A SIG, or Standardized Information Gathering questionnaire, is a vendor risk assessment tool built and maintained by Shared Assessments. It comes in two main templates, SIG Core and SIG Lite, and it exists to standardize how organizations collect security and privacy due diligence data from third parties. Its job is to replace one-off vendor surveys with a common language that both sides of an assessment already understand.
TL;DR:
- Using SIG Lite is appropriate for low-risk vendors or initial screenings, while SIG Core is necessary for vendors managing sensitive data or critical supply chain components.
- The latest SIG updates, such as the 2026 version, include explicit questions on AI governance and operational resilience that must be reviewed regularly to maintain compliance.
- Building and maintaining a centralized answer library with evidence attachments and confidence scores significantly reduces response times and avoids duplicate work.
- Over-scoping to SIG Core for every vendor wastes resources, as risk-based template selection improves efficiency and focus on higher-risk areas.
- Automation tools that parse and populate SIG responses from a reusable library can cut response times from weeks to days, especially for organizations handling frequent assessments.
Table of Contents
- What Is a SIG Questionnaire, and Why Does It Exist?
- Who Maintains the SIG, and How Often Does It Change?
- SIG Core, SIG Lite, and Custom Templates: Picking the Right Fit
- What Risk Domains and Frameworks Does the SIG Map To?
- When Should You Actually Use a SIG?
- How to Run or Respond to a SIG Assessment Without Losing Weeks
- SIG vs. CAIQ: Which One Do You Actually Need?
- What Actually Slows Down SIG Response Times, and What Fixes It
- Where Assessors Go Wrong, and How to Correct Course
- Closing the Loop: Faster SIG Responses Without Cutting Corners
- Where to Verify SIG Templates and Updates
- Sources
- FAQ
What Is a SIG Questionnaire, and Why Does It Exist?
Before Shared Assessments built the SIG, every bank, hospital, and software vendor had its own version of the same security survey. A vendor working with fifteen clients might answer fifteen slightly different questionnaires asking, in fifteen different ways, whether it encrypts data at rest. The SIG fixed that by giving the industry one structured set of questions that both assessors and vendors could reuse.
That standardization does more than save time. When every assessor asks the same question about, say, multi-factor authentication, risk teams can compare vendors against each other using consistent data rather than reconciling inconsistent formats. It also gives vendors a single, well-understood target to prepare answers against, instead of guessing what a new client's custom form actually wants to know.
The SIG questionnaire covers a wide span of territory. A completed SIG typically touches:
- Information security policy and governance structure
- Access control and identity management practices
- Data protection, encryption, and privacy handling
- Business continuity and disaster recovery planning
- Physical and environmental security controls
- Vendor and fourth-party risk management practices
That range is the point. A vendor might pass a penetration test with flying colors but still have no documented incident response plan, and a narrow questionnaire would never catch it. The SIG's breadth is designed to surface exactly those gaps.
Who Maintains the SIG, and How Often Does It Change?
Shared Assessments, an industry consortium focused on third-party risk standards, owns and publishes the SIG. Organizations that want the editable templates and full mapping documentation license access through the SIG Manager Content Library, which bundles the Core and Lite templates along with supporting guidance on how to scope them.
Version control matters more with the SIG than most people expect. Shared Assessments updates the questionnaire regularly to keep pace with new regulations and emerging risk categories, and the 2026 revision is a good example of why that cadence matters: it adds explicit questions on AI governance and operational resilience, reflecting how quickly AI tooling has become a vendor risk issue in its own right. Teams that reused an answer library built on a 2023 or 2024 template without checking the changelog would have missed those questions entirely. Frameworks like the NIST AI Risk Management Framework now give assessors a reference point for evaluating those newer AI governance items, since the SIG itself asks the question but doesn't grade the answer.
If your team licenses the Content Library, treat the update notes as required reading each cycle, not optional background.
SIG Core, SIG Lite, and Custom Templates: Picking the Right Fit
Not every vendor deserves the same depth of scrutiny, and Shared Assessments built the SIG around that reality rather than pretending one form fits all. Three template options exist:
- SIG Lite is a streamlined, program-level questionnaire built for lower-risk vendors, quick RFIs, and initial screening where you need a fast yes-or-no read on basic controls.
- SIG Core goes deeper, asking control-level questions with more granularity, and it's the right call for vendors handling sensitive data or occupying a critical spot in your supply chain.
- Custom SIG lets you build a questionnaire from specific risk domains and standard mappings, useful when your industry has regulatory quirks the standard templates don't fully address.
The deciding factor should be your inherent risk calculation, not habit or convenience. Shared Assessments' own guidance recommends scoping the questionnaire to match the vendor's actual risk profile: data sensitivity, access level, regulatory exposure, and how replaceable the vendor is if something goes wrong.
