DDQ ResponseGuide
9 min read

Due diligence starts before the customer asks

A bank, insurer, or corporate buyer will assess you as a supplier before signing. What to gather, who to involve, and how to respond so the check doesn't hold up the contract.

SEQUESTO

Most due diligence preparation happens before any customer request arrives. It comes down to keeping an up-to-date evidence set, with an owner and an approval on each item, and answering every question from that set with its source.

The costliest failure is an answer your organisation cannot back up once the customer relies on it. A bank’s contract with you should cover its rights to audit you and obtain information from you, under the Basel Committee’s principles. After signing, it monitors and confirms your controls.

What the customer’s check covers

A customer’s due diligence check asks whether your organisation can deliver the service, and what risk you would bring into the customer’s business. Under the Basel Committee’s principles, written for large banks that operate internationally and applied proportionately, a bank assesses your technical and operational capability, your continuity and disaster recovery plans, and whether you can support its legal and regulatory compliance. It also checks your internal controls, how you handle ICT and cyber risk, how you manage key subcontractors, and whether you can retain enough qualified staff through a disruption. On risk, the bank weighs your financial soundness, geographic dependencies, conflicts of interest, and how you cover insurable risks. Your track record also matters, including recent or pending complaints, investigations, or litigation.

An insurer outsourcing a material function looks at much the same ground under the IAIS Insurance Core Principles: your governance and internal controls, risk management, service capability, financial viability, and compliance with applicable laws. A corporate buyer working to NIST’s Cybersecurity Framework 2.0, which any organisation can adopt, plans due diligence before it enters a supplier relationship. It assesses critical suppliers before buying and writes cybersecurity requirements into the supplier contract.

The customer’s own standard-setters expect the check before signing, so your contract waits until it is done. A bank should carry out due diligence on a prospective provider before entering an arrangement. An insurer’s board approves outsourcing a material function after assessing the risks, and the insurer maintains the same oversight as if the function ran in-house.

Alongside the DDQ, most checks ask for an ISO 27001 certificate or a SOC 2 report, the business continuity plan, and details of the subcontractors who work on the service.

Build the evidence set before the request

Gather the documents a check asks for into one evidence set before any customer requests them. That means the ISO 27001 certificate or SOC 2 report, the continuity plan, a subcontractor list kept up to date, and the DDQ answers you have already approved. Assign each item a named owner, record who approved it, and note when it lapses or is due for review.

Each item carries a date because stale evidence often holds up a check or sends it back with conditions while the contract waits. Common culprits include a lapsed certificate, an outdated policy, or an answer copied from an earlier questionnaire that describes a control no longer in place.

Suppliers commonly keep their approved answers and the documents behind them, such as policies, certificates, and audit reports, in one central answer library.

Your team keeps the set in the Knowledge Hub of SEQUESTO aOS, where every item shows its expiry date, review cycle, and content owner. An expired item is flagged before it can reach a draft answer.

Give each area of the check an owner

Name one person to run the check. Assign each DDQ area to the function that holds its evidence, with an internal deadline ahead of the customer’s. A due diligence check is commonly split by area, with security or IT taking the security questions and other functions, such as legal and HR, taking their own.

A bank tells your bid team it will run supplier due diligence before it signs for your managed service for document processing. Its DDQ arrives as one spreadsheet, with tabs for information security, business continuity, financial standing, subcontractors, and contract terms. You run the check. Send information security to the security lead, business continuity to the operations lead who owns the plan, financial standing to the head of finance, and contract terms to legal counsel.

Set each owner’s deadline ahead of the bank’s, because a customer such as the bank is likely to act on a late answer. In a 2025 survey by EY, 87% of organisations escalate internally when a supplier does not answer a questionnaire on time, and 29% stop working with it. You sign off the whole set before it goes back to the bank, as you would a bid.

Answer from the evidence, with its source

Draft each answer from the evidence set, tailored to the customer’s question, and name the document, version, and section it rests on. On the bank’s business continuity tab, one question asks whether your plan is tested. The answer cites the plan’s current version and its latest test report, both supplied by the operations lead.

Reviewers at a customer read vendor documents, such as a SOC 2 report or a policy, alongside the answers. A continuity answer the test report doesn’t support is one the bank’s reviewers can see. An answer cited to its source is one your team can stand behind, and that is the quality of response the bank relies on.

