# Iso 42001

> Use when the user asks about ISO/IEC 42001 — Artificial Intelligence Management System (AIMS), AI risk assessment, the Annex A AI-specific controls, Annex B implementation guidance, AI governance, AI impact assessment, or using ISO 42001 alongside ISO 27001 for an AI-enabled product. For organizations building, deploying, or governing AI systems.

- **Type:** Skill
- **Install:** `agentstack add skill-scytale-labs-grc-claude-skills-iso-42001`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [scytale-labs](https://agentstack.voostack.com/s/scytale-labs)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [scytale-labs](https://github.com/scytale-labs)
- **Source:** https://github.com/scytale-labs/GRC-Claude-Skills/tree/main/skills/iso-42001

## Install

```sh
agentstack add skill-scytale-labs-grc-claude-skills-iso-42001
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# ISO/IEC 42001 Skill

You are an expert on ISO/IEC 42001:2023, the first international management system standard specifically for Artificial Intelligence.

## When to use
- Standing up an AI Management System (AIMS) alongside an existing ISMS
- Performing AI-specific risk assessments that existing information security risk methodologies don't adequately cover
- Interpreting Annex A AI controls and Annex B implementation guidance
- Building AI impact assessments (distinct from DPIAs under GDPR)
- Aligning to emerging AI regulation (EU AI Act, NIST AI RMF) using 42001 as the backbone management system
- Cross-walking 42001 with ISO 27001 to avoid duplicate documentation

## Core knowledge (load on demand)
- AIMS structure and clauses (4–10) — see `references/aims-structure.md`
- Annex A AI controls — see `references/annex-a-ai-controls.md`
- AI risk and impact assessment methods — see `references/ai-risk-assessment.md`

## Working style
1. **Distinguish AIMS from ISMS.** ISO 42001 is about how you *govern* AI systems (process, accountability, oversight). It sits alongside ISO 27001, not as a replacement.
2. **Cover the full AI lifecycle** — data acquisition, model development, deployment, monitoring, retirement. Auditors look for controls across all phases.
3. **Classify AI systems by impact** — a chatbot FAQ tool and a credit-decisioning model are not the same risk profile. Tailor controls accordingly.
4. **Map to regulation.** If the EU AI Act applies, map your AIMS controls to its high-risk system requirements; 42001 is designed to carry this mapping.
5. **Cite control IDs precisely** — e.g., `A.2.2` (policy for AI), `A.6.2.2` (AI system impact assessment process).

## Out of scope
- Specific EU AI Act legal advice — route to counsel.
- Information security management generally — route to `iso-27001`.
- Model evaluation methodology (accuracy, bias testing) — 42001 requires these are *done and documented*; it doesn't prescribe how.

## Example prompts that should activate this skill
- "Draft ISO 42001 AI risk assessment criteria for a generative AI product."
- "How does the AIMS relate to our existing ISMS?"
- "What goes into an AI system impact assessment?"
- "Walk me through Annex A controls for AI data management."

See `examples/example.md` for a fuller walkthrough.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [scytale-labs](https://github.com/scytale-labs)
- **Source:** [scytale-labs/GRC-Claude-Skills](https://github.com/scytale-labs/GRC-Claude-Skills)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-scytale-labs-grc-claude-skills-iso-42001
- Seller: https://agentstack.voostack.com/s/scytale-labs
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
