A SIG Lite or CAIQ response sheet lands in a security team's inbox and the reflex is to start at row one and answer every question from scratch. Most rows do not need a fresh answer. A SOC 2 Type II report, an ISO 27001 certificate, a HIPAA badge, an active Data Privacy Framework listing and a public subprocessor list already cover a large share of the standard question families in both forms, and each carries a date so a reviewer can check whether it is still current rather than trusting a checkbox. This piece maps the recurring SIG Lite and CAIQ domains, governance, access control, business continuity, privacy, third-party management, to the specific evidence row that answers each one, and shows where running a whole vendor list through a bulk vendor security check saves the most reviewer time.
What SIG Lite and CAIQ actually ask
SIG Lite is Shared Assessments' condensed Standardized Information Gathering questionnaire. It groups questions into domains such as information security policy, asset and information management, human resources security, physical and environmental security, IT operations, access control, application security, third-party management, incident event and communications management, business resiliency, compliance and privacy. CAIQ, the Consensus Assessments Initiative Questionnaire, is the Cloud Security Alliance's equivalent, written for cloud services and tied to the CSA STAR registry. The domains overlap heavily with SIG Lite. Neither form asks a vendor to invent new controls for the exercise. Both ask the vendor to describe controls that, if the vendor holds a current report or certificate, are already documented, dated and in most cases public.
The CAIQ asks a cloud provider to document, in a standard format, which security controls it already has in place, so a customer is not left writing a bespoke questionnaire for every vendor.
| Questionnaire domain | Typical row | Evidence that already answers it |
|---|---|---|
| Governance and risk | Is there a board-approved information security policy? | SOC 2 Type II report or ISO 27001 certificate scope statement |
| Access control | Is multi-factor authentication enforced for privileged accounts? | SOC 2 Type II control testing (CC6 series) or ISO 27001 Annex A controls |
| Business resiliency | Is the disaster recovery plan tested at least annually? | SOC 2 Type II availability criterion or ISO 22301 certificate |
| Third-party and subprocessor management | Is there a current list of subprocessors and their locations? | Public subprocessor list |
| Privacy and cross-border transfer | What legal mechanism covers EU-US data transfer? | Active Data Privacy Framework listing |
| Healthcare data handling | Will the vendor sign a Business Associate Agreement? | HIPAA badge, checked against whether a BAA has actually been captured |
| Payment data | Is the service validated under PCI DSS? | Entry in the Visa Global Registry with a validity date |
| AI and model governance | Is there a management system for AI risk? | ISO 42001 certificate |
Recurring SIG Lite and CAIQ domains mapped to the public evidence row that answers them.
Access control and encryption rows
Access control domains ask variations of the same question: is access provisioned on a documented request, reviewed periodically, and revoked on termination, with multi-factor authentication on privileged and remote access. A SOC 2 Type II report tests exactly this, over a review period stated on the cover page, not a single point in time. That distinction matters because a Type I report only confirms controls were designed, not that they operated. ISO 27001 covers the same ground through Annex A controls, listed against the certificate's scope statement rather than tested over a period. Neither document proves a vendor is "SOC 2 certified": SOC 2 is a report an auditor issues, not a certification a vendor holds, and a reviewer who sees that phrase on a vendor's site should treat it as a sign the marketing copy has drifted from the underlying evidence.
Business continuity and incident response rows
SIG Lite's business resiliency domain and CAIQ's equivalent both ask whether a disaster recovery plan exists, whether it has been tested in the last year, and what the target recovery time is. A SOC 2 Type II report scoped to the availability criterion covers testing cadence. An ISO 22301 certificate covers the management system behind it. Incident response rows, notification timelines, a named incident response team, follow the same pattern: the evidence is either in the SOC 2 report's control descriptions or absent, in which case the row genuinely needs a live answer rather than an inference from a badge.
- 19
- Frameworks on one trust centre
- Zoom lists nineteen frameworks including FedRAMP, GovRAMP, TX-RAMP, C5, IRAP and ISMAP, in the CertReports index on 2026-09-26.
- 26
- Subprocessors disclosed on one page
- Notion and 8x8 each publish a subprocessor list naming twenty-six entities, in the CertReports index on 2026-09-26.
- 11
- Frameworks on a single Vanta trust centre
- Intercom's trust centre lists eleven frameworks, in the CertReports index on 2026-09-26.
Data privacy and cross-border transfer rows
Privacy domains ask what legal mechanism covers a transfer of personal data out of the EU or UK, whether a data processing agreement is available, and who the subprocessors are. An active Data Privacy Framework listing answers the transfer mechanism row directly, provided the listing is still active rather than lapsed. A public subprocessor list answers the subprocessor row, though a reviewer still has to check the list is current rather than a static page from the vendor's last funding round.
Intercom's trust centre is a useful example of how many of these rows sit on one page. Look at the DPF row for the transfer mechanism, the subprocessor list for the third-party row, and the HIPAA badge for the healthcare row, then check whether a Business Associate Agreement has actually been captured rather than assumed from the badge.

Intercom · Trust report
Customer support · Public evidence as of 29 Sep 2026
Framework overview
CertReports state for each framework with public evidence: 1 verified, 10 vendor-stated.
DPFVerifiedValid to 14 Nov 2026HIPAAVendor-statedBadge only, BAA not captured
SOC 2Vendor-statedTrust centre · 29 Sep 2026GDPRVendor-statedTrust centre · 29 Sep 2026
ISO 27001Vendor-statedTrust centre · 29 Sep 2026CSA STARVendor-statedTrust centre · 29 Sep 2026
ISO 27701Vendor-statedTrust centre · 29 Sep 2026
ISO 42001Vendor-statedTrust centre · 29 Sep 2026
ISO 27018Vendor-statedTrust centre · 29 Sep 2026
2Documents and agreements
Legal and review documents Intercom publishes or offers, as of 29 Sep 2026.
