Third-party risk assessment

SIG questionnaire, what it is and how to answer it

A SIG questionnaire is the vendor risk assessment that Shared Assessments publishes under the name Standardized Information Gathering. A buyer sends you an Excel workbook, you answer it about your own controls, and because the questions are standard the same answers serve the next buyer who asks. Shared Assessments states that the SIG measures security risks across 21 risk control areas, or domains, within a service provider’s environment.

Built for customer trust, legal, and revenue teams.

One question set, three sizes

SIG Core vs SIG Lite, and how a SIG questionnaire gets scoped

SIG Core and SIG Lite are not two questionnaires. They are scope levels the buyer picks from one question set, which is why two workbooks with the same name can be wildly different lengths. The descriptions below are Shared Assessments’ own, taken from the page linked in each row.

SIG Lite

SIG FAQ on sharedassessments.org
What it is
Shared Assessments describes the SIG Lite as a foundation of low-risk level questions for third parties. It is what arrives when the service you provide is judged lower risk, or when the buyer wants a first read before deciding whether a fuller assessment is warranted.
Scope level
Lite, which is one of the three scope levels a buyer can choose per domain
Sent to
A lower-risk vendor, an early-stage review, or a screen ahead of a deeper assessment.

SIG Core

SIG FAQ on sharedassessments.org
What it is
Shared Assessments describes the SIG Core as a comprehensive set of questions for third-party service providers that pose a higher risk. It is the edition a buyer sends when you hold sensitive data, run something they depend on, or sit deep in their supply chain.
Scope level
Core, the middle of the three scope levels, which a buyer can also mix with Detail on individual domains
Sent to
A vendor handling regulated or sensitive data, or one whose outage would be their outage.

Scoped SIG

SIG FAQ on sharedassessments.org
What it is
Shared Assessments defines scoping as the act of configuring or creating a SIG Template by choosing the type and level of questions that are appropriate to your assessment requirements. A buyer picks any number of risk domains or control families, mixes the Lite, Core and Detail levels across them, and can add up to 100 custom questions of their own.
Scope level
Whatever the buyer selected, which is why no two scoped SIGs match
Sent to
A review where neither Lite nor Core is specific enough to the service being bought.

Two details catch teams out. There is no published question count for a SIG, because the size is whatever the buyer scoped and Shared Assessments refreshes the content on an annual release cycle, so any figure you read elsewhere is a snapshot of one year and one scope. And the file itself is a spreadsheet. Shared Assessments states that the program only provides the SIG products for user interfaces in Microsoft Excel currently, so plan around a workbook rather than a web form.

What it covers

The 21 risk domains a SIG questionnaire covers

Shared Assessments states that the SIG measures security risks across 21 risk control areas, or domains, within a service provider’s environment. The list below is theirs, from the product page linked underneath it.

  • Access Control
  • Application Management
  • Artificial Intelligence (AI)
  • Asset and Information Management
  • Cloud Services
  • Compliance Management
  • Cybersecurity Incident Management
  • Endpoint Security
  • Enterprise Risk Management
  • Environmental, Social, Governance (ESG)
  • Human Resources Security
  • Information Assurance
  • IT Operations Management
  • Network Security
  • Nth Party Management
  • Operational Resilience
  • Physical and Environmental Security
  • Privacy Management
  • Server Security
  • Supply Chain Risk Management (SCRM)
  • Threat Management

That spread is why a SIG cannot be answered by one person. Access control and network security sit with security, application management with engineering, privacy management and compliance management with legal, human resources security with HR, and nth party management with whoever owns your subprocessor list. The domain list above is from the SIG on sharedassessments.org.

The domains move. Shared Assessments released the 2026 SIG workbook on 19 September 2025 and named ISO 42001 for AI management systems, NIST SP 800-171, the Business Resilience Council operational resilience framework and the restructured ISO 27001:2022 Annex A controls among its new framework references, which is what an AI governance or resilience domain looks like when it arrives in a questionnaire. Their release note lists the rest.

Who asks

Who asks you for a SIG questionnaire

  • Enterprise third-party risk and procurement teams, at vendor onboarding and again at reassessment. The SIG is the workbook a mature risk program standardizes on, which is why the same file arrives from companies that have never spoken to each other.
  • Banks, insurers and other regulated buyers, whose own examiners expect a documented assessment of every service provider that touches customer data.
  • A buyer using a hosted risk platform, which sends SIG-derived questions through a portal rather than as a file. The questions are the same and the answers are the same, only the surface changed.
  • An existing customer, when your architecture, your subprocessors or your certifications change mid-contract.

The standard exists so that you answer once and reuse it. Shared Assessments describes the SIG as standardizing the initial assessment of vendors and other third parties, which only pays off for you if your answers live somewhere they can be reused rather than in the last workbook you emailed.

