---
title: "SIG Questionnaire Guide: Core, Lite and How to Respond"
url: "https://www.arphie.ai/blog/sig-questionnaire"
collection: blog
lastUpdated: 2026-07-24T23:21:08.221Z
---

# SIG Questionnaire Guide: Core, Lite and How to Respond

The Standardized Information Gathering (SIG) Questionnaire is a configurable third-party risk assessment maintained by Shared Assessments. Buyers use it to evaluate how a vendor manages cybersecurity, privacy, resilience, artificial intelligence, supply-chain, and other operational risks. Vendors can complete it alongside a request for proposal (RFP), during security review and procurement, or at onboarding, renewal, and periodic reassessment.



There is no timeless question count or one-size-fits-all SIG file. Shared Assessments updates the workbook annually, and an assessor can use a preconfigured scope or select questions for a particular relationship. Arphie helps response teams confirm and preserve that structure. Arphie drafts from current company knowledge and shows the source and confidence behind each answer. Teams can coordinate the right subject-matter experts. Teams can export the completed response back to the buyer's format.



## SIG questionnaire at a glance



Arphie turns the SIG from a separate spreadsheet exercise into part of the same governed response workflow used for RFPs, due diligence questionnaires (DDQs), and custom security reviews. Teams can [import the original Excel workbook](https://www.arphie.ai/features). Arphie detects its questions and sections. Arphie drafts from connected knowledge and lets reviewers inspect sources and confidence. Teams can export the finished response to the original file without a manual rebuild.



| Item | Answer |
| --- | --- |
| Full name | Standardized Information Gathering Questionnaire |
| Maintained by | Shared Assessments |
| Main purpose | Standardize the collection of third-party control and risk information |
| Current coverage | 21 risk domains |
| Common scopes | SIG Lite, SIG Core, and a custom scope drawn from SIG Detail |
| Typical format | A licensed Excel workbook, SIG Evolution (SIG EV), or questions transferred into another assessment platform or buyer portal |
| Typical respondents | Security, governance, risk and compliance (GRC), privacy, IT, engineering, legal, human resources, and business continuity owners |



Shared Assessments describes the [current SIG product](https://sharedassessments.org/sig-excel/) as a way to build, customize, analyze, and store vendor assessments. The product includes SIG Manager, a user guide, an enhancement document, and a version-delta workbook that traces question changes back to 2008.



In March 2026, Shared Assessments [launched SIG Evolution (SIG EV)](https://www.24-7pressrelease.com/press-release/532793/shared-assessments-announces-launch-of-sig-evolution-sig-ev-at-the-2026-third-party-risk-summit). SIG EV is a secure browser-based platform for [creating, distributing, reviewing, and scoring assessments](https://sharedassessments.org/sig-faq/). Vendors can still complete SIG questionnaires offline in Excel. Organizations can import those responses into SIG EV.



A completed SIG is not a certification. It is a structured set of vendor assertions and, where requested, supporting evidence. The buyer still decides whether the answers meet its risk appetite and whether any gaps require clarification, remediation, a compensating control, or formal acceptance.



## Prepare before a SIG request arrives



Long questionnaires become much easier when the work starts before an opportunity reaches the security-review stage.



### Build an authoritative source inventory



Identify the systems and documents that can support control claims. Common sources include information-security and privacy policies, standards and procedures, audit reports, and penetration-test summaries. Architecture diagrams, data-flow diagrams, continuity evidence, and disaster-recovery evidence can support other claims. Subprocessor records, insurance certificates, and control-testing results may also be relevant.



Each source needs an owner, approved audience, review date, and access rule. A current internal procedure and a customer-shareable policy summary may support the same topic but serve different disclosure needs.



[Arphie](https://www.arphie.ai/integrations) connects directly to the systems where these documents already live. The inventory becomes a living source rather than a static list that someone has to keep re-checking.



### Maintain reusable answers with context



A response record should include more than polished prose. Store:



- The approved answer.



- The product, entity, region, and deployment scope it covers.



- The source documents or records behind it.



- The content owner and approver.



- The last review date and the event that should trigger another review.



- Disclosure restrictions or required redactions.



This context prevents a correct answer for one product or geography from being reused in the wrong place.



### Map domain owners and reviewers



Security may lead the project, but it should not improvise answers for every domain. Map likely SIG sections to accountable owners. Accountable owners may sit across privacy, legal, infrastructure, application security, HR, procurement, compliance, finance, and resilience. Assign backup reviewers for high-volume periods. Define who can approve an exception or future commitment.



