AI Security Assessment for AI-Native Products
Assess the governance, security, and privacy of your AI systems against the Cloud Security Alliance's AI-CAIQ — the questionnaire enterprises increasingly send when procuring AI-powered products. 242 control questions, 18 domains, one actionable remediation plan.
242 questions · 18 domains · About 45–90 minutes · Save & resume anytime
What Is the AI-CAIQ?
Published by the Cloud Security Alliance, AI-CAIQ (AI Consensus Assessments Initiative Questionnaire) adapts the well-established CAIQ methodology to AI systems. Where the classic CAIQ evaluates cloud service controls, AI-CAIQ adds the questions that matter when a product includes machine learning or generative AI.
Version 2.0 of the framework defines 242 control questions across 18 domains — 17 shared with the CCM, plus a dedicated Model Security domain covering model governance, training data provenance, and AI-specific operational risks.
Enterprise buyers increasingly send these questions during procurement of AI-powered products. Being able to answer them with evidence is becoming a competitive requirement.
It complements — not replaces — ISO 27001 and CAIQ: those cover your ISMS and cloud controls; AI-CAIQ covers the AI layer on top.
What It Evaluates
AI Governance & Accountability
Accountability structures, model inventory, risk management processes for AI development and deployment.
Model Security
The dedicated MDS domain — protection of models, training data, and inference infrastructure, including prompt injection and model abuse considerations.
Data & Privacy
Training data provenance, personal data handling in prompts and outputs, retention and minimization practices.
Operational Resilience
Monitoring AI behavior in production, incident response for AI-specific failures, change management for models.
18 Domains — Including Model Security
AI-CAIQ v2.0 extends the 17 CCM domains with a dedicated Model Security domain for AI-specific controls.
From Answers to Action
Not just a questionnaire score — a complete path to closing your AI security gaps
Score Your Posture
Rate each control question and get an instant AI security coverage view across all 18 domains.
Identify Gaps
See exactly which AI controls are missing or partial, ranked by severity and domain.
AI Remediation
Each gap comes with concrete steps, recommended tools, cost, and effort — generated for AI-CAIQ controls.
Fix on a Roadmap
Prioritized 30/90/180-day plan so improvements happen in the right order.
AI-Native SaaS
Your product is built on LLMs or machine learning. Show buyers you govern models, data, and outputs with the same rigor as the rest of your stack.
Teams Adding AI Features
You shipped AI capabilities onto an existing SaaS product. AI-CAIQ surfaces the controls that standard frameworks don't ask about yet.
Security & GRC Leads
Get ahead of enterprise AI questionnaires with a structured, evidence-ready self-assessment you can hand to procurement.
Related Pages
CAIQ Assessment
Assess your cloud service controls with CSA CCM v4 / CAIQ 4.1.
Frameworks Explained
Where AI-CAIQ sits next to ISO 27001 and the classic CAIQ.
Security Assessment for SaaS
The broader playbook for enterprise security reviews.
Sample Report
See the output: score, gaps, and AI-generated remediation.
Know Your AI Security Posture Before Buyers Ask
Start with a free assessment. Get your AI security score, gap analysis, and remediation plan — about 45 to 90 minutes, saved automatically as you go.
