Provebase

Glossary

What is a SIG questionnaire?

The SIG (Standardized Information Gathering) questionnaire is a standardized set of third-party risk questions maintained by Shared Assessments. It gives buyers a consistent, industry-recognized way to assess a vendor’s security, privacy, and resilience controls across many risk domains, instead of every company writing its own questionnaire from scratch.

SIG Core vs SIG Lite

Shared Assessments publishes the SIG in scoped versions. SIG Lite is a shorter, higher-level assessment for lower-risk vendors, while SIG Core is a comprehensive questionnaire covering a broad range of control domains for higher-risk relationships. The content is updated periodically to track evolving regulations and threats.

Why buyers use it

A standardized questionnaire lets a risk team compare vendors on the same basis and reuse their review process. For vendors, it means the same recognizable questions appear again and again — which is exactly why a reusable, evidence-grounded answering process pays off.

FAQ

Related questions

Is the SIG the same as the CAIQ?
No. The SIG is maintained by Shared Assessments and covers broad third-party risk; the CAIQ is maintained by the Cloud Security Alliance and focuses on cloud security controls. A vendor may be asked for either or both.

Bring us your ugliest questionnaire

We’re onboarding a small group of design partners — certified teams on Drata or Vanta handling 10+ questionnaires a quarter. Watch the agent run the entire workflow live, on your real evidence — you approve every answer.

Get early access

or email hello@provebase.ai

Get early access

Tell us a bit about your team and we’ll be in touch.