- Home
- Skills
- Legal & Compliance
- AI Governance Policy Builder (EU AI Act, ISO 42001)
Works with the AI tools you already use
AI Governance Policy Builder (EU AI Act, ISO 42001)
Stand up an AI governance program — classify your AI by risk and map it to the EU AI Act, NIST AI RMF, and ISO/IEC 42001. Guidance, not legal advice.
$12
AI Governance Policy Builder (EU AI Act, ISO 42001)
Example session with this skill installed
We are a retail company deploying a third-party AI tool for resume screening in our HR department. We operate in the EU. Classify our risk under the EU AI Act and outline the controls we need.
- Read your context and instructions
- Compiled the ai governance policy
I have analyzed your HR resume screening tool deployment. As you are using a third-party tool in a professional context, you are primarily classified as a
Deployer under the EU AI Act.
AI Governance Assessment: HR Resume Screening
| Category | Detail |
|---|---|
| System Name | HR Recruitment AI (Third-party) |
| EU AI Act Tier | High-Risk (Annex III: Employment, workers management and access to self-employment) |
| Organisational Role | Deployer (User) |
| Primary Frameworks | EU AI Act Art. 26 (deployer obligations) + Art. 27 (Fundamental Rights Impact Assessment, where applicable); NIST AI RMF (Map, Govern); ISO/IEC 42001 §8 (Operational Planning and Control) |
| Data Sensitivity | High (candidate PII, potential special-category data if the tool infers protected characteristics) |
Required Governance Controls
Human oversight: Assign a named reviewer with authority to override or reject AI-driven screening outcomes before any hiring decision is finalized (Art. 26(2)).
Instructions compliance: Confirm use strictly follows the third-party provider's instructions for use; document any deviation (Art. 26(1)).
Input data governance: Where you control input data (e.g., CVs, scoring criteria), ensure it is relevant and representative for the tool's intended purpose.
- Log retention: Retain automatically generated logs for at least six months (Art. 26(6)).
Worker notification: Inform affected candidates and, where applicable, workers' representatives that an AI system is used in the recruitment process.
Fundamental Rights Impact Assessment (FRIA): Confirm whether your organisation falls within the categories required to complete a FRIA before deployment (Art. 27) — applies to certain public bodies and private entities providing public services; verify applicability for your case.
ISO/IEC 42001 alignment: Document this system in your AI asset register, map it to operational controls (§8), and include it in ongoing performance evaluation (§9).
Note on timing: Annex III high-risk obligations for employment-related AI were extended by the Digital Omnibus — verify the current applicable date for your system category at eur-lex.europa.eu before treating any deadline as fixed.
Next steps
- Add this system to your AI asset register with the High-Risk (Annex III) tier and Deployer role recorded.
- Confirm with the third-party provider whether they have completed conformity assessment and CE marking as a high-risk AI provider.
- Determine FRIA applicability for your organisation type before go-live.
- Draft or update your AI usage policy to disclose AI-assisted screening to candidates.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
A governance-in-a-box advisor for teams putting AI oversight in place. From your inventory of AI systems and a little context, it classifies each system by risk against the EU AI Act tiers (including Annex III high-risk and general-purpose AI), builds a reusable AI asset register, drafts an acceptable-use policy, and assembles a governance framework — roles, lifecycle gates, oversight — aligned to the NIST AI RMF, with a control crosswalk to ISO/IEC 42001 and the evidence to keep.
It's for the person handed "get us AI-governance-ready" — a CISO, DPO, compliance lead, or founder — who needs structured starting-point artifacts fast, not a blank page or a generic template. Use it to stand up a program from scratch, classify systems against the EU AI Act, inventory shadow AI, draft an AI usage policy, or find the gaps in a posture you already have.
It is guidance, not legal advice. Outputs are starting points for a qualified lawyer, DPO, or compliance professional to review before adoption — it does not determine your legal obligations or certify compliance, and it won't understate a system's risk tier to reduce obligations. Because AI regulation is phased and moving, it never bakes in a deadline or penalty figure; it points every regulatory specific to the official source to confirm for your category. It aligns you to ISO/IEC 42001 but does not replace third-party certification, technical AI-security testing, or SOC 2 / ISO 27001 audit readiness.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 11 days ago
- Passed all security checks, Safe to install