AICM and AI-CAIQ FAQ
Released: 11/05/2025

The AI Controls Matrix (AICM) is a framework of vendor-agnostic controls (policies, procedures, and technical measures) that are essential for developing, implementing, and operating AI technologies in a secure and responsible manner. It is created and updated by CSA and incorporates elements of the Cloud Controls Matrix (CCM), ISO/IEC 42001, ISO/IEC 27001, NIST AI RMF 1.0, BSI AIC4, and other foundational frameworks.
The Consensus Assessment Initiative Questionnaire for AI (AI-CAIQ) is a set of questions that map to the AICM. These questions guide organizations in performing a self-assessment of their AI safety controls or an evaluation of third-party vendors.
This FAQ further explains what the AICM and AI-CAIQ are, why they’re important, how to use them, and how they fit into the STAR for AI program.
Prefer to access this resource without an account? Download it now.



