Home / AI-CAIQ
CSA AI-CAIQ COMPLETION GUIDE

How to Complete an AI-CAIQ Questionnaire With Traceable Evidence

The Cloud Security Alliance’s AI-CAIQ gives organizations a structured way to assess AI controls and evaluate third-party AI vendors. For vendors responding to enterprise buyers, the hard part is rarely writing prose—it is proving each answer with current governance, security, privacy and operational evidence.

Updated 15 September 2026 · References official CSA materials

What AI-CAIQ is for

CSA describes AI-CAIQ as a set of questions mapped to its AI Controls Matrix (AICM), designed to support self-assessment of AI safety controls and evaluation of third-party vendors. That means a good response should not be treated as marketing copy. It should reflect the controls, policies and operating practices that actually exist.

Build your evidence pack before completing the questionnaire

Governance

AI policy, ownership, approval process, risk classification, inventory, change management and escalation.

Security

Identity/access, secrets, logging, secure development, vulnerability management, incident response and supplier controls.

Privacy & data

Collection, purpose, retention, deletion, subprocessors, transfers, training-data position and customer-content handling.

Model operations

Model/provider inventory, evaluation, monitoring, versioning, fallbacks, human oversight and limitations.

AI-CAIQ completion workflow

  1. Use the current questionnaire version provided by the buyer or official source.
  2. Map each question to an internal evidence owner.
  3. Answer from documented controls and operating practices—not assumptions.
  4. Use source citations or internal references so reviewers can verify the answer.
  5. Mark gaps where the organization does not yet have evidence.
  6. Review statements that create legal, security or compliance commitments with the appropriate owner.
  7. Store the approved response and evidence date for future refreshes.

Common AI-CAIQ response mistakes

Overstating a control

“We monitor all models continuously” is materially different from periodic evaluation. Match the wording to reality.

Confusing provider controls with your controls

Your model provider’s certification does not automatically prove your application’s full control environment.

Using stale evidence

Model providers, data flows and AI features can change faster than annual policies.

Ignoring applicability

Explain when a control does not apply and why, instead of forcing a yes/no answer.

Official AI-CAIQ sources

For authoritative definitions and current questionnaire guidance, use the CSA AICM & AI-CAIQ FAQ and CSA’s Filling in the AI-CAIQ guidance. ProcureDeal is not affiliated with or endorsed by CSA.

Continue preparing