SecurityDraft / Resources / The AI-CAIQ explained
Founder's guide

The AI-CAIQ, explained for a 12-person AI startup

31 July 2026·8 min read·For B2B AI founders

Your buyer's security team sent something called an "AI-CAIQ" and expects you to fill it in. Here's what it is, why it exists, and how a small AI startup with no compliance team should actually approach it — in plain English.

If a large customer has just handed you a questionnaire with the letters AI-CAIQ on it, don't panic and don't Google your way into a compliance rabbit hole. It's a specific, knowable thing, and once you understand what it's for, it stops being intimidating. This is the explanation we wish every founder got before they opened the spreadsheet.

What the AI-CAIQ actually is

Enterprises have assessed cloud vendors for years using a questionnaire from the Cloud Security Alliance (CSA) — the industry body enterprise security teams already trust for cloud assessment. That questionnaire, the CAIQ (Consensus Assessment Initiative Questionnaire), pairs with a control framework called the Cloud Controls Matrix. If you've ever filled in a vendor security questionnaire, you've met its descendants.

In 2025 the CSA extended that same model to AI. They published the AI Controls Matrix (AICM) — a framework of AI-specific controls — and its questionnaire companion, the AI-CAIQ. Together they cover 18 control domains and 247 control objectives (AICM v1.1, June 2026), spanning the things a buyer worries about specifically because you're an AI vendor: training data, model provenance, the AI supply chain, model security, output safety, and governance.

Two things make it matter to you right now. First, it's free and public — anyone can download it from the CSA. Second, because it comes from the body enterprises already trust, buyers are converging on it: they either send you the AI-CAIQ directly, or they build their own AI questionnaire that borrows heavily from it. Answer it well once, and you've answered most of what any enterprise will ask.

The short version The AI-CAIQ is a free, standardised list of the security and governance questions enterprises ask AI vendors, published by the same people who standardised cloud vendor questionnaires. It's becoming the default. That's good news: it means the target stops moving.

What it's really asking about

The 18 domains sound heavy, but for a small application-layer AI vendor they cluster into a handful of things a reviewer genuinely cares about. In plain language:

01Data handling. What data you receive, where it goes, where it's stored, how long you keep it, and how it's deleted.
02Training & your data. The big one — whether the buyer's data is ever used to train or fine-tune a model. Usually the first question and the one they read most carefully.
03Model & AI supply chain. Which model providers you call (OpenAI, Anthropic, Bedrock and the like), and what your contractual position with them is on data.
04Model security. Prompt injection, output safety, guardrails, and keeping one customer's data and context isolated from another's.
05Governance. Who's accountable for AI risk internally, and how your practices line up with the EU AI Act, ISO/IEC 42001 or the NIST AI Risk Management Framework.

Notice what's not here: you don't need to be a research lab, and you don't need to have built the model. Most AI startups are application-layer vendors calling someone else's model, and the AICM's supply-chain and model-security domains are built for exactly that. The reviewer isn't expecting you to own a data centre. They're expecting you to know your own architecture and describe it precisely.

How a small team should approach it

You are not going to hire a compliance function to answer one questionnaire, and you shouldn't. Here's the sane sequence.

Gather before you write

Almost every answer already exists somewhere in your company — it's just scattered. Before you type a single response, pull together your architecture and data-flow notes, your list of model providers and sub-processors, any SOC 2 or ISO evidence you already have, and your DPA. Most of the questionnaire is describing things you already do; the work is retrieval, not invention.

Work from the standard, not the spreadsheet

Even if a specific buyer sent their own custom questionnaire, answer the underlying AI-CAIQ well and you'll have your answers ready for the next buyer too — because they're all pulling from the same source. This is the difference between answering one deal's questionnaire and building an asset you reuse on every deal after it. Our free AI-CAIQ starter worksheet covers the twenty highest-frequency questions with, for each, what it's really probing and an honest answer pattern — it's the fastest way to start.

Be precise, and don't oversell

Security reviewers read a lot of questionnaires and can smell a vague or inflated answer instantly. "We take security seriously" wastes their time; "customer data is processed in eu-west-1, never used to train models, and deleted 30 days after contract termination" gets you through review. Precise beats impressive. And if the honest answer is "we don't do that yet," say so plainly with your plan — reviewers respect a clear gap far more than a fudged claim they'll catch later.

Answering the AI-CAIQ once, well, turns every future security review from a fire drill into a copy-paste. That's the whole return on doing it properly.

One thing to be clear-eyed about

Filling in the AI-CAIQ is not certification, and it isn't an audit. It's a set of representations you make to your buyer — statements you're on the hook for being true. That's a feature, not a bug: it's what lets a twelve-person company answer without a compliance department. But it means the answers must genuinely be yours, verified by someone who knows your systems. Be cautious of anyone offering to "certify" or "guarantee compliance" off a stack of your documents in a week — a real ISO 42001 certificate or an independent audit comes from an accredited auditor, and that's a different, much heavier thing.

What you can sensibly outsource is the drafting. Turning your existing docs into a complete, well-structured, framework-mapped set of answers is repeatable work, and getting it drafted for you can turn a two-week slog into a day of review. That's exactly what SecurityDraft does: we draft the completed AI-CAIQ, a trust page and the cross-framework mapping from your own material, and hand it to you to verify, correct and sign off. You own every word; we draft, you verify. We don't audit, attest, assure or certify — and we say so on the cover of everything we produce.

Skip the two-week slog

Get your AI-CAIQ drafted from your own docs — ready to verify and sign.

A completed AI-CAIQ, a public trust page, and EU AI Act / ISO 42001 / NIST AI RMF mapping, drafted from the documentation you already have. You review, sign off, and own it. Fixed price from £900 ex-VAT, turnaround in days.

Free Want to try it yourself first? Download the free AI-CAIQ starter worksheet — the 20 most-asked questions, what each is really asking, and an honest answer pattern for each. No sign-up.

enquiries@securitydraft.com

SecurityDraft drafts prepared responses from information you supply. You review, verify, correct and sign off every answer; the answers are your representations to your buyer. Not an audit, attestation, assurance or certification. CSA AI-CAIQ / AICM is the property of the Cloud Security Alliance.