Skip to content

CAIQ (Consensus Assessments Initiative Questionnaire)

Definition

A questionnaire published by the Cloud Security Alliance, designed specifically for cloud service providers. It maps to the CSA Cloud Controls Matrix (CCM) and addresses cloud-specific concerns including data residency, virtualisation security, and the shared responsibility model.

Publisher
Cloud Security Alliance (CSA)
Maps to
CSA Cloud Controls Matrix (CCM)
Audience
Cloud service providers specifically
Covers
Data residency, virtualisation security, shared responsibility

Common questions

How is the CAIQ different from a generic vendor security questionnaire?+

Generic questionnaires are often written for on-premises IT vendors and miss cloud-specific concerns. CAIQ questions are built around the CCM and specifically probe issues unique to cloud delivery, such as multi-tenant isolation, data residency across regions, and where the shared responsibility boundary sits between provider and customer.

How does an assessor typically use CAIQ responses in a due-diligence review?+

Responses are cross-checked against the vendor's actual certifications, such as SOC 2 or ISO 27001 reports, rather than accepted at face value, since CAIQ is a self-assessment questionnaire that the vendor completes about its own controls.

Related terms

Audit Rights Clause
A contractual provision giving the buying organisation the right to assess, inspect, or commission a third-party audit of the vendor's security controls....
Fourth-Party Risk
The risk arising from a vendor's own subcontractors and suppliers. If a critical vendor outsources key processes to a subcontractor, the organisation's...
Inherent Risk
The level of risk a vendor relationship carries before any controls are applied. Inherent risk determines how deep an assessment must be:...
SIG (Standardised Information Gathering)
A vendor security questionnaire published by Shared Assessments. The SIG Core covers eighteen risk domains including access control, data security, and business...
SOC 2 Type II Report
An independent audit report on a service organisation's controls related to security, availability, processing integrity, confidentiality, and privacy. Type II reports cover...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.