CAIQ v4 Control STA-09 Extractive Review Standard

How to answer 'Do you assess the security of your own vendors?' on a CAIQ

Reviewer Guidance & Pitfalls

State the evaluation criteria (requiring current SOC 2 Type II or ISO 27001 from critical vendors), the review frequency (annual re-assessment), and whether a formal vendor risk tiering policy is in place.

Example Answer Passing Enterprise Audit

Compliant Response Template
Yes. All third-party vendors with access to customer data or production infrastructure undergo an annual security review requiring SOC 2 Type II or ISO 27001 certifications (SOC 2, CC9.2).

Filling out a CAIQ or SIG Lite right now?

QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.

Zero spam. 100% confidential. No credit card required.