Skip to main content
Category: Third-Party Risk

Standardized Information Gathering (SIG)

Also known as: SIG, SIG Questionnaire, Standardized Information Gathering Questionnaire, Standard Information Gathering Questionnaire, Shared Assessments SIG
Simply put

The Standardized Information Gathering (SIG) questionnaire is a standardized set of questions used to collect information from a third party, such as a vendor, in order to assess the risks of working with them. Organizations commonly use it to gather assessment documentation and support security risk reviews of their suppliers. Because the questions are standardized, it aims to make vendor information easier to request and compare.

Formal definition

SIG is a standardized questionnaire developed and maintained by Shared Assessments and used within third-party and vendor risk management programs to obtain assessment documentation and perform security risk assessments of third parties. According to the evidence, the questionnaire is designed to map to requirements of numerous cyber regulations and frameworks and is offered in more than one scope variant (for example, SIG Core and SIG Lite). As a data-collection instrument, it supports the assessment stage of third-party due diligence; it does not itself constitute a control, an audit, or a compliance determination, and interpreting responses and treating identified risks remain management activities within the assessing organization. This entry does not cover specific question content, version details, licensing terms, or implementation tooling, which vary and are not established by the evidence provided.

Why it matters

Third-party relationships expand an organization's attack surface and introduce risks that fall outside its direct control. A structured means of gathering information from vendors is therefore central to third-party risk management, and the SIG questionnaire is one widely referenced instrument for that purpose. Because its questions are standardized, it can help organizations request comparable information across multiple suppliers rather than relying on ad hoc, inconsistent inquiries, which in turn can make security risk reviews more repeatable.

Standardization also has value on the supplier side of the relationship. A vendor that receives similar questionnaires from many customers may be able to respond more efficiently to a common instrument, and assessing organizations may be able to interpret responses more consistently. According to the evidence, the SIG questionnaire is designed to map to the requirements of numerous cyber regulations and frameworks, which can help organizations relate the information collected to obligations they are already tracking.

It is important to keep the questionnaire's role in perspective. SIG is a data-collection tool that supports the assessment stage of due diligence; it is not itself a control, an audit, or a compliance determination. Collecting completed responses does not by itself establish that a vendor is secure or compliant. The work of evaluating responses, corroborating them where warranted, and deciding how to treat any identified risks remains a management responsibility within the assessing organization.

Who it's relevant to

Third-party and vendor risk managers
Professionals responsible for assessing suppliers commonly use the SIG questionnaire to collect assessment documentation and support security risk reviews in a consistent, comparable way across a vendor portfolio.
Compliance and security assessment teams
Teams evaluating vendors against regulatory and framework expectations may find the questionnaire useful because it is designed to map to the requirements of many cyber regulations and frameworks, though relating responses to specific obligations remains their responsibility.
Vendors and suppliers responding to assessments
Organizations on the receiving end of due diligence requests may complete the SIG questionnaire to provide required assessment documentation to their customers, potentially responding to a standardized instrument rather than to varied, one-off inquiries.
Internal auditors and assurance functions
Assurance professionals reviewing the effectiveness of a third-party risk management program may examine how questionnaire responses are gathered and used, while keeping their independent assurance role distinct from the management activities of collecting and acting on the information.

Inside SIG

Standardized Questionnaire Structure
SIG is a library of questions organized to assess a third party's controls across multiple risk domains, providing a consistent format that requesting organizations and vendors can reuse across engagements rather than building bespoke questionnaires each time.
Risk Domain Coverage
The question set is typically arranged by control areas such as information security, IT and cybersecurity, privacy and data protection, business resiliency, and related operational risk topics, allowing an assessor to gather evidence about how a vendor manages risk across these areas.
Scalable Question Sets
SIG commonly offers different scopes so that an assessment can be tailored to the criticality of the relationship, ranging from a broader, more detailed set to a more focused subset for lower-risk or preliminary assessments. The precise naming and composition of these tiers may vary by release.
Content Mapping to External References
SIG content is frequently mapped to widely used control frameworks and regulatory reference points so that a single response can support multiple assessment needs. Specific mappings and coverage vary by version and should be verified against the issuing organization's current materials.
Third-Party Risk Management Tool
SIG functions primarily as an evidence-gathering and due-diligence instrument within a third-party or supplier risk management program, supporting the assessment and treatment of risk arising from external relationships rather than governing internal decision rights.

Common questions

Answers to the questions practitioners most commonly ask about SIG.

