If you sell to enterprise buyers in financial services, healthcare, or any regulated industry, there is a reasonable chance you have already encountered the SIG questionnaire. If you have not, you will. It tends to arrive at the worst possible moment, right when a deal is gaining traction, usually forwarded by someone in procurement with a subject line like "Please complete by Friday." The Standardized Information Gathering (SIG) questionnaire is the most widely used third-party risk assessment framework in enterprise procurement. It is a structured document, often hundreds of questions deep, that buyers use to pick apart every dimension of a vendor's security, privacy, and compliance posture before allowing that vendor anywhere near their environment.
For the vendor on the receiving end, how this plays out depends almost entirely on whether you have done the work before the questionnaire lands. Teams with a prepared evidence library and clear internal routing can turn one around in a few days. Teams without those things watch it sit in someone's inbox for two weeks while the deal stalls. This guide covers what the SIG actually is, how the domains break down, what buyers are really looking for in each section, and how to get through the process without losing your mind or your sales cycle. For the broader context of how SIG fits into the vendor assessment landscape, see our guide on security questionnaire automation.
What Is the SIG Questionnaire?
TL;DRThe SIG (Standardised Information Gathering) questionnaire is a vendor risk assessment framework from Shared Assessments covering 19 risk domains. It standardises how enterprise buyers evaluate vendor security, privacy, and compliance posture. Two versions exist: SIG Core (850+ questions for critical vendors) and SIG Lite (125-175 questions for lower-risk relationships).
The SIG (Standardised Information Gathering) questionnaire is a vendor risk assessment framework produced by Shared Assessments, a non-profit industry consortium whose members include some of the world's largest financial institutions, insurers, and professional services firms. The problem it was built to solve is straightforward: before the SIG existed, every large enterprise designed its own bespoke questionnaire. Different format. Different scope. Different expectations. Vendors found themselves answering what were essentially the same questions, phrased slightly differently, for every buyer in their pipeline. The waste was enormous.
The SIG's contribution is a shared vocabulary. When a buyer sends you one, you are both working from the same architecture of risk domains, the same question numbering, and the same evidence expectations. The questionnaire spans 19 risk domains and covers cybersecurity, IT, privacy, data governance, and business resiliency in granular detail.
That standardisation is precisely what makes the SIG, despite its considerable length, more manageable than a fully bespoke assessment. You can prepare for it. You can build a reusable response library around it. And once you have done so, the second SIG takes a fraction of the time the first one did.
SIG Core vs SIG Lite: Which Will You Receive?
TL;DRSIG Core is the full 850+ question assessment reserved for high-risk, critical vendor relationships. SIG Lite is an abbreviated 125-175 question version for lower-risk vendors. The buyer decides which version you receive based on their internal risk classification of your relationship; you do not choose.
The SIG comes in two configurations, calibrated to different levels of vendor risk.
| SIG Core | SIG Lite | |
|---|---|---|
| Questions | 850+ across 20 risk domains | Approx. 125-175 questions |
| Used for | Tier 1 / critical vendors; high data sensitivity | Lower-risk vendor relationships |
| Depth | Full evidence requirements; detailed narrative answers | Abbreviated controls; lighter evidence |
| Time to complete | 8-20+ hours without automation | 2-5 hours without automation |
| Who sends it | Large enterprises, financial institutions, healthcare | Mid-market buyers; routine vendor reviews |
Which version lands in your inbox depends on how the buyer has classified your relationship in their own risk framework. Simple as that.
If you are a SaaS platform handling sensitive customer data or touching financial records, expect SIG Core. If you are a lower-risk tool, maybe a scheduling app or a design platform, you might get SIG Lite. Or nothing at all. If you are genuinely unsure which to prepare for, ask the buyer's procurement contact early. Nobody has ever lost a deal by asking that question upfront, and plenty of teams have wasted days preparing for the wrong version.
The 20 SIG Domains: What Each Section Covers
TL;DRSIG Core organises questions across 20 risk domains, from Enterprise Risk Management and Security Policy through to Artificial Intelligence and Supply Chain Risk. Each domain maps to a recognised area of information security or operational risk. Understanding the domain structure lets you route questions to the right internal owner immediately.
