UNUS London — About // Meshach McKenzie, Founder & Compliance Architect — Document Class: Public
Home Solutions Industries Standards Academy Blogs About Book Discovery Call UNUS Govern
U
Evidence Over Assertion  ·  Structural Enforcement  ·  Database-First Governance  ·  SRA · FCA · ISO 9001 · ISO 27001 · ITIL 4 · IEC  ·  Production-Ready Infrastructure  ·  Immutable Audit Trails  ·  Clause-Level Alignment  ·  Evidence Over Assertion  ·  Structural Enforcement  ·  Database-First Governance  ·  SRA · FCA · ISO 9001 · ISO 27001 · ITIL 4 · IEC  ·  Production-Ready Infrastructure  ·  Immutable Audit Trails  ·  Clause-Level Alignment  · 
About — Founder Story

Built on One
Unbreakable Principle

Compliance must be evidenced at the structural level.
Not described. Not asserted. Enforced.

UNUS London exists because every regulated organisation in the UK faces the same structural problem — they have compliance policies, but they cannot evidence compliance when it is demanded. The solution is not a better policy document. It is infrastructure that makes evidence automatic.

Founder Profile — UNUS London
MM
Meshach McKenzie
Founder & Compliance Architect
OrganisationUNUS London
SpecialisationDatabase-First Governance
IndustriesLegal · Finance · Mfg · Healthcare
StackPostgreSQL · n8n · Supabase
LocationImperial Central, Slough UK
Contactcompliance@unuslondon.com
Status: Accepting Engagements
🏛️
Industries Served
Legal · Finance
Manufacturing · Healthcare
📐
Standards Aligned
SRA · FCA · ISO 9001
ISO 27001 · ITIL 4 · IEC
🗄️
Tech Stack
PostgreSQL · n8n
Supabase · HTML
📍
Location
Imperial Central
Slough, United Kingdom

Where UNUS London
Came From

The problem that created UNUS London is not complicated to describe. Regulated organisations are required to evidence compliance. Almost none of them can. When a regulator arrives — an SRA inspector, an FCA supervisor, a CQC assessor — what is typically produced in response to their questions is a collection of documents, spreadsheets, and folder structures that were never designed to be interrogated under pressure. The evidence is inconsistent. The records are incomplete. The outcome is a finding that could have been avoided.

Meshach McKenzie observed this pattern across multiple regulated sectors and drew a conclusion that most compliance consultants resist: the problem is not a training problem, a process problem, or a policy problem. It is a systems problem. Organisations without governance infrastructure will fail to evidence compliance regardless of how well their people understand the regulatory framework, because there is no system producing evidence automatically and immutably.

"The compliance industry has spent decades teaching people what the rules are. Nobody was building the infrastructure to prove you were following them."

The conventional response to compliance failure is to commission a consultant to write a new policy, run a training session, or implement a generic software tool. None of these address the root cause. A policy document cannot produce evidence on demand. A training record does not generate an audit trail. A SharePoint folder is not a compliance system.

UNUS London was founded on a different premise: that compliance infrastructure must be built at the database level, where enforcement is structural rather than procedural. When the compliance rule is encoded in a PostgreSQL trigger, it cannot be bypassed by oversight, convenience, or time pressure. The audit trail is immutable because the database makes it so — not because someone remembered to update a spreadsheet.

This is not a theoretical position. Every system UNUS London builds has been deployed in a production environment for a real regulated client. The SRA Supervision Register enforces the self-supervision prohibition at the trigger level. The Client Matter Checklist Engine blocks closure until every required step has been completed. The SRA Readiness Report Generator produces audit-ready evidence on a weekly schedule without human intervention. Evidence is not gathered when the regulator arrives. It has already been generated, timestamped, and stored — continuously, automatically, without anyone having to think about it.

The name UNUS — Latin for one — reflects the founding principle: one infrastructure layer, one source of truth, one audit trail. All compliance evidence flows from a single, structured, immutable record. There are no parallel spreadsheets. No conflicting versions. No question about which document is current. The database is the record, and the record is always correct.

