iso-standards-readiness
정보
이 스킬은 개발자가 ISO 13485 및 17025와 같은 표준에 대한 증빙 파일을 구성하고 검토하는 데 도움을 주며, 문서, 리스크 파일, 인증 범위를 구조화합니다. 외부 종속성 없이 로컬 JSON/Markdown을 사용하여 다양한 규제 프레임워크(FDA, MDR 등)에 대한 증빙 경계를 구분합니다. 규정 준수 결정을 내리는 용도가 아닌, 감사 대비 문서를 준비하는 데 사용하십시오.
빠른 설치
Claude Code
추천npx skills add K-Dense-AI/claude-scientific-skills -a claude-code/plugin add https://github.com/K-Dense-AI/claude-scientific-skillsgit clone https://github.com/K-Dense-AI/claude-scientific-skills.git ~/.claude/skills/iso-standards-readinessClaude Code에서 이 명령을 복사하여 붙여넣어 스킬을 설치하세요
문서
ISO Standards Readiness Evidence Preparation
Purpose
Use this skill to organize declared scope, controlled documents, implementation records, traceability, and readiness evidence for substantive human review against a named standard. It summarizes process workflows and provides deterministic local checks. It contains no clause text and performs no audit.
This is a router. SKILL.md holds the boundary, the lane discipline, the shared
workflow, and the CLI contract. Per-standard depth lives in references/.
Non-negotiable boundary
This skill cannot:
- certify or accredit anything, issue or validate a certificate, accreditation schedule, or licence, or promise an audit, assessment, or inspection result;
- determine legal/regulatory applicability, device classification, reportability, conformity route, product authorization, market access, licensure, personnel qualification, or compliance;
- replace authorized management, the management representative, laboratory director, quality manager, authorized signatory, RA/QA, legal counsel, regulatory/competent authorities, a notified body, an MDSAP Auditing Organization, an accreditation body, an assessor, or a certification body;
- validate a method, compute or approve measurement uncertainty, establish metrological traceability, set risk-acceptability criteria, or judge whether a risk, decision rule, or reference interval is fit for purpose; or
- infer implementation, competence, conformity, compliance, or readiness from a template, checklist, filename, keyword, document count, percentage, or script result.
Always label outputs draft evidence-preparation material for authorized human review. Preserve unresolved decisions as blockers rather than resolving them.
ISO and IEC copyright
ISO and IEC standards are copyrighted. Obtain each standard from ISO, IEC, an ISO national member, or another authorized source. Do not retrieve, paste, reproduce, or generate clause text. Summarize the organization's own process and cite the controlled authorized copy. See ISO copyright. Accreditation-body, CAP, and scheme checklists that quote requirements are separately licensed — keep them out of shared repositories and prompts too.
Standards covered
Read the reference file for the standard in play before preparing evidence. Each one carries its own current edition, lane, domain vocabulary, and failure modes.
| Standard | Profile key | Lane | Reference |
|---|---|---|---|
| ISO 13485 medical device QMS | iso-13485 | Certification | references/iso-13485.md |
| ISO 14971 device risk management | iso-14971 | No lane of its own | references/iso-14971.md |
| ISO/IEC 17025 testing and calibration laboratories | iso-17025 | Accreditation | references/iso-17025.md |
| ISO 15189 medical laboratories | iso-15189 | Accreditation | references/iso-15189.md |
A standard absent from this table is out of scope for the bundled checks. Do not repurpose a profile for a standard it does not name — a domain vocabulary borrowed from a different standard produces a report that looks complete and means nothing.
Current baseline (read the ledger before any time-sensitive statement)
- ISO 13485:2016 Edition 3, confirmed after its 2025 systematic review. EN ISO 13485:2016/A11:2021 is a European amendment, not an ISO international "Amendment 1:2021."
- ISO 14971:2019 Edition 3, confirmed in 2025, with ISO/TR 24971:2020 as its informative guidance companion. There is no ISO 14971 certificate.
- ISO/IEC 17025:2017 Edition 3 remains current; no successor edition identified.
- ISO 15189:2022 Edition 4 replaced the 2012 edition, absorbed the POCT requirements formerly in ISO 22870, and its accreditation transition closed in December 2025 — implemented, not upcoming.