SIG Core organises its questions across 20 risk domains. Each domain maps to a recognised area of information security, data protection, or operational risk. Understanding what each domain is actually asking allows you to route questions to the right internal owner from the moment the questionnaire arrives.
| # | Domain | What it assesses |
|---|---|---|
| A | Enterprise Risk Management | Governance structure, risk appetite, board-level oversight of vendor risk |
| B | Security Policy | Existence, ownership, and review cadence of your information security policies |
| C | Organizational Security | Security team structure, roles, responsibilities, and reporting lines |
| D | Asset & Info Management | Data classification, inventory management, and information handling procedures |
| E | Human Resources Security | Background screening, onboarding controls, security training, offboarding procedures |
| F | Physical & Environmental Security | Data centre access controls, physical perimeter security, environmental protections |
| G | IT Operations Management | Change management, capacity planning, operational procedures, and incident logging |
| H | Access Control | Identity management, authentication standards, privilege access, and access reviews |
| I | Application Security | Secure development lifecycle, code review, vulnerability management, testing |
| J | Cybersecurity Incident Management | Incident detection, response procedures, breach notification, lessons learned |
| K | Operational Resilience | Business continuity planning, disaster recovery, RTO/RPO commitments |
| L | Compliance & Operational Risk | Regulatory obligations, audit findings, compliance monitoring processes |
| M | Endpoint Device Security | Laptop/mobile device controls, MDM, encryption, remote wipe capabilities |
| N | Network Security | Firewall architecture, segmentation, intrusion detection, remote access controls |
| O | Privacy | Personal data handling, consent mechanisms, data subject rights, privacy by design |
| P | Threat Management | Vulnerability scanning, penetration testing, threat intelligence, patching cadence |
| Q | Server Security | Hardening standards, patch management, logging and monitoring on server infrastructure |
| R | Cloud Hosting Services | Cloud architecture, shared responsibility model, cloud provider controls |
| S | Artificial Intelligence | AI system inventory, risk classification, human oversight, AI governance framework |
| T | Supply Chain Risk Management | Subprocessor management, fourth-party risk, vendor concentration risk |
Domain S: Artificial Intelligence, what to prepare in 2026 This domain is relatively new. It was added because buyers started noticing that their vendors were deploying AI systems without any documented governance around them, and that made risk teams uncomfortable for obvious reasons. If your product or infrastructure involves AI, the questions in Domain S will ask you to disclose your AI system inventory, explain how you classify AI risk, describe your human oversight mechanisms, and show alignment with relevant governance standards. Having an ISO 42001 certification or at least a credible EU AI Act readiness statement puts you ahead of most vendors, who still treat this section as an afterthought. That gap is closing fast.
Who Sends SIG Questionnaires and Why?
TL;DRBanks, insurers, healthcare networks, and large enterprises with mature vendor risk programmes send SIG questionnaires. These are organisations where a vendor security failure is not theoretical but a documented operational risk. If your customer base includes regulated financial services or healthcare buyers, plan on receiving a SIG.
The short answer: risk-mature organisations that manage too many vendor relationships to design a custom questionnaire for each one. Banks. Insurance companies. Healthcare networks. Large professional services firms. These are organisations where a vendor security failure is not a theoretical risk but something that has happened to a competitor or, in some cases, to them directly.
If your customer base includes any of the following, plan on receiving a SIG:
- Banks, investment managers, and insurance companies conducting third-party risk management under DORA, SOC requirements, or internal policy
- Healthcare organisations assessing vendors before granting access to patient data or clinical systems
- Large enterprise technology buyers with mature vendor risk programmes
- Government agencies and public sector organisations with formal procurement and due diligence requirements
- Any regulated entity whose own compliance framework requires documented evidence of vendor controls
One pattern worth noting: the SIG is increasingly being used as a self-assessment tool. Some organisations complete a SIG against their own controls and publish the results in their Trust Center, making a pre-completed version available so buyers can pull it without sending a formal request. It is a smart play. Complete it once, share it broadly, and the volume of inbound SIG requests drops over time.
How to Complete a SIG Questionnaire: Step by Step
TL;DRCompleting a SIG Core requires six steps: assign a single questionnaire owner, map each domain to an internal subject matter expert, gather your evidence library (SOC 2 reports, ISO certificates, policies), answer consistently with your documented posture, conduct a cross-functional review, and save the completed SIG as a reusable template.
Getting through a SIG Core accurately requires preparation, clear internal routing, and the right evidence already assembled. There is no shortcut around that. But there is a method that works.
For teams that receive SIG questionnaires regularly, security questionnaire automation cuts the time per questionnaire dramatically. The process below is essential either way.
Step 1: Assign a questionnaire owner
Do this before you open the spreadsheet. One person owns the process for this specific assessment. Not answering every question themselves, but coordinating: who gets which section, when it is due back, and where the gaps are. Without a single point of ownership, SIG questionnaires end up in the limbo of shared responsibility, which in practice means nobody's responsibility. We have seen deals stall for weeks because three people each assumed someone else was handling Domain O.
