AI is moving fast. See how Whisperly helps you get control back and reduce risk.See how →
    Compliance 18 min read

    What Is a SIG Questionnaire and How Do You Complete One?

    The SIG questionnaire is the most widely used vendor security assessment. Learn what SIG Core and SIG Lite cover, who sends them, and how to complete one efficiently.

    Tijana Zunic
    Tijana Zunic| CEO & Co-founder, Whisperly
    Published: · Last reviewed: · Reviewed by: Nikola Maric, Software and AI Engineer
    SIG questionnaire explained: what SIG Core and SIG Lite cover, who sends them, and how to complete one efficiently and accurately.

    If you sell to enterprise buyers in financial services, healthcare, or any regulated industry, there is a reasonable chance you have already encountered the SIG questionnaire. If you have not, you will. It tends to arrive at the worst possible moment, right when a deal is gaining traction, usually forwarded by someone in procurement with a subject line like "Please complete by Friday." The Standardized Information Gathering (SIG) questionnaire is the most widely used third-party risk assessment framework in enterprise procurement. It is a structured document, often hundreds of questions deep, that buyers use to pick apart every dimension of a vendor's security, privacy, and compliance posture before allowing that vendor anywhere near their environment.

    For the vendor on the receiving end, how this plays out depends almost entirely on whether you have done the work before the questionnaire lands. Teams with a prepared evidence library and clear internal routing can turn one around in a few days. Teams without those things watch it sit in someone's inbox for two weeks while the deal stalls. This guide covers what the SIG actually is, how the domains break down, what buyers are really looking for in each section, and how to get through the process without losing your mind or your sales cycle. For the broader context of how SIG fits into the vendor assessment landscape, see our guide on security questionnaire automation.

    What Is the SIG Questionnaire?

    TL;DRThe SIG (Standardised Information Gathering) questionnaire is a vendor risk assessment framework from Shared Assessments covering 19 risk domains. It standardises how enterprise buyers evaluate vendor security, privacy, and compliance posture. Two versions exist: SIG Core (850+ questions for critical vendors) and SIG Lite (125-175 questions for lower-risk relationships).

    The SIG (Standardised Information Gathering) questionnaire is a vendor risk assessment framework produced by Shared Assessments, a non-profit industry consortium whose members include some of the world's largest financial institutions, insurers, and professional services firms. The problem it was built to solve is straightforward: before the SIG existed, every large enterprise designed its own bespoke questionnaire. Different format. Different scope. Different expectations. Vendors found themselves answering what were essentially the same questions, phrased slightly differently, for every buyer in their pipeline. The waste was enormous.

    The SIG's contribution is a shared vocabulary. When a buyer sends you one, you are both working from the same architecture of risk domains, the same question numbering, and the same evidence expectations. The questionnaire spans 19 risk domains and covers cybersecurity, IT, privacy, data governance, and business resiliency in granular detail.

    That standardisation is precisely what makes the SIG, despite its considerable length, more manageable than a fully bespoke assessment. You can prepare for it. You can build a reusable response library around it. And once you have done so, the second SIG takes a fraction of the time the first one did.

    SIG Core vs SIG Lite: Which Will You Receive?

    TL;DRSIG Core is the full 850+ question assessment reserved for high-risk, critical vendor relationships. SIG Lite is an abbreviated 125-175 question version for lower-risk vendors. The buyer decides which version you receive based on their internal risk classification of your relationship; you do not choose.

    The SIG comes in two configurations, calibrated to different levels of vendor risk.

    SIG CoreSIG Lite
    Questions850+ across 20 risk domainsApprox. 125-175 questions
    Used forTier 1 / critical vendors; high data sensitivityLower-risk vendor relationships
    DepthFull evidence requirements; detailed narrative answersAbbreviated controls; lighter evidence
    Time to complete8-20+ hours without automation2-5 hours without automation
    Who sends itLarge enterprises, financial institutions, healthcareMid-market buyers; routine vendor reviews

    Which version lands in your inbox depends on how the buyer has classified your relationship in their own risk framework. Simple as that.

    If you are a SaaS platform handling sensitive customer data or touching financial records, expect SIG Core. If you are a lower-risk tool, maybe a scheduling app or a design platform, you might get SIG Lite. Or nothing at all. If you are genuinely unsure which to prepare for, ask the buyer's procurement contact early. Nobody has ever lost a deal by asking that question upfront, and plenty of teams have wasted days preparing for the wrong version.

