We (MITRE) developed the referenced extension schema. Mac OS provides an installation receipt capability much like other package managers on other UNIX systems. It seems that OVAL should support checking this system provided audit trail.
If the audit trail is unreliable or unsuitable for the purpose, that's another good discussion.