Premium and Business plans · v1.0.0
Audit & Risk
Board-ready AI-governance posture, impact assessments and audit
- Protocols
- 2
- Skills
- 8
- Public sources
- 4
- Workflows
- 1



The Audit & compliance register: every piece of AI work the firm produced, who authorised it and whether the checks passed, with period, matter and person filters, totals, and an Export button.
What it does
Assesses the firm's own compliance posture and produces risk registers and inspection bundles.
Typical tasks
- 01Assess the firm's compliance posture against the SRA Code
- 02Produce a risk register for a practice group
- 03Prepare a monthly COLP inspection bundle
Best for
- Compliance officers and risk managers.
- AI governance assessments and pre-audit preparation.
- Board and SRA reporting.
How it works
From task to memo, in 4 steps.
Every step is recorded under How this was made on the finished run, with a pass, a needs a look, or a failure against each check. Nothing here is a description of intent. It is what the software does.
01
Define the scope
Define the assessment scope: which frameworks (SRA, EU AI Act, NIST, ISO), which systems, and which time period.
02
Provide context
Provide context: existing policies, risk registers and prior audit reports.
03
Assess and score
The agent maps evidence against each framework's rules and articles, and scores gaps by risk.
04
Review the report
Review the structured report: gap analysis, risk ratings and remediation recommendations, gated by Privilege Review before circulation.
Governed by
2 protocols.
Protocols run before and during the work: they plan, confirm the jurisdiction, screen personal data, check privilege. Gates run after, on the output, and they are code rather than a model's opinion. A failed gate is shown, never hidden.
Protocols
- 01Planning ProtocolMaps out the plan before any work starts: which sources answer which part of the task, in what order.
- 02Privilege ReviewAssesses the output for privileged or confidential material and flags disclosure risk before it is circulated.
Skills
- SRA Compliance Rules
- EU AI Act Compliance
- NIST AI RMF Mapping
- ISO 42001 Controls
- COLP / COFA Duties
- Client Matter Risk Scoring
- AI Use-Case Registry & AIA Method
- Vendor AI Terms Review
What comes back
A document with its working attached.
- 01Summary
- 02Gap analysis
- 03Risk register
- 04Remediation roadmap
Sources it may cite
Connectors in the catalogue
Catalogue tiles, not live integrations today. Documents are uploaded to the matter.
- Atlassian
- Microsoft 365
- OpenLaw
Try it
Three tasks to start with.
These are the prompts the agent suggests inside the product. Paste your own document under any of them.
Assess our SRA compliance posture
Assess our current AI governance posture against SRA Rules 2.1, 2.2, 2.5, 4.3 and Principle 7. Produce a gap analysis with risk ratings and a remediation roadmap:
Run an EU AI Act readiness check
Assess our EU AI Act readiness under Articles 6, 13, 14 and 99: high-risk classification, transparency obligations and human oversight mechanisms. Flag anything not yet in place:
Build a risk register
Build a risk register for our AI use cases, with likelihood, impact, existing controls and a risk owner for each entry:
What it does not do yet
- Automatic evidence-gathering across live systems is not yet supported: the assessment works from the policies, registers and prior reports you provide.
Workflows