For organisations moving from scattered AI experiments to a repeatable operating model — without creating unnecessary bureaucracy around every low-impact use case.
Typical governance workstream
Designed around the EU context
The governance model is informed by the EU AI Act, ISO/IEC 42001, ISO/IEC 27001 and NIST AI RMF. These sources are used as complementary lenses rather than treated as interchangeable. Legal applicability is assessed separately from internal risk management.
A practical starting package
- Current-state AI inventory and gap scan.
- Role and decision-rights map.
- Risk-tier model with escalation criteria.
- Minimum acceptable-use policy.
- AI supplier review baseline.
- Human-oversight and incident route.
- 90-day implementation roadmap with owners.
Good fit
This approach is particularly useful for European SMEs, knowledge-intensive teams, education and public/social-service organisations that need structure but do not want a governance programme designed only for large multinationals.
Related resources
Reference framework sources
Build the operating model around your actual AI use
Describe the use cases, organisational context and current governance. SundAI can help identify the smallest useful control model and the highest-priority gaps.
Contact SundAI →