SIG questionnaire questions are useful only when they are scoped with judgment. Sending every question to every vendor feels thorough, but it often creates slow reviews, weak answers, and tired business owners. A better approach is to match the question set to the service, data access, business criticality, and evidence needed for a real risk decision.
This guide is written for TPRM analysts who need a practical way to scope SIG questions before sending a vendor review. It sits next to our main SIG questionnaire guide, our SIG Lite guide, and our SIG Core guide, so you can move from concept to working assessment without starting from a blank page.
What SIG Questionnaire Questions Are Trying To Do
They turn broad vendor risk into reviewable control areas
The SIG questionnaire is maintained by Shared Assessments and is used to create structured third party assessments. Shared Assessments describes the SIG Questionnaire as an Excel document created from the SIG Manager, either from a standard scoping template or a custom scoping template. Google Cloud also describes SIG as a way for organizations to build, customize, analyze, and store vendor assessments for third party risk.
They support decisions, not paperwork for its own sake
The point is not to collect a beautiful spreadsheet. The point is to decide whether the vendor can safely provide the service, whether any gaps need treatment, and whether evidence supports the answers. Good SIG scoping keeps the review tied to that decision.
How To Scope SIG Questions Before Sending Them
Start with the vendor risk rating
Shared Assessments says the SIG level should be chosen based on the depth and breadth of due diligence needed for the third party risk rating and vendor classification. That is the right starting point. A low risk vendor should not receive the same question burden as a critical vendor that stores regulated customer data or supports an important business process.
Map the service before choosing domains
Before choosing questions, write down what the vendor actually does. Note the service, the systems involved, the data types, user access, hosting model, subcontractors, geographic exposure, and business dependency. This stops the review from drifting into generic security theater.
Choose the question depth that matches the decision
Use a lighter question set when the service has limited data, limited connectivity, and low operational impact. Use a deeper question set when the vendor stores sensitive data, connects to internal systems, supports regulated activity, or could disrupt customers if it fails.
SIG Lite Questions Versus SIG Core Questions
Use SIG Lite when the review needs a practical screen
SIG Lite is useful when the vendor risk is lower and the team needs a consistent baseline. It can help analysts confirm that basic security, privacy, resilience, access, and incident controls exist before the vendor moves forward.
Use SIG Core when the vendor needs deeper review
SIG Core fits service providers that pose higher risk. That usually means sensitive data, important processes, broader system access, regulated services, or material business dependency. In those cases, the analyst needs more than short answers. Evidence review matters.
Question Areas Analysts Should Not Skip
Data handling
Ask what data the vendor receives, where it is stored, who can access it, how long it is retained, and how it is deleted. Do not accept a broad privacy statement as a substitute for the actual data path.
Access control
Ask how users are approved, how privileged access is controlled, how access is reviewed, and how leavers are removed. For vendors with customer data or internal connectivity, weak access control usually deserves follow up evidence.
Incident response
Ask how incidents are detected, who is notified, how quickly customers are informed, and whether the vendor can separate confirmed exposure from possible exposure. Recent supplier breaches keep proving that notice timing is part of real third party risk.
Subcontractors and fourth parties
Ask which subcontractors support hosting, support, analytics, customer service, payment, logistics, or data processing. A vendor answer is incomplete if a major fourth party can touch the same data or service path.
Business continuity
Ask how the vendor restores service, tests backups, handles regional outages, and prioritizes customers during disruption. The answer should match the business process you depend on, not just a generic continuity policy.
Evidence That Makes SIG Answers Useful
Look for proof, not polished language
Useful evidence may include policies, control reports, architecture diagrams, access review records, backup test results, incident procedures, vulnerability reports, penetration test summaries, encryption standards, and business continuity test records. The evidence should support the answer and fit the service being reviewed.
Ask for explanations when evidence does not match the answer
A vendor may answer yes to a control while the evidence shows a narrow or outdated process. Flag the difference politely and ask for clarification. The risk note should explain what is known, what is missing, and whether the gap changes the approval decision.
Authority CTA For Analysts
Use a template before you send the review
If you are preparing a SIG based assessment, start with the LearnTPRM vendor security questionnaire template to shape your evidence requests, then use the LearnTPRM third party risk assessment questionnaire template for broader risk context. For intake and approval notes, the LearnTPRM vendor due diligence checklist gives analysts a clean way to record what was reviewed and what still needs an owner decision.
Practical SIG Scoping Checklist
- Confirm the vendor risk rating before choosing the question depth
- Write down the service, data access, users, integrations, and business process
- Choose SIG Lite for lower risk reviews that need a baseline screen
- Choose SIG Core when the vendor stores sensitive data or supports a critical process
- Remove questions that do not match the service or risk decision
- Add custom questions only when a real risk or regulatory need is missing
- Ask for evidence for answers that affect approval or residual risk
- Track unanswered items separately from accepted risk items
- Escalate gaps that affect customer data, availability, regulatory duties, or incident notice
- Save the final scope and decision notes in the vendor file
Common Mistakes To Avoid
Sending too many questions
More questions do not automatically mean better assurance. If half the questionnaire does not apply, the vendor will rush, the reviewer will skim, and the useful issues may get buried.
Accepting yes without evidence
A yes answer is a lead, not proof. For important controls, ask for evidence that a reasonable reviewer can understand and tie back to the service.
Ignoring fourth party access
A vendor may look clean while its hosting provider, support partner, analytics tool, or fulfillment partner carries the real exposure. Scope those paths early.
Analyst Takeaway
The best SIG review is not the longest one. It is the one that asks the right questions, collects the right evidence, and gives the business a clear decision. Scope the questionnaire to the vendor risk, keep the evidence tied to the service, and use templates to make the review repeatable without making it mechanical.
FAQ
What are SIG questionnaire questions
SIG questionnaire questions are structured vendor assessment questions from Shared Assessments. They help teams review security, privacy, resilience, and related controls before or during a supplier relationship.
How should analysts choose SIG Lite or SIG Core
Shared Assessments says the choice should depend on due diligence depth, third party risk rating, and vendor classification. SIG Lite fits lower risk reviews while SIG Core fits higher risk service providers.
Should every vendor receive the same SIG questions
No. A good review is scoped to the service, data access, business criticality, regulatory exposure, and control evidence needed for a decision.
Can teams add custom SIG questions
Shared Assessments says custom questions can be added, but its FAQ warns that SIG wording itself should not be edited without written permission.
What evidence should come with SIG answers
Useful evidence may include policies, diagrams, audit reports, incident procedures, access reviews, backup test results, encryption standards, and business continuity test records.