Database-first governance infrastructure that makes compliance evidence retrievable in under 30 seconds. Not a consultant. Not a SaaS subscription. A system you own — live in 14 days.
Case triage, knowledge-base search, compliance drafting, clinical documentation — AI has entered day-to-day operations across law firms, financial services, manufacturers and healthcare providers faster than governance has caught up. Our own ISO/IEC 42001 gap analysis of AI-integrated systems found the same pattern holds almost everywhere we look.
Infrastructure controls exist — audit logs, access controls — but they are rarely constituted as a governing AIMS. Without one, there is no defensible answer when a regulator or client due-diligence questionnaire asks how AI use is controlled.
Hallucination in regulatory advice, vendor model outage, data leakage via API, biased outputs affecting protected groups — these risks are rarely identified, assessed or owned by anyone in particular.
No signed AI policy, no acceptable-use definitions, no individual designated as AI Risk Owner or AI System Owner. When something goes wrong, there is no documented chain of accountability to point to.
This is the same evidence gap our Governance Academy and ISO/IEC 42001 nine-gap audit content is built to close — see the free resources below.
None of this is hypothetical. Each of these obligations is either already in force or has a defined compliance date. Here's what's expected in your sector — and what a gap costs.
The SRA expects COLPs and MLROs to explain and evidence how AI is used in regulated activity — not just that it's used. Client panel reviews increasingly ask for it directly.
Risk: panel review failure · SRA supervision findings
Legal & Professional →Consumer Duty requires AI-assisted decisions to produce good outcomes and be explainable. Under SM&CR, a named Senior Manager is accountable for those outcomes — even when the model itself isn't directly regulated.
Risk: Consumer Duty enforcement · personal SMF liability
Financial Services →Predictive maintenance and AI-assisted defect detection fall inside your quality management system. Surveillance and recertification audits increasingly ask for documented control of these tools, not just the machines.
Risk: recertification non-conformance · lost supplier status
Manufacturing →AI-assisted triage, documentation and clinical decision support sit inside CQC Well-Led evidence and the Data Security & Protection Toolkit. Automated decisions affecting patients also engage UK GDPR Article 22.
Risk: "Requires Improvement" rating · DSPT non-compliance
Healthcare →EU AI Act — Cross-Sector
Prohibited-practice obligations (Feb 2025) and general-purpose AI model obligations (Aug 2025) are already in force. High-risk system obligations, originally due August 2026, are proposed for delay to December 2027 under the EU's 2026 Digital Omnibus — organisations building AI-assisted systems now should design to the original timeline, not assume the delay finalises as proposed.
Build it yourself with UNUS Govern Asset Monitor, buy a fully-deployed compliance system from us, or let us run the whole thing for you. Same architecture. Same evidence layer. Different commercial shapes.
Provision UNUS Govern on your own infrastructure. Asset Monitor continuously tracks every component, every schema, every workflow — surfacing drift, expiry, and audit gaps before the regulator sees them. For teams with the engineering capacity to operate it.
We deploy a complete, production-ready compliance system in 14 days. You own the code on day one. No SaaS lock-in, no monthly retention. Three tiers — Basic, Intermediate, and Enterprise — cover the full range of regulatory scope. Govern is then added as the operational wrapper for continuous evidence.
We operate the evidence layer for you. The Governance Engine runs scheduled readiness sweeps, asset drift checks, and audit-pack generation on a continuous cadence — so the next regulator visit, ISO surveillance audit, or FCA supervisory dialogue lands on an already- prepared system. You see the dashboard. We do the work behind it.
The traditional choice was expensive consultants or locked-in SaaS. Neither leaves you owning the outcome. UNUS London changes that equation permanently.
| Evaluation Criteria | Traditional SaaS | Big 4 Consultancy | UNUS London |
|---|---|---|---|
| 3-Year Total Cost | £936,000+ | £450,000+ | £77,000 |
| Time to Production | 2 weeks (then perpetual dependency) | 12–18 months | 14 days |
| Code Ownership | ✗ Never | ~ After final payment | ✓ Day 1 |
| Audit Evidence Retrieval | ~ Manual exports | ✗ PDF documents | ✓ <30 seconds, live |
| Immutable Audit Trail | ✗ Logs only | ✗ Not standard | ✓ Database-layer triggers |
| Regulatory Compliance Mapping | ~ Generic templates | ~ Framework docs | ✓ Hard-coded in schema |
| Live Readiness Score (0–100) | ✗ Not available | ~ Qualitative only | ✓ Live dashboard |
| Monthly Subscription Required | ✗ Forever | ✗ Ongoing retainer | ✓ One-time fee option |
| Open Source Stack | ✗ Proprietary | ✗ Vendor-tied | ✓ PostgreSQL + n8n |
| Infrastructure Ownership | ✗ Cloud vendor | ✗ Consultant holds keys | ✓ Your servers |
| Verdict | Perpetual cost centre | Expensive, slow delivery | The Asset You Own |
Every UNUS London system is architected against named clauses in these frameworks from the schema up — not mapped to them afterward in a spreadsheet.
AI management systems — policy, risk, human oversight and continual improvement for organisations that develop, provide or use AI.
Explore →Risk-tiered obligations for AI systems placed on or used in the EU market — prohibited practices, GPAI transparency, high-risk conformity.
Explore →Information security management — the ISMS backbone most regulated firms already hold, and the natural integration point for an AIMS.
Explore →Service value system for change management, service transition and standard operating procedures — how governance becomes repeatable practice.
Explore →IT asset management — the software and hardware inventory discipline underneath every audit-ready evidence trail.
Explore →Quantities and units — correct electrotechnical notation for manufacturing and engineering evidence documentation.
Explore →Everything below is free or self-serve. If you want to understand your own gaps before talking to us, start here.
Build your own compliance infrastructure alongside us — every schema, workflow and SOP taught step by step.
Join the Academy →A short self-assessment against the Act's risk tiers — see where your AI use sits and what it triggers.
Get the Scorecard →ISO/IEC 42001 nine-gap audit guides mapped against SRA, FCA Consumer Duty, CQC and ISO 9001 — by industry.
Browse Ebooks →Long-form breakdowns of the compliance evidence problem, written for the people who have to answer to a regulator.
Read the Blog →Select your industry. Adjust the sliders to match your current situation. Every factor is calculated against verified industry benchmark data.
30-min discovery call · No sales pitch · Honest recommendation
Calculations use conservative estimates based on published research (Gartner, MakeUK, Thomson Reuters, HDI 2024–2025) and anonymised UNUS client data. Individual results will vary.
A 60-minute discovery call includes a no-obligation review of your current compliance evidence gaps. No sales pitch — a genuine assessment of where your governance infrastructure stands today.
Your details are used only to respond to your enquiry. No marketing without consent.
No obligation. A genuine review of your compliance evidence gaps.
📅 Book on Calendly — Free ↗