### Separate facts from buyer-specific commitments



Statements about current controls can often be reused. Contractual commitments, custom service levels, remediation dates, and responses that change the product's obligations require fresh review. Keeping these two categories separate reduces the chance that a one-off concession becomes the apparent company standard.



### Connect the response workflow to current knowledge



Copying answers into a static library creates another system that can go stale. Our [integrations](https://www.arphie.ai/integrations) connect response work to sources such as SharePoint, Confluence, Google Drive, Box, Dropbox, websites, and other repositories. The response team can draft from current approved knowledge while maintaining a governed set of reusable answers for questions that should remain verbatim.



## Who uses the SIG questionnaire, and when?



The SIG creates a common format between two sides of a third-party relationship:



- The **buyer, assessor, or outsourcer** sends the questionnaire to understand the risk introduced by a product or service.



- The **vendor or service provider** responds with information about its controls, practices, and evidence.



Many enterprises play both roles. Shared Assessments' [guide for outsourcers and vendors](https://sharedassessments.org/paper/outsourcers-vendors-sig/) notes that an organization may assess its own providers while answering SIG requests from its customers.



A buyer may request a SIG:



- Before signing a contract or approving a new service.



- During onboarding for a vendor that handles sensitive data or supports a critical process.



- At renewal or on a scheduled reassessment cycle.



- After a material change to the product, hosting model, data flow, subprocessor chain, or control environment.



- When regulation or internal policy requires documented third-party due diligence.



The requested depth should follow the relationship's inherent risk. A low-risk tool with no sensitive-data access does not need the same review as a critical cloud service that stores regulated information. In practice, response teams still receive over-scoped files. First confirm the service, entity, deployment, geography, and data flow in scope. Clear scoping can remove irrelevant questions before subject-matter experts start writing.



## SIG Lite vs. SIG Core vs. SIG Detail



SIG Manager provides preconfigured Lite and Core questionnaires and can generate a custom assessment by risk domain, control family, regulation, or another selected scope. SIG Detail is the full question library from which deeper custom assessments can be built.



| Scope | Depth | Common fit | Official 2025 count, for reference |
| --- | --- | --- | --- |
| SIG Lite | Broad, higher-level view of internal controls | Lower-risk relationships, preliminary screening, or basic due diligence | 128 |
| SIG Core | Deeper examination of how controls operate | Critical vendors or services that store or manage sensitive or regulated information | 627 |
| SIG Detail | Full content library for custom scoping | Assessments built around selected domains, regulations, control families, or specialized risk | 1,936 |



Those counts come from Shared Assessments' [official 2025 release note](https://sharedassessments.org/blog/2025-sig/). They are not permanent specifications. Annual releases add, retire, and reorganize questions, and buyers can customize the workbook. When planning a response, use the year and question set in the actual request rather than a count copied from an older guide.



Depth matters as much as length. A lighter assessment tends to ask whether foundational controls exist. A deeper assessment can examine control design, ownership, and scope. A deeper assessment can also ask about testing frequency, supporting evidence, and exception handling.



## SIG, CAIQ, and custom questionnaires in an Arphie RFP workflow



SIG, the Consensus Assessments Initiative Questionnaire (CAIQ), and buyer-specific security forms test different things. All three may still arrive inside the same RFP, procurement, or due-diligence process. Arphie keeps those formats in one response workflow instead of forcing sales engineering and security teams to maintain separate copy-and-paste processes for each questionnaire.



| Questionnaire | What the buyer is assessing | How it fits the RFP process | How Arphie helps |
| --- | --- | --- | --- |
| SIG | Broad third-party cybersecurity, privacy, IT, resilience, governance, AI, and operational risk | Cross-domain due diligence before or alongside a commercial decision | Imports the structured file, retrieves approved answers and evidence, and lets the team assign exceptions to the right reviewer |
| CAIQ | Cloud security controls derived from the Cloud Controls Matrix | Cloud-assurance review for a service provider | Reuses the same current company knowledge while preserving CAIQ-specific scope and wording |
| Custom questionnaire | The buyer's product, architecture, contractual, policy, and risk requirements | Account-specific questions in an RFP, portal, or security review | Drafts from connected sources and lets the team assign novel, sensitive, or low-confidence answers to subject-matter experts |



The Cloud Security Alliance describes [CAIQ](https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4-1) as a set of questions based on its Cloud Controls Matrix. CAIQ is therefore more cloud-focused. SIG spans additional third-party risks such as HR security, operational resilience, privacy, nth-party management, and enterprise risk. A custom questionnaire can examine buyer-specific architecture and contract terms. A custom questionnaire may also cover recovery objectives, subprocessors, or integrations.



