iso-42001-aims-architect

Design ISO/IEC 42001:2023 AI management systems with scope and governance artifacts.

2|Updated Jul 6, 2026
One-click install
npx skills add https://github.com/nguyenpv1980-wq/Project-Aegis --skill iso-42001-aims-architect
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: iso-42001-aims-architect
Source: https://github.com/nguyenpv1980-wq/Project-Aegis/tree/main/.claude/skills/iso-42001-aims-architect
Command: npx skills add https://github.com/nguyenpv1980-wq/Project-Aegis --skill iso-42001-aims-architect

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps teams design an ISO/IEC 42001:2023-ready AI management system without confusing it with a single-feature risk review, an NIST AI RMF program, or an ISO 27001 security system. It turns scattered AI governance practices into a structured, auditable management system with scope, policy, assessments, evidence, and improvement loops.

Core Features & Use Cases

  • AIMS Scope Design: Defines which AI systems are in scope and what role the organization plays for each system, such as developer, provider, or user.
  • Three Distinct Assessments: Separates AI risk assessment, AI risk treatment, and AI system impact assessment so organizational risk is not mixed up with impacts on individuals and societies.
  • Governance Mapping: Reuses existing controls and shipped artifacts like agent governance, lifecycle risk management, and per-feature AI reviews as operational inputs instead of rebuilding them.
  • Compliance Readiness: Produces the artifacts needed for clause 4–10 readiness, internal audit planning, management review, and Annex A selection while keeping licensing constraints and verification items explicit.
  • Use Case: A company selling an AI SaaS product in the EU can use this Skill to structure its ISO 42001 certification preparation and connect product reviews, governance evidence, and treatment decisions into one AIMS.

Quick Start

Ask for an ISO 42001 AIMS design for your organization, including AI scope, the three assessments, Annex A selection, and the evidence and review plan.

Frequently Asked Questions about iso-42001-aims-architect

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is an ISO 42001 AI management system and how does it differ from a standard AI risk assessment?

An ISO 42001 AI management system (AIMS) provides a structured, auditable governance framework covering scope, policy, and improvement loops. Unlike a single AI risk assessment, it separates organizational risk treatment from AI system impact assessment on individuals and society.

How do I prepare for ISO 42001 certification readiness?

Prepare for ISO 42001 certification readiness by defining your AI scope, generating clause 4–10 governance artifacts, completing the three distinct assessments, planning internal audits, and mapping existing AI controls to Annex A selection requirements.

How do I separate AI system impact assessment from organizational AI risk treatment?

Separate AI system impact assessment from AI risk treatment by evaluating effects on individuals and societies independently from organizational risk mitigation. This ensures compliance readiness and prevents mixing distinct governance evidence streams.

Does ISO 42001 AIMS design work with existing NIST AI RMF and ISO 27001 controls?

ISO 42001 AIMS design reuses existing controls from frameworks like NIST AI RMF and ISO 27001 as operational inputs. It maps current agent governance and lifecycle risk management into the new AIMS instead of rebuilding your security system from scratch.

How do I define AI scope boundaries for an AIMS as an AI SaaS provider?

Define AI scope boundaries by identifying which AI systems are included and specifying your organization's role for each system, such as developer, provider, or user. This establishes clear governance mapping and certification readiness for your SaaS product.

What are the limitations of using an AIMS for ISO 42001 compliance?

An AIMS focuses strictly on designing a certifiable management system and producing governance artifacts, meaning it does not assert specific Annex A control counts or replace the formal external audit required to achieve actual ISO 42001 certification.