To handle a SIG Lite without spending weeks on it, the method comes down to a few moves: first gather your dated security documents, answer domain by domain rather than line by line, honestly flag the missing controls with an improvement plan, then have each domain reviewed by the person responsible for it. The first questionnaire builds a reusable answer base; the next ones only update it.

What is the SIG, and SIG Lite?

The SIG (Standardized Information Gathering) is a vendor risk assessment questionnaire published and maintained by Shared Assessments, an industry organization specialized in third-party risk management. Instead of an in-house questionnaire specific to each customer, it is a shared format: the same questions, the same structure, reusable from one client to the next.

In practice, the SIG most often comes as a workbook (usually a spreadsheet) organized by risk domains. Shared Assessments counts 21 of them, for example access control, application security, asset management, business continuity, incident response, third-party management, and cloud security. Each question calls for a closed answer (yes, no, not applicable) and a comment space. Shared Assessments revises this content on an annual cycle.

Shared Assessments defines three levels. SIG Lite serves basic due diligence or a preliminary assessment: it is the short version, often the first questionnaire received. SIG Core targets third parties that process sensitive or regulated data, over a broader scope. SIG Detail goes deep on a specific domain, with detailed questions drawn from the content library. This library is not a level: it is the pool of questions you draw from to compose a tailored questionnaire. The exact number of questions at each level changes with every annual edition: rely on the version you were sent rather than a general figure.

The SIG is a standard maintained by Shared Assessments and revised every year. Its value lies in its reusability: prepared once, your answers serve every customer that adopts it.

Shared Assessments, SIG program

Two things set it apart from an in-house questionnaire: it is standardized, so your answers are largely reusable from one customer to the next, and it is structured by domains, so you can prepare it in coherent blocks rather than question by question.

Who sends it, and why

The SIG is used mainly in the financial sector: banks, insurers, asset managers, enterprise customers that assess their providers before contracting and then throughout the relationship. Shared Assessments reports more than 100,000 SIGs exchanged each year, which makes it one of the reference formats for third-party risk management, even though it now reaches beyond finance.

In practice, SIG Lite most often arrives through the procurement team, the vendor risk management function, or the customer’s security officer, at the time of onboarding or renewal. The goal on the customer side is constant: to document, for its own risk file, proof that your company masters what it claims to master. The person reading your answers is not looking for “Yes”: they are looking for usable answers, with a policy cited, a date, a scope.

How to fill it out, section by section

The temptation is to open the workbook and answer in order, line after line. That is the longest path: the questions in a single domain almost always rely on the same two or three documents. It is much faster to start from the documents.

1. Build the document base

Before answering anything, gather what already exists. For a SIG Lite, the typical base fits on a short list:

  • an information security policy, dated and signed;
  • an access management policy and an onboarding and offboarding procedure;
  • an encryption policy (at rest, in transit, key management);
  • a continuity plan and the latest restore test;
  • an incident management and notification procedure;
  • a sub-processor register and data location;
  • a secure development policy and the latest penetration test;
  • any certifications with their scope (ISO 27001, SOC 2).

Every document found here prevents ten improvised answers later. And the inventory of gaps you discover at this stage is already, in itself, a useful deliverable.

2. Answer domain by domain

Handle the SIG in coherent blocks, in the order of its 21 risk domains, not in the raw order of the lines. The questions in a single domain rest on the same documents: handling them together ensures the answers are consistent with each other and cuts the search time.

For each question, the structure of a good answer is always the same: the position (yes, no, not applicable), the reference to the document that proves it with its version and date, and the exact scope covered. “Yes, see Access Management Policy v3, section 4, reviewed in January 2026, production scope” is worth infinitely more than a bare “Yes.”

3. Handle gaps honestly

Every mid-sized company will have missing or partial controls. That is expected. What disqualifies a dossier is not the gap: it is the unverifiable “Yes,” which will be caught in review or, worse, during a document-based validation.

For each gap, three possible answers: “No, planned for next quarter” with a dated plan, “Not applicable” with a one-sentence justification, or “Partially” with the scope actually covered. Third-party risk management teams know how to read a credible improvement plan; they also know how to spot a box checked too quickly.

4. Prepare the internal review

A SIG commits your company. Before sending, each domain has to go before the person who answers for it: the security officer or whoever fills that role for the technical measures, legal for subcontracting and contractual commitments, management for the timelines and plans announced, the data protection officer when personal data is involved. Prepare this review by listing, domain by domain, who validates what: that is what turns three weeks of round-trips into a one-hour meeting.

The mistakes that cost round-trips

The same causes produce the same follow-ups. In SIG Lite dossiers that come back with a list of additional questions, you almost always find:

  • “Yes” answers with no reference: the answer may exist, but with no document cited it is unverifiable and will be challenged;
  • mixed-up scopes: the group policy cited for a product it does not cover;
  • missing or expired dates: a policy not reviewed in three years says the opposite of what it claims;
  • inconsistencies between domains: “systematic” encryption on the cryptography side, but exceptions on the backup side;
  • answers that contradict a previous dossier: if the same customer has assessed you before, it will compare from one year to the next.

The remedy is the same for all of them: a single answer base, kept up to date, with each answer’s supporting evidence, its date, and the person who validated it. The first SIG builds this base; the next ones only update it.