    The 20 SIG Domains: What Each Section Covers

    TL;DRSIG Core organises questions across 20 risk domains, from Enterprise Risk Management and Security Policy through to Artificial Intelligence and Supply Chain Risk. Each domain maps to a recognised area of information security or operational risk. Understanding the domain structure lets you route questions to the right internal owner immediately.

    SIG Core organises its questions across 20 risk domains. Each domain maps to a recognised area of information security, data protection, or operational risk. Understanding what each domain is actually asking allows you to route questions to the right internal owner from the moment the questionnaire arrives.

    #DomainWhat it assesses
    AEnterprise Risk ManagementGovernance structure, risk appetite, board-level oversight of vendor risk
    BSecurity PolicyExistence, ownership, and review cadence of your information security policies
    COrganizational SecuritySecurity team structure, roles, responsibilities, and reporting lines
    DAsset & Info ManagementData classification, inventory management, and information handling procedures
    EHuman Resources SecurityBackground screening, onboarding controls, security training, offboarding procedures
    FPhysical & Environmental SecurityData centre access controls, physical perimeter security, environmental protections
    GIT Operations ManagementChange management, capacity planning, operational procedures, and incident logging
    HAccess ControlIdentity management, authentication standards, privilege access, and access reviews
    IApplication SecuritySecure development lifecycle, code review, vulnerability management, testing
    JCybersecurity Incident ManagementIncident detection, response procedures, breach notification, lessons learned
    KOperational ResilienceBusiness continuity planning, disaster recovery, RTO/RPO commitments
    LCompliance & Operational RiskRegulatory obligations, audit findings, compliance monitoring processes
    MEndpoint Device SecurityLaptop/mobile device controls, MDM, encryption, remote wipe capabilities
    NNetwork SecurityFirewall architecture, segmentation, intrusion detection, remote access controls
    OPrivacyPersonal data handling, consent mechanisms, data subject rights, privacy by design
    PThreat ManagementVulnerability scanning, penetration testing, threat intelligence, patching cadence
    QServer SecurityHardening standards, patch management, logging and monitoring on server infrastructure
    RCloud Hosting ServicesCloud architecture, shared responsibility model, cloud provider controls
    SArtificial IntelligenceAI system inventory, risk classification, human oversight, AI governance framework
    TSupply Chain Risk ManagementSubprocessor management, fourth-party risk, vendor concentration risk

    Domain S: Artificial Intelligence, what to prepare in 2026 This domain is relatively new. It was added because buyers started noticing that their vendors were deploying AI systems without any documented governance around them, and that made risk teams uncomfortable for obvious reasons. If your product or infrastructure involves AI, the questions in Domain S will ask you to disclose your AI system inventory, explain how you classify AI risk, describe your human oversight mechanisms, and show alignment with relevant governance standards. Having an ISO 42001 certification or at least a credible EU AI Act readiness statement puts you ahead of most vendors, who still treat this section as an afterthought. That gap is closing fast.

    The 20 SIG questionnaire risk domains — vendor security assessment — Whisperlywhisperly.ai/sig-questionnaireThe SIG covers 20 risk domains.Here is what each one assesses.DOMAINWHAT IT COVERSA–CEnterprise risk · Security policy · Org structureD–FAsset management · HR security · Physical controlsG–IIT operations · Access control · App securityJ–LIncident response · Resilience · ComplianceM–PEndpoints · Network · Privacy · Threat managementQ–RServer hardening · Cloud hostingSNEW · 2026Artificial IntelligenceAI inventory · Risk classification · Human oversightTSupply chain · Subprocessors · Fourth-party risk

    Who Sends SIG Questionnaires and Why?

    TL;DRBanks, insurers, healthcare networks, and large enterprises with mature vendor risk programmes send SIG questionnaires. These are organisations where a vendor security failure is not theoretical but a documented operational risk. If your customer base includes regulated financial services or healthcare buyers, plan on receiving a SIG.

    The short answer: risk-mature organisations that manage too many vendor relationships to design a custom questionnaire for each one. Banks. Insurance companies. Healthcare networks. Large professional services firms. These are organisations where a vendor security failure is not a theoretical risk but something that has happened to a competitor or, in some cases, to them directly.

