---
title: "CAIQ v4.1 Questionnaire: What It Is and How to Answer"
url: "https://www.arphie.ai/blog/caiq-questionnaire"
collection: blog
lastUpdated: 2026-07-30T21:57:03.976Z
---

# CAIQ v4.1 Questionnaire: What It Is and How to Answer

The Consensus Assessments Initiative Questionnaire (CAIQ) is the Cloud Security Alliance's standardized questionnaire for assessing security controls in cloud services. Cloud service providers use it to describe whether controls are implemented, who owns each responsibility, and how customers should interpret the provider's security posture.



CAIQ is standardized, but completing it is rarely simple. A reliable response has to match the right service and version, explain shared responsibilities, and support each claim with current evidence. The work becomes difficult when policies and audit material are scattered, several subject-matter experts own different controls, old questionnaire versions remain in circulation, or reviewers must reconcile inconsistent answers without exposing restricted security information.



The current version is **CAIQ v4.1**, released on January 27, 2026. The Full questionnaire contains 283 questions based on 207 Cloud Controls Matrix (CCM) controls across 17 domains. [CAIQ-Lite](https://cloudsecurityalliance.org/artifacts/ccm-lite-and-caiq-lite-v4/) narrows the assessment to 138 questions when a customer accepts a shorter review.



[Arphie's security questionnaire workflow](https://www.arphie.ai/security-teams) addresses these bottlenecks by importing the CAIQ Excel workbook, drafting answers from the knowledge base and selected connected sources, and showing the source and confidence behind each draft. Reviewers can then collaborate on exceptions and complete human approval and sign-off.



You can download the official files from the Cloud Security Alliance (CSA):



- [Cloud Controls Matrix and CAIQ v4.1 bundle](https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4-1).



- [STAR Level 1 Security Questionnaire (CAIQ v4.1)](https://cloudsecurityalliance.org/artifacts/star-level-1-security-questionnaire-caiq-v4-1).



- [CCM-Lite and CAIQ-Lite](https://cloudsecurityalliance.org/artifacts/ccm-lite-and-caiq-lite-v4/).



## CAIQ v4.1 at a glance



| Detail | Current CAIQ information |
| --- | --- |
| Owner | Cloud Security Alliance |
| Current version | CAIQ v4.1 |
| Release date | January 27, 2026 |
| Full questionnaire | 283 questions |
| CAIQ-Lite | 138 questions |
| Underlying framework | CCM v4.1: 207 controls across 17 domains |
| Core answer options | Yes, No, or N/A |
| Primary use | Cloud provider self-assessment and customer or auditor due diligence |
| STAR use | The designated STAR Level 1 workbook can be submitted to the CSA STAR Registry |



CAIQ is designed for infrastructure as a service (IaaS), platform as a service (PaaS), and software as a service (SaaS). Its standardized language makes it easier for a provider to reuse accurate control information and for a customer to compare cloud services without starting every review from a blank questionnaire.



## How CAIQ relates to the Cloud Controls Matrix (CCM)



The CAIQ and CCM serve different purposes:



- **The CCM defines the controls.** It is CSA's cloud security and privacy control framework.



- **CAIQ turns those controls into assessment questions.** A customer, auditor, or provider can use the answers to evaluate how the controls apply to a specific cloud service.



The relationship is not always one control to one question. A CCM control can contain several requirements, so CAIQ may split it into multiple questions. That is why CAIQ v4.1 has 283 questions for 207 controls.



The official v4.1 workbook identifies each question by its CAIQ question ID, mapped CCM control, control title, and domain. Separate response fields record the provider answer, shared-responsibility ownership, provider implementation description, and customer responsibilities.



### How to run a CAIQ response



The process works best when one person runs the questionnaire and subject-matter experts approve the answers in their areas.



CSA creates and updates the CAIQ template. The customer or auditor chooses which version to use, what product or service to assess, and when the response is due. The cloud provider completes the questionnaire and approves the answers before sending it back.



