Agent skill

Aims Audit

by alirezarezvani in alirezarezvani/claude-skills

/cs:aims-audit <scope — ISO/IEC 42001 AIMS internal-audit 6-question forcing interrogation.

MITAuto-check passedLegal & Compliance

Install Aims Audit

skills CLI
$ npx skills add alirezarezvani/claude-skills --skill aims-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-skills aims-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/compliance-os/skills/aims-audit .claude/skills/aims-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aims-audit
GitHub stars
28k
Token cost
~1.3k tokens
SKILL.md length
455 words
Files
1
Skills in repo
342
Repo updated
First seen
Licence
MIT

At a glance

/cs:aims-audit <scope — ISO/IEC 42001 AIMS internal-audit 6-question forcing interrogation.

  • Works in 6 steps: Does the AIMS scope statement name every… → Does the AI policy commit to lawful use… → What's the risk register coverage, and… → …
  • Tasks that involve Audit readiness
  • SKILL.md covers When to Run, The Six AIMS Questions, Workflow and Output Format, plus 2 more sections
  • Calls python

What it does

Aims Audit is an agent skill from alirezarezvani/claude-skills. /cs:aims-audit <scope — ISO/IEC 42001 AIMS internal-audit 6-question forcing interrogation. Use before certification stage 1, before annual internal audit cycles, or when onboarding a new AI system into an existing AIMS.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Audit readiness and AI governance. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.

When your agent uses it

  • Tasks that involve Audit readiness
  • Tasks that involve AI governance

Example prompts

  • “/aims-audit”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Does the AIMS scope statement name every AI system?
  2. Does the AI policy commit to lawful use AND beneficial purpose AND human oversight AND continual improvement?
  3. What's the risk register coverage, and which Annex A controls treat each risk?
  4. Has the AI risk assessment been re-run since the last material model change?
  5. What's the Clause 9.2 internal audit plan, and is auditor independence respected?
  6. Has the AIMS been integrated with existing ISMS / QMS, or built in parallel?

What it can do on your machine

Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Aims Audit loads about 1.3k tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 455 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alirezarezvani/claude-skills at commit 19392f7, republished under its MIT licence (© alirezarezvani). 455 words, ~1,308 tokens.

Download SKILL.mdSave it as .claude/skills/aims-audit/SKILL.md (or your agent's skills folder).
name
aims-audit
description
/cs:aims-audit <scope> — ISO/IEC 42001 AIMS internal-audit 6-question forcing interrogation. Use before certification stage 1, before annual internal audit cycles, or when onboarding a new AI system into an existing AIMS.

/cs:aims-audit — AIMS ISO 42001 Forcing Questions

Command: /cs:aims-audit <scope>

The ISO 42001 AIMS specialist pressure-tests any AI Management System work. Six questions before any certification commitment, internal audit cycle, or new-system onboarding.

When to Run

  • Before stage 1 ISO 42001 certification audit
  • Before annual internal audit cycle (Clause 9.2)
  • When onboarding a new AI system into existing AIMS scope
  • When AI risk register hasn't been refreshed in > 6 months
  • After material model change (re-evaluate risks per Clause 6.1.2)
  • When audit findings hint at AIMS / ISMS / QMS duplication

The Six AIMS Questions

1. Does the AIMS scope statement name every AI system?

Scope omission = certification finding.

  • Including: embedded models, third-party AI services, "experimental" production systems
  • Run aims_gap_analyzer.py to verify Clause 4.3 evidence
  • "AI features added by SaaS vendors we use" = in scope if they affect the company's services
2. Does the AI policy commit to lawful use AND beneficial purpose AND human oversight AND continual improvement?

Missing any of the four = critical nonconformity at stage 1.

  • AI policy is NOT info-sec policy — it has separate substantive content
  • Reference ISO 42001 Annex A.2.2 + Clause 5.2
  • Marketing-copy "AI ethics" doesn't pass
3. What's the risk register coverage, and which Annex A controls treat each risk?

Risk identification without control mapping = Clause 6.1.3 fails.

  • Run ai_risk_register_builder.py per ISO 23894 methodology
  • Every high/critical risk must link to ≥ 1 Annex A control
  • "Residual verdict: additional_treatment_required" must be closed before stage 1
4. Has the AI risk assessment been re-run since the last material model change?

Concept drift is not a one-time event.

  • Article 9 EU AI Act + ISO 42001 Clause 6.1.2 both require iterative risk assessment
  • Material change = retraining on new data, fine-tuning, architecture change, deployment context change
  • If "we did it 18 months ago and haven't touched it," the AIMS is broken
Show full SKILL.md (158 more words)Show less
5. What's the Clause 9.2 internal audit plan, and is auditor independence respected?

Without 9.2 plan, the AIMS is incomplete.

  • Run aims_audit_scheduler.py with scope + auditors + prior findings
  • Audit every clause + applicable Annex A control over rolling 3-year cycle
  • Same auditor cannot audit own work
  • Cross-check with cs-quality-regulatory if integrated with 13485 audit programme
6. Has the AIMS been integrated with existing ISMS / QMS, or built in parallel?

Parallel systems = 5x ongoing maintenance cost.

