Included with the toolkit

Your toolkit comes with an AI assistant that builds it with you

Install one skill. Answer questions about your organisation once. The assistant drafts your policies, procedures and registers across the whole kit, prepares every Statement of Applicability decision for you to confirm — and leaves your audit records deliberately empty, because those are yours to earn.

What it is

A skill you install into your own AI assistant. Once installed, it knows how this toolkit is organised — which document comes first, what belongs in each one, and which ones you must never fill in ahead of time.

It works on your own computer, on your own copy of the toolkit. Your answers and your documents stay with you.

Before you start

You need an AI assistant that supports installable skills — Claude, for example — and Python 3 on your computer. Nothing else to install, and no account to create with us.

Getting started

Five steps from opening the toolkit to having a draft of your management system.

  1. 01

    Install the skill

    Open the folder 00. Start Here — Master Index, then AI Assistant Skill. Install the file ending in .skill in your assistant. There is a short README in the same folder if you get stuck.

  2. 02

    Point it at your toolkit and ask

    Open a conversation with your assistant, give it access to your toolkit folder, and ask in your own words. You do not need to remember any commands.

    Try saying

    • Help me build our AIMS from this toolkit
    • Interview me and fill in the templates
  3. 03

    Tell it about your organisation

    It interviews you — who you are, what AI systems you use or build, who is accountable. If you already have documents that answer some of this — an AI inventory, an org chart, an existing ISO 27001 scope statement — give it those first: it reads them and only asks about the gaps. It can also research your context from public sources such as your website, your sector and the regulations where you operate. This context analysis is worth doing properly: it feeds your scope and, through it, your Statement of Applicability — the document your auditor will spend the most time with. Your answers are saved to a single file you can correct and reuse.

  4. 04

    Let it build

    It creates a new, tailored copy of the toolkit with your organisation's details written consistently through every document. Your original toolkit is never changed, so you can always start again. It works in the toolkit's own order — scope first, then your AI systems, then risks, then your Statement of Applicability — because each step depends on the one before.

  5. 05

    Review what it produced

    You get your documents plus a list of everything it could not answer. Anything it did not know is marked clearly in the document itself, so nothing is quietly invented. Work through that list, then read the documents properly — they are yours, and you are the one who has to stand behind them.

What it fills in, and what it leaves for you

Not every document in the toolkit is the same kind of thing. The assistant sorts the Word documents into three groups and treats each differently.

GroupDocumentsWhat happens
Drafted35Your policies, procedures, plans and the registers that can be known up front — written from your answers, using your real systems, roles and locations.
Tailored23Forms and guides you complete once per AI system, dataset or supplier. The wording is adapted to your organisation; the rows stay blank for you to fill in as you go.
Left empty17Your incident register, corrective actions, audit findings and reports, management review minutes, monitoring records.

Why 17 documents stay empty

Those documents are your evidence. They record things that must genuinely have happened — an audit you ran, a review you held, an incident you dealt with. An auditor who finds them already filled in will treat that as fabricated evidence, and it can cost you the certificate.

The assistant will not complete them, even if you ask it to. They fill up as you run your management system, which is what having one is for. To show you what good entries look like, the toolkit includes a Completed Examples Guide for a fictional organisation — to learn from, never to copy.

Decisions that stay yours

The assistant drafts and recommends. It will stop and hand these back to you every time:

  • Approving your AI policytop management signs it.
  • Accepting residual riska named person accepts it, on the record.
  • Signing off your Statement of Applicabilityincluding why you excluded anything.
  • Setting your risk appetiteyour tolerance, your call.
  • Confirming EU AI Act classificationit recommends, you confirm.

Everything you can ask it to do

Ask in plain language — these are the built-in capabilities. Every one respects the same rule: facts come from you, decisions stay with you, and evidence is never invented.

Build my AIMS

Try saying

  • Help me build our AIMS from this toolkit

The full flow above: interview or read your documents, save your answers to one file, and build a tailored copy of the whole kit.

Complete the SoA

Try saying

  • Help me complete the Statement of Applicability

For each of the 38 Annex A controls it prepares a recommendation based on your own systems, data and suppliers. You confirm or amend each one; only your confirmed decisions are written into the workbook, with a backup made first.

Classify under the EU AI Act

Try saying

  • Classify our systems under the EU AI Act

Matches each AI system against the classifier in the EU AI Act mapping, explains the recommended tier with the relevant articles and dates, and tracks the resulting obligations per system. You confirm — and for borderline cases it tells you to involve counsel.

Select our risks

Try saying

  • Which risks from the library apply to us?

The toolkit ships a library of 41 common AI risks mapped to every Annex A control. The assistant helps you select and adapt the ones that genuinely apply — never paste the whole library.

