Questionnaire standards

CAIQ v4, and how to answer it without starting from scratch

The Consensus Assessment Initiative Questionnaire is the Cloud Security Alliance's standard way for a cloud provider to document its controls once, instead of answering the same questions for every customer.

In short

CAIQ v4 is the questionnaire form of the CSA's Cloud Controls Matrix: each control in the CCM becomes one or more yes/no questions with room for explanation. It arrives as a multi-tab Excel workbook, usually with a cover or instructions sheet first and the questions on a later tab. Answering it well is less about writing prose than about pointing at the policy or report that already says what you do.

CAIQ v4 at a glance

Published byCloud Security Alliance (CSA)
Based onThe Cloud Controls Matrix (CCM), organised into control domains covering areas such as identity, encryption, logging, incident response and supply chain
Typical sizeSeveral hundred questions — enough that answering by hand is a multi-day job
FormatExcel workbook, multiple sheets
Who asks for itEnterprise buyers of cloud and SaaS products, often as an accepted substitute for their own form
RelatedA completed CAIQ can be submitted to the CSA STAR registry, which some buyers check before they send you anything

How the file is put together

The shape of the workbook is what trips most tools up, and it is worth knowing before you upload anything.

The first sheet is almost never the questions. It is typically a cover page, a licence notice, or instructions for the vendor filling it in.
Questions live on their own tab, grouped by control domain, with a control ID column before the question text.
Answers are usually split across a yes/no column and a free-text column for explanation — sometimes with further columns for the customer's own reviewer notes.
Some customers add or hide columns before sending it, so column positions cannot be assumed to be fixed.

What Compliance Concierge does with a CAIQ v4

The question tab is detected automatically, so a cover or instructions sheet in front does not derail the import.
The question column is found by content rather than by position, which survives the control ID and section columns that come first.
Every draft answer names the source document it came from and shows the exact snippets it relies on.
A second model re-checks each draft against its citations; anything it cannot confirm is marked as needing evidence rather than shipped as an answer.
The export writes your approved answers back into the original workbook — same tab, same rows, formatting and other sheets untouched.

None of this certifies you. The tool drafts answers from the documents you upload, shows the evidence behind each one, and refuses to export anything a person has not signed off. Where your documents do not cover a control, it says so instead of filling the cell.

This page provides orientation and does not replace legal advice. Whether and how a rule applies to your company depends on the individual case.

The 17 control domains, and the seven that cost the most time

CAIQ questions are grouped by CCM domain, and the domains are not equally hard. These seven are where answers get sent back for rework — what each is really asking, which document normally answers it, and the mistake that shows up most often.

A&A

Audit & Assurance

What it asks
Whether an independent party audits you, how often, and whether the buyer may see the result.
What answers it
SOC 2 Type II report or ISO 27001 certificate with the statement of applicability, plus the date of the most recent one.
Common mistake
Naming a certification whose scope is not the product being sold — a parent company's ISO 27001 while the service runs in a subsidiary's environment. Scope is the first thing a reviewer checks.
IAM

Identity & Access Management

What it asks
Who can reach production, how that access is granted and revoked, and how often it is reviewed.
What answers it
Access control policy, joiner-mover-leaver procedure, the record of the last access review, MFA enforcement settings.
Common mistake
Answering “quarterly” because the policy says quarterly, when no review has actually been recorded. The question is about practice, and the follow-up asks for the last record.
CEK

Cryptography, Encryption & Key Management

What it asks
What is encrypted, with which algorithms, and who holds the keys.
What answers it
Cryptographic policy or encryption standard, the cloud provider's configuration, the key rotation procedure.
Common mistake
Claiming “encrypted at rest” because the platform does it by default, without knowing whether keys are provider-managed or customer-managed. That distinction is frequently the actual question.
DSP

Data Security & Privacy Lifecycle Management

What it asks
What data is held, where it lives, how long it is kept and how it is deleted.
What answers it
Retention and deletion policy, records of processing under Art. 30 GDPR, a data flow or residency description, the DPA.
Common mistake
Stating a retention period that contradicts the privacy policy or the DPA. Both are public documents and buyers do read them alongside the questionnaire.
LOG

Logging & Monitoring

What it asks
What is logged, how long logs are kept, and whether anyone reads them.
What answers it
Logging policy with a retention period, alerting configuration, the on-call rota.
Common mistake
Answering about application logs when the question is about security audit logs. LOG became its own domain in v4, so answer libraries built on v3 often have nothing to reuse here.
SEF

Security Incident Management, E-Discovery & Cloud Forensics

What it asks
What happens when something goes wrong, and how quickly the customer is told.
What answers it
Incident response plan with severity tiers and notification timelines, plus the record of the last test or tabletop exercise.
Common mistake
Inventing a notification deadline to fill the field. If the plan states no number, the honest answer is what it does state — and then fixing the plan.
STA

Supply Chain Management, Transparency & Accountability

What it asks
Which subprocessors are used, what they can reach, and how they are assessed.
What answers it
The public subprocessor list, the vendor assessment procedure, the subprocessor clause of the DPA.
Common mistake
A subprocessor list that is out of date, or that omits the AI provider. This is currently the most closely read domain of the seven.

The remaining ten domains

  • AIS Application & Interface Security
  • BCR Business Continuity Management & Operational Resilience
  • CCC Change Control & Configuration Management
  • DCS Datacenter Security
  • GRC Governance, Risk Management & Compliance
  • HRS Human Resources Security
  • IPY Interoperability & Portability
  • IVS Infrastructure & Virtualization Security
  • TVM Threat & Vulnerability Management
  • UEM Universal Endpoint Management

CCM and CAIQ v4.1 were published on 27 January 2026: still 207 controls across the same 17 domains, but the questionnaire grew to 283 questions. Everything below applies to both — check the version cell on the cover sheet, because buyers send whichever they standardised on.

Frequently asked

What is the difference between CAIQ and the CCM?+

The Cloud Controls Matrix is the control framework: a structured list of what a cloud provider should have in place. CAIQ is the questionnaire built from it — the same controls phrased as questions a customer can send you. If you have mapped your controls to the CCM, you have already done most of the work of a CAIQ.

Can I reuse last year's CAIQ?+

Partly, and that is the point of keeping a reviewed answer library. Controls change slowly, but evidence goes stale: a penetration test date, a subprocessor list or a certification expiry that was true last year may not be now. Reuse the wording, re-check anything with a date in it.

Do I have to answer every question?+

Not necessarily, but leaving cells blank without explanation is what triggers follow-up rounds. A clear "not applicable, because we do not operate our own data centres" closes a question. An empty cell reopens it.

Is an AI-drafted CAIQ acceptable to a customer?+

What a customer objects to is an unbacked claim, not the tool that typed it. That is why every draft here carries its citation and why nothing exports until a person has approved it — the answer you send is one a human signed off, with the evidence attached.

Other assessments we cover: SIG & SIG Lite, HECVAT, VSA, TISAX / VDA ISA, DORA, ISO 27001. For the process itself, see the guide to answering security questionnaires. Tools that automate this kind of workbook, compared honestly: Vanta, SafeBase and Conveyor.

Answer your CAIQ v4 with evidence

Upload your policies and the workbook. Every draft is cited from your own documents, and nothing leaves until you approve it. The first questionnaire is free.