Skip to main content
Category: Third-Party Risk

Due Diligence Questionnaire

Also known as: DDQ, due diligence questionnaire (DDQ)
Simply put

A Due Diligence Questionnaire (DDQ) is a structured, formal document containing questions used to gather information about another party, such as a target company, supplier, or distributor, before entering into a business transaction or relationship. It commonly asks about the party's operations, financial position, legal and regulatory standing, and adherence to relevant standards and laws. Organizations use the responses to assess risks and make more informed decisions.

Formal definition

A DDQ is a standardized set of structured enquiries directed to a counterparty, target, third party, or intermediary to obtain information supporting risk assessment and decision-making ahead of a transaction or ongoing relationship. Typical coverage may include business operations, financial performance, and legal and regulatory compliance, though the specific content varies by context, sector, and the nature of the transaction. DDQs are used in settings such as corporate transactions (for example, to obtain information about a target company) and third-party or distributor oversight, where standardized questionnaires can streamline the collection and review of information. As an information-gathering instrument, a DDQ supports due diligence but does not by itself verify the accuracy of responses or guarantee any outcome; independent verification and validation are typically separate activities. This entry does not cover implementation specifics, tooling, or legal advice, and applicable requirements may differ across jurisdictions and industries.

Why it matters

A Due Diligence Questionnaire supports informed decision-making by structuring the collection of information about a counterparty before an organization commits to a transaction or ongoing relationship. In compliance and third-party risk management, standardized enquiries help ensure that relevant areas, such as a party's operations, financial position, and legal and regulatory standing, are considered consistently rather than ad hoc. This consistency can be particularly valuable where multiple counterparties are being assessed and comparable information is needed to evaluate risk.

DDQs also serve an efficiency function. In some sectors, such as investment fund distribution, standardized questionnaires are intended to streamline oversight by reducing duplicated effort, difficulty, and expense for the parties involved. By providing a common set of enquiries, a DDQ can make the process of gathering and reviewing information more manageable for both the requesting organization and the responding party.

It is important to recognize the limits of the instrument. A DDQ gathers information but does not, by itself, verify the accuracy of the responses provided or guarantee any particular outcome. Independent verification and validation are typically separate activities, and the specific content and weight given to a DDQ vary by context, sector, and jurisdiction. Treating questionnaire responses as conclusive without corroboration is a common misuse that can undermine the risk assessment it is meant to support.

Who it's relevant to

Compliance officers
Compliance teams use DDQs to gather structured information on a counterparty's legal and regulatory standing and adherence to relevant standards and laws, supporting third-party and intermediary oversight. They should treat responses as inputs to be corroborated rather than as verified facts, and tailor questionnaire scope to applicable jurisdictional and sectoral requirements.
Risk managers
Risk professionals rely on DDQ responses to assess risks associated with a target, supplier, or distributor before and during a relationship. The instrument supports consistent, comparable information gathering, but risk managers should account for its limitation as an unverified source and integrate it with independent verification and validation activities.
Professionals involved in corporate transactions
In corporate transactions, DDQs are used to obtain information about a target company or business, informing decisions ahead of a deal. Those managing the transaction use the responses to identify areas warranting deeper review, recognizing that the questionnaire supports but does not replace substantive due diligence.
Distributor and third-party oversight functions
In settings such as investment fund distribution, standardized DDQs are intended to streamline distributor oversight and reduce time, difficulty, and expense for fund managers and distributors. Functions responsible for ongoing third-party monitoring use them to collect comparable information efficiently across multiple relationships.

Inside DDQ

Corporate and Ownership Information
Requests for legal entity details, ownership structure, ultimate beneficial ownership, and organizational background used to establish who the counterparty is and how it is controlled.
Financial and Operational Details
Questions covering financial standing, operational capacity, and business continuity arrangements that help the requesting party assess stability and delivery capability. The specific items sought commonly vary by industry and the nature of the relationship.
Compliance and Regulatory Posture
Inquiries into the counterparty's adherence to applicable laws, regulations, and internal policies, which may include anti-bribery, sanctions screening, and data protection practices. Applicable obligations typically depend on jurisdiction and sector.
Risk and Control Environment
Questions about the counterparty's own governance structures, risk management processes, and internal controls, allowing the requesting party to assess control maturity as an input to its risk assessment.
Supporting Documentation Requests
Requests for evidence such as policies, certifications, licenses, or attestations to corroborate responses. The questionnaire itself typically gathers self-reported information and is one input among several rather than independent verification.

