Install any skill in seconds. Free to start, no credit card required.
Get Started Free →/cs:iso27001-audit-prep <scope> — ISO 27001 ISMS audit readiness 6-question forcing interrogation. Use before annual Clause 9.2 internal audit, surveillance audit prep, or stage 1 certification readiness.
.claude/skills/alirezarezvani-iso27001-audit-prep/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | -26% | 0% |
| case-03 | ✗→✓ | ▲ Improved | -24% | 0% |
| case-12 | ✗→✓ | ▲ Improved | 98% | 0% |
| case-17 | ✗→✓ | ▲ Improved | 16% | 0% |
| case-19 | ✗→✓ | ▲ Improved | 2% | 0% |
Command: /cs:iso27001-audit-prep <scope>
The ISO 27001 ISMS auditor pressure-tests any ISMS work. Six sample-driven questions before any internal audit, stage 1 readiness, or surveillance audit.
No 3-year coverage discipline, no defensible programme.
isms_audit_scheduler.py in ra-qm-team/skills/isms-audit-expert/Stale risk register = certification finding.
iso27001_audit_playbook.md for stage 1 expectationsMost-cited finding area.
Second-most-cited finding area.
A.5.24-27 + A.6.8 — high-stakes audit area.
Clause 9.3 required inputs are prescriptive — easy to miss.
multi_framework_audit_playbook.md) preferred to separate reviewsbash# 1. Audit programme planning python ra-qm-team/skills/isms-audit-expert/scripts/isms_audit_scheduler.py audit_scope.json # 2. Mock audit for readiness check python ../../skills/compliance-os/scripts/audit_simulator.py iso27001_scope.json # 3. Cross-framework reuse (SOC 2 = 75% overlap; ISO 42001 = 60% reuse) python ../../skills/compliance-os/scripts/cross_framework_mapper.py program.json
markdown# ISO 27001 Audit Prep: <scope> **Date:** YYYY-MM-DD ## The Decision Being Made [programme-plan | finding-severity | cert-readiness | incident-followup] ## Audit Programme Status - Clauses scheduled this year: <list> - Annex A controls scheduled: <count> - Rolling 3-year coverage: clean | gaps in <list> - Auditor independence: clean | issues in <list> ## Risk Register Health - Last refresh: YYYY-MM-DD - High/critical risks without Annex A control link: N - Residual risk acceptance documentation: complete | gaps ## High-Stakes Controls Status - A.5.15 + A.8.2 + A.8.3 access control: pass/fail with sample - A.5.19-A.5.21 supplier mgmt: pass/fail with sample - A.5.24-27 + A.6.8 incident response: pass/fail with sample - A.8.15-16 logging: pass/fail with sample ## Management Review Status - Last review date: YYYY-MM-DD - Required Article 9.3 inputs present: yes/no - Open action items past due: N ## Cross-Framework Impact - SOC 2 controls affected: <list> - ISO 42001 controls affected (if applicable): <list> - GDPR Article 32 controls affected: <list> ## Verdict 🟢 READY | 🟡 CLOSE-CRITICALS-FIRST | 🔴 NOT-READY ## Top 3 Actions [3 concrete next steps with owner + corrective-action timeline]
/cs:compliance-readiness — for multi-framework view/cs:soc2-audit-prep — for SOC 2 cross-walk pair (75% overlap)/cs:aims-audit — for ISO 42001 AIMS cross-walk/cs:gdpr-audit-prep — for Article 32 organizational measures overlap/cs:ciso-review — for executive cybersecurity strategy/cs:decide — to log the verdictcs-ciso-iso27001isms-audit-expert../soc2-audit-prep/, ../aims-audit/, ../gdpr-audit-prep/, ../compliance-readiness/Version: 1.0.0
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-21 | pass→pass | 11,053 | 10,679 | -3% | 1 | 1 | 0% | 1,916 | 3,572 | +86% | 0 | 0 | — |
case-22 | pass→pass | 16,611 | 15,614 | -6% | 1 | 1 | 0% | 2,800 | 4,285 | +53% | 0 | 0 | — |
case-14 | pass→pass | 10,018 | 9,640 | -4% | 1 | 1 | 0% | 1,780 | 3,372 | +89% | 0 | 0 | — |
case-15 | pass→pass | 13,372 | 15,310 | +14% | 1 | 1 | 0% | 2,594 | 4,384 | +69% | 0 | 0 | — |
case-01 | fail→pass | 33,580 | 15,833 | -53% | 1 | 1 | 0% | 6,257 | 4,629 | -26% | 0 | 0 | — |
case-02 | fail→fail | 36,765 | 17,890 | -51% | 1 | 1 | 0% | 6,248 | 4,949 | -21% | 0 | 0 | — |
case-03 | fail→pass | 28,155 | 13,132 | -53% | 1 | 1 | 0% | 5,183 | 3,960 | -24% | 0 | 0 | — |
case-04 | pass→pass | 13,943 | 8,675 | -38% | 1 | 1 | 0% | 2,323 | 3,254 | +40% | 0 | 0 | — |
case-05 | pass→pass | 9,550 | 8,043 | -16% | 1 | 1 | 0% | 1,584 | 3,015 | +90% | 0 | 0 | — |
case-20 | pass→pass | 17,363 | 16,291 | -6% | 1 | 1 | 0% | 3,027 | 4,512 | +49% | 0 | 0 | — |
case-06 | pass→pass | 11,666 | 11,455 | -2% | 1 | 1 | 0% | 2,011 | 3,553 | +77% | 0 | 0 | — |
case-07 | fail→fail | 10,593 | 8,511 | -20% | 1 | 1 | 0% | 1,846 | 2,988 | +62% | 0 | 0 | — |
case-08 | pass→pass | 9,344 | 8,392 | -10% | 1 | 1 | 0% | 1,616 | 3,046 | +88% | 0 | 0 | — |
case-09 | pass→pass | 13,579 | 8,802 | -35% | 1 | 1 | 0% | 2,074 | 3,180 | +53% | 0 | 0 | — |
case-10 | pass→pass | 10,674 | 13,868 | +30% | 1 | 1 | 0% | 1,926 | 4,167 | +116% | 0 | 0 | — |
case-11 | pass→pass | 15,141 | 18,752 | +24% | 1 | 1 | 0% | 2,553 | 5,067 | +98% | 0 | 0 | — |
case-12 | fail→pass | 11,037 | 11,484 | +4% | 1 | 1 | 0% | 1,853 | 3,665 | +98% | 0 | 0 | — |
case-13 | pass→pass | 6,602 | 8,701 | +32% | 1 | 1 | 0% | 1,200 | 3,211 | +168% | 0 | 0 | — |
case-16 | pass→pass | 14,179 | 17,215 | +21% | 1 | 1 | 0% | 2,598 | 4,792 | +84% | 0 | 0 | — |
case-17 | fail→pass | 9,273 | 1,927 | -79% | 1 | 1 | 0% | 1,635 | 1,896 | +16% | 0 | 0 | — |
case-18 | fail→fail | 8,270 | 1,358 | -84% | 1 | 1 | 0% | 1,447 | 1,828 | +26% | 0 | 0 | — |
case-19 | fail→pass | 10,863 | 1,520 | -86% | 1 | 1 | 0% | 1,901 | 1,945 | +2% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +23 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.