Pro Tip: Don't default to SIG Core for every vendor just because it feels more thorough. Sending a 900-question Core questionnaire to a low-risk marketing tool vendor wastes your analysts' review time and the vendor's patience, and it trains vendors to rush answers rather than think about them.
What Risk Domains and Frameworks Does the SIG Map To?
A SIG questionnaire is organized around defined risk domains, and each domain maps to specific control questions rather than vague prompts. The domains typically include:
- Enterprise risk management and governance
- Information security and access control
- Data privacy and protection
- Third and fourth-party (vendor) risk management
- Business resilience and continuity
- Physical and environmental security
- Compliance and regulatory management
What makes the SIG genuinely useful for cross-framework work is its mapping. Questions in the SIG correspond directly to controls in ISO/IEC 27001, NIST CSF, PCI-DSS, GDPR, and the Cloud Security Alliance's Cloud Controls Matrix. That mapping means a single completed SIG can support multiple compliance obligations at once instead of forcing a vendor to fill out separate forms for each standard an assessor cares about.
SIG Core and SIG Lite differ mainly in how deep that mapping goes. Lite asks whether a control exists, and Core asks how it's implemented, who owns it, and what evidence supports it. If your assessment needs to satisfy an auditor who wants control-level detail tied to a specific ISO clause, Lite won't get you there.
When Should You Actually Use a SIG?
The SIG fits naturally into several points in a vendor's lifecycle, and knowing which moment you're in helps you pick the right depth. Third-party involvement in cloud security incidents remains a significant driver of breaches, which is exactly why front-loading due diligence with a structured questionnaire pays off before a contract is signed, not after.
Common use cases include:
- Initial vendor due diligence, before a contract is signed and access is granted
- Periodic reassessment, typically annually or on a risk-based schedule for existing vendors
- Mergers and acquisitions, where you're inheriting a target company's vendor relationships sight unseen
- Procurement gate reviews, where security sign-off is a condition of moving a deal forward
Scoping by criticality is where most programs either save or waste real time. A vendor with production database access processing regulated customer data warrants SIG Core, full stop. A vendor providing a free trial of scheduling software with no data access beyond a shared calendar rarely needs more than SIG Lite. Watch for signals like data classification level, network access scope, and whether the vendor sits upstream of a regulated process. Those signals should drive the template choice more than the vendor's size or reputation.
How to Run or Respond to a SIG Assessment Without Losing Weeks
Whether you're the one sending the SIG or the one filling it out, the process looks remarkably similar on both sides of the table. Here's the sequence that keeps things moving:
- Scope the assessment. Confirm which template (Core, Lite, or custom) fits the vendor's inherent risk before anyone opens a spreadsheet.
- Assign ownership. Route domain-specific sections to the people who actually know the answers, not to whoever happens to be free that week.
- Gather evidence. Pull policy documents, audit reports, and configuration screenshots that back up each answer rather than relying on memory.
- Annotate answers with context. A bare "yes" tells a reviewer nothing about how confident that answer is or what evidence supports it.
- Validate before submission. Have a second reviewer check for contradictions between sections, since inconsistent answers are the fastest way to trigger follow-up questions.
- Store the results centrally. File the completed SIG and its evidence where the next assessment cycle can find it, not buried in someone's inbox.
The best-run programs build a living answer library rather than starting from a blank template every time. When new evidence is added, they tag it with a confidence score and a reviewer's name, so the next person handling that question knows whether to trust the existing answer or dig deeper.
Pro Tip: Split large SIG Core assessments into domain-specific batches rather than tackling all 15 domains in one document. It's far easier to get a network engineer to answer 40 access-control questions in one sitting than to get them to review an 800-question file and find their section buried on page 47.
For vendors fielding SIGs from multiple clients each quarter, the real bottleneck usually isn't knowledge, it's retrieval. A well-organized answer library, scoped to inherent risk and mapped to evidence, turns a two-week response cycle into a matter of days.
SIG vs. CAIQ: Which One Do You Actually Need?
CAIQ, the Consensus Assessments Initiative Questionnaire from the Cloud Security Alliance, and the SIG solve overlapping but distinct problems. CAIQ was purpose-built for cloud service providers and maps tightly to the Cloud Controls Matrix, making it the sharper tool when you're assessing a pure cloud vendor and want a standardized, cloud-specific lens.
The SIG covers more ground. It handles any third-party relationship, cloud or otherwise, and it lets you scope depth from a quick Lite screen to a full Core deep dive. If your vendor is a payroll processor with on-premises servers, a physical office, and a subcontracted call center, CAIQ won't touch most of that. The SIG will.
