturing and engineering evidence documentation.

Explore →

Free Resources, The Academy,
and What We've Published

Everything below is free or self-serve. If you want to understand your own gaps before talking to us, start here.

Free 7-Day Trial

Governance Academy

Build your own compliance infrastructure alongside us — every schema, workflow and SOP taught step by step.

Join the Academy →
Free Scorecard

EU AI Act Readiness Scorecard

A short self-assessment against the Act's risk tiers — see where your AI use sits and what it triggers.

Get the Scorecard →
Free + Paid Guides

Ebook Store

ISO/IEC 42001 nine-gap audit guides mapped against SRA, FCA Consumer Duty, CQC and ISO 9001 — by industry.

Browse Ebooks →
Free to Read

Blogs & Insights

Long-form breakdowns of the compliance evidence problem, written for the people who have to answer to a regulator.

Read the Blog →

Calculate Your
3-Year Savings vs. SaaS

Select your industry. Adjust the sliders to match your current situation. Every factor is calculated against verified industry benchmark data.

Your Current Situation
Typical Client Results
Your 3-Year ROI
3-Year SaaS Cost
£0
Includes 15% year-on-year price increases
3-Year UNUS Cost
£0
One-time setup + optional managed service. 100% code ownership.
Labour Savings (3-Year)
£0
Total 3-Year Savings
£0
Combined ROI
0%

30-min discovery call  ·  No sales pitch  ·  Honest recommendation

Calculations use conservative estimates based on published research (Gartner, MakeUK, Thomson Reuters, HDI 2024–2025) and anonymised UNUS client data. Individual results will vary.

Frequently Asked

No. Once deployed, every system has a clean HTML frontend interface. Your team interacts with forms, dashboards, and reports — not SQL. The database architecture sits below the surface, enforcing compliance rules automatically. You need no technical knowledge to operate the system day-to-day.
You own the code from Day 1. You can modify, extend, or migrate the system without any involvement from UNUS London. Future development support is available under a separate arrangement — but it is never a condition of using what you've bought.
Days 1–3: Requirements confirmation and schema sign-off. Days 4–8: Database build, stored procedures, and triggers. Days 9–12: n8n workflow construction and frontend integration. Days 13–14: Testing, data migration, and handover. The 14-day guarantee applies to standard mini solution scope — bespoke enterprise work carries longer timelines.
All systems are deployed on Supabase PostgreSQL hosted in the UK region by default — fully UK GDPR and DPA 2018 compliant. For Enterprise clients, deployment to your own infrastructure is available. You always know exactly where your data is and who can access it.
Yes — and this is by design. Mini solutions are architected with upgrade paths built in. The schema design anticipates integration with the other systems in the suite. When you're ready to upgrade, the data doesn't need to be migrated — the new systems connect to the database you already have.
A SaaS product gives you a shared platform with generic workflows and templated reports. You rent access to it indefinitely. UNUS London builds a bespoke system specific to your firm, mapped to your regulatory obligations, deployed on infrastructure you control, and transferred to you as owned code on Day 1.

Ready to own your
compliance infrastructure?

A 60-minute discovery call includes a no-obligation review of your current compliance evidence gaps. No sales pitch — a genuine assessment of where your governance infrastructure stands today.

Start the Conversation

📍
Address
Imperial Central, 23–25 Mill Street
Slough, United Kingdom
📞
Phone
07388 735375
✉️
📅
Discovery Call
Schedule via Calendly ↗
in f ig

Your details are used only to respond to your enquiry. No marketing without consent.

OR BOOK DIRECTLY

Book a 60-Minute Discovery Call

No obligation. A genuine review of your compliance evidence gaps.

📅 Book on Calendly — Free ↗