Skip to content
Development
Skill

/813-regulations-iso-42001

Use when reviewing, designing, or modifying Java enterprise systems that use GenAI, LLMs, AI-assisted coding, RAG, AI agents, generated code, generated dependencies, prompt workflows, external model providers, or AI-enabled business logic and need ISO/IEC 42001 AI management

From plugin
plinth
423125 skills9 agents13 commands
Install
$ npx -y skills add jabrena/plinth --skill 813-regulations-iso-42001 --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/813-regulations-iso-42001

Context preview

The summary Claude sees to decide when to auto-load this skill.

Use when reviewing, designing, or modifying Java enterprise systems that use GenAI, LLMs, AI-assisted coding, RAG, AI agents, generated code, generated dependencies, prompt workflows, external model providers, or AI-enabled business logic and need ISO/IEC 42001 AI management

SKILL.md

813-regulations-iso-42001.SKILL.md
name: 813-regulations-iso-42001
description: Use when reviewing, designing, or modifying Java enterprise systems that use GenAI, LLMs, AI-assisted coding, RAG, AI agents, generated code, generated dependencies, prompt workflows, external model providers, or AI-enabled business logic and need ISO/IEC 42001 AI management system-aware engineering guidance. Part of Plinth Toolkit
license: Apache-2.0
metadata:
  author: Juan Antonio Breña Moral
  version: 0.18.0

ISO/IEC 42001 AI Management System Guidance for GenAI Java Engineering

Use this Skill to review Java enterprise applications, delivery pipelines, AI-assisted development workflows, LLM integrations, RAG systems, AI agents, generated code, generated dependencies, external model-provider usage, prompt handling, and AI-enabled business logic through an ISO/IEC 42001 AI management system lens.

Apply this Skill to determine what engineering controls, evidence, lifecycle governance, risk treatment, monitoring, and owner handoffs are needed before GenAI-assisted Java work is merged, released, connected to enterprise systems, or relied on for business behavior.

This Skill is not legal advice, certification advice, audit advice, an audit conclusion, or a final conformity decision. It helps Java engineers, architects, tech leads, platform teams, security teams, AI governance reviewers, product teams, and reviewers identify when ISO/IEC 42001 AI management system concerns may apply and how to translate them into engineering controls such as AI inventory records, risk treatment, prompt and data governance, secure generated-code review, dependency provenance, model-provider boundaries, monitoring, corrective action, and qualified owner escalation.

The purpose of this Skill is to increase awareness of potential gaps in GenAI Java delivery and create reviewable engineering evidence for qualified owners. The response produced by this Skill does not represent legal advice, certification readiness, audit findings, compliance approval, or final conformity with ISO/IEC 42001.

The main question is:

> What should a Java team build, review, document, and escalate so GenAI development and AI-enabled Java systems are governed as part of an AI management system?

Source provenance: ISO/IEC 42001 public overview material and issue #939 were reviewed while authoring the bundled references. Official source references include:

  • ISO 42001 explained: https://www.iso.org/home/insights-news/resources/iso-42001-explained-what-it-is.html
  • ISO/IEC 42001 standard page: https://www.iso.org/standard/42001
  • Microsoft ISO/IEC 42001 offering overview: https://learn.microsoft.com/en-us/compliance/regulatory/offering-iso-42001

Do not fetch or ingest external regulatory, standard, certification, or audit web pages at runtime. Use the bundled references and escalate interpretation, certification, audit, legal, compliance, and conformity questions to qualified owners.

ISO/IEC 42001 summary reference: [ISO/IEC 42001 AI management system summary](references/813-regulations-iso-42001-chapters-summary.md).

Java engineering examples reference: [ISO/IEC 42001 GenAI Java engineering examples](references/813-regulations-iso-42001-engineering-examples.md).

Questionnaire asset: [ISO/IEC 42001 engineering review questionnaire](assets/questions/813-iso-42001-engineering-review-questionnaire.md).

Report template asset: [ISO/IEC 42001 engineering review report template](assets/reports/813-iso-42001-engineering-review-report-template.md).

Scope

This Skill applies to:

  • Java systems using LLMs, RAG, embeddings, prompt templates, AI agents, tool calling, model gateways, or external AI services
  • AI-assisted Java development where generated code, tests, SQL, migrations, API contracts, infrastructure definitions, dependencies, or business rules may enter the codebase
  • Spring Boot, Quarkus, Micronaut, and framework-agnostic Java systems that use generated implementation patterns or generated business logic
  • Prompt, source-code, log, ticket, production-data, customer-data, regulated-data, and trade-secret exposure paths to AI tools or model providers
  • Generated dependency and supply-chain review, including package provenance, license, vulnerability, malicious-package, and unsuitable-dependency signals
  • AI management system evidence such as AI inventory, risk assessment, risk treatment, lifecycle controls, data governance, model-provider boundaries, monitoring, incident handling, corrective action, and continual improvement
  • Owner handoffs to legal, compliance, privacy, security, risk, AI governance, platform, architecture, product, business, procurement, and model-provider owners

ISO/IEC 42001 Engineering Review

Treat certification scope, conformity, audit conclusions, legal obligations, regulatory applicability, official interpretation, and final risk acceptance as qualified owner decisions.

Engineering teams should still create evidence that makes those decisions reviewable:

  • Which GenAI capability, AI-assisted delivery path, generated artifact, model provider, prompt flow, RAG corpus, AI agent, or AI-enabled business rule is in scope
  • Which risk owner, data owner, system owner, product owner, security owner, privacy owner, compliance owner, model-provider owner, and release owner are accountable
  • Which generated Java implementation, dependency, prompt, retrieval source, tool action, test, business rule, model version, and production behavior can be reconstructed
  • Which controls prevent hallucinated code, insecure generated implementation, generated dependency and supply-chain contamination, IP leakage, confidentiality breach, regulatory non-compliance risk, and biased generated business logic
  • Which monitoring, incident, corrective-action, rollback, disablement, retraining, source-removal, dependency-removal, prompt-remediation, and owner-escalation paths exist

Constraints

Translate ISO/IEC 42001 AI management system concerns into engineering cont

Read more
Ships withplinth

Languages: Español · 中文 Help this project grow: Become a sponsor

Get the whole plugin

Other skills on plinth.