SIG Core vs. SIG Lite vs. CAIQ: Choosing the Right Vendor Questionnaire
A practical guide to matching standardized security questionnaires — SIG Core, SIG Lite, CAIQ, or custom — to vendor tier, data sensitivity, and regulatory scope. Every third party risk program eventually faces the same question: which questionnaire do we send? Choose one that's too deep and you'll drown your vendors — and your analysts — in hundreds of answers nobody reads. Choose one that's too shallow and you'll approve a critical vendor on the strength of a checkbox exercise. The good news is that the industry has largely converged on a small set of standardized questionnaires, and the decision usually comes down to two factors: the vendor's inherent risk and the type of service they provide. SIG Core: depth for the vendors that matter most SIG Core is the comprehensive version of Shared Assessments' Standardized Information Gathering questionnaire. It covers the full breadth of risk domains — access control, incident management, resilience, privacy, physical security, and more — and it exists for one purpose: deep due diligence on the vendors whose failure would genuinely hurt you. Use SIG Core when a vendor processes sensitive data at scale, holds privileged access to your environment, or underpins a business function you cannot easily replace. The cost is real — completing it takes vendors significant effort — so reserve it for relati