Common questions

Answers to the questions practitioners most commonly ask about DDQ.

Does completing a due diligence questionnaire confirm that a third party is compliant or low-risk?
No. A due diligence questionnaire is a self-reported information-gathering instrument, not an assurance activity. It captures a counterparty's own representations at a point in time; it does not independently verify those representations, nor does it guarantee that the third party is compliant or that residual risk is acceptable. The responses are typically an input to a risk assessment rather than a conclusion about risk. Where independent confidence is required, organizations commonly supplement questionnaires with verification such as review of certifications, audit reports, or on-site assessment, which are distinct assurance activities.
Is a due diligence questionnaire the same as a third-party risk assessment?
No, though the terms are sometimes used interchangeably. The questionnaire is one data-collection component; the risk assessment is the broader analytical process of evaluating the third party against the organization's objectives, risk criteria, and applicable obligations. A questionnaire may feed a risk assessment, but the assessment also draws on other sources and applies judgment, scoring, and decision-making that the questionnaire itself does not perform. Treating a completed questionnaire as a finished risk assessment can overstate the work actually done.
How should the scope and depth of a questionnaire be tailored to different third parties?
Many programs use a tiered approach, aligning the length and rigor of the questionnaire to the assessed inherent risk of the relationship, considering factors such as the nature of services, data access, criticality, and regulatory sensitivity. Lower-risk vendors may receive a shorter set of questions, while higher-risk relationships may warrant more detailed inquiries and requests for supporting evidence. The appropriate segmentation depends on the organization's risk criteria, sector, and jurisdiction, so no single standard structure applies universally.
Who within an organization typically owns and reviews questionnaire responses?
Ownership commonly sits with the business or procurement function initiating the relationship, often described as first-line responsibility, while second-line functions such as risk or compliance may set the questionnaire standards and review responses against policy. In the terms of the three lines model associated with the IIA, internal audit as a third-line function would provide independent assurance over the process rather than complete or approve individual questionnaires. Specific role allocation varies by organization size and structure; this entry does not prescribe a particular operating model.
How often should due diligence questionnaires be refreshed after onboarding?
Because questionnaire responses reflect conditions at a point in time, many programs establish periodic reassessment, with frequency often driven by the third party's risk tier and by trigger events such as material changes in service, ownership, or regulatory status. There is no single mandated interval that applies across all jurisdictions and sectors; the cadence typically reflects the organization's risk appetite and any applicable regulatory expectations. Ongoing monitoring may complement, but does not replace, periodic reassessment.
What can be done to improve the reliability of self-reported questionnaire responses?
Reliability may be improved by requesting supporting evidence for key assertions, corroborating responses against independent sources such as certifications or third-party audit reports where available, and following up on incomplete or ambiguous answers. Some programs use attestation or sign-off by an accountable representative of the third party to reinforce accountability. These measures reduce, but do not eliminate, the limitations of self-reporting; the questionnaire remains a representation rather than verified fact, and this entry does not address specific tooling or verification techniques.

Common misconceptions

Completing a due diligence questionnaire proves a counterparty is compliant or low risk.
A questionnaire commonly captures self-reported information at a point in time. It informs an assessment but does not by itself verify accuracy or guarantee any compliance or risk outcome; corroboration through supporting evidence and, where warranted, independent assurance is typically needed.
A due diligence questionnaire is an audit or assurance activity.
Issuing and reviewing a questionnaire is generally a management activity supporting a decision about a relationship. It is distinct from independent auditing or assurance work performed with objectivity by a separate function, and the two should not be conflated.
One standard questionnaire suits every counterparty and jurisdiction.
The relevant questions commonly vary by the nature of the relationship, the counterparty's role, the applicable regulatory context, and the risk it presents. Applying a single fixed template without tailoring may omit material areas or gather information disproportionate to the risk.

Best practices

Scope the questionnaire to the specific relationship and risk level, tailoring the depth and content rather than applying a single fixed template to all counterparties.
Align requested information with the jurisdictions, sectors, and internal policies that apply to the relationship, recognizing that obligations may differ across contexts.
Treat responses as self-reported inputs and, where risk warrants, seek supporting documentation or independent corroboration before relying on them.
Keep the questionnaire process as a management-led assessment distinct from any independent assurance or audit review of the same counterparty.
Document how responses feed into the risk assessment and the resulting decision, so the basis for accepting, conditioning, or declining the relationship is traceable.
Establish periodic refresh and re-assessment triggers, since a questionnaire reflects a point in time and a counterparty's circumstances may change.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.