Agent skill

Aims Audit

by borghei in borghei/Claude-Skills

ISO 42001 AI Management System (AIMS) audit-prep playbook. An agent skill from borghei/Claude-Skills.

MITAuto-check passedLegal & Compliance

Install Aims Audit

skills CLI
$ npx skills add borghei/Claude-Skills --skill aims-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills aims-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ra-qm-team/audit-prep/aims-audit .claude/skills/aims-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aims-audit
GitHub stars
881
Token cost
~2k tokens
SKILL.md length
765 words
Files
5 (incl. scripts, references)
Skills in repo
349
Repo updated
First seen
Licence
MIT

At a glance

ISO 42001 AI Management System (AIMS) audit-prep playbook. An agent skill from borghei/Claude-Skills.

  • Works in 2 steps: (documentation review) → (operational assessment)
  • An ISO 42001 certification audit is scheduled (Stage 1
  • SKILL.md covers When to use this skill, ISO 42001 audit structure, AIMS audit-prep sprint and ISO 42001 clauses + Annex A…, plus 7 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Aims Audit is an agent skill from borghei/Claude-Skills. ISO 42001 AI Management System (AIMS) audit-prep playbook. Use when an ISO 42001 certification audit is scheduled (Stage 1 or Stage 2), when a surveillance or internal AIMS audit is due, or when preparing an AI Impact Assessment (AIIA).

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/aims-internal-audit-playbook.md`, `references/iso42001-aims-readiness-checklist.md` and `scripts/ai_impact_assessment_checker.py`).

It sits in Legal & Compliance, covering Audit readiness. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • An ISO 42001 certification audit is scheduled (Stage 1
  • Internal AIMS audit is due
  • Preparing an AI Impact Assessment (AIIA)

Example prompts

  • “/aims-audit”

Requirements

  • Python 3

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. (documentation review)
  2. (operational assessment)

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Aims Audit loads about 2k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 62 tokens; SKILL.md has 765 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 765 words, ~1,978 tokens.

Download SKILL.mdSave it as .claude/skills/aims-audit/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
aims-audit
description
ISO 42001 AI Management System (AIMS) audit-prep playbook. Use when an ISO 42001 certification audit is scheduled (Stage 1 or Stage 2), when a surveillance or internal AIMS audit is due, or when preparing an AI Impact Assessment (AIIA).
license
MIT + Commons Clause
metadata.version
1.0.0
metadata.author
borghei
metadata.category
compliance
metadata.domain
ra-qm-team
metadata.updated
2026-05-27
metadata.tags
iso42001, aims, ai-management-system, audit-prep, certification, ai-governance, ai-impact-assessment

AIMS Audit Prep (ISO 42001)

Operational playbook for ISO 42001:2023 AI Management System (AIMS) audit preparation. Whether targeting initial certification, surveillance audit, or annual internal audit.

When to use this skill vs. iso42001-ai-management:

  • This skill: audit imminent; need readiness sprint
  • iso42001-ai-management: building AIMS from scratch; multi-quarter program

When to use this skill

SituationSkill applies
ISO 42001 Stage 1 audit scheduledYes — documentation review prep
Stage 2 (onsite/operational) auditYes — operational evidence sprint
Annual surveillance auditYes — surveillance prep
Internal AIMS auditYes — internal audit playbook
AI Impact Assessment for new systemYes — scripts/ai_impact_assessment_checker.py
Building AIMS from scratchUse ra-qm-team/iso42001-ai-management

ISO 42001 audit structure

Stage 1 (documentation review)
  • Auditor reviews AIMS documentation (typically 1-3 days)
  • Confirms scope, applicability, key documents present
  • Identifies gaps before Stage 2
  • Typically 2-3 weeks before Stage 2
Stage 2 (operational assessment)
  • Auditor onsite (or remote) verifies AIMS operating effectively
  • 3-10 days depending on scope + system count
  • Walkthroughs, interviews, evidence sampling
  • Conclusion: certification recommended (subject to non-conformity closure) or not
Surveillance audits
  • Annual; reduced scope vs initial
  • Typically 1-3 days
  • Focus on high-risk areas + changes since prior audit
Re-certification (year 3)
  • Full audit; similar to initial
  • Typically every 3 years

