Template

Due diligence questionnaire template.

The sections and sample questions a vendor DDQ should cover, the evidence to ask for, and when to use the ILPA DDQ instead.

Published 29 September 2026.

Which template

Start with the right kind of DDQ.

"Due diligence questionnaire" covers three different documents, and the right template depends on who is asking whom:

  • Vendor or third-party DDQ. A customer asks a supplier about security, privacy, finances and operations before signing. The template below is for this case.
  • Investor DDQ. An LP asks a fund manager about strategy, team, track record and terms before committing capital. Use the free, industry-standard ILPA DDQ rather than a homemade template.
  • M&A DDQ. A buyer's request list against an acquisition target's data room, usually drafted by counsel for the specific deal.

Template

A vendor due diligence questionnaire template.

These are the sections almost every vendor DDQ converges on, with sample questions for each. Copy the sections that fit your risk, drop the ones that do not, and keep the questions short and specific enough to answer with a fact or a document.

SectionSample questionsEvidence to request
Company and ownershipFull legal name, registration number and jurisdiction.
Who owns more than 10 percent of the company?
Any litigation, sanctions or regulatory action in the last five years?
Corporate records, entity chart, legal register
Financial standingAnnual revenue band and most recent audited accounts.
Insurance held, with carriers and limits (cyber, E&O, general liability).
Financial statements, insurance certificates
Information securityDo you maintain a written information security policy, reviewed at least annually?
Is customer data encrypted at rest and in transit?
When was the last independent penetration test, and were findings remediated?
Which certifications or reports do you hold (SOC 2, ISO 27001)?
Security policy set, pen test summary, audit reports
Data protection and privacyWhat personal data will you process on our behalf, and where is it stored?
List your subprocessors.
How is data returned or deleted at the end of the contract?
Privacy policy, DPA, subprocessor list, retention schedule
Business continuityWhat are your recovery time and recovery point objectives?
When was the continuity plan last tested?
BCP and DR plan, test records
Compliance and ethicsDo you have anti-bribery and sanctions screening policies?
Do staff receive annual compliance training?
Compliance policies, training records
Subcontractors and supply chainWhich third parties support the service, and how are they assessed?
Do we have a right to audit?
Vendor register, vendor management policy
Operations and supportService levels, support hours and escalation path.
How are changes to the service communicated?
SLA, service description, terms

For a deeper security section, many buyers attach a standard questionnaire instead of writing their own, most often the SIG, SIG Lite or CAIQ. That saves the supplier time, since many already keep a completed copy.

Sending one

If you are sending the DDQ.

  • Scale it to the risk. A supplier with no access to your data does not need 300 security questions. Tier your vendors and send a short form to low-risk ones.
  • Ask for evidence, not essays. Request the policy, report or certificate alongside the answer. It is faster to review and harder to overstate.
  • Accept equivalents. A current SOC 2 report or ISO 27001 certificate can answer a whole section. Say so up front.
  • Allow "not applicable" with a reason, and ask for gaps to be stated with the compensating control rather than glossed over.

Answering one

If you are answering the DDQ.

Nearly every question in the table above is answered by a document you already keep: the third column is your checklist. Gather the current versions in one folder, answer each question briefly with a reference to the file and section, and state gaps honestly instead of guessing. The full process is in what is a vendor DDQ and how to answer a security questionnaire fast.

Mattercite does that step for you. Upload the folder, import the DDQ in the format it arrived (Excel, CSV, Word or PDF), and review a draft answer for each question that cites the file and page it came from. Questions your documents do not support are flagged as Needs Information, and the completed file goes back in the sender's format.

Questions

Common questions.

What should a due diligence questionnaire include?

For a vendor DDQ: company and ownership, financial standing, information security, data protection and privacy, business continuity, compliance and ethics, subcontractors, and operations and support. Each question should be answerable with a short fact or a document.

Is there a standard due diligence questionnaire template?

For investors assessing private fund managers, yes: the ILPA DDQ 2.0 is the common standard. For vendors there is no single standard, but most buyers use the sections on this page, and many attach the SIG, SIG Lite or CAIQ for the security portion.

How long should a vendor DDQ be?

As long as the risk warrants. A short form of 30 to 50 questions suits most low-risk suppliers; critical suppliers with access to sensitive data may receive several hundred questions, often including a standard security questionnaire.

Can I answer a DDQ automatically?

You can draft it automatically from your own documents and then review it. Mattercite imports the DDQ as it arrived, drafts each answer with a citation to your source file and page, and flags questions your documents do not support, so a person approves every answer before it goes back.

Try it

Received a DDQ? Answer it from your documents.

Upload your policies, import the questionnaire as it arrived, and review answers that cite the source. Fourteen days free, 150 questions, no credit card.

Related: the ILPA DDQ explained, what is a vendor DDQ, DDQs.