Due Diligence Questionnaire (DDQ)
Definition
A structured questionnaire sent to a prospective vendor before onboarding, asking the vendor to describe its security controls, certifications, incident history, subprocessor relationships, and data handling practices. The DDQ is the primary pre-contract risk assessment instrument in most TPRM programmes.
- Used in
- Third-party risk management (TPRM) programmes
- Timing
- Sent before vendor onboarding
- Covers
- Security controls, certifications, incident history, subprocessors
- Role
- Primary pre-contract risk assessment instrument
Common questions
What happens if a vendor's DDQ answers are later found to be inaccurate?+
Inaccurate DDQ responses are treated as a contract and risk-management issue, potentially triggering remediation clauses, closer monitoring, or termination rights, and can factor into fraud or negligent-misrepresentation claims if the misstatement caused measurable harm.
Does a completed DDQ replace the need for ongoing vendor monitoring?+
No, the DDQ is a point-in-time snapshot taken before onboarding. Mature TPRM programmes pair it with periodic reassessment, since a vendor's controls, subprocessors, and incident history can change materially after the contract begins.
Related terms
- Offboarding Controls
- The set of actions taken when a vendor relationship ends: revoking access credentials, recovering or destroying shared data, terminating network connectivity, and...
- Right-to-Audit Clause
- A contractual provision that gives the organisation the right to audit or assess the vendor's security controls, either directly or through a...
- Subprocessor
- A third party engaged by a vendor (the processor) to perform part of the service that involves the organisation's data. Under GDPR...
- Third-Party Risk
- The information security, operational, legal, or reputational risk introduced to an organisation by its relationships with external parties including vendors, suppliers, cloud...
- Vendor Tiering
- The classification of vendors into risk tiers, typically Tier 1 (critical), Tier 2 (significant), and Tier 3 (low), based on factors such...