πŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
All tools
alphaAI Security Verification Standard

AI SVS

A verification standard for AI systems β€” in development.

In the wildβ€” AI SVS runsβ€” Issues surfacedβ€” CountriesΒ· opt-in only

The problem

Every AI security audit reinvents the checklist from scratch. NIST AI RMF and ISO 42001 are useful, but they sit at a level of abstraction that doesn't tell you what to actually check. There's no equivalent to OWASP ASVS for AI, so we started writing one.

What it does

It's a structured set of verification requirements across eight domains β€” training data, model integrity, prompt handling, deployment, identity and access, observability, supply chain, and incident response β€” each mapped back to NIST AI RMF and ISO 42001. Right now it's the internal standard the other tools here are built against. The self-serve version you can run against your own system is still being written.

Capabilities

  • Requirements grouped into 8 AI-security domains
  • Three intended rigor levels β€” essentials, production, regulated
  • Designed to map to NIST AI RMF, ISO 42001, and the EU AI Act
  • JSON + Markdown evidence export (planned)

How you run it

Being honest: this is the one thing here you can't run yet. It's the standard we're drafting, and the guided in-browser assessment is still in build. Everything else on this page you can use today.

Roadmap

  • Domain structure + approach drafted
  • Full published requirement set
  • NIST / ISO 42001 / EU AI Act mapping
  • In-browser guided assessment + export
  • Team workspaces + evidence attachments

FAQ

What is the AI Security Verification Standard (AI SVS)?

AI SVS is a structured set of verification requirements for securing AI and LLM applications, grouped into eight domains β€” training data, model integrity, prompt handling, deployment, identity and access, observability, supply chain, and incident response. Like OWASP’s Application Security Verification Standard (ASVS) for web apps, it turns β€œis this AI system secure?” into specific, testable checks rather than general guidance.

How is AI SVS different from the OWASP LLM Top 10?

The OWASP Top 10 for LLM Applications is an awareness list that names the main risk categories. AI SVS goes a step further: for each domain it states the controls that must be present and can be verified, so it works as a review checklist for an audit rather than only for awareness.

What frameworks does AI SVS map to?

Its requirements are designed to map back to the NIST AI RMF, ISO/IEC 42001, and the EU AI Act, so an AI SVS review supports the broader governance frameworks rather than duplicating them.

Included with any PlayCISO plan

AI SVS runs inside PlayCISO for subscribers. The source stays private β€” no public repos, nothing to fork, nothing for attackers to study. Weekly, monthly, and yearly plans all include every tool.

OWASP AISVS Checklist β€” AI Security Verification Standard Β· PlayCISO