ISO/IEC 42001 — current attestation · Stage 1 audit · 2027-Q1

Framework · ISO 42001

ISO 42001 — AI management system.

ISO/IEC 42001 covers the AI management system — the AIMS controls that govern every model that pulls a lever. This page walks the framework, the controls in scope, and how to request the latest report.

ISO/IEC 42001 is the framework that audits Helmsway's AI control tower — the system that decides which model pulls which lever, on which signal, at which corridor. It tells a security reviewer that AI governance isn't a policy document behind an NDA; it is the same controls the operational platforms run, with named owners, residual-risk tiers and quarterly review windows.

Internal audit + AIMS review

Audit cadence · AIMS

AIMS review window — quarterly AI risk-register review against the assessment row the auditor pulls at the next surveillance window, plus a six-month internal audit that diffs the AI risk register line-by-line against the AIMS controls in scope below and the Helmsway levers they govern.

Statement of applicability — AIMS

Every AIMS control family, declared.

The AIMS SoA booklet names every Annex A control family applicable to the AI system — applicable, not-applicable or justified-exclusion — with a one-line rationale per row. The auditor diffs the named rows against the next surveillance find; the prose is the framing, the rows are the test.

Levers under AIMS

Four automations. One named owner per lever.

Every AIMS control area in scope above maps onto a specific Helmsway automation. The four-card grid below names each lever and the AIMS controls that gate it — the inverse-direction reading a security reviewer expects after the Annex A walkthrough.

Data sources

Where the AIMS draws its input from.

The four connectors below feed the platform the data the AIMS-governed models act on. Each connector ships with its own data-scope page so a reviewer reads the connector surface, the data lineage pointer, and the eval-suite gate in one pass.

AIMS risk treatment plan

How each named AIMS risk is treated.

Every named AIMS risk carries a treatment choice, a residual tier and the next review window. The risk register is the same booklet the surveillance audit diffs at the next window — four named rows below, written against the AI control tower the SoA booklet declares.

  • Model-output drift

    Eval-suite gate + corridor re-confirmation by a human-in-the-loop before write-back

    Residual: Low

  • Prompt-injection on inbound context

    Injection-screening layer at the guardrail + journalised refusal on flagged inputs

    Residual: Low

  • Training-signal provenance gap

    Versioned lineage pointer on every training signal + dataset-change review at each shift

    Residual: Low

  • Human-override drift

    Named guardrail owner + override journal + monthly AIMS review window

    Residual: Medium

Latest report

Request the latest ISO 42001 report.

The AI risk register, the dataset lineage matrix and the eval-suite cadence ship on a mutual NDA under one business day. Send a note and the security contact comes back to you directly.

Replies land with the security contact, not a sales sequence.

See it on your store

See it on your store →

Skip the questionnaire — book a Scale-tier demo and watch the helm pull a lever on your Shopify store.

See it on your store →

ISO/IEC 42001 covers the AI management system — the AIMS controls that govern every model that pulls a lever. This page walks the framework, the controls in scope, and how to request the latest report.

← Back to trust center