- FDA QMSR effective and enforced since 2026-02-02; Part 820 is titled Quality Management System Regulation; QSIT is retired in favour of Compliance Program 7382.850.
- MDSAP current Audit Approach is MDSAP AU P0002.010, version date 2026-02-02.
- Accreditation recognition: Global Accreditation Cooperation Incorporated commenced full operations 2026-01-01, replacing ILAC and IAF, with its own MRA; former IAF MLA / ILAC MRA outputs stay recognized during the transition.
- EU: use current consolidated MDR/IVDR texts, current OJEU harmonised-standard decisions, current MDCG guidance, and the product-specific conformity route.
Read references/source-ledger.md before making any time-sensitive statement. It
records provenance limitations, including which entries still need confirmation against
the ISO catalogue.
Keep the assurance lanes separate
Lane confusion, not missing documents, causes most substantive errors here. Certification, accreditation, regulator inspection, mandatory licensure, regulatory audit programmes, and product conformity assessment are decided by different bodies against different bases, and none substitutes for another. Two rules that are violated constantly:
- Organizations are certified; laboratories are accredited. "ISO 17025 certified" and "ISO 15189 certified" are category errors.
- A certificate never displaces a regulator. ISO 13485 certification does not exempt anyone from FDA inspection, and ISO 15189 accreditation does not satisfy CLIA.
Read references/assurance-lanes.md for the full lane table, scope-statement limits,
and the titling rule.
Core workflow
Step 1: Declare the standard, purpose, and authorized owners
Name the standard(s), the lane(s) the work supports, and the owners: management representative or laboratory director, quality owner, legal/applicability owner, process or technical owners, approvers, and escalation route. A lane is a declared input, never an inference.
PYTHONDONTWRITEBYTECODE=1 python3 scripts/validate_scope_intake.py \
assets/templates/scope-intake-template.json --standard iso-13485
Use the matching template and profile:
| Profile | Template |
|---|---|
iso-13485, iso-14971 | assets/templates/scope-intake-template.json |
iso-17025 | assets/templates/laboratory-scope-intake-template.json |
iso-15189 | assets/templates/medical-laboratory-scope-intake-template.json |
--standard defaults to iso-13485. Every distributed template intentionally fails
closed; copy it outside the skill and complete it with controlled organizational
evidence. Undetermined applicability raises HUMAN_DECISION_REQUIRED — leave it as a
blocker.
Step 2: Freeze source/version evidence
For every standard, regulation, guidance, scheme document, audit model, and product source, record publisher, official title, edition/version/date, authorized location, access and currency-review dates, scope/applicability owner, impact assessment, status, evidence, and approval.
Do not use search snippets as controlled requirements. Do not silently update an incorporated edition when a publisher releases a new one — FDA incorporated a specific ISO 13485 edition, and a later ISO or EN publication does not change it.
Step 3: Inventory controlled documents and records
Do not count named procedures or scan keywords. Build an explicit register linking documents, records, source versions, owners, approvals, effective dates, retention bases, training, and change records.
PYTHONDONTWRITEBYTECODE=1 python3 scripts/audit_document_records.py \
assets/templates/document-register-template.json
This check is standard-agnostic. Read references/evidence-architecture.md for the
evidence architecture.
Step 4: Review process implementation
Assess controlled procedures and sampled records across the domains your profile declares — the per-standard reference file lists them. Each item needs owner, status, evidence IDs, source/version, approval, and open-gap links.
A procedure describing an activity is not evidence the activity happened. Sample records in every domain you report on, and state what you sampled and what you did not.
Step 5: Run the focused checks that apply to the lane
Device lanes (iso-13485, iso-14971) — risk/design/production/post-market chain:
PYTHONDONTWRITEBYTECODE=1 python3 scripts/check_traceability.py \
assets/templates/traceability-matrix-template.json
All standards — corrective action and effectiveness:
PYTHONDONTWRITEBYTECODE=1 python3 scripts/check_capa.py \
assets/templates/capa-record-template.json
All standards — suppliers and externally provided products and services, including calibration providers, reference-material suppliers, and referral or subcontracted laboratories:
PYTHONDONTWRITEBYTECODE=1 python3 scripts/check_supplier_controls.py \
assets/templates/supplier-controls-template.json
Pending or ineffective CAPA effectiveness evidence blocks closure. Critical supplier controls stay blocked until risk-based controls and approvals are evidenced.
