Human oversight
People retain decision rights, escalation paths and the ability to challenge, correct or stop AI-supported outcomes.
HUMAN-CENTRED · SECURITY-INFORMED · EVIDENCE-BASED
SundAI uses a practical lifecycle that connects organisational governance, security engineering, human impact and adoption. The goal is not paperwork for its own sake, but AI that remains useful, understandable and under meaningful control.
CORE PRINCIPLES
People retain decision rights, escalation paths and the ability to challenge, correct or stop AI-supported outcomes.
Assess who may be excluded, disadvantaged or unable to understand and contest a process.
Build data minimisation, access control, supplier review, monitoring and safe fallback into the workflow.
Owners, users and affected people should understand purpose, limitations and where responsibility sits.
Prioritise use cases by value, feasibility, human impact and risk—not novelty alone.
Review controls, evidence, incidents, suppliers and model behaviour as the system and context change.
FRAMEWORK MAPPING
They can complement one another, but they are not interchangeable and do not remove the need for system-specific legal and risk analysis.
Roles, prohibited practices, risk classification, literacy, transparency, obligations and evidence relevant to the organisation.
Management-system structure: policy, objectives, roles, risk processes, controls, measurement and continual improvement.
Information-security governance around access, assets, suppliers, incidents, secure operations and assurance.
A practical lens for governing, mapping, measuring and managing AI risk across the lifecycle.
When applicable, connect AI use to wider cybersecurity, third-party, resilience, incident and ICT-risk obligations.
OPERATING LIFECYCLE
Find formal, embedded and informal AI use.
Identify role, purpose, people affected and required review depth.
Evaluate security, legal, operational and human-impact risk.
Approve, restrict, redesign, pilot, reject or retire with named accountability.
Record testing, supplier answers, controls, approvals and rationale.
Review changes, incidents, performance, renewals and residual risk.
ACCURATE CLAIMS
SundAI does not claim organisational ISO certification unless a current certificate explicitly covers the organisation and scope. A framework mapping supports implementation; it is not legal advice, a certification audit or automatic proof of compliance.