Syntic

Skills may execute instructions and code that could affect your environment. Marketplace scans reduce risk but do not guarantee safety. Always review files, run your own security checks, and use at your own risk.

Regulatory & QualityFree Safe

iso42001-specialist

Security Scan Summary

Status: Safe

Source: Syntic Skills registry

Automated security scan completed with no high-risk patterns detected. Manual review is still required.

About This Skill

Use when scoring AIMS gaps against ISO 42001 Clauses 4-10, building an AI risk register with Annex A control mapping, or planning a Clause 9.2 internal audit cycle for AI systems.

Downloadable SKILL.md

Download SKILL.md and place it in your Syntic skills folder. For Syntic Code, install in your local skills directory, review contents, and run in a controlled environment first. Acknowledge the risk notice above to enable the download.

SKILL.md
---
name: iso42001-specialist
description: Use when scoring AIMS gaps against ISO 42001 Clauses 4-10, building an AI risk register with Annex A control mapping, or planning a Clause 9.2 internal audit cycle for AI systems.
category: Regulatory & Quality
version: 1.0.0
tools: []
---

# ISO/IEC 42001 AI Management System Specialist

Internal-audit-grade operating skill for ISO/IEC 42001:2023. **Three decisions, not executive AI strategy:**

1. **Where are the AIMS gaps against Clauses 4–10?** Coverage scoring per clause plus remediation priority.
2. **What's the AI risk register, and which controls treat each risk?** Annex A.2–A.10 control mapping, following the ISO 23894 risk method.
3. **What's the Clause 9.2 internal audit plan?** A 12-month schedule with scope, frequency, and auditor-independence checks.

This is **not a replacement for executive AI strategy** — deciding whether to build or buy a model, and what business risk to accept, stays with leadership; this skill operates the management-system discipline that captures those decisions in audit-ready evidence. It is **not an EU AI Act compliance skill** — 42001 is a voluntary management-system standard, the AI Act is binding product-safety regulation; they overlap (a high-risk system under AI Act Article 6(2) typically needs the QMS in Article 17, which 42001 can partly satisfy) but the artefacts differ — route Article-level conformity assessment elsewhere. It is **not a substitute for ISO 23894 + 38507** — 42001 is the management system, 23894 is the AI risk methodology that feeds Clause 6.1, and 38507 is the governance lens; treat those as the methodology bridge behind the risk-register work below.

## Key questions to ask first

- Does the AIMS scope statement (Clause 4.3) name every AI system, including embedded models and third-party AI services? If "AI features added by our SaaS vendors" isn't in scope, the AIMS is incomplete.
- Does the AI policy (Clause 5.2) commit to lawful use *and* beneficial purpose *and* human oversight *and* continual improvement? Missing any of the four is a nonconformity at certification.
- Has the AI risk assessment (Clause 6.1.2) been re-run since the last material model change? Concept drift isn't a one-time event.
- Who signs the AI impact assessment for high-impact systems (Annex A.5.4)? No signed accountability means the control is missing.
- What's the internal-audit cadence (Clause 9.2)? ISO management-system standards expect at least once per 3-year cycle per clause; mature programs go annual.
- Is there a documented procedure for AI incidents (Annex A.9.3)? Untreated post-deployment monitoring is the most common nonconformity in early adopters.

## Decision 1: AIMS Gap Analysis (Clauses 4–10)

ISO 42001 shares the Annex SL high-level structure with ISO 9001/27001/13485: Clauses 4–10 are the management-system requirements, Annex A (A.1–A.10) is the AI-specific operational controls.

| Clause | Requires | Common gap |
|---|---|---|
| 4. Context | AI scope, interested parties, external context | Scope omits third-party AI services |
| 5. Leadership | AI policy, roles, accountability | Policy is marketing copy, not a real commitment |
| 6. Planning | AI risk + impact assessment, objectives | Risk register doesn't link to controls |
| 7. Support | Resources, competence, awareness, documented info | Competence requirements undefined for ML engineers |
| 8. Operation | Operational planning, AI system lifecycle | Lifecycle stages not mapped to Annex A controls |
| 9. Performance | Monitoring, internal audit, management review | Drift monitoring exists in code but not in management review inputs |
| 10. Improvement | Nonconformity, corrective action, continual improvement | CAPA loop duplicated instead of reused from 13485/9001 |

Score each clause full/partial/missing against an evidence inventory, and produce a prioritized remediation list.