- Subprocessor list · Public
- Privacy policy · Public
1Security practices
Public statements from Intercom, shown as statements, not attestations, as of 29 Sep 2026.
- Penetration testing · annual
14Subprocessors
Named on Intercom's public subprocessor list, last seen 29 Sep 2026.
Ably
Amazon Web Services, Inc.
Anthropic, PBC- CACartesia AI, Inc.
Cloudflare, Inc.
Eleven Labs, Inc.
Google
Mailgun Technologies, LLC- and 6 more on the evidence page
Healthcare-specific rows: HIPAA and the BAA
Every SIG Lite and CAIQ sheet aimed at a vendor touching health data asks some version of 'will you sign a BAA'. HIPAA has no certificate and no certifying body, so a badge on a trust centre only ever means the vendor is willing to support HIPAA-regulated customers, not that a Business Associate Agreement exists for this specific relationship. Writing "HIPAA certified" as a settled fact is the same error as writing "SOC 2 certified": HIPAA compliance is a status between two named parties under a signed BAA, not a badge a vendor earns once. The BAA checklist covers what to confirm before sending protected health information to a vendor, and it is the one row on this domain that public evidence alone cannot close.
What a badge does not prove
A HIPAA badge, a SOC 2 mention or a DPF logo on a trust centre confirms the vendor is registered or reports against a framework. It does not confirm the specific control was tested this quarter, or that a BAA was signed for your account. Check the date on the underlying document, not the badge.
Payment and government-sector rows: PCI DSS and FedRAMP
Payment data rows ask whether the service is validated under PCI DSS, and the only place that validation is reliably recorded is a card network's own registry, such as the Visa Global Registry, which states a validity date rather than a permanent status. Government or public-sector rows ask about FedRAMP. Since 4 July 2026, under the Consolidated Rules for 2026, the current label is "FedRAMP Certified"; "Ready" became a legacy status on 28 July 2026 and no longer describes an active authorisation path. A questionnaire row that still asks whether a vendor is FedRAMP Ready is asking about a status that has already changed, and FedRAMP in 2026 explains what replaced it.
How to pre-fill a SIG Lite or CAIQ sheet from public evidence
- 1
List the vendor's stated frameworks
Pull every framework the vendor states publicly, with the report type and date, before opening the questionnaire template.
- 2
Match domains to evidence types
Use a mapping like the table above to sort rows into 'answered by a dated document' and 'needs a live answer'.
- 3
Check the date, not the badge
A SOC 2 report, ISO certificate or DPF listing is only useful if it is current; check the period end date or the registry's own status field.
- 4
Flag the rows evidence cannot reach
BAAs, specific penetration test scopes, and internal exception processes are rarely public. Mark these for a live answer rather than guessing from a badge.
- 5
Run the whole vendor list at once
Applying this mapping across a full vendor register in one pass is faster than repeating the exercise per contract renewal.
What the public record cannot answer
A trust centre or registry entry is strong on scope and dates and weak on anything specific to your relationship with the vendor. It will not tell you whether a BAA has been signed for your account, whether a specific exception was granted to a control during the audit period, or how the vendor would handle a breach notification clause you are trying to negotiate. Reading a trust centre properly means treating it as a fast first pass that answers perhaps half the rows on a SIG Lite sheet, not a substitute for the vendor-specific rows a live contact still has to answer. Teams reviewing more than a handful of vendors a quarter tend to find that lining candidates up on the compare vendors side by side view, next to the mapping above, cuts the first renewal cycle down faster than working the sheet vendor by vendor.
People also ask
What questions are in a vendor security questionnaire?
Most questionnaires, including SIG Lite and CAIQ, group questions into recurring domains: information security governance, human resources security, access control, application security, encryption, physical security, business continuity and disaster recovery, incident response, third-party and subprocessor management, privacy and cross-border data transfer, and specific rows for regulated data such as health records or payment cards. The exact wording varies by template, but the domains repeat across almost every vendor risk programme.
What is SIG Lite?
SIG Lite is Shared Assessments' condensed version of the Standardized Information Gathering questionnaire. It covers the same domains as the full SIG at a higher level, with fewer, broader questions, and is typically used for lower-risk vendors or as a first-pass triage before a fuller review. Many of its rows can be answered directly from a vendor's SOC 2 report, ISO 27001 certificate, or trust centre disclosures rather than requiring a fresh written response.
How long does a security questionnaire take?
It depends on how much of the answer set already exists as public evidence. A vendor with a current SOC 2 report, an active DPF listing and a maintained trust centre can have most rows answered in a day or two by matching questions to those documents. A vendor with no public evidence requires a written response for every row, which typically takes the vendor's security team one to several weeks depending on internal review.
Can a trust centre replace a questionnaire?
No. A trust centre answers the rows that map to dated, published evidence: framework badges, certificate scope, subprocessor lists and privacy transfer mechanisms. It does not confirm vendor-specific items such as a signed Business Associate Agreement for your account, a negotiated breach notification clause, or an exception granted during an audit period. Treat it as a fast first pass, then send the remaining rows as a shorter, targeted questionnaire.
Solomon Amos · Founder, CertReports
Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.
Read next on CertReports
You might also like
The BAA checklist: what to check before sending PHI to a vendor
Solomon Amos · 9 Sep 2026 · 11 min read
The EU-US Data Privacy Framework, explained for vendor reviews
Solomon Amos · 7 Sep 2026 · 10 min read