Breakdown · Third-party risk
Vendor questionnaires: answer once, reuse
The SIG from Shared Assessments and the CAIQ from the Cloud Security Alliance: what they ask, and how to build one evidence base that answers both.
By Sentrix · Published 2026-09-20
Every new customer sends its security questionnaire, and every questionnaire looks like the previous one without being identical to it. The teams that answer by hand spend weeks a year on it. Two standardized questionnaires dominate the market, and understanding their structure makes it possible to answer once and reuse.
What the sources say
The SIG (Standardized Information Gathering) is published by Shared Assessments. According to the scoping guide for the 2024 edition, the SIG Lite is a set of program-level questions designed for lower-risk third parties, also useful as a preliminary assessment; the SIG Core offers a deeper scope for medium to high-risk third parties, with questions at the control definition level, and is typically used to assess organizations that store or manage highly sensitive or regulated data, or critical services. A custom SIG can be scoped by risk domain, by reference to a standard or a regulation, or by control family, with three scope levels: Lite, Core and Detail. The choice must align with the inherent risk calculation of the third party being assessed.
The CAIQ (Consensus Assessments Initiative Questionnaire) is published by the Cloud Security Alliance (CSA). According to the announcement of version 4 in June 2021, it has 261 questions, aligned with the Cloud Controls Matrix (CCM) version 4 and its 17 domains and 197 controls; answers are yes, no or not applicable, and a section on the shared security responsibility model states, for each control, whether the provider or the customer implements it. A completed CAIQ can be submitted to the CSA STAR registry at Level 1 (self-assessment); Level 2 corresponds to a third-party audit, a SOC 2 attestation or an ISO/IEC 27001 certification.
Both publishers present their questionnaire the same way: a common language so that the vendor answers once and the buyer stops sending its own form.
Why it matters
A questionnaire is a projection: every question asks, in a different form, for proof that a control exists. The SIG and the CAIQ project the same set of controls (identity, encryption, logging, continuity, incident management, fourth parties) onto two grids. A customer's in-house questionnaire does the same thing onto a third.
Answering question by question means translating again every time. Answering from a base of documented controls means matching a question to a control already proven, then attaching the evidence.
The cost of the manual approach is not only time. It is inconsistency: two different answers to the same question, at two customers, six months apart, because two people answered. An attentive buyer compares them.
What we think at Sentrix
The evidence base that answers the SIG, the CAIQ and in-house questionnaires is built in a season, and then maintained with the annual audit.
- Choose a pivot framework, usually ISO 27001:2022 or the SOC 2 trust services criteria, and attach every implemented control to it with its owner and its evidence.
- Fill in the CAIQ v4 once and a SIG Core starting from the pivot: each question gets the control reference and the evidence excerpt, not a sentence written for the occasion.
- Publish what can be published: a CAIQ on the STAR registry (Level 1) and a trust center answer a good share of requests in advance.
- Keep a versioned answer library, with the date of last validation and the validator's name, so that an answer does not outlive the control it describes.
- Answer in-house questionnaires by mapping: each question points to an existing SIG or CAIQ answer; only genuinely new questions get written, and they go into the library.
- Feed the gaps back into the risk treatment plan: a question you answer "no" to at three customers in a row is a gap, not a wording issue.
On the buyer side, the discipline is the same: a questionnaire aligned with the SIG or the CAIQ, chosen according to the vendor's inherent risk, a SIG Lite for a low-risk vendor and a SIG Core or a full CAIQ for the one that handles your sensitive data. The third-party risk module of the Sentrix platform keeps these answers with the evidence and the revalidation reminders.
For ISO 27001:2022, this program covers controls 5.19 to 5.22 (supplier relationships and monitoring of supplier services); for SOC 2, criterion CC9.2; for DORA, the register of information on ICT providers. See the SOC 2 and DORA framework pages.
The next step
Pull out the last three questionnaires you received and count the questions you answered differently. That number is the measure of your debt; the answer library starts with those questions.
Sources
Frequently asked questions
- What is the difference between the SIG and the CAIQ?
- The SIG, published by Shared Assessments, is a general third-party risk questionnaire offered in several scopes (Lite, Core, Detail) and sliceable by risk domain or by reference standard. The CAIQ, published by the Cloud Security Alliance, is specific to cloud services: its 261 questions in version 4 follow the Cloud Controls Matrix and are answered yes, no or not applicable, with a shared responsibility column. A SaaS vendor often receives both.
- Should we publish our CAIQ to the STAR registry?
- If you sell a cloud service, yes, at Level 1: it is a public self-assessment that answers in advance the buyers who use the CAIQ and makes your answers comparable from one year to the next. Level 2 adds a third-party audit based on SOC 2 or ISO/IEC 27001; it makes sense when you already hold one of those attestations and your customers are in regulated sectors.
- How do we avoid answering differently from one customer to the next?
- By answering from a library of answers tied to controls, not from the question. Each answer carries the control reference, the evidence excerpt, the validation date and the validator's name. A customer's questionnaire is then handled by mapping: most questions point to an existing answer, and only the new questions are written, then added to the library.
Let's talk about your compliance program.
Last updated: 2026-09-20