Step 2: Map each domain to an internal owner
The SIG's domain structure actually makes this straightforward, once you have done it once. Domain H (Access Control) and Domain N (Network Security) go to your security engineer or CISO. Domain O (Privacy) and Domain T (Supply Chain) go to your DPO or legal counsel. Domain I (Application Security) goes to your engineering lead. Domain K (Operational Resilience) goes to infrastructure or IT ops.
Build this routing map before you begin. Then send every section out simultaneously. Parallelising the work is the single biggest time-saver available to you, and it costs nothing. In the Whisperly Security Automation tool it is easy to connect the entire team to work at one place and with the same knowledge base.
Step 3: Gather your evidence library
Most SIG domains require not just narrative answers but attached evidence. Policy documents, audit reports, penetration test summaries, certification certificates. The fewer of these you have to draft from scratch, the faster the process moves.
The highest-value documents to have ready: your SOC 2 Type II report (covers Domains G, H, I, N, and Q extensively), your ISO 27001 certificate and statement of applicability (covers Domains B through N), your GDPR documentation including your DPA template and Records of Processing Activities (covers Domain O), and your subprocessor list (covers Domain T). If you have those four assets current and accessible, you have already answered the majority of questions before you start typing.
Step 4: Answer consistently with your documented posture
This one trips up more teams than you might expect. Your answers need to reflect your actual controls, not the controls you intend to have by next quarter. Buyers cross-reference SIG responses against certifications, pentest results, and sometimes prior assessments you submitted to other buyers in the same industry. An inconsistency between what you claim in the SIG and what an auditor later finds creates a problem that is simultaneously a compliance issue and a reputational one.
If a control does not exist yet, say so. Describe the remediation plan. Buyers almost universally prefer an honest gap with a timeline over an inflated answer that unravels during diligence.
Step 5: Review before submission
Have a second pair of eyes on the completed questionnaire before it goes out. Ideally your CISO or legal counsel for the sensitive domains. Domain J (Incident Management), Domain L (Compliance), and Domain O (Privacy) carry the highest reputational and legal risk if something is inaccurate. Also check that every attached document is current. An expired SOC 2 report or a certification from two years ago does more harm than attaching nothing.
Step 6: Save your completed SIG as a template
Once submitted, save it. The majority of your answers will remain valid for the next 12 months, subject to any material changes in your infrastructure or controls. Better still, load your approved answers into a security questionnaire response library so the next SIG that arrives can be pre-populated automatically. The difference between building a SIG from scratch and reviewing a pre-filled one is, conservatively, 10-15 hours of work.
How Certifications Reduce SIG Completion Time
TL;DRCertifications like SOC 2 Type II and ISO 27001 provide audited, third-party evidence that controls exist, replacing narrative assertions with verified documentation. A vendor holding both certifications can complete most SIG Core domains by citing those reports, reducing original writing to residual questions those frameworks do not cover.
The most effective approach to SIG completion is not answering faster. It is reducing the number of questions that need original answers at all. That is what certifications do. When a domain asks whether you have implemented a particular control, a certification provides audited, third-party evidence that the control exists. You are not asserting it. An independent auditor already verified it.
| Certification | SIG domains it covers |
|---|---|
| SOC 2 Type II | G (IT Operations), H (Access Control), I (Application Security), J (Incident Management), N (Network Security), Q (Server Security) |
| ISO 27001 | B (Security Policy), C (Organisational Security), D (Asset Management), E (HR Security), F (Physical Security), G (IT Operations), H (Access Control), K (Operational Resilience), N (Network Security) |
| ISO 42001 | S (Artificial Intelligence): AI system governance, risk classification, human oversight |
| GDPR compliance documentation | O (Privacy): data subject rights, consent, DPA, ROPA, DPIA |
A vendor holding both SOC 2 Type II and ISO 27001 can typically complete the bulk of a SIG Core by citing those two certifications. Original narrative answers become necessary only for the residual questions those frameworks do not directly address. For a detailed guide to SOC 2, see our SOC 2 Guidebook. For ISO 27001, see our ISO 27001 Guidebook.
The SIG and GDPR: What Vendors Need to Know
TL;DRSIG Domain O maps directly to GDPR Article 28 obligations for data processors: technical and organisational measures, documentation, subprocessor restrictions, and audit cooperation. Your responses in this domain are legal representations that customers rely on for their own compliance. Prepare them from live GDPR documentation, not from memory.
Domain O is where things get legally interesting. For European vendors, or for any vendor processing personal data on behalf of EU customers, the questions in this section map directly to the obligations GDPR Article 28 imposes on data processors. The requirement to implement appropriate technical and organisational measures, maintain documentation, restrict subprocessing, and co-operate with audits: these are not aspirational recommendations. They are legal obligations.