Effort

How long a SIG questionnaire takes, and why

Two things set the clock. The first is the scope the buyer chose, and because that is a per-domain choice you cannot estimate a SIG before you open it. The second is how findable your own evidence is. Almost every answer already exists somewhere in a policy, an audit report, a control narrative or last quarter’s questionnaire. The work is finding it, deciding whether it is still true, and getting the ones that are not in front of the person who owns them.

The 21 domains add a second cost that a question count never shows, which is coordination. A SIG Core crosses security, engineering, legal, HR and vendor management, so the calendar, not the typing, is usually what a reviewer is waiting on. Narrow the list you send other people to the questions only they can answer.

That is also why the second SIG is rarely cheaper than the first for a team working out of a folder of spreadsheets. Nothing carries forward, so the next reassessment repeats most of the retrieval. Teams that keep a sourced knowledge base pay the retrieval cost once and spend later cycles reviewing.

The procedure

How to answer a SIG questionnaire well

  1. 01

    Read what you were actually sent before answering anything

    The buyer chose the domains and the scope level, so a workbook labelled SIG can be a short screen or a full assessment of 21 domains. Count the rows, note which domains are in scope, and find the custom questions the buyer added. That tells you who you need and how long this will take.

  2. 02

    Fix the scope of the answer, not just the questionnaire

    Name the product, the environment and the regions the answers describe. A SIG answered across two products at once produces answers a reviewer cannot rely on, and it is the fastest route to a second round of follow-up questions.

  3. 03

    Answer from a document, never from memory

    Each answer should trace to a policy, a control narrative, your SOC 2 Type II report, a penetration test, or a configuration you can show. Reviewers escalate on unsupported claims far more often than on an honest no with a date next to it.

  4. 04

    Keep the SIG consistent with the evidence you attach to it

    A reviewer reads your SIG next to your SOC 2 report and your policies. A workbook that claims a control the report scopes out is worse than a gap, because it puts every other answer in doubt. Reconcile the three before you send, and fix the document if the document is what is wrong.

  5. 05

    Use the additional information column instead of over-claiming

    Partial coverage, a compensating control, or a dated roadmap item all read better than a yes you cannot evidence. That column is what a reviewer actually reads when the answer itself is ambiguous.

  6. 06

    Send the real gaps to the person who owns them, and keep the rest moving

    Access control belongs to security, application management to engineering, privacy and compliance to legal, human resources security to HR, and nth party management to whoever owns the subprocessor list. Route the handful nobody can answer and do not stall the workbook on them.

  7. 07

    Keep the finished answers somewhere the next SIG can reuse them

    Shared Assessments updates the SIG at least annually, and buyers reassess on their own cycle, so this workbook is not the last one. Answers kept in a maintained, sourced corpus make the next SIG a review. Answers kept in a sent email make it a rebuild.

Compared

SIG questionnaire vs CAIQ vs HECVAT

All three are standard questionnaires, published by different bodies for different buyers. Which one lands in your inbox says more about who is buying than about how thorough they are.

SIG questionnaire

Published by
Shared Assessments, a membership organization founded in 2005
What it covers
Twenty-one risk domains covering security alongside privacy, operational resilience, ESG, AI and nth party management, so it reaches well past the technical controls.
How you get it
Licensed. Shared Assessments states that its members have access to the SIG and that other companies buy or license it, so it is not a free download.

CAIQ

Read the CAIQ page
Published by
Cloud Security Alliance
What it covers
The control objectives of the Cloud Controls Matrix, turned into yes/no questions about one cloud service. Narrower than a SIG and deeper on cloud architecture.
How you get it
Free to download, and a completed CAIQ can be published on the CSA STAR Registry for buyers to read without asking you.

HECVAT

Read the HECVAT page
Published by
EDUCAUSE
What it covers
Higher education technology purchases, including IT accessibility questions the other two do not ask at all.
How you get it
Free to colleges, universities and their vendors, distributed by EDUCAUSE as one Excel workbook.

The practical consequence is that the answers travel and the workbooks do not. Your encryption at rest, your incident response process and your subprocessor list do not change because the question moved from a SIG row to a CAIQ row to a HECVAT tab. Maintain one set of sourced evidence and every one of these becomes a mapping exercise. Keep three folders of finished spreadsheets and you answer the same question three times a year. There is also a step-by-step HECVAT walkthrough if that is the workbook in front of you.

The official copy

Where the official SIG questionnaire comes from

We do not republish the questions on this page. The SIG is licensed content from Shared Assessments, so the question text comes from them. If a buyer sent you a SIG, answer the copy they sent.

SIG and Standardized Information Gathering are published by Shared Assessments. The domain list, the scope-level descriptions, the format and the release date on this page are theirs, taken from the pages linked above. Where Shared Assessments does not publish a figure, such as a question count for the current release, this page does not state one.

With Wolfia

How Wolfia answers SIG questionnaires

Wolfia reads the SIG workbook you were sent, drafts every answer from your own policies, audit reports and previous questionnaires, and puts a citation on each one so a reviewer can check the claim instead of trusting it. Questions your corpus cannot answer come back as gaps routed to the person who owns that domain, not as confident guesses. The finished file comes back as Excel with the answers in the right cells, and the same knowledge base answers a CAIQ or a HECVAT without a second setup.

