Due diligence questionnaire (DDQ)
A due diligence questionnaire (DDQ) is a structured document, typically 100 to 200 questions, that one organization sends to another to assess risk before a formal relationship begins: a vendor contract, an investment, or an acquisition. The party being assessed fills it out, section by section, across company background, financial health, legal and compliance standing, information security, operational continuity, and ESG. The party that sent it reads the answers, and the evidence attached to them, to decide whether the risk is acceptable.Who sends due diligence questionnaires
DDQs travel in one direction: from the party assessing risk to the party being assessed. Four groups send almost all of them, and what they ask for differs enough that a single canned answer library rarely survives all four.Institutional investors and limited partners
- When it arrives
- Fund manager and GP assessments before capital is committed.
- What it asks for
- Investment strategy, team background, performance attribution, fee structures, risk controls, and ESG policy. The ILPA template published by the Institutional Limited Partners Association is the reference framework in private equity.
Enterprise procurement and vendor risk teams
- When it arrives
- Vendor onboarding reviews before a SaaS contract is signed.
- What it asks for
- Security controls, certifications, subprocessors, business continuity, and data handling, plus company and financial background. These are the DDQs a B2B SaaS seller sees most, and they repeat on a renewal cadence as part of third-party risk management.
Acquirers and their legal teams
- When it arrives
- M&A due diligence on an acquisition target.
- What it asks for
- Legal liabilities, pending litigation, intellectual property ownership, contract obligations, and financial exposure. Longer than a vendor DDQ, because the capital at stake is larger.
Regulated-industry buyers
- When it arrives
- Standalone cybersecurity DDQs in finance and healthcare.
- What it asks for
- Deep control-level questions mapped to a framework, plus sector obligations: HIPAA controls and business associate agreements in healthcare, regulatory standing in finance.
DDQ vs security questionnaire vs RFP
These three get conflated constantly, and answering one like another is the fastest way to signal that your team does not understand what the reviewer needs. The simplest test: if a buyer sends 150 questions about SOC 2, subprocessors, and data retention, that is a security questionnaire. If the same document also asks about your financials and your litigation history, that is a DDQ.RFP
Sent by Procurement- Primary focus
- Vendor selection
- Where it lands in the deal
- Early, while several vendors are still in play. Forward-looking and competitive: what can you do, and what does it cost.
Security questionnaire
Sent by Security or IT- Primary focus
- Cybersecurity controls
- Where it lands in the deal
- After a shortlist, narrow by design. Encryption, access management, incident response, certifications, subprocessors. Nothing about your balance sheet.
DDQ
Sent by Legal, compliance, investors- Primary focus
- Full risk assessment
- Where it lands in the deal
- Before signature or before capital moves. Security is one section among finance, legal history, operations, and compliance.
The sections a DDQ covers
Templates vary by sender and industry, but the shape is stable. What unites every section is documentation: claiming a control exists without attaching the artifact that proves it invites a follow-up round and adds weeks to the review.Company background
Ownership structure, leadership team, years in operation, subsidiary and parent relationships.Evidence expected: Corporate registration, org chart, cap table summary.Financial health
Revenue, audited statements, debt obligations, insurance coverage, bankruptcy history.Evidence expected: Audited financial statements, certificates of insurance.Legal and compliance
Pending litigation, regulatory violations in recent years, data privacy posture under GDPR and sector rules.Evidence expected: Privacy policy, DPA, regulatory filings, counsel attestation.Information security
Access management, encryption at rest and in transit, incident response SLAs, penetration testing cadence, subprocessors.Evidence expected: SOC 2 Type II report, ISO 27001 certificate, penetration test summary, security policies.Operational continuity
Business continuity plan, disaster recovery objectives, backup verification, vendor dependencies.Evidence expected: BCP and DR plan documents, evidence of the last tested restore.ESG
Environmental practices, labor and supply chain ethics, diversity commitments, governance.Evidence expected: Published ESG or code-of-conduct policy, supplier standards.How to answer a due diligence questionnaire
The work that actually consumes the hours is not the hard questions. It is re-answering questions you have already answered, in a format you have not seen before. Six steps, in order.- Read the whole document before answering anything. Find the sections that are not yours (the finance rows, the legal history, the insurance certificates) and route them to their owners on day one, because those are the answers that arrive last.
- Answer from your current documentation, not from a past submission. A response written before your last SOC 2 audit, an infrastructure migration, or a policy revision is a factual mismatch waiting to be caught, and a caught mismatch buys you another review round.
- Attach the evidence with the answer. A claim that a control exists, with no policy, certificate, or report behind it, generates a follow-up request every single time.
- Keep one owner per questionnaire. Two people answering different tabs from different memories is how the same company reports two different data retention periods in one document.
- Say so when the answer is no. A documented compensating control reads better to a reviewer than a hedge, and far better than a claim that unravels in the follow-up call.
- Reuse the answer, not the file. The same questions come back from the next buyer in a different format, so what you want to carry forward is a reviewed answer and its source, not the spreadsheet you filled in last quarter.