HUMAN-CENTRED · SECURITY-INFORMED · EVIDENCE-BASED

Turn principles and regulation into ownership, controls and evidence.

SundAI uses a practical lifecycle that connects organisational governance, security engineering, human impact and adoption. The goal is not paperwork for its own sake, but AI that remains useful, understandable and under meaningful control.

CORE PRINCIPLES

Six checks that remain relevant throughout the AI lifecycle.

01

Human oversight

People retain decision rights, escalation paths and the ability to challenge, correct or stop AI-supported outcomes.

02

Fairness & accessibility

Assess who may be excluded, disadvantaged or unable to understand and contest a process.

03

Security & privacy

Build data minimisation, access control, supplier review, monitoring and safe fallback into the workflow.

04

Transparency

Owners, users and affected people should understand purpose, limitations and where responsibility sits.

05

Measured value

Prioritise use cases by value, feasibility, human impact and risk—not novelty alone.

06

Continuous governance

Review controls, evidence, incidents, suppliers and model behaviour as the system and context change.

FRAMEWORK MAPPING

Different frameworks answer different governance questions.

They can complement one another, but they are not interchangeable and do not remove the need for system-specific legal and risk analysis.

EU AI Act

Roles, prohibited practices, risk classification, literacy, transparency, obligations and evidence relevant to the organisation.

ISO/IEC 42001

Management-system structure: policy, objectives, roles, risk processes, controls, measurement and continual improvement.

ISO/IEC 27001

Information-security governance around access, assets, suppliers, incidents, secure operations and assurance.

NIST AI RMF

A practical lens for governing, mapping, measuring and managing AI risk across the lifecycle.

NIS2 & DORA

When applicable, connect AI use to wider cybersecurity, third-party, resilience, incident and ICT-risk obligations.

OPERATING LIFECYCLE

A repeatable path from discovery to ongoing review.

Discover

Find formal, embedded and informal AI use.

Classify

Identify role, purpose, people affected and required review depth.

Assess

Evaluate security, legal, operational and human-impact risk.

Decide

Approve, restrict, redesign, pilot, reject or retire with named accountability.

Evidence

Record testing, supplier answers, controls, approvals and rationale.

Monitor

Review changes, incidents, performance, renewals and residual risk.

ACCURATE CLAIMS

Standards-informed without overstating certification or compliance.

SundAI does not claim organisational ISO certification unless a current certificate explicitly covers the organisation and scope. A framework mapping supports implementation; it is not legal advice, a certification audit or automatic proof of compliance.

Proportionate scopeTraceable decisionsHuman oversightContinuous review