iso42001

Guides ISO/IEC 42001 AIMS implementation, gap analysis, risk assessment, and certification readiness.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill iso42001-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: iso42001
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/iso42001
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill iso42001-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Organizations adopting AI struggle to interpret and implement ISO/IEC 42001:2023, the first international AI Management System standard, including its mandatory AI risk assessments, impact assessments, and 38 Annex A controls. ## Core Features & Use Cases - Gap Analysis & SoA Generation: Produces clause-by-clause compliance tables and a Statement of Applicability covering all 38 Annex A controls with implementation status. - AI Risk & Impact Assessment (AISIA): Walks through the mandatory Clause 6.1.2 assessments with likelihood × severity scoring and Low/Medium/High impact classification. - Policy & Certification Support: Drafts AI policies with document control blocks and provides Stage 1/Stage 2 audit readiness checklists. - Use Case: A compliance lead at a company deploying an AI hiring tool asks for a gap analysis; the skill returns a RAG-status table of missing clauses, a completed AISIA classifying the system as high impact, and a 30/60/90-day remediation roadmap. ## Quick Start Ask the skill to perform an ISO 42001 gap analysis for your organization, stating whether you are an AI provider, AI user, or both.

Frequently Asked Questions about iso42001

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an ISO 42001 gap analysis?

Provide your organization role (AI provider, user, or both), the AI systems in scope, and current documentation. The skill assesses Clauses 4-10 and Annex A controls, returning a table with requirement, RAG status, evidence needed, and a prioritized remediation roadmap.

What is an AI System Impact Assessment (AISIA) under ISO 42001?

The AISIA is a mandatory Clause 6.1.2 assessment of an AI system's impacts on individuals and society. It evaluates intended purpose, affected populations, severity, and reversibility, then classifies impact as Low, Medium, or High to drive control selection.

How many controls does ISO 42001 Annex A contain?

Annex A contains 38 controls across nine domains (A.2 through A.10), covering AI policy, internal organization, resources, impact assessment, lifecycle, data, transparency, responsible use, and third-party relationships. Applicability depends on whether you are an AI provider or user.

Does ISO 42001 apply to companies that only use third-party AI?

Yes. ISO 42001 applies to both AI providers and AI users. AI users focus on controls like A.9 responsible use, A.10.3 supplier assessments, and A.6.2.6 monitoring, while provider-specific controls like A.7 data governance may be less applicable.

What documents are needed for ISO 42001 Stage 1 certification audit?

Stage 1 requires the AIMS scope document, signed AI policy, AI system register, completed AI risk assessments and AISIAs, Statement of Applicability, measurable AI objectives, internal audit programme, and management review agenda.

How does ISO 42001 relate to the EU AI Act?

The ISO 42001 AISIA aligns closely with the EU AI Act's Fundamental Rights Impact Assessment for high-risk systems. Organizations can extend their 42001 assessments to cover FRIA requirements, and certification may support EU AI Act conformity efforts.