For an RFP response team, the operational job stays consistent across all three. Preserve the buyer's exact question and scope. Retrieve a vetted answer when one fits. Draft from current evidence when it does not. Escalate commitments or uncertainty before submission. [Arphie's AI agents](https://www.arphie.ai/blog/ai-for-rfps) handle that shared response layer while keeping the differences between SIG, CAIQ, and custom forms intact.



## How to complete a SIG questionnaire in eight steps



### 1. Confirm the version, scope, deadline, and submission method



Record the workbook year and whether the request is Lite, Core, Detail, or custom. Identify the product and legal entity in scope. Confirm required attachments, buyer contacts, and clarification rules. Then confirm the deadline and whether the final response belongs in Excel, a portal, or both.



Ask early about irrelevant sections. A clear scoping decision is faster and safer than filling every non-applicable row with generic language.



### 2. Preserve the original workbook



Work from a controlled copy. Keep question IDs, formulas, and macros intact. Preserve hidden sheets, validations, answer options, and requested evidence fields too. Do not reformat the file simply to make it easier to read internally; the buyer may depend on its structure for automated analysis.



If the project moves into response software, verify that the tool can export back to the original format. Arphie's [questionnaire features](https://www.arphie.ai/features) support Excel and Word import. Arphie's questionnaire features also detect questions and sections with AI. Teams can export the response into the original file.



### 3. Triage and assign by domain



Group questions by domain and route them to the people accountable for the underlying controls. Separate drafting from approval when the answer creates security, privacy, legal, or service obligations. Track unanswered questions and low-confidence drafts in one project view. Keep requested evidence and blockers there too instead of spreading them across email threads.



### 4. Reuse approved answers with context



Start with a verbatim approved response when the question, product scope, entity, and control state truly match. When the wording differs, retrieve the relevant approved facts and adapt the answer to the buyer's question.



[Arphie](https://www.arphie.ai/blog/ai-for-rfps) handles this distinction automatically: when a direct Q&A match exists, it returns the vetted answer verbatim. When no direct match exists, Arphie searches connected company knowledge to draft from relevant sources.



Keyword matching alone is not enough. "How do you encrypt customer data?" and "Describe cryptographic controls for regulated information" may require related evidence. The correct answer can change by data state and product. The correct answer can also vary by environment and key-management scope.



### 5. Attach or cite the right evidence



Support material assertions with current, shareable evidence when the buyer requests it. Check the audit period, document version, system scope, and confidentiality level. A SOC 2 report may validate a control environment. A data-flow diagram or policy can answer a narrower question. A recovery-test result or subprocessor list may support a different request.



Do not attach the entire evidence room by default. Give the buyer what is relevant and authorized, and use a secure exchange process for restricted material.



### 6. Escalate gaps and exceptions accurately



Distinguish among:



- **Not applicable:** The control does not apply to the scoped service.



- **Alternative or compensating control:** The objective is met another way.



- **Planned change:** The control is not present today but has an approved roadmap.



- **Unresolved gap:** The current state does not meet the request and needs a risk decision.



Never write a future state as if it already exists. State the present condition and add approved context. Route any commitment through the person authorized to make it.



### 7. Run cross-functional review and sign-off



Organize the final review around risk rather than only around sections. Security verifies control claims and evidence. Privacy and legal check data-use and contractual statements. Product and engineering verify architecture and feature claims. The response lead checks consistency, completeness, terminology, and alignment across related answers.



The final approver should see exceptions and low-confidence answers together. Buyer-specific commitments and evidence restrictions should be visible in the same review rather than discovered row by row.



[Arphie's response workspace](https://www.arphie.ai/security-teams) lets teams assign reviewers and collaborate through comments. Reviewers can inspect sources and confidence before approval and sign-off. The team does not have to pass a large workbook through email.



### 8. Export, quality-check, and learn



Reopen the exported workbook and test it before submission. Confirm that required fields are complete and answer options stayed valid. Test the formulas, macros, and evidence links. Check that no internal comments or restricted attachments leaked into the file.



