Catalogue of Tools & Metrics for Trustworthy AI

These tools and metrics are designed to help AI actors develop and use trustworthy AI systems and applications that respect human rights and are fair, transparent, explainable, robust, secure and safe.

CXO Ready



CXO Ready

CXO Ready is an AI governance and regulatory compliance platform designed to help organisations identify, risk-classify, and manage the AI systems they operate, in the context of regulatory obligations under frameworks such as the EU AI Act, UK GDPR, and ISO 42001. The platform is intended to function as a centralised system of record for AI system oversight, providing an alternative to manual tracking methods such as spreadsheets or informal approval processes.

The platform builds an inventory of AI systems in use across an organisation, including internally developed models, third-party AI-enabled software, and AI tools adopted by staff without formal authorisation ("shadow AI"). This inventory is populated through structured team surveys and system-level assessments, capturing information on system ownership, intended purpose, data flows, and lifecycle stage. Each identified system is then assessed against defined regulatory criteria, including risk-tier classification under the EU AI Act and evaluation of privacy-related requirements such as consent mechanisms and the applicability of Data Protection Impact Assessments.

A distinguishing feature of the platform's methodology is its approach to evidence: rather than relying solely on self-reported survey responses, risk scores are intended to be linked to documented artefacts confirming the presence of specific controls (e.g. human oversight mechanisms, bias and drift monitoring, model testing records, and emergency deactivation ("kill switch") capabilities.) Where gaps or non-conformities are identified, the platform generates prioritised remediation tasks with assigned owners and target dates and can compile the resulting documentation into exportable records for use in audits, regulatory inquiries, or third-party security reviews.

Use Cases

There is no use cases for this tool yet.

Would you like to submit a use case for this tool?

If you have used this tool, we would love to know more about your experience.

Add use case
Partnership on AI

Disclaimer: The tools and metrics featured herein are solely those of the originating authors and are not vetted or endorsed by the OECD or its member countries. The Organisation cannot be held responsible for possible issues resulting from the posting of links to third parties' tools and metrics on this catalogue. More on the methodology can be found at https://oecd.ai/catalogue/faq.