What is a SIG Questionnaire
SIG Questionnaire (Standardized Information Gathering) is an industry-standard, framework-mapped set of third-party risk assessment questions used to evaluate a vendor's security, privacy and operational controls through structured self-assessment.
On this page
SIG stands for Standardized Information Gathering, and the questionnaire is a structured, framework-mapped library of questions that vendors complete to describe their own security, privacy and operational controls. It was built to replace the inconsistent, one-off questionnaires that buyers and suppliers had previously exchanged during due diligence, giving both sides a common reference point instead of a bespoke form invented for each engagement.
Structure and content
Question library and modular design
The SIG Questionnaire draws from an underlying content library of more than 1,800 vetted questions, from which organisations select the subset relevant to a given vendor engagement. This modular design is what allows the same underlying standard to produce very different questionnaire instances: a cloud hosting provider and a payroll processor can each receive a SIG-derived questionnaire scoped to their actual service, rather than a generic form padded with irrelevant items. The wording and framework mappings of each question remain standardised even as the selection changes, which is what preserves comparability across vendors and across assessment cycles.
Risk domains covered
Depending on version and release year, the questionnaire measures risk across roughly 19 to 21 defined domains, spanning access control, application security, cloud services, privacy management, operational resilience, and supply chain or nth-party risk. This breadth is deliberate. A vendor's exposure rarely sits in one control area alone, and a questionnaire limited to network security would miss privacy handling or subcontractor risk that could carry equal or greater consequence. The domain structure also lets an assessor drill into one area, such as incident response, without re-running the entire questionnaire.
Versions and scoping
SIG Core
SIG Core is the most comprehensive standard version, containing on the order of 810 to 855 questions, and is intended for vendors that store, process or manage sensitive or regulated information. Its depth suits high-risk or business-critical relationships where a superficial review would leave meaningful gaps unexamined. Because it takes considerably longer for a vendor to complete and for an assessor to review, organisations tend to reserve SIG Core for suppliers whose failure would carry material operational, financial or regulatory consequence.
SIG Lite
SIG Lite is a shorter version, typically containing around 126 to 133 questions, designed to give a high-level view of a vendor's security posture. It suits initial screening or lower-risk third parties where full-depth review would be disproportionate to the exposure involved. Many due diligence workflows use SIG Lite as a first pass, reserving SIG Core for vendors that the initial screen flags as higher risk or that handle sensitive customer data directly.
Custom SIG
Because the underlying question library exceeds 1,800 items, organisations are not limited to the published standard templates. A custom SIG can be assembled to match a specific service type, contractual obligation or regulatory requirement, while retaining the standardised wording and control mappings that make responses comparable across vendors. This matters for buyers who need consistency across a large vendor portfolio without forcing every supplier through an identically shaped form.
Framework mappings and comparison to CAIQ
Cross-mapping to external standards
Each question in the SIG Questionnaire is mapped to multiple external controls and regulatory requirements, enabling alignment to frameworks such as ISO 27001, NIST cybersecurity guidance, PCI DSS, SOC 2 criteria, GDPR and HIPAA within a single assessment. This cross-mapping is a practical efficiency: a vendor answering one SIG instance is implicitly providing evidence relevant to several frameworks at once, rather than completing separate questionnaires for each one. Buyers benefit correspondingly, since a single completed questionnaire can support multiple compliance and audit needs.
SIG versus CAIQ
The Cloud Security Alliance's Consensus Assessments Initiative Questionnaire (CAIQ) is the closest comparable instrument, but it is scoped specifically to cloud service providers and structured around the Cloud Controls Matrix. SIG is broader in scope, covering non-cloud vendors and a wider set of operational and privacy domains, and is not tied to a single control taxonomy in the way CAIQ is tied to cloud security. Organisations assessing a cloud vendor sometimes request both, using CAIQ for cloud-specific control detail and SIG for the wider risk picture.
Self-assessment nature and evidentiary role
What completion actually demonstrates
A completed SIG Questionnaire is a self-assessment, not an audit or certification. Vendors provide the responses themselves, and an assessor evaluates them; there is no independent verification built into the instrument. The completed questionnaire therefore serves as documented evidence that due diligence took place and that a vendor's self-reported controls were reviewed, not as proof that those controls operate as described. Treating a returned SIG as equivalent to a SOC 2 report or an ISO certificate overstates what a self-assessment can establish.
Retention and ongoing monitoring
Completed questionnaires are typically retained alongside supporting documents such as policies, certifications and incident response plans, forming part of a vendor risk file. This file is not a one-time artefact. Because the SIG content itself changes annually, and because a vendor's own control environment changes over time, a questionnaire from two cycles ago is limited evidence of current posture. Ongoing monitoring programmes generally schedule re-assessment on a cadence tied to vendor risk tier rather than relying on a single historical submission.
Implementation and tooling
In practice, the SIG Questionnaire is an Excel document generated from stored scoping templates by a companion tool, Shared Assessments' SIG Manager, according to Shared Assessments. That tool lets users create, customise, store, compare and recall questionnaire instances as part of a broader third-party risk management process, rather than treating each assessment as a standalone file. This distinction matters: the questionnaire is the artefact a vendor completes, while the management tooling is what generates, versions and archives it across an entire vendor portfolio. Confusing the two leads teams to underestimate how much configuration and version control sits behind what looks, on the surface, like a single spreadsheet.
Adoption and annual evolution
Usage relative to custom questionnaires
Survey data on third-party risk programmes indicates that about 18 percent use an industry-standard questionnaire such as SIG, while roughly 57 percent rely on custom questionnaires built in-house. This suggests SIG is widely recognised as a reference standard without being the default choice for most programmes, likely because building or maintaining a custom questionnaire still feels more tailored to some risk teams even where it sacrifices cross-vendor comparability.
Annual update cycle
SIG content is updated on an annual cycle to incorporate new regulations, emerging risks and evolving best practices. Published figures for question counts and domain numbers, such as 810 to 855 questions in SIG Core or 19 to 21 domains, shift slightly from one release to the next as a result. These are not fixed properties of the standard but a snapshot of a living questionnaire that is maintained rather than issued once and left static.
Where SEQUESTO fits into the SIG process
A SIG Questionnaire is standardized on the buyer's side but not on yours: the same framework-mapped questions arrive in different files, from different vendors, on different deadlines, and someone on your team still has to map each one back to evidence you can defend. SEQUESTO is built for that second half, the self-assessment work of turning a fixed set of questions into sourced, approved answers without starting from a blank sheet each time.
Upload the SIG file as received (Excel, Word or PDF) and SEQUESTO's Document Processing pipeline parses it into a structured question list, preserving section, category, weighting and required status. Agents draft answers by retrieving from your Knowledge Hub, past responses, ISO and SOC 2 evidence, security policies, with a citation attached to every answer so a reviewer can check the source before it goes out. Your reviewers edit and approve inside a configured workflow, and the audit log records who approved what and when, giving you the chain of custody a SIG response is meant to demonstrate in the first place.