Comprehensive AI safety and alignment audit framework for businesses deploying AI agents. Built around the UK AI Security Institute Alignment Project standards (2026), EU AI Act requirements, and NIST AI RMF.
What This Skill Does
When activated, the agent performs a structured safety audit of your AI deployment:
AI System Inventory — Catalogs all AI models, agents, and automated decision systems in use
Risk Classification — Maps each system to EU AI Act risk tiers (Unacceptable/High/Limited/Minimal)
Safety Controls Assessment — Evaluates 30 controls across 6 domains
Gap Analysis — Identifies missing safeguards with severity and remediation cost
Compliance Roadmap — Generates a prioritized 90-day action plan
6 Audit Domains (30 Controls)
1. Model Governance (5 controls)
Model registry with version tracking
Access control and deployment permissions
Update and rollback procedures
Vendor risk assessment for third-party models
Model retirement and data deletion policy
2. Data Protection (5 controls)
Data residency and sovereignty mapping
PII detection and handling in AI pipelines
Training data provenance documentation
Data retention aligned with AI lifecycle
Cross-border data transfer compliance
3. Output Safety (5 controls)
Hallucination detection and mitigation
Bias testing across protected characteristics
Content filtering for harmful outputs
Confidence scoring and uncertainty flagging
Human-in-the-loop for high-stakes decisions
4. Security (5 controls)
Prompt injection defense
Model extraction prevention
API rate limiting and abuse detection
Adversarial input testing
Supply chain security for AI dependencies
5. Monitoring & Observability (5 controls)
Real-time output quality tracking
Drift detection (data and model)
Incident logging and alerting
Performance degradation monitoring
Cost tracking per AI workflow
6. Organizational Readiness (5 controls)
Named AI safety officer
Staff training program with completion tracking
Board-level AI risk reporting
Incident response playbook
Third-party audit schedule
Scoring
Each control scores 0-3:
0 — Not implemented
1 — Partially implemented, no documentation
2 — Implemented with documentation
3 — Implemented, documented, tested, and audited
Total: 90 points max
0-30: Critical risk — stop deploying until gaps are addressed
1---2name: afrexai-ai-safety-audit3description: AI Safety Audit4---5# AI Safety Audit67Comprehensive AI safety and alignment audit framework for businesses deploying AI agents. Built around the UK AI Security Institute Alignment Project standards (2026), EU AI Act requirements, and NIST AI RMF.89## What This Skill Does1011When activated, the agent performs a structured safety audit of your AI deployment:12131. **AI System Inventory** — Catalogs all AI models, agents, and automated decision systems in use142. **Risk Classification** — Maps each system to EU AI Act risk tiers (Unacceptable/High/Limited/Minimal)153. **Safety Controls Assessment** — Evaluates 30 controls across 6 domains164. **Gap Analysis** — Identifies missing safeguards with severity and remediation cost175. **Compliance Roadmap** — Generates a prioritized 90-day action plan1819## 6 Audit Domains (30 Controls)2021### 1. Model Governance (5 controls)22- Model registry with version tracking23- Access control and deployment permissions24- Update and rollback procedures25- Vendor risk assessment for third-party models26- Model retirement and data deletion policy2728### 2. Data Protection (5 controls)29- Data residency and sovereignty mapping30- PII detection and handling in AI pipelines31- Training data provenance documentation32- Data retention aligned with AI lifecycle33- Cross-border data transfer compliance3435### 3. Output Safety (5 controls)36- Hallucination detection and mitigation37- Bias testing across protected characteristics38- Content filtering for harmful outputs39- Confidence scoring and uncertainty flagging40- Human-in-the-loop for high-stakes decisions4142### 4. Security (5 controls)43- Prompt injection defense44- Model extraction prevention45- API rate limiting and abuse detection46- Adversarial input testing47- Supply chain security for AI dependencies4849### 5. Monitoring & Observability (5 controls)50- Real-time output quality tracking51- Drift detection (data and model)52- Incident logging and alerting53- Performance degradation monitoring54- Cost tracking per AI workflow5556### 6. Organizational Readiness (5 controls)57- Named AI safety officer58- Staff training program with completion tracking59- Board-level AI risk reporting60- Incident response playbook61- Third-party audit schedule6263## Scoring6465Each control scores 0-3:66- **0** — Not implemented67- **1** — Partially implemented, no documentation68- **2** — Implemented with documentation69- **3** — Implemented, documented, tested, and audited7071**Total: 90 points max**72- 0-30: Critical risk — stop deploying until gaps are addressed73- 31-55: High risk — remediate within 30 days74- 56-75: Moderate risk — address within 90 days75- 76-90: Strong posture — maintain and iterate7677## Regulatory Mapping7879| Framework | Status | Key Requirements |80|-----------|--------|-----------------|81| EU AI Act | Enforcing 2026 | Risk classification, conformity assessment, transparency |82| UK AI Safety Institute | Active 2026 | Alignment testing, frontier model evaluation |83| NIST AI RMF | Published | Govern, Map, Measure, Manage lifecycle |84| ISO 42001 | Published | AI management system certification |85| SOC 2 + AI | Emerging | Agent-specific controls (CC6/CC7/CC8) |8687## Cost Benchmarks8889| Company Size | Full Audit Cost | Annual Compliance | Non-Compliance Risk |90|-------------|----------------|-------------------|-------------------|91| 15-50 employees | $8K – $20K | $18K – $45K | $200K+ |92| 50-200 employees | $20K – $55K | $45K – $120K | $500K – $2M |93| 200-1000 employees | $55K – $150K | $120K – $400K | $2M – $10M |9495## Output Format9697The agent delivers:981. **Executive Summary** — Overall score, top 3 risks, recommended actions992. **Detailed Scorecard** — All 30 controls with scores and evidence1003. **Gap Analysis** — Missing controls ranked by risk severity1014. **90-Day Roadmap** — Phased remediation plan with cost estimates1025. **Board Report Template** — One-page summary for leadership103104## Industry Adjustments105106The audit adjusts control weighting based on industry:107- **Healthcare**: Output safety and data protection weighted 2x108- **Financial Services**: Model governance and monitoring weighted 2x109- **Legal**: Output safety (hallucination) weighted 3x110- **Manufacturing**: Security and monitoring weighted 2x111- **Government/Defense**: All domains weighted equally at maximum112113---114115## Go Deeper116117- **[AI Revenue Leak Calculator](https://afrexai-cto.github.io/ai-revenue-calculator/)** — Quantify what safety gaps cost your business118- **[Industry Context Packs ($47)](https://afrexai-cto.github.io/context-packs/)** — Pre-built compliance frameworks for your specific vertical119- **[Agent Setup Wizard](https://afrexai-cto.github.io/agent-setup/)** — Deploy agents with safety controls from day one120121### Bundles122- AI Playbook — $27123- Pick 3 Industries — $97124- All 10 Industries — $197125- Everything Bundle — $247
Run npx skillmds@latest add johnalbertini14-glitch/afrexai-ai-safety-audit in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
AI Safety Audit It is listed under Security on SkillMD.
This skill has not completed SkillMD's automated safety review yet. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
johnalbertini14-glitch (@johnalbertini14-glitch) published this skill. Their other Agent Skills are listed on their SkillMD profile.