The Standardized Information Gathering (SIG) questionnaire is published and licensed by Shared Assessments, an industry consortium formed in 2005 - originally under BITS, the technology arm of the Financial Services Roundtable - when a group of major banks and audit firms decided it made no sense for every bank to keep sending its shared vendors a bespoke security questionnaire. The SIG is the result: a standardized, modular question set that a vendor can answer once and reuse across many customer relationships, and that a buyer can trust follows a consistent structure instead of reinventing due-diligence questions from scratch. It is not a certification and it does not carry ISO or AICPA-style accreditation; it is a shared vocabulary and a licensed content set, maintained and revised annually by Shared Assessments.
SIG Core vs. SIG Lite
The SIG ships in two working sizes, and picking the right one for a given vendor is most of what makes the tool useful rather than a burden:
- SIG Core is the full instrument - several hundred questions organized under multiple subject areas across roughly twenty risk domains (access control, cloud security, cybersecurity incident management, privacy and data governance, business resiliency, third- and fourth-party management, and - since the 2025 edition - a dedicated artificial intelligence domain, among others). It is meant for vendors that store, process, or transmit sensitive or regulated data and warrant a deep, control-by-control review.
- SIG Lite is a much shorter subset covering only the highest-priority controls across those same domains. It is meant as an initial screen or as the standing questionnaire for lower-tier vendors where a full SIG Core would be disproportionate to the risk.
The 2026 SIG Workbook formalized this choice further by adding built-in Scoping Presets - Lite, Core, and an intermediate Detail preset - so a team can right-size the question set to a vendor's tier without hand-editing a spreadsheet of eight hundred rows every time. That matters because the single most common misuse of the SIG, in practice, is sending SIG Core to every vendor regardless of tier: it is the reason vendors dread receiving one, and it defeats the tool's own design.
What changed in the 2025 and 2026 editions
Shared Assessments revises the SIG on an annual cycle, and the two most recent editions both track the same shift the rest of TPRM is going through: vendors are now themselves buyers and builders of AI, and questionnaires that only ask about traditional infosec controls miss that risk entirely.
- The 2025 SIG update added explicit AI-governance content and referenced ISO/IEC 42001, the international AI management system standard, alongside expanded privacy and operational-resilience questions.
- The 2026 SIG Workbook went further on the same theme: it standardizes assessment of a vendor's AI use across the lifecycle - data collection, model training, deployment, and bias monitoring - rather than treating "do you use AI" as a single yes/no question. It also added "Hover Helpers" (embedded guidance text on individual controls, meant to cut down the back-and-forth clarification emails a questionnaire otherwise generates) and referenced the Business Resilience Council's Operational Resilience Framework. Shared Assessments has also signaled a move away from the traditional Excel workbook toward SIG Evolution (SIG EV), a browser-based platform for creating, distributing, and scoring assessments.
No new risk domains were introduced in the 2026 edition; the AI content deepened within the domain the 2025 edition had already added. That is a useful signal in itself - the SIG's authors are treating AI risk as mature enough to assess in depth, not just flag as a checkbox.
"Trust, but verify": the SIG's relationship to the SCA
The detail buyers most often miss is that the SIG was never meant to stand alone. Shared Assessments pairs it with the Standardized Control Assessment (SCA) - a set of onsite or virtual testing procedures, known before a 2018 rename as the Agreed Upon Procedures (AUP) - under a "trust, but verify" model. The SIG is the trust half: a vendor's own account of its controls. The SCA is the verify half: an assessor actually tests whether those controls operate as described. A completed SIG with no independent verification behind it is still, fundamentally, a self-report - the same limitation covered in why manual vendor risk assessment doesn't scale. Programs that treat a filed SIG as the end of due diligence for a critical vendor are skipping the half of Shared Assessments' own model that actually tests the answer.
How the SIG relates to CAIQ, SOC 2, and ISO 27001
These get confused because they all show up in the same due-diligence packet, but they answer different questions. The SIG is a general-purpose questionnaire usable for any vendor type; the CSA's CAIQ is its cloud-specific counterpart, mapped to the Cloud Security Alliance's Cloud Controls Matrix and published as a free component of the CSA STAR registry rather than a licensed product - which is why cloud-native vendors often keep a CAIQ on file even when their customers standardize on the SIG for everyone else. SOC 2 and ISO/IEC 27001, by contrast, are not questionnaires at all - they are independent audits performed by a CPA firm or accredited certification body. A mature due-diligence packet typically layers the SIG (or CAIQ) for structured self-reported detail alongside SOC 2 or ISO 27001 evidence for independently audited assurance; see the glossary for how each term is defined individually.
Where platforms actually add value on top of the SIG
Licensing and distributing the SIG is table stakes for any TPRM platform; OneTrust and ProcessUnity are particularly strong at managing SIG distribution, scoring, and workflow inside a broader GRC program, and Panorays bundles SIG-based assessment with its own external scanning. The harder problem the SIG does not solve on its own is the "verify" half of Shared Assessments' own model: a completed SIG is still a self-report until something checks it. Rescana's approach is to treat a vendor's SIG responses as one input and cross-reference them against independently observed evidence and attack-surface signal - the same premise covered in automated evidence collection and evidence-based risk scoring - rather than filing the questionnaire away as the assessment's conclusion.
Frequently asked questions
What is the SIG questionnaire?
The SIG (Standardized Information Gathering) questionnaire is a standardized, licensed vendor-security questionnaire published by Shared Assessments, an industry consortium formed in 2005 by major banks and audit firms. It lets a vendor answer one consistent set of questions - covering access control, cloud security, incident management, privacy, business resiliency, third- and fourth-party management, and (since 2025) artificial intelligence, among other domains - and reuse those answers across many customer relationships, instead of completing a differently worded bespoke questionnaire for every buyer.
What is the difference between SIG Core and SIG Lite?
SIG Core is the full questionnaire - several hundred questions across roughly twenty risk domains - intended for vendors that handle sensitive or regulated data and warrant deep, control-by-control review. SIG Lite is a much shorter subset covering only the highest-priority controls in those same domains, intended as an initial screen or as the standing questionnaire for lower-tier vendors. The 2026 SIG Workbook added a third, intermediate Detail preset alongside Lite and Core so a team can scope the question set to a vendor's actual risk tier rather than defaulting to the full SIG Core for every vendor.
Is the Shared Assessments SIG questionnaire free to use?
No. The SIG is a licensed product - Shared Assessments reports several hundred organizations hold a license to distribute it - which sets it apart from the CSA's CAIQ, a comparable cloud-specific questionnaire that the Cloud Security Alliance publishes as a free part of its STAR registry. Many TPRM and GRC platforms include SIG licensing and distribution as part of their product, which is typically how individual security teams access and send it without licensing it directly themselves.
What is the Standardized Control Assessment (SCA) and how does it relate to the SIG?
The SCA is Shared Assessments' companion set of onsite or virtual testing procedures - known before a 2018 rename as the Agreed Upon Procedures (AUP) - built to independently verify that a vendor's controls actually operate as its SIG answers describe. Shared Assessments frames the pairing as 'trust, but verify': the SIG captures a vendor's self-reported account of its controls, and the SCA is the mechanism for testing that account rather than accepting it at face value. A completed SIG with no SCA or equivalent independent verification behind it remains, in substance, a self-report.