## Decision 2: AI Risk Register + Annex A Control Mapping

Clause 6.1.2 requires AI risk assessment; Clause 6.1.3 requires risk treatment. Annex A provides 38 controls across 10 categories, and every risk in the register must map to at least one control that treats it.

| Category | Covers |
|---|---|
| A.2 AI policy | Policy content, alignment with other policies |
| A.3 Internal organization | Roles & responsibilities, reporting concerns |
| A.4 Resources for AI systems | Data resources, tooling, human resources |
| A.5 Assessing impacts | System impact assessment and its documentation |
| A.6 AI system lifecycle | Objectives, lifecycle phases, verification & validation |
| A.7 Data for AI systems | Data management, quality, provenance, preparation |
| A.8 Information for interested parties | System documentation, user information, incident communication |
| A.9 Use of AI systems | Intended use, monitoring of operation, logging |
| A.10 Third-party & customer relationships | Supplier and customer relationships |

ISO/IEC 23894:2023 supplies the AI-specific risk-management process (the methodology); 42001 Annex A supplies the controls; the risk register is the bridge. For each identified risk, record source/event/consequence/likelihood/impact, map to controls, and record a residual-risk verdict per the ISO 23894 treatment options (avoid/mitigate/transfer/accept), with management sign-off for anything accepted.

## Decision 3: Clause 9.2 Internal Audit Plan

Clause 9.2 requires internal audits "at planned intervals" to confirm the AIMS conforms and is effectively implemented — the cadence and depth are organizational choices. Mature-program defaults: cover every clause and every applicable Annex A control over a rolling 3-year cycle; run an annual full-system audit on the "always relevant" Clauses 4, 5, 9, 10; run quarterly or semi-annual deep dives on Clauses 6, 7, 8 by AI system or lifecycle phase; and enforce auditor independence — nobody audits their own work, and the owner of an A.6 lifecycle control can't audit Clause 8 operation for that same system.

## Workflows

**AIMS gap closure for certification (4–8 weeks):** inventory current evidence; review the gap matrix by clause; assign an owner and due date per gap, targeting closure before Stage 1; cross-check against existing ISO 27001/13485 artifacts (many are reusable) and EU AI Act obligations; output a prioritized remediation plan.

**AI risk register build (1–2 weeks):** run ISO 23894 risk identification across the AI lifecycle (data, model, deployment, decommission); capture each risk with source/event/consequence/likelihood/impact; map every high/critical risk to at least one Annex A control as treatment; document residual-risk acceptance with management sign-off; log via management review (Clause 9.3).

**Annual internal audit plan (1 day):** pull last year's findings and the certification-cycle phase (year 1/2/3); confirm auditor independence per assignment; confirm coverage hits every clause and applicable Annex A control over the rolling 3-year cycle; submit for management-review approval.

**Cross-framework reuse mapping (per new AI system):** pull existing ISO 27001 Annex A controls and ISO 13485 procedures relevant to the system; for each 42001 Annex A control, check whether an existing artifact already satisfies it (e.g. 27001 A.8.16 monitoring can extend to AI system monitoring); add an AI-specific overlay only where nothing already covers it; document the mapping in the AIMS scope statement.

## Output format

State the bottom line (gap severity plus the one thing to close first) in one sentence; name the decision type (gap-closure / risk-treatment / audit-scope); cite clause numbers and control IDs as evidence, not adjectives; give 3 concrete next steps with owners and dates; and flag what only the compliance officer or CAIO can decide — risk acceptance, scope expansion, certification readiness.

## Adjacent work

Reuse ISO 27001 ISMS controls for AIMS A.7 data controls; reuse ISO 13485 CAPA and management-review machinery; feed GDPR DPIA output into the AIMS A.5 impact assessment for personal-data systems; mirror the ISO 27001 internal-audit pattern for the AIMS audit scheduler; reuse SOC 2 trust-services controls for AIMS A.10 third-party relationships; route binding EU AI Act Article-level compliance to that specialist; and escalate build-vs-buy/cost-economics strategy to executive AI leadership, not this skill.

Bundle Download

Includes SKILL.md and bundled support files where provided. Risk acknowledgement is required.

Install Targets

Syntic App

  1. 1. Create a dedicated folder for this skill in your local skills library.
  2. 2. Place SKILL.md into that folder.
  3. 3. Restart Syntic and invoke this skill on matching tasks.

Syntic Code (CLI)

  1. 1. Save SKILL.md in your local Syntic Code skills directory.
  2. 2. Keep related files in the same skill folder.
  3. 3. Run in a safe environment and validate outputs.

Source

https://github.com/alirezarezvani/claude-skills/blob/main/ra-qm-team/compliance-team-iso42001/skills/iso42001-specialist/SKILL.md

Open Source Link
Regulatory & Quality

Related Skills