    If your customer base includes any of the following, plan on receiving a SIG:

    • Banks, investment managers, and insurance companies conducting third-party risk management under DORA, SOC requirements, or internal policy
    • Healthcare organisations assessing vendors before granting access to patient data or clinical systems
    • Large enterprise technology buyers with mature vendor risk programmes
    • Government agencies and public sector organisations with formal procurement and due diligence requirements
    • Any regulated entity whose own compliance framework requires documented evidence of vendor controls

    One pattern worth noting: the SIG is increasingly being used as a self-assessment tool. Some organisations complete a SIG against their own controls and publish the results in their Trust Center, making a pre-completed version available so buyers can pull it without sending a formal request. It is a smart play. Complete it once, share it broadly, and the volume of inbound SIG requests drops over time.

    How to Complete a SIG Questionnaire: Step by Step

    TL;DRCompleting a SIG Core requires six steps: assign a single questionnaire owner, map each domain to an internal subject matter expert, gather your evidence library (SOC 2 reports, ISO certificates, policies), answer consistently with your documented posture, conduct a cross-functional review, and save the completed SIG as a reusable template.

    Getting through a SIG Core accurately requires preparation, clear internal routing, and the right evidence already assembled. There is no shortcut around that. But there is a method that works.

    For teams that receive SIG questionnaires regularly, security questionnaire automation cuts the time per questionnaire dramatically. The process below is essential either way.

    Step 1: Assign a questionnaire owner

    Do this before you open the spreadsheet. One person owns the process for this specific assessment. Not answering every question themselves, but coordinating: who gets which section, when it is due back, and where the gaps are. Without a single point of ownership, SIG questionnaires end up in the limbo of shared responsibility, which in practice means nobody's responsibility. We have seen deals stall for weeks because three people each assumed someone else was handling Domain O.

    Step 2: Map each domain to an internal owner

    The SIG's domain structure actually makes this straightforward, once you have done it once. Domain H (Access Control) and Domain N (Network Security) go to your security engineer or CISO. Domain O (Privacy) and Domain T (Supply Chain) go to your DPO or legal counsel. Domain I (Application Security) goes to your engineering lead. Domain K (Operational Resilience) goes to infrastructure or IT ops.

    Build this routing map before you begin. Then send every section out simultaneously. Parallelising the work is the single biggest time-saver available to you, and it costs nothing. In the Whisperly Security Automation tool it is easy to connect the entire team to work at one place and with the same knowledge base.

    Step 3: Gather your evidence library

    Most SIG domains require not just narrative answers but attached evidence. Policy documents, audit reports, penetration test summaries, certification certificates. The fewer of these you have to draft from scratch, the faster the process moves.

    The highest-value documents to have ready: your SOC 2 Type II report (covers Domains G, H, I, N, and Q extensively), your ISO 27001 certificate and statement of applicability (covers Domains B through N), your GDPR documentation including your DPA template and Records of Processing Activities (covers Domain O), and your subprocessor list (covers Domain T). If you have those four assets current and accessible, you have already answered the majority of questions before you start typing.

    Step 4: Answer consistently with your documented posture

    This one trips up more teams than you might expect. Your answers need to reflect your actual controls, not the controls you intend to have by next quarter. Buyers cross-reference SIG responses against certifications, pentest results, and sometimes prior assessments you submitted to other buyers in the same industry. An inconsistency between what you claim in the SIG and what an auditor later finds creates a problem that is simultaneously a compliance issue and a reputational one.

    If a control does not exist yet, say so. Describe the remediation plan. Buyers almost universally prefer an honest gap with a timeline over an inflated answer that unravels during diligence.

    Step 5: Review before submission

    Have a second pair of eyes on the completed questionnaire before it goes out. Ideally your CISO or legal counsel for the sensitive domains. Domain J (Incident Management), Domain L (Compliance), and Domain O (Privacy) carry the highest reputational and legal risk if something is inaccurate. Also check that every attached document is current. An expired SOC 2 report or a certification from two years ago does more harm than attaching nothing.

    Step 6: Save your completed SIG as a template

    Once submitted, save it. The majority of your answers will remain valid for the next 12 months, subject to any material changes in your infrastructure or controls. Better still, load your approved answers into a security questionnaire response library so the next SIG that arrives can be pre-populated automatically. The difference between building a SIG from scratch and reviewing a pre-filled one is, conservatively, 10-15 hours of work.

