Skills may execute instructions and code that could affect your environment. Marketplace scans reduce risk but do not guarantee safety. Always review files, run your own security checks, and use at your own risk.
aims-audit
Security Scan Summary
Status: Safe
Source: Syntic Skills registry
Automated security scan completed with no high-risk patterns detected. Manual review is still required.
About This Skill
Use when preparing for ISO/IEC 42001 certification stage 1, running an annual internal audit cycle, or onboarding a new AI system into an existing AI Management System.
Downloadable SKILL.md
Download SKILL.md and place it in your Syntic skills folder. For Syntic Code, install in your local skills directory, review contents, and run in a controlled environment first. Acknowledge the risk notice above to enable the download.
--- name: aims-audit description: Use when preparing for ISO/IEC 42001 certification stage 1, running an annual internal audit cycle, or onboarding a new AI system into an existing AI Management System. category: Compliance version: 1.0.0 tools: [] --- # AIMS ISO 42001 Audit Six forcing questions that pressure-test any AI Management System (AIMS) work before a certification commitment, an internal audit cycle, or onboarding a new AI system. ## When to run Before a stage 1 ISO 42001 certification audit; before the annual internal audit cycle (Clause 9.2); when onboarding a new AI system into existing AIMS scope; when the AI risk register hasn't been refreshed in over 6 months; after a material model change (Clause 6.1.2 requires re-evaluating risk); or when audit findings hint at AIMS/ISMS/QMS duplication. ## The six questions ### 1. Does the AIMS scope statement name every AI system? Scope omission is a certification finding. This includes embedded models, third-party AI services, and "experimental" production systems — even AI features added by SaaS vendors you use are in scope if they affect the company's services. Verify against Clause 4.3 evidence. ### 2. Does the AI policy commit to lawful use AND beneficial purpose AND human oversight AND continual improvement? Missing any of the four is a critical nonconformity at stage 1. The AI policy is not the info-sec policy — it needs its own substantive content (ISO 42001 Annex A.2.2, Clause 5.2). Marketing-copy "AI ethics" doesn't pass. ### 3. What's the risk-register coverage, and which Annex A controls treat each risk? Risk identification without control mapping fails Clause 6.1.3. Follow ISO 23894 methodology; every high/critical risk must link to at least one Annex A control, and any "additional treatment required" residual verdict must be closed before stage 1. ### 4. Has the AI risk assessment been re-run since the last material model change? Concept drift is not a one-time event. Both EU AI Act Article 9 and ISO 42001 Clause 6.1.2 require iterative risk assessment. Material change includes retraining on new data, fine-tuning, architecture change, or deployment-context change — an assessment from 18 months ago that hasn't been revisited means the AIMS is broken. ### 5. What's the Clause 9.2 internal-audit plan, and is auditor independence respected? Without a 9.2 plan the AIMS is incomplete. Every clause and applicable Annex A control needs coverage over a rolling 3-year cycle, and the same auditor cannot audit their own work. Cross-check against any integrated ISO 13485 audit programme. ### 6. Has the AIMS been integrated with the existing ISMS/QMS, or built in parallel? Parallel systems run roughly 5x the ongoing maintenance cost. Around 60% of Clause 4-10 evidence reuses ISO 27001 / ISO 13485 with AI scope appended, and the CAPA loop should be one loop with AI-tagged nonconformities, not a separate one. Cross-check ISO 27001 alignment with the relevant security teammate. ## What to produce For the scope under review, cover: gap analysis across Clauses 4-10 (weighted coverage %, critical/major gap counts, certification readiness — ready / stage-2-candidate / not-ready); the AI risk register (total risks by severity, count requiring additional treatment, top risk needing action); the Clause 9.2 audit plan (12-month clause/control coverage, auditor-independence status, prior-year follow-up scheduling); and cross-framework reuse (% of AIMS evidence reused from ISO 27001, % from ISO 13485 if applicable, % net-new — mostly Annex A). Close with a verdict — STAGE-1-READY / CLOSE-CRITICALS-FIRST / NOT-READY — and the top 3 actions with an owner and date each. ## Escalate to a teammate For the multi-framework view, EU AI Act-specific questions, executive AI-strategy decisions, or ISO 27001 cross-framework alignment, @mention the relevant compliance, AI-governance, or security teammate.
Bundle Download
Includes SKILL.md and bundled support files where provided. Risk acknowledgement is required.
Install Targets
Syntic App
- 1. Create a dedicated folder for this skill in your local skills library.
- 2. Place SKILL.md into that folder.
- 3. Restart Syntic and invoke this skill on matching tasks.
Syntic Code (CLI)
- 1. Save SKILL.md in your local Syntic Code skills directory.
- 2. Keep related files in the same skill folder.
- 3. Run in a safe environment and validate outputs.
Source
https://github.com/alirezarezvani/claude-skills/blob/main/compliance-os/skills/aims-audit/SKILL.md
Open Source LinkRelated Skills
ai-act-readiness
Use when doing AI-system intake, preparing for EU deployment, or running the annual compliance refresh — the...
Compliancecompliance-os
Use when standing up a multi-framework compliance program, planning the annual audit calendar, or preparing...
Compliancecompliance-readiness
Use when adopting a new compliance framework, finalizing the annual audit calendar, or signing off on...
Compliancefda-qsr-audit-prep
Use when prepping an annual internal FDA QSR audit or inspection readiness review, or responding to a Form...