AIMS audit-prep sprint

4-week sprint (mature AIMS, surveillance audit)
Week 1: Internal audit + gap analysis
Week 2: Remediation + AI inventory refresh
Week 3: Documentation review + walkthrough rehearsal
Week 4: Auditor onsite
8-week sprint (Stage 1 + Stage 2 initial certification)
Weeks 1-3: AIMS documentation completion (Annex A controls coverage)
Weeks 4-5: Stage 1 audit + gap closure
Weeks 6-7: Stage 2 operational evidence prep + mock walkthroughs
Week 8: Stage 2 audit

ISO 42001 clauses + Annex A controls

Clauses (4-10): management system
ClauseTopic
4Context of the organization
5Leadership
6Planning (including AI risk + AI objectives)
7Support (resources, competence, awareness, communication, documentation)
8Operation (AI lifecycle, supplier relationships)
9Performance evaluation (monitoring, internal audit, management review)
10Improvement (nonconformity, continual improvement)
Annex A controls (10 areas)
Annex A areaTopics
A.2Policies related to AI
A.3Internal organization
A.4Resources for AI systems
A.5Assessing impacts of AI systems
A.6AI system lifecycle
A.7Data for AI systems
A.8Information for interested parties
A.9Use of AI systems
A.10Third-party relationships

Critical audit areas

AI Inventory + Impact Assessments
ItemEvidenceCommon gap
Complete AI system inventoryInventory documentShadow AI not captured
AI Impact Assessment (AIIA) per systemPer-system AIIASkipped for "low-risk" systems
AIIA reviewed periodicallyReview recordsOne-time only
Risk classification of systemsPer systemNot documented
AI Policy + Governance
ItemEvidenceCommon gap
AI policy approved + datedSigned policyNot signed / stale
AI ethics principlesDocumented principlesGeneric; not actionable
AI governance bodyCharter / minutesNot formalized
Roles + responsibilitiesRACINot defined
AI Lifecycle Management (Annex A.6)
ItemEvidenceCommon gap
AI development lifecycle definedProcess documentationNot formalized
Data quality controlsPer systemGeneric only
Model validation proceduresPer systemValidation skipped
AI system testingPer systemInadequate testing
Deployment controlsPer systemNo controls
Operational monitoringPer systemDrift not monitored
Decommissioning proceduresPer systemNot defined
Show full SKILL.md (311 more words)Show less
Data Governance (Annex A.7)
ItemEvidenceCommon gap
Data sources documentedPer systemVague
Data quality assessedQuality metricsNot measured
Data lineage trackedDocumentationUntracked
Sensitive data protectionControlsInsufficient
Third-party AI (Annex A.10)
ItemEvidenceCommon gap
Third-party AI inventoryListIncomplete
Vendor due diligence for AIPer vendorGeneric IT only
Contract terms for AI vendorsAI-specific clausesStandard MSA only

Clarify First

Before running the audit-prep, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Audit type and stage — Stage 1 documentation review, Stage 2 operational, surveillance, or internal (sets sprint length and whether the focus is documentation or operational evidence)
  • AIMS maturity — mature system vs building from gaps (picks the 4-week vs 8-week sprint)
  • AI systems in scope — which systems and how many (drives the AIIA count and Annex A coverage)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the readiness assessment.

