LegalAI Space

Premium and Business plans · v1.0.0

Audit & Risk

Board-ready AI-governance posture, impact assessments and audit

Protocols
2
Skills
8
Public sources
4
Workflows
1
Audit & compliance
The Audit & compliance register: every piece of AI work the firm produced, who authorised it and whether the checks passed, with period, matter and person filters, totals, and an Export button.

The Audit & compliance register: every piece of AI work the firm produced, who authorised it and whether the checks passed, with period, matter and person filters, totals, and an Export button.

What it does

Assesses the firm's own compliance posture and produces risk registers and inspection bundles.

The Audit & Risk Agent does the internal work: compliance posture against the SRA Code and the EU AI Act, risk registers and structured assessment reports, drawing on skills covering COLP and COFA duties, SRA compliance rules, EU AI Act compliance, NIST AI RMF mapping, ISO 42001 controls and client-matter risk scoring.

Typical tasks

  1. 01Assess the firm's compliance posture against the SRA Code
  2. 02Produce a risk register for a practice group
  3. 03Prepare a monthly COLP inspection bundle

Best for

  • Compliance officers and risk managers.
  • AI governance assessments and pre-audit preparation.
  • Board and SRA reporting.

How it works

From task to memo, in 4 steps.

Every step is recorded under How this was made on the finished run, with a pass, a needs a look, or a failure against each check. Nothing here is a description of intent. It is what the software does.

  1. 01

    Define the scope

    Define the assessment scope: which frameworks (SRA, EU AI Act, NIST, ISO), which systems, and which time period.

  2. 02

    Provide context

    Provide context: existing policies, risk registers and prior audit reports.

  3. 03

    Assess and score

    The agent maps evidence against each framework's rules and articles, and scores gaps by risk.

  4. 04

    Review the report

    Review the structured report: gap analysis, risk ratings and remediation recommendations, gated by Privilege Review before circulation.

Governed by

2 protocols.

Protocols run before and during the work: they plan, confirm the jurisdiction, screen personal data, check privilege. Gates run after, on the output, and they are code rather than a model's opinion. A failed gate is shown, never hidden.

Protocols

  1. 01Planning ProtocolMaps out the plan before any work starts: which sources answer which part of the task, in what order.
  2. 02Privilege ReviewAssesses the output for privileged or confidential material and flags disclosure risk before it is circulated.

Skills

  • SRA Compliance Rules
  • EU AI Act Compliance
  • NIST AI RMF Mapping
  • ISO 42001 Controls
  • COLP / COFA Duties
  • Client Matter Risk Scoring
  • AI Use-Case Registry & AIA Method
  • Vendor AI Terms Review

What comes back

A document with its working attached.

A risk register or assessment report, plus the printable inspection bundle carrying a content digest.
  1. 01Summary
  2. 02Gap analysis
  3. 03Risk register
  4. 04Remediation roadmap

Sources it may cite

Connectors in the catalogue

Catalogue tiles, not live integrations today. Documents are uploaded to the matter.

  • Atlassian
  • Microsoft 365
  • OpenLaw

Try it

Three tasks to start with.

These are the prompts the agent suggests inside the product. Paste your own document under any of them.

  • Assess our SRA compliance posture

    Assess our current AI governance posture against SRA Rules 2.1, 2.2, 2.5, 4.3 and Principle 7. Produce a gap analysis with risk ratings and a remediation roadmap:

  • Run an EU AI Act readiness check

    Assess our EU AI Act readiness under Articles 6, 13, 14 and 99: high-risk classification, transparency obligations and human oversight mechanisms. Flag anything not yet in place:

  • Build a risk register

    Build a risk register for our AI use cases, with likelihood, impact, existing controls and a risk owner for each entry:

What it does not do yet

  • Automatic evidence-gathering across live systems is not yet supported: the assessment works from the policies, registers and prior reports you provide.