Inside the provider, a security or governance, risk, and compliance (GRC) lead should coordinate the work. This person confirms the scope, controls the workbook, tracks open questions, and sends each question to the right owner. Security, IT, engineering, privacy, legal, and business continuity owners then confirm the answers and evidence for the controls they manage. The coordinator resolves gaps and routes the completed response for final sign-off.



This project role is separate from the ownership recorded in CAIQ's Shared Security Responsibility Model. Those fields say whether the provider, customer, or another party implements a specific control. They do not name the person managing the questionnaire.



### Use the correct file for STAR Level 1



CSA's v4.1 bundle includes a reference CAIQ inside the main CCM workbook and a separate **STAR Level 1 Security Questionnaire**. CSA states that the reference version cannot be submitted to the STAR Registry. If you are preparing the Full Level 1 self-assessment, use the workbook specifically labeled for STAR submission.



CSA also accepts [CCM-Lite and CAIQ-Lite](https://cloudsecurityalliance.org/research/ccm-lite) for STAR Level 1 submissions. Use the Lite workbook only when its reduced scope matches the assessment.



STAR Level 1 is a self-assessment and transparency mechanism, not an independent certification. CSA's higher assurance levels involve third-party certification or attestation.



Arphie helps after you select the correct workbook. You can import the exact Full or Lite Excel file, and Arphie detects its questions and sections so drafting and review can happen against that file. Your coordinator should still confirm whether the customer expects a private assessment or a STAR submission before work begins.



## Should you use Full CAIQ v4.1 or CAIQ-Lite?



Use the version requested by the customer or assessment owner. When you can choose, assessment depth and purpose should drive the decision.



- **Full CAIQ v4.1 is the best fit if:** You need detailed cloud due diligence, a comprehensive control review, or the designated STAR Level 1 submission workflow. It contains 283 questions mapped to all 207 CCM controls.



- **CAIQ-Lite is the best fit if:** You need a faster initial engagement or lower-depth review and the customer accepts the reduced scope. It contains 138 questions mapped to a 96-control CCM subset.



Do not silently replace a Full questionnaire with Lite. Record which version you answered, the product and deployment model in scope, and any services or regions that are excluded.



Many older CAIQ templates remain in circulation. Under [CSA's v4.1 transition timeline](https://cloudsecurityalliance.org/blog/2026/02/19/ccm-v4-1-transition-timeline), new STAR Level 1 submissions can use v4.0.x or v4.1 before the December 2027 switch to v4.1-only submissions. Services that were already in the STAR Registry before v4.1 was released have a two-year transition window ending in January 2028. If a customer sends an older workbook, confirm whether they need that exact version or will accept the current one. Avoid copying old answers forward without checking changed questions and control mappings.



## What does the CAIQ questionnaire cover?



CAIQ v4.1 follows the CCM's 17 cloud security domains:



| Domain | What it addresses |
| --- | --- |
| Audit & Assurance | Audit policies, independent assessments, findings, and remediation |
| Application & Interface Security | Secure development, application controls, and interfaces |
| Business Continuity Management and Operational Resilience | Continuity, recovery, resilience, and availability planning |
| Change Control and Configuration Management | Controlled changes, baselines, and configuration processes |
| Cryptography, Encryption & Key Management | Encryption, keys, certificates, and cryptographic controls |
| Datacenter Security | Physical and environmental safeguards for facilities |
| Data Security and Privacy Lifecycle Management | Data handling, classification, retention, privacy, and deletion |
| Governance, Risk and Compliance | Governance, policy, risk management, and compliance oversight |
| Human Resources | Workforce screening, responsibilities, awareness, and offboarding |
| Identity & Access Management | Authentication, authorization, privileges, and access reviews |
| Interoperability & Portability | Data and service portability and interoperability |
| Infrastructure Security | Cloud infrastructure, networks, compute, and virtualization safeguards |
| Logging and Monitoring | Event logging, monitoring, alerting, and review |
| Security Incident Management, E-Discovery, & Cloud Forensics | Incident response, investigation, evidence, and notification |
| Supply Chain Management, Transparency, and Accountability | Third parties, dependencies, ownership, and transparency |
| Threat & Vulnerability Management | Threat intelligence, vulnerability identification, and remediation |
| Universal Endpoint Management | Endpoint inventory, configuration, protection, and monitoring |



