Due diligence

What is a DDQ(due-diligence questionnaire)?

6 min read · Updated June 2026

A due-diligence questionnaire (DDQ) is a structured document one organisation sends another to evaluate it before a deal, investment, or partnership. It gathers standardised information on operations, finances, security, compliance, and risk, so the requester can make an informed decision and document why they trusted the other party.

Who sends DDQs, and why

DDQs are sent by anyone who needs to understand and document the risk of working with you before they commit. The most common senders are investors and asset allocators assessing a fund or company, procurement teams onboarding a new supplier, and partners evaluating a commercial relationship. The questionnaire gives them a consistent, comparable record across everyone they assess.

Common types of DDQ

  • Investment / financial DDQ: used by investors and asset managers to assess a fund or company.
  • Operational due diligence (ODD): focuses on operations, controls, and key-person risk.
  • Security DDQ: how you protect data and systems (often overlapping with a security questionnaire).
  • ESG DDQ: environmental, social, and governance practices.
  • Vendor / third-party risk DDQ: used in procurement to onboard and review suppliers.
  • AML / KYC questionnaires: anti-money-laundering and know-your-customer checks.

What a DDQ usually covers

The exact sections vary by type, but most DDQs ask about:

  • Company background, ownership, and structure.
  • Financials and commercial track record.
  • Operations, processes, and key personnel.
  • Information security and data protection.
  • Compliance, legal, and regulatory standing.
  • Business continuity and disaster recovery.
  • ESG and, where relevant, insurance and references.

How to answer a DDQ well

  1. 1Read the context: who is asking, and what decision does the DDQ support?
  2. 2Reuse a maintained answer library so you are not rewriting standard responses each time.
  3. 3Ground every claim in evidence you can produce on request (policies, statements, certificates).
  4. 4Keep answers consistent: the same question should not get two different answers across documents.
  5. 5Get the right subject-matter expert and, where needed, legal sign-off before submitting.
  6. 6Track versions, so you know exactly what you told whom, and when.

DDQ vs RFP vs security questionnaire

These overlap but serve different goals. A DDQ assesses risk and trust before a relationship. An RFP (request for proposal) evaluates whether your product is the right one to buy. A security questionnaire is a focused slice, often a section of a DDQ or RFP, about how you protect data. One well-maintained answer library can feed all three.

Frequently asked questions

What does DDQ stand for?

DDQ stands for due-diligence questionnaire: a structured set of questions used to evaluate an organisation before an investment, acquisition, partnership, or supplier relationship.

What is the difference between a DDQ and an RFP?

A DDQ assesses the risk and trustworthiness of an organisation before entering a relationship, covering areas like finances, operations, security, and compliance. An RFP (request for proposal) evaluates whether a specific product or service is the right one to buy. A security questionnaire is often a section within either.

How often are DDQs updated?

Requesters typically refresh DDQs at onboarding and then on a periodic cycle (often annually) or when something material changes. Because the same questions recur, maintaining a current, source-backed answer library makes each refresh far quicker.

Do this in a fraction of the time

Diligio centralises your approved answers, drafts each response grounded in your sources, and independently verifies it before you review. RFPs, DDQs, and security questionnaires, answered from one knowledge base.

Related guides

Due diligence

DDQ vs RFP: what is the difference?

RFPs

RFP vs RFI vs RFQ: what is the difference?

RFPs

The RFP response process: a step-by-step guide

RFPs

How to build an RFP content library

RFPs

The bid/no-bid decision: when to respond to an RFP

Security questionnaires

How to respond to security questionnaires faster

Security questionnaires

SIG vs CAIQ vs VSAQ: the security questionnaires explained

Security questionnaires

Vendor security assessment checklist

Compliance

SOC 2 vs ISO 27001: what is the difference?

Compliance

ISO 27001 readiness checklist: how to prepare for certification

Compliance

SOC 2 for startups: a practical guide

Compliance

GDPR compliance for SaaS: a practical guide

Compliance

HIPAA compliance for software vendors

Compliance

PCI DSS compliance, explained

Compliance

The NIST Cybersecurity Framework, explained

Compliance

ISO 42001, the AI management standard, explained

Compliance

ISO 27017 and ISO 27018: cloud security and privacy, explained

Compliance

ISO 22301 and business continuity, explained

Compliance

DORA, explained

Compliance

Cyber Essentials, explained

Compliance

The CCPA and CPRA, explained

Compliance

NIST 800-53, explained

Compliance

NIST 800-171 and CMMC, explained

Compliance

FedRAMP, explained

Compliance

HITRUST CSF, explained

Financial regulation

BSA/AML, explained

Financial regulation

The FATF 40 Recommendations, explained

Financial regulation

MiFID II and MAR, explained

Financial regulation

Consumer credit and fair lending, explained

Due diligence

Third-party risk management (TPRM): a practical guide