Agent skill · magnus919
ai-governance
Design and operate an organization's AI governance system: define governance principles, operating models and decision rights, risk frameworks, lifecycle gates, and fairness, transparency, privacy, security, regulatory, and board-oversight controls. Use when standing up a governance program, tiering AI use-case risk, reviewing an LLM or agent system for governance and safety gaps, mapping a regulation to a compliance plan, scoring governance maturity, or preparing board reporting. For regulated life-sciences use cases, also cover GxP, ALCOA+, data integrity, electronic records, validation/assurance, and QMS interfaces. Do not use for interpreting regulations as legal advice (route to legal-strategy), data-governance mechanics (data-architect/data-engineering), or implementing application security (secure-software-engineering).
What it needs
About 5k tokens when loaded.
What this skill does
AI Governance AI governance is the system an organization uses to decide, before a model is built and while it runs, who is accountable for an AI system, what risk it is allowed to carry, what evidence must gate each lifecycle stage, and how the organization reports and audits that posture. This skill teaches an agent to reason about and operate that system: it is a methodology skill, not a tool manual and not legal or security advice. Scope: What This Skill Owns You own You don't own --------- --------------- Governance principles and how they translate into policy and controls Drafting or opining on legal interpretation of a regulation The governance operating model: councils, stewards, decision rights, RACI, federated vs. centralized Data-platform mechanics, pipelines, and lineage tooling internals Risk frameworks: NIST AI RMF, ISO/IEC 42001 & 23894, model-risk tiering, risk registers Implementing authentication, authorization, or vulnerability fixes Lifecycle stage gates across ideation, build, evaluate, deploy, monitor, retire CI/CD pipeline and deployment-gate configuration Fairness, bias, transparency, explainability, and accountability controls Product portfolio/roadmap governance cadences Privacy and data governance for training and operational data Capital allocation, org structure, or M&A governance GxP AI governance overlay: ALCOA+, data integrity, electronic records, risk-based assurance, QMS interfaces Legal applicability determinations, validation protocols, SOPs, or quality-system operation LLM/agent safety: prompt injection, excessive agency, red-teaming, supply chain Host-level or application-level security scanning Regulatory landscape and compliance mapping (as guidance, not advice) Legal drafting, regulatory filings, or attorney-client work product Third-party and model due diligence, board reporting, audit Any authoritative statement of "your system is compliant" This is a prevention-and-operations methodology: it gives the agent frameworks, de …
How to use it
Reference it in AdaL, Claude Code, Cursor or any coding agent — nothing to install:
@skills magnus919/ai-governance