Due diligence questionnaire (DDQ)

A due diligence questionnaire (DDQ) is a structured document, typically 100 to 200 questions, that one organization sends to another to assess risk before a formal relationship begins: a vendor contract, an investment, or an acquisition. The party being assessed fills it out, section by section, across company background, financial health, legal and compliance standing, information security, operational continuity, and ESG. The party that sent it reads the answers, and the evidence attached to them, to decide whether the risk is acceptable.

Who sends due diligence questionnaires

DDQs travel in one direction: from the party assessing risk to the party being assessed. Four groups send almost all of them, and what they ask for differs enough that a single canned answer library rarely survives all four.

Institutional investors and limited partners

When it arrives
Fund manager and GP assessments before capital is committed.
What it asks for
Investment strategy, team background, performance attribution, fee structures, risk controls, and ESG policy. The ILPA template published by the Institutional Limited Partners Association is the reference framework in private equity.

Enterprise procurement and vendor risk teams

When it arrives
Vendor onboarding reviews before a SaaS contract is signed.
What it asks for
Security controls, certifications, subprocessors, business continuity, and data handling, plus company and financial background. These are the DDQs a B2B SaaS seller sees most, and they repeat on a renewal cadence as part of third-party risk management.

Acquirers and their legal teams

When it arrives
M&A due diligence on an acquisition target.
What it asks for
Legal liabilities, pending litigation, intellectual property ownership, contract obligations, and financial exposure. Longer than a vendor DDQ, because the capital at stake is larger.

Regulated-industry buyers

When it arrives
Standalone cybersecurity DDQs in finance and healthcare.
What it asks for
Deep control-level questions mapped to a framework, plus sector obligations: HIPAA controls and business associate agreements in healthcare, regulatory standing in finance.

DDQ vs security questionnaire vs RFP

These three get conflated constantly, and answering one like another is the fastest way to signal that your team does not understand what the reviewer needs. The simplest test: if a buyer sends 150 questions about SOC 2, subprocessors, and data retention, that is a security questionnaire. If the same document also asks about your financials and your litigation history, that is a DDQ.

RFP

Sent by Procurement
Primary focus
Vendor selection
Where it lands in the deal
Early, while several vendors are still in play. Forward-looking and competitive: what can you do, and what does it cost.

Security questionnaire

Sent by Security or IT
Primary focus
Cybersecurity controls
Where it lands in the deal
After a shortlist, narrow by design. Encryption, access management, incident response, certifications, subprocessors. Nothing about your balance sheet.

DDQ

Sent by Legal, compliance, investors
Primary focus
Full risk assessment
Where it lands in the deal
Before signature or before capital moves. Security is one section among finance, legal history, operations, and compliance.

The sections a DDQ covers

Templates vary by sender and industry, but the shape is stable. What unites every section is documentation: claiming a control exists without attaching the artifact that proves it invites a follow-up round and adds weeks to the review.

Company background

Ownership structure, leadership team, years in operation, subsidiary and parent relationships.Evidence expected: Corporate registration, org chart, cap table summary.

Financial health

Revenue, audited statements, debt obligations, insurance coverage, bankruptcy history.Evidence expected: Audited financial statements, certificates of insurance.

Legal and compliance

Pending litigation, regulatory violations in recent years, data privacy posture under GDPR and sector rules.Evidence expected: Privacy policy, DPA, regulatory filings, counsel attestation.

Information security

Access management, encryption at rest and in transit, incident response SLAs, penetration testing cadence, subprocessors.Evidence expected: SOC 2 Type II report, ISO 27001 certificate, penetration test summary, security policies.

Operational continuity

Business continuity plan, disaster recovery objectives, backup verification, vendor dependencies.Evidence expected: BCP and DR plan documents, evidence of the last tested restore.

ESG

Environmental practices, labor and supply chain ethics, diversity commitments, governance.Evidence expected: Published ESG or code-of-conduct policy, supplier standards.

