---
title: "Due Diligence Questionnaire"
url: "https://www.arphie.ai/glossary/due-diligence-questionnaire"
collection: glossary
lastUpdated: 2026-08-10T18:26:14.323Z
---

# Due Diligence Questionnaire

Due diligence questionnaires can decide whether a vendor is approved, an investment advances, or a deal reaches contract. Yet “DDQ” can describe very different documents across software sales, third-party risk, mergers and acquisitions, and investment management. Knowing which kind you have, what evidence it requests, and who can approve each answer prevents avoidable delays and risky commitments.



## What Is a Due Diligence Questionnaire?



A **due diligence questionnaire (DDQ)** is a structured set of questions that one party sends another to collect facts and supporting evidence before entering, renewing, or expanding a business relationship or transaction. The issuer uses the responses to identify risk, compare options, and decide whether it needs clarification, remediation, contract protections, or a different course of action.



The DDQ is one input to due diligence. It does not certify a company, prove that every stated control works, or make the final risk decision. For supplier relationships, the [NIST Cybersecurity Framework 2.0](https://doi.org/10.6028/NIST.CSWP.29) places planning and due diligence before formal supplier or third-party relationships, which helps explain why a DDQ often gates contract signature.



### DDQ vs. RFP, Security Questionnaire, and Audit



These documents can appear in the same sales or procurement process, but each supports a different decision.



| Document | Main decision | Typical scope |
| --- | --- | --- |
| Due diligence questionnaire | Is the organization or transaction an acceptable risk? | The relationship-specific mix of corporate, financial, legal, operational, security, privacy, and compliance topics. |
| Request for proposal (RFP) | Which solution best meets a defined business need? | Capabilities, implementation, service, pricing, and commercial terms. |
| Security questionnaire | Does the supplier's security and privacy posture meet requirements? | Information security, privacy, data handling, resilience, and related evidence. It may sit inside a broader DDQ. |
| Audit or independent assessment | Are selected controls designed and operating as stated? | Evidence review, testing, and findings against a defined standard or scope. |
| Due diligence request list | Which records need examination in a transaction? | Documents such as contracts, financial statements, corporate records, tax filings, and intellectual property schedules. |



When a DDQ reaches your response team, our [knowledge activation platform](https://www.arphie.ai/platform) imports the original Word or Excel file, drafts source-backed answers from connected company knowledge, and keeps owners and reviewers in one governed project. This handoff is most useful on client-issued DDQs, where response speed can keep a suitable deal moving without giving up review control.



## What Are the Main Types of DDQ?



The words around “DDQ” reveal the relationship being evaluated. A **client DDQ** and a **vendor DDQ** can describe the same exchange from opposite sides: the client issues it, and the vendor responds. In finance, DDQ may describe an investment manager, fund, or financial counterparty assessment. Other DDQs use different questions because the underlying decision changes.



| DDQ type | Issuer and respondent | What it evaluates |
| --- | --- | --- |
| Client or vendor DDQ | A prospective or current customer evaluates a supplier. | The supplier's product, security, privacy, compliance, resilience, financial health, and service delivery. |
| Third-party risk DDQ | Procurement, governance, risk and compliance (GRC), or security evaluates a vendor or business partner. | Inherent risk, controls, access to data and systems, subcontractors, business continuity, and ongoing monitoring needs. |
| Investment manager or fund DDQ | A limited partner, allocator, or consultant evaluates a manager or fund. | The firm, team, strategy, track record, governance, operations, risk management, service providers, and fund terms. |
| M&A DDQ | A buyer or investor evaluates an acquisition target. | Corporate structure, financial performance, tax, contracts, litigation, intellectual property, people, technology, and liabilities. |
| Financial crime DDQ | A bank or financial institution evaluates a correspondent or other financial counterparty. | Ownership, customer base, anti-money laundering controls, sanctions, transaction monitoring, and payment transparency. |
| Ethics or business-partner DDQ | Compliance or legal evaluates an agent, distributor, joint-venture partner, or other intermediary. | Beneficial ownership, conflicts, anti-bribery controls, sanctions exposure, government relationships, and reputation risk. |



## What Does a Due Diligence Questionnaire Cover?



Every DDQ should follow the decision at hand. A software-as-a-service (SaaS) buyer needs to understand how a vendor handles customer data. An allocator needs to understand how an investment manager runs a strategy. An acquirer needs to understand which obligations and liabilities come with a target company.



The following question areas recur across business and vendor DDQs. The exact scope and evidence depend on the relationship.



| Question area | Example questions | Common evidence and owner |
| --- | --- | --- |
| Organization and ownership | Which legal entity will contract? Who owns or controls it? Which affiliates or subcontractors are involved? | Corporate records, ownership charts, and organization charts. Legal or corporate operations owns the response. |
| Product and service scope | Which service, deployment, region, and customer data are in scope? Which dependencies support delivery? | Service descriptions, architecture diagrams, data-flow diagrams, and subprocessor lists. Product, sales engineering, and privacy contribute. |
| Information security | How are access, encryption, vulnerability management, secure development, and incident response handled? | Policies, audit reports, certifications, penetration-test summaries, and control records. Security or GRC owns the response. |
| Privacy and data governance | Which data is collected, where is it processed, how long is it retained, and how is it deleted? | Data inventories, privacy policies, retention schedules, data processing terms, and subprocessors. Privacy or legal owns the response. |
| Operations and resilience | How does the organization maintain service through an outage or disruption? What recovery objectives apply? | Business continuity plans, disaster recovery test summaries, service commitments, and incident procedures. Operations, security, and legal contribute. |
| Compliance and legal | Which laws, licenses, investigations, disputes, sanctions, or contractual duties apply? | Registrations, compliance policies, litigation schedules, and counsel-approved disclosures. Legal or compliance owns the response. |
| Financial viability and insurance | Can the organization support the relationship? Which liabilities are insured? | Financial statements, funding information, and insurance certificates. Finance or risk owns the response. |
| People and workforce | Which personnel support the service? How are screening, training, succession, and access termination handled? | Workforce policies, training records, and succession plans. Human resources and the relevant operating leader contribute. |
| Ethics and sustainability | How does the organization address bribery, conflicts, human rights, environmental obligations, or responsible investment? | Codes of conduct, program policies, reporting, and governance records. Compliance, legal, or sustainability owns the response. |



