Compatible-standard reports are lenses on AI Controls Matrix (AICM) answers from the function diagnostic — the AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) is the attestation view of that spine, shown as a sample. Not certification.
Security Governance, Risk & Assurance. Answer for Initech.
Pick the line that matches where you are today, least to most mature. Each question is a real control objective; the verification note says where to confirm it. 26/26 to answer.
Re-assessing Initech. A rated sample: illustrative answers are loaded, nothing is saved. Change what improved and the maturity and the gate recompute live.
Governance
GRC-01Is there an AI governance program with documented policies and procedures?
GRC-02Is there an AI risk management program feeding decisions, with named ownership?
GRC-03Are AI policies reviewed on a tracked cadence with metrics and exceptions managed?
HRS-15Are the analysts using AI in this function trained on acceptable use and on verifying AI output before acting on it?
GRC-15Is there named human supervision for AI-assisted assurance work — someone accountable for what the AI drafts?
App Security
AIS-01Is there an application security policy covering the AI-enabled apps your teams assure?
AIS-04Is there a secure development lifecycle (SDLC) for AI-enabled applications?
AIS-07Is application vulnerability remediation tracked to closure with metrics?
AI Supported Development and Supply Chain Security
TVM-01Is there a threat & vulnerability management policy covering AI components and their dependencies?
TVM-03Are vulnerabilities in AI components and their supply chain identified?
TVM-08Is remediation for AI-component vulnerabilities scheduled and tracked?
Privacy and Compliance
A&A-01Is there a written audit and assurance approach for your AI systems?
verify · Ask for the audit & assurance policy and whether AI is named in scope.
A&A-02Does someone independent of the AI work check that its controls actually hold?
verify · Ask who performed the last independent review and which AI areas it covered.
A&A-05Is there a managed process for planning AI audits and tracking findings to closure?
verify · Ask for the audit plan and the findings register with owners and due dates.
A&A-06When an AI audit finds a gap, is the fix owned and chased to done with status reported?
verify · Pull the corrective-action log from the last AI audit and check the close-out rate.
Risk & Provider Assessment & Management
STA-01Is there a written approach to the risk your AI suppliers and model providers bring?
verify · Ask for the supply-chain risk policy and whether AI/model providers are in scope.
STA-08Do you know every external AI service, model, and data source your systems depend on?
verify · Ask for the AI supply-chain inventory and when it was last reconciled.
STA-10Are the risks from your AI providers assessed and managed on an ongoing basis?
verify · Ask for the last provider risk assessment and its refresh trigger.
STA-13Do you verify your AI providers actually meet the security commitments they made?
verify · Ask for the provider attestations or audit reports you hold and their dates.
IPY-01Is there a written approach to avoiding lock-in to a single AI provider?
verify · Ask for the portability policy and whether AI/model providers are addressed.
IPY-03Could you move to a different AI model or provider without a rebuild?
verify · Ask how the app calls the model and what a provider swap would take.
IPY-04Can you get your data and prompts back out of an AI provider if you leave?
verify · Check the provider contract for data-return/portability terms and test an export.
Infrastructure Security and Resilience
BCR-01Is there a written plan for keeping AI services running through disruption?
verify · Ask for the business-continuity policy and whether AI services are in scope.
BCR-02Have you worked out what an AI outage or failure would actually cost the business?
verify · Ask for the impact analysis and the recovery targets for the AI services.
BCR-08Can you restore the data and configuration your AI depends on if it is lost?
verify · Ask for the last successful restore test of the AI data and configuration.
BCR-06Do you rehearse recovering an AI service before a real outage happens?
verify · Ask for the last continuity exercise and its findings.