All posts
Vendor Risk Management8 min readAug 16, 2026

SIG questionnaire

Ashish / CEO/Co-Founder
SIG questionnaire

The SIG questionnaire, short for Standardized Information Gathering, is a standardized third-party risk questionnaire created and continually updated by Shared Assessments. Buyers use it to assess vendors and other third parties across areas such as cybersecurity, IT, privacy, data governance, and business resilience; vendors may complete it in response to customer due diligence, RFPs, or as part of their own assurance process. Shared Assessments describes SIG as a way to standardize vendor-risk assessments—not as proof that a vendor is automatically secure or acceptable.

The practical value of SIG depends on how it is used, a completed questionnaire should help a buyer make a defensible decision: approve, request remediation, accept risk with conditions, reject or defer the engagement, or schedule reassessment.

What is the SIG questionnaire?

SIG is a structured assessment tool for third-party and vendor risk management. It gives buyers a consistent way to ask vendors about controls, practices, and risk areas that matter to the service being purchased.

Organizations commonly use SIG to evaluate prospective service providers, reassess existing vendors, support RFP or security assurance workflows, and perform internal self-assessments. Vendors may also complete SIG proactively or when responding to customer due diligence requests, according to Shared Assessments’ SIG overview.

SIG is not a replacement for judgment. Its answers should be reviewed against the vendor’s role, data access, operational importance, contractual obligations, and available evidence—or, rather, against those factors together, not separately.

When should you use SIG in vendor risk management?

Use SIG when the vendor relationship is important enough to justify a structured, repeatable control assessment. Common triggers:

  • a new vendor that will support a critical business process
  • access to sensitive customer, employee, financial, regulated, or proprietary data
  • technology services that connect to internal systems or production environments
  • a vendor that supports resilience, availability, or incident response obligations
  • periodic reassessment of an existing higher-risk provider
  • RFPs where security, privacy, or operational controls materially affect selection

SIG may be excessive where the vendor has little or no access to sensitive data, provides a commodity service, or has already supplied assurance artifacts that answer the relevant risk questions. In those cases, a lighter questionnaire, a targeted follow-up, or another assessment format may be more proportionate.

NIST’s cyber supply chain risk guidance supports this risk-based approach: assessment depth and frequency should reflect supplier criticality, with more extensive methods for critical suppliers and tracked improvement actions where gaps are found. NISTIR 8276 is not a SIG scoring standard, but it supports using supplier criticality to determine how much review is appropriate.

SIG Core vs SIG Lite vs scoped SIG: how to choose

Shared Assessments provides standard SIG Lite and SIG Core scoping templates. Its SIG FAQ describes Lite as a low-risk foundation and Core as a broader question set for higher-risk service providers. It also supports custom-scoped templates that select relevant risk domains or control families and may mix Lite, Core, and Detail scope levels.

Don't rely on unverified question counts, domain counts, or copied templates from third-party sites. Confirm the current version, delivery method, licensing terms, and scope options through Shared Assessments before issuing or relying on a specific SIG package.

Use the table below as a practical starting point; then tailor it to your risk appetite, service scope, and contractual requirements.

Vendor factorLikely SIG approachWhy
Critical service providerSIG Core or a scoped Core-based assessmentA failure could affect operations, customers, or resilience obligations.
Handles sensitive customer, employee, financial, or regulated dataSIG Core or a scoped SIG with targeted evidenceData exposure usually requires deeper review of security, privacy, and governance controls.
Low-risk SaaS with limited accessSIG Lite or a shorter assessmentThe review should stay proportionate to the actual engagement.
Highly regulated processing or outsourced control dependencySIG Core plus targeted evidence requestsQuestionnaire answers may need support from policies, reports, or other assurance evidence.
Vendor already provides strong, relevant assurance artifactsSIG Lite or scoped follow-upAvoid duplicating review where existing evidence already addresses the risk.
Narrow service with limited control relevanceCustom-scoped SIGFocus the vendor on the domains and control families that apply to the service.
Cloud, managed service, or technology provider integrated with production systemsSIG Core or scoped SIG focused on the integration riskSystem access, availability, incident response, and change management may matter more than generic corporate controls.

The point is not to send the longest questionnaire possible. It is to ask enough to support the decision you need to make.

What does SIG cover?

SIG spans multiple risk domains, including cybersecurity, IT, privacy, data governance, and business resilience, according to Shared Assessments. Its Content Library includes mappings from many questions to applicable controls, frameworks, and regulations, including NIST and ISO references, as described in the SIG FAQ.

For buyers, the mapping matters because it can help organize responses against recognized control expectations and reduce duplicate assessment work. It does not make a vendor compliant by itself, and it does not remove the need to verify whether the answer and evidence apply to the service in scope.