Note that check_traceability.py concerns design and risk traceability, not
metrological traceability — the words collide and it is the wrong tool for laboratory
work.
Step 6: Address lane-specific regulator evidence separately
For the US device lane only:
PYTHONDONTWRITEBYTECODE=1 python3 scripts/check_qmsr_transition.py \
assets/templates/qmsr-transition-template.json
Review current Part 820/FDA source basis, supplemental provisions, obsolete QSR/QSIT references, pre-effective-date records, inspection-accessible management/quality/ supplier-audit records, current inspection-process training, complaint and servicing records, labeling/packaging controls, supplier/software/change evidence, and prohibited certificate-equivalence claims. Do not build an old-820-to-ISO clause map as the current control framework.
Laboratory lanes have no equivalent bundled check. CLIA, licensure, and national
inspection evidence stays with the authorized compliance owner; see
references/iso-15189.md.
Step 7: Assemble a bounded readiness manifest
Copy the evidence template outside the skill. Use relative paths to local .json,
.md, or .markdown evidence only, and one declared lane purpose per manifest.
PYTHONDONTWRITEBYTECODE=1 python3 scripts/validate_evidence_manifest.py \
/path/to/evidence-manifest.json \
--standard iso-17025 \
--base-dir /path/to/controlled-export \
--verify-files \
--output /path/to/manifest-report.json
Then generate a domain-level gap view against the same profile:
PYTHONDONTWRITEBYTECODE=1 python3 scripts/gap_analyzer.py \
/path/to/evidence-manifest.json \
--standard iso-17025 \
--base-dir /path/to/controlled-export \
--verify-files \
--output /path/to/gap-report.json
The analyzer uses explicit manifest labels. It does not infer evidence from filenames,
keywords, or proprietary standard text, and does not calculate a compliance score. A
domain absent from expected_domains is reported not-assessed, which is not a
not-applicable determination.
Read references/gap-analysis-checklist.md for the fail-closed review questions.
Step 8: Human review and controlled handoff
Present:
- declared standard, scope, assurance lane(s), and unresolved applicability decisions;
- the exact source/version baseline;
- evidence sampled and the limitations of that sample;
- structural findings grouped by process and risk;
- actions, change, and CAPA owners with dates;
- approval state; and
- the authorized party responsible for the next decision.
Never title the result "certificate," "accreditation," "compliance report," "audit pass," "deemed status," or "ready for inspection." A suitable title is Draft evidence review for authorized human assessment, naming the lane it was prepared for.
CLI behavior and safety
All bundled CLIs:
- use the Python standard library only;
- perform no network requests;
- accept bounded local JSON; optional evidence verification accepts only bounded local JSON/Markdown;
- reject symbolic-link inputs, duplicate JSON keys, non-finite numbers, excessive size/nesting/items, and unsafe evidence paths;
- refuse an unlisted
--standardvalue rather than falling back to a default; - use no dynamic evaluation, executable deserialization, pickle, or shell execution;
- refuse to overwrite reports unless
--forceis explicit; and - produce deterministic sorted JSON.
Treat the manifest itself as a controlled organizational record. An optional SHA-256
comparison detects a local file mismatch only; it does not establish provenance,
authenticity, adequacy, or trust in a user-supplied manifest. Values in JSON
local_path and evidence.location fields refer to the user's controlled export, not
to bundled skill resources; unresolved placeholders must never be opened.
Exit codes:
0: no structural finding for the supplied fields; not a compliance, conformity, competence, or accreditation result;1: structural/evidence gaps found;2: invalid or unsafe input/output, including an unlisted standard.
Run python3 scripts/<name>.py --help for each interface.