Quick start

  1. Run readiness score: python3 scripts/aims_readiness_score.py --config aims-controls.yaml
  2. Check AIIA per system: python3 scripts/ai_impact_assessment_checker.py --aiia system-aiia.yaml
  3. Pick sprint length based on score
  4. Execute sprint per references/iso42001-aims-readiness-checklist.md

Common AIMS audit findings

  • AI inventory incomplete — shadow AI not captured
  • AIIA missing for systems that look "small" but have impact
  • AI lifecycle process not implemented (designed only)
  • Data governance generic — not AI-specific
  • Performance monitoring missing — drift not detected
  • AI policy stale — written before current AI deployment
  • Third-party AI vendors not assessed
  • Continual improvement not evidenced

Tooling

ScriptPurpose
scripts/aims_readiness_score.pyScore AIMS readiness per clause + Annex A area
scripts/ai_impact_assessment_checker.pyValidate AI Impact Assessment completeness

References


  • ra-qm-team/iso42001-ai-management — deep ISO 42001 AIMS program management
  • ra-qm-team/eu-ai-act-specialist — EU AI Act regulatory companion
  • ra-qm-team/audit-prep/ai-act-readiness — AI Act audit-prep variant
  • ra-qm-team/audit-prep/compliance-readiness — multi-framework readiness

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in ra-qm-team/audit-prep/aims-audit of borghei/Claude-Skills.

  • SKILL.md
  • references/aims-internal-audit-playbook.md
  • references/iso42001-aims-readiness-checklist.md
  • scripts/ai_impact_assessment_checker.py
  • scripts/aims_readiness_score.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Aims Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Aims Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Aims Audit this skillborghei/Claude-Skills881—~2kAutomated safety check: PassMIT
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills48k1 repos~4.6kAutomated safety check: NotesMIT
Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repos~3.7kAutomated safety check: PassMIT
Fleet Triagegoogle-labs-code/jules-sdk136—~1.2kAutomated safety check: PassApache-2.0
PCI DSS Compliancewshobson/agents40k11 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    942 GitHub starsUsed in 1 repo~3.7k tokens
    Legal & ComplianceAuto-check passed
  • Fleet Triage

    google-labs-code/jules-sdk

    Official

    Cognitive triage of fleet audit findings. An agent skill from google-labs-code/jules-sdk.

    136 GitHub stars~1.2k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • PCI DSS Compliance

    wshobson/agents

    Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption.

    40k GitHub starsUsed in 11 repos~1.9k tokens
    Legal & ComplianceAuto-check passed
  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    419 GitHub stars~2.6k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed

More from borghei/Claude-Skills

All 349 skills in this repo
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    881 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    881 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    881 GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    881 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    881 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Brainstorm Okrs

    borghei/Claude-Skills

    OKR brainstorming and validation using the Radical Focus framework — outcome objectives, measurable key results, counter-metrics.

    881 GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Questions about Aims Audit

What does Aims Audit do?

ISO 42001 AI Management System (AIMS) audit-prep playbook. An agent skill from borghei/Claude-Skills. Aims Audit is an agent skill from borghei/Claude-Skills. ISO 42001 AI Management System (AIMS) audit-prep playbook.

When should I use Aims Audit?

Aims Audit fits situations like: an ISO 42001 certification audit is scheduled (Stage 1; internal AIMS audit is due; preparing an AI Impact Assessment (AIIA).

How do I install Aims Audit in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill aims-audit -a claude-code`. Or copy the skill folder (ra-qm-team/audit-prep/aims-audit in borghei/Claude-Skills) into .claude/skills/aims-audit in your project. Claude Code loads it when a task matches its description.

How do I install Aims Audit in Codex?

Run `npx skills add borghei/Claude-Skills --skill aims-audit -a codex`. Or copy the skill folder (ra-qm-team/audit-prep/aims-audit in borghei/Claude-Skills) into .agents/skills/aims-audit in your project. Codex loads it when a task matches its description.

Can I use Aims Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill aims-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aims-audit, .gemini/skills/aims-audit, .github/skills/aims-audit and .opencode/skills/aims-audit in your project.

What does Aims Audit need to run?

Going by SKILL.md and its folder, Aims Audit needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Aims Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Aims Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Aims Audit use?

Aims Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Aims Audit use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.2k tokens, read only when the agent opens those files.

What are the alternatives to Aims Audit?

Skills that share tags, products or a category with Aims Audit: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars), Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 942 stars) and Fleet Triage (google-labs-code/jules-sdk, 136 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Aims Audit?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 881 GitHub stars. The repository holds 349 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.