AI SVS
A verification standard for AI systems — in development.
The problem
Every AI security audit reinvents the checklist from scratch. NIST AI RMF and ISO 42001 are useful, but they sit at a level of abstraction that doesn't tell you what to actually check. There's no equivalent to OWASP ASVS for AI, so we started writing one.
What it does
It's a structured set of verification requirements across eight domains — training data, model integrity, prompt handling, deployment, identity and access, observability, supply chain, and incident response — each mapped back to NIST AI RMF and ISO 42001. Right now it's the internal standard the other tools here are built against. The self-serve version you can run against your own system is still being written.
Capabilities
- Requirements grouped into 8 AI-security domains
- Three intended rigor levels — essentials, production, regulated
- Designed to map to NIST AI RMF, ISO 42001, and the EU AI Act
- JSON + Markdown evidence export (planned)
How you run it
Being honest: this is the one thing here you can't run yet. It's the standard we're drafting, and the guided in-browser assessment is still in build. Everything else on this page you can use today.
Roadmap
- Domain structure + approach drafted
- Full published requirement set
- NIST / ISO 42001 / EU AI Act mapping
- In-browser guided assessment + export
- Team workspaces + evidence attachments
AI SVS runs inside PlayCISO for subscribers. The source stays private — no public repos, nothing to fork, nothing for attackers to study. Weekly, monthly, and yearly plans all include every tool.