CtrlK
BlogDocsLog inGet started
Tessl Logo

iso42001-specialist

ISO/IEC 42001:2023 AI Management System (AIMS) specialist for compliance teams running internal audits. Three decisions: (1) Where are the gaps against Clauses 4-10 and what do we close first? (2) What goes in the AI risk register and which Annex A controls treat each risk? (3) What's the 12-month internal audit plan that satisfies Clause 9.2? Use when preparing for certification, scoping internal audit cycles, or onboarding AI systems into an existing ISMS (27001) / QMS (13485) program. NOT an executive AI strategy skill (see chief-ai-officer-advisor). NOT EU AI Act compliance (see compliance-team-eu-ai-act).

65

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

The risk profile of this skill

Fix and improve this skill with Tessl

tessl review fix ./ra-qm-team/compliance-team-iso42001/skills/iso42001-specialist/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable compliance skill body with concrete commands, sequenced workflows, and real bundle references that resolve to existing files. It is slightly verbose (repeated framing, keyword stuffing, inline tabular detail) and lacks explicit error-recovery feedback loops.

Suggestions

Collapse the restated three-decisions framing and trim the Keywords block to the highest-value terms to reduce token cost without losing discoverability.

Move the full 10-row Annex A category table and the clause gap table into references/aims_controls_annex_a.md and references/iso42001_clauses.md, keeping only a compact overview inline.

Add an explicit validate-fix-retry loop to Workflow 1 (e.g., re-run aims_gap_analyzer.py after remediation to confirm each gap moved from partial/missing to full) so the gap-closure workflow has a real feedback checkpoint.

DimensionReasoningScore

Conciseness

Mostly efficient and free of basic-concept padding, but the three-decisions framing is restated, the Keywords block is a long stuffed list, and several 'framework' explanatory paragraphs plus the inline clause/Annex tables could be tightened or moved to references.

3 / 5

Actionability

Provides concrete, runnable commands in Quick Start and Workflows ('python scripts/aims_gap_analyzer.py path/to/aims_evidence.json') with real tool names and JSON inputs, though some workflow steps are prose comments rather than executable lines.

4 / 5

Workflow Clarity

Four workflows are clearly sequenced with confirmation checkpoints ('Confirm auditor independence per assignment', 'For each high/critical risk, confirm ≥ 1 Annex A control is selected', 'Confirm coverage hits every clause'), but there are no explicit validate-fix-retry feedback loops.

4 / 5

Progressive Disclosure

Good structure with a clear overview (three decisions, Key Questions, summary tables) and well-signaled one-level-deep references ('See references/iso42001_clauses.md') plus a References section listing all four files; minor gap is that the 10-row Annex A category table and clause table sit inline rather than purely as overview pointers.

4 / 5

Total

15

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A highly specific, third-person description that clearly states both capability and trigger conditions while explicitly disambiguating from adjacent skills. The only minor gap is synonym coverage in trigger terms; otherwise it is exemplary.

DimensionReasoningScore

Specificity

Lists multiple concrete actions across three explicit decisions — 'gaps against Clauses 4-10', 'AI risk register... which Annex A controls treat each risk', and '12-month internal audit plan that satisfies Clause 9.2' — giving comprehensive, non-generic coverage.

5 / 5

Completeness

Explicitly answers both what (the three named decisions) and when ('Use when preparing for certification, scoping internal audit cycles, or onboarding AI systems into an existing ISMS (27001) / QMS (13485) program') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Strong natural-domain keywords ('certification', 'internal audit', 'AI risk register', 'AIMS', 'Annex A controls') with a concrete 'Use when preparing for certification, scoping internal audit cycles, or onboarding AI systems' trigger, though a few common synonyms a user might say are absent.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (ISO/IEC 42001 AIMS internal-audit compliance) and draws explicit negative boundaries ('NOT an executive AI strategy skill', 'NOT EU AI Act compliance') naming the adjacent skills, minimizing wrong-skill triggering.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.