What Is a DDQ?

A DDQ (due diligence questionnaire) is a structured, evidence-backed set of questions one organisation sends another before an investment, acquisition or vendor relationship. Bid and vendor teams complete DDQs to prove ownership, financial, compliance and security controls.

A due diligence questionnaire is a formal, written information request that asks the recipient to describe, with supporting documents, how its organisation is owned, governed, financed, operated and controlled. It differs from an informal information request because it is structured, repeatable, and designed to produce a documentary record rather than a conversation. The sending organisation, whether an institutional investor, an acquirer, or a corporate procurement function, uses the DDQ to build an evidence base for a decision it is about to make or a relationship it continues to rely on.

What a DDQ Is

Definition and core purpose

A DDQ exists to convert an organisation's internal state, its ownership structure, financial condition, compliance programme and operational controls, into a written, verifiable record that another party can assess. That is its core purpose: not persuasion, but evidence.

The mechanism is straightforward. A sender issues a fixed list of questions, often accompanied by a schedule of required documents, and the recipient must answer each one factually, attaching proof rather than description. A due diligence questionnaire is a formal document with questions designed to ascertain a third party's compliance with industry standards, laws, regulations and cybersecurity practices material to the assessing company.

For recipients, vague or unsupported answers carry real cost. A DDQ answer without an attached certificate, policy extract or audit report is treated as unverified, and unverified answers slow or block the underlying decision. This is why DDQ response is increasingly treated as a discipline in its own right, distinct from general proposal writing.

What distinguishes a DDQ from the wider due diligence process

A DDQ is one instrument within due diligence, not the process itself. Due diligence also includes site visits, interviews, independent research and reference checks; the DDQ is the documentary spine that ties those activities together.

The distinction matters because a completed DDQ, however thorough, represents self-reported information. A DDQ is a structured set of questions that one organisation sends to another to verify how it operates before committing capital, awarding business or continuing a relationship, and the completed questionnaire becomes part of the sender's formal due diligence record. Analysts and risk teams treat it as a starting point for verification, not the verification itself.

In practice, this means a site visit, a reference call or an independent audit can still follow a strong DDQ response. A recipient that assumes the questionnaire is the entire gate, rather than the entry point to further scrutiny, misjudges what is actually being assessed.

Where DDQs Are Used

Institutional investor due diligence

Institutional investors use DDQs to assess fund managers before committing capital, and the practice is formalised through standardised templates. ILPA states that a standardised investor DDQ in private markets is intended to standardise the key areas of inquiry investors raise during manager diligence and to provide a framework for ongoing monitoring of progress in areas such as diversity, equity and inclusion.

The mechanism here is comparability. When many managers answer the same standardised question set, investors and consultants can compare responses across a shortlist rather than reconciling bespoke formats from each manager. ILPA's widely used private equity DDQ covers many fund-diligence topics, including track record, so that investors can ask consistent questions across managers systematically.

A limit worth noting: standardisation reduces friction but does not remove the need for judgement. Two managers can answer the same standardised questions accurately and still present materially different risk profiles once an investor weighs the answers against its own mandate.

Mergers and acquisitions

In M&A, an acquirer issues a DDQ to a target to surface information about ownership, financial performance, contracts, litigation, and regulatory standing before a transaction closes. It sits alongside legal, financial and operational workstreams rather than replacing them.

The mechanism is that the target's answers, and the documents attached to them, feed directly into valuation, warranty negotiation and closing conditions. A gap or inconsistency in a DDQ response can trigger further investigation, a price adjustment or a specific indemnity in the transaction agreement.

Vendor and third-party risk management

Corporate procurement and third-party risk functions use DDQs to assess prospective and existing suppliers before onboarding and periodically afterwards. In vendor contexts, a due diligence questionnaire is the primary pre-contract risk assessment instrument in many third-party risk management programmes, asking a prospective vendor to describe its security controls, certifications, incident history, subprocessor relationships, and data handling practices.

