The SIG is a large question bank organized into risk domains — information security, access control, privacy, business resilience, third-party oversight, and more — from which the assessing company issues the depth it needs. SIG Core is the comprehensive library, issued to high-risk or critical vendors; SIG Lite is the scoped-down version for lower-risk ones, and many enterprises tailor further. Which depth you receive usually mirrors your vendor tier in the customer’s program: the more data and access you hold, the more questions you answer.
Both are standardized, which is where the similarity ends. The SIG is general-purpose third-party-risk tooling: any vendor category, scalable depth, run by enterprise and financial-services risk teams as part of formal programs. The Consensus Assessments Initiative Questionnaire (CAIQ) is deliberately narrower — a fixed, cloud-focused question set from the Cloud Security Alliance for evaluating cloud service providers specifically. A SaaS company can face both in the same quarter: the SIG from a bank’s procurement machine, the CAIQ from a buyer standardizing its cloud assessments.
A full SIG response is a project — hundreds of answers that must stay consistent with your policies, your certifications, and one another, then survive re-review at renewal. The teams that stay sane maintain one answer library and reuse it across the SIG, the CAIQ, and every bespoke security questionnaire in between; the ones that improvise pay in engineer-evenings. Agency’s questionnaire service exists for exactly this: we answer from your evidence, you approve, and the deal keeps moving.