01
The Observation
Regulated organisations cannot evidence compliance
Across multiple regulated sectors, the same structural failure: policies exist, but audit trails do not. Evidence cannot be retrieved on demand.
02
The Diagnosis
This is a systems problem — not a training problem
No amount of policy writing or compliance training produces evidence automatically. Only infrastructure does. The absence of a system is the cause of every avoidable audit failure.
03
The Principle
Enforcement must be structural — not procedural
Compliance rules encoded in PostgreSQL triggers cannot be bypassed. Audit logs generated by AFTER INSERT triggers cannot be retrospectively altered. This is the only reliable compliance architecture.
04
The Build
UNUS London is founded
A compliance architecture firm built on one principle: evidence must be structural. Every system deployed produces immutable, auditor-ready records automatically — without human intervention.
05
Now
Production systems across four regulated industries
Legal, financial services, manufacturing, and healthcare clients deploy UNUS systems. The Governance Academy makes the same systems available to practitioners who build their own infrastructure.
The Founding Observation
Organisations do not fail regulatory audits because their people do not understand the rules. They fail because they have no system generating proof that the rules were followed.
Meshach McKenzie — Founder, UNUS London

What UNUS London
Stands For

Mission Statement
To make compliance evidenceable — by building database-first governance infrastructure that produces immutable, auditor-ready records automatically, for every regulated organisation in the UK.
  • Evidence over assertion — always
  • Enforcement at the database level — not the application level
  • Ownership transferred — not retained
  • Infrastructure that runs without human intervention
  • Documentation written for the person deploying it — not the person who built it
01
Evidence Over Assertion
Every claim about compliance must be backed by a record that was generated automatically, timestamped precisely, and stored immutably. The database does not lie, forget, or omit. If the evidence does not exist in the system, the compliance did not occur.
02
Structural Enforcement
Compliance rules that depend on human memory, manual process, or application-layer validation will eventually be bypassed — by oversight, pressure, or convenience. Rules enforced at the database trigger level cannot be circumvented, regardless of how data is accessed.
03
Genuine Ownership Transfer
Every system UNUS London builds is transferred entirely to the client. The schema runs in their database. The workflow runs in their n8n instance. The evidence records are their records. UNUS London has no access to client data, and no ongoing dependency is created.
04
Precision Over Comprehensiveness
UNUS London does not build generic compliance platforms. Each system addresses one specific regulatory obligation, enforces it at the database level, and produces exactly the evidence that obligation requires. Nothing superfluous. Nothing missing.
05
Documentation as a First-Class Deliverable
A system without documentation is a system that cannot be maintained, extended, or audited. Every UNUS deployment includes a complete build guide written for the person operating the system — not the person who architected it. Non-technical compliance officers should be able to maintain what was built.
06
Regulatory Specificity
Generic governance platforms satisfy no regulator. UNUS systems are clause-level aligned — each design decision traceable to a specific SRA Code provision, MLR regulation, ISO clause, or IEC standard. When the inspector asks which obligation a system satisfies, the answer is a paragraph number — not a category name.

What UNUS London
Is Not

Understanding what UNUS London declines to be is as important as understanding what it builds. These distinctions are not marketing positions. They are the consequence of a firm belief about what actually closes the compliance evidence gap.

Not a compliance consultancy
UNUS London does not write policies, produce reports, or deliver recommendations. When a consultant leaves, they take their knowledge with them and leave a document behind. UNUS London leaves infrastructure — running in your database, owned by you, generating evidence without anyone present.
Not a SaaS compliance platform
SaaS tools hold your compliance data in their database, on their infrastructure, under their access controls. When you cancel, the data is gone. UNUS systems run on your Supabase account, your n8n instance, your infrastructure. You own the evidence. Always.
Not a training provider
Training teaches people what the rules are. It does not produce a supervision log entry, an AML screening record, or an immutable audit trail. UNUS London builds the systems that produce those records automatically — regardless of whether anyone has received training that day.
Not a generic document management system
SharePoint, Google Drive, and similar tools store documents. They do not enforce compliance obligations, prevent non-compliant actions, or generate timestamped evidence of process completion. UNUS systems are not document stores — they are enforcement infrastructure with an evidence trail.
What UNUS London IsA compliance architecture firm that builds production-ready, database-first governance infrastructure for regulated UK organisations. Every system is clause-level aligned to a specific regulatory framework, enforced at the PostgreSQL trigger level, documented for non-technical operators, and transferred entirely to the client. The evidence it generates is immutable. The system that generates it is owned by the organisation it serves.

The Architecture
Approach

Every UNUS London engagement follows the same disciplined approach — from regulatory obligation to production system. The sequence is non-negotiable because every step depends on the one before it.

