Skip to content

Evidence request lists

SIG (Shared Assessments)

Evidence request list. 31 controls, 31 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Access Control

SHAREASSESS-2
Access Control, Identity, Authentication

Per SIG: access control + identity. Vendor demonstrates strong authentication + privileged access + access reviews.

Artefacts an auditor will ask for
  • SIG evidence for SHAREASSESS-2
Where this commonly fails
  • SIG questionnaire + 4th-party partial

Cloud

SHAREASSESS-8
Cloud, SaaS, Infrastructure

Per SIG: cloud + SaaS controls.

Artefacts an auditor will ask for
  • SIG evidence for SHAREASSESS-8
Where this commonly fails
  • SIG questionnaire + 4th-party partial

Governance

SHAREASSESS-1
Information Governance and Risk

Per SIG (Shared Assessments) Standardized Information Gathering: vendor risk assessment. Requirements include (a) governance + risk management of vendors + (b) information security policies + (c) risk identification + treatment + (d) maintain SIG questionnaire responses.

Artefacts an auditor will ask for
  • SIG evidence for SHAREASSESS-1
Where this commonly fails
  • SIG questionnaire + 4th-party partial

Privacy

SHAREASSESS-7
Privacy, Compliance, GDPR Alignment

Per SIG: privacy + GDPR + compliance.

Artefacts an auditor will ask for
  • SIG evidence for SHAREASSESS-7
Where this commonly fails
  • SIG questionnaire + 4th-party partial

Resilience

SHAREASSESS-5
Incident Response, BCM, DR

Per SIG: incident response + BCM + DR.

Artefacts an auditor will ask for
  • SIG evidence for SHAREASSESS-5
Where this commonly fails
  • SIG questionnaire + 4th-party partial

SIG: Application, Network and Threat Management

SIG-I-01
Application Security

Apply secure software development lifecycle practices including secure coding standards, code review, vulnerability testing, dependency management, and pre release security gates.

Artefacts an auditor will ask for
  • Secure SDLC policy
  • Static and dynamic analysis scan reports
  • Software composition analysis results
  • Pre release sign off records
Where this commonly fails
  • No dependency scanning for open source components
  • Findings closed without retest
SIG-N-01
Network Security

Implement network segmentation, perimeter and internal firewalling, intrusion detection and prevention, secure remote access, and continuous monitoring across the production environment.

Artefacts an auditor will ask for
  • Network architecture diagrams
  • Firewall ruleset reviews
  • IDS and IPS deployment evidence
  • VPN and zero trust configuration documentation
Where this commonly fails
  • Flat network with limited segmentation
  • Firewall rules not reviewed at least annually
SIG-P-01
Threat Management

Maintain threat intelligence, vulnerability management, penetration testing, and red team capabilities to identify and remediate weaknesses in a timely manner.

Artefacts an auditor will ask for
  • Threat intelligence sources and feeds
  • Vulnerability scan reports with remediation timelines
  • Annual external penetration test report
  • Red team or purple team exercise reports
Where this commonly fails
  • Critical vulnerabilities open beyond SLA
  • Penetration test scope omits new applications

SIG: Asset, People and Physical Security

SIG-D-01
Asset and Information Management

Maintain a complete and current inventory of information assets, data classification, ownership, and handling requirements throughout the asset lifecycle.

Artefacts an auditor will ask for
  • Asset inventory with owner and classification
  • Data classification policy and labeling guide
  • Onboarding and decommissioning records
  • Data flow diagrams
Where this commonly fails
  • Inventory missing cloud assets
  • Classification labels inconsistent across systems
SIG-E-01
Human Resources Security

Implement background screening, onboarding, training, awareness, sanctions, and termination procedures appropriate to data sensitivity and role risk.

Artefacts an auditor will ask for
  • Background check policy and records
  • Annual security awareness training completion logs
  • Sanctions policy
  • Termination checklists and access removal records
Where this commonly fails
  • Contractor screening not performed
  • Awareness training completion below threshold
SIG-F-01
Physical and Environmental Security

Protect facilities and equipment from unauthorized physical access, environmental hazards, and operational disruptions through layered controls including perimeter, access management, monitoring, and environmental safeguards.

Artefacts an auditor will ask for
  • Badge access logs
  • CCTV configuration and retention policy
  • Environmental sensor readings and alarms
  • Visitor management records
Where this commonly fails
  • Tailgating not addressed by controls
  • Environmental alarm response not tested

SIG: Cloud, Mobile and Artificial Intelligence

SIG-R-01
Cloud Hosting Services

Establish controls for cloud hosted services including shared responsibility, identity federation, configuration hardening, logging, and use of cloud security posture management.