Is completing a SIG questionnaire the same as being certified or audited?
No. The SIG is a standardized questionnaire used to gather information about a third party's controls across domains such as information security, privacy, and resilience. It is a self-assessment or information-gathering instrument rather than an independent audit or certification. Responses are typically provided by the assessed organization itself, so they represent management's assertions rather than an assurance opinion issued by an independent party. Where independent validation is needed, organizations commonly supplement the SIG with attestation reports, certifications, or on-site assessments, which fall outside the SIG's own scope.
Does a strong set of SIG responses guarantee that a third party is secure or compliant?
No. A SIG captures information about the presence and design of controls as described by the responding party at a point in time. It does not, on its own, test whether those controls operate effectively, nor does it guarantee any security or compliance outcome. It also does not replace the requesting organization's own risk assessment and decision-making. Responses may need corroboration through supporting evidence or independent assurance, and the questionnaire's coverage may not address every obligation relevant to a particular jurisdiction, sector, or contract.
How do the different SIG formats or tiers typically differ, and how do teams choose between them?
The SIG is commonly offered in more than one scope, with a shorter format used for a higher-level or lower-risk view and a fuller format used for more detailed, in-depth assessment. Teams typically select the scope based on the inherent risk of the engagement, the sensitivity of data involved, and the criticality of the service. The specific structure, content, and available tiers vary by release, so organizations should confirm the current options against the version they are using rather than assume a fixed layout.
How is a SIG assessment usually integrated into a third-party risk management program?
In many programs the SIG is used during due diligence and periodic reassessment stages of the third-party lifecycle. It is commonly triggered after an initial inherent risk tiering step so that the depth of the questionnaire is matched to the risk of the relationship. Results typically feed into risk analysis, contract terms, and remediation tracking. The SIG supports these processes but does not by itself define risk appetite, tolerances, or the acceptance decision, which remain governance and management responsibilities within the requesting organization.
What evidence or follow-up commonly accompanies SIG responses?
Because SIG responses are self-reported, requesting organizations frequently ask for supporting documentation to corroborate key answers. This may include independent attestation or audit reports, certifications, policy or standard excerpts, or the results of targeted validation. The extent of corroboration sought is generally proportionate to the assessed risk. What specific evidence is appropriate depends on the engagement, applicable obligations, and the requester's own assurance requirements, and is not dictated by the questionnaire itself.
How frequently is a SIG typically refreshed for an existing third party?
Reassessment cadence is usually set by the requesting organization's third-party risk policy rather than by the questionnaire. Common practice is to reassess higher-risk or higher-criticality relationships more often than lower-risk ones, and to trigger an out-of-cycle reassessment following significant changes such as a change in services, a material incident, or changes in the control environment. Appropriate frequency varies by organization, sector, and jurisdiction, so it should be defined within the program's own governance.

Common misconceptions

Completing a SIG questionnaire demonstrates compliance with a specific law or regulation.
SIG is an information-gathering questionnaire used to assess a third party's controls; it is not a compliance certification. Responses inform a risk assessment but do not by themselves establish adherence to any particular statute, regulation, or standard, and any mapping to external references should be independently verified.
A SIG response is an independent assurance report over the vendor's controls.
A SIG is typically a self-reported management assertion from the responding organization. It is not an audit or an independent assurance engagement, and it does not carry the objectivity of an examination performed by an independent assurance provider. Practitioners may seek separate independent evidence where higher assurance is warranted.
One SIG questionnaire fits every vendor relationship.
SIG is designed to be scoped to the risk and criticality of the specific relationship. Applying a single, uniform scope to all vendors can either over-burden low-risk suppliers or under-assess high-risk ones; the level of inquiry is commonly calibrated to the assessed risk.

Best practices

Scope the SIG questionnaire to the criticality and inherent risk of each third-party relationship rather than applying a single scope uniformly across all vendors.
Corroborate self-reported SIG responses with independent evidence, such as external assurance reports or on-site validation, particularly for high-risk or critical relationships.
Verify any framework or regulatory mappings against the issuing organization's current materials before relying on them, as coverage and mappings may vary by version.
Integrate SIG results into the broader third-party risk management process so that identified gaps drive documented risk treatment, remediation tracking, and re-assessment.
Use the appropriate SIG scope for the stage of due diligence, applying a more focused subset for preliminary or lower-risk reviews and a broader set for detailed assessments.
Retain completed questionnaires and supporting evidence to support ongoing monitoring and to demonstrate that due diligence was performed proportionate to the assessed risk.
Application Security Isn’t Optional Anymore.