These domains make CAIQ broader than a compliance badge checklist. A complete answer set may require input from both security teams and governance, risk, and compliance (GRC) teams. Privacy and legal owners may also need to contribute. Other contributors may come from IT, engineering, infrastructure, and business continuity.



## How to answer CAIQ v4.1



The fastest reliable process separates reusable control evidence from customer-specific scope. That lets you reuse approved facts without treating every deployment, integration, or exception as identical.



### 1. Confirm the version, service, and purpose



Before assigning questions, record:



- The CAIQ version and whether it is Full or Lite.



- The product, service, deployment model, and environment in scope.



- Relevant regions, data types, and customer configurations.



- The requested due date and review contact.



- Whether the response is private due diligence or a STAR submission.



This prevents a technically correct answer for one service from being reused for another service with a different architecture or responsibility boundary.



### 2. Assemble approved source material



Start with current, approved evidence rather than old questionnaire prose. Useful sources include:



- Security and privacy policies.



- A SOC 2 report or other audit evidence.



- Architecture and data-flow documentation.



- Encryption and key-management standards.



- Identity and access procedures.



- Incident response and business continuity plans.



- Penetration-test summaries and vulnerability-management records.



- Subprocessor and third-party inventories.



- Standard contract, security addendum, and customer responsibility language.



Create disclosure rules for each source. Some documents may support an answer without being safe to attach or quote in full.



### 3. Assign owners by domain



Route questions to the people accountable for the underlying control. Domain-level routing is a useful starting point, but one person should own final coordination so terminology, scope, and exceptions stay consistent.



Maintain an escalation path for questions that cross security, privacy, legal, and engineering. A question should not sit unresolved because two teams each assume the other owns it.



### 4. Apply the official answer semantics



CAIQ v4.1 uses **Yes**, **No**, and **N/A**:



- **Yes** means the relevant part of the control is implemented.



- **No** means it is in scope but not implemented.



- **N/A** means it is outside the assessment scope and does not apply to the service.



The workbook also asks who owns implementation under the Shared Security Responsibility Model (SSRM). Responsibility may belong to the provider or customer. It may be outsourced. It may also be shared between the provider and customer or between the provider and a third party. For an N/A answer, leave ownership blank. Use Not Determined when the control is not applicable to the provider or any other entity in the cloud supply chain, or when the provider lacks clarity about who owns it.



An N/A answer is not a substitute for an inconvenient No. Explain the scope reason. For a No, state the gap, the responsible party, and the remediation or compensating control when disclosure is appropriate. For shared controls, separate provider responsibilities from customer configuration or operating duties.



### 5. Add implementation detail and evidence references



A useful response is more than a one-word attestation. Give the reviewer enough context to understand what is implemented and where the claim is supported.



A practical answer pattern is:



- **Answer:** Yes, No, or N/A.



- **Ownership:** Name the applicable SSRM ownership model.



- **Implementation:** Describe how the service meets the requirement, including material scope limits.



- **Evidence:** Cite the approved policy, audit section, standard, diagram, or record.



- **Customer responsibility:** State any configuration, access, retention, or operating action the customer must perform.



An encryption answer should distinguish data in transit from data at rest. The answer should identify the service in scope. It should cite the approved standard or audit evidence. It should also explain any customer-managed key responsibility. A bare statement such as "Yes, we encrypt data" is not enough.



### 6. Review for contradictions and disclosure risk



Run a cross-functional review before release. Look for:



- The same control answered differently in nearby questions.



- Claims that exceed the supporting policy or audit scope.