Artefacts an auditor will ask for
  • Shared responsibility model documentation per cloud provider
  • Cloud configuration baselines and benchmarks
  • CSPM tool reports
  • Identity federation configuration evidence
Where this commonly fails
  • Default cloud account configurations left in place
  • Logging not centralized across cloud accounts
SIG-S-01
Mobile Computing Security

Apply controls to mobile devices and applications used to access in scope data including device encryption, application containerization, jailbreak detection, and remote wipe capabilities.

Artefacts an auditor will ask for
  • Mobile device management policy
  • MDM and MAM configuration evidence
  • Jailbreak or root detection reports
  • Remote wipe logs
Where this commonly fails
  • BYOD devices outside MDM scope
  • No jailbreak detection enforced
SIG-U-01
Artificial Intelligence Risk Management

Govern the development, procurement, and use of artificial intelligence and machine learning systems including model risk management, data governance, transparency, bias and fairness testing, and human oversight.

Artefacts an auditor will ask for
  • AI use case inventory
  • AI risk assessment and approval records
  • Bias and fairness testing reports
  • Human oversight procedures and escalation paths
Where this commonly fails
  • Shadow AI tools used without approval
  • No documented bias testing prior to production deployment

SIG: Incident Management and Resiliency

SIG-J-01
Cybersecurity Incident Management

Maintain an incident response capability with defined plans, classifications, escalation paths, communications protocols, evidence handling, lessons learned, and regulatory and customer notification procedures.

Artefacts an auditor will ask for
  • Incident response plan and playbooks
  • Tabletop exercise reports
  • Notification templates and contact lists
  • Post incident review reports
Where this commonly fails
  • No tabletop exercises within 12 months
  • Customer notification timelines not tracked
SIG-K-01
Business Resiliency

Maintain business continuity and disaster recovery programs including business impact analysis, recovery objectives, plans, periodic testing, and dependencies on third party providers.

Artefacts an auditor will ask for
  • Business impact analysis with RTO and RPO
  • Approved BCP and DR plans
  • Annual test reports
  • Supplier dependency map
Where this commonly fails
  • RTO and RPO not validated against tested recovery
  • Critical supplier failover untested

SIG: Operations, Access and Endpoint

SIG-G-01
IT Operations Management

Document and follow operational procedures for change management, capacity management, system hardening, backup, and operational monitoring for production systems.

Artefacts an auditor will ask for
  • Operations procedure manual
  • Change advisory board minutes and tickets
  • Backup completion and restore test logs
  • Capacity reports
Where this commonly fails
  • Backup restore not tested
  • Emergency changes routinely used to bypass CAB
SIG-H-01
Access Control

Implement formal access provisioning, periodic recertification, least privilege, separation of duties, and privileged access management across systems hosting in scope data.

Artefacts an auditor will ask for
  • Access management policy
  • User access review reports
  • Privileged access management tool logs
  • Joiner mover leaver workflows
Where this commonly fails
  • Privileged accounts shared
  • User reviews completed without manager attestation
SIG-M-01
End User Device Security

Protect end user devices through configuration baselines, endpoint detection and response, encryption, mobile device management, and patch management.

Artefacts an auditor will ask for
  • Hardening baseline documents
  • EDR console coverage report
  • MDM enrollment report
  • Patch compliance reports
Where this commonly fails
  • Personal devices accessing data without MDM controls
  • EDR coverage below 95 percent
SIG-Q-01
Server Security

Apply hardened build standards, configuration management, integrity monitoring, antimalware, and logging on servers hosting in scope data and applications.

Artefacts an auditor will ask for
  • Server hardening standards aligned to CIS Benchmarks
  • Configuration management tool reports
  • File integrity monitoring alerts
  • Antimalware coverage reports
Where this commonly fails
  • Servers built outside golden image process
  • Integrity monitoring exclusions undocumented

SIG: Privacy and Supply Chain

SIG-O-01
Privacy

Manage personal data in accordance with applicable privacy laws and contractual obligations, including data subject rights, lawful basis, cross border transfers, and breach notification.

