Iso42001
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
ISO 42001 AI Management System (AIMS) compliance. An agent skill from borghei/Claude-Skills.
$ npx skills add borghei/Claude-Skills --skill iso42001-ai-management -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install borghei/Claude-Skills iso42001-ai-management --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ra-qm-team/iso42001-ai-management .claude/skills/iso42001-ai-management && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "iso42001-ai-management" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/iso42001-ai-management into .claude/skills/iso42001-ai-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iso42001-ai-management", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/iso42001-ai-managementType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add borghei/Claude-Skills --skill iso42001-ai-management -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install borghei/Claude-Skills iso42001-ai-management --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/ra-qm-team/iso42001-ai-management .agents/skills/iso42001-ai-management && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "iso42001-ai-management" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/iso42001-ai-management into .agents/skills/iso42001-ai-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iso42001-ai-management", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add borghei/Claude-Skills --skill iso42001-ai-management -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install borghei/Claude-Skills iso42001-ai-management --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/ra-qm-team/iso42001-ai-management .cursor/skills/iso42001-ai-management && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "iso42001-ai-management" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/iso42001-ai-management into .cursor/skills/iso42001-ai-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iso42001-ai-management", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/borghei/Claude-Skills.git --path ra-qm-team/iso42001-ai-management--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add borghei/Claude-Skills --skill iso42001-ai-management -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install borghei/Claude-Skills iso42001-ai-management --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/ra-qm-team/iso42001-ai-management .gemini/skills/iso42001-ai-management && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "iso42001-ai-management" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/iso42001-ai-management into .gemini/skills/iso42001-ai-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iso42001-ai-management", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install borghei/Claude-Skills iso42001-ai-managementInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add borghei/Claude-Skills --skill iso42001-ai-management -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/ra-qm-team/iso42001-ai-management .github/skills/iso42001-ai-management && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "iso42001-ai-management" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/iso42001-ai-management into .github/skills/iso42001-ai-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iso42001-ai-management", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add borghei/Claude-Skills --skill iso42001-ai-management -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install borghei/Claude-Skills iso42001-ai-management --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/ra-qm-team/iso42001-ai-management .opencode/skills/iso42001-ai-management && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "iso42001-ai-management" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/iso42001-ai-management into .opencode/skills/iso42001-ai-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iso42001-ai-management", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
iso42001-ai-managementISO 42001 AI Management System (AIMS) compliance. An agent skill from borghei/Claude-Skills.
Iso42001 AI Management is an agent skill from borghei/Claude-Skills. ISO 42001 AI Management System (AIMS) compliance. Use for ISO 42001 readiness assessments, AI governance planning, AI impact assessments, Annex A control validation, responsible AI implementation, and AIMS certification preparation.
Its SKILL.md is about 7.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/ai-lifecycle-management.md`, `references/iso42001-clause-guide.md` and `scripts/ai_impact_assessor.py`).
It sits in Legal & Compliance, covering Audit readiness, LLM guardrails and AI governance. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
pythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Iso42001 AI Management loads about 7.4k tokens when it runs, and up to ~19k if it reads all its reference files. Until then it costs about 64 tokens; SKILL.md has 2,786 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 2,786 words, ~7,410 tokens.
.claude/skills/iso42001-ai-management/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Tools and guidance for ISO/IEC 42001:2023 — the first international standard for AI Management Systems (AIMS).
Assesses organizational readiness against all ISO 42001 clauses and Annex A controls. Scores each clause on a 0-100 scale and identifies gaps for certification preparation.
# Assess readiness from a JSON profile
python scripts/aims_readiness_checker.py --input org_profile.json
# Generate a blank input template
python scripts/aims_readiness_checker.py --template > org_profile.json
# JSON output for automation
python scripts/aims_readiness_checker.py --input org_profile.json --json
# Export report to file
python scripts/aims_readiness_checker.py --input org_profile.json --output report.jsonAssessment Areas:
| Clause | Area | Key Checks |
|---|---|---|
| Clause 4 | Context | Scope defined, interested parties, AIMS boundaries |
| Clause 5 | Leadership | AI policy, governance structure, management commitment |
| Clause 6 | Planning | Risk assessment methodology, AI objectives, impact assessments |
| Clause 7 | Support | Resources, competence, awareness, documentation |
| Clause 8 | Operation | AI lifecycle, data management, risk treatment, third-party controls |
| Clause 9 | Performance | Monitoring, internal audit, management review |
| Clause 10 | Improvement | Corrective actions, continual improvement, incident management |
| Annex A | Controls | A.2-A.10 control implementation status |
Output:
Generates comprehensive AI impact assessments evaluating fairness, transparency, safety, privacy, and security dimensions. Maps impacts to interested parties and provides risk treatment recommendations.
