Skip to main content
Category: Breach and Risk Assessment

SIG Questionnaire

Also known as: SIG, Standardized Information Gathering Questionnaire, Standard Information Gathering Questionnaire, SIG Core, SIG Lite
Simply put

The SIG (Standardized Information Gathering) Questionnaire is a standardized set of questions that organizations use to collect information about a vendor's security, privacy, and risk practices. It is maintained by Shared Assessments and helps a company evaluate the risks of working with a third party. Different versions exist, including a fuller version and a lighter version, so the depth of questioning can be matched to the level of scrutiny needed.

Formal definition

The SIG Questionnaire is a standardized vendor-risk assessment instrument maintained by Shared Assessments, used within third-party and supply-chain risk management programs to gather information on a vendor's control environment. It is issued in tiered forms (commonly referenced as SIG Core and SIG Lite) that vary in scope and depth, and its content is intended to map to the requirements of multiple cybersecurity regulations and frameworks, allowing a single questionnaire to support several compliance objectives. In practice it functions as a self-assessment or evidence-gathering tool completed by the vendor and reviewed by the assessing organization; the responses inform risk decisions but do not by themselves constitute an audit, certification, or a guarantee of compliance. Note that the SIG is a security- and risk-oriented instrument rather than a data governance artifact, and it does not substitute for controller/processor obligations, records of processing activities, or contractual data protection terms under any specific privacy regime. This entry does not address version-specific question counts, licensing terms, or the internal control domains covered by the questionnaire, and treatment of vendor-risk documentation varies by jurisdiction and applicable framework.

Why it matters

Third-party and supply-chain relationships extend an organization's risk surface beyond its own perimeter, and assessing a vendor's control environment before and during an engagement is a core discipline of third-party risk management. The SIG Questionnaire matters because it provides a standardized, widely recognized instrument for gathering that information, which reduces the friction of every organization inventing its own bespoke vendor questionnaire. Because a single SIG can be mapped to the requirements of multiple cybersecurity regulations and frameworks, it can support several assessment objectives at once and give vendors a consistent format to respond to, rather than fielding a different set of questions from each customer.

Its value, however, is bounded by what it is: a self-assessment or evidence-gathering tool completed by the vendor and reviewed by the assessing organization. The responses inform risk decisions but do not by themselves constitute an audit, a certification, or a guarantee of compliance. Treating a completed SIG as proof of a vendor's security posture, rather than as one input to be corroborated with evidence and, where warranted, independent assurance, is a common misuse that can leave real gaps unaddressed.

Just as importantly, the SIG is a security- and risk-oriented instrument rather than a data governance or privacy compliance artifact. It does not substitute for allocating controller and processor obligations, maintaining records of processing activities, or putting appropriate contractual data protection terms in place under any specific privacy regime. Organizations that rely on a SIG to discharge those distinct obligations conflate vendor security assessment with data protection accountability, which under governance frameworks generally requires demonstrable evidence rather than a self-reported questionnaire response.

Who it's relevant to

Third-Party Risk Management teams
TPRM and vendor risk teams use the SIG to gather standardized information about a vendor's control environment and to inform risk decisions during onboarding and ongoing monitoring. They should treat responses as one input to be corroborated with supporting evidence, not as an audit or certification.
Security and information security leads
Because the SIG is a security- and risk-oriented instrument, security teams are typically the ones interpreting responses about a vendor's controls. They generally coordinate with governance and privacy functions, since the questionnaire does not by itself cover data governance artifacts or controller/processor obligations.
Vendors and service providers
Organizations that supply services often complete the SIG as a self-assessment for their customers. The standardized format and tiered versions can reduce the burden of responding to many differently structured questionnaires, though completing one does not demonstrate compliance on its own.
Data protection and privacy officers
DPOs and privacy leads should recognize that a completed SIG does not substitute for records of processing activities, allocation of controller and processor responsibilities, or contractual data protection terms under any specific privacy regime. It may complement, but not replace, those distinct accountability obligations.
Compliance and governance teams
Compliance functions benefit from the SIG's mapping to multiple cybersecurity regulations and frameworks, which can support several assessment objectives at once. They should ensure that reliance on self-reported questionnaire responses is backed by demonstrable evidence where the applicable framework requires it.

Inside SIG

Standardized Assessment Structure
The SIG (Standardized Information Gathering) Questionnaire is a repository of questions used to assess third-party and vendor risk across multiple control domains. It is maintained by Shared Assessments and provides a common framework so that organizations can evaluate suppliers using consistent categories rather than bespoke questionnaires.
Control Domain Coverage
The questionnaire typically spans domains such as information security, privacy, data governance, business resilience, and operational controls. Coverage is organized so that assessors can examine how a vendor handles confidentiality, integrity, and availability alongside governance topics like data ownership and policy.
Tiered Question Sets
SIG is generally offered in different scopes so that assessors can select a broader or more focused set of questions depending on the criticality of the vendor relationship. This allows the depth of due diligence to be matched to the assessed risk of the engagement.
Mapping to External Frameworks
The questionnaire is generally designed to align with recognized standards and regulatory reference points so responses can be cross-referenced to controls an organization already tracks. Precise mappings and the specific frameworks referenced depend on the version in use and should be confirmed against the current release.
Vendor Self-Attestation Responses
The completed questionnaire captures a vendor's stated responses about its controls. These attestations are declarations of intent and practice and, under an accountability model, generally require supporting evidence or independent verification to be relied upon.