Your SIG responses in Domain O are not merely a procurement checkbox. They are representations that your customers will rely upon when demonstrating their own regulatory compliance. Get this section wrong and you create a liability chain. Prepare it from your live GDPR documentation: your Data Processing Agreement template, your Records of Processing Activities, and any DPIA summaries for high-risk processing activities. If CCPA compliance is also relevant, your CCPA documentation addresses the questions US-based buyers typically add to Domain O.
Reducing SIG Volume with a Trust Center
TL;DRPublishing a completed SIG in a Trust Center, alongside certifications, policies, and DPA templates, allows prospective buyers to access it on demand. Each published SIG reduces inbound questionnaire volume because buyers who find a current, completed version will often use it instead of sending their own.
Here is the move that pays the most dividends over time: publish your completed SIG. A Trust Center lets you make a completed SIG, along with your certifications, policies, and DPA template, available to prospective buyers on demand. Publicly, or gated behind an NDA request. Either way, when buyers find a current, completed SIG already sitting in your Trust Center, a significant number of them will use it instead of sending their own version. That is one less questionnaire in your pipeline, completely eliminated before it begins.
The logic compounds. Each completed SIG you publish reduces the number of new SIGs you have to fill out. Whisperly's free Trust Center makes publishing your security documentation straightforward, with no engineering work required.
Frequently Asked Questions
How long does a SIG Core questionnaire take to complete?
It depends. That is not a hedge; it genuinely ranges from about 8 hours to well over 20, depending on how much of your evidence already exists in documented form. If your SOC 2 report is current, your ISO 27001 statement of applicability is up to date, and your privacy documentation is maintained, your team is mostly reviewing and attaching rather than writing from scratch. In that scenario, 2-4 hours of focused review is realistic. But if you are building answers from zero, with multiple stakeholders who have never seen the SIG format before, budget 15-20 hours and plan around it.
What is the difference between SIG Core and SIG Lite?
SIG Core is the full assessment: all 20 risk domains, 850-plus questions, and it is reserved for vendors the buyer considers critical or high-risk. SIG Lite covers the same domain structure but in abbreviated form, roughly 125-175 questions, and is aimed at lower-risk vendor relationships or initial screening. The buyer decides which one you get based on how they have classified you in their risk framework. You do not choose.
Who produces the SIG questionnaire?
Shared Assessments, a non-profit consortium of financial services, insurance, healthcare, and professional services organisations. They update the framework periodically, which is why the version year matters. A SIG 2024 and a SIG 2025 may have meaningful differences in Domain S (Artificial Intelligence) in particular, where the questions have been expanded significantly in recent years.
Do I need SOC 2 to complete a SIG questionnaire?
No. But it helps enormously. A SOC 2 Type II report provides independently audited evidence for the control domains that make up the majority of SIG questions. Without one, every control question becomes a narrative assertion that a buyer's risk team has to evaluate on trust. With a current SOC 2 attached, those same questions are answered by pointing to a third-party audit. The difference in credibility, and in the time your team spends writing, is significant.
Can I reuse a completed SIG for multiple buyers?
Yes, with a caveat. The factual content, your policies, controls, architecture, and certifications, stays valid across multiple assessments as long as those controls remain in place. What changes is the specific questionnaire format and any buyer-specific addenda. Automation platforms can take your pre-approved answers and map them into whatever format the next buyer sends, eliminating the re-keying while still letting you tailor responses where a particular buyer asks something non-standard.
What happens if I cannot answer a SIG question?
Say so. Clearly and specifically. If a control does not exist or is not yet implemented, describe where you are in the remediation process and give a timeline. Buyers with mature risk programmes are far more tolerant of a transparent gap than an inflated answer that later proves wrong. Some questions may also be genuinely not applicable to your business, for example, questions about on-premises hardware when you are a fully cloud-native SaaS vendor. Mark those N/A with a brief explanation. Never leave a question blank; that reads as evasion, not oversight.
How does the SIG relate to ISO 27001 and SOC 2?
The SIG is a questionnaire. ISO 27001 and SOC 2 are certifications. Different instruments, overlapping territory. Achieving either certification does not exempt you from completing a SIG, no buyer will accept that argument, but it simplifies the process considerably because your audited controls provide pre-verified answers to the majority of domain questions. Think of certifications as the raw material and the SIG as the format you present that material in.
Where does the EU AI Act affect SIG completion?
