
The questionnaire you choose determines what you can learn, how long you wait to learn it, and how much goodwill you burn with the vendor answering it. SIG, CAIQ, and custom instruments are not interchangeable options on a dropdown. They are different tools with different coverage, different lengths, and different completion economics, and the right answer changes by vendor tier and by what the vendor touches.
What each instrument actually is
SIG (Standardized Information Gathering)
Maintained by Shared Assessments and updated annually, the SIG is the broadest general-purpose instrument in common use. It spans roughly 19 to 21 risk domains depending on the release year, reaching well beyond information security into privacy, business resilience, ESG, and supply chain risk. It ships in two scopes: SIG Core, a comprehensive bank that can run to many hundreds of questions, and SIG Lite, a condensed subset of a few hundred designed for lower-risk relationships. Because it is scoping-based, you select the domains relevant to the engagement rather than sending the whole bank.
CAIQ (Consensus Assessment Initiative Questionnaire)
Maintained by the Cloud Security Alliance, the CAIQ is purpose-built to assess cloud service providers against the CSA Cloud Controls Matrix (CCM). CAIQ v4 runs to roughly 260 yes/no questions mapped directly to CCM control IDs. Its defining advantage is the STAR Registry: many cloud providers publish a completed CAIQ publicly, which means for some vendors the assessment is a download, not a request. Its defining limit is scope: it interrogates cloud service security deeply and says little about the vendor's broader corporate governance, physical operations, or non-cloud services.
Custom questionnaires
A custom instrument asks exactly what you need to know and nothing else. That precision is its strength: you can encode your contractual requirements, your specific regulatory obligations, and the exact controls your risk acceptance depends on. Its costs are real: you own the authoring, the framework mapping, the answer-quality rubric, and the maintenance forever, and vendors cannot reuse a prior response, which slows completion. The disciplined use of custom content is as a supplement: a 20 to 40 question module layered onto a standard instrument, covering what the standard cannot.
Coverage, length, and completion tradeoffs
| Dimension | SIG Core | SIG Lite | CAIQ | Custom |
|---|---|---|---|---|
| Scope | Broadest: security, privacy, resilience, and beyond | Same domains, reduced depth | Cloud service security, deep but narrow | Whatever you write |
| Typical length | Several hundred to 800+ questions (scoped) | Roughly 150 to 350 | Roughly 260 yes/no | You decide; discipline required |
| Vendor familiarity | High among mature vendors | High | Very high among cloud providers; often pre-published | None; every answer is new work |
| Typical turnaround | Weeks to a month or more | One to three weeks | Days if pre-published, else two to three weeks | Highly variable; longest per question |
| Framework mapping | Cross-referenced to major frameworks by the maintainer | Same | Native to CCM; CSA publishes mappings outward | You build and maintain it |
| Best at | Deep diligence on critical, complex vendors | Proportionate diligence at scale | Cloud/SaaS providers | Regulatory specifics, contract-specific controls |
The completion-rate economics deserve emphasis because they drive real program outcomes. Response effort scales worse than linearly with question count: as an illustrative rule of thumb, doubling questionnaire length more than doubles turnaround time and measurably increases the share of low-effort answers. A shorter standard instrument that vendors have answered before will beat a longer bespoke one on both speed and answer quality in most engagements. This is also one of the fastest ways to streamline vendor risk assessments for your own team, since familiar instruments generate fewer clarification cycles.
Mapping to frameworks
If your program reports against SOC 2, ISO 27001, NIST CSF, or sector rules, the questionnaire is only useful insofar as answers land on your control framework. Three practical notes:
- The SIG's maintainer cross-references it to a wide set of frameworks and regulations, which lets one vendor response feed multiple compliance narratives.
- The CAIQ maps natively to the CCM, and CSA maintains outward mappings from CCM to ISO 27001, NIST, and others. For cloud vendors this chain is usually sufficient.
- Custom questions are unmapped until you map them. A custom question without a framework mapping and a scoring rubric is an opinion collector. If you cannot say which control a question serves, cut the question.
The selection decision table
Choose the instrument with two inputs: the vendor's tier from your vendor tiering framework, and the nature of the data or access involved.
| Vendor situation | Recommended instrument | Rationale |
|---|---|---|
| Tier 1, handles regulated or sensitive data, complex services | SIG Core (scoped) + custom supplement | Breadth for the relationship, custom module for your regulatory and contractual specifics |
| Tier 1 cloud/SaaS provider hosting your data | CAIQ + custom supplement (+ SIG domains for non-cloud concerns) | Deep cloud coverage, often pre-published; supplement covers governance and your specifics |
| Tier 2, meaningful data access, standard services | SIG Lite, or CAIQ if cloud-native | Proportionate depth, high familiarity, fast turnaround |
| Tier 2 cloud tool, limited data sensitivity | Published CAIQ from the STAR Registry, reviewed not re-requested | Assurance at near-zero vendor effort |
| Tier 3, no sensitive data, no system access | Short custom screener (15 to 30 questions) or attestation + certificate evidence | A full instrument here is cost without risk reduction |
| Any tier, post-incident targeted reassessment | Custom, scoped to the failed and adjacent control domains | Standard instruments are the wrong shape for event-driven depth |
Two overrides trump the table. First, if the vendor holds privileged access into your environment, treat them one tier higher than their spend or category suggests. Second, if a current certification with a mapped report (such as an independent audit report) covers a domain, accept the artifact and skip those questions; asking a vendor to hand-answer what an auditor already verified is pure friction.
Running a mixed portfolio without chaos
Most programs land on a mix: SIG-based instruments for critical vendors, CAIQ for cloud providers, short custom screeners at the low end. The operational risk of a mixed portfolio is inconsistency in how answers become scores and decisions. Guard against it with three rules: normalize every instrument's answers onto one internal control framework, apply one scoring methodology across instruments, and record which instrument and version each assessment used so year-over-year comparisons are honest. Assessment platforms handle this normalization layer for you; ThirdSentry, for instance, runs SIG, CAIQ, and custom questionnaires through the same assessment and scoring workflow so a mixed portfolio still produces comparable vendor decisions.
For where questionnaire selection sits in the overall program, see the TPRM program guide.
The bottom line
SIG buys breadth and familiarity, CAIQ buys cloud depth and pre-published speed, custom buys precision at a permanent maintenance cost. Choose by tier and data access, supplement rather than replace, and never send a question you cannot map to a control and a scoring rule. ThirdSentry supports all three instrument types on one assessment engine, which is what makes a proportionate, mixed-instrument program practical to actually run.