# Assess an AI system from a JSON description
python scripts/ai_impact_assessor.py --input ai_system.json
# Generate a blank input template
python scripts/ai_impact_assessor.py --template > ai_system.json
# Export assessment report
python scripts/ai_impact_assessor.py --input ai_system.json --output assessment.json
# Generate markdown report
python scripts/ai_impact_assessor.py --input ai_system.json --format markdown --output assessment.mdAssessment Dimensions:
| Dimension | Evaluates | Key Factors |
|---|---|---|
| Fairness | Bias, discrimination, equity | Training data diversity, protected attributes, outcome parity |
| Transparency | Explainability, interpretability | Model complexity, decision documentation, user disclosure |
| Safety | Reliability, robustness, harm prevention | Failure modes, edge cases, human oversight, fallback mechanisms |
| Privacy | Data protection, consent, minimization | PI processing, consent mechanisms, data retention, anonymization |
| Security | Adversarial resilience, access control | Attack vectors, model integrity, access management, audit logging |
| Accountability | Governance, responsibility, auditability | Decision ownership, audit trails, escalation procedures |
Features:
references/iso42001-clause-guide.md
Comprehensive clause-by-clause guidance:
references/ai-lifecycle-management.md
End-to-end AI system lifecycle guidance:
Before running the assessment, confirm these inputs. If any is unknown or vague, ASK — do not assume:
Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the assessment.
Step 1: Define AIMS scope
→ Identify AI systems in scope
→ Determine organizational boundaries
→ Document interested parties and requirements
Step 2: Generate assessment template
→ python scripts/aims_readiness_checker.py --template > org_profile.json
→ Fill in organizational details and current state
Step 3: Run readiness assessment
→ python scripts/aims_readiness_checker.py --input org_profile.json
Step 4: Review results
→ Address critical gaps (Clauses 5, 6, 8 typically weakest)
→ Prioritize Annex A controls by risk
→ Develop remediation roadmap
Step 5: Conduct AI impact assessments
→ python scripts/ai_impact_assessor.py --template > ai_system.json
→ Assess each in-scope AI system
→ python scripts/ai_impact_assessor.py --input ai_system.json
Step 6: Plan implementation
→ See references/iso42001-clause-guide.md for requirements
→ See references/ai-lifecycle-management.md for operational controlsStep 1: Identify AI system for assessment
→ Document system purpose, inputs, outputs, and decisions
→ Identify affected individuals and groups
Step 2: Generate assessment template
→ python scripts/ai_impact_assessor.py --template > ai_system.json
→ Complete all sections (model details, data sources, deployment context)
Step 3: Conduct assessment
→ python scripts/ai_impact_assessor.py --input ai_system.json --format markdown --output report.md
Step 4: Review dimension scores
→ Fairness: check for bias in training data and outcomes
→ Transparency: verify explainability mechanisms
→ Safety: validate failure modes and human oversight
→ Privacy: confirm data protection measures
→ Security: assess adversarial resilience
Step 5: Implement risk treatments
→ Apply recommended mitigations per dimension
→ Document residual risk acceptance decisions
→ Assign treatment owners and timelines
Step 6: Monitor and review
→ Schedule periodic reassessment (quarterly minimum)
→ Track treatment implementation progress
→ Update assessment when system changes materiallyStep 1: Gap analysis
→ python scripts/aims_readiness_checker.py --input org_profile.json
→ Target overall score of 80+ for certification readiness
Step 2: Document AIMS
→ AI policy (Clause 5.2)
→ AIMS scope (Clause 4.3)
→ Risk assessment methodology (Clause 6.1)
→ Statement of Applicability for Annex A controls
→ AI objectives (Clause 6.2)
Step 3: Implement operational controls
→ AI lifecycle procedures (Clause 8)
→ Data management processes (Annex A.7)
→ Third-party management (Annex A.10)
→ Impact assessments for all AI systems (Annex A.5)
Step 4: Conduct internal audit
→ Use references/iso42001-clause-guide.md audit questions
→ Document findings and corrective actions
→ Verify closure of nonconformities
Step 5: Management review
→ Present AIMS performance to top management
→ Review AI objectives achievement
→ Obtain commitment for continual improvement
Step 6: Stage 1 and Stage 2 audits
→ Stage 1: Documentation review (readiness check)
→ Stage 2: Implementation effectiveness audit
→ Address any nonconformities from auditISO/IEC 42001:2023 is the world's first international standard for AI Management Systems (AIMS). Published in December 2023, it provides a framework for organizations to responsibly develop, provide, and use AI systems. The standard follows the ISO Harmonized Structure (Annex SL) for management system standards, enabling integration with ISO 27001, ISO 9001, and ISO 14001.
