Skip to main content
Category: Assessment and Due Diligence

SIG Core

Also known as: Standardized Information Gathering (SIG) Questionnaire, SIG Core Questionnaire
Simply put

SIG Core is a standardized questionnaire used to gather detailed information about a third-party service provider's security and risk controls. It is the more comprehensive version in the SIG family and is typically used for vendors that handle sensitive or regulated information or otherwise pose higher risk. Organizations send it during due diligence to understand how a provider manages risk across many different areas.

Formal definition

SIG Core is a standardized assessment questionnaire maintained under the Shared Assessments program, designed to collect information from third-party service providers across multiple risk domains. It represents the more extensive tier of the SIG questionnaire family (contrasted with the shorter SIG Lite), containing a broad library of questions covering controls and definitions, and is generally recommended for higher-risk third parties, including those that store or manage highly sensitive or regulated information such as personal data. As a self-reported instrument, SIG Core supports information gathering during onboarding and periodic reassessment but does not, on its own, constitute independent verification of a provider's controls, nor does completion confer any certification or compliance guarantee; findings typically require corroboration (for example, through attestations, audit reports, or independent testing). The exact number of risk domains and questions varies by release version, so practitioners should confirm the domain and question counts against the specific SIG content version in use rather than relying on a fixed figure.

Why it matters

Higher-risk third parties, particularly those that store, process, or manage highly sensitive or regulated information such as personal data, often warrant a deeper level of scrutiny than a lightweight screening can provide. SIG Core addresses this need by offering a comprehensive, industry-standard set of questions spanning multiple risk domains, giving assessing organizations a structured and repeatable way to understand how a provider manages its controls. Because it is standardized under the Shared Assessments program, it also reduces the friction of every buyer designing bespoke questionnaires and every provider answering slightly different versions of the same question.

That said, SIG Core's value is bounded by what it actually is: a self-reported information-gathering instrument. Completion does not verify that the described controls exist or operate effectively, nor does it confer any certification or compliance status. Findings typically need corroboration through attestations, independent audit reports, or direct testing before an organization can rely on them for a risk decision. Treating a completed SIG Core as evidence of assurance rather than as a starting point for validation is a common and consequential mistake.

Its usefulness is also time-bound. A SIG Core response captures a point-in-time picture that can become stale as a provider's environment, ownership, subcontractors, or control posture change. In many programs it supports both onboarding due diligence and periodic reassessment, but it is not a substitute for ongoing monitoring, and it primarily illuminates the direct third party rather than fourth-party or Nth-party dependencies further down the chain.

Who it's relevant to

Third-Party Risk and Vendor Risk Teams
These teams use SIG Core to conduct structured due diligence on higher-risk providers and to standardize how they collect control information across many vendors. They are responsible for interpreting self-reported answers, assigning risk tiers, and ensuring that questionnaire findings are corroborated with independent evidence rather than accepted at face value.
Procurement and Sourcing Professionals
Procurement teams often incorporate SIG Core into onboarding workflows for vendors that will handle sensitive or regulated data, using it to gather risk information before a contract is finalized. Understanding that a completed questionnaire is a starting point, not a certification or a guarantee of compliance, helps them set appropriate contractual and monitoring expectations.
Security and Compliance Assessors
Assessors rely on SIG Core to probe a provider's security and risk controls in depth and to identify areas that require follow-up through attestations, audit reports, or independent testing. Because domain and question counts vary by release, they need to work from the specific SIG content version in use and treat responses as claims to be validated.
Service Providers Responding to Assessments
Vendors that store or manage highly sensitive or regulated information are frequently asked to complete SIG Core as part of client due diligence and periodic reassessment. Familiarity with the questionnaire helps them respond accurately and prepare supporting evidence, while recognizing that their completed response does not by itself certify or verify their control environment.

Inside SIG Core

Standardized question set
A curated set of assessment questions maintained by Shared Assessments and drawn from the broader SIG question library. The exact count varies by annual release, so practitioners should reference the specific version in use rather than assuming a fixed number of questions.
Risk domain coverage
SIG Core is organized into a number of risk domains spanning areas such as information security, privacy, cybersecurity, business resilience, and related operational controls. The number and naming of domains change across releases, so the version-specific documentation should be consulted for the authoritative domain list.
Breadth-oriented design
SIG Core is intended to provide broad coverage across multiple risk areas for higher-risk or more critical third parties, sitting between the more targeted SIG Lite and the fully customizable SIG detailed/full library approach.
Alignment mapping
SIG content is typically mapped to recognized frameworks and regulations to support cross-referencing, though such mapping aids comparison rather than conferring certification or guaranteeing compliance with any specific regime.
Self-reported response format
The questionnaire is generally completed by the assessed third party as a self-attestation. Responses reflect what the vendor reports and do not by themselves constitute independent verification of the controls described.

