Skip to main content
14 speakers. 7 enterprise risk teams. One day in Charlotte, Oct. 22.Save My Seat
BlackKite: Home
Menu
Back to Glossary

SIG (Standardized Information Gathering)

The Standardized Information Gathering questionnaire is a comprehensive vendor due diligence tool developed by Shared Assessments, widely adopted across industries as a standard template for collecting self-reported information on a vendor's security controls and risk practices. It is designed to be scalable across vendor tiers and risk levels.

Shared Assessments publishes SIG in more than one depth, so a team can match the questionnaire to how much scrutiny a given vendor actually needs. The questions map to widely used frameworks and regulations, which is what makes one completed SIG reusable across more than one buyer relationship. What a SIG can't do on its own is confirm that a vendor's answers still hold true after the questionnaire gets submitted.

What Do the Different SIG Versions Cover?

Shared Assessments publishes SIG at more than one depth, so a team can size the questionnaire to the vendor's risk tier instead of sending every vendor the same document. All versions draw from the same underlying library of questions, organized into roughly 20 risk domains covering areas like access control, data governance, business continuity, and privacy.

  • SIG Lite asks whether a control exists, without requiring the vendor to explain how it works. It suits lower-risk vendors or a first-pass screen.
  • SIG Core asks a vendor to describe how a control operates and often requests supporting evidence, which suits vendors handling sensitive data or regulated processes.
  • SIG Detail is the full underlying question library that Core and Lite are drawn from, used when a team needs to build a fully custom scope.

Roughly Twenty Domains Structure Every Version

The domains span technical categories like network security and endpoint security alongside operational ones like human resources, physical security, and third-party or nth-party risk management, so a single SIG response speaks to a vendor's program as a whole, not just its technology stack.

Which Regulatory Frameworks Does a SIG Response Map To?

A completed SIG maps to dozens of external frameworks and regulations, so one response can support due diligence across several of them at once. Shared Assessments maintains and publishes these crosswalks directly, which is what turns a single completed questionnaire into evidence a compliance team can point to for more than one regulatory conversation.

  • ISO 27001, the international standard for information security management systems.
  • NIST frameworks, the U.S. government's cybersecurity and risk guidance.
  • GDPR, the EU's data protection regulation.
  • PCI DSS, the payment card industry's data security standard.
  • SOC 2, the U.S. auditing standard for service organizations.

One Response Supports Multiple Frameworks at Once

A vendor mapping its controls once against the SIG's crosswalks avoids re-answering the same underlying question in five different formats for five different customers, which is most of the efficiency case for using a standardized questionnaire at all.

Regulated Industries Get the Most Value

A healthcare vendor completing one SIG response can address HIPAA-adjacent questions and general security due diligence in the same document, rather than filling out a separate form for each relationship that asks for the same underlying evidence.

How Often Is the SIG Questionnaire Updated?

Shared Assessments updates the SIG annually to reflect new regulatory requirements and changes in how attackers operate, and it launched SIG Evolution (SIG EV) in March 2026, moving the Excel-based workbook into a browser-based platform for building and distributing assessments. A vendor completing this year's version is answering questions that don't exist in a five-year-old copy still circulating in some buyer's file, which is why a risk team should confirm which edition a vendor actually used before trusting a response as current.

What Can a SIG Response Not Tell a Risk Team?

A SIG response is a vendor's word, not an independent finding, so a perfectly completed questionnaire says nothing about whether those controls are still true today. Black Kite's 2026 Supply Chain Vulnerability Report found that 87% of organizations experienced at least one AI-driven cyberattack in a single year, roughly the same window a SIG response is expected to stay current before the next reassessment cycle. A vendor isn't necessarily misrepresenting anything when a gap shows up between a SIG response and reality; the environment simply moved faster than the paperwork did. That gap is the reason a SIG works best paired with continuously collected evidence rather than treated as a standalone verdict.

How Does a SIG Response Differ From a SOC 2 Report or ISO 27001 Certification?

The biggest difference is who does the checking. A vendor completes a SIG directly, while a SOC 2 report or an ISO 27001 certification requires an independent auditor or certification body to sign off first. A SIG response can be produced in days because it doesn't require scheduling an external audit. A SOC 2 report or an ISO 27001 certification takes longer to produce but carries a third party's opinion behind it, not just the vendor's own account. Many due diligence programs use a SIG as the first, fast pass and reserve a SOC 2 or ISO 27001 request for vendors that clear an initial risk threshold. A Compliance Score measures a related but separate thing. It reflects how many recognized controls a vendor complies with out of the total identified, drawn from internet-facing documents, uploaded documents, and technical scans together.

What Should a Risk Team Do When a SIG Response Doesn't Match Reality?

The organization relying on the vendor carries the exposure until the mismatch is caught, so verification matters more than the questionnaire itself. A gap between a SIG response and independently observable evidence, such as an outside-in assessment or a continuously updated cyber rating, doesn't necessarily mean the vendor lied; it often just means the SIG is already out of date.

  • Cross-check specific claims, not the whole document, against independently observable data before accepting a response as final.
  • Ask for evidence behind a SIG Core answer, since Core responses are supposed to include supporting documentation, not just a checked box.
  • Flag the finding, not just the vendor, so remediation targets the specific control gap instead of restarting the entire questionnaire.

How Does Black Kite Use SIG Responses in Its Questionnaire Automation?

Black Kite reads a completed SIG the same way it reads any other vendor documentation, automatically mapping it against 20+ global and industry frameworks through its questionnaire automation so a risk team sees where the response already proves a control and where a real gap remains. That intelligence-first approach combines an outside-in view of a vendor's exposed footprint with the inside-out evidence a SIG or a vendor's own documentation provides as part of vendor compliance management, which is how a review that once took weeks can move to a same-day decision. Teams still evaluating vendors through a traditional vendor risk assessment process can layer this mapping on top without changing which questionnaire they send.

See also: Third-Party Due Diligence: 5-Step Checklist