How to answer a due diligence questionnaire

The work that actually consumes the hours is not the hard questions. It is re-answering questions you have already answered, in a format you have not seen before. Six steps, in order.
  1. Read the whole document before answering anything. Find the sections that are not yours (the finance rows, the legal history, the insurance certificates) and route them to their owners on day one, because those are the answers that arrive last.
  2. Answer from your current documentation, not from a past submission. A response written before your last SOC 2 audit, an infrastructure migration, or a policy revision is a factual mismatch waiting to be caught, and a caught mismatch buys you another review round.
  3. Attach the evidence with the answer. A claim that a control exists, with no policy, certificate, or report behind it, generates a follow-up request every single time.
  4. Keep one owner per questionnaire. Two people answering different tabs from different memories is how the same company reports two different data retention periods in one document.
  5. Say so when the answer is no. A documented compensating control reads better to a reviewer than a hedge, and far better than a claim that unravels in the follow-up call.
  6. Reuse the answer, not the file. The same questions come back from the next buyer in a different format, so what you want to carry forward is a reviewed answer and its source, not the spreadsheet you filled in last quarter.

How Wolfia answers DDQs

Wolfia is an AI agent that reads your existing documentation, the policies, past submissions, and security evidence you already have, and drafts the DDQ from it. Every answer carries a citation to the source it came from, so a reviewer verifies rather than rewrites. The knowledge base maintains itself from your live sources, so a renewed certificate or a revised policy does not become a manual update chore.Format is the part most tools stop at. Wolfia fills DDQs in Excel, PDF, and Word, and the browser agent completes web-based portals such as OneTrust and ServiceNow end to end, without copy-paste. Because a DDQ, a security questionnaire, and an RFP all draw on the same organizational knowledge, one knowledge base answers all three.Amplitude uses Wolfia to get through security reviews without the bottleneck. Read how.Book a demo

Go deeper

This page is the short answer. Each of these goes further on one part of it.

Frequently asked questions

What does DDQ stand for?DDQ stands for Due Diligence Questionnaire: a structured set of questions one organization sends to another to assess risk before a deal, an investment, or a vendor relationship proceeds. The acronym also has an unrelated chemistry meaning, 2,3-Dichloro-5,6-dicyano-1,4-benzoquinone, an oxidizing reagent used in organic synthesis.
What is the difference between a DDQ and a security questionnaire?A security questionnaire is scoped to cybersecurity controls: encryption, access management, incident response, certifications. A DDQ covers the full risk picture, with financial health, legal history, operational processes, and compliance posture alongside security. A security questionnaire is effectively one section of a DDQ, sent on its own.
How long does a DDQ take to complete?A first draft of a 100-question DDQ typically takes 4 to 5 hours, and reported end-to-end effort runs 10 to 20 hours once internal review and evidence gathering are counted. Most of that time goes to searching previous answers and chasing colleagues for current certification documents, not to writing anything new.
How many questions are in a DDQ?Most institutional DDQs contain 100 to 200 questions. Investor DDQs that add ESG and operational sections often exceed 150, and M&A due diligence questionnaires run longer still because the capital at stake is larger.
What is the ILPA DDQ?The ILPA DDQ is the standardized due diligence template published by the Institutional Limited Partners Association, used by limited partners to evaluate general partners before committing capital. It covers fund strategy, organizational structure, performance, fee structures, risk management, and ESG, so LPs can compare funds on consistent criteria instead of each writing their own variant.
Who fills out a DDQ?The party being evaluated fills it out: the vendor responding to a procurement team, the fund manager answering an investor, the SaaS company meeting an enterprise security requirement, or the acquisition target supplying information to an acquirer. Sending and receiving are separate roles, and most companies that receive DDQs never send them.
Can you reuse DDQ answers across questionnaires?Yes, and it is where most of the time saving lives, because the same questions recur across buyers in different formats. The reuse has to be of a reviewed answer and its source, not of an old file: an answer written before your last audit, migration, or policy revision creates a factual mismatch a reviewer will catch.
Can AI fill out DDQs in vendor portals like OneTrust or ServiceNow?Most AI tools only suggest an answer for a person to copy and paste. Wolfia fills DDQs in Excel, PDF, and Word, and its browser agent completes web-based portals such as OneTrust and ServiceNow end to end, with every answer citing the source document it came from.
Does automation replace the human reviewer on a DDQ?No, and it should not. Due diligence answers can become contractual claims, so a person approves them. What automation changes is the shape of the work: the agent drafts grounded, cited answers and flags the low-confidence ones, so the reviewer clears the routine answers quickly and spends attention on the few that need it.