Management report

Try saying

  • Create a management report

Reads your own risk register, SoA and action registers and drafts a management summary from what they actually contain — top residual risks, decisions waiting for management, overdue actions. Empty registers are reported as empty. Also prepares your management review inputs and agenda; the minutes are written after the meeting, by you.

Per-system documents

Try saying

  • Create the documents for each of our AI systems

One impact assessment, model card and transparency notice per AI system — plus data records per dataset and a vendor questionnaire per supplier — with identification details filled in and every assessment left for the people doing it.

What changed?

Try saying

  • What changed since the previous build?

After you update your answers and rebuild, it compares the two builds and lists which documents actually changed and need re-approval — separated from documents where only version fields moved.

Review calendar

Try saying

  • Make a review calendar

Collects the review date of every document into a calendar file (.ics) for Outlook or Google Calendar, so document reviews happen instead of being discovered at the audit.

Practice an incident

Try saying

  • Prepare an incident exercise

Generates a tabletop exercise from your own incident procedure and your own systems. Run it with your team, then let the assistant help you record what actually happened — the honest way to get your first incident-register entries.

Maturity check

Try saying

  • Run the maturity self-assessment

Interviews you through the maturity workbook, area by area. The scores are your judgement — it explains what each level looks like, records your reasoning, and summarises strengths, gaps and next actions.

Add your logo

Try saying

  • Add our logo to the toolkit

Puts your logo in the top-right of every document and spreadsheet, in a fresh copy. Only the headers change — nothing in your content moves.

Check my toolkit

Try saying

  • Check my toolkit

Reports what is still unfinished: placeholders not yet replaced, how much of your SoA is decided, and any references pointing at documents that are not there.

Your AIMS in Confluence

Prefer your management system as a living wiki instead of a folder of files? Ask the assistant to publish your built, reviewed AIMS to a Confluence space. This is the structure you get:

Try saying

  • Set up our AIMS in Confluence
AIMS Home — scope, policy, status, key roles, how to report a concern
  └─ 00 Start here — manual, audit guide, version history
  └─ 01 Context and scope
  └─ 02 Leadership and policy
  └─ 03 Objectives and support
  └─ 04 AI system inventory
  └─ 05 Risks and impacts
  └─ 06 Controls and Statement of Applicability
  └─ 07 Lifecycle and data controls
  └─ 08 Use, transparency and third parties
  └─ 09 Monitoring, audit and review
  └─ 10 Improvement
  └─ Per-system documents — one page set per AI system
  └─ Registers — live tables your team keeps up to date
  • Policies, procedures and plans become readable pages, each with its document-control block on top.
  • Templates are attached with a short page explaining when to use them.
  • Evidence pages get their table structure with empty rows — the no-fabrication rule travels with the content, and Confluence page history gives real entries real timestamps.
  • After a rebuild, only pages that actually changed are updated — never pages carrying newer edits by your team.

Your AIMS in Confluence

Before publishing, you decide which copy is the controlled one — the files or the wiki — and who may edit. Document control does not stop at the wiki, and the assistant will ask you to settle this first.

One licence, one organisation

The toolkit and its assistant are licensed for use with one customer organisation. Building or branding kits for several organisations from a single licence is not permitted — each client organisation needs its own.

Implementing ISO/IEC 42001 professionally for clients? We offer reseller discounts for consultants and implementation partners — contact us. Contact us

Common questions

Do I have to answer everything in one go?

No. Anything you do not know becomes a marked gap in the documents and a line on your to-do list. Fill it in later, update your answers file, and build again.

What if something changes — a new AI system, a new owner?

Update your answers file and run the build again, then ask what changed: you get a list of exactly which documents need re-review and re-approval. Keep the answers file alongside your toolkit; it is the record of what your management system is based on.

Can it overwrite my work?

No. Every build writes to a new folder and refuses to write over one that already exists. When it records your confirmed SoA decisions in the workbook, it backs the workbook up first and only fills empty cells. Your original toolkit is never modified.

Will it fill in my audit records if I insist?

No. Seventeen documents — incident register, audit findings, management review minutes, monitoring records and similar — record things that must actually have happened. Pre-filling them is fabricating audit evidence. When something real does happen, the assistant helps you record it properly: it asks you for the facts and formats them; the facts always come from you.

I am a consultant with several clients. How does this work?

One answers file per client, one branded copy per client — with a licence for each client organisation. We offer reseller discounts for professionals implementing ISO/IEC 42001: contact us.

Does this mean I am ready to certify?

It means you have your documented management system, ready for your review — which is what a Stage 1 audit looks at. Stage 2 samples evidence that the system actually runs: audits you carried out, reviews you held, monitoring you did. That evidence only exists once you use it. No toolkit can shortcut that part.

Do not have the toolkit yet?

The assistant comes with it — 90 files covering policies, registers, risk and impact assessments, audit materials, an AI risk library, EU AI Act tools and awareness materials, for a one-time €199.