Access also matters. Current SIG content follows an annual release cycle, and Shared Assessments is moving toward SIG Evolution, a web-based delivery method that retains the SIG methodology and content; the Excel workbook remains available for some workflows. Access requires agreement to Shared Assessments terms and is available through membership, subscription, or licensing. Do not use unofficial downloads or reproduced question sets as a substitute for current licensed materials.

How to scope and issue a SIG without over-questioning vendors

Before sending SIG, define the decision the assessment must support. A practical scoping process is:

  1. Tier the vendor by criticality, data access, system connectivity, and operational impact.
  2. Identify the service in scope, including the specific product, environment, data flows, and subcontractor dependencies where relevant.
  3. Select SIG Lite, SIG Core, or a custom scope based on the vendor tier and review objective.
  4. Remove or deprioritize irrelevant areas where the chosen SIG format and your process allow it.
  5. Define evidence expectations before sending the questionnaire, especially for high-risk control areas.
  6. Set response expectations, including due date, owner, acceptable evidence age, and how follow-up questions will be handled.

Avoid collecting questions that are not relevant to the service and review objective. Irrelevant scope creates supplier burden and increases the amount your team must review without necessarily improving the risk decision.

A simple buyer-side workflow looks like this:

Vendor intake → risk tiering → SIG scope selection → evidence request → response review → findings → remediation or exception → risk acceptance, rejection, or deferral → reassessment cadence

That flow keeps SIG connected to governance. The questionnaire is the input; the decision record is the output.

How to review SIG responses and evidence

A completed SIG is not the end of assessment. Reviewers should evaluate whether the responses are complete, consistent, relevant to the scoped service, and supported by appropriate evidence.

For higher-risk suppliers, NIST notes that organizations may combine questionnaires or attestations with formal certifications, third-party assessments, and site visits according to risk. NISTIR 8276 supports using more extensive assessment methods for critical suppliers, but it does not prescribe a universal evidence checklist.

Examples of evidence a reviewer may request, where relevant, include:

  • security and privacy policies
  • access control procedures or configuration evidence
  • SOC 2 reports or ISO 27001 certificates, where applicable
  • incident response plans or tabletop exercise evidence
  • encryption and key management documentation
  • business continuity or disaster recovery test evidence
  • data processing, retention, or privacy documentation
  • vulnerability management or penetration test summaries

The key question is not “Did the vendor attach a document?” It is basically whether the evidence supports the specific answer for the service you are buying.

Flag responses for follow-up when they are:

  • incomplete or left unanswered
  • vague “yes” answers without support
  • inconsistent with other responses or attached evidence
  • marked “not applicable” without a clear reason
  • supported by outdated evidence
  • based on corporate controls that do not apply to the product or environment in scope
  • contradicted by audit reports, incidents, exceptions, or known service limitations

Do not treat SIG as a universal pass/fail instrument. Your organization should define how findings are triaged, who can accept risk, and what evidence is required before approval.

What happens after SIG review: remediation, exceptions, and reassessment

After review, SIG findings should move into a documented governance path. Common outcomes include:

  • Accept: evidence is sufficient and residual risk is within appetite.
  • Remediate: the vendor must address a gap before approval or within an agreed plan.
  • Accept with exception: the business proceeds with a documented risk owner, rationale, and compensating controls.
  • Reject or defer: the risk is too high for the intended use or the vendor cannot provide sufficient assurance.
  • Reassess: the vendor remains approved, but review frequency reflects tier, criticality, and material changes.

A remediation workflow should be specific enough to track closure:

  1. Identify the finding and affected control area.
  2. Assign severity or priority using your internal criteria.
  3. Define the required vendor action or compensating control.
  4. Assign an owner and due date.
  5. Track evidence of closure.
  6. Document residual risk and approval decision.
  7. Set reassessment based on vendor tier and risk changes.

NIST recommends tracking improvement actions and establishing remediation-acceptance criteria as part of supplier risk management. It also supports setting assessment frequency and depth according to supplier criticality, rather than using one cadence for every vendor.

Conclusion: Use SIG as a decision tool, not just a questionnaire

SIG helps standardize vendor-risk assessment, but its value comes from proportionate scoping, evidence review, and documented follow-through. Choose Lite, Core, or a custom scope based on the vendor’s risk—not convenience—and turn responses into remediation, exception, acceptance, rejection, or reassessment decisions, as needed.

Teams may also choose to connect questionnaire responses, evidence, findings, controls, and remediation inside their operational compliance workflow. Ciphrix’s perspective is that security assurance works best as a living operating system, not as a recurring document chase, in practice.

Get started

Ready to see Ciphrix in action?

Built by AWS Security Leaders | AWS Partner | Certified companies across 3 continents