
How Amplitude handles 400+ security questionnaires a year with a single reviewer
$1.5M+
Annual value delivered
Hours
Per security review, down from weeks
A SIG questionnaire is the vendor risk assessment that Shared Assessments publishes under the name Standardized Information Gathering. A buyer sends you an Excel workbook, you answer it about your own controls, and because the questions are standard the same answers serve the next buyer who asks. Shared Assessments states that the SIG measures security risks across 21 risk control areas, or domains, within a service provider’s environment.
Built for customer trust, legal, and revenue teams.
SIG Core and SIG Lite are not two questionnaires. They are scope levels the buyer picks from one question set, which is why two workbooks with the same name can be wildly different lengths. The descriptions below are Shared Assessments’ own, taken from the page linked in each row.
Two details catch teams out. There is no published question count for a SIG, because the size is whatever the buyer scoped and Shared Assessments refreshes the content on an annual release cycle, so any figure you read elsewhere is a snapshot of one year and one scope. And the file itself is a spreadsheet. Shared Assessments states that the program only provides the SIG products for user interfaces in Microsoft Excel currently, so plan around a workbook rather than a web form.
Shared Assessments states that the SIG measures security risks across 21 risk control areas, or domains, within a service provider’s environment. The list below is theirs, from the product page linked underneath it.
That spread is why a SIG cannot be answered by one person. Access control and network security sit with security, application management with engineering, privacy management and compliance management with legal, human resources security with HR, and nth party management with whoever owns your subprocessor list. The domain list above is from the SIG on sharedassessments.org.
The domains move. Shared Assessments released the 2026 SIG workbook on 19 September 2025 and named ISO 42001 for AI management systems, NIST SP 800-171, the Business Resilience Council operational resilience framework and the restructured ISO 27001:2022 Annex A controls among its new framework references, which is what an AI governance or resilience domain looks like when it arrives in a questionnaire. Their release note lists the rest.
The standard exists so that you answer once and reuse it. Shared Assessments describes the SIG as standardizing the initial assessment of vendors and other third parties, which only pays off for you if your answers live somewhere they can be reused rather than in the last workbook you emailed.
Two things set the clock. The first is the scope the buyer chose, and because that is a per-domain choice you cannot estimate a SIG before you open it. The second is how findable your own evidence is. Almost every answer already exists somewhere in a policy, an audit report, a control narrative or last quarter’s questionnaire. The work is finding it, deciding whether it is still true, and getting the ones that are not in front of the person who owns them.
The 21 domains add a second cost that a question count never shows, which is coordination. A SIG Core crosses security, engineering, legal, HR and vendor management, so the calendar, not the typing, is usually what a reviewer is waiting on. Narrow the list you send other people to the questions only they can answer.
That is also why the second SIG is rarely cheaper than the first for a team working out of a folder of spreadsheets. Nothing carries forward, so the next reassessment repeats most of the retrieval. Teams that keep a sourced knowledge base pay the retrieval cost once and spend later cycles reviewing.
01
The buyer chose the domains and the scope level, so a workbook labelled SIG can be a short screen or a full assessment of 21 domains. Count the rows, note which domains are in scope, and find the custom questions the buyer added. That tells you who you need and how long this will take.
02
Name the product, the environment and the regions the answers describe. A SIG answered across two products at once produces answers a reviewer cannot rely on, and it is the fastest route to a second round of follow-up questions.
03
Each answer should trace to a policy, a control narrative, your SOC 2 Type II report, a penetration test, or a configuration you can show. Reviewers escalate on unsupported claims far more often than on an honest no with a date next to it.
04
A reviewer reads your SIG next to your SOC 2 report and your policies. A workbook that claims a control the report scopes out is worse than a gap, because it puts every other answer in doubt. Reconcile the three before you send, and fix the document if the document is what is wrong.
05
Partial coverage, a compensating control, or a dated roadmap item all read better than a yes you cannot evidence. That column is what a reviewer actually reads when the answer itself is ambiguous.
06
Access control belongs to security, application management to engineering, privacy and compliance to legal, human resources security to HR, and nth party management to whoever owns the subprocessor list. Route the handful nobody can answer and do not stall the workbook on them.
07
Shared Assessments updates the SIG at least annually, and buyers reassess on their own cycle, so this workbook is not the last one. Answers kept in a maintained, sourced corpus make the next SIG a review. Answers kept in a sent email make it a rebuild.