After submission, capture approved new language and corrections. Add buyer clarifications and reusable evidence. Record where the team waited on an owner or discovered stale content. Those lessons should improve the next response, not disappear into an archived project.



## What does the SIG questionnaire cover?



The current SIG measures risk across [21 domains](https://sharedassessments.org/sig-excel/):



- Access Control



- Application Management



- Artificial Intelligence



- Asset and Information Management



- Cloud Services



- Compliance Management



- Cybersecurity Incident Management



- Endpoint Security



- Enterprise Risk Management



- Environmental, Social, and Governance



- Human Resources Security



- Information Assurance



- IT Operations Management



- Network Security



- Nth Party Management



- Operational Resilience



- Physical and Environmental Security



- Privacy Management



- Server Security



- Supply Chain Risk Management



- Threat Management



Shared Assessments groups SIG controls into four broad areas: governance and risk management, information protection, IT operations and business resilience, and security incident and threat management. The range is intentionally wider than a technical security checklist. A response may require input from privacy, legal, HR, and procurement. Resilience and enterprise-risk owners may also need to join the security team. In Arphie, response leads can assign those sections to the appropriate reviewers. Response leads can keep sources, comments, and approvals in one response project.



SIG questions also map to external standards, regulations, and guidance. Shared Assessments' official user-reference documentation says the [2025 SIG contains direct mappings to 31 key reference documents](https://sharedassessments.org/paper/user-references-sig/), plus additional crosswalks. The [current product page](https://sharedassessments.org/sig-excel/) lists ISO/IEC 27001 and 27002, NIST Cybersecurity Framework 2.0, and NIST SP 800-53. The current product page also names the EU General Data Protection Regulation and the Digital Operational Resilience Act. Other examples include PCI DSS, the Cloud Controls Matrix, and the Cybersecurity Maturity Model Certification.



Shared Assessments' [2026 update](https://sharedassessments.org/blog/2026-sig-workbook-updates/) included four mapping and reference changes:



- Added an ISO/IEC 42001 reference.



- Made the NIST SP 800-171 mapping more detailed.



- Aligned the SIG with the Business Resilience Council's Operational Resilience Framework.



- Updated prior ISO 27001 mappings to reflect ISO 27001:2022 and its restructured Annex A controls.



These mappings can reduce duplicate evidence work, but they do not mean that submitting a SIG makes a vendor compliant with every referenced standard. Each framework has its own scope, requirements, and assurance process.



## How to scale SIG responses without losing control



Automation should remove avoidable administrative work and direct expert attention to the controls, gaps, and commitments that need judgment. It should not answer every question without people.



A governed workflow can:



- Import the original workbook and detect its questions, sections, and requested answer types.



- Return a verbatim approved answer when an exact, in-scope match exists.



- Draft from current, permissioned sources when there is no direct match.



- Show the source passages and a confidence signal behind each draft.



- Route low-confidence, sensitive, or novel questions to the right owner.



- Manage comments, deadlines, reviewers, and sign-off in one place.



- Preserve an audit trail and export the completed response to the buyer's format.



Generic artificial intelligence can produce fluent answers that are unsupported or wrong for the scoped product. A reliable system should make uncertainty visible and ground drafts in company-approved information. A reliable system should respect source permissions and keep accountable reviewers in the loop.



Our [security questionnaire automation platform](https://www.arphie.ai/security-teams) supports SIG, CAIQ, vendor assessments, and custom questionnaires. Arphie's AI agents draft from connected knowledge and show the supporting sources and confidence level. The workflow coordinates reviewers and keeps an audit trail. Our [security controls](https://www.arphie.ai/security) include an annual SOC 2 Type 2 audit and annual third-party penetration testing. Arphie's security controls also include encryption, single sign-on for enterprise customers, role-based access, and customer-data isolation.



## Turn the next SIG into a repeatable response workflow



A SIG response is easier to defend when every answer has a current source, an accountable owner, clear scope, and the right review. Build that system before the file arrives. Then use automation to retrieve, draft, route, and export the work without hiding uncertainty.



Arphie connects company knowledge to source-backed first drafts and confidence signals. Arphie supports cross-functional review. Arphie also preserves faithful Excel and Word workflows for SIG, CAIQ, and custom questionnaires. [Contact us](https://www.arphie.ai/contact) to see how our AI agents can help your team respond faster without giving up control.