Key Characteristics:
| Requirement | Section | Description |
|---|---|---|
| Organization context | 4.1 | Internal/external issues relevant to AI objectives |
| Interested parties | 4.2 | Stakeholders, their requirements, and expectations |
| AIMS scope | 4.3 | Boundaries and applicability of the AIMS |
| AIMS establishment | 4.4 | Establish, implement, maintain, and improve the AIMS |
| Requirement | Section | Description |
|---|---|---|
| Leadership commitment | 5.1 | Top management demonstrates commitment to AIMS |
| AI policy | 5.2 | Responsible AI principles, ethical guidelines, organizational values |
| Roles and responsibilities | 5.3 | Clear assignment of AIMS roles, authority, and accountability |
AI Policy Must Include:
AI Governance Structure:
| Requirement | Section | Description |
|---|---|---|
| Risks and opportunities | 6.1 | Actions to address AI-specific risks and opportunities |
| AI risk assessment | 6.1.2 | Methodology for identifying and evaluating AI risks |
| AI objectives | 6.2 | Measurable objectives for responsible AI |
| Impact assessment | 6.1.4 | Assessment of AI system impacts on individuals and society |
AI Risk Assessment Must Cover:
| Requirement | Section | Description |
|---|---|---|
| Resources | 7.1 | Compute, data, expertise, and infrastructure |
| Competence | 7.2 | Required skills for AI roles, training plans |
| Awareness | 7.3 | AI literacy across the organization |
| Communication | 7.4 | Internal/external communication on AI matters |
| Documented information | 7.5 | Document creation, control, and retention |
| Requirement | Section | Description |
|---|---|---|
| Operational planning | 8.1 | Planning and controlling AI processes |
| AI risk assessment | 8.2 | Executing risk assessments per methodology |
| AI risk treatment | 8.3 | Implementing risk treatment plans |
| AI system lifecycle | 8.4 | Managing AI systems through all lifecycle stages |
AI System Lifecycle Stages:
Data Management for AI:
Third-Party and Supplier Management:
| Requirement | Section | Description |
|---|---|---|
| Monitoring and measurement | 9.1 | AI system performance metrics and KPIs |
| Internal audit | 9.2 | Planned audits of the AIMS |
| Management review | 9.3 | Top management review of AIMS effectiveness |
AI Performance Metrics:
| Requirement | Section | Description |
|---|---|---|
| Nonconformity | 10.1 | Corrective actions for nonconformities |
| Continual improvement | 10.2 | Ongoing enhancement of the AIMS |
| AI incident management | 10.3 | Handling AI system incidents and near-misses |
| Control | Title | Description |
|---|---|---|
| A.2 | AI Policies | Policies for responsible AI aligned with organizational objectives |
| A.3 | Internal Organization | Roles, responsibilities, segregation of duties for AI |
| A.4 | Resources for AI Systems | Compute, data, tools, and expertise management |
| A.5 | Assessing AI System Impact | Impact assessment processes for AI systems |
| A.6 | AI System Lifecycle | Controls across design, development, deployment, retirement |
| A.7 | Data for AI Systems | Data quality, provenance, bias, governance, protection |
| A.8 | Information for Interested Parties | Transparency, disclosure, and communication |
| A.9 | Use of AI Systems | Acceptable use policies, human oversight, user guidance |
| A.10 | Third-Party Relationships | Supplier management, outsourced AI, component evaluation |
Annex B provides non-normative guidance for implementing Annex A controls:
AI-specific risk sources organized by category:
AI-specific control objectives:
Sector-specific considerations:
| Standard | Relationship | Integration Points |
|---|---|---|
| ISO 27001 | Information security | Risk assessment, access controls, incident management |
| ISO 9001 | Quality management | Process approach, document control, continual improvement |
| ISO 14001 | Environmental management | Impact assessment, lifecycle thinking |
| ISO 31000 | Risk management | Risk framework, assessment methodology |
| ISO 22989 | AI concepts/terminology | Foundational definitions |
| ISO 23894 | AI risk management | Risk management guidance |
| EU AI Act Requirement | ISO 42001 Mapping |
|---|---|
| Risk management system (Art. 9) | Clause 6.1, 8.2, 8.3, Annex A.5 |
| Data governance (Art. 10) | Clause 8.4, Annex A.7 |
| Technical documentation (Art. 11) | Clause 7.5, Annex A.6 |
| Transparency (Art. 13) | Annex A.8 |
| Human oversight (Art. 14) | Annex A.9 |
| Accuracy, robustness, security (Art. 15) | Clause 9.1, Annex A.6 |
| Quality management system (Art. 17) | Full AIMS (Clauses 4-10) |
| Conformity assessment | Certification process |
| Phase | Activity | Duration |
|---|---|---|
| Preparation | Gap analysis, implementation, internal audit | 6-12 months |
| Stage 1 Audit | Documentation review, readiness assessment | 1-2 days |
| Gap Remediation | Address Stage 1 findings | 1-3 months |
