
The lever arch file worked. That was the problem.
For most of those 20 years, compliance got done. Filings went in on time. Registers were accurate. But it got done because of people, not because of systems. At Lloyds there were five of us processing over 300 director changes a year across the group. The knowledge that made that possible lived in our heads, and in a file of process notes that only made sense if you already knew the answer.
Here is the part I find hard to admit. In two decades as a practitioner, I never once got the information I needed out of an entity management system without asking someone on my team for help. Not once.
Two things eventually pushed me. The first was a risk realisation. If one particular person went on extended leave, we did not have a process, we had a gap. That is not a resourcing issue, it is a control failure waiting to be discovered by someone else.
The second was more prosaic. A board member asked me how many entities we had in a particular jurisdiction and who sat on each board. That should be a ten second answer. It took me two days.
What tipped me from complaining to building was noticing I had spent years waiting for someone else to solve it. The vendors were building document repositories designed for lawyers doing deals. Nobody was building for the person who actually signs and files. If you have done the job and you can see the gap, at some point waiting becomes a choice. So I stopped waiting.
We spent real money on ISO 27001 and ISO 9001 before we had earned a single pound of revenue. From the outside it looked like vanity certification. It was not.
I knew exactly who we were selling to: global enterprises, banks, organisations with hundreds of entities and a security function with teeth. I had also sat on the buying side of that process for two decades. I had rejected vendors for precisely these reasons. So the question was never whether we would be asked, it was whether we would be ready when we were. But the advice I would actually give other founders is not “get certified early”. That is the output, not the decision.
The decision was this: work out who your customer is before you build anything, then build the company to their standard rather than to your own convenience. Everything else follows from that. Our security posture, our quality processes, our documentation, even how we run implementation, all of it was shaped by what an enterprise buyer needs rather than what was fastest for us in year one.
The second order benefit surprised me. Certification forced us to write down how we work while we were still small enough for that to be achievable. We are now 50 people, remote first across the UK and US. That early documentation is a large part of why we can bring someone new in and have them productive quickly. If we had left it until we were 40 people it would have cost ten times as much and been half as good.
I will be honest that it slowed us down, and there were weeks it felt like process theatre. It was not. Trust is a design decision, not a sales one, and you cannot sell trust you have not already built.
Walk any legal tech exhibition floor this year and you will be promised autonomous agents roughly every four metres. Ask a simple question, though: what does your agent actually do on a Tuesday afternoon, in my team, for my entities? The answers get vague quickly.
Three things make us different.
First, we started from the job rather than the model. KAIA automates work that already exists and already eats a team’s week: ingesting documents, extracting entity data, monitoring compliance obligations, moving a filing through to completion. We did not need to invent a problem, because I spent 20 years living inside this one.
Second, architecture. Most legacy platforms are document stores with search bolted on top. We built the entity as the central data object, with everything else hanging off it. That sounds like an internal engineering detail. It is not. It is the difference between software that can take an action and software that can only summarise a document you have already found.
Third, and most importantly, AI operated, human controlled. The Company Secretary signs the filing. Their name goes on the register. So every action KAIA takes is auditable, reversible, and a human approves anything with consequences. “The model decided” is not a defence to a regulator, and it is not a defence to a board. I would rather tell a prospect clearly what KAIA does not do than win a deal on a demo they cannot reproduce in their own environment.
If you take one thing from this, take a question you can use on any vendor, including us. Ask them to walk you through the full audit trail for a single decision their AI made. Not the demo. The audit trail. That conversation ends faster than it should.
The future of law is at LegalTechTalk – events for legal transformation
The legal industry is undergoing a major transformation, driven by technological advances, changing demographics, and new business models. Lawyers who are able to adapt to these changes will be well-positioned for success in the future.
Upcoming Events:
EUROPE · 16 – 17 June 2027 →
USA · 13 – 15 December 2027 →
Get news and insights delivered straight to your inbox!
Join 5,000+ legal leaders shaping the future of law for two days of insight, innovation and unmissable networking — now with your biggest saving!