    How Certifications Reduce SIG Completion Time

    TL;DRCertifications like SOC 2 Type II and ISO 27001 provide audited, third-party evidence that controls exist, replacing narrative assertions with verified documentation. A vendor holding both certifications can complete most SIG Core domains by citing those reports, reducing original writing to residual questions those frameworks do not cover.

    The most effective approach to SIG completion is not answering faster. It is reducing the number of questions that need original answers at all. That is what certifications do. When a domain asks whether you have implemented a particular control, a certification provides audited, third-party evidence that the control exists. You are not asserting it. An independent auditor already verified it.

    CertificationSIG domains it covers
    SOC 2 Type IIG (IT Operations), H (Access Control), I (Application Security), J (Incident Management), N (Network Security), Q (Server Security)
    ISO 27001B (Security Policy), C (Organisational Security), D (Asset Management), E (HR Security), F (Physical Security), G (IT Operations), H (Access Control), K (Operational Resilience), N (Network Security)
    ISO 42001S (Artificial Intelligence): AI system governance, risk classification, human oversight
    GDPR compliance documentationO (Privacy): data subject rights, consent, DPA, ROPA, DPIA

    A vendor holding both SOC 2 Type II and ISO 27001 can typically complete the bulk of a SIG Core by citing those two certifications. Original narrative answers become necessary only for the residual questions those frameworks do not directly address. For a detailed guide to SOC 2, see our SOC 2 Guidebook. For ISO 27001, see our ISO 27001 Guidebook.

    The SIG and GDPR: What Vendors Need to Know

    TL;DRSIG Domain O maps directly to GDPR Article 28 obligations for data processors: technical and organisational measures, documentation, subprocessor restrictions, and audit cooperation. Your responses in this domain are legal representations that customers rely on for their own compliance. Prepare them from live GDPR documentation, not from memory.

    Domain O is where things get legally interesting. For European vendors, or for any vendor processing personal data on behalf of EU customers, the questions in this section map directly to the obligations GDPR Article 28 imposes on data processors. The requirement to implement appropriate technical and organisational measures, maintain documentation, restrict subprocessing, and co-operate with audits: these are not aspirational recommendations. They are legal obligations.

    Your SIG responses in Domain O are not merely a procurement checkbox. They are representations that your customers will rely upon when demonstrating their own regulatory compliance. Get this section wrong and you create a liability chain. Prepare it from your live GDPR documentation: your Data Processing Agreement template, your Records of Processing Activities, and any DPIA summaries for high-risk processing activities. If CCPA compliance is also relevant, your CCPA documentation addresses the questions US-based buyers typically add to Domain O.

    Reducing SIG Volume with a Trust Center

    TL;DRPublishing a completed SIG in a Trust Center, alongside certifications, policies, and DPA templates, allows prospective buyers to access it on demand. Each published SIG reduces inbound questionnaire volume because buyers who find a current, completed version will often use it instead of sending their own.

    Here is the move that pays the most dividends over time: publish your completed SIG. A Trust Center lets you make a completed SIG, along with your certifications, policies, and DPA template, available to prospective buyers on demand. Publicly, or gated behind an NDA request. Either way, when buyers find a current, completed SIG already sitting in your Trust Center, a significant number of them will use it instead of sending their own version. That is one less questionnaire in your pipeline, completely eliminated before it begins.

    The logic compounds. Each completed SIG you publish reduces the number of new SIGs you have to fill out. Whisperly's free Trust Center makes publishing your security documentation straightforward, with no engineering work required.

    Frequently Asked Questions

    How long does a SIG Core questionnaire take to complete?

    It depends. That is not a hedge; it genuinely ranges from about 8 hours to well over 20, depending on how much of your evidence already exists in documented form. If your SOC 2 report is current, your ISO 27001 statement of applicability is up to date, and your privacy documentation is maintained, your team is mostly reviewing and attaching rather than writing from scratch. In that scenario, 2-4 hours of focused review is realistic. But if you are building answers from zero, with multiple stakeholders who have never seen the SIG format before, budget 15-20 hours and plan around it.

    What is the difference between SIG Core and SIG Lite?

