All articlesdocument collection

Due Diligence Questionnaire (DDQ): What It Is + How It Works

A DDQ is a standardized questions-plus-documents checklist. The term means three different things—here's what professionals actually need to know.

AT

Arthur Teboul

Founder, DokuTrak

August 3, 20269 min read
On this page

A due diligence questionnaire (DDQ) is a standardized set of questions—and, critically, an attached list of required documents—that one party sends to another to assess risk, suitability, and compliance before a transaction or relationship. The term is used in three distinct professional contexts, and they're easy to conflate, so I'll define them up front.

In investment management, an LP sends a DDQ to a fund manager to evaluate whether the fund is a safe place to invest. In vendor and third-party risk assessment, an organization sends a DDQ to a vendor to assess cybersecurity, privacy, and operational risk before signing a contract. In M&A due diligence, a buyer's counsel sends the target a legal request list covering corporate records, financials, intellectual property, and other documentation before closing a deal.

Each context has different standards, different senders and receivers, and different document requirements. But they share a core workflow reality: a DDQ is a large, repeated document-and-information request that gets emailed back and forth—often across multiple rounds—until every item is collected, verified, and signed off.

TL;DR: A due diligence questionnaire is a standardized questions-plus-documents checklist used in investment, vendor assessment, and M&A deal contexts. The 2025 EY survey finds companies send third parties an average of 55 questionnaires with 101–350 questions each. Email workflows break down; structured collection with no-account upload and AI file validation replaces scattered email threads with per-item tracking. Start collecting documents with DokuTrak.


What Are the Three Types of DDQs?

The term "due diligence questionnaire" gets applied to three different workflows that professionals often mix up. Defining each cleanly is the first step to picking the right tool.

Investment management DDQs are sent by Limited Partners (LPs)—pension funds, endowments, family offices—to fund managers (GPs) before deploying capital. The industry standard is the ILPA DDQ 2.0 (Institutional Limited Partners Association, updated November 2021). It covers 20 topics: firm and fund information, investment strategy, team, alignment of interests, governance, compliance, reporting, and ESG. It includes an Appendix A—Requested Documents, explicitly bundling the questions with a standardized document-request list. ILPA designed this template specifically to reduce questionnaire sprawl. Their own language: customized DDQs "have created an extraordinary administrative burden on all interested parties, including LPs, GPs and placement agents." ILPA isn't the only standard-setter here—AIMA's DDQ has standardized hedge-fund and alternatives due diligence since 1997 (2025 edition, March 2025).

Vendor and third-party risk (TPRM) DDQs are sent by organizations to their vendors and service providers to assess operational, cybersecurity, and compliance risk. The standard is the SIG questionnaire (Shared Assessments' Standardized Information Gathering, updated 2025). The SIG covers 21 risk domains across 4 control areas: Governance & Risk Management; Information Protection; IT Operations & Business Resilience; Security Incident & Threat Management. It's delivered as tiered questionnaires (SIG Lite for basic assessment, SIG Core for comprehensive, SIG Detail for in-depth), with question counts varying annually as threats evolve.

M&A due diligence is conducted by the buyer's legal counsel, who sends the target company a request list for documents spanning corporate records, financial statements, tax compliance, intellectual property, contracts, employment agreements, litigation history, environmental records, and regulatory licenses. Unlike ILPA and SIG, there's no single mandated template—each transaction is tailored by counsel to the deal type and industry. But the document categories recur consistently across deals, per the Thomson Reuters M&A due diligence guide (updated July 2024).

These three workflows are fundamentally different: different senders, different risk frameworks, different standards bodies. But they share one friction point: they're all large, document-heavy processes that break down when managed over email.


The Scale of the DDQ Problem: Why It Matters

The administrative burden isn't hypothetical. The 2025 EY Global Third-Party Risk Management Survey (conducted with Oxford Economics, n=500 TPRM executives) quantifies the sprawl. (EY, May 2025)

Companies that use standardized questionnaires still send third parties an average of 55 questionnaires each year. When they do receive responses, 45% of those questionnaires contain 101–200 questions, and 36% contain 201–350 questions. The volume matters because each questionnaire is a separate email thread, a separate deadline, and a separate accountability chain.

The consequence: 87% of organizations now escalate late responders (up from 70% in 2023). Late response to a DDQ isn't a minor inconvenience—it's escalated because the organization can't proceed with the transaction or onboarding until the questionnaire is complete.

In parallel, the RiskRecon 2024 survey found that 44% of organizations assess more than 100 third parties per year, yet only 4% have high confidence their questionnaires accurately reflect real-world risk. The sheer volume overwhelms the process.

Add Gartner's finding: 45% of organizations experienced third-party-related business interruptions in the past two years, per their December 2023 survey. A delayed or incomplete DDQ response can cascade into deal delays or operational risk materializing downstream.

The root cause is process, not people.


Why Email Breaks the DDQ Workflow

When DDQs are managed over email and spreadsheets, three failures cascade:

First, version chaos. The initial questionnaire is sent. The recipient replies with answers and attachments. You request clarification or additional documents. They send a revised version. Weeks later, you're not sure which email thread contains the definitive response, which attachment is the latest version, and whether all the requested documents are actually there.

Second, document requests get lost. The ILPA DDQ includes Appendix A—a standardized list of supporting documents. When that appendix is buried in an email attachment and passed back and forth, items fall through the cracks. You think a document was submitted; you follow up; they think they already sent it. The accountability is unclear because email doesn't track whether each specific item was actually received.

