aims-audit

Audits AI Management Systems against ISO/IEC 42001 using six forcing questions.

25.3k|3.6k|Updated Oct 19, 2025
One-click install
npx skills add https://github.com/alirezarezvani/claude-skills --skill aims-audit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: aims-audit
Source: https://github.com/alirezarezvani/claude-skills/tree/main/compliance-os/skills/aims-audit
Command: npx skills add https://github.com/alirezarezvani/claude-skills --skill aims-audit

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Organizations preparing for ISO/IEC 42001 certification often miss critical AIMS gaps—scope omissions, incomplete AI policies, stale risk assessments, or missing Clause 9.2 audit plans—that cause stage 1 audit failures. This Skill pressure-tests an AI Management System with six forcing questions before certification, annual internal audits, or new AI system onboarding.

Core Features & Use Cases

  • Six-Question AIMS Interrogation: Systematically checks scope coverage, AI policy commitments, risk register control mapping, risk reassessment cadence, Clause 9.2 audit planning, and ISMS/QMS integration.
  • Scripted Gap Analysis: Invokes aims_gap_analyzer.py, ai_risk_register_builder.py, and aims_audit_scheduler.py to produce weighted coverage scores, risk severity breakdowns, and 12-month audit plans.
  • Structured Verdict Output: Generates a readiness report with gap counts, cross-framework reuse percentages, and a STAGE-1-READY / CLOSE-CRITICALS-FIRST / NOT-READY verdict.
  • Use Case: Before a stage 1 ISO 42001 certification audit, run the skill against your AIMS scope to identify critical nonconformities, verify every high risk maps to an Annex A control, and confirm auditor independence in the internal audit plan.

Quick Start

Ask the AI to run an AIMS audit on your AI management system scope using /cs:aims-audit before your upcoming ISO 42001 certification audit.

Frequently Asked Questions about aims-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare for an ISO 42001 stage 1 certification audit?

Run the six AIMS forcing questions covering scope completeness, AI policy commitments, risk register control mapping, reassessment cadence, Clause 9.2 audit planning, and ISMS/QMS integration. The skill produces a readiness verdict with critical gaps and top remediation actions.

What does an ISO 42001 internal audit checklist include?

It covers Clause 4.3 scope evidence, Clause 5.2 AI policy requirements, Clause 6.1 risk assessment and treatment mapping to Annex A controls, and Clause 9.2 internal audit planning with auditor independence. Every high or critical risk must link to at least one Annex A control.

When should the AI risk assessment be re-run under ISO 42001?

Re-run it after any material model change such as retraining on new data, fine-tuning, architecture changes, or deployment context changes. Clause 6.1.2 and EU AI Act Article 9 both require iterative risk assessment rather than one-time evaluation.

Can ISO 42001 AIMS integrate with an existing ISO 27001 ISMS?

Yes, roughly 60% of Clauses 4-10 evidence can be reused from ISO 27001 or ISO 13485 with AI scope appended. The CAPA loop should be a single loop with AI-tagged nonconformities rather than a parallel system.

What causes critical nonconformities in ISO 42001 audits?

Common causes include scope statements omitting embedded or third-party AI systems, AI policies missing commitments to lawful use, beneficial purpose, human oversight, or continual improvement, and high risks lacking mapped Annex A controls.