AI principles — Seven Sutras + ISO 42001 + NIST + EU AI Act literacy
Primary statement
Foundational AI principles: MeitY AIGG2025.3 Seven Sutras (Trust, Inclusion, Transparency, Accountability, Safety, Innovation, Sustainable Growth) + ISO 42001 A.2.2 AI policy + A.2.3 alignment with other policies + NIST AI RMF GOVERN-1.1 legal/regulatory + EU AI Act Article 4 AI literacy. Principles-led approach grounds operational AI controls.
Audit-fatigue payoff
A unified AI principles framework — Seven Sutras + ISO 42001 policy + NIST regulatory + EU AI Act literacy — satisfies foundational AI requirements across all 5 contributing frameworks. The Seven Sutras provide the India-specific lens.
Strictness matrix
Scope
Scope: Seven Sutras (Trust, Inclusion, Transparency, Accountability, Safety, Innovation, Sustainable Growth) cover all AI systems. Plus ISO 42001 AI policy + NIST regulatory.
Ceiling source: meity_ai:AIGG2025.3
Rationale: MeitY AIGG2025.3 broadest principles scope.
Threshold
Threshold: AI literacy among staff DEALING with AI systems. Provider and deployer obligation.
Ceiling source: eu_ai_act:Art.4
Rationale: EU AI Act Art 4 literacy threshold is uniquely strict.
Method
Method: written AI policy approved at appropriate management level + alignment with security/privacy/risk/HR/procurement policies (A.2.3) + Seven Sutras integration + EU AI Act Art 4 literacy programme + NIST GOVERN-1.1 legal/regulatory tracking.
Ceiling source: iso42001:A.2.2
Rationale: ISO 42001 A.2.2 + A.2.3 + MeitY + EU AI Act Art 4 combined are the most prescriptive.
Frequency
AI policy review: planned cycle + on material change. AI literacy: induction + annual refresher. Regulatory tracking: continuous.
Ceiling source: iso42001:A.2.2
Rationale: Annual policy review + induction/refresher literacy is the cadence.
Evidence
Evidence: AI policy + alignment matrix + Seven Sutras integration + AI literacy training records + regulatory tracking.
Ceiling source: iso42001:A.2.2
Rationale: ISO 42001 A.2.2 evidence is the audit-defensible specification.
Auditor test pattern
Step 1: Inspect AI policy. Step 2: Verify alignment with other policies (A.2.3). Step 3: Verify Seven Sutras reflected in policy or methodology. Step 4: Inspect AI literacy training records.
Common findings
Common findings: (1) AI policy generic, not principle-led; (2) Seven Sutras referenced but not operationalised; (3) AI literacy absent for staff dealing with AI; (4) Alignment matrix theoretical.