    SIG Core is the full assessment: all 20 risk domains, 850-plus questions, and it is reserved for vendors the buyer considers critical or high-risk. SIG Lite covers the same domain structure but in abbreviated form, roughly 125-175 questions, and is aimed at lower-risk vendor relationships or initial screening. The buyer decides which one you get based on how they have classified you in their risk framework. You do not choose.

    Who produces the SIG questionnaire?

    Shared Assessments, a non-profit consortium of financial services, insurance, healthcare, and professional services organisations. They update the framework periodically, which is why the version year matters. A SIG 2024 and a SIG 2025 may have meaningful differences in Domain S (Artificial Intelligence) in particular, where the questions have been expanded significantly in recent years.

    Do I need SOC 2 to complete a SIG questionnaire?

    No. But it helps enormously. A SOC 2 Type II report provides independently audited evidence for the control domains that make up the majority of SIG questions. Without one, every control question becomes a narrative assertion that a buyer's risk team has to evaluate on trust. With a current SOC 2 attached, those same questions are answered by pointing to a third-party audit. The difference in credibility, and in the time your team spends writing, is significant.

    Can I reuse a completed SIG for multiple buyers?

    Yes, with a caveat. The factual content, your policies, controls, architecture, and certifications, stays valid across multiple assessments as long as those controls remain in place. What changes is the specific questionnaire format and any buyer-specific addenda. Automation platforms can take your pre-approved answers and map them into whatever format the next buyer sends, eliminating the re-keying while still letting you tailor responses where a particular buyer asks something non-standard.

    What happens if I cannot answer a SIG question?

    Say so. Clearly and specifically. If a control does not exist or is not yet implemented, describe where you are in the remediation process and give a timeline. Buyers with mature risk programmes are far more tolerant of a transparent gap than an inflated answer that later proves wrong. Some questions may also be genuinely not applicable to your business, for example, questions about on-premises hardware when you are a fully cloud-native SaaS vendor. Mark those N/A with a brief explanation. Never leave a question blank; that reads as evasion, not oversight.

    How does the SIG relate to ISO 27001 and SOC 2?

    The SIG is a questionnaire. ISO 27001 and SOC 2 are certifications. Different instruments, overlapping territory. Achieving either certification does not exempt you from completing a SIG, no buyer will accept that argument, but it simplifies the process considerably because your audited controls provide pre-verified answers to the majority of domain questions. Think of certifications as the raw material and the SIG as the format you present that material in.

    Where does the EU AI Act affect SIG completion?

    Domain S. That is where it concentrates. Buyers subject to the EU AI Act will use Domain S to check whether their AI vendors have governance frameworks that hold up under the regulation. They want to see your AI system inventory, your risk classification methodology, and evidence of human oversight controls. Documenting these in advance, ideally with an ISO 42001 certification backing them up, turns Domain S into a 20-minute reference exercise rather than a multi-day research project under deadline pressure.

    GuideWhy it connects to this article
    Security Questionnaire Automation & RFP AutomationThe parent guide covering how to automate SIG and all other questionnaire responses end to end
    SOC 2 GuidebookSOC 2 is the single highest-impact certification for reducing SIG completion time: covers Domains G, H, I, J, N, Q
    ISO 27001 GuidebookISO 27001 certification maps directly to SIG Domains B through N: an essential evidence asset
    ISO 42001 GuidebookRequired evidence for SIG Domain S (Artificial Intelligence): increasingly requested by enterprise buyers
    GDPR GuidebookGDPR documentation is the primary evidence source for SIG Domain O (Privacy)
    ROPA AutomationRecords of Processing Activities: key evidence for SIG Domain O subprocessor and data flow questions
    CCPA GuidebookUS-facing vendors: CCPA compliance documentation for Domain O questions from US enterprise buyers
    EU AI Act GuidebookRegulatory context for SIG Domain S (Artificial Intelligence): what buyers are now asking AI vendors to prove
    Vendor Assessment (product)How Whisperly automates the sending side: building and managing your own vendor questionnaire programme
    HECVAT Questionnaire GuideThe higher education peer: vendors with mixed customer bases of universities and enterprises will encounter both frameworks
    Trust CenterPublish your completed SIG and certifications so buyers can self-serve without sending a new assessment
    SIG Questionnaire
    850+ questions
    Whisperly AI
    SOC 2ISO 27001GDPR42001
    Knowledge Base
    Policies & certs
    Draft Answers
    95%
    88%
    What used to take 15 hours, done in a fraction of the time
    SIG questionnaire automation — without versus with Whisperly — whisperly.aiwhisperly.ai850 questions. Answered before your team opensthe file.WITHOUT WHISPERLYWITH WHISPERLYForwarded to 3 teamsAI extracts every questionOutdated Google SheetMatched to verified policiesAsk engineering, again95% confidence per answerAnother week goneExported. Same day.20 hours. Every time.A fraction of that. Every time.No manual knowledge base. No searching.AI-powered. Human-reviewed.
    Automate with Whisperly

