Based on CSA AI-CAIQ v2.0

AI Security Assessment for AI-Native Products

Assess the governance, security, and privacy of your AI systems against the Cloud Security Alliance's AI-CAIQ — the questionnaire enterprises increasingly send when procuring AI-powered products. 242 control questions, 18 domains, one actionable remediation plan.

242 questions · 18 domains · About 45–90 minutes · Save & resume anytime

What Is the AI-CAIQ?

Published by the Cloud Security Alliance, AI-CAIQ (AI Consensus Assessments Initiative Questionnaire) adapts the well-established CAIQ methodology to AI systems. Where the classic CAIQ evaluates cloud service controls, AI-CAIQ adds the questions that matter when a product includes machine learning or generative AI.

Version 2.0 of the framework defines 242 control questions across 18 domains — 17 shared with the CCM, plus a dedicated Model Security domain covering model governance, training data provenance, and AI-specific operational risks.

Enterprise buyers increasingly send these questions during procurement of AI-powered products. Being able to answer them with evidence is becoming a competitive requirement.

It complements — not replaces — ISO 27001 and CAIQ: those cover your ISMS and cloud controls; AI-CAIQ covers the AI layer on top.

What It Evaluates

  • AI Governance & Accountability

    Accountability structures, model inventory, risk management processes for AI development and deployment.

  • Model Security

    The dedicated MDS domain — protection of models, training data, and inference infrastructure, including prompt injection and model abuse considerations.

  • Data & Privacy

    Training data provenance, personal data handling in prompts and outputs, retention and minimization practices.

  • Operational Resilience

    Monitoring AI behavior in production, incident response for AI-specific failures, change management for models.

18 Domains — Including Model Security

AI-CAIQ v2.0 extends the 17 CCM domains with a dedicated Model Security domain for AI-specific controls.

01Audit & Assurance
02Application & Interface Security
03Business Continuity Management & Operational Resilience
04Change Control and Configuration Management
05Cryptography, Encryption & Key Management
06Datacenter Security
07Data Security and Privacy Lifecycle Management
08Governance, Risk and Compliance
09Human Resources
10Identity & Access Management
11Interoperability & Portability
12Infrastructure Security
13Logging and Monitoring
14Model SecurityAI-specific
15Security Incident Management, E-Discovery, & Cloud Forensics
16Supply Chain Management, Transparency, and Accountability
17Threat & Vulnerability Management
18Universal Endpoint Management

From Answers to Action

Not just a questionnaire score — a complete path to closing your AI security gaps

Score Your Posture

Rate each control question and get an instant AI security coverage view across all 18 domains.

Identify Gaps

See exactly which AI controls are missing or partial, ranked by severity and domain.

AI Remediation

Each gap comes with concrete steps, recommended tools, cost, and effort — generated for AI-CAIQ controls.

Fix on a Roadmap

Prioritized 30/90/180-day plan so improvements happen in the right order.

AI-Native SaaS

Your product is built on LLMs or machine learning. Show buyers you govern models, data, and outputs with the same rigor as the rest of your stack.

Teams Adding AI Features

You shipped AI capabilities onto an existing SaaS product. AI-CAIQ surfaces the controls that standard frameworks don't ask about yet.

Security & GRC Leads

Get ahead of enterprise AI questionnaires with a structured, evidence-ready self-assessment you can hand to procurement.

Know Your AI Security Posture Before Buyers Ask

Start with a free assessment. Get your AI security score, gap analysis, and remediation plan — about 45 to 90 minutes, saved automatically as you go.

    Feedback
    Back to Top