Artefacts an auditor will ask for
  • Privacy program policy
  • Data subject request handling procedure and metrics
  • Records of processing activities
  • Transfer impact assessments and standard contractual clauses
Where this commonly fails
  • No transfer impact assessment for non adequacy jurisdictions
  • DSR metrics not tracked against statutory deadlines
SIG-T-01
Supply Chain Risk Management

Manage risk across the supply chain including subservice organizations, fourth parties, hardware and software providers, and concentration risk, with appropriate due diligence and continuous monitoring.

Artefacts an auditor will ask for
  • Supplier inventory with risk tiering
  • Due diligence questionnaires and reports
  • Continuous monitoring tool outputs
  • Concentration risk analysis
Where this commonly fails
  • No fourth party visibility
  • Continuous monitoring not actioned

SIG: Questionnaire Scope and Use

SIG-CORE-01
SIG Core Coverage and Use

Use SIG Core for comprehensive due diligence covering all SIG questions across all domains, suitable for higher risk relationships and assurance level requirements.

Artefacts an auditor will ask for
  • Completed SIG Core questionnaire
  • Linked evidence library
  • Internal quality review report
  • Subject matter expert sign offs by domain
Where this commonly fails
  • Domain experts not engaged in response review
  • Evidence library out of sync with current state
SIG-LITE-01
SIG Lite Coverage and Use

Use SIG Lite for high level due diligence covering essential controls across all SIG domains where a lower assurance tier is appropriate, ensuring responses are reviewed and approved by accountable owners.

Artefacts an auditor will ask for
  • Completed SIG Lite questionnaire
  • Reviewer and approver sign off
  • Evidence attachments where requested
  • Annual refresh log
Where this commonly fails
  • Responses not refreshed annually
  • No evidence attachments supporting yes responses

SIG: Risk, Policy and Organisation

SIG-A-01
Risk Assessment and Treatment Program

Maintain a documented risk assessment and treatment program covering information security, operational, third party, and compliance risks, with defined ownership, frequency, and integration into business decision making.

Artefacts an auditor will ask for
  • Risk management policy and procedure
  • Current risk register with owners
  • Treatment plans with target dates and approvals
  • Risk committee minutes
Where this commonly fails
  • Risk register stale beyond annual cycle
  • No documented risk acceptance approvals at appropriate level
SIG-B-01
Information Security Policy Suite

Establish, approve, communicate, and periodically review a suite of information security policies that cover access control, acceptable use, data classification, encryption, vulnerability management, incident response, and supplier management.

Artefacts an auditor will ask for
  • Approved policy library with version control
  • Executive or board approval records
  • Distribution and acknowledgement logs
  • Annual review evidence
Where this commonly fails
  • Policies not reviewed annually
  • Acknowledgement coverage below 95 percent of workforce
SIG-C-01
Organizational Security and Roles

Define the security organization, governance structure, roles, segregation of duties, and reporting lines for the chief information security function and related committees.

Artefacts an auditor will ask for
  • Security org chart with reporting lines
  • Documented security roles and responsibilities
  • Information security committee charter and minutes
  • Segregation of duties matrix
Where this commonly fails
  • CISO reports into role that controls budget for security
  • No segregation of duties evidence
SIG-L-01
Compliance and Operational Risk

Identify, track, and demonstrate compliance with applicable laws, regulations, contractual obligations, and industry standards relevant to the services delivered to the client.

Artefacts an auditor will ask for
  • Compliance obligation register
  • Recent independent audit and assessment reports
  • Contract obligation tracker
  • Regulatory change monitoring procedure
Where this commonly fails
  • No central register of contractual security commitments
  • Audit findings not remediated within agreed dates

Technical Security

SHAREASSESS-3
Network Security, Endpoint, Data Protection

Per SIG: technical security including network + endpoint + data protection + encryption + DLP.

Artefacts an auditor will ask for
  • SIG evidence for SHAREASSESS-3
Where this commonly fails
  • SIG questionnaire + 4th-party partial

Third-Party

SHAREASSESS-6
Third Party / Subcontractor Management

Per SIG: subcontractor + 4th-party management.

Artefacts an auditor will ask for
  • SIG evidence for SHAREASSESS-6
Where this commonly fails
  • SIG questionnaire + 4th-party partial

Vulnerability and AppSec

SHAREASSESS-4
Vulnerability Management, Patching, Application Security

Per SIG: vulnerability management + patching + app security + secure SDLC.

Artefacts an auditor will ask for
  • SIG evidence for SHAREASSESS-4
Where this commonly fails
  • SIG questionnaire + 4th-party partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the SIG (Shared Assessments) framework page.