Standardized Information Gathering (SIG) Questionnaire
The Standardized Information Gathering (SIG) Questionnaire is a standardized set of questions used to collect security and risk information from vendors and other third parties. Organizations use it to assess how well a vendor protects data and manages security before or during a business relationship. It provides a common format so companies do not have to build vendor security questions from scratch each time.
The SIG Questionnaire is a standardized vendor risk assessment instrument used to perform security risk assessments of third parties. It is maintained and distributed through the Shared Assessments program, where a questionnaire is generated from a stored template and can be scoped and customized to the assessment's needs. The questionnaire maps to the requirements of numerous cybersecurity regulations and frameworks, enabling organizations to evaluate a vendor's security controls in a consistent, comparable manner. In practice, tooling such as a SIG Manager is used to create the Excel-based questionnaire from a standard scoping template, and variants exist to support broader or more focused assessments. Note that the SIG supports the information-gathering and control-evaluation stage of third-party due diligence; interpreting responses, validating evidence, and making risk decisions remain the responsibility of the assessing organization.
Why it matters
As organizations increasingly depend on third parties for critical services, the security posture of those vendors becomes an extension of the organization's own risk exposure. The SIG Questionnaire addresses a practical problem in third-party risk management: without a standardized instrument, each organization would have to design vendor security questions from scratch, and each vendor would face a different questionnaire from every customer. By providing a common, mapped format, the SIG reduces duplicated effort on both sides and enables assessing organizations to evaluate vendor security controls in a more consistent and comparable manner.
The SIG is valuable precisely because it maps to the requirements of numerous cybersecurity regulations and frameworks, allowing a single questionnaire to inform multiple compliance and due diligence needs. This makes it useful during vendor onboarding, periodic reassessment, and contract renewal. However, it is important to be clear about what the SIG does and does not accomplish. It supports the information-gathering and control-evaluation stage of due diligence; it does not, on its own, validate that a vendor's stated controls are actually in place or effective. The value of a SIG-based assessment depends heavily on the assessing organization's willingness to interpret responses critically, request supporting evidence, and follow up on gaps.
A common mistake is to treat a completed SIG as proof of vendor security or as a substitute for a risk decision. It is neither. Interpreting responses, validating evidence, and deciding whether a vendor's risk is acceptable remain the responsibility of the assessing organization. Used well, the SIG is a structured starting point for a risk conversation; used poorly, it becomes a checkbox exercise that produces a false sense of assurance.
Who it's relevant to
Inside SIG
Common questions
Answers to the questions practitioners most commonly ask about SIG.