Frameworks

The Shared Assessments SIG questionnaire explained: SIG Core, SIG Lite, and how to use it well

The SIG is the closest thing third-party risk management has to a lingua franca: one licensed questionnaire that hundreds of organizations use so vendors are not forced to answer a differently worded version of the same hundred questions for every customer. Here is what is actually in it, how it has changed recently, and where it fits - and does not fit - in a working program.

The Standardized Information Gathering (SIG) questionnaire is published and licensed by Shared Assessments, an industry consortium formed in 2005 - originally under BITS, the technology arm of the Financial Services Roundtable - when a group of major banks and audit firms decided it made no sense for every bank to keep sending its shared vendors a bespoke security questionnaire. The SIG is the result: a standardized, modular question set that a vendor can answer once and reuse across many customer relationships, and that a buyer can trust follows a consistent structure instead of reinventing due-diligence questions from scratch. It is not a certification and it does not carry ISO or AICPA-style accreditation; it is a shared vocabulary and a licensed content set, maintained and revised annually by Shared Assessments.

SIG Core vs. SIG Lite

The SIG ships in two working sizes, and picking the right one for a given vendor is most of what makes the tool useful rather than a burden:

The 2026 SIG Workbook formalized this choice further by adding built-in Scoping Presets - Lite, Core, and an intermediate Detail preset - so a team can right-size the question set to a vendor's tier without hand-editing a spreadsheet of eight hundred rows every time. That matters because the single most common misuse of the SIG, in practice, is sending SIG Core to every vendor regardless of tier: it is the reason vendors dread receiving one, and it defeats the tool's own design.

What changed in the 2025 and 2026 editions

Shared Assessments revises the SIG on an annual cycle, and the two most recent editions both track the same shift the rest of TPRM is going through: vendors are now themselves buyers and builders of AI, and questionnaires that only ask about traditional infosec controls miss that risk entirely.

No new risk domains were introduced in the 2026 edition; the AI content deepened within the domain the 2025 edition had already added. That is a useful signal in itself - the SIG's authors are treating AI risk as mature enough to assess in depth, not just flag as a checkbox.

"Trust, but verify": the SIG's relationship to the SCA

The detail buyers most often miss is that the SIG was never meant to stand alone. Shared Assessments pairs it with the Standardized Control Assessment (SCA) - a set of onsite or virtual testing procedures, known before a 2018 rename as the Agreed Upon Procedures (AUP) - under a "trust, but verify" model. The SIG is the trust half: a vendor's own account of its controls. The SCA is the verify half: an assessor actually tests whether those controls operate as described. A completed SIG with no independent verification behind it is still, fundamentally, a self-report - the same limitation covered in why manual vendor risk assessment doesn't scale. Programs that treat a filed SIG as the end of due diligence for a critical vendor are skipping the half of Shared Assessments' own model that actually tests the answer.

How the SIG relates to CAIQ, SOC 2, and ISO 27001

These get confused because they all show up in the same due-diligence packet, but they answer different questions. The SIG is a general-purpose questionnaire usable for any vendor type; the CSA's CAIQ is its cloud-specific counterpart, mapped to the Cloud Security Alliance's Cloud Controls Matrix and published as a free component of the CSA STAR registry rather than a licensed product - which is why cloud-native vendors often keep a CAIQ on file even when their customers standardize on the SIG for everyone else. SOC 2 and ISO/IEC 27001, by contrast, are not questionnaires at all - they are independent audits performed by a CPA firm or accredited certification body. A mature due-diligence packet typically layers the SIG (or CAIQ) for structured self-reported detail alongside SOC 2 or ISO 27001 evidence for independently audited assurance; see the glossary for how each term is defined individually.

Where platforms actually add value on top of the SIG

Licensing and distributing the SIG is table stakes for any TPRM platform; OneTrust and ProcessUnity are particularly strong at managing SIG distribution, scoring, and workflow inside a broader GRC program, and Panorays bundles SIG-based assessment with its own external scanning. The harder problem the SIG does not solve on its own is the "verify" half of Shared Assessments' own model: a completed SIG is still a self-report until something checks it. Rescana's approach is to treat a vendor's SIG responses as one input and cross-reference them against independently observed evidence and attack-surface signal - the same premise covered in automated evidence collection and evidence-based risk scoring - rather than filing the questionnaire away as the assessment's conclusion.

Frequently asked questions

What is the SIG questionnaire?

The SIG (Standardized Information Gathering) questionnaire is a standardized, licensed vendor-security questionnaire published by Shared Assessments, an industry consortium formed in 2005 by major banks and audit firms. It lets a vendor answer one consistent set of questions - covering access control, cloud security, incident management, privacy, business resiliency, third- and fourth-party management, and (since 2025) artificial intelligence, among other domains - and reuse those answers across many customer relationships, instead of completing a differently worded bespoke questionnaire for every buyer.

What is the difference between SIG Core and SIG Lite?

SIG Core is the full questionnaire - several hundred questions across roughly twenty risk domains - intended for vendors that handle sensitive or regulated data and warrant deep, control-by-control review. SIG Lite is a much shorter subset covering only the highest-priority controls in those same domains, intended as an initial screen or as the standing questionnaire for lower-tier vendors. The 2026 SIG Workbook added a third, intermediate Detail preset alongside Lite and Core so a team can scope the question set to a vendor's actual risk tier rather than defaulting to the full SIG Core for every vendor.

Is the Shared Assessments SIG questionnaire free to use?

No. The SIG is a licensed product - Shared Assessments reports several hundred organizations hold a license to distribute it - which sets it apart from the CSA's CAIQ, a comparable cloud-specific questionnaire that the Cloud Security Alliance publishes as a free part of its STAR registry. Many TPRM and GRC platforms include SIG licensing and distribution as part of their product, which is typically how individual security teams access and send it without licensing it directly themselves.

What is the Standardized Control Assessment (SCA) and how does it relate to the SIG?

The SCA is Shared Assessments' companion set of onsite or virtual testing procedures - known before a 2018 rename as the Agreed Upon Procedures (AUP) - built to independently verify that a vendor's controls actually operate as its SIG answers describe. Shared Assessments frames the pairing as 'trust, but verify': the SIG captures a vendor's self-reported account of its controls, and the SCA is the mechanism for testing that account rather than accepting it at face value. A completed SIG with no SCA or equivalent independent verification behind it remains, in substance, a self-report.