- Stale dates, product names, subprocessors, or certification language.



- N/A answers with no scope explanation.



- Shared controls that omit customer responsibilities.



- Remediation details that expose sensitive security information.



- Attachments containing secrets, personal data, or restricted audit material.



Security or GRC should approve the control position. Legal and privacy should review contractual, regulatory, and data-handling statements where needed. Product or engineering owners should confirm architecture-specific answers.



### 7. Approve, export, and preserve the response set



Keep approval status separate from draft status. Export only the approved answer set into the requested workbook, preserving question IDs and workbook structure. Save the final file with the version, service, scope, customer, and approval date in its record.



### 8. Maintain answers as controls change



Treat the finished CAIQ as reusable evidence, not a one-time spreadsheet. Assign a content owner to each reusable answer. Review an answer when its supporting policy or audit changes. Product launches, architecture changes, new subprocessors, or incidents should also trigger review. Revisit the answer set whenever CSA releases a new CAIQ version.



Track where a response was used. When a material fact changes, you can identify affected answers and avoid carrying stale language into the next assessment.



## Common CAIQ response mistakes



- Reusing a v3.1 or v4.0 answer set without checking v4.1 changes.



- Giving a blanket Yes when only part of the control is implemented.



- Marking a control N/A without a clear service or scope reason.



- Omitting customer responsibilities for shared controls.



- Treating audit coverage as proof for products or periods outside the report's scope.



- Copying unapproved answers from an old customer questionnaire.



- Sending sensitive evidence without checking disclosure restrictions.



- Letting several reviewers edit the workbook without one accountable owner.



## CAIQ vs. SIG vs. custom security questionnaires



These questionnaires can appear in the same deal, but they are not interchangeable.



| Questionnaire | Owner and focus | What respondent teams should know |
| --- | --- | --- |
| CAIQ | Cloud Security Alliance; cloud controls mapped to the CCM | Use the requested Full or Lite version and make shared cloud responsibility explicit |
| SIG | Shared Assessments; broader third-party risk | Scope and versions differ from CAIQ; see our [SIG questionnaire guide](https://www.arphie.ai/blog/sig-questionnaire) for the dedicated workflow |
| Custom customer questionnaire | Written or adapted by an individual buyer | It may combine several frameworks with customer-specific product, privacy, legal, and architecture questions |



CAIQ gives you a reusable cloud-control baseline. It does not prevent a customer from asking follow-up questions or requesting a different format. Our [security questionnaire FAQ](https://www.arphie.ai/blog/security-questionnaire-faq) covers broader workflow, accuracy, integration, and review questions that arise across custom assessments.



## Complete CAIQ faster without weakening review



The bottleneck is rarely typing Yes or No. It is locating current evidence, deciding scope, routing exceptions, and proving that the final answer is approved. Arphie brings those steps into one [security questionnaire workflow](https://www.arphie.ai/security-teams):



- **Import the questionnaire with Arphie.** [Arphie](https://www.arphie.ai/features) imports the CAIQ Excel workbook and detects its questions and sections.



- **Draft with Arphie from approved knowledge.** Arphie's AI agents use the knowledge base and selected connected sources to prepare first drafts.



- **Review the evidence in Arphie.** Reviewers can inspect the source and confidence signal behind each draft before accepting or revising it.



- **Route exceptions in Arphie.** Teammates can comment, tag subject-matter experts, and work through questions that need security, GRC, IT, engineering, privacy, or legal input.



- **Approve and export from Arphie.** The team completes human review and sign-off, then exports the finished questionnaire back into the original Excel file.



Automation should shorten evidence retrieval and repetitive drafting. It should not make control decisions on its own. Keep a human owner responsible for scope and exceptions. That owner should confirm shared-responsibility language. The owner should also control disclosure and final approval.



If CAIQ responses are consuming security and GRC time or slowing customer reviews, [contact us](https://www.arphie.ai/contact) to see a source-backed CAIQ workflow with your own approved content.