CAIQ v4, and how to answer it without starting from scratch
The Consensus Assessment Initiative Questionnaire is the Cloud Security Alliance's standard way for a cloud provider to document its controls once, instead of answering the same questions for every customer.
In short
CAIQ v4 is the questionnaire form of the CSA's Cloud Controls Matrix: each control in the CCM becomes one or more yes/no questions with room for explanation. It arrives as a multi-tab Excel workbook, usually with a cover or instructions sheet first and the questions on a later tab. Answering it well is less about writing prose than about pointing at the policy or report that already says what you do.
CAIQ v4 at a glance
| Published by | Cloud Security Alliance (CSA) |
| Based on | The Cloud Controls Matrix (CCM), organised into control domains covering areas such as identity, encryption, logging, incident response and supply chain |
| Typical size | Several hundred questions — enough that answering by hand is a multi-day job |
| Format | Excel workbook, multiple sheets |
| Who asks for it | Enterprise buyers of cloud and SaaS products, often as an accepted substitute for their own form |
| Related | A completed CAIQ can be submitted to the CSA STAR registry, which some buyers check before they send you anything |
How the file is put together
The shape of the workbook is what trips most tools up, and it is worth knowing before you upload anything.
What Compliance Concierge does with a CAIQ v4
None of this certifies you. The tool drafts answers from the documents you upload, shows the evidence behind each one, and refuses to export anything a person has not signed off. Where your documents do not cover a control, it says so instead of filling the cell.
Frequently asked
What is the difference between CAIQ and the CCM?+
The Cloud Controls Matrix is the control framework: a structured list of what a cloud provider should have in place. CAIQ is the questionnaire built from it — the same controls phrased as questions a customer can send you. If you have mapped your controls to the CCM, you have already done most of the work of a CAIQ.
Can I reuse last year's CAIQ?+
Partly, and that is the point of keeping a reviewed answer library. Controls change slowly, but evidence goes stale: a penetration test date, a subprocessor list or a certification expiry that was true last year may not be now. Reuse the wording, re-check anything with a date in it.
Do I have to answer every question?+
Not necessarily, but leaving cells blank without explanation is what triggers follow-up rounds. A clear "not applicable, because we do not operate our own data centres" closes a question. An empty cell reopens it.
Is an AI-drafted CAIQ acceptable to a customer?+
What a customer objects to is an unbacked claim, not the tool that typed it. That is why every draft here carries its citation and why nothing exports until a person has approved it — the answer you send is one a human signed off, with the evidence attached.
Other assessments we cover: SIG & SIG Lite, HECVAT, VSA. For the process itself, see the guide to answering security questionnaires.
Answer your CAIQ v4 with evidence
Upload your policies and the workbook. Every draft is cited from your own documents, and nothing leaves until you approve it. The first questionnaire is free.