Due Diligence Questionnaire

What is an DDQ?

A Due Diligence Questionnaire (DDQ) is a standardized set of questions an organization sends to assess a counterparty's risk posture — covering security, compliance, financials, and operations. DDQs recur (often annually), which makes a maintained answer knowledge base especially valuable.

When DDQs are used

DDQs are standard in financial services (allocators to asset managers), vendor risk management, and enterprise procurement — issued before onboarding and re-issued on review cycles, with formats from industry-standard questionnaires to bespoke spreadsheets.

What a typical DDQ contains

  1. 01Organization, ownership, and financial standing
  2. 02Governance and compliance program
  3. 03Information security controls and certifications
  4. 04Operational resilience and business continuity
  5. 05Legal, regulatory, and insurance disclosures
  6. 06Sub-processor / third-party risk sections

How to respond to an DDQ

Consistency is the scored dimension nobody prints on the form. DDQ reviewers compare your answers against your published documents, your certifications, and — most dangerously — your own previous submissions. An answer that drifts between quarters without an explained change is itself a risk flag. This is the structural argument for generating DDQ answers from a single maintained corpus (policies, attestations, financial statements) rather than from the last spreadsheet: consistency becomes a property of the system instead of a reviewer's vigilance.

Answer what is asked, disclose what is true, and resist both over- and under-sharing. Thin answers trigger follow-up cycles that cost more than a complete first answer; over-sharing beyond the question's scope creates gratuitous exposure and future consistency obligations. Where the honest answer is unflattering — an incident, a control gap, an exception — pair the disclosure with the remediation state and date; risk reviewers score maturity of response, and a managed weakness reads better than a suspicious perfection.

Industrialize the recurrence. A mid-sized vendor or fund answers hundreds of substantially overlapping questionnaires yearly; treating each as fresh authorship burns the exact experts (security, compliance, finance) whose time is scarcest. The scalable pattern: maintain the source documents, generate cited draft answers per questionnaire, route genuinely novel or sensitive questions to the owning expert, and fold every improved answer back into the corpus — so the system gets faster and more consistent with every DDQ instead of merely surviving it.

DDQ vs the other solicitation types

TypePurposeCommitmentTypical outcome
DDQAssess counterparty risk before/while doing businessDisclosures are relied upon; accuracy carries liabilityRisk review → onboarding conditions or approval; recurs on cycle
RFPCompare competing solution approaches and pricesProposals are offers; award forms a contractEvaluation → shortlist/discussions → award
RFQObtain comparable prices for a specified purchaseQuotes are typically binding offers for the validity periodComparison → award, often lowest responsive
RFISurvey the market and shape a future procurementNon-binding for both sidesShortlists, requirement shaping → often an RFP/ITT follows
ITTAward a defined scope through auditable competitionTenders are binding offers; strict process law appliesRubric scoring → award with standstill/feedback
SIQRegister and qualify supplier facts into buyer systemsDeclarations relied upon for onboarding and complianceSupplier record created/refreshed; gates category eligibility
PQQShortlist capable suppliers before tender evaluationDeclarations binding; misstatements risk exclusionPass → invited to tender; scored ranking may cap invitees
GrantAward non-repayable funds to advance program goalsAward creates obligations: performance + reportingPanel review → award with terms and reporting cycle

DDQ — common questions

How is a DDQ different from a security questionnaire?

Security questionnaires are the infosec-focused subset; DDQs sweep wider — financials, governance, legal, operations — with security as one section. Response mechanics are identical.

Who should answer DDQs?

Drafts can be generated from your policy corpus; ownership of final answers belongs with the domain owners (CISO, compliance, finance) reviewing cited drafts rather than authoring from scratch.

How do we keep hundreds of DDQs consistent?

Ground answers in one maintained source-document corpus and cite them; when an answer improves, fix the source document so every future questionnaire inherits the correction.

Related reading

Answering an DDQ right now?

Upload it and BidAuthor extracts every requirement — tables and attachments included — and drafts cited answers from your knowledge base in minutes.