CAIQ v4 Control STA-20 Extractive Review Standard

How to answer 'What criteria trigger a mandatory security reassessment of an existing vendor?' on a CAIQ

Reviewer Guidance & Pitfalls

List triggers: annual review, material scope changes, significant security incidents, or subprocessor changes.

Example Answer Passing Enterprise Audit

Compliant Response Template
Vendor re-assessments are triggered annually or immediately upon scope expansion, reported security incidents, or major architecture changes (SOC 2, CC9.2).

Filling out a CAIQ or SIG Lite right now?

QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.

Zero spam. 100% confidential. No credit card required.