Catalogue of Tools & Metrics for Trustworthy AI

These tools and metrics are designed to help AI actors develop and use trustworthy AI systems and applications that respect human rights and are fair, transparent, explainable, robust, secure and safe.

CREST AI Accreditation Standards for Cybersecurity Services



The CREST AI Accreditation Standards for Cybersecurity Services enable cybersecurity service providers to apply to have their use of AI within their service provision independently assured by CREST as part of its accreditation process. The first AI accreditation was launched in July 2026 and gives service providers a practical framework for demonstrating responsible AI use within accredited cyber security services through independent assessment.

  • Domain 7: Responsible AI Use, part of the Company General Requirements, covers the governance, oversight, transparency and responsible organisational use of AI by the service provider. CREST’s AI Hub describes these requirements as covering AI governance, accountability and oversight.
  • Annex B: AI-Enabled Penetration Testing, part of the Penetration Testing Accreditation Standard, introduces requirements for service providers using AI within penetration testing, helping ensure AI enhances professional judgement while maintaining the quality, integrity and trust expected of CREST-accredited services. CREST also describes this as providing assurance that AI is used in penetration testing in a controlled, authorised and professionally supervised way.
  • Security Testing of AI establishes independently assessable requirements for organisations testing AI-enabled systems. It covers security testing of relevant components of AI systems, including models, application layers and orchestration components.

Together, these standards provide practical, independently assessable requirements supporting responsible AI use within accredited cybersecurity services and the security testing of AI systems. They build on CREST’s voluntary AI principles by providing independently verifiable assurance.

Use Cases

There is no use cases for this tool yet.

Would you like to submit a use case for this tool?

If you have used this tool, we would love to know more about your experience.

Add use case
Partnership on AI

Disclaimer: The tools and metrics featured herein are solely those of the originating authors and are not vetted or endorsed by the OECD or its member countries. The Organisation cannot be held responsible for possible issues resulting from the posting of links to third parties' tools and metrics on this catalogue. More on the methodology can be found at https://oecd.ai/catalogue/faq.