The iOS model uses App Store reviews (with whatever static analysis secret sauce they do), plus user permission requests for access to some things like location and contacts.
I'd suggest Nokia's Symbian permission model was better, if a little annoying. It asked each time the app tried to use a given permission (until you permanently allowed/disallowed it).