The SIG questionnaire — Standardized Information Gathering, from Shared Assessments — is one of the most widely used templates in third-party due diligence. It ships in two main depths, SIG Core and SIG Lite, so buyers can match the number of questions to the risk in front of them. This guide explains what the SIG covers, how the two tiers differ, and where it sits among other security questionnaires.
The SIG questionnaire is a standardized, configurable risk-assessment template from Shared Assessments that lets a buyer evaluate a vendor's security, privacy, and resilience controls across many domains using a shared, reusable question set.
The SIG — Standardized Information Gathering — is a library of vendor-risk questions maintained by Shared Assessments, a member-driven industry body. Rather than every buyer writing questions from scratch, the SIG gives the market a common vocabulary: a single, versioned question set that spans the control domains a third-party assessment normally touches.
A full SIG covers a broad sweep of risk domains — access control, application security, asset and information management, cloud hosting, incident response, business resilience, and privacy among them. Because it is standardized and refreshed on a regular release cycle, both sides benefit: buyers ask questions that map to recognized frameworks, and vendors answer a form they have likely seen before rather than deciphering a one-off spreadsheet.
The SIG is not one fixed form. It is issued in tiers so the depth can match the risk:
The distinction matters because sending SIG Core to every vendor is the classic due-diligence mistake: it buries the handful of answers that matter under hundreds that don't, and it trains vendors to autopilot through your questions. SIG Lite exists precisely so that depth can be a decision, not a default.
The SIG appears most often in regulated and enterprise procurement — financial services, healthcare, and any program that assesses a large vendor population and needs consistency across it. Its value grows with scale: when you assess hundreds of vendors, a standardized set makes results comparable and repeatable in a way that bespoke forms never are.
It also plays well with evidence you already hold. A SIG response is frequently read alongside a vendor's SOC 2 report, an ISO 27001 certificate, or a CAIQ for cloud-specific controls — each answering part of the picture. Mature programs treat the SIG as the connective tissue between those artifacts rather than a replacement for them, and they accept an existing document in place of re-asking what it already covers.
A standardized questionnaire solves the consistency problem, but not the proportionality one. The SIG can still be sent at the wrong depth — Core where Lite would do, or Lite where the vendor's access demanded Core. The fix is to let the vendor's actual exposure set the tier before you choose a form.
This is the inside-out principle: classify each vendor by what they hold of yours — data, network access, facilities, designs, people, supply — and let that exposure decide how hard you look. You then choose SIG Core, SIG Lite, or a custom domain selection because the risk warrants it, not because it was the template already open.
For vendors on the receiving end, the SIG's standardization is an opportunity. Because the same underlying questions recur across buyers, a well-built reusable answer library turns each new SIG from a writing job into a mapping job. Answer once, store it, and the next request becomes a matter of alignment rather than authorship.
Publishing that evidence in a trust center goes one step further: buyers can self-serve your certifications, subprocessor list, and standard answers before a form is ever sent — often shortening the questionnaire, and sometimes removing it entirely.
Publish your SIG answers, certifications, and subprocessor list once — with NDA-gated documents, a reusable answer library, a custom domain, and unlimited imports, and no paid gates.
See the Trust Center →The SIG (Standardized Information Gathering) questionnaire is a standardized vendor-risk template from Shared Assessments. It spans many control domains — access control, application security, incident response, resilience, and privacy among them — so buyers can assess a vendor with a common, reusable question set.
SIG Core is the comprehensive, deep questionnaire for higher-risk vendors that hold significant access or sensitive data. SIG Lite is a shorter, higher-level subset for lower-risk relationships or a first-pass screen. Both draw from the same Shared Assessments content library.
No. The SIG is broad and cross-domain, from Shared Assessments. The CAIQ, from the Cloud Security Alliance, is focused on cloud service providers and maps to the Cloud Controls Matrix. Many programs use both: the SIG for overall vendor risk and the CAIQ for cloud-specific controls.
Shared Assessments releases the SIG on a regular cycle, refreshing the content to track evolving frameworks and regulations. Using a current version keeps a vendor's answers mapped to the standards buyers expect.