Organizations collaborate on mutual goal of evaluating risks and defining controls related to generative artificial intelligence.

The Cloud Security Alliance (CSA) and Whistic have announced a strategic partnership aimed at promoting the responsible development, use, and management of artificial intelligence (AI) technologies. As per the agreement, Whistic will support the CSA's AI Safety Initiative, focusing on developing an AI extension to the Security, Trust, Assurance, and Risk (STAR) certification and the Compliance Automation Revolution, which is set to be unveiled later this month.

Jim Reavis, co-founder and CEO of Cloud Security Alliance, highlighted the importance of trust in AI solutions, given their prevalence across cloud and Software-as-a-Service (SaaS) offerings. He expressed enthusiasm for the partnership, stating, “We’re extremely pleased to partner with Whistic in furthering a responsible AI future.” Whistic's CEO, Nick Sorensen, echoed this sentiment, emphasizing the goal of creating industry standards and practices that ensure AI’s safe and transparent use.

As part of the partnership, CSA members will gain access to a three-month free trial of Whistic, enabling them to evaluate vendor security documentation against CSA’s Consensus Assessment Initiative Questionnaire (CAIQ) frameworks. Additionally, participants will have access to the Whistic Trust Catalog, which contains thousands of profiles with vendor security and compliance documentation.

Moreover, CSA members who have completed CAIQ profiles, as well as non-member enterprises on CSA’s Security, Trust, Assurance, and Risk Registry, can contribute their documentation to the Whistic Trust Center, facilitating automatic responses to ad-hoc security questionnaires.

The organizations will also hold a webinar on January 28, led by Whistic’s Nick Sorensen and CSA’s Chief Technology Officer Daniele Catteddu, to discuss how AI is transforming third-party risk management through automated processes.

This collaboration underscores a growing recognition of the importance of secure AI practices in managing third-party risk and enhancing vendor assessments.