  • 60% of Clauses 4-10 evidence reuses ISO 27001 / 13485 with AI scope appended
  • CAPA loop should be ONE loop with AI-tagged nonconformities, not separate
  • Reference cross_framework_mapping_ai.md for the reuse map
  • Cross-check with cs-ciso-advisor on ISO 27001 alignment

Workflow

bash
# 1. AIMS gap analysis
python ra-qm-team/skills/iso42001-specialist/scripts/aims_gap_analyzer.py evidence.json

# 2. AI risk register
python ra-qm-team/skills/iso42001-specialist/scripts/ai_risk_register_builder.py risks.json

# 3. Internal audit plan
python ra-qm-team/skills/iso42001-specialist/scripts/aims_audit_scheduler.py audit_scope.json

# 4. Cross-framework reuse map (via compliance-os)
python ../../skills/compliance-os/scripts/cross_framework_mapper.py program.json

Output Format

markdown
# AIMS Audit: <scope>
**Date:** YYYY-MM-DD

## The Decision Being Made
[gap-closure | risk-treatment | audit-scope | new-system-onboarding]

## Gap Analysis (Clauses 4-10)
- Weighted coverage: X%
- Critical gaps: N
- Major gaps: M
- Certification readiness: ready | stage_2_candidate | not_ready

## AI Risk Register
- Total risks: N
- By severity: critical=X, high=Y, medium=Z, low=W
- Requires additional treatment: K
- Top risk requiring action: <description>

## Clause 9.2 Audit Plan
- 12-month coverage: clauses=X, controls=Y
- Auditor independence: clean | issues
- Prior-year follow-up: scheduled in Q1

## Cross-Framework Reuse
- ISO 27001 evidence reused: % of AIMS Clauses 4-10
- 13485 evidence reused: % (if applicable)
- Net-new for AIMS: % (mostly Annex A)

## Verdict
🟢 STAGE-1-READY | 🟡 CLOSE-CRITICALS-FIRST | 🔴 NOT-READY

## Top 3 Actions
[3 concrete next steps with owner + date]

Routing

  • /cs:compliance-readiness — for multi-framework view
  • /cs:ai-act-readiness — if EU AI Act also applies
  • /cs:caio-review — for executive AI strategy decisions
  • /cs:ciso-review — for ISO 27001 cross-framework alignment
  • /cs:decide — to log the verdict
  • /cs:freeze 30 — on certification commitments

Version: 1.0.0

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in compliance-os/skills/aims-audit of alirezarezvani/claude-skills.

Open the folder on GitHubat commit 19392f7

Compare with similar skills

Aims Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Aims Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Aims Audit this skillalirezarezvani/claude-skills28k—~1.3kAutomated safety check: PassMIT
Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~3.7kAutomated safety check: PassMIT
Eu AI Act Readinessseb1n/awesome-ai-agent-skills206—~3.3kAutomated safety check: PassMIT
Iso42001 AI Managementborghei/Claude-Skills886—~7.4kAutomated safety check: PassMIT
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills48k1 repos~4.6kAutomated safety check: NotesMIT

Similar skills

  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    943 GitHub starsUsed in 1 repo~3.7k tokens
    Legal & ComplianceAuto-check passed
  • Eu AI Act Readiness

    seb1n/awesome-ai-agent-skills

    Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…

    206 GitHub stars~3.3k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • Iso42001 AI Management

    borghei/Claude-Skills

    ISO 42001 AI Management System (AIMS) compliance. An agent skill from borghei/Claude-Skills.

    886 GitHub stars~7.4k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes
  • Fleet Triage

    google-labs-code/jules-sdk

    Official

    Cognitive triage of fleet audit findings. An agent skill from google-labs-code/jules-sdk.

    137 GitHub stars~1.2k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed

More from alirezarezvani/claude-skills

All 342 skills in this repo
  • Agile Product Owner

    alirezarezvani/claude-skills

    Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.

    28k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Product Strategist

    alirezarezvani/claude-skills

    OKR cascade toolkit for product leaders: generates aligned company-to-team OKRs from five strategy types and scores how well they line up.

    28k GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • App Store Optimization

    alirezarezvani/claude-skills

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.

    28k GitHub starsUsed in 1 repo~4.2k tokens
    Auto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Campaign Analytics

    alirezarezvani/claude-skills

    Calculates attribution, funnel and ROI figures for marketing campaigns with three Python scripts that need only the standard library.

    28k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Code to PRD

    alirezarezvani/claude-skills

    Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.

    28k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed

Questions about Aims Audit

What does Aims Audit do?

/cs:aims-audit <scope — ISO/IEC 42001 AIMS internal-audit 6-question forcing interrogation. Aims Audit is an agent skill from alirezarezvani/claude-skills. /cs:aims-audit <scope — ISO/IEC 42001 AIMS internal-audit 6-question forcing interrogation.

When should I use Aims Audit?

Aims Audit fits situations like: tasks that involve Audit readiness; tasks that involve AI governance.

How do I install Aims Audit in Claude Code?

Run `npx skills add alirezarezvani/claude-skills --skill aims-audit -a claude-code`. Or copy the skill folder (compliance-os/skills/aims-audit in alirezarezvani/claude-skills) into .claude/skills/aims-audit in your project. Claude Code loads it when a task matches its description.

How do I install Aims Audit in Codex?

Run `npx skills add alirezarezvani/claude-skills --skill aims-audit -a codex`. Or copy the skill folder (compliance-os/skills/aims-audit in alirezarezvani/claude-skills) into .agents/skills/aims-audit in your project. Codex loads it when a task matches its description.

Can I use Aims Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill aims-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aims-audit, .gemini/skills/aims-audit, .github/skills/aims-audit and .opencode/skills/aims-audit in your project.

What does Aims Audit need to run?

Going by SKILL.md and its folder, Aims Audit needs the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Aims Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Aims Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Aims Audit use?

Aims Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Aims Audit use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Aims Audit?

Skills that share tags, products or a category with Aims Audit: Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars), Eu AI Act Readiness (seb1n/awesome-ai-agent-skills, 206 stars), Iso42001 AI Management (borghei/Claude-Skills, 886 stars) and HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Aims Audit?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,891 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.

Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.