AssureDeck/Resources/AI-CAIQ V1.1 / EVIDENCE GUIDE

AI-CAIQ V1.1 / EVIDENCE GUIDE

Complete AI-CAIQ with evidence, not optimistic prose.

AI-CAIQ v1.1 is a structured self-assessment and third-party evaluation questionnaire mapped to CSA's AI Controls Matrix. A useful response set does more than mark yes or no: it identifies the system in scope, the accountable owner, the source artifact, the approval state, and every unresolved gap.

Reviewed 24 July 20269 minute readIndependent practitioner guide
320AI-CAIQ v1.1 questions
247AICM v1.1 control objectives
18AICM security domains
23 JUNAI-CAIQ v1.1 release date
01

SCOPE BEFORE ANSWERS

Name the provider role and one defensible system boundary.

CSA publishes role-specific guidance for model providers, orchestrated service providers, application providers, AI customers, and cloud service providers. Your answer can change materially with the role. An application vendor should not imply that it controls a foundation model provider's training environment; it should state which controls it owns, inherits, or must verify.

Start with one named AI service, its production boundary, intended use, customers, deployment regions, model and infrastructure providers, material data flows, and human decision points. If the scope cannot be drawn, the answer set cannot be approved consistently.

  • One named service and production environment
  • Provider role and inherited-control boundary
  • Models, APIs, infrastructure, subprocessors, and data stores
  • Intended use, prohibited use, and material limitations
02

CLAIM / SOURCE / OWNER

Separate an answer from the proof that supports it.

An answer is a representation to a buyer. Evidence is the artifact or system record that makes the representation reviewable. A policy title alone rarely proves implementation, and a screenshot without scope, date, or owner is difficult to reuse.

For each material response, record the approved claim, source URI, artifact owner, system scope, review date, and evidence state. Use explicit states such as Proven, Partial, and Missing. Partial means the source supports only part of the claim; Missing means the claim is not ready to make.

  • Approved answer language, not a model-generated draft
  • Direct source link plus artifact date and owner
  • Known limitation or exception beside the answer
  • Next action and accountable owner for every gap
03

BUILD THE EVIDENCE ROOM

Collect the recurring artifacts before chasing 320 rows.

Question-by-question drafting is slow because many answers depend on the same small set of source records. Build the reusable evidence room first, then map each question to those records.

The highest-leverage packet normally includes governance ownership, a system and provider inventory, data lifecycle records, identity and access evidence, evaluation and security testing, monitoring, incident response, change control, resilience, and a living risk register. The list is operational guidance, not a reproduction of CSA's questionnaire.

  • System card and architecture or data-flow record
  • Model, vendor, and subprocessor register
  • AI evaluation plan, results, thresholds, and exceptions
  • AI incident runbook, monitoring evidence, and tabletop record
  • Change log, release approvals, and residual-risk decisions
04

CONTROL THE DRAFT

Run a governed answer workflow.

A reliable workflow has five states: draft, evidence review, owner review, approved, and retired. Keep source language and buyer-facing language connected so that a changed model, vendor, policy, or control can trigger review.

Do not hide uncertainty to improve a score. Unsupported yes answers create commercial and legal exposure. A precise partial answer with a dated remediation owner is more defensible than a broad promise that no team can evidence.

  • Draft only from bounded source material
  • Route technical claims to technical owners
  • Route privacy and contractual claims to accountable reviewers
  • Freeze the approved version used for each buyer
05

KNOW THE ASSURANCE PATH

Treat STAR for AI as a separate program decision.

CSA states that STAR for AI Level 1 is a designation earned by completing and submitting the AI-CAIQ self-assessment to the STAR Registry. Valid-AI-ted adds automated validation, while Level 2 requires a third-party ISO/IEC 42001 certification and a Valid-AI-ted AI-CAIQ.

AssureDeck can help organize evidence and prepare client-approved answers. It does not award a STAR designation, perform certification, issue an assurance opinion, or guarantee that CSA or a buyer will accept a submission.

06

ACCEPTANCE CRITERIA

Know when the response set is ready to ship.

A response library is ready when the scope is explicit, every material answer has an owner and state, source links resolve for authorized reviewers, exceptions are visible, open gaps have dates and owners, and an accountable client reviewer has approved the version.

The goal is not a perfect-looking workbook. It is a response set that your security, product, privacy, legal, and sales teams can reuse without inventing new claims under deadline pressure.

FREE / NO EMAIL GATE

AI Procurement Evidence Inventory

An original, framework-neutral CSV for claims, owners, source links, approval dates, evidence states, and gap actions. Example rows are clearly marked and must be replaced with your facts.

Download CSV

PRIMARY SOURCES

Verify the framework at the source.

CSA AI-CAIQ v1.1Official questionnaire description and release date.CSA AI Controls Matrix v1.1Official control count, domains, roles, and package contents.CSA AICM v1.1 release analysisOfficial 320-question count and Scope-Select-Implement-Assess flow.CSA STAR for AIOfficial current assurance levels and requirements.

5-DAY / FIXED SCOPE

Find the evidence gaps before the buyer does.

The Evidence Gap Scan covers one defined AI system. We inventory existing proof, map the highest-risk claims, identify unsupported answers, and return a prioritized owner-by-owner backlog. Work begins after the agreed kickoff inputs are complete.

$5,000 fixedFixed scope. No payment is taken on this site.

No credentials or confidential files. Contact data is used only for this request. Read the privacy notice below.

Privacy notice ↗