---
title: "Shared Assessments"
url: "https://www.arphie.ai/glossary/shared-assessments"
collection: glossary
lastUpdated: 2026-08-04T22:13:09.069Z
---

# Shared Assessments

[Shared Assessments](https://sharedassessments.org/) is a member-led organization that develops standardized tools, research, education, and professional resources for third-party risk management (TPRM). Its best-known resource is the Standardized Information Gathering (SIG) questionnaire used in vendor due diligence.



The standard format gives buyers a consistent assessment method. On the respondent side, [we built Arphie](https://www.arphie.ai/features) to turn approved company knowledge into source-backed SIG first drafts, coordinate reviewers, and route answers for final sign-off.



Shared Assessments is not a regulator or government agency. The SIG itself is not a certification, although Shared Assessments offers Certified Third Party Risk Professional (CTPRP) and Certified Third Party Risk Assessor (CTPRA) professional certifications. The buyer still defines its requirements and makes the final risk decision.



## What Does Shared Assessments Provide?



The Shared Assessments program covers questionnaire-based due diligence, control testing, program maturity, and professional education. Each resource serves a different part of the third-party risk lifecycle.



### SIG Questionnaire and SIG EV



The Standardized Information Gathering questionnaire provides a structured set of questions for third-party risk assessments. It covers cybersecurity, privacy, resilience, supply-chain, artificial intelligence, and other operational risk domains.



In 2026, Shared Assessments introduced SIG Evolution (SIG EV), the secure, browser-based delivery of the SIG methodology. SIG EV supports assessment creation, distribution, collaboration, review, and scoring. It is the long-term primary delivery method for the SIG, while the Excel SIG Workbook remains available for offline and legacy workflows as SIG EV develops.



SIG EV preserves the underlying questions, structure, methodology, and annual content release cycle. It changes how an assessment is accessed and managed. A buyer can use a standard SIG Lite or SIG Core scope or customize an assessment from the broader content library. SIG EV focuses on standardized assessments rather than replacing a buyer's full governance, risk, and compliance (GRC) or TPRM system.



The release year, selected scope, and delivery format all affect the response. When a customer sends an Excel SIG Workbook, you can import it into Arphie and export completed responses into the original file. For a browser-based SIG EV request, you can use Quick-Ask in Arphie to retrieve source-backed answers while you work in the customer's requested interface.



### Standardized Control Assessment



The Standardized Control Assessment (SCA) provides procedures for evaluating whether a third party's controls are designed and operating as expected. It supports onsite, virtual, and internal control reviews, giving assessors a deeper form of assurance than questionnaire assertions alone.



We do not use Arphie to perform the assessor's control-testing judgment. We help the vendor response team retrieve the policies, control descriptions, and other evidence needed to answer related requests and coordinate the people accountable for those materials.



### Vendor Risk Management Maturity Model



The Vendor Risk Management Maturity Model (VRMMM) helps an organization evaluate its TPRM program and identify areas for improvement. It examines governance, policies, lifecycle practices, resources, technology, and other program capabilities.



### Guides, Mappings, Education, and Community



Shared Assessments also publishes guidance, research, events, certifications, and mappings between its tools and widely used standards or regulations. These resources give practitioners a common vocabulary as risks and requirements change.



The SIG, SCA, and VRMMM define assessment content and methods. Our job in Arphie is different on the respondent side: we activate the vendor's current company knowledge so security, compliance, sales engineering, and proposal teams can produce a controlled response.



## Who Uses Shared Assessments Tools?



Shared Assessments tools support both sides of a third-party relationship. We built Arphie for the vendor teams preparing and approving answers, while the buyer and its assessors remain responsible for evaluating risk.



| User | How They Use Them | Where Arphie Fits |
| --- | --- | --- |
| Organizations conducting due diligence | Classify and assess vendors, collect evidence, document findings, and support monitoring. | We help the vendor prepare its response; we do not make the buyer's risk decision. |
| Vendors and service providers | Answer customer questions in a recognized format and organize evidence for future requests. | Our AI agents draft source-backed answers from approved company knowledge and preserve reviewer control. |
| Assessors and auditors | Apply structured criteria to plan and document control reviews. | We help evidence owners retrieve and coordinate supporting material without replacing control testing. |
| Security, privacy, legal, IT, procurement, and business teams | Supply subject-matter input or use assessment results in relationship decisions. | On the response side, we use Arphie to assign questions, centralize comments, and give owners, writers, and reviewers appropriate permissions. |



Many companies occupy both sides. A software company may assess its own cloud providers while completing a SIG for an enterprise customer. We support the second workflow in Arphie, where that company must answer accurately, preserve context, and secure internal approval.



## Shared Assessments and the SIG Questionnaire



“Shared Assessments” and “SIG” are related terms, but they are not synonyms. Shared Assessments is the organization and broader program. The SIG is one of its assessment products.



A customer may send:



- A secure SIG EV link for a browser-based response.



- A licensed Excel SIG Workbook for an offline or legacy workflow.



- Questions transferred into a GRC platform.



- A subset selected for the relationship.



- A proprietary questionnaire informed by SIG controls.



- A SIG followed by evidence requests and clarification.



