Guide · Assessment

The SIG questionnaire, Core and Lite.

Assessment · 8 min read · Updated July 2026

The SIG questionnaire — Standardized Information Gathering, from Shared Assessments — is one of the most widely used templates in third-party due diligence. It ships in two main depths, SIG Core and SIG Lite, so buyers can match the number of questions to the risk in front of them. This guide explains what the SIG covers, how the two tiers differ, and where it sits among other security questionnaires.

In one sentence

The SIG questionnaire is a standardized, configurable risk-assessment template from Shared Assessments that lets a buyer evaluate a vendor's security, privacy, and resilience controls across many domains using a shared, reusable question set.

What the SIG questionnaire is

The SIG — Standardized Information Gathering — is a library of vendor-risk questions maintained by Shared Assessments, a member-driven industry body. Rather than every buyer writing questions from scratch, the SIG gives the market a common vocabulary: a single, versioned question set that spans the control domains a third-party assessment normally touches.

A full SIG covers a broad sweep of risk domains — access control, application security, asset and information management, cloud hosting, incident response, business resilience, and privacy among them. Because it is standardized and refreshed on a regular release cycle, both sides benefit: buyers ask questions that map to recognized frameworks, and vendors answer a form they have likely seen before rather than deciphering a one-off spreadsheet.

SIG Core vs SIG Lite

The SIG is not one fixed form. It is issued in tiers so the depth can match the risk:

  • SIG Core. The comprehensive set — a deep, wide-ranging questionnaire intended for vendors that hold significant access or sensitive data. It is the version you reach for when a vendor's exposure justifies full scrutiny across every domain.
  • SIG Lite. A shorter, higher-level subset drawn from the same library. It gathers a broad picture quickly, for lower-risk relationships or as a first-pass screen before you decide whether a deeper review is warranted.
  • Custom scoping. Because the SIG is built from a structured content library, buyers can also select the specific domains relevant to a given vendor rather than sending the entire set — the standardized way to right-size a questionnaire.

The distinction matters because sending SIG Core to every vendor is the classic due-diligence mistake: it buries the handful of answers that matter under hundreds that don't, and it trains vendors to autopilot through your questions. SIG Lite exists precisely so that depth can be a decision, not a default.

When the SIG is used

The SIG appears most often in regulated and enterprise procurement — financial services, healthcare, and any program that assesses a large vendor population and needs consistency across it. Its value grows with scale: when you assess hundreds of vendors, a standardized set makes results comparable and repeatable in a way that bespoke forms never are.

It also plays well with evidence you already hold. A SIG response is frequently read alongside a vendor's SOC 2 report, an ISO 27001 certificate, or a CAIQ for cloud-specific controls — each answering part of the picture. Mature programs treat the SIG as the connective tissue between those artifacts rather than a replacement for them, and they accept an existing document in place of re-asking what it already covers.

Scope depth to exposure, not to a template

A standardized questionnaire solves the consistency problem, but not the proportionality one. The SIG can still be sent at the wrong depth — Core where Lite would do, or Lite where the vendor's access demanded Core. The fix is to let the vendor's actual exposure set the tier before you choose a form.

This is the inside-out principle: classify each vendor by what they hold of yours — data, network access, facilities, designs, people, supply — and let that exposure decide how hard you look. You then choose SIG Core, SIG Lite, or a custom domain selection because the risk warrants it, not because it was the template already open.

Answering the SIG once

For vendors on the receiving end, the SIG's standardization is an opportunity. Because the same underlying questions recur across buyers, a well-built reusable answer library turns each new SIG from a writing job into a mapping job. Answer once, store it, and the next request becomes a matter of alignment rather than authorship.

Publishing that evidence in a trust center goes one step further: buyers can self-serve your certifications, subprocessor list, and standard answers before a form is ever sent — often shortening the questionnaire, and sometimes removing it entirely.

Answer once, keep it
Polestead's Trust Center is free at full depth.

Publish your SIG answers, certifications, and subprocessor list once — with NDA-gated documents, a reusable answer library, a custom domain, and unlimited imports, and no paid gates.

See the Trust Center →
FAQ

Common questions.

What is the SIG questionnaire?+

The SIG (Standardized Information Gathering) questionnaire is a standardized vendor-risk template from Shared Assessments. It spans many control domains — access control, application security, incident response, resilience, and privacy among them — so buyers can assess a vendor with a common, reusable question set.

What is the difference between SIG Core and SIG Lite?+

SIG Core is the comprehensive, deep questionnaire for higher-risk vendors that hold significant access or sensitive data. SIG Lite is a shorter, higher-level subset for lower-risk relationships or a first-pass screen. Both draw from the same Shared Assessments content library.

Is the SIG the same as CAIQ?+

No. The SIG is broad and cross-domain, from Shared Assessments. The CAIQ, from the Cloud Security Alliance, is focused on cloud service providers and maps to the Cloud Controls Matrix. Many programs use both: the SIG for overall vendor risk and the CAIQ for cloud-specific controls.

How often is the SIG updated?+

Shared Assessments releases the SIG on a regular cycle, refreshing the content to track evolving frameworks and regulations. Using a current version keeps a vendor's answers mapped to the standards buyers expect.

Keep reading
Security questionnaires
The wider practice the SIG sits inside.
CAIQ
The cloud-specific questionnaire, compared.
Trust Center →
Publish your answers once, free at full depth.