| Stage 2 Audit | Implementation effectiveness assessment | 2-5 days |
| Certification | Certificate issued (3-year validity) | Upon passing |
| Surveillance | Annual surveillance audits | 1-2 days/year |
| Recertification | Full reassessment every 3 years | 2-4 days |
Phase 1 — Foundation (Months 1-3):
Phase 2 — Core Implementation (Months 4-6):
Phase 3 — Operationalize (Months 7-9):
Phase 4 — Verify and Certify (Months 10-12):
| Problem | Possible Cause | Resolution |
|---|---|---|
| Readiness score low on Clause 5 (Leadership) despite executive sponsorship | AI policy does not include ethical principles, responsible AI commitment, or framework for setting AI objectives | Update AI policy to explicitly address all required elements: ethical principles, responsible AI, legal alignment, continual improvement commitment, and AI objectives framework; obtain formal management sign-off |
| AI impact assessment returns High/Critical risk across all dimensions | AI system processes sensitive personal data, makes autonomous decisions, and affects large populations without safeguards | Implement targeted mitigations per dimension: human-in-the-loop for safety, bias testing for fairness, explainability mechanisms for transparency, data protection for privacy; re-run assessment after mitigation |
| Annex A controls scored as "Not Implemented" despite operational practices | Practices exist informally but are not documented per ISO 42001 requirements | Document all existing AI practices as formal procedures; create evidence artifacts (policy documents, meeting minutes, risk registers, training records); map to specific Annex A control objectives |
| Certification body auditor questions AI risk assessment methodology | Risk assessment does not cover all seven required risk categories (fairness, transparency, safety, privacy, security, accountability, societal) | Update risk assessment methodology to explicitly address all ISO 42001 risk categories; use ai_impact_assessor.py template to ensure comprehensive coverage; document risk criteria and tolerance levels |
| Third-party AI components lack governance controls | Organization uses third-party AI models or APIs without formal evaluation or supplier management | Implement Annex A.10 (Third-Party Relationships) controls; evaluate all third-party AI components; establish contractual requirements for AI service providers; monitor supplier AI practices |
| Data management procedures incomplete for AI lifecycle | Data quality, provenance, and bias assessment not systematically performed for training and evaluation data | Implement Annex A.7 (Data for AI Systems) controls; establish data quality assessment procedures; document data provenance and lineage; conduct bias assessments per dataset; define retention and disposal procedures |
| Stage 1 audit finds AIMS documentation insufficient | Documentation follows generic QMS structure without AI-specific elements | Restructure documentation to address all ISO 42001 clauses (4-10) and Annex A controls (A.2-A.10); include AI-specific policies, risk assessments, impact assessments, and lifecycle procedures |
aims_readiness_checker.py, with all clauses at Defined maturity level or aboveIn Scope:
Out of Scope:
eu-ai-act-specialist bias detector for technical testingImportant Notes:
| Skill | Integration | When to Use |
|---|---|---|
eu-ai-act-specialist | ISO 42001 AIMS maps directly to EU AI Act requirements; certification demonstrates Art. 17 QMS compliance | When building AI governance satisfying both ISO 42001 and EU AI Act obligations |
information-security-manager-iso27001 | ISO 27001 security controls integrate with AIMS via shared Annex SL structure; risk assessment methodologies align | When implementing joint ISMS + AIMS covering both information security and AI governance |
gdpr-dsgvo-expert | AIMS data management (Annex A.7) aligns with GDPR data protection requirements; AI processing requires DPIA | When AI systems process personal data and require both AIMS and GDPR compliance |
isms-audit-expert | Internal audit methodology and finding management shared between ISO 27001 and ISO 42001 | When conducting internal audits covering both ISMS and AIMS |
Assesses organizational readiness against all ISO 42001:2023 clauses and Annex A controls.
| Flag | Required | Description |
|---|---|---|
--input <file> | Yes (unless --template) | Path to JSON organizational profile for assessment |
--template | No | Generate blank input template to stdout |
--json | No | Output results in JSON format for automation |
--output <file> | No | Export report to specified file path |
Assessment Scope: Clause 4 (Context), Clause 5 (Leadership), Clause 6 (Planning), Clause 7 (Support), Clause 8 (Operation), Clause 9 (Performance), Clause 10 (Improvement), and Annex A controls (A.2-A.10).
