Article

SIG, CAIQ and bespoke forms

Know what you have been sent, and how each format should be filled out.

The whole vendor risk assessment process can be summed up as a predictable three-step cycle of corporate grief.

You start by letting out a heavy SIGh at the enormous enterprise spreadsheet. Then you realise that auditing your cloud architecture is no piece of CAIQ. Finally, you end up thoroughly Be-spooked by a custom form written by a client who still prints out their emails.

In the end it does not matter whether the form is standardised or built by hand. You are either drowning in a sea of cells or lost somewhere in the cloud.

Why you are being asked at all

When a company hires your business, they often give you access to their internal data, their networks, or their customers' details. If your systems are breached, the client carries the financial, legal, and regulatory fallout.

Because of that, a client cannot simply take your word that your security is sound. Their security or compliance team has to check how you operate before signing. This is Third-Party Risk Management. The questionnaire is the tool they use to review your homework, find gaps, and show their own regulators that they took care over who they let near their data.

When you are asked to fill one out, it will usually take one of three shapes. Here is how to handle each.

1. The SIG (Standardised Information Gathering)

The SIG is a large questionnaire maintained by an organisation called Shared Assessments. It has been around for years and covers almost every corporate risk domain you can think of, from physical building security to staff background checks.

Who uses it: global retail banks, major insurers, and large healthcare networks. These organisations have thousands of vendors, and the SIG gives them a strict, repeatable template for scoring everyone the same way.

The structural logic: the SIG runs on parent-child logic. Answer "No" to a main question and the next several sub-questions may grey out automatically, because they no longer apply to you. Because the format is so structured, the responses are often processed and checked by software, which means inconsistent or contradictory answers across the form tend to get flagged before a person ever looks at them.

How to fill it: use the dropdown menus exactly as provided, usually Yes, No, or N/A. Do not leave the comment columns empty. If you answer "No" or "N/A" to a control, use the comment box to set out what you do instead, drawing on what your own policies actually say.

2. The CAIQ (Consensus Assessments Initiative Questionnaire)

Created by the Cloud Security Alliance, the CAIQ is built specifically for cloud-based services such as SaaS platforms, software tools, and hosting. Like the SIG, it is a well-established format that has been in circulation for years.

Who uses it: technology companies buying software, cloud-first startups, and enterprise IT teams assessing a new web application. If your service lives in the cloud, this is the form you are most likely to see.

The structural logic: the CAIQ leans heavily on cloud architecture. The questions look at how you separate one client's data from another's, how you manage encryption keys, and how you secure your cloud environment.

How to fill it: these questions are written to draw out a binary answer. Stick to a clear Yes or No wherever you can, and keep the supporting text short. The standardised, structured nature of the CAIQ also makes it easy to run through automated checks, so vague or inconsistent answers stand out quickly. If you complete the CAIQ regularly, it can form the basis of a public self-assessment on the Cloud Security Alliance STAR registry, subject to their submission requirements.

3. Bespoke or custom forms

These are questionnaires built from scratch by a client's own procurement, legal, or security team.

Who uses it: universities, local government, and mid-sized regional businesses. These organisations often do not have the budget for vendor risk software, so they write their own forms, usually focused on specific local regulations or on a security scare they have lived through.

The structural logic: there is none to speak of. These forms tend to be a mix of old compliance checklists, generic IT questions, and a few queries prompted by whatever cyberattack was in the news recently.

How to fill it: these are the unpredictable ones. Because they are non-standard, they are usually read by a person rather than processed by software, and often by someone who is not a security specialist. That cuts both ways: there is more room for a sensible narrative answer, but also more room for a vaguely worded question to lead you astray. The trap is letting a badly worded question push you into a careless answer. If a client asks something casual like "Is your office network safe?", work out the control they are really asking about (network and wireless security), then answer that control from what your documentation actually says about it. Translate the vague question into the proper one, but answer it from your evidence, not from whatever sounds impressive. An answer you cannot support is one you do not want on record.

Quick reference

Format Typical client Best answering strategy
SIG Global banks, enterprise firms, healthcare networks Follow the spreadsheet structure. Use the dropdowns exactly as intended.
CAIQ Tech buyers, SaaS platforms, cloud software users Give direct, binary answers about your cloud setup.
Bespoke Local government, universities, mid-sized firms Write natural narrative answers. Map their vague questions to your formal policies.

The point underneath all three

Look at what you just read. Three formats, three different logics, three different ways of asking. The SIG wants dropdowns and parent-child branches. The CAIQ wants binary cloud answers. The bespoke form wants whatever its author woke up thinking about. This is exactly why a saved library of past answers does not solve the problem: the questions seldom line up from one form to the next, so a stored answer is usually the wrong shape for the next question that lands.

The thing that does carry across every format is your underlying documentation. Your policies and standards do not change because a prospect chose a different spreadsheet. So the reliable way to answer any of these is to start from your own evidence and write each answer to the question in front of you, in the shape that question expects.

These formats are not going anywhere. The SIG and the CAIQ are entrenched in how large organisations buy, and bespoke forms will keep appearing for as long as someone in procurement has a blank document and a deadline. The forms themselves stay much the same year to year, even as the checking around them gets more automated. That combination, old static forms read by increasingly capable software, is exactly why a thin or inconsistent answer is more likely to get caught than it used to be, and why answering from real evidence is the safe approach rather than the optional one.

May your future spreadsheets be short, your cloud controls cleanly binary, and your clients blissfully free of custom Word documents.

Or you can upload your documents above, and we will answer the questionnaire from your evidence, whichever format it turns up in.