Definition
What a vendor DDQ is.
A vendor due diligence questionnaire is the structured list of questions a company sends to a supplier before signing, and often again at renewal, to establish whether the supplier is safe to do business with. It is the written form of a simple question: if we give you our data, our money, or a place in our supply chain, what could go wrong, and what have you done about it?
"DDQ" is used for several related documents, and it helps to know which one is in front of you:
- Vendor or third-party DDQ. Sent by a customer's procurement, risk, or security team to a supplier. Covers the company, its finances, security, privacy, compliance, and operations. This is the one this page is about.
- Investor or LP DDQ. Sent by an institutional investor to a fund manager before committing capital. The ILPA Due Diligence Questionnaire 2.0 (November 2021) is the common standard. See the ILPA DDQ explained.
- M&A DDQ. A buyer's question list against a target's data room during an acquisition. Same mechanics, higher stakes, run by counsel.
A security questionnaire such as a SIG or CAIQ is a specialized DDQ that covers only the security domain. A vendor DDQ is broader: security is one section among several.
Contents
What a vendor DDQ asks.
There is no single standard vendor DDQ. Most are assembled by the buyer from a template, and they converge on the same sections:
| Section | Typical questions | Where the answers live |
|---|---|---|
| Company and ownership | Legal entity, ownership, officers, years in business, headcount, locations, sanctions and litigation history | Corporate records, entity chart, legal register |
| Financial standing | Revenue band, audited accounts, insurance coverage and limits, credit references | Financial statements, insurance certificates |
| Information security | Policies, access control, encryption, vulnerability management, penetration testing, incident response, certifications held | ISMS policy set, pen test summary, SOC 2 report or ISO certificate |
| Data protection and privacy | What personal data is processed, where, legal basis, subprocessors, retention, deletion, cross-border transfers, DPA terms | Privacy policy, DPA template, subprocessor list, retention schedule |
| Business continuity | Backup, recovery objectives, failover, last test, dependency on single suppliers | BCP/DR plan, test records |
| Compliance and ethics | Anti-bribery, sanctions screening, modern slavery, code of conduct, regulatory licenses | Compliance policies, training records |
| Subcontractors and supply chain | Who else touches the service, how they are vetted, right to audit | Vendor register, subprocessor list, vendor management policy |
| Operations and support | SLAs, support hours, change management, escalation paths, exit and data return | Service description, SLA, terms of service |
The last column is the point. Nearly every question on a vendor DDQ is answered by a document the supplier already keeps. The work is finding the passage and stating it plainly, not composing new material.
Purpose
Why buyers send them.
Three reasons, and it helps to answer with all three in mind.
- Regulatory obligation. Financial services, healthcare, and public sector buyers are required to assess third parties and to keep evidence that they did. Your answers become part of their file, which is why vague answers get sent back.
- Risk decision. Someone is scoring your answers to decide whether to sign, and under what terms. A No with a compensating control can pass; an unsupported Yes that is later contradicted can end the relationship.
- Contract inputs. Answers about insurance, subprocessors, data location, and recovery objectives feed directly into the agreement. What you write here you will be held to.
Answering
How to answer one well.
- Triage first. Count the questions, find the sections that do not apply to your service, and ask the sender whether N/A with a reason is acceptable and whether an existing report (SOC 2, ISO 27001, a published CAIQ) covers any section.
- Assemble the source folder. The right-hand column of the table above is the checklist. One folder, current versions only.
- Answer from the documents and note the source. Short, direct, with a file and section reference. Reviewers read hundreds of these; a sentence and a citation beats a paragraph.
- Be honest about gaps. No, with what you do instead and when it changes, is a mature answer. A guess is a liability.
- Review once for overstatement and consistency, then return the file in the format it arrived. The full process is in how to answer a security questionnaire fast; it applies to the whole DDQ, not only the security section.
Tooling
Where Mattercite fits.
Mattercite is built for the "answer from the documents" step. Upload the source folder, import the DDQ in the format it arrived (Excel, CSV, Word, or PDF), and review an answer for each question that cites the file and page it came from. Questions the documents do not cover are flagged as Needs Information for your team to resolve, and the export goes back in the buyer's format. There is no answer library to build first. More on the DDQ page.
Questions
Common questions.
What is the difference between a DDQ and a security questionnaire?
A security questionnaire covers one domain: information security. A vendor DDQ is broader and covers the company itself, its finances, insurance, privacy, compliance, continuity, and supply chain, with security as one section. Standard security questionnaires such as the SIG and CAIQ often appear inside or alongside a DDQ.
Who sends vendor DDQs?
A customer's procurement, vendor risk, security, or compliance function, usually before contract signature and again at renewal or after a material change. Regulated buyers in financial services, healthcare, and government send them as a matter of obligation.
How long does a vendor DDQ take to answer?
It depends on the length and on whether your source documents are current. A 50-question onboarding DDQ can be a same-day job for a supplier with policies in order. A 300-question enterprise DDQ answered from memory and old spreadsheets commonly takes a week or more of combined time, most of it spent finding answers that already exist in documents.
Is the ILPA DDQ a vendor DDQ?
No. The ILPA Due Diligence Questionnaire is for institutional investors assessing private fund managers, covering strategy, team, track record, fund terms, governance, ESG, and DEI. It is a DDQ, but an investor one, not a supplier one. Mattercite handles both.