Third, bad files aren't caught until late. A recipient uploads a document two weeks ago. You don't open it until days before the deadline. The ID expired six months ago. The tax return is the wrong year. The scan is too blurry to read. Now you're re-requesting with days to spare, and the recipient is either unavailable, unwilling to fix it quickly, or has already moved on. You've created a second collection cycle at the worst moment.

Email wasn't built for workflows that require tracking 55+ separate questionnaires, hundreds of questions, and dozens of supporting documents. It's built for single conversations.


How Structured Collection Fixes DDQ Friction

The fix isn't new processes—it's making your existing process visible and enforceable.

A structured DDQ workflow replaces email chaos with:

  1. Per-item tracking. Instead of "did they send the questionnaire?", you see status per document: Client → Document name → Status (not submitted / submitted / flagged / accepted). You can see at a glance which items are still outstanding.

  2. No-account secure upload. Clients don't create a login. They receive an email with a secure link, click it, and upload directly. Mobile-optimized. No passwords, so there's less to abandon.

  3. Automated reminders. Day 3, day 7, day 14—the system sends reminders automatically. No manual follow-ups. The burden shifts from you chasing to the system enforcing.

  4. AI file validation at intake. The system flags documents that don't meet requirements (expired ID, unreadable scan, wrong format) the moment they're uploaded, while the client is still engaged. You don't discover problems late.

  5. Submission history and versioning. If a client re-submits a corrected file, you see both versions and accept the new one without confusion. Clear audit trail.

This is the workflow I built DokuTrak to handle: the document-collection side of a DDQ. I'm not building the questionnaire itself—ILPA, Shared Assessments, and M&A counsel have that covered. What I'm solving is the operational reality: collecting, validating, and tracking the supporting documents that make a DDQ actionable.

DokuTrak handles this for any use case where you're collecting documents from external parties—whether it's a fund manager responding to an LP's ILPA DDQ, a vendor completing a SIG questionnaire with attached security policies and SOC reports, or a target company gathering documents for M&A due diligence.


When You Need a DDQ (And When You Don't)

You need a formal DDQ if you're in one of the three contexts:

  • You're raising a private fund and LPs are asking for the ILPA DDQ before committing capital.
  • You're onboarding a new vendor and your compliance team requires the SIG questionnaire plus supporting documentation.
  • You're buying a company and counsel is requesting a comprehensive due diligence package.

You probably don't need a formal DDQ if you're collecting basic intake documents (W-9, insurance proof, identity verification) from clients. In that case, you're just collecting documents—the formal questionnaire framing is overkill. Use a simpler no-account secure link and let the client upload directly.

The distinction matters because DDQs carry formal standards and compliance weight. Using the right tool for the right job saves time.


The Real Takeaway

A DDQ is a large, standardized, high-stakes document-collection workflow. The term gets used for three different things—investment, vendor risk, M&A—but the friction is the same: email and spreadsheets collapse under the volume.

The fix is structure: clear item tracking, no-account upload, automated reminders, and file validation at intake. DokuTrak handles the document-collection half of this workflow—the part that actually lives in your inbox and your clients' uploads. Spend your time reviewing substantive answers, not hunting for attachments.

For the full framework, start with the document collection hub. For a practical walkthrough on structuring your intake process, see How to Collect Documents from Clients Without Chasing Them. For a deeper look at the tracking side, read Document Tracking System: Know Which Clients Haven't Filed.

Start your free 14-day trial — first client request free, no card, then no charge for 14 days.


Sources

Frequently asked questions

What is a due diligence questionnaire?

A due diligence questionnaire (DDQ) is a standardized list of questions and required documents one party sends to another to assess risk, suitability, and compliance. It's used in three contexts: investment management (ILPA DDQ), vendor risk assessment (Shared Assessments' SIG), and M&A due diligence. All three share the same pain: large, repeated document requests emailed back and forth.

What is the ILPA DDQ?

The ILPA (Institutional Limited Partners Association) Due Diligence Questionnaire 2.0 is the industry standard template LPs (investors) use to evaluate GPs (fund managers) before investing. Published November 2021, it covers 20 topic areas from investment strategy to ESG, plus Appendix A—a standardized document-request list. ILPA built the template explicitly to fight questionnaire sprawl and reduce the administrative burden on all parties.

What is a SIG questionnaire?

SIG (Standardized Information Gathering), published by Shared Assessments, is the vendor-risk standard. It helps organizations assess third-party cybersecurity, privacy, and operational risk before onboarding. SIG 2025 covers 21 risk domains across 4 control areas, delivered as tiered questionnaires: SIG Lite (basic), SIG Core (comprehensive), and SIG Detail (in-depth). Question counts vary by tier and are updated annually.

How many questions are in a typical DDQ?

It depends on the type. The ILPA DDQ covers 20 topics. The SIG questionnaire varies by tier (Lite, Core, Detail). Per the 2025 EY survey, 45% of organizations report questionnaires with 101–200 questions and 36% report 201–350. With an average of 55 questionnaires sent, the volume compounds quickly.

What's the difference between a DDQ and a due diligence request list?

In investment management and vendor assessment, a DDQ bundles questions with a document-request list (like ILPA's Appendix A). In M&A, counsel sends a 'due diligence request list' for corporate, financial, tax, IP, and employment records. Both are large, multi-round document-collection workflows: 'questionnaire' emphasizes the questions, 'request list' the documents. In practice, the same pain.

Why do DDQs create so much work?

DDQs sprawl when organizations don't standardize. Investors send custom questionnaires; vendors request their own security assessments; targets face dozens of separate requests across a deal. The 2025 EY survey found companies send third parties an average of 55 questionnaires, with 87% now escalating late responders (up from 70% in 2023). Email and version chaos make it worse.