  • Questionnaire Agent reads the SIG workbook, drafts every answer with a citation, and returns Excel as Excel with the answers in the right cells.
  • Knowledge Base Agent keeps the policies, audit reports and prior answers behind those answers current, so the next reassessment is a review rather than a rebuild.
  • Chrome Extension Agent fills the same answers into OneTrust, ServiceNow, ProcessUnity, UpGuard and Zip when the buyer routes its assessment through a portal instead of sending a file.
  • Trust Center publishes the documentation a reviewer asks for alongside the workbook, so buyers self-serve before they send anything.
  • CAIQ is the Cloud Security Alliance questionnaire a cloud buyer sends instead, answered from the same corpus.
  • HECVAT is the workbook higher education sends, answered the same way.
  • Security questionnaire questions are the questions buyers ask outside any named standard, with worked answers.
  • The longer SIG walkthrough covers preparation and team ownership question by question.
Customer stories

Security, GRC and revenue teams that answer faster and close sooner

All case studies
Amplitude product analytics dashboard
Amplitude

How Amplitude handles 400+ security questionnaires a year with a single reviewer

$1.5M+

Annual value delivered

Hours

Per security review, down from weeks

Read the story
Handshake employer console with a candidate evaluation card
Handshake

How Handshake cut questionnaire effort by 90% for Fortune 100 reviews

90%

Of questionnaire work done by AI

<2 days

Turnaround, down from five

Read the story
FAQ

SIG questionnaire questions people ask before they answer one

What is a SIG questionnaire?

A SIG questionnaire is a vendor risk assessment published by Shared Assessments, where SIG stands for Standardized Information Gathering. A buyer sends it to a service provider, who answers it about its own controls. Shared Assessments states that the SIG measures security risks across 21 risk control areas, or domains, within a service provider’s environment, and that the SIG products are provided in Microsoft Excel.

What is the difference between SIG Core and SIG Lite?

They are two scope levels of the same question set rather than two questionnaires. Shared Assessments describes the SIG Lite as a foundation of low-risk level questions for third parties, and the SIG Core as a comprehensive set of questions for third-party service providers that pose a higher risk. A buyer can also build a scoped SIG, choosing any number of risk domains or control families and mixing the Lite, Core and Detail levels across them, plus up to 100 custom questions of their own.

How many questions are in a SIG questionnaire?

There is no single number, and that is by design. Shared Assessments publishes the SIG as scope levels a buyer configures rather than as one fixed question set, so the workbook in your inbox depends on which domains were selected and at which level, and the content moves with the annual release. Count the rows in the file you were sent rather than planning against a figure from a blog post.

How long does a SIG questionnaire take?

It tracks two things, the scope the buyer chose and how findable your own evidence is. A scoped SIG Lite covering a few domains is an afternoon. A SIG Core across all 21 domains is a cross-team exercise, because access control, application management, privacy, human resources security and nth party management have different owners inside your company. The typing is not the cost. Finding the current answer, deciding whether it is still true, and getting the ones that are not in front of the person who owns them is the cost.

What is the difference between a SIG questionnaire and a CAIQ?

Different publishers and different reach. The SIG comes from Shared Assessments and spans 21 risk domains across the business, including privacy, operational resilience, ESG and nth party management. The CAIQ comes from the Cloud Security Alliance and asks about the control objectives of the Cloud Controls Matrix for one cloud service, so it goes deeper on cloud architecture and does not ask about most of what a SIG asks. The CAIQ is a free download and can be published publicly on the CSA STAR Registry. The SIG is licensed.

Is the SIG questionnaire free to download?

No. Shared Assessments states that its members have access to the SIG and that many more companies use it through independent purchase or license. If a buyer sent you a SIG, answer the copy they sent.

What format does a SIG questionnaire arrive in?

An Excel workbook. Shared Assessments states that the program only provides the SIG products for user interfaces in Microsoft Excel currently. In practice a buyer may instead load SIG-derived questions into a hosted risk platform and send you a portal link, in which case the questions are the same and only the surface changed.

What software answers a SIG Lite questionnaire?

Wolfia does. It reads the SIG Lite workbook a buyer sent you, drafts each answer from your own policies, SOC 2 report and previous questionnaires, puts a citation on every answer so a reviewer can check the claim instead of trusting it, routes anything it cannot ground to the person who owns that topic, and returns the file as Excel with the answers in the right cells. The same knowledge base answers a SIG Core, a CAIQ and a HECVAT, so the evidence is maintained once rather than per questionnaire.

Bring us a live one

Bring the SIG a buyer just sent you

We will answer it live, from your own documents, with a citation on every line and the gaps named rather than filled in.

Book an exploratory call
Get started

Take the waiting out of your sales cycle

See Wolfia handle your security questionnaires, customer audits, contract reviews and trust center requests. Unlimited seats and outcome-based pricing.

Book a demo