01
Phase One
Regulatory Obligation Mapping
Every engagement begins with the specific regulatory clause that creates the evidence obligation. Not a category of compliance — a paragraph number. SRA Code §7.1. MLR 2017 Regulation 28. ISO 9001 Clause 7.5. The system is designed backwards from the evidence that obligation demands.
02
Phase Two
Database Schema Design
The compliance obligation is translated into a PostgreSQL schema. Tables, columns, constraints, ENUM types, and foreign key relationships are designed to make non-compliant data states structurally impossible — not merely discouraged. A supervision record without a valid supervisor cannot be inserted. A matter cannot close with an incomplete checklist.
03
Phase Three
Enforcement & Audit Layer
Trigger functions enforce business rules at the database level. AFTER INSERT/UPDATE triggers write to immutable audit log tables — every change recorded, timestamped, and attributed. Stored procedures expose complex compliance operations as single callable units. The audit trail is a structural output of the system, not an optional add-on.
04
Phase Four
Automation Workflow
n8n automation connects the database to the outside world — scheduled compliance reports delivered by email, MLRO alerts triggered the moment a high-risk flag is raised, SLA monitoring with automatic escalation. Evidence generation is continuous and automatic. The regulator does not trigger evidence collection. The system already collected it.
05
Phase Five
Transfer, Documentation & Handover
The completed system is transferred entirely to the client — schema scripts, workflow JSON, HTML frontend, and a complete build guide written for the person who will operate and maintain it. The guide is not a technical reference document. It is an operational manual a compliance officer can follow on their own, with every SQL script and configuration step included in full.
What Every Deployment Includes
🗄️
PostgreSQL Schema
Tables, constraints, ENUM types, stored procedures, trigger functions, and audit log views — production-ready, executed in Supabase SQL Editor
⚙️
n8n Workflow JSON
Import-ready automation workflow — webhook triggers, scheduled reports, alert routing, and Gmail delivery, fully configured
🌐
HTML Frontend Interface
Deployable interface for the system — styled to the UNUS design system, no additional engineering required
📘
Complete Build Guide
30–50 page operational manual written for compliance officers — every SQL script, every configuration step, every debugging note included in full
🔍
Evidence Retrieval Queries
The exact SQL queries to run when a regulator asks for evidence — in the room, in real time, returning auditor-ready records in under 30 seconds

Standards UNUS London
Builds Against

Every system deployed by UNUS London is aligned to one or more of the following regulatory frameworks at the clause level. Alignment means the specific database constraint, trigger, or workflow node is traceable to the paragraph it enforces.

SRA Code of Conduct 2019Solicitors Regulation Authority — legal sector governance
Money Laundering Regulations 2017UK MLR — AML risk, CDD, and SAR obligations
ISO 9001:2015Quality Management Systems — documented information (Cl. 7.5)
ISO/IEC 27001:2022Information Security Management — Annex A controls
ITIL 4Service Value System — Change Enablement, Incident, Service Desk
IEC 80000 SeriesQuantities and Units — SI unit notation in governance documentation
ISO/IEC 19770-1:2017IT Asset Management — four-tier maturity, Annex SL alignment
FCA SM&CRSenior Managers & Certification Regime — financial services
CQC Quality StatementsCare Quality Commission — Well-Led and clinical governance
IEC 62443OT Cybersecurity — Security Levels, zone and conduit architecture
IEC 82079-1Technical documentation — instructions for use, safety notices
PUWER / COSHHUK Health & Safety — equipment maintenance and COSHH records

A Personal Note on
Why This Matters

I built UNUS London because I kept watching the same thing happen to good organisations. A regulator arrives. The people in the room understand their regulatory obligations perfectly. But they cannot produce the evidence to prove they have been meeting them — because no system was ever built to generate that evidence automatically.

The outcome is always the same. Findings are raised. Conditions are imposed. Reputations are affected. And the organisation goes back to writing a new policy — as though the problem was that the rules were not documented clearly enough.

The rules were not the problem. The absence of infrastructure was the problem.

Every system I build at UNUS London is designed to close that gap permanently. Not by describing what compliance looks like — but by building the infrastructure that makes compliance automatic and its evidence irrefutable. When the inspector asks for proof, the answer is already in the database. It has been there since the first record was written.

That is what I mean when I say evidence must be structural. And that is what every UNUS London system delivers.

Meshach
Meshach McKenzie
Founder & Compliance Architect — UNUS London
Founding Principles — UNUS London
P-01
Evidence Over AssertionIf the record does not exist in the system, the compliance did not occur.
P-02
Structural EnforcementRules encoded in PostgreSQL triggers cannot be bypassed by oversight, pressure, or convenience.
P-03
Ownership TransferThe client owns the infrastructure. UNUS London retains no access to client data.
P-04
Continuous EvidenceThe regulator does not trigger collection. Evidence is already generated, timestamped, and stored.
P-05
Clause-Level AlignmentEvery design decision is traceable to a paragraph number — not a category name.
compliance@unuslondon.com  ·  @UNUSlondon

If You Are Ready to Build
Real Compliance Infrastructure

A 60-minute discovery call with Meshach McKenzie identifies your compliance evidence gaps and scopes exactly what infrastructure will close them. No generic recommendations. No policy documents. A system — built and transferred.