ai · security · skills

Assessment FAQ · the assurance deliverable

The same questionnaire, pointed both ways.

Supply-chain due diligence is a vibe until it’s a question set. The AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) serves two audiences on one control spine: if you provide AI, it becomes a STAR-for-AI submission; if you consume it, a provider-evaluation pack.

AI-CAIQthe AICM consensus questionnaireYou provide AI→ STAR for AI Level 1You consume AI→ provider-evaluation packSame spine, same questions — a self-assessment registry submission one way, a due-diligence question set the other.

STAR for AI Level 1 is a self-assessment — not an audit certification. The artefact is honest about which it is.

Why it holds up

Because both directions ride the same control spine, the evidence you produced for the coverage assessment is the evidence that answers the questionnaire — you attest once, from one ledger.

“Can I prove my AI posture to a customer — and vet a provider’s — from the same control set?”

The answer

One control set, two assurance artefacts.

Provide: a completed AI-CAIQ prepared for a STAR-for-AI Level 1 registry submission. Consume: a provider-evaluation pack that turns supply-chain due diligence into a scorable question set. PCI DSS is out of scope for v1; coverage waits for v2.

The mapping from AI Controls Matrix (AICM) controls to ISO/IEC 42001, the EU AI Act, NIST AI 600-1, and BSI AIC4 — the substrate for the assurance artefact — is the crosswalk drill.

The crosswalk, standard by standard →

Browse the control spine →
← Back to Insights

Subscribe for the next essay.