Before drafting, capture the release year, delivery format, customer entity, product or service, deployment, data flow, geography, due date, and requested scope. Similar questions can require different answers when the assessed service, control boundary, or contract changes.



In Arphie, we separate the reusable knowledge from the delivery format. You can import an Excel questionnaire, draft and review it in Arphie, then export it in place. When the request stays in SIG EV or another online system, you can use Quick-Ask to access the same approved knowledge without treating a prior answer as automatically current.



## What a Vendor Needs to Complete a SIG



A complete SIG response usually draws on several evidence owners:



- **Security:** Governance, access, encryption, incident response, vulnerability management, and testing.



- **Privacy or Legal:** Data processing, data-subject rights, transfers, subprocessors, and contract terms.



- **IT and Engineering:** Infrastructure, architecture, operations, backups, and change management.



- **Business Continuity:** Resilience and recovery.



- **Human Resources:** Personnel security and training.



- **Procurement or Vendor Management:** Supply-chain controls.



- **Product or Business Teams:** Service-specific scope.



Useful sources include current policies, control descriptions, audit reports, certifications, architecture and data-flow diagrams, test summaries, subprocessor records, continuity plans, and approved company answers.



You can connect Arphie to repositories such as SharePoint, Confluence, and Google Drive. Our AI agents use the approved material to produce a first draft and show the sources and confidence level behind each answer. Evidence owners can then focus on gaps, exceptions, and claims that require judgment.



The SIG is not a certification. Completing it records vendor assertions and evidence for the buyer's assessment. The buyer may request clarification, remediation, a compensating control, or additional assurance after reviewing the response.



## Why a Standard SIG Still Creates Manual Work



Standard questions do not create standard answers. The response still depends on the vendor's product, hosting model, customer data, geography, control environment, and contractual commitments. Policies also change, so a completed SIG can become stale even when the next customer asks nearly identical questions.



The hardest work is usually retrieval and coordination. Response leads search several repositories, decide which evidence applies, ask subject-matter experts to resolve exceptions, and preserve the customer's spreadsheet or browser workflow.



In Arphie, we reduce that work without removing accountability. We connect live company knowledge to the response, show the source and confidence behind AI-generated answers, preserve the customer's Excel format, and route questions to the appropriate reviewers. Security, privacy, legal, and other accountable owners still approve what leaves the company.



## A Reliable Shared Assessments Response Workflow



### 1. Preserve the Assessment Format



Follow the controls of the requested delivery method. In SIG EV, complete the assessment through the secure link without changing the question structure. In Excel, preserve required tabs, formulas, IDs, dropdowns, comments, attachments, and question order. In Arphie, we support complex Excel questionnaires and export completed responses into the original file, which removes a separate reformatting step.



### 2. Establish Scope



Record the product, service, legal entity, deployment, hosting model, customer data, geography, and assessment period. Scope determines whether an existing answer applies and which evidence supports it.



### 3. Retrieve Approved Sources



Use current evidence rather than the nearest prior response. Live integrations in Arphie let our AI agents draft from approved company knowledge. Visible source links and confidence signals make each answer traceable for review.



### 4. Assign Exceptions and High-Risk Questions



Route legal commitments, customer-specific controls, unresolved gaps, and low-confidence answers to the people authorized to decide them. In Arphie, response leads can assign individual questions, tag colleagues in comments, and set appropriate owner, writer, and reviewer permissions.



### 5. Reconcile Related Materials



Align SIG answers with the contract, data processing agreement, security documentation, trust materials, subprocessor list, and other customer questionnaires. A source-backed first draft makes conflicts easier to locate, but the accountable reviewer decides which wording and evidence are valid for the customer.



### 6. Approve and Retain Context



Resolve blanks, contradictions, unsupported “yes” answers, and attachment gaps before submission. Preserve the final response with its customer, scope, version, evidence, decisions, and approval context. In Arphie, the response team can keep the project, assignments, comments, and approved answers together for governed reuse.



## Shared Assessments vs. CAIQ



The SIG and the Cloud Security Alliance's Consensus Assessments Initiative Questionnaire (CAIQ) are standardized assessment resources from different organizations.



- The **SIG** spans a broad range of third-party operational risk domains and can be scoped for the relationship.



- The **CAIQ** aligns with the Cloud Controls Matrix and concentrates on cloud security controls.



A customer may request either framework or both. Cross-framework mappings can reduce duplicate evidence work, but they do not make every question equivalent. Wording, scope, version, and expected proof still matter.



In Arphie, you can draw SIG and CAIQ answers from the same approved knowledge base while keeping the original question, source, and confidence level visible. Human reviewers adapt each response to the framework, customer, and requested evidence before final sign-off.



## The Bottom Line



Shared Assessments gives third-party risk practitioners a common set of tools and language. The SIG is its most visible questionnaire, while the SCA, VRMMM, education, and research support other parts of the risk-management lifecycle.



For vendor response teams, the standard questionnaire is only one part of the work. Current evidence, clear scope, named owners, format preservation, and controlled approval determine whether a response is reliable. With Arphie, we connect those parts so your experts can spend less time retrieving and transferring answers and more time reviewing the claims that need judgment.