Assessment FAQ · the assurance deliverable
The same questionnaire, pointed both ways.
Supply-chain due diligence is a vibe until it’s a question set. The AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) serves two audiences on one control spine: if you provide AI, it becomes a STAR-for-AI submission; if you consume it, a provider-evaluation pack.
STAR for AI Level 1 is a self-assessment — not an audit certification. The artefact is honest about which it is.
Why it holds up
Because both directions ride the same control spine, the evidence you produced for the coverage assessment is the evidence that answers the questionnaire — you attest once, from one ledger.
“Can I prove my AI posture to a customer — and vet a provider’s — from the same control set?”
The answer
One control set, two assurance artefacts.
Provide: a completed AI-CAIQ prepared for a STAR-for-AI Level 1 registry submission. Consume: a provider-evaluation pack that turns supply-chain due diligence into a scorable question set. PCI DSS is out of scope for v1; coverage waits for v2.
The mapping from AI Controls Matrix (AICM) controls to ISO/IEC 42001, the EU AI Act, NIST AI 600-1, and BSI AIC4 — the substrate for the assurance artefact — is the crosswalk drill.