A due diligence questionnaire, commonly shortened to DDQ, is a structured set of questions used to investigate an organisation before a transaction, investment, contract or third-party relationship. It requests facts and evidence about areas such as ownership, finance, security, privacy, compliance, operations and resilience.

DDQs cross organisational boundaries. One workbook can contain legal representations, technical control questions, financial figures and operational commitments. Answers age at different rates and may require confidential evidence. Copying last year’s response without checking the scope, date and owner creates contradiction, over-disclosure and false assurance.

A reliable DDQ response is an evidence-controlled disclosure process. Every material answer should have an accountable owner, an approved source, a current scope and a review state. Reuse should accelerate discovery, not replace verification.

A DDQ is broader than a security questionnaire

A security questionnaire focuses on technical and organisational safeguards, while a DDQ may investigate the whole relationship. Depending on the decision, it can cover beneficial ownership, financial stability, sanctions, insurance, data protection, information security, business continuity, subcontractors, service performance and pending disputes. Investment and merger diligence can extend further into customers, intellectual property, tax and employment.

The categories overlap, but the approval path differs. A chief information security owner cannot validate audited revenue, and a lawyer should not attest to an operational recovery time without the service owner. The response process needs domain routing and a single coordinator who reconciles the complete narrative.

Typical diligence domains and evidence
DomainTypical questionsPossible evidence
CorporateOwnership, entities, governanceRegisters, organization records
SecurityControls, incidents, testingPolicies, audit reports, summaries
PrivacyData roles, transfers, retentionNotices, records, agreements
OperationalDelivery, continuity, suppliersPlans, metrics, registers
FinancialStability, insurance, liabilitiesApproved statements, certificates

Evidence must match the claim, scope and review date

A policy proves that an organisation has defined an expectation; it does not by itself prove consistent operation. An audit report may provide stronger assurance but only for its stated systems and period. A certificate can expire. A penetration-test summary describes a point in time. Good responses name the relevant control and avoid implying more than the evidence establishes.

Create a disclosure ladder. Public documentation can be shared early. Controlled summaries may be provided under confidentiality. Detailed reports, samples or customer-specific material may require a secure room and need-to-know review. This lets the counterparty validate real evidence while reducing unnecessary exposure.

  • Record source owner, approval date, scope and expiry.
  • Use an evidence identifier rather than uncontrolled attachments.
  • Separate implemented control, compensating measure and roadmap.
  • Redact personal and customer-specific information where appropriate.
  • Revalidate content when the question changes meaning or scope.

Useful outcomes from due diligence questionnaire

  • Question owners receive only the items that require their judgement.
  • Repeated answers are reused with provenance and current validation.
  • Claims, exceptions and planned remediation are distinguished clearly.
  • Sensitive evidence is disclosed proportionately and through an approved channel.
  • The submitted questionnaire has a complete review and approval record.

How to run the work

  1. 01

    Classify the request and disclosure boundary

    Confirm the counterparty, transaction, entities, products, geography, deadline and confidentiality arrangement. Separate security, privacy, legal, financial and operational domains. Decide which documents can be shared immediately, which need restricted access and which require redaction or a later diligence stage.

  2. 02

    Build an answer and evidence map

    Route each question to an accountable subject owner. Search approved prior responses, policies, audit reports, registers and product documentation. Record the source date and scope. A similar answer is only a candidate until the owner confirms that it applies to this request.

  3. 03

    Draft with explicit answer states

    Answer the exact question and distinguish yes, no, partially implemented, not applicable and planned. Add concise context when a binary answer would mislead. Link evidence to the claim it supports and avoid broad statements that extend beyond the assessed entity, service or period.

  4. 04

    Review, approve and preserve

    Run cross-functional review for contradictions, unsupported commitments and disclosure risk. Obtain the required legal, security, finance and commercial approvals. Submit through the authorized channel, preserve the exact final version and feed approved new answers back into the controlled knowledge base.

Questions that change the decision

  • Which entity, product, geography and period does each answer cover?
  • Who owns the truth and approval for this question domain?
  • What evidence is sufficient, current and proportionate to disclose?
  • Does a yes or no answer need qualification to remain accurate?
  • Which exception requires remediation, escalation or commercial acceptance?

Where teams lose control

01

An inherited answer can be factually true for one product and false for another.

02

Broad claims such as always or fully can create contractual or regulatory exposure.

03

Uncontrolled attachments can reveal customer, architecture or personnel information unnecessarily.

04

Contradictory answers across security, privacy and legal sections erode trust.

05

A spreadsheet without version control makes it difficult to prove what was approved and sent.

Measure the finished job

Measure the completed workflow, including review effort and exceptions. Output volume on its own is not evidence of a better process.

  • questions assigned to an accountable owner
  • answers supported by a current approved source
  • items returned for contradiction or unsupported language
  • median owner response and review time
  • new reusable answers accepted into the knowledge base
  • post-submission corrections or buyer follow-up questions

Common questions

What does DDQ stand for?

DDQ stands for due diligence questionnaire. It is a structured information request used to assess an organisation, transaction or third party before an investment, contract or other material decision.

What is included in a due diligence questionnaire?

The scope depends on the decision. Common areas include ownership, finance, insurance, security, privacy, compliance, business continuity, subcontractors, operational performance and legal matters. The request may also ask for documents that substantiate the answers.

Can DDQ answers be automated?

Retrieval, routing, draft preparation, consistency checks and evidence linking can be assisted. Accountable owners still need to verify context, current facts, exceptions and disclosure. High-risk legal, security and financial representations should not be published from unreviewed reused text.

How is a DDQ different from an RFP?

A DDQ investigates whether the organisation and its controls are acceptable. An RFP evaluates how a supplier proposes to meet a requirement. A procurement can contain both: solution questions in the RFP and organisational diligence in a separate questionnaire.

Malcolm Ferguson

Malcolm Ferguson

Procurement and sourcing specialist

Malcolm writes from the buyer side about procurement, sourcing, due diligence and the evidence suppliers need to pass a serious evaluation.

Proposal software for source-grounded RFP, RFI, DDQ and questionnaire response work.

Bid, proposal, presales, security and compliance teams. Start with the workflow, constraints and evidence you already have.

See Ziva