What is the CAIQ?
Who sends it, and why
The CAIQ is sent by enterprises that have standardised their cloud vendor-risk programme on the Cloud Security Alliance's framework rather than reinventing one internally. The appeal for the buyer is comparability: every vendor answers the same questions, in the same shape, against the same underlying control library, so a security team can put ten vendors side by side and read them in one afternoon.
For the vendor, this cuts both ways. A CAIQ that lands on your desk is a signal the buyer has a mature review process — the deal is credible and the questionnaire is real work. It also means the answers you give this quarter will be re-used by other buyers on the same standard; a strong CAIQ is an asset that keeps paying, and a weak one is a liability that follows you.
What it covers
The CAIQ mirrors the structure of the Cloud Controls Matrix — the CSA's control framework for cloud services — spanning the areas that matter to a cloud buyer: identity and access management, data security and encryption, governance and risk, resilience and business continuity, threat and vulnerability management, human resources, supply-chain assurance and more. The exact set of control domains and the wording of individual questions varies by version, and buyers frequently trim, extend or annotate the questionnaire to suit their own risk framework.
Read the version your buyer sent, not a template you found online. Two CAIQs with the same name can differ meaningfully; the answers you re-use should be portable in substance, not copy-pasted verbatim.
The AI questions inside it
Buyer-adapted CAIQs, together with the CSA's AI-focused additions, now probe the parts of your business that a general security questionnaire never used to reach. Reviewers ask about model provenance, training-data rights, the human oversight sitting behind an automated decision, whether an AI sub-processor is on the path of customer data, and how you classify systems against the EU AI Act or ISO/IEC 42001. This is the section where AI vendors lose deals — not because the questions are hard, but because the artefacts that back the answers do not exist in the organisation.
The Answer Library sets out each of these questions with a model answer, the evidence a reviewer expects to see, and the reason a weak answer fails. It is free and ungated, and it is the fastest way to see what a good CAIQ answer to an AI question actually looks like.
How to answer it well
Answers cited to real documents beat prose. A reviewer who spot-checks one answer and finds a sealed, owned, dated document behind it stops spot-checking; a reviewer who finds a paragraph attached to nothing keeps digging until something breaks. Cite the policy, the register, the control record, the named owner. Where a question has no artefact, do not invent one — state the gap, name the interim control, give a date, and move on.
Consistency matters as much as depth. The CAIQ will be read next to your trust page, your website and your contract. Reviewers notice when the numbers, the owners or the dates disagree across surfaces; one contradiction costs more than either version.
Answer it from a record, not a scramble
Import your controls and vendors, answer each question cited to a sealed record, and hold open honestly the ones you cannot yet ground. When the reviewer spot-checks, the citation opens; when a gap is real, the interim control and the date read as maturity, not evasion. This is the motion Hael runs: one record, sealed documents, cited answers, honest gaps.