SIG Questionnaire
The SIG (Standardized Information Gathering) Questionnaire is a standardized set of questions that organizations use to collect information about a vendor's security, privacy, and risk practices. It is maintained by Shared Assessments and helps a company evaluate the risks of working with a third party. Different versions exist, including a fuller version and a lighter version, so the depth of questioning can be matched to the level of scrutiny needed.
The SIG Questionnaire is a standardized vendor-risk assessment instrument maintained by Shared Assessments, used within third-party and supply-chain risk management programs to gather information on a vendor's control environment. It is issued in tiered forms (commonly referenced as SIG Core and SIG Lite) that vary in scope and depth, and its content is intended to map to the requirements of multiple cybersecurity regulations and frameworks, allowing a single questionnaire to support several compliance objectives. In practice it functions as a self-assessment or evidence-gathering tool completed by the vendor and reviewed by the assessing organization; the responses inform risk decisions but do not by themselves constitute an audit, certification, or a guarantee of compliance. Note that the SIG is a security- and risk-oriented instrument rather than a data governance artifact, and it does not substitute for controller/processor obligations, records of processing activities, or contractual data protection terms under any specific privacy regime. This entry does not address version-specific question counts, licensing terms, or the internal control domains covered by the questionnaire, and treatment of vendor-risk documentation varies by jurisdiction and applicable framework.
Why it matters
Third-party and supply-chain relationships extend an organization's risk surface beyond its own perimeter, and assessing a vendor's control environment before and during an engagement is a core discipline of third-party risk management. The SIG Questionnaire matters because it provides a standardized, widely recognized instrument for gathering that information, which reduces the friction of every organization inventing its own bespoke vendor questionnaire. Because a single SIG can be mapped to the requirements of multiple cybersecurity regulations and frameworks, it can support several assessment objectives at once and give vendors a consistent format to respond to, rather than fielding a different set of questions from each customer.
Its value, however, is bounded by what it is: a self-assessment or evidence-gathering tool completed by the vendor and reviewed by the assessing organization. The responses inform risk decisions but do not by themselves constitute an audit, a certification, or a guarantee of compliance. Treating a completed SIG as proof of a vendor's security posture, rather than as one input to be corroborated with evidence and, where warranted, independent assurance, is a common misuse that can leave real gaps unaddressed.
Just as importantly, the SIG is a security- and risk-oriented instrument rather than a data governance or privacy compliance artifact. It does not substitute for allocating controller and processor obligations, maintaining records of processing activities, or putting appropriate contractual data protection terms in place under any specific privacy regime. Organizations that rely on a SIG to discharge those distinct obligations conflate vendor security assessment with data protection accountability, which under governance frameworks generally requires demonstrable evidence rather than a self-reported questionnaire response.
Who it's relevant to
Inside SIG
Common questions
Answers to the questions practitioners most commonly ask about SIG.