SCOPE BEFORE ANSWERS
Name the provider role and one defensible system boundary.
CSA publishes role-specific guidance for model providers, orchestrated service providers, application providers, AI customers, and cloud service providers. Your answer can change materially with the role. An application vendor should not imply that it controls a foundation model provider's training environment; it should state which controls it owns, inherits, or must verify.
Start with one named AI service, its production boundary, intended use, customers, deployment regions, model and infrastructure providers, material data flows, and human decision points. If the scope cannot be drawn, the answer set cannot be approved consistently.
- One named service and production environment
- Provider role and inherited-control boundary
- Models, APIs, infrastructure, subprocessors, and data stores
- Intended use, prohibited use, and material limitations
CLAIM / SOURCE / OWNER
Separate an answer from the proof that supports it.
An answer is a representation to a buyer. Evidence is the artifact or system record that makes the representation reviewable. A policy title alone rarely proves implementation, and a screenshot without scope, date, or owner is difficult to reuse.
For each material response, record the approved claim, source URI, artifact owner, system scope, review date, and evidence state. Use explicit states such as Proven, Partial, and Missing. Partial means the source supports only part of the claim; Missing means the claim is not ready to make.
- Approved answer language, not a model-generated draft
- Direct source link plus artifact date and owner
- Known limitation or exception beside the answer
- Next action and accountable owner for every gap
BUILD THE EVIDENCE ROOM
Collect the recurring artifacts before chasing 320 rows.
Question-by-question drafting is slow because many answers depend on the same small set of source records. Build the reusable evidence room first, then map each question to those records.
The highest-leverage packet normally includes governance ownership, a system and provider inventory, data lifecycle records, identity and access evidence, evaluation and security testing, monitoring, incident response, change control, resilience, and a living risk register. The list is operational guidance, not a reproduction of CSA's questionnaire.
- System card and architecture or data-flow record
- Model, vendor, and subprocessor register
- AI evaluation plan, results, thresholds, and exceptions
- AI incident runbook, monitoring evidence, and tabletop record
- Change log, release approvals, and residual-risk decisions
CONTROL THE DRAFT
Run a governed answer workflow.
A reliable workflow has five states: draft, evidence review, owner review, approved, and retired. Keep source language and buyer-facing language connected so that a changed model, vendor, policy, or control can trigger review.
Do not hide uncertainty to improve a score. Unsupported yes answers create commercial and legal exposure. A precise partial answer with a dated remediation owner is more defensible than a broad promise that no team can evidence.
- Draft only from bounded source material
- Route technical claims to technical owners
- Route privacy and contractual claims to accountable reviewers
- Freeze the approved version used for each buyer
KNOW THE ASSURANCE PATH
Treat STAR for AI as a separate program decision.
CSA states that STAR for AI Level 1 is a designation earned by completing and submitting the AI-CAIQ self-assessment to the STAR Registry. Valid-AI-ted adds automated validation, while Level 2 requires a third-party ISO/IEC 42001 certification and a Valid-AI-ted AI-CAIQ.
AssureDeck can help organize evidence and prepare client-approved answers. It does not award a STAR designation, perform certification, issue an assurance opinion, or guarantee that CSA or a buyer will accept a submission.
ACCEPTANCE CRITERIA
Know when the response set is ready to ship.
A response library is ready when the scope is explicit, every material answer has an owner and state, source links resolve for authorized reviewers, exceptions are visible, open gaps have dates and owners, and an accountable client reviewer has approved the version.
The goal is not a perfect-looking workbook. It is a response set that your security, product, privacy, legal, and sales teams can reuse without inventing new claims under deadline pressure.
FREE / NO EMAIL GATE
AI Procurement Evidence Inventory
An original, framework-neutral CSV for claims, owners, source links, approval dates, evidence states, and gap actions. Example rows are clearly marked and must be replaced with your facts.
PRIMARY SOURCES