Join our Newsletter — 33% off our NHI Course
Home Glossary AI Security CAIQ Questionnaire
AI Security

CAIQ Questionnaire

← Back to Glossary
By NHI Mgmt Group Updated September 2, 2026 Domain: AI Security

The CAIQ is a standardized cloud security questionnaire used to document a provider’s controls in a consistent format. It maps yes-or-no questions to the Cloud Controls Matrix, which lets buyers compare providers against the same control baseline instead of creating a new review form for every assessment.

Expanded Definition

The CAIQ Questionnaire is a structured due diligence instrument for cloud and SaaS security reviews, but its real value is not the form itself. It is the consistency created when a provider answers the same control questions in a repeatable way, usually against the Cloud Controls Matrix. In practice, that makes CAIQ useful for comparing providers, documenting control assertions, and spotting gaps that would otherwise be hidden inside custom questionnaires.

Definitions vary across vendors on how much evidence a CAIQ response should include, and no single standard governs this yet. Some buyers treat it as an intake tool, while others use it as a formal control attestation artifact, which can create false confidence if “yes” answers are not backed by verifiable proof. For a broader governance lens, the NIST Cybersecurity Framework 2.0 is useful because it frames security outcomes rather than questionnaire completion. The most common misapplication is treating a completed CAIQ as evidence of security maturity, which occurs when teams accept self-attested answers without validating scope, ownership, or control operation.

Examples and Use Cases

Implementing CAIQ rigorously often introduces assessment overhead, requiring organisations to weigh faster vendor comparison against the cost of evidence validation and follow-up questions.

  • A procurement team sends the CAIQ to three SaaS vendors so each one responds to the same cloud control baseline instead of rewriting a bespoke review form.
  • A security team uses CAIQ responses to identify where a provider claims encryption, logging, or access controls, then requests proof for the highest-risk services.
  • A third-party risk program maps questionnaire answers to internal risk ratings, which helps standardize review outcomes across business units.
  • A buyer cross-checks CAIQ claims against incident history and public disclosures, including cases such as the DeepSeek breach, to see whether control statements match operational reality.
  • A cloud governance team uses CAIQ responses as an onboarding artifact, then revisits them during renewal rather than assuming the original responses remain current.

The questionnaire is most effective when it is treated as a control mapping tool, not as a substitute for assurance. Public cloud and AI service reviews are increasingly sensitive to exposed credentials and weak identity boundaries, which makes questionnaire answers only one part of the evidence chain. If the provider uses NHIs, the review should also consider how secrets, service accounts, and API permissions are governed in production. In that sense, the CAIQ can reveal where a provider says it has controls, while the buyer still has to determine whether those controls actually reduce exposure to misuse.

Why It Matters in NHI Security

CAIQ matters in NHI security because attackers often exploit the gap between stated controls and actual secret handling. When cloud providers, SaaS platforms, or AI services manage tokens, API keys, and service credentials poorly, the risk moves from abstract governance to immediate compromise. NHIMG research on secrets management shows that organisations spend an average of 32.4% of security budgets on secrets management and code security, yet still face a 27-day average remediation time for leaked secrets, which highlights how slow control validation can be in practice.

A CAIQ review should therefore test whether a provider’s identity, access, and secret-handling answers align with operational behavior, not just policy language. That is especially important where autonomous agents or integrations use NHIs to call external services, because a weak answer about credential storage can become a live attack path. The CAIQ also complements broader control frameworks by making vendor claims easier to compare before onboarding, renewal, or incident response. Organisations typically encounter the real cost of a weak questionnaire process only after a vendor compromise or secret leak, at which point CAIQ becomes operationally unavoidable for root-cause review and third-party containment.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02CAIQ exposes provider claims about secret handling and NHI control ownership.
NIST CSF 2.0GV.SC-4CAIQ supports supplier risk evaluation and security requirement comparison.
NIST SP 800-63Identity assurance concepts inform how access and authenticator claims should be reviewed.
NIST Zero Trust (SP 800-207)RAZero Trust emphasizes verifying trust assumptions instead of accepting self-attestation.
NIST AI RMFGOVAI governance guidance aligns where CAIQ is used for AI service and agent dependency reviews.

Use CAIQ responses to verify how service credentials, tokens, and API keys are stored and governed.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 2, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org