How to validate an AIBOM: a step-by-step procedure
A practical procedure for checking an AIBOM you have generated or received from a supplier, using open-source tools and a written field policy. Allow about an hour for the first one; later ones can be automated.
- Identify the format and version first, because validation tools are version-specific.
- Use cyclonedx-cli for CycloneDX and spdx3-validate for SPDX 3 (JSON Schema plus SHACL).
- Apply a written required-field policy, such as CERT-In Table 10, after schema checks pass.
- Finish by comparing listed hashes with the artefacts actually deployed.
Before you start
You need the AIBOM file, a written list of required fields, and access to the model artefacts or registry the AIBOM describes. The procedure below applies the four layers described in AIBOM validation: schema, policy, consistency and provenance.
Step 1: identify format and version
Open the file and check its header. A CycloneDX JSON document declares bomFormat and specVersion. An SPDX 3 document is JSON-LD and references the SPDX 3 context. Record both, because each tool validates against a specific version. CycloneDX ML-BOM fields exist from version 1.5 onwards [1].
Step 2: run schema validation
CycloneDX. Run the CycloneDX CLI validate command with the input file and, if needed, the specification version. It supports versions 1.0 to 1.7 [2].
SPDX 3. Run both structural and semantic checks. The SPDX project publishes a JSON Schema and a SHACL model and recommends using both [3]. spdx3-validate, installed with pip install spdx3-validate, performs both in one run [4].
Fix or reject any schema errors before continuing. Later steps assume a well-formed document.
Step 3: confirm AI components are present
Check that the document actually describes AI. In CycloneDX, look for components of type machine-learning-model with a modelCard, and components of type data [5]. In SPDX 3, look for AIPackage and DatasetPackage elements [6]. A file that contains only software packages is an SBOM, not an AIBOM.
Step 4: apply the field policy
For each model component, check every required field. A CERT-In-based policy requires the Table 10 elements, including Model Name, Model Version, Model Type, Model Developer, Model Licensing Information, Software Dependencies, ML Models and Algorithms, Model Performance Metrics, Data Source and Data Sets Information [7]. See CERT-In AIBOM requirements for a field mapping. Record results in a table like this:
| Component | Field | Result | Action |
|---|---|---|---|
| fraud-model 3.2 | Model Performance Metrics | Missing | Return to owner |
| fraud-model 3.2 | Data Source | Present, prose only | Request dataset component |
| support-chat | Model Version | "latest" | Require pinned revision |
The table is an illustration of the format, not real data.
Step 5: check consistency
- Every dataset and base model referenced by a model exists as a component or a resolvable external reference.
- Licence identifiers are valid, and model, dataset and dependency licences do not conflict with your intended use.
- Software dependencies list versions, so they can be matched to vulnerability data.
- Timestamps and authors are present on the document.
Step 6: verify provenance
Compare each model's listed hash with the artefact in your registry or deployment. If the model is signed, verify the signature; Sigstore's model_signing tool supports Sigstore, public-key and PKCS #11 signing [8]. For serialised model files, check whether a scan has been run; ModelScan covers Pickle, H5 and SavedModel formats [9].
Step 7: record the result
Store the AIBOM, the tool outputs, the policy results and the decision (accept, accept with conditions, reject) together, with the date and reviewer. When the next version arrives, diff it against this one; the CycloneDX CLI includes a diff command [2].
Automating it
Once the steps are stable, run steps 2 to 6 in CI when a model is registered, and at intake for supplier deliveries. Keep step 7's decision with a named human for production models.
How IntelliXBOM helps
IntelliXBOM runs schema and required-field checks on CycloneDX and SPDX AIBOMs, including CERT-In AIBOM policies, and reports gaps per component. It keeps each version with diffs and stores validation results as timestamped evidence.
Frequently asked questions
What tool validates a CycloneDX AIBOM?
The open-source CycloneDX CLI validates CycloneDX documents against specification versions 1.0 to 1.7. It checks structure only, so add a policy check for required AI fields.
How do I validate an SPDX 3.0 AIBOM?
Validate against both the SPDX 3 JSON Schema and the SHACL model. The spdx3-validate tool, installed with pip, runs both checks.
What should I do if a supplier AIBOM fails validation?
Record the specific failures per component and field, return them to the supplier with a deadline, and decide whether the system can proceed with conditions. Keep the failed version for your records.
Sources
- Introducing OWASP CycloneDX v1.5 (26 June 2023)OWASP CycloneDXcyclonedx.org/news/cyclonedx-v1.5-released/
- CycloneDX CLICycloneDX (GitHub)github.com/CycloneDX/cyclonedx-cli
- Validating SPDX 3 JSON-LD documentsSPDX spdx-3-model (GitHub)github.com/spdx/spdx-3-model/blob/develop/serialization/jsonld/validation.md
- spdx3-validateGitHub (JPEWdev)github.com/JPEWdev/spdx3-validate
- CycloneDX v1.6 JSON ReferenceOWASP CycloneDXcyclonedx.org/docs/1.6/json/
- SPDX 3.0.1 specification: AI profile, AIPackage classSPDX / Linux Foundationspdx.github.io/spdx-spec/v3.0.1/model/AI/Classes/AIPackage/
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
- Model Transparency (model_signing)Sigstore (GitHub)github.com/sigstore/model-transparency
- ModelScan: protection against model serialisation attacksProtect AI (GitHub)github.com/protectai/modelscan
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.