Due Diligence Questionnaire (DDQ): Complete Guide and 100-Question Template for UK Transactions

due diligence questionnaire

Buyers and investors need a consistent, comparable view of the business they’re evaluating, but sellers often field the same requests three or four times, scattered across email chains and spreadsheets. A due diligence questionnaire (DDQ) is a structured set of questions issued to a target company, fund manager, or supplier to gather information, test claims, and surface risk before a deal, investment, or contract goes ahead.

This guide explains how DDQs work in UK M&A, private equity, and supplier contexts, walks through the process end to end, and sets out a 100-question checklist organised by business area. You’ll also find a downloadable template in PDF, Word, and Excel, and a practical workflow for running the whole exercise through a virtual data room.

What is a due diligence questionnaire?

DDQ meaning in UK transactions

A due diligence questionnaire is a structured document of specific enquiries sent from one party to another during a transaction or onboarding process. A thorough, evidence-backed response gives the requesting party a documented basis for their investment, purchase, or contracting decision.

In UK deals, a DDQ usually sits alongside site visits, expert reports, and adviser-to-adviser conversations rather than replacing them. It defines the scope of what needs answering and creates a written record of what was disclosed, which matters if a dispute surfaces later.

What is a DDQ used for?

DDQs turn up across several types of UK transaction and business relationship:

  • Mergers and acquisitions, where a buyer verifies the target’s legal, financial, and operational position, often run alongside a wider M&A data room process
  • Private equity investments, covering both target-company diligence and fund-manager evaluation
  • Supplier onboarding, checking a new supplier’s financial stability and compliance record
  • Partnerships and joint ventures, where each side wants assurance about the other’s standing
  • Compliance reviews, including anti-money laundering checks and ongoing third-party risk monitoring

UK deal volumes fell 12% during 2025, while aggregate deal values rose 12% and the average deal size climbed 28%, according to PwC’s analysis of the UK M&A market. Fewer, larger transactions raise the stakes attached to each one, and a well-run DDQ process is one of the more direct ways to manage that risk.

Due diligence questionnaire vs due diligence checklist

Due diligence questionnaire

Questions issued to another party that require answers and supporting evidence, not just an internal tracking entry.

Due diligence checklist

An internal or shared list used to track documents, workstreams, reviews, and completion status across the wider diligence exercise.

Information request list

A document-focused request, often shorter and less structured, that may accompany or precede a detailed DDQ.

Who prepares and answers a DDQ?

Buyer or investor responsibilities

The buyer or investor side owns the scope of the exercise: deciding which risks are material, designing specific rather than open-ended questions, and reviewing answers before accepting them at face value. A vague answer should trigger a sharper follow-up, not a tick in the box.

Seller, target, or fund-manager responsibilities

The receiving side needs a coordinated response process, usually a single point of contact pulling input from finance, legal, HR, and operations, and checking each answer against the evidence before it goes out. An answer that’s true for most of the business but not all of it needs to say so.

The role of legal and specialist advisers

Several specialist teams typically contribute on both sides of a DDQ:

  • Corporate counsel, covering legal structure, contracts, and disputes
  • Financial advisers, covering accounts, forecasts, and deal structuring
  • Tax specialists, covering filings, positions, and historic liabilities
  • HR teams, covering workforce, pensions, and employment risk
  • IT and cybersecurity specialists, covering systems, data protection, and incident history
  • ESG advisers, covering environmental, social, and governance matters

Types of due diligence questionnaires

Vendor due diligence questionnaire

“Vendor due diligence questionnaire” carries two distinct meanings, and treating them as interchangeable causes confusion when scoping a project. The first is a supplier or third-party risk questionnaire: a business asks a current or prospective supplier about financial stability, compliance, and operational resilience.

The second is vendor due diligence in the M&A sense: before going to market, a seller commissions its own due diligence report on the target, covering much of the ground a buyer would investigate, and shares the findings with prospective bidders to speed up the sale.

Supplier due diligence questionnaire

A supplier due diligence questionnaire tests whether a supplier can be relied on to deliver lawfully and consistently over the life of a contract. Typical areas include:

  • Financial resilience, including credit history and cash position
  • Regulatory compliance relevant to the supplier’s sector
  • Information security controls protecting shared data
  • Business continuity and disaster recovery arrangements
  • Reliance on subcontractors, and how those relationships are managed
  • Service delivery track record, including any missed commitments

Customer due diligence questionnaire

A customer due diligence questionnaire sits in a different category. It’s the identity and risk-verification process a regulated UK business runs on a new customer under the Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 (as amended), rather than a commercial risk assessment of a counterparty.

Firms in scope must verify a customer’s identity, understand beneficial ownership, and assess the money-laundering risk the relationship presents. The name overlaps with transaction DDQs, but the legal basis and purpose are different.

Private equity due diligence questionnaire

Private equity DDQs operate at two levels. A PE firm evaluating a target company runs a DDQ covering the same ground as most M&A transactions: financials, legal position, commercial contracts, and operational risk.

Separately, limited partners evaluating a fund manager send a DDQ covering investment strategy, track record, governance, fees, and conflicts of interest, rather than one company’s operations. A private equity due diligence software platform can help fund managers manage the volume of DDQs arriving from multiple LPs, since many of the underlying questions repeat across investors.

