TrustCenter

The SIG questionnaire, explained

If a bank or insurer is reviewing you, a SIG is likely coming. Complete it once a year and it becomes a document in your trust centre rather than a project.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

The SIG, the Standardized Information Gathering questionnaire, is a third-party risk questionnaire published and updated annually by Shared Assessments. Financial institutions, insurers and large enterprises use it to assess vendors. It comes in two main sizes: SIG Lite, a shorter version for lower-risk relationships, and SIG Core, a much longer version for vendors handling sensitive data or critical services. Buyers can also scope a custom subset.

What is the difference between SIG Lite and SIG Core?

SIG Lite and SIG Core compared
SIG LiteSIG Core
Used forInitial screening and lower-risk vendorsVendors with sensitive data or critical services
DepthHigh-level questions across the risk domainsDetailed questions across the same domains
Effort with an answer libraryHours to a daySeveral days
ReuseShare under NDA from your trust centreSame, and update when controls change

Shared Assessments licenses the SIG, and buyers typically hold the licence and send you the questionnaire. Check the version year on what you receive, because content changes year to year.

How do we answer a SIG efficiently?

  1. Map it to your report. Many SIG domains line up with SOC 2 common criteria or ISO 27001 Annex A. Reference the report where the buyer allows.
  2. Answer from your library. Reuse approved wording from your answer library.
  3. Be precise on "N/A". Explain why a control does not apply rather than leaving it blank.
  4. Keep the completed version. Store it dated in your trust centre's gated library and offer it to the next buyer who asks.

What do Canadian financial buyers add?

Federally regulated financial institutions assess third parties under OSFI's Guideline B-10 on third-party risk management, so expect questions on subcontractors, data location, business continuity and exit. See the fintech page for what to publish for those reviews.

Not sure whether you were sent a SIG or a CAIQ? SIG Lite vs CAIQ compares the two side by side.

Common questions

Do we need to buy the SIG to answer one?

Usually not. The buyer holds the licence and sends you the questionnaire. If you want to complete one proactively to share, check Shared Assessments' current licensing terms for vendors.

Does a SOC 2 report replace a SIG?

Sometimes, for part of it. Many buyers accept report references for overlapping questions but still require the questionnaire itself. Ask which sections they will accept the report for.

Get a SIG completed from your evidence

Quoted per questionnaire or as part of a managed trust centre.

Get matched