CAIQ v4 Control GRC-03 Extractive Review Standard

How to answer 'How often do you perform formal enterprise risk assessments?' on a CAIQ

Reviewer Guidance & Pitfalls

State that formal enterprise risk assessments are conducted at least annually or upon significant architectural changes, with findings reviewed by executive leadership.

Example Answer Passing Enterprise Audit

Compliant Response Template
Formal enterprise risk assessments are conducted annually by the security team and reviewed with leadership to prioritize remediation and update security controls (SOC 2, CC3.1).

Filling out a CAIQ or SIG Lite right now?

QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.

Zero spam. 100% confidential. No credit card required.