Join our Newsletter — 33% off our NHI Course

CAIQ Questionnaire

The CAIQ is a standardized cloud security questionnaire used to document a provider’s controls in a consistent format. It maps yes-or-no questions to the Cloud Controls Matrix, which lets buyers compare providers against the same control baseline instead of creating a new review form for every assessment.

Expanded Definition

The CAIQ Questionnaire is a structured due diligence instrument for cloud and SaaS security reviews, but its real value is not the form itself. It is the consistency created when a provider answers the same control questions in a repeatable way, usually against the Cloud Controls Matrix. In practice, that makes CAIQ useful for comparing providers, documenting control assertions, and spotting gaps that would otherwise be hidden inside custom questionnaires.

Definitions vary across vendors on how much evidence a CAIQ response should include, and no single standard governs this yet. Some buyers treat it as an intake tool, while others use it as a formal control attestation artifact, which can create false confidence if “yes” answers are not backed by verifiable proof. For a broader governance lens, the NIST Cybersecurity Framework 2.0 is useful because it frames security outcomes rather than questionnaire completion. The most common misapplication is treating a completed CAIQ as evidence of security maturity, which occurs when teams accept self-attested answers without validating scope, ownership, or control operation.

Examples and Use Cases

Implementing CAIQ rigorously often introduces assessment overhead, requiring organisations to weigh faster vendor comparison against the cost of evidence validation and follow-up questions.

  • A procurement team sends the CAIQ to three SaaS vendors so each one responds to the same cloud control baseline instead of rewriting a bespoke review form.
  • A security team uses CAIQ responses to identify where a provider claims encryption, logging, or access controls, then requests proof for the highest-risk services.
  • A third-party risk program maps questionnaire answers to internal risk ratings, which helps standardize review outcomes across business units.
  • A buyer cross-checks CAIQ claims against incident history and public disclosures, including cases such as the DeepSeek breach, to see whether control statements match operational reality.
  • A cloud governance team uses CAIQ responses as an onboarding artifact, then revisits them during renewal rather than assuming the original responses remain current.

The questionnaire is most effective when it is treated as a control mapping tool, not as a substitute for assurance. Public cloud and AI service reviews are increasingly sensitive to exposed credentials and weak identity boundaries, which makes questionnaire answers only one part of the evidence chain. If the provider uses NHIs, the review should also consider how secrets, service accounts, and API permissions are governed in production. In that sense, the CAIQ can reveal where a provider says it has controls, while the buyer still has to determine whether those controls actually reduce exposure to misuse.

Why It Matters in NHI Security

CAIQ matters in NHI security because attackers often exploit the gap between stated controls and actual secret handling. When cloud providers, SaaS platforms, or AI services manage tokens, API keys, and service credentials poorly, the risk moves from abstract governance to immediate compromise. NHIMG research on secrets management shows that organisations spend an average of 32.4% of security budgets on secrets management and code security, yet still face a 27-day average remediation time for leaked secrets, which highlights how slow control validation can be in practice.

A CAIQ review should therefore test whether a provider’s identity, access, and secret-handling answers align with operational behavior, not just policy language. That is especially important where autonomous agents or integrations use NHIs to call external services, because a weak answer about credential storage can become a live attack path. The CAIQ also complements broader control frameworks by making vendor claims easier to compare before onboarding, renewal, or incident response. Organisations typically encounter the real cost of a weak questionnaire process only after a vendor compromise or secret leak, at which point CAIQ becomes operationally unavoidable for root-cause review and third-party containment.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-02 CAIQ exposes provider claims about secret handling and NHI control ownership.
NIST CSF 2.0 GV.SC-4 CAIQ supports supplier risk evaluation and security requirement comparison.
NIST SP 800-63 Identity assurance concepts inform how access and authenticator claims should be reviewed.
NIST Zero Trust (SP 800-207) RA Zero Trust emphasizes verifying trust assumptions instead of accepting self-attestation.
NIST AI RMF GOV AI governance guidance aligns where CAIQ is used for AI service and agent dependency reviews.

Use CAIQ responses to verify how service credentials, tokens, and API keys are stored and governed.