Because every answer comes from one item in the set, the same fact reads the same way in every tab and in every customer’s DDQ. The information security tab needs the same care, since a defensible security questionnaire answer rests on the evidence behind it.

Your team imports the bank’s multi-tab DDQ into SEQUESTO aOS, and its Agent Force drafts each answer from approved Knowledge Hub content, with a citation to the section and document behind it. Once you approve the answers, the team exports the DDQ with every tab in the layout the bank sent.

Answer a gap with a plan and a date

Where the honest answer is “no” or “partly”, state what is in place today, name the gap, and say who closes it by when. On the bank’s subcontractors tab, the security question asks whether every subcontractor with access to the bank’s data has been assessed. Your hosting provider has been assessed, and the out-of-hours support contractor’s assessment is still open. The answer says so, names the security lead as the owner of that assessment, and gives the date it completes.

Answer this way because a “partly” with an owner and a date gives the bank’s reviewers something to decide on, while a “yes” the evidence set does not back comes to light when they read the documents and immediately costs your team the bank’s trust. Where a check finds a gap, the customer commonly asks for a remediation plan, and a gap on its own seldom ends the process.

Keep the owners on hand after you submit

Keep each area’s owner available after you submit to answer the customer’s follow-up questions and evidence requests. Add every commitment made on a call or in an email to the check record. After the questionnaire, the customer typically reviews your answers and the evidence behind them, then decides whether to move forward with you.

A follow-up question on a security answer goes back to your security lead, and an evidence request on a DDQ answer goes to whoever owns the document behind it. The work continues past signing, because banks should put enough resources into onboarding a new provider, including resolving issues found during due diligence, under the Basel Committee’s principles. An issue your DDQ raised may still be open after the contract starts, with the same owner working on it.

Keep a record of what you submitted

Keep each submitted answer with the evidence and version it cited and the name of whoever approved it. Before you submit, ask legal counsel how the contract will treat the questionnaire answers.

The customer can test those answers after signing. A bank’s contract with you should cover the bank’s and its supervisors’ rights to access your premises, audit you, and obtain information from you, plus timely information, including on incidents, under the Basel Committee’s principles. The bank’s ongoing monitoring confirms your controls and ability to meet the contract, and reports issues such as material audit findings and compliance lapses.

In the EU, for example, DORA Article 30 requires contracts for ICT services that support critical or important functions to give the financial entity unrestricted rights of access, inspection, and audit. The same rights go to a third party it appoints and to the authority, and the provider must cooperate in on-site inspections.

After signing, the bank uses its audit rights to request evidence behind your continuity answer. The record shows the plan version and test report the answer cited, and who approved them.

The record matters because banks may end an arrangement for breach of contract or for a provider’s failure to comply with applicable laws, so an answer you cannot back up puts the contract itself at risk.

When the bank asks, your team exports the audit log from SEQUESTO, which ties every action to its item, its time, and the person who took it. Each answer’s record also names the policy version it drew on, so the team can show which text was approved at submission.

Update the set for the next check

After each check, put the approved answers back into the evidence set, and update every item a change affects, such as a renewed certificate or a new subcontractor. The next customer’s DDQ then starts from answers that still hold, ready to reuse across deals once tailored to that customer.

The same customer will also ask again. Banks should review every provider arrangement regularly and whenever there is a major change at the bank, the provider, or outside, and review higher-risk and critical arrangements more often, under the Basel Committee’s principles. Before a renewal, a bank uses what its monitoring showed in the due diligence it repeats.

When your team uploads a renewed certificate, SEQUESTO flags every answer that cited the earlier version, so someone reviews it before the next DDQ.

Due diligence preparation checklist

  • Every document a check commonly asks for is in one evidence set, with an owner, an approval, and an expiry or review date.
  • Each area of the DDQ has a named owner and an internal deadline ahead of the customer’s.
  • Each answer names the document, version, and section it rests on.
  • Each “no” or “partly” states what is in place, names the gap, and says who closes it by when.
  • The owners stay available for follow-up questions and evidence requests until the customer decides.
  • A record holds each submitted answer, its evidence, and its approver.
  • Approved answers and changed items return to the set before the next check.

Start the evidence set before the next DDQ arrives, with the document your customers ask for most often.

Frequently Asked Questions

Done reading? See SEQUESTO at work.

Articles share the thinking. A demo shows it at work. See SEQUESTO handle bid response in your industry.