Khiliad Legal
Navigation
Services
Governance and Certification

AI governance your firm can stand behind.

The SRA expects law firms to have effective governance in place for how AI is used. We help you build it, document it, and where appropriate, certify it to the world’s first international AI management standard, ISO 42001.

The SRA Code of Conduct for Firms, Rule 2.1(a)

Firms must have effective governance structures, arrangements, systems and controls in place to ensure they comply with regulatory and legislative requirements. The use of AI does not change this obligation. It extends it.

The problem
AI is already in your firm. Whether you have a policy or not, your people are using it.
What good looks like
Documented. Supervised. Defensible. Governance that shows regulators, clients, and your own team exactly how AI is being used and controlled.
Why Governance Matters

This is not optional anymore.

The SRA is clear. Firms using AI must have governance in place. Recent tribunal decisions have confirmed that using AI without adequate supervision is a professional conduct risk, not just a technology risk. The question is not whether your firm needs a governance framework. It is whether yours is fit for purpose.

1

The SRA expects it

Rule 2.1(a) of the Code of Conduct for Firms requires effective governance, systems and controls. The SRA has confirmed that compliance officers for legal practice are responsible for regulatory compliance when new technology is introduced. That includes AI.

2

The courts have weighed in

Recent tribunal decisions have established that supervising AI output is a professional obligation, not a choice. Firms that cannot demonstrate how that supervision works are exposed. Documentation is not bureaucracy. It is protection.

3

Clients are beginning to ask

Commercially sophisticated clients, particularly those in financial services, energy, and the public sector, are starting to include AI governance in their supplier due diligence. ISO 42001 certification answers those questions before they become a barrier to work.

4

AI mistakes scale differently

A junior lawyer’s error affects one matter. An ungoverned AI tool used across a practice can introduce the same error across dozens. Governance frameworks exist to catch systemic risk before it becomes systemic harm.

The SRA’s Own Words

Governance that is fit for purpose.

SRA guidance on AI governance
“Make sure your governance frameworks remain fit-for-purpose and underpin the responsible adoption, use and monitoring of AI. Your client’s best interests must remain at the centre of your decisions about the use of technology.”

The SRA has also stated that firms should appoint a senior individual with overall oversight of AI systems, establish a committee responsible for training and monitoring, carry out regular audits, and ensure governance structures are agile enough to respond to a changing regulatory landscape. Most firms have not yet done this in any documented way.

The Law Society

Good practice includes appointing a senior individual with overall AI oversight, setting up a committee for training and monitoring, carrying out regular audits, and maintaining an agile governance structure that can respond as the regulatory picture evolves.

What We Deliver

Practical governance, not paper exercises.

Everything we deliver is grounded in how your firm actually works. We do not apply a generic template and call it a framework. We look at your practice, your tools, your people, and your risk profile, and we build governance that is specific, defensible, and usable.

AI Policy for your firm

A written policy covering acceptable use, prohibited uses, data handling, supervision requirements, and staff responsibilities. Written in plain English. Specific to your practice area and size.

AI Risk Register

A documented register of the AI systems and tools your firm uses, the risks associated with each, the controls in place, and who is responsible. The foundation of any credible governance framework.

Roles and Responsibilities Framework

Clarity on who owns AI governance at firm level. Who is the senior responsible individual. What the COLP’s role covers. How oversight is structured and what gets escalated.

Audit and Review Process

A structured process for regular governance reviews. What to check, how often, who is responsible, and what good looks like. Designed to be sustainable, not a one-off exercise.

ISO 42001 Certification Pathway

For firms seeking formal certification, we build the complete AI Management System required by the standard and guide you through to independent audit and certification. See below for detail.

ISO 42001

The standard
that changes things.

ISO/IEC 42001:2023 explained

The world’s first certifiable AI management standard

Published in December 2023, ISO 42001 is the international standard for establishing, implementing, maintaining, and continually improving an AI Management System within an organisation. It is the only AI governance framework in the world that is independently certifiable.