Templates
Scope intake, per profile:
assets/templates/scope-intake-template.json— device lifecycleassets/templates/laboratory-scope-intake-template.json— testing/calibrationassets/templates/medical-laboratory-scope-intake-template.json— examinations
Shared registers and records:
assets/templates/document-register-template.jsonassets/templates/capa-record-template.jsonassets/templates/traceability-matrix-template.jsonassets/templates/supplier-controls-template.jsonassets/templates/evidence-manifest-template.jsonassets/templates/qmsr-transition-template.json— US device lane only
Management-system documentation:
assets/templates/quality-manual-template.mdassets/templates/procedures/CAPA-procedure-template.mdassets/templates/procedures/document-control-procedure-template.md
Every template is deliberately draft/pending, uses placeholders, and includes
owner/status/evidence/approval fields. Copy and control it; never edit a distributed
template into a purported approved record.
References
Shared:
references/assurance-lanes.md— what each lane decides, and the titling rulereferences/source-ledger.md— dated authoritative source baseline and provenance limitationsreferences/evidence-architecture.md— documentation and record architecturereferences/gap-analysis-checklist.md— fail-closed evidence review questionsreferences/quality-manual-guide.md— controlled manual development
Per standard:
references/iso-13485.md— device QMS process/evidence framework, QMSR, MDSAP, EUreferences/iso-14971.md— risk-management chain and the missing-link failure modesreferences/iso-17025.md— laboratory competence, traceability, uncertainty, and decision rulesreferences/iso-15189.md— medical laboratories, POCT, reporting, and the CLIA lane
GitHub 저장소
자주 묻는 질문
iso-standards-readiness Skill이란 무엇인가요?
iso-standards-readiness은(는) K-Dense-AI이(가) 만든 Claude Skill입니다. Skill은 Claude가 필요할 때 불러오는 지침과 리소스를 묶어 추가 프롬프트 없이 iso-standards-readiness 관련 작업을 수행할 수 있게 합니다.
iso-standards-readiness은(는) 어떻게 설치하나요?
이 페이지의 설치 명령을 사용하세요. iso-standards-readiness을(를) Claude Code 플러그인으로 추가하거나 저장소를 skills 디렉터리에 복제한 다음 Claude를 다시 시작해 Skill을 불러옵니다.
iso-standards-readiness은(는) 어떤 카테고리에 속하나요?
iso-standards-readiness은(는) 테스팅 카테고리에 속합니다.
iso-standards-readiness은(는) 무료로 사용할 수 있나요?
네. iso-standards-readiness은(는) AIMCP에 등록되어 있으며 무료로 설치할 수 있습니다.
연관 스킬
이 Claude Skill은 MMLU, GSM8K를 포함한 60개 이상의 표준화된 학술 과제에서 LLM 성능을 벤치마크하기 위해 lm-evaluation-harness를 실행합니다. 개발자들이 모델 품질을 비교하고, 학습 진행 상황을 추적하거나 학술 결과를 보고할 수 있도록 설계되었습니다. 이 도구는 HuggingFace와 vLLM 모델을 포함한 다양한 백엔드를 지원합니다.
이 스킬은 cron 표현식을 사용하여 Worker를 스케줄링하기 위한 Cloudflare Cron Triggers 구현에 관한 포괄적인 지식을 제공합니다. 주기적 작업, 유지보수 작업, 자동화된 워크플로우 설정 방법을 다루며, 잘못된 cron 표현식이나 시간대 문제 같은 일반적인 이슈들을 해결하는 방법을 포함합니다. 개발자들은 이를 통해 스케줄된 핸들러 구성, cron 트리거 테스트, Workflows 및 Green Compute와의 연동 작업을 수행할 수 있습니다.
이 Claude Skill은 Python 스크립트를 통해 로컬 웹 애플리케이션을 테스트하기 위한 Playwright 기반 툴킷을 제공합니다. 프론트엔드 검증, UI 디버깅, 스크린샷 캡처, 로그 확인 기능을 지원하며 서버 라이프사이클을 관리합니다. 브라우저 자동화 작업에 사용하되 컨텍스트 오염을 방지하기 위해 소스 코드를 읽지 않고 스크립트를 직접 실행하세요.
이 스킬은 테스트 통과를 확인한 후 체계적인 통합 옵션을 제시하여 개발자가 완성된 작업을 마무리하도록 돕습니다. 구현이 완료된 후 머지, PR 생성, 브랜치 정리와 같은 워크플로우를 안내합니다. 코드가 준비되고 테스트가 완료되었을 때 개발 프로세스를 체계적으로 마무리하기 위해 사용하세요.