    Automate your SIG questionnaire responses with Whisperly

    Whisperly extracts every question from your SIG, matches it against your live compliance documentation, including SOC 2, ISO 27001, GDPR records, and ISO 42001, and generates confidence-rated draft answers before your team needs to engage. What used to take 15 hours takes a fraction of that.

    Book a demo | Explore RFP and questionnaire automation | Launch your free Trust Center

    | Supplier Due Diligence Checklist | A practical guide covering GDPR, AI governance, and security certifications for vendor due diligence |

    | Vendor Security Questionnaire Guide | Complete guide to vendor security questionnaires: what they cover, how frameworks compare, and how to respond efficiently |

    For workflow tips that apply across SIG and other frameworks, see our security questionnaire best practices.

    SIG questionnairevendor riskthird-party risk assessmentsecurity questionnairecomplianceVendor Management

    Questions & Answers

    How long does a SIG Core questionnaire take to complete?+

    Without automation and without a pre-built evidence library, a SIG Core typically takes between 8 and 20 hours of combined effort across multiple team members. A well-maintained response library, particularly one backed by SOC 2 and ISO 27001 certifications, can reduce this to 2-4 hours of review rather than creation.

    What is the difference between SIG Core and SIG Lite?+

    SIG Core covers all 20 risk domains with full detail, typically 850 or more questions, and is used for critical or high-risk vendor relationships. SIG Lite covers the same domain structure in abbreviated form, with approximately 125-175 questions, and is used for lower-risk vendors or for initial screening before a full vendor security assessment.

    Who produces the SIG questionnaire?+

    The SIG is produced and maintained by Shared Assessments, a non-profit consortium of financial services, insurance, healthcare, and professional services organisations. The framework is updated periodically to reflect changes in the threat landscape and regulatory environment, including new domains such as AI governance.

    Do I need SOC 2 to complete a SIG questionnaire?+

    No, but holding a SOC 2 Type II report substantially reduces the effort required. SOC 2 provides independently audited evidence for the control domains that make up the majority of SIG questions.

    Can I reuse a completed SIG for multiple buyers?+

    Yes, within limits. The factual content of your SIG responses remains valid across multiple assessments for as long as those controls remain in place. Automation platforms can take your pre-approved answers and map them into any buyer SIG format.

    What happens if I cannot answer a SIG question?+

    If a control does not exist or is not yet implemented, the correct approach is to say so clearly and describe your timeline and plan for remediation. Buyers are generally more tolerant of a transparent gap with a credible remediation plan than an inflated answer. For more on questionnaire best practices, see our dedicated guide.

    How does the SIG relate to ISO 27001 and SOC 2?+

    The SIG is a questionnaire framework, not a certification. ISO 27001 and SOC 2 are certification and audit standards whose requirements map closely to SIG domain coverage. Achieving either certification substantially simplifies the SIG completion process.

    Where does the EU AI Act affect SIG completion?+

    Domain S of the SIG, Artificial Intelligence, is the primary area where the EU AI Act affects your SIG responses. Buyers subject to the AI Act will use Domain S to verify that their AI vendors have appropriate governance frameworks in place.

    Tijana Zunic

    Written by

    Tijana Zunic

    CEO & Co-founder, Whisperly

    Reviewed by: Nikola Maric, Software and AI Engineer

    Share
    Get Started

    Ready to make compliance
    feel effortless?

    Join 100+ companies automating GRC with Whisperly. Get audit-ready in weeks, not months.

    Stay ahead of compliance changes

    Practical compliance tips, delivered to your inbox every two weeks.