All three are standard questionnaires, published by different bodies for different buyers. Which one lands in your inbox says more about who is buying than about how thorough they are.
The practical consequence is that the answers travel and the workbooks do not. Your encryption at rest, your incident response process and your subprocessor list do not change because the question moved from a SIG row to a CAIQ row to a HECVAT tab. Maintain one set of sourced evidence and every one of these becomes a mapping exercise. Keep three folders of finished spreadsheets and you answer the same question three times a year. There is also a step-by-step HECVAT walkthrough if that is the workbook in front of you.
We do not republish the questions on this page. The SIG is licensed content from Shared Assessments, so the question text comes from them. If a buyer sent you a SIG, answer the copy they sent.
SIG and Standardized Information Gathering are published by Shared Assessments. The domain list, the scope-level descriptions, the format and the release date on this page are theirs, taken from the pages linked above. Where Shared Assessments does not publish a figure, such as a question count for the current release, this page does not state one.
Wolfia reads the SIG workbook you were sent, drafts every answer from your own policies, audit reports and previous questionnaires, and puts a citation on each one so a reviewer can check the claim instead of trusting it. Questions your corpus cannot answer come back as gaps routed to the person who owns that domain, not as confident guesses. The finished file comes back as Excel with the answers in the right cells, and the same knowledge base answers a CAIQ or a HECVAT without a second setup.

$1.5M+
Annual value delivered
Hours
Per security review, down from weeks

90%
Of questionnaire work done by AI
<2 days
Turnaround, down from five
A SIG questionnaire is a vendor risk assessment published by Shared Assessments, where SIG stands for Standardized Information Gathering. A buyer sends it to a service provider, who answers it about its own controls. Shared Assessments states that the SIG measures security risks across 21 risk control areas, or domains, within a service provider’s environment, and that the SIG products are provided in Microsoft Excel.
They are two scope levels of the same question set rather than two questionnaires. Shared Assessments describes the SIG Lite as a foundation of low-risk level questions for third parties, and the SIG Core as a comprehensive set of questions for third-party service providers that pose a higher risk. A buyer can also build a scoped SIG, choosing any number of risk domains or control families and mixing the Lite, Core and Detail levels across them, plus up to 100 custom questions of their own.
There is no single number, and that is by design. Shared Assessments publishes the SIG as scope levels a buyer configures rather than as one fixed question set, so the workbook in your inbox depends on which domains were selected and at which level, and the content moves with the annual release. Count the rows in the file you were sent rather than planning against a figure from a blog post.
It tracks two things, the scope the buyer chose and how findable your own evidence is. A scoped SIG Lite covering a few domains is an afternoon. A SIG Core across all 21 domains is a cross-team exercise, because access control, application management, privacy, human resources security and nth party management have different owners inside your company. The typing is not the cost. Finding the current answer, deciding whether it is still true, and getting the ones that are not in front of the person who owns them is the cost.
Different publishers and different reach. The SIG comes from Shared Assessments and spans 21 risk domains across the business, including privacy, operational resilience, ESG and nth party management. The CAIQ comes from the Cloud Security Alliance and asks about the control objectives of the Cloud Controls Matrix for one cloud service, so it goes deeper on cloud architecture and does not ask about most of what a SIG asks. The CAIQ is a free download and can be published publicly on the CSA STAR Registry. The SIG is licensed.
No. Shared Assessments states that its members have access to the SIG and that many more companies use it through independent purchase or license. If a buyer sent you a SIG, answer the copy they sent.
An Excel workbook. Shared Assessments states that the program only provides the SIG products for user interfaces in Microsoft Excel currently. In practice a buyer may instead load SIG-derived questions into a hosted risk platform and send you a portal link, in which case the questions are the same and only the surface changed.
Wolfia does. It reads the SIG Lite workbook a buyer sent you, drafts each answer from your own policies, SOC 2 report and previous questionnaires, puts a citation on every answer so a reviewer can check the claim instead of trusting it, routes anything it cannot ground to the person who owns that topic, and returns the file as Excel with the answers in the right cells. The same knowledge base answers a SIG Core, a CAIQ and a HECVAT, so the evidence is maintained once rather than per questionnaire.
We will answer it live, from your own documents, with a citation on every line and the gaps named rather than filled in.
See Wolfia handle your security questionnaires, customer audits, contract reviews and trust center requests. Unlimited seats and outcome-based pricing.
Book a demo