Output: Overall readiness score (0-100), per-clause scores with maturity level (Initial/Developing/Defined/Managed/Optimized), Annex A control implementation status, gap analysis with prioritized recommendations, and certification readiness assessment (Ready/Near Ready/Significant Gaps).
Generates comprehensive AI impact assessments across six risk dimensions with regulatory mapping.
| Flag | Required | Description |
|---|---|---|
--input <file> | Yes (unless --template) | Path to JSON AI system description for assessment |
--template | No | Generate blank AI system template to stdout |
--format <fmt> | No | Output format: json (default) or markdown |
--output <file> | No | Export assessment report to specified file path |
Assessment Dimensions: Fairness (bias, discrimination, equity), Transparency (explainability, interpretability), Safety (reliability, robustness, harm prevention), Privacy (data protection, consent, minimization), Security (adversarial resilience, access control), Accountability (governance, responsibility, auditability).
Output: Per-dimension risk scoring (Low/Medium/High/Critical), interested party impact mapping, risk treatment options (Avoid/Mitigate/Transfer/Accept), regulatory mapping (EU AI Act risk tier, ISO 42001 Annex A controls), residual risk calculation, and markdown or JSON report.
© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references) in ra-qm-team/iso42001-ai-management of borghei/Claude-Skills.
Open the folder on GitHubat commit 4a698e8
Iso42001 AI Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Iso42001 AI Management this skillborghei/Claude-Skills | 891 | — | ~7.4k | Automated safety check: Pass | MIT | |
| Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~3.7k | Automated safety check: Pass | MIT | |
| Eu AI Act Readinessseb1n/awesome-ai-agent-skills | 206 | — | ~3.3k | Automated safety check: Pass | MIT | |
| AI GovernanceHack23/cia | 239 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Compliance Osalirezarezvani/claude-skills | 28k | — | ~3.3k | Automated safety check: Pass | MIT | |
| Iso42001 Specialistalirezarezvani/claude-skills | 28k | — | ~3.5k | Automated safety check: Pass | MIT |
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
seb1n/awesome-ai-agent-skills
Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…
Hack23/cia
AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents
alirezarezvani/claude-skills
Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…
alirezarezvani/claude-skills
ISO/IEC 42001:2023 AI Management System (AIMS) specialist for compliance teams running internal audits.
alirezarezvani/claude-skills
/cs:aims-audit <scope — ISO/IEC 42001 AIMS internal-audit 6-question forcing interrogation.
borghei/Claude-Skills
Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.
borghei/Claude-Skills
Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.
borghei/Claude-Skills
Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.
borghei/Claude-Skills
Idea to AI-generated prototype to customer validation to engineering handoff.
borghei/Claude-Skills
Analytics engineering across data modeling, dbt, transformation, and semantic layers.
borghei/Claude-Skills
Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.
Categories
ISO 42001 AI Management System (AIMS) compliance. An agent skill from borghei/Claude-Skills. Iso42001 AI Management is an agent skill from borghei/Claude-Skills. ISO 42001 AI Management System (AIMS) compliance.
Iso42001 AI Management fits situations like: ISO 42001 readiness assessments; AI governance planning; AI impact assessments; annex A control validation.
Run `npx skills add borghei/Claude-Skills --skill iso42001-ai-management -a claude-code`. Or copy the skill folder (ra-qm-team/iso42001-ai-management in borghei/Claude-Skills) into .claude/skills/iso42001-ai-management in your project. Claude Code loads it when a task matches its description.
Run `npx skills add borghei/Claude-Skills --skill iso42001-ai-management -a codex`. Or copy the skill folder (ra-qm-team/iso42001-ai-management in borghei/Claude-Skills) into .agents/skills/iso42001-ai-management in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill iso42001-ai-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/iso42001-ai-management, .gemini/skills/iso42001-ai-management, .github/skills/iso42001-ai-management and .opencode/skills/iso42001-ai-management in your project.
Going by SKILL.md and its folder, Iso42001 AI Management needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Iso42001 AI Management is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 7.4k tokens (SKILL.md is roughly 30k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Iso42001 AI Management: Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Eu AI Act Readiness (seb1n/awesome-ai-agent-skills, 206 stars), AI Governance (Hack23/cia, 239 stars) and Compliance Os (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 891 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.
Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.