The scale of this activity is substantial. Survey data cited in DDQ guidance reports that companies send third parties an average of 55 questionnaires with 101 to 350 questions each, illustrating why vendor-side bid and compliance teams treat DDQ responses as an ongoing operational load rather than a one-off task.

A structured due diligence questionnaire used in vendor risk management typically contains 100 to 200 questions covering company background, financial health, legal and compliance standing, information security, operational continuity and ESG, meaning a single response can touch nearly every function in a supplier organisation.

What a DDQ Typically Covers

Ownership, governance and financials

Most DDQs open with questions about legal structure, ownership, board composition, and financial standing, because these establish who the counterparty is before assessing any operational detail. This section answers a basic but essential question: who is accountable, and are they solvent?

The mechanism is that ownership and governance disclosures reveal conflicts of interest, related-party arrangements and financial fragility that would otherwise remain invisible in a purely operational conversation. Financial statements, auditor opinions and organisational charts are the standard supporting evidence.

A due diligence questionnaire is a comprehensive questionnaire used to assess a potential investment opportunity, business partnership or acquisition target by gathering detailed information about business operations, financial performance and legal and regulatory compliance, which is why this section rarely appears in isolation from the compliance sections that follow.

Compliance and regulatory posture

Compliance sections ask whether the organisation meets the laws, regulations and industry standards relevant to the sender's jurisdiction and sector. This answers whether the counterparty can legally and reliably operate within the terms of the intended relationship.

The mechanism relies on documentary proof: licences, regulatory filings, sanctions screening results, litigation history and policy attestations. A due diligence questionnaire is a formal document with questions designed to ascertain a third party's compliance with industry standards, laws and regulations material to the assessing company, and answers without supporting documents are generally treated as incomplete.

A practical limit is jurisdictional mismatch: a compliance framework built for one regulatory environment may not map cleanly onto a counterparty operating across several, which is why cross-border DDQs often carry supplementary, market-specific questions.

Information security and operational resilience

Security and resilience questions probe how the counterparty protects data, manages incidents, and maintains service continuity, and they now make up a large share of most vendor DDQs. This section answers whether an operational disruption at the counterparty becomes a disruption for the sender.

The mechanism involves certifications, penetration test summaries, incident response records and business continuity plans submitted as evidence alongside narrative answers. A due diligence questionnaire in vendor contexts asks a prospective vendor to describe security controls, certifications, incident history, subprocessor relationships and data handling practices before onboarding.

Because this domain changes quickly, security sections are most likely to be flagged as stale at refresh, and recipients most often need to update evidence between DDQ cycles rather than simply resubmitting prior answers.

DDQ vs Adjacent Instruments

DDQ versus RFP

A DDQ verifies how an organisation operates; an RFP asks how it proposes to solve a stated problem. The two instruments serve different stages of a relationship and are frequently confused because both arrive as long, structured question sets.

An RFP is typically issued early in a buying cycle to compare solutions, pricing and approach across competing vendors. A DDQ is risk- and compliance-centric and is issued once a vendor, fund, or target is shortlisted to verify baseline controls, operational readiness, and regulatory alignment through factual, auditable responses rather than persuasive proposals.

The practical consequence is that teams answering both need different postures. RFP answers can reasonably describe intended approach; DDQ answers must describe current, evidenced state, and treating the two the same way produces DDQ responses that read as marketing rather than proof.

DDQ versus single-domain security questionnaires

A DDQ is broader than a security questionnaire, covering the whole firm rather than one control domain. This distinction matters because a recipient who has only built evidence for information security will still face gaps when a full DDQ arrives.

Security questionnaires, such as those built on frameworks like SIG or CAIQ-style formats, focus narrowly on technical and organisational security controls. A DDQ typically folds a security section in alongside ownership, financial, legal and governance sections, making it a firm-level instrument rather than a control-domain one.

