SRA AI guidance: a supervision checklist for law firms
Turn SRA AI guidance into a practical review process: named responsibility, original sources, exceptions, staff instructions and recorded decisions.

An AI-assisted task needs a clear owner, a defined review and a way to stop work that cannot be checked. A policy saying that staff must verify everything does not explain who checks a particular output or what happens when that person is unavailable.
For a first implementation, choose one task and write its review procedure alongside the workflow. A source-linked chronology is a useful example: the reviewer needs the original pages, proposed entries, unresolved conflicts and corrections together.
Start with the actual supervisory obligation
The Solicitors Regulation Authority (SRA)'s effective-supervision guidance, updated on 12 June 2026, calls for appropriate human review, scrutiny and professional judgement for AI-assisted work, with ultimate responsibility retained by an authorised individual. Supervision arrangements should reflect the work's risks and the competence and capacity of the people involved. The guidance explains existing obligations rather than introducing a new set of standards. SRA: effective supervision.
The SRA's AI warning also addresses false information and risks to client confidentiality. A paid tool is not, by itself, evidence of suitable safeguards. SRA: misuse of AI.
The following procedure is an Ampliflow implementation proposal. It is not a regulator-approved checklist, a compliance certificate or a substitute for the firm's professional judgement.
Define what the reviewer must receive
- 01Source and version
- 02Proposed output
- 03Exceptions visible
- 04Named reviewer
- 05Recorded correction
- 06Approved next action
Give each run a matter identifier, a defined task and a record of the source versions used. Present the output as a proposal until the relevant review is complete.
| Review input | Why it matters | Proposed failure response |
|---|---|---|
| Original document and page | Allows a fact to be checked in context | Hold an entry whose source cannot be opened |
| Conflicting or uncertain information | Prevents apparent certainty hiding a dispute | Keep separate accounts and flag the question |
| Reviewer and permitted action | Makes responsibility explicit | Hold release if no authorised reviewer is available |
| Corrections and final version | Shows what was actually accepted | Preserve the reviewed version separately from the draft |
Keep the review manageable. A document index and a draft letter may need different procedures. The firm should decide which work requires individual approval and where a different form of supervision is appropriate; the software should enforce the agreed arrangement.
Put the AI policy into a task record
A law firm AI policy needs to tell staff which task is permitted, which tool and account to use, what information may enter it, who checks the output and where to report a problem. A broad instruction to “use AI responsibly” leaves those decisions unresolved.
For one approved task, keep a short record with these fields: task owner; permitted inputs; required source references; reviewer and cover; action allowed after review; exception route; review date. Link to the firm's actual policy rather than copying a second version into several tools.
This is a suggested operational record. It does not replace a firm's full policy or professional assessment. Use the supplier and confidentiality checks for data handling and the evaluation checklist to test the controls before live work.
Test the absence of a reviewer
In a synthetic exercise, assign the task to an unavailable reviewer. Check that the work remains pending, reaches the agreed substitute and retains its original source references. An automatic reassignment is only useful if the recipient is authorised and can accept the work.
Next, remove access to one source. The system should show that limitation rather than presenting an old answer as freshly verified. Include an unreadable page and a disputed date, using the synthetic disclosure example.
These exercises evaluate a proposed control. They do not establish that a firm meets every applicable obligation.
Record decisions without collecting everything
Agree which information is necessary for the review record: source version, output version, reviewer, decision, corrections and timing are candidates. Determine access and retention with the firm. Copying entire confidential documents into unrestricted application logs creates a separate problem.
Make rejection a normal outcome. A useful review system records why an output was rejected and permits staff to complete the task manually. Staff should not have to approve a poor draft to clear a queue.
Measure review quality and workload
Track time waiting for review, correction effort, unresolved exceptions and the proportion of proposed outputs accepted. Examine serious errors individually; a favourable average can conceal one material permission or source failure.
Discuss those results with the people doing the work. If review creates a new bottleneck, narrow the task or revise the process before extending it. The first-workflow guide helps choose that scope, while the legal hub connects supervision with document preparation and enquiry handling.