This guide covers all domains tested in the CAIA examination — assessed against the PAI-8 AI Safety Standard. Each domain includes key concepts, worked audit scenarios, and the evidence-gathering approach required at each maturity level.
Every PAI-8 control is assessed against a four-level maturity scale. Knowing which level requires which evidence is central to the CAIA exam.
| Control | Domain |
|---|---|
| C1 | AI Governance |
| C2 | Risk Assessment |
| C3 | Data Stewardship |
| C4 | Model Validation |
| C5 | Human Oversight |
| C6 | Incident Response |
| C7 | Audit Trail |
| C8 | Vendor & Supply Chain |
| + | Audit Methodology |
An organisation has a published AI ethics policy but no evidence it has been communicated to staff or embedded in any decision-making process. What PAI-8 maturity level does this represent?
During a C1 audit interview, the CISO says they own all AI risk. The CTO says AI governance is an ethics matter owned by Legal. What is your finding?
An organisation conducts AI risk assessments annually, but a major model upgrade occurred six months ago without triggering a reassessment. What is your C2 finding?
An organisation uses historical customer service chat logs to fine-tune their LLM. The original privacy notice said data was collected "to provide customer service." Is this a C3 finding?
Before deploying a new LLM, the team tests it with 10–15 ad-hoc prompts chosen by the lead engineer. There is no defined eval set, no pass threshold, and no documentation. What C4 maturity level?
An organisation has a documented AI output review process that is applied regularly, with defined reviewers and escalation criteria. What additional evidence is needed to achieve C5 L3?
An organisation has a mature IT incident response process but no AI-specific incident definitions, categorisation, or response procedures. They handle AI incidents as IT incidents. What is your C6 finding?
An organisation logs all AI interactions: user input, AI output, and timestamp. Model version and system prompt version are not logged. What is your C7 finding?
An organisation has signed a contract with an LLM API provider. There is no clause requiring the provider to notify the organisation of material model changes. What is the C8 finding?
During a C1 interview, the Head of AI says "we have L2 governance — we have a committee, we meet monthly, and we apply it to all AI deployments." What evidence do you request to substantiate this claim?
You now have the PAI-8 framework and audit methodology foundation. The CAIA exam tests applied reasoning — read each scenario carefully, identify which control domain applies, assess the evidence against the maturity level criteria, and select the most precise finding.
Purchase Exam Access — $97 →