ai-governance-checker

Scan software repositories for missing AI regulatory compliance artifacts.

3|2|Updated Jan 23, 2026
One-click install
npx skills add https://github.com/robotijn/ctoc --skill ai-governance-checker
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ai-governance-checker
Source: https://github.com/robotijn/ctoc/tree/main/skills/compliance/ai-governance-checker
Command: npx skills add https://github.com/robotijn/ctoc --skill ai-governance-checker

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Organizations deploying AI systems face severe regulatory penalties (up to €35 million or 7% of global annual turnover) for non-compliance with the EU AI Act, NIST AI RMF, and ISO/IEC 42001, but lack a systematic way to verify they have all required governance artifacts before an audit or regulator inquiry.

Core Features & Use Cases

  • Multi-Framework Compliance Scanning: Audits AI systems against the binding EU AI Act, voluntary NIST AI RMF 1.0 (including the NIST AI 600-1 Generative AI Profile), and certifiable ISO/IEC 42001:2023 AI management system standard.
  • Artifact Gap Detection: Flags missing mandatory artifacts including AI system inventory, risk classification, technical documentation, data lineage, human oversight surfaces, conformity assessments, CE marking, incident reporting runbooks, and AI literacy training programs.
  • Prohibited Practice Detection: Identifies implementations of hard-banned AI practices under EU AI Act Article 5 that trigger immediate stop-ship penalties.
  • Use Case: A company deploying a CV resume screener (classified as high-risk under EU AI Act Annex III §4) can use this skill to verify they have the required human-in-the-loop override, technical documentation, conformity assessment, and EU database registration to avoid €15 million in high-risk non-compliance penalties.

Quick Start

Use the ai-governance-checker skill to scan your repository for missing AI regulatory compliance artifacts under the EU AI Act, NIST AI RMF, and ISO 42001.

Frequently Asked Questions about ai-governance-checker

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I check my AI system for EU AI Act compliance gaps before an audit?

To verify ISO 42001 compliance, scan your repository to detect missing Annex A reference controls and AI management system artifacts, ensuring your organization meets the certifiable standard requirements before an external audit.

How do I detect prohibited AI practices under EU AI Act Article 5?

To detect prohibited AI practices under EU AI Act Article 5, scan your codebase and implementation artifacts to identify hard-banned use cases that trigger immediate stop-ship penalties during regulatory review.

Can I use a single tool to audit against both NIST AI RMF and ISO 42001?

Yes, you can perform multi-framework compliance scanning to audit your AI systems simultaneously against the voluntary NIST AI RMF 1.0, including the NIST AI 600-1 Generative AI Profile, and the certifiable ISO/IEC 42001:2023 standard.

What mandatory artifacts are required for high-risk AI system compliance?

Mandatory artifacts for high-risk AI system compliance include an AI system inventory, risk classification, technical documentation, data lineage records, human-in-the-loop oversight surfaces, conformity assessments, CE marking, and EU database registration.

Does NIST AI RMF cover generative AI risk classification requirements?

Yes, NIST AI RMF coverage includes the NIST AI 600-1 Generative AI Profile, which defines specific generative AI risk categories that must be assessed alongside standard risk classification and inventory management requirements.