It is not a technical standard about how AI works. It is a governance standard about how organisations use AI responsibly. That distinction matters enormously for law firms, where the question is never about the algorithm. It is always about the people, the processes, and the accountability.

Context and leadership
Understanding your organisation’s AI context and assigning clear leadership accountability
Risk and impact assessment
Identifying, evaluating, and treating AI-specific risks across your practice
Policies and controls
Written policies covering acceptable use, data handling, bias, and supervision
Monitoring and improvement
Ongoing audit, review, and continuous improvement of your AI governance
Independent certification
Third-party audit and formal certification by an accredited certification body
How It Works

Two stages to certified.

Certification follows a clear sequence. Everything has to be in place before the audit can happen. We handle stage one. The audit itself is conducted independently.

Stage 1

Get everything in place

A certified ISO implementation lead works with your firm to build the complete governance foundation. Every policy, framework, and documented process your firm needs - written, structured, and ready for audit. This is the work that has to be done before certification is possible.

Discovery, gap analysis, and build · 4 to 8 weeks
Governance Framework
AI Policy and Governance Package
From £10,000
Scoped to your firm, excl. VAT
Written AI use policy, tailored to your practice
AI risk register and impact assessments
Roles and responsibilities framework
Audit and ongoing review process
Delivered by a certified ISO implementation lead
Stage 2

The audit

Once everything is in place, an independent auditor conducts the formal ISO 42001 audit. We prepare your firm, coordinate with the certification body, and stay alongside you throughout. The audit itself is conducted independently — that is what makes the certification meaningful.

Conducted by accredited independent auditors · Outcome: ISO 42001 certification
Full Certification
ISO 42001 Certification Pathway
From £10,000
Scoped to your firm, excl. VAT and audit body fees
Gap analysis against the ISO 42001 standard
Full audit preparation and pre-audit review
Coordination with accredited certification body
Support through the certification audit itself
ISO 42001 certification on successful completion
Common Questions

Things people usually ask.

Does my firm actually need ISO 42001 certification?+
Probably not yet, but that depends on your client base and your ambitions. ISO 42001 certification makes the most sense for firms that are already winning or targeting clients who include AI governance in their due diligence, or for firms that want to position themselves as leaders on this issue before it becomes table stakes. What every SRA-regulated firm needs is a documented governance framework. We can deliver that without the certification pathway if that is the right fit for where your firm is now.
How is ISO 42001 different from a generic AI policy?+
A generic AI policy tells your team what they can and cannot do. ISO 42001 goes further: it requires you to establish a full management system around AI, covering risk assessment, impact assessment, governance structure, monitoring, continuous improvement, and independent audit. It is the difference between having a rule and being able to prove, to an external auditor, that the rule is working. The certification is what makes it credible to people outside your firm.
How long does the ISO 42001 certification process take?+
For a firm with little existing governance in place, typically three to five months from starting with us to completing the certification audit. The timeline depends on the complexity of your AI use, how many tools and systems need to be documented, and the availability of the certification body. We will give you a realistic timeline before you commit to anything.
What does ISO 42001 certification actually cost?+
Our fee for building the AI Management System and guiding you through the process is scoped and fixed before we begin. The certification body charges a separate audit fee, which varies depending on the size and complexity of your firm. We will confirm both figures during the scoping conversation so you know the full cost upfront.
We already have a data protection policy. Does that cover AI governance?+
Partially. UK GDPR and data protection obligations are a component of responsible AI use, but they do not cover the full picture. AI governance also requires you to address how AI outputs are supervised and verified, which tools are appropriate for which tasks, how risk is assessed and documented, and how your governance is reviewed over time. A data protection policy is a starting point, not a complete governance framework.
Get Started

Not sure what your firm needs?

Tell us where you are and we will tell you what makes sense. If a standalone governance framework is the right fit, we will say so. If ISO 42001 certification makes sense for your firm, we will explain exactly what that involves.