Domain S. That is where it concentrates. Buyers subject to the EU AI Act will use Domain S to check whether their AI vendors have governance frameworks that hold up under the regulation. They want to see your AI system inventory, your risk classification methodology, and evidence of human oversight controls. Documenting these in advance, ideally with an ISO 42001 certification backing them up, turns Domain S into a 20-minute reference exercise rather than a multi-day research project under deadline pressure.
Related Whisperly Guides
| Guide | Why it connects to this article |
|---|---|
| Security Questionnaire Automation & RFP Automation | The parent guide covering how to automate SIG and all other questionnaire responses end to end |
| SOC 2 Guidebook | SOC 2 is the single highest-impact certification for reducing SIG completion time: covers Domains G, H, I, J, N, Q |
| ISO 27001 Guidebook | ISO 27001 certification maps directly to SIG Domains B through N: an essential evidence asset |
| ISO 42001 Guidebook | Required evidence for SIG Domain S (Artificial Intelligence): increasingly requested by enterprise buyers |
| GDPR Guidebook | GDPR documentation is the primary evidence source for SIG Domain O (Privacy) |
| ROPA Automation | Records of Processing Activities: key evidence for SIG Domain O subprocessor and data flow questions |
| CCPA Guidebook | US-facing vendors: CCPA compliance documentation for Domain O questions from US enterprise buyers |
| EU AI Act Guidebook | Regulatory context for SIG Domain S (Artificial Intelligence): what buyers are now asking AI vendors to prove |
| Vendor Assessment (product) | How Whisperly automates the sending side: building and managing your own vendor questionnaire programme |
| HECVAT Questionnaire Guide | The higher education peer: vendors with mixed customer bases of universities and enterprises will encounter both frameworks |
| Trust Center | Publish your completed SIG and certifications so buyers can self-serve without sending a new assessment |
Automate your SIG questionnaire responses with Whisperly
Whisperly extracts every question from your SIG, matches it against your live compliance documentation, including SOC 2, ISO 27001, GDPR records, and ISO 42001, and generates confidence-rated draft answers before your team needs to engage. What used to take 15 hours takes a fraction of that.
Book a demo | Explore RFP and questionnaire automation | Launch your free Trust Center
| Supplier Due Diligence Checklist | A practical guide covering GDPR, AI governance, and security certifications for vendor due diligence |
| Vendor Security Questionnaire Guide | Complete guide to vendor security questionnaires: what they cover, how frameworks compare, and how to respond efficiently |
For workflow tips that apply across SIG and other frameworks, see our security questionnaire best practices.
Further Reading on Whisperly
Questions & Answers
How long does a SIG Core questionnaire take to complete?+
Without automation and without a pre-built evidence library, a SIG Core typically takes between 8 and 20 hours of combined effort across multiple team members. A well-maintained response library, particularly one backed by SOC 2 and ISO 27001 certifications, can reduce this to 2-4 hours of review rather than creation.
What is the difference between SIG Core and SIG Lite?+
SIG Core covers all 20 risk domains with full detail, typically 850 or more questions, and is used for critical or high-risk vendor relationships. SIG Lite covers the same domain structure in abbreviated form, with approximately 125-175 questions, and is used for lower-risk vendors or for initial screening before a full vendor security assessment.
Who produces the SIG questionnaire?+
The SIG is produced and maintained by Shared Assessments, a non-profit consortium of financial services, insurance, healthcare, and professional services organisations. The framework is updated periodically to reflect changes in the threat landscape and regulatory environment, including new domains such as AI governance.
Do I need SOC 2 to complete a SIG questionnaire?+
No, but holding a SOC 2 Type II report substantially reduces the effort required. SOC 2 provides independently audited evidence for the control domains that make up the majority of SIG questions.
Can I reuse a completed SIG for multiple buyers?+
Yes, within limits. The factual content of your SIG responses remains valid across multiple assessments for as long as those controls remain in place. Automation platforms can take your pre-approved answers and map them into any buyer SIG format.
What happens if I cannot answer a SIG question?+
If a control does not exist or is not yet implemented, the correct approach is to say so clearly and describe your timeline and plan for remediation. Buyers are generally more tolerant of a transparent gap with a credible remediation plan than an inflated answer. For more on questionnaire best practices, see our dedicated guide.
How does the SIG relate to ISO 27001 and SOC 2?+
Where does the EU AI Act affect SIG completion?+
Domain S of the SIG, Artificial Intelligence, is the primary area where the EU AI Act affects your SIG responses. Buyers subject to the AI Act will use Domain S to verify that their AI vendors have appropriate governance frameworks in place.

Reviewed by: Nikola Maric, Software and AI Engineer