Common questions

Answers to the questions practitioners most commonly ask about SIG.

Does completing a SIG Questionnaire mean a vendor is compliant with data protection law?
No. The SIG (Standardized Information Gathering) Questionnaire is a due diligence and assessment tool used to collect information about a third party's security, privacy, and control environment. Responses reflect what a vendor states about its practices; they are not an attestation of compliance with any specific regime such as the EU GDPR, UK GDPR, CCPA and CPRA, HIPAA, or ISO/IEC 27701. Compliance depends on the applicable jurisdiction, the nature of the processing, and how controls are actually implemented and evidenced. A questionnaire response should generally be treated as an input to a risk assessment, not as proof of a compliant state.
Is a SIG Questionnaire the same as a formal audit or certification of a vendor's controls?
No. A SIG Questionnaire is typically a self-reported instrument in which the responding organization describes its own controls. It is distinct from an independent audit or a third-party certification, where an external party examines and validates evidence. Under governance and accountability principles, demonstrable evidence generally carries more weight than stated intent, so questionnaire answers are often corroborated with supporting artifacts such as reports, policies, or certifications obtained separately. The questionnaire itself does not verify the claims it captures.
How should an organization decide which SIG scope or tier to send to a vendor?
Scope selection is generally driven by the risk profile of the engagement, including the sensitivity of the data involved, the volume of processing, the criticality of the service, and whether special category or sensitive data is handled. A more limited set is often used for lower-risk relationships, while a fuller set is used where the vendor acts on personal data in a higher-risk capacity. The appropriate tier should be documented as part of the assessment rationale. This entry does not prescribe specific tier names or content, which are defined by the questionnaire's own structure and may change across versions.
Who within the organization should own the review of SIG responses?
Ownership typically spans several functions rather than sitting with one role. Information security teams generally assess control-related responses covering confidentiality, integrity, and availability, while data protection or privacy functions review responses relevant to processing of personal data, roles as controller or processor, and related obligations. Procurement or vendor management often coordinates the workflow. Accountability for accepting residual risk should be assigned to a defined risk owner. This entry does not cover internal approval thresholds, which vary by organization.
What should reviewers do when SIG responses appear incomplete or inconsistent?
Reviewers generally follow up to request clarification and, where appropriate, corroborating evidence such as supporting documentation or independent reports. Gaps or inconsistencies are typically logged as findings and factored into the risk rating for the engagement, with remediation expectations or contractual conditions applied as needed. Because the questionnaire is self-reported, unresolved discrepancies should not be treated as satisfied. This entry does not define specific remediation timelines or escalation criteria, which depend on internal policy and the risk involved.
How does a SIG Questionnaire fit alongside other data protection assessment obligations?
A SIG Questionnaire is one component of third-party risk management and does not replace regime-specific obligations. For example, it is not a substitute for a data protection impact assessment, which is required only in certain circumstances rather than universally, nor for maintaining records of processing activities where applicable. It also does not itself establish or document cross-border transfer mechanisms, retention rules, or lawful bases for processing. Organizations generally integrate questionnaire outputs into a broader assessment and evidence set rather than relying on them in isolation. Enforcement penalties and jurisdiction-specific requirements are out of scope for this entry.

Common misconceptions

Completing a SIG Questionnaire demonstrates that a vendor is compliant with GDPR, CCPA, HIPAA, or another regime.
The SIG Questionnaire is a due diligence tool for gathering information about a vendor's controls; it is not a compliance certification. Compliance depends on jurisdiction, the applicable instrument, and actual implementation. A completed questionnaire supports an assessment but does not by itself establish that any legal obligation has been met.
A vendor's answers on the SIG can be taken at face value as evidence of adequate controls.
SIG responses are self-attestations that reflect what the vendor states, not what has been independently verified. Under governance and accountability frameworks, demonstrable evidence such as reports, audit results, or artifacts is generally needed rather than stated intent alone.
The SIG Questionnaire is a security-only exercise and has nothing to do with data governance or privacy.
While it covers information security controls, the questionnaire also touches governance and privacy topics. These areas overlap but remain distinct: security addresses confidentiality, integrity, and availability, while governance covers ownership, stewardship, and policy, and privacy addresses the handling of personal data. Treating the questionnaire as security-only overlooks its governance-related content.

Best practices

Scope the questionnaire to the criticality of the vendor relationship, using a broader set for high-risk engagements and a more focused set where the risk is limited, rather than applying one depth to every supplier.
Treat vendor responses as self-attestations and request supporting evidence, such as independent audit reports or control artifacts, before relying on them for accountability purposes.
Confirm framework mappings against the specific SIG version in use rather than assuming a fixed alignment, since referenced standards and coverage can differ between releases.
Use the questionnaire to inform, not replace, your own risk assessment and any required privacy analysis; do not assume it satisfies obligations that depend on jurisdiction and implementation.
Clearly distinguish security control questions from governance and privacy questions when reviewing responses, so that overlapping topics are assessed against the correct obligations and owners.
Document the assessment outcome and the evidence reviewed so that reliance on the questionnaire is demonstrable, and note explicitly where areas such as cross-border transfer mechanics, retention rules, or enforcement exposure fall outside the scope of the questionnaire and require separate review.