Technical guides, regulatory analysis, and build documentation for COLPs, MLROs, Practice Managers, and Compliance Officers. Written by the team that builds the systems.
Law firms fail SRA inspections not because supervision didn't happen — but because they cannot prove it did. The solution is infrastructure, not advice.
Most firms treat the SRA Supervision Register as a spreadsheet exercise. The register is in fact a live operational system — and the regulator is testing whether yours can answer questions in 30 seconds.
A client care checklist in a Word document is an aspiration. A client care checklist in a PostgreSQL schema with mandatory fields and audit triggers is a compliance system.
The Money Laundering Regulations 2017 place a specific supervisory burden on the MLRO that most firms are not meeting structurally. Here is what the infrastructure looks like.
FCA supervisors do not want to see a PDF. They want to see evidence that your Senior Manager obligations are assigned, tracked, and producible under inspection pressure.
A breach register kept in a spreadsheet has no integrity. Any cell can be edited after the fact. An immutable PostgreSQL table with audit triggers cannot. The FCA knows the difference.
A £50,000/yr ITSM subscription doesn't deliver compliance — it delivers dependency. The same architecture built on open infrastructure costs a fraction and produces evidence the regulator can audit.
ISO/IEC 27001:2022 Annex A controls are only effective when enforced at the system layer. A policy document is an intention. A Row Level Security policy in PostgreSQL is a control.
ITIL 4 does not mandate any specific tool. It mandates a process. Here is how to build a Change Advisory Board workflow and approval audit trail in n8n and PostgreSQL for under £2,000.