SIG Lite is the condensed third-party-risk questionnaire from Shared Assessments β the same ~19-21 risk-domain skeleton as the full SIG Core, at roughly a third of the question count. Every question row carries the same fields: question ID, risk domain, question text, a Yes/No/N-A response, a free-text Additional Information field, and mappings to frameworks like ISO 27001 and NIST. If a customer sent you one: you don't need to buy anything β build an answer library from your existing SOC 2 / ISO evidence and answer it in days.
A security assessment questionnaire is a data structure, not a test. Once you see the structure β domains β questions β constrained responses β mappings β answering stops being scary.
The SIG (Standardized Information Gathering) questionnaire is published annually by Shared Assessments and is one of the two dominant vendor security questionnaire formats (the other being CAIQ for cloud). Enterprises use it to assess third parties before and during a vendor relationship. It ships in tiers: SIG Core β the full several-hundred-question library for high-risk vendors β and SIG Lite β the condensed top-level version for lower-risk vendors or first-pass screening. Buyers can also scope a custom SIG anywhere in between.
Practical translation: if you are a small SaaS vendor and a Fortune-1000 prospect sent you a SIG Lite, that is usually GOOD news β you got the lighter tier. Answer it well and quickly and you look like a bigger operation than you are.
Recent SIG releases organize questions into roughly 19-21 risk domains (the exact list shifts slightly each annual release β recent additions include AI and Nth-party/supply-chain risk). The domains you will see:
| Domain cluster | What the questions probe |
|---|---|
| Governance & risk | Enterprise risk management, security policy, organizational security, compliance management |
| People & physical | Human resources security, physical & environmental security |
| Core technical | Access control, network security, application security, server/endpoint security, cloud hosting |
| Operations | IT operations management, incident event & communications management, threat management |
| Resilience & data | Business resilience / continuity, asset & information management, privacy |
| Extended risk | Supply chain / Nth-party risk, ESG, artificial intelligence (newer releases) |
Whether it arrives as a spreadsheet or through a TPRM portal (OneTrust, ProcessUnity, Archer, Venminderβ¦), each SIG Lite question carries the same field structure:
| Field | What goes in it |
|---|---|
| Question ID / number | Stable identifier (e.g., a domain-prefixed number) β use it to key your answer library |
| Risk domain / category | Which of the ~19-21 domains the question belongs to |
| Question text | The control question itself, phrased for a Yes/No answer |
| Response | Constrained field: Yes / No / N/A (some portals add 'Yes with exceptions') |
| Additional Information | Free text β context, compensating controls, scope caveats. Your honesty lives here |
| Framework references | Mappings to ISO 27001, NIST, PCI DSS etc. β how the buyer traces your answer back to standards |
| Dimension | SIG Lite | SIG Core |
|---|---|---|
| Depth | Top-level question per topic β roughly a third the size | Full drill-down library, several hundred questions |
| Who gets it | Lower-risk vendors Β· initial screening | High-risk vendors handling sensitive data at volume |
| Time to answer (prepared) | Days with an answer library | 1-3 weeks even when prepared |
| Time to answer (cold) | 1-2 weeks of pain | A month of pain and internal chasing |
| Structure | Same domains, same fields | Same domains, same fields β just more rows |
Build the answer library ONCE: export every question, answer each honestly, and attach the evidence pointer (your SOC 2 report section, policy doc, or screenshot) next to it. Then every future questionnaire β SIG Lite, CAIQ, custom β is a lookup job, not a research project. Three rules that keep you out of trouble: (1) never answer Yes to a control you don't run β "No, compensating control: β¦" in the Additional Information field beats a discovered lie every time; (2) use N/A aggressively and explain why in one sentence β a 40-person SaaS legitimately N/As big chunks of physical-security and mainframe questions; (3) don't volunteer scope you weren't asked about. Turn it around inside a week and you'll beat 80% of the vendors in the queue.
We build the answer library, map every response to your actual SOC 2 / ISO evidence, draft the Additional-Information context in plain honest English, and turn SIG Lites around in days β without a compliance-consultant retainer.