Common questions

Answers to the questions practitioners most commonly ask about SIG Core.

Does completing a SIG Core questionnaire mean a vendor is certified or independently verified?
No. SIG Core is a standardized self-assessment questionnaire, so its responses are self-reported by the vendor unless separately corroborated. Completing it does not constitute a certification, an attestation validated by a third party, or independent verification of the controls described. Many programs treat SIG Core responses as a starting point that may warrant supporting evidence, on-site validation, or independent audit reports depending on the risk tier assigned to the relationship.
Is SIG Core the same as a full risk assessment of a third party?
No. SIG Core is a questionnaire that gathers information across multiple risk domains; it is an input to a risk assessment rather than the assessment itself. The assessment is the analytical process of evaluating the gathered responses against your organization's risk criteria, risk tiering, and control expectations. A completed questionnaire without that analysis does not produce a risk determination, and it typically does not by itself distinguish inherent risk from residual risk.
When should an organization use SIG Core rather than a more tailored questionnaire?
SIG Core is generally used for broader or higher-scrutiny assessments where a wide range of risk domains needs to be covered in a standardized way. In many programs, the choice depends on the vendor's risk tier: lower-risk or narrowly scoped relationships may use a more focused subset, while relationships involving sensitive data, critical services, or higher inherent risk may warrant the broader Core coverage. The appropriate scope should be driven by your risk tiering rather than applied uniformly to all vendors.
How do organizations handle the fact that a completed SIG Core is a point-in-time snapshot?
A completed questionnaire reflects the vendor's stated posture as of the date it was answered, and it can become stale as controls, personnel, subcontractors, or the threat environment change. Many programs address this by scheduling periodic reassessments, defining reassessment triggers such as material changes or incidents, and supplementing the questionnaire with ongoing monitoring. The questionnaire supports onboarding and periodic review but does not by itself provide continuous assurance between assessments.
Should responses be accepted at face value, or does supporting evidence matter?
Because responses are self-reported, many programs request supporting documentation for higher-risk domains or higher-tier vendors, such as policies, independent audit or examination reports, or other evidence, rather than relying on the answers alone. The level of corroboration typically scales with the assessed risk of the relationship. Treating questionnaire responses as claims to be validated, rather than as verified facts, helps distinguish an attestation from independent verification.
How does SIG Core fit alongside other frameworks and standards in a program?
SIG Core is often mapped to or used in conjunction with recognized frameworks and standards so that responses can be aligned to control expectations an organization already tracks. In many programs it is one component of a broader third-party risk workflow that may also incorporate contractual requirements, ongoing monitoring, and independent reports. Its coverage centers on the domains included in the questionnaire, so risks outside those domains, or risks arising beyond the direct third party such as fourth-party or Nth-party exposure, may require separate methods to address.

Common misconceptions

SIG Core has a fixed number of risk domains and questions that stays constant year to year.
The domain count and question count are revised across annual SIG releases. Citing a single figure without noting the version can be misleading; practitioners should confirm the count against the specific version they are using.
A completed SIG Core questionnaire independently verifies a third party's controls.
SIG Core is typically a self-reported attestation. It captures the vendor's own assertions and does not substitute for independent verification such as testing, on-site assessment, or a review of independent audit reports.
SIG Core covers all categories of third-party risk.
SIG Core emphasizes information security, privacy, cybersecurity, and operational resilience domains. Depending on the release it may not fully address financial, geopolitical, or ESG risk, and coverage should be checked against program needs rather than assumed to be comprehensive.

Best practices

Confirm which SIG version (release year) you are using and reference that version's documentation for the authoritative domain and question counts rather than relying on figures from prior releases.
Treat SIG Core responses as self-reported attestations and pair them with independent verification, such as review of independent audit reports or on-site validation, for higher-risk third parties.
Scope the questionnaire to the risk tier of the relationship, using SIG Core for broader coverage of more critical vendors and lighter approaches where breadth is not warranted.
Identify gaps where SIG Core's domain coverage does not extend to financial, geopolitical, or ESG risk, and supplement with additional assessments as needed.
Refresh SIG Core assessments on a defined cadence so point-in-time responses do not become stale, and trigger re-assessment on material changes in the relationship.
Use SIG's framework mappings to support cross-referencing, but do not represent a completed questionnaire as certification of or compliance with any specific regulation.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide