The SIG questionnaire, explained
If a bank or insurer is reviewing you, a SIG is likely coming. Complete it once a year and it becomes a document in your trust centre rather than a project.
The SIG, the Standardized Information Gathering questionnaire, is a third-party risk questionnaire published and updated annually by Shared Assessments. Financial institutions, insurers and large enterprises use it to assess vendors. It comes in two main sizes: SIG Lite, a shorter version for lower-risk relationships, and SIG Core, a much longer version for vendors handling sensitive data or critical services. Buyers can also scope a custom subset.
What is the difference between SIG Lite and SIG Core?
| SIG Lite | SIG Core | |
|---|---|---|
| Used for | Initial screening and lower-risk vendors | Vendors with sensitive data or critical services |
| Depth | High-level questions across the risk domains | Detailed questions across the same domains |
| Effort with an answer library | Hours to a day | Several days |
| Reuse | Share under NDA from your trust centre | Same, and update when controls change |
Shared Assessments licenses the SIG, and buyers typically hold the licence and send you the questionnaire. Check the version year on what you receive, because content changes year to year.
How do we answer a SIG efficiently?
- Map it to your report. Many SIG domains line up with SOC 2 common criteria or ISO 27001 Annex A. Reference the report where the buyer allows.
- Answer from your library. Reuse approved wording from your answer library.
- Be precise on "N/A". Explain why a control does not apply rather than leaving it blank.
- Keep the completed version. Store it dated in your trust centre's gated library and offer it to the next buyer who asks.
What do Canadian financial buyers add?
Federally regulated financial institutions assess third parties under OSFI's Guideline B-10 on third-party risk management, so expect questions on subcontractors, data location, business continuity and exit. See the fintech page for what to publish for those reviews.
Not sure whether you were sent a SIG or a CAIQ? SIG Lite vs CAIQ compares the two side by side.
Common questions
Do we need to buy the SIG to answer one?
Usually not. The buyer holds the licence and sends you the questionnaire. If you want to complete one proactively to share, check Shared Assessments' current licensing terms for vendors.
Does a SOC 2 report replace a SIG?
Sometimes, for part of it. Many buyers accept report references for overlapping questions but still require the questionnaire itself. Ask which sections they will accept the report for.
Get a SIG completed from your evidence
Quoted per questionnaire or as part of a managed trust centre.
Get matched