What is an DDQ?
A Due Diligence Questionnaire (DDQ) is a standardized set of questions an organization sends to assess a counterparty's risk posture — covering security, compliance, financials, and operations. DDQs recur (often annually), which makes a maintained answer knowledge base especially valuable.
When DDQs are used
DDQs are standard in financial services (allocators to asset managers), vendor risk management, and enterprise procurement — issued before onboarding and re-issued on review cycles, with formats from industry-standard questionnaires to bespoke spreadsheets.
What a typical DDQ contains
- 01Organization, ownership, and financial standing
- 02Governance and compliance program
- 03Information security controls and certifications
- 04Operational resilience and business continuity
- 05Legal, regulatory, and insurance disclosures
- 06Sub-processor / third-party risk sections
How to respond to an DDQ
Consistency is the scored dimension nobody prints on the form. DDQ reviewers compare your answers against your published documents, your certifications, and — most dangerously — your own previous submissions. An answer that drifts between quarters without an explained change is itself a risk flag. This is the structural argument for generating DDQ answers from a single maintained corpus (policies, attestations, financial statements) rather than from the last spreadsheet: consistency becomes a property of the system instead of a reviewer's vigilance.
Answer what is asked, disclose what is true, and resist both over- and under-sharing. Thin answers trigger follow-up cycles that cost more than a complete first answer; over-sharing beyond the question's scope creates gratuitous exposure and future consistency obligations. Where the honest answer is unflattering — an incident, a control gap, an exception — pair the disclosure with the remediation state and date; risk reviewers score maturity of response, and a managed weakness reads better than a suspicious perfection.
Industrialize the recurrence. A mid-sized vendor or fund answers hundreds of substantially overlapping questionnaires yearly; treating each as fresh authorship burns the exact experts (security, compliance, finance) whose time is scarcest. The scalable pattern: maintain the source documents, generate cited draft answers per questionnaire, route genuinely novel or sensitive questions to the owning expert, and fold every improved answer back into the corpus — so the system gets faster and more consistent with every DDQ instead of merely surviving it.
DDQ vs the other solicitation types
| Type | Purpose | Commitment | Typical outcome |
|---|---|---|---|
| DDQ | Assess counterparty risk before/while doing business | Disclosures are relied upon; accuracy carries liability | Risk review → onboarding conditions or approval; recurs on cycle |
| RFP | Compare competing solution approaches and prices | Proposals are offers; award forms a contract | Evaluation → shortlist/discussions → award |
| RFQ | Obtain comparable prices for a specified purchase | Quotes are typically binding offers for the validity period | Comparison → award, often lowest responsive |
| RFI | Survey the market and shape a future procurement | Non-binding for both sides | Shortlists, requirement shaping → often an RFP/ITT follows |
| ITT | Award a defined scope through auditable competition | Tenders are binding offers; strict process law applies | Rubric scoring → award with standstill/feedback |
| SIQ | Register and qualify supplier facts into buyer systems | Declarations relied upon for onboarding and compliance | Supplier record created/refreshed; gates category eligibility |
| PQQ | Shortlist capable suppliers before tender evaluation | Declarations binding; misstatements risk exclusion | Pass → invited to tender; scored ranking may cap invitees |
| Grant | Award non-repayable funds to advance program goals | Award creates obligations: performance + reporting | Panel review → award with terms and reporting cycle |
DDQ — common questions
How is a DDQ different from a security questionnaire?
Security questionnaires are the infosec-focused subset; DDQs sweep wider — financials, governance, legal, operations — with security as one section. Response mechanics are identical.
Who should answer DDQs?
Drafts can be generated from your policy corpus; ownership of final answers belongs with the domain owners (CISO, compliance, finance) reviewing cited drafts rather than authoring from scratch.
How do we keep hundreds of DDQs consistent?
Ground answers in one maintained source-document corpus and cite them; when an answer improves, fix the source document so every future questionnaire inherits the correction.
Related reading
Answering an DDQ right now?
Upload it and BidAuthor extracts every requirement — tables and attachments included — and drafts cited answers from your knowledge base in minutes.