A quick decision checklist:
- Assessing a cloud-only service provider with narrow scope? CAIQ often gets you there faster.
- Assessing a vendor with mixed infrastructure, physical operations, or broad data access? SIG covers more of the actual risk surface.
- Need mapping across multiple regulatory frameworks in one document? SIG's cross-mapping to ISO, NIST CSF, PCI-DSS, and GDPR gives you more reuse value.
Many mature TPRM programs use both, sending CAIQ to pure cloud vendors and reserving SIG Core or Lite for everyone else.
What Actually Slows Down SIG Response Times, and What Fixes It
The real bottleneck in most SIG programs isn't the questionnaire itself, it's duplicate work. Teams answer the same question about encryption-at-rest for the fortieth time that quarter because nobody built a system to retrieve the answer they gave in March.
Three things consistently reduce that rework: a canonical answer library with confidence scores attached to each entry, evidence attachments linked directly to the question they support, and an audit trail showing who reviewed and approved each answer. Teams that build all three tend to see real gains in reuse rates and reviewer confidence, since nobody has to guess whether an answer from last year still applies. Integrations with the TPRM platforms and collaboration tools a security team already uses cut out the manual copy-paste step that otherwise eats hours per questionnaire.

Where Assessors Go Wrong, and How to Correct Course
The most common SIG mistake isn't laziness, it's over-scoping. Teams send SIG Core to every vendor regardless of risk, then rubber-stamp answers because nobody has time to actually read 900 responses closely. That trades thoroughness for theater.
Evidence quality should always outrank a clean row of "yes" answers. A vendor who writes two honest sentences about a partial control beats one who checks every box without proof. Keep your template selection tied to your inherent risk model, revisit that mapping whenever Shared Assessments issues an update, and resist the urge to treat scope as a one-size decision.
— Gaspard
Closing the Loop: Faster SIG Responses Without Cutting Corners
If your team is drowning in duplicate SIG questions every quarter, the fix usually isn't more headcount, it's better retrieval. A Questionnaire Automation Tool can parse SIG Core, SIG Lite, and custom formats directly, pull answers from a living library instead of starting cold, and flag evidence gaps before a reviewer ever sees them.
[Image illustrating the concept or feature]
That same answer library also feeds a customizable Trust Center, so vendors fielding repeat SIG requests can point clients to a self-service page instead of rebuilding the same document from scratch. For teams juggling AI governance additions from the 2026 SIG update alongside legacy control questions, having one indexed source of truth matters more than ever. If your SIG volume has outgrown spreadsheets and shared drives, take a look at the security questionnaire automation platform and book a walkthrough to see how your own answer library would map into it.
Where to Verify SIG Templates and Updates
For the most current template versions and scoping guidance, go straight to the source rather than a secondhand summary:
- Shared Assessments' official SIG page for licensing and template access
- The "Which SIG Should I Use" guidance PDF for scoping logic by inherent risk
- Mitratech's summary of the 2026 SIG update for what changed this cycle
Sources
- Which SIG Should I Use_11.1.2023
- Signature block
- SIG 2026: Key Updates and Considerations | Mitratech
FAQ
What Does SIG Stand for in a Security Assessment?
SIG stands for Standardized Information Gathering, a questionnaire framework published by Shared Assessments for evaluating third-party security and privacy controls. It's distinct from the everyday ".sig" email signature file, even though both share the same three-letter abbreviation.
What Is a .SIG File Used For Outside of Vendor Risk?
Outside of third-party risk work, a .sig file typically refers to a small text file containing an email or forum signature block, automatically appended to outgoing messages. Some Outlook installations and legacy file systems still use the .sig extension this way, which has nothing to do with vendor questionnaires.
Is SIG Ever Used as Slang, and Does It Mean Anything Else?
In casual online use, "sig" often just refers to a signature image or text block on forums and social profiles, not a security document. In cybersecurity and compliance contexts, though, SIG almost always refers to the Standardized Information Gathering questionnaire from Shared Assessments.
How Is SIG Core Different From SIG Lite in Practice?
SIG Lite asks lighter, program-level questions suited to lower-risk vendors and quick screening, while SIG Core asks deeper, control-level questions for vendors handling sensitive data or occupying critical roles in your supply chain. The choice between them should follow your inherent risk calculation rather than vendor size alone.
Can Automation Tools Help Complete a SIG Faster?
Yes. Tools like Skypher's Questionnaire Automation platform parse SIG Core and Lite formats directly and pull answers from a reusable library, which cuts down the repetitive work of retyping the same control answers for every new vendor relationship. Current pricing details are available directly on the Skypher site.
