What is the SIG questionnaire?
SIG Core and SIG Lite
The SIG is a single question library, published and maintained by Shared Assessments, delivered at two depths. SIG Lite is the broad first-pass screen a buyer uses when they need a quick, comparable view across many vendors. SIG Core is the full assessment, used where the vendor is material — where they hold customer data, sit on a critical process, or fall inside a regulated relationship.
Buyers choose the depth per vendor risk tier, and the depth you receive is itself a signal: a Lite means you have cleared the first hurdle and are being triaged; a Core means the buyer has decided you matter and is investing time to understand you. Answer both from the same underlying record — the Lite is a subset of the Core, and inconsistencies between the two are one of the first things a reviewer will notice.
Who sends it
The SIG is the default in financial services, insurance and healthcare, and it flows down from those buyers to their supply chains — so a technology vendor selling into a bank or an insurer typically sees the SIG rather than the CAIQ. If your buyer is regulated, expect the SIG; if their regulator scrutinises third-party risk, expect the SIG Core.
Shared Assessments updates the library annually and publishes the changes; buyers frequently sit a version or two behind the latest release. Read the version your buyer sent and answer against that; do not assume the current release matches the questionnaire on your desk.
The AI content
Recent SIG releases carry dedicated AI risk content — model use, data provenance, human oversight, third-party AI and the governance around it. This is the section AI vendors are least ready for, and it is where reviewers concentrate. The vendor who answers "N/A" to the AI section because they consume an AI API rather than train a model is the red flag, not the safe answer: the SIG is asking about the AI you use as much as the AI you build, and the reviewer will follow up.
The Answer Library carries a model answer for each of these AI questions, with the evidence a reviewer expects behind it. Use it to see what a defensible SIG answer looks like before you write yours.
How to answer it well
The citation principle from any serious questionnaire applies with more force in the SIG, because the SIG will be re-used: the answers you give this buyer will be re-issued to the next. Attach evidence per answer, name the owner, date the artefact. Buyers pay for the SIG library because it lets them compare vendors; make yours the one that reads as coherent.
Consistency across the SIG, your trust page and your public statements is what reviewers check. A SIG that says one number and a trust page that says another does not read as an update in flight; it reads as a control you do not know the state of.
Answer it from a record
Import your controls and vendors, answer each question cited to a sealed record, and hold open honestly the ones you cannot yet ground. When the reviewer spot-checks, the citation opens; when a gap is real, the interim control and the date read as maturity, not evasion. This is the motion Hael runs: one record, sealed documents, cited answers, honest gaps.