## Which DDQ Template Should You Use?



A template is useful when it matches the relationship and the level of risk. Starting with a recognized standard also makes repeat assessments easier to compare. Custom questions still belong where a specific product, transaction, regulation, or risk appetite requires them.



| Relationship or assessment | Useful starting point | What it provides |
| --- | --- | --- |
| Broad third-party risk | Shared Assessments [Standardized Information Gathering (SIG)](https://sharedassessments.org/sig-faq/) | Risk-based scoping for third-party controls, including Lite and Core options and custom questionnaires. |
| Cloud service security | Cloud Security Alliance Consensus Assessments Initiative Questionnaire ([CAIQ v4.1](https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4-1)) | Yes-or-no assessment questions mapped to the Cloud Controls Matrix, which has 207 controls across 17 security domains. |
| Private equity manager diligence | Institutional Limited Partners Association (ILPA) [DDQ 2.0](https://ilpa.org/resources-tools/resource-library/due-diligence-questionnaire/) | A standardized framework for questions that limited partners ask managers, available in PDF and Word formats. |
| Alternative investment manager diligence | Alternative Investment Management Association (AIMA) [modular DDQs](https://www.aima.org/sound-practices/due-diligence-questionnaires.html) | Questionnaires for investment managers and related strategies, with template selection based on the firm and product. |
| Correspondent banking and financial crime | Wolfsberg [CBDDQ and FCCQ](https://wolfsberg-group.org/resources/correspondent-banking) | Standard questionnaires for financial crime risk management in correspondent relationships. |
| Investment fund distributor oversight | EFAMA and ICI [distributor DDQ](https://www.efama.org/newsroom/news/investment-funds-distributor-due-diligence-questionnaire) | A uniform questionnaire for onboarding and ongoing oversight of fund distribution channels. |



SIG and CAIQ both appear in technology sales, but they are not interchangeable. SIG spans a broad third-party risk program, while CAIQ concentrates on cloud security controls. Our [SIG questionnaire guide](https://www.arphie.ai/blog/sig-questionnaire) and [CAIQ guide](https://www.arphie.ai/blog/caiq-questionnaire) explain the formats and response workflows in detail.



## How to Respond to a DDQ



A strong response creates a traceable chain from each question to its context, source, accountable owner, approved answer, and shareable evidence.



![DDQ response chain from question to approved evidence](https://cdn.prod.website-files.com/672fc2345132970736914b73/6a79e18c58a467295ccc556f_a95440e6-ec88-4669-8531-05b001528bcf.png)



| Response stage | What to do | Why it matters |
| --- | --- | --- |
| Scope and preserve | Record the issuer, purpose, in-scope entity, product, geography, deadline, requested standard, file format, and evidence rules. Preserve question IDs, formulas, hidden tabs, dropdowns, character limits, and attachment instructions. | Context determines whether an existing answer applies, while file control prevents workbook or portal errors. |
| Draft from authoritative sources | Give the direct answer, define its scope, cite the supporting evidence, and state any approved qualification. Separate reusable facts from context-dependent facts, control gaps, exceptions, and new legal or commercial commitments. | A familiar answer may still be wrong for the product, entity, region, or customer in scope. |
| Review by risk and authority | Give one coordinator ownership of the deadline and complete file. Route security, privacy, finance, legal, and operational claims to the owners who can approve them, with an explicit sign-off state for high-risk answers. | “Drafted” and “approved for this submission” are different statuses. |
| Reconcile and retain | Match answers to evidence, resolve blanks and conflicting dates, confirm attachments, and export in the requested format. Retain each reusable answer with its source, scope, owner, and review trigger. | Final reconciliation catches inconsistencies and turns one deadline into better preparation for the next DDQ. |



Our [client DDQ guide](https://www.arphie.ai/glossary/client-ddq) goes deeper on the respondent-side workflow for customer-issued questionnaires.



## What Makes a DDQ Response Credible?



Credibility comes from precision and traceability. “Yes” may satisfy a dropdown, but it rarely explains scope. A long answer can still fail if it hides an exception or cites no support.



Several shortcuts undermine that credibility:



- **Context-free reuse.** An answer for one product, legal entity, hosting model, or geography is applied elsewhere.



- **Unapproved promises.** A responder converts a current practice into a contractual commitment.



- **Evidence mismatch.** The attachment covers a different scope, period, or claim.



- **Excess disclosure.** The response shares sensitive details beyond what the evaluation requires.



- **Workbook damage.** Sorting, copying, or exporting breaks the issuer's formulas, identifiers, or required format.



- **False certainty.** An unclear or unsupported answer is presented as settled fact.



## Where AI Helps With DDQs



AI is useful for parsing repeated questions, retrieving relevant source material, and producing a first draft. People still own disclosures, exceptions, commitments, and final sign-off. Our AI agents draft from connected knowledge and show answer sources and confidence signals so reviewers can assess each response instead of accepting black-box text. Our [AI-powered DDQ guide](https://www.arphie.ai/glossary/ai-powered-ddqs) explains the automation and governance choices in more depth.