Unfortunately, there is no such tool that talks about converting from internal to external security.
Running the detail security report would be a good way to see everything you have defined at the moment.
Then SYSVIEW 16.0 documentation describes what the SAF/RACF entity names need to look like:
Implement External Security (SAF)
Conceptually, external checking is done in the same manner that internal security is structured (product interfaces, commands, subcommands, jobname actions, resources) but you just have to define the corresponding entity names.