Organisations that treat their security questionnaire evidence library as sufficient for DDQ response often discover, mid-process, that financial and governance sections require an entirely separate evidence chain they have not yet centralised.

Standardised DDQ Templates

Association-published templates

Several industry bodies publish standardised DDQ templates so that investors can ask consistent questions and managers can prepare a single, reusable response set. AIMA states that association-published DDQs helped investors assess fund investments they might make and helped fund managers choose service providers, directors, and boards for those funds.

The mechanism is network-level efficiency: once a template is adopted broadly, a manager can reuse much of the response across multiple investor relationships, updating only what has changed. This reduces duplicated effort on both sides of the exchange.

A limit is that standardised templates cover common ground well but rarely eliminate bespoke follow-up questions, particularly where an investor's mandate, jurisdiction or risk appetite falls outside the template's default scope.

Tailoring by fund structure

Standardised DDQs are increasingly tailored to specific fund structures rather than issued as one generic form. INREV's non-listed real estate framework provides three tailored questionnaires, one for non-listed real estate vehicles, one for fund-of-funds and multi-manager structures, and one for real estate debt vehicles, to meet the needs of different fund structures while maintaining a high level of scrutiny.

This tailoring reflects that debt and equity vehicles have different risk drivers, so a single question set would either omit material questions or force irrelevant ones on respondents. INREV's non-listed real estate DDQ helps investors and consultants understand a fund manager's structure, strategy and business, as well as a specific vehicle's strategy, risk processes and terms.

For respondents, this means a fund manager operating multiple vehicle types cannot rely on a single completed DDQ; each structure typically requires its own tailored version, even when much of the underlying evidence overlaps.

Responding to a DDQ

Evidence and documentation practices

Effective DDQ response depends on attaching current, verifiable evidence to every answer rather than relying on narrative alone. This is the single practice that most separates a response that clears review quickly from one that generates follow-up queries.

Specialised DDQ response guidance emphasises reading the whole document before answering, routing sections to their owners on day one, answering from current documentation rather than past submissions, and attaching evidence with each answer. Expert guidance on building DDQ response capability further highlights centralising evidence in a secure, version-controlled repository and mapping controls directly to evidence.

A worked consequence: a security section answered from an outdated or expired policy is treated as a false or misleading answer, not a minor oversight, because DDQ evidence is expected to reflect present-day state.

Recurring refresh and ongoing monitoring

A completed DDQ is rarely a one-time artefact. Most institutional and vendor risk programmes require periodic refresh so the sender's due diligence record stays current as the counterparty changes.

Advanced DDQ evidence libraries are built on principles such as immutability and version control, where every document, screenshot, or policy has a clear version history, and updates are archived rather than deleted, creating an audit trail that demonstrates the state of compliance over time. This allows a sender to trace exactly what a counterparty represented at each refresh point, not only what it represents now.

The consequence for recipients is operational: without a maintained evidence library, each refresh cycle effectively restarts the response from scratch, which is precisely the burden that version-controlled, centrally governed evidence repositories are designed to remove.

Where SEQUESTO fits into a DDQ response

A DDQ asks one organisation to prove its controls to another, with evidence, not assertion, expected on every line. That evidence requirement creates the tension: answers must be accurate and traceable, but they also have to come out fast, drawn from certifications and policy documents that live in different files and different owners' heads. SEQUESTO is built for the evidence side of that trade-off, not the speed side alone.

Incoming DDQs, whatever their format or number of tabs, get parsed into a structured list of questions. AI Agents retrieve matching content from a permission-scoped Knowledge Hub by meaning rather than keyword, draft an answer with source citations for each question, and route it to your team for review and approval before anything is exported back into the original file format. Every retrieval, draft and approval is logged with actor and timestamp, so the audit trail a regulator or institutional client asks for already exists when they ask for it.

Frequently Asked Questions

Further Reading

Put the terminology to work

Now you know the language, see how Sequesto automates the process. Book a demo and experience AI-powered bid management first-hand.