ILPA due diligence questionnaire

The ILPA DDQ and Diversity Metrics Template are intended to standardise the key areas of inquiry investors pose when diligencing managers, giving LPs and GPs a shared framework rather than each investor building its own list. The current version, ILPA DDQ 2.0, was released in 2021, succeeding the original v1.2 from 2018, and its ESG section has since been aligned with the PRI’s private equity responsible investment questionnaire, with a supplementary climate module added in 2025.

Hedge fund due diligence questionnaire

The AIMA DDQ is the template prospective investors typically use to assess hedge fund managers, and is widely treated as the industry standard. It covers firm governance, investment strategy, risk management, operational infrastructure, service providers, and regulatory compliance, and its most recent edition extended coverage beyond hedge funds to private credit and private equity strategies.

ESG due diligence questionnaire

An ESG due diligence questionnaire asks a target or supplier to substantiate the sustainability claims made in its reporting. Typical lines of enquiry cover:

  • Environmental liabilities and historic contamination risk
  • Emissions data and reduction targets
  • Workforce practices, including pay, safety, and working conditions
  • Supply-chain issues, including labour practices among suppliers
  • Governance arrangements overseeing ESG risk
  • Reporting controls behind published ESG metrics
  • Evidence supporting specific public ESG claims

How the DDQ process works: a step-by-step guide

A DDQ works best as a managed process rather than a one-off document drop. These six steps cover a typical UK transaction from initial scoping through to sign-off.

  1. Define the transaction and risk scope.

    Decide what’s actually material to this deal, sector, and counterparty, rather than sending every question in a master template. A supplier onboarding review and a £50 million acquisition warrant very different depth.

  2. Select and customise the template.

    Start from a base template, strip out anything irrelevant, and add sector-specific questions the standard set won’t cover, such as clinical governance for a healthcare target or spectrum licensing for a telecoms business.

  3. Issue the questionnaire and assign owners.

    Every question needs a named owner, an internal reviewer, an approver, a deadline, and a priority level, so nothing goes unanswered because no one was responsible for it.

  4. Prepare answers and supporting evidence. 

    Answers should point to something concrete: a contract clause, a policy document, a set of accounts, a register entry, a certificate, or a report, not a general description.

  5. Review responses and raise follow-up questions.

    Sort each answer into one of five categories: answered, partially answered, not applicable, evidence missing, or material issue identified. That sorting determines what happens next.

  6. Record findings and sign off.

    Material findings feed directly into valuation, deal structure, warranties, indemnities, conditions to completion, and any remediation plans agreed before or after signing.

DDQ checklist: 100 due diligence questions organised by business area

This is the working core of the guide: 100 questions across ten business areas, covering the ground a UK buyer, investor, or onboarding team typically needs to test. Use the full set for a significant acquisition or fund investment, and select a relevant subset for smaller deals or supplier reviews.

1. Corporate structure and ownership — questions 1–10

  1. What is the target’s exact legal name, registered number, and registered office address?
  2. In which jurisdiction was the company incorporated, and has it changed jurisdiction or legal form?
  3. Who are the current shareholders, and what percentage does each hold?
  4. Who are the ultimate beneficial owners, and has beneficial ownership changed in the past three years?
  5. Does the group include subsidiaries, joint ventures, or dormant companies not shown on the main structure chart?
  6. Can you provide an up-to-date group structure chart showing all entities and ownership percentages?
  7. Are the articles of association, shareholders’ agreement, and any side letters current and consistent with each other?
  8. Who sits on the board, and have there been recent changes in directors or company secretary?
  9. Has the company undergone any restructuring, demerger, or change of control in the last five years?
  10. Are there any disputes or unresolved matters relating to share ownership or entitlement?

2. Financial performance and position — questions 11–20

  1. Can you provide audited financial statements for the last three financial years?
  2. What do the most recent management accounts show, and how do they reconcile with the audited figures?
  3. How has revenue moved over the last three years, broken down by product, service, or customer segment?
  4. What adjustments have been made to reported EBITDA, and what is the justification for each?
  5. What is the current level of net debt, and what are the material terms of any financing facilities?
  6. How is working capital managed across the trading cycle, and has it been volatile?
  7. Can you provide a cash flow statement and commentary on any significant swings?
  8. What financial forecasts or budgets exist for the current and next financial year?
  9. What capital expenditure has been committed, and what is planned but not yet contracted?
  10. Are there off-balance-sheet liabilities, guarantees, or contingent obligations not reflected in the accounts?

3. Tax — questions 21–30

  1. In which jurisdictions does the company file tax returns, and are all filings up to date?
  2. Are there any open, ongoing, or recently concluded tax investigations or enquiries?
  3. Is the company registered for VAT, and are there disputes or irregularities in its VAT treatment?
  4. Is PAYE and National Insurance correctly operated for all employees and contractors?
  5. Does the group have transfer pricing arrangements between related entities, and are they documented?
  6. Are there unused tax losses or reliefs, and what conditions apply to their use?
  7. Has the company claimed tax incentives, reliefs, or grants, and are the conditions still being met?
  8. What deferred tax assets or liabilities are recognised, and what assumptions support them?
  9. Are there uncertain tax positions where the company has made a judgement call rather than following clear guidance?
  10. Has the company received correspondence from HMRC or other tax authorities in the last three years?

4. Legal and regulatory compliance — questions 31–40

This is also the area most affected by recent UK legislative change, including a new corporate criminal offence that took effect in September 2025.

  1. What licences, permits, or regulatory approvals does the business hold, and are they all current?
  2. Are there ongoing or recent investigations by a regulator, government body, or law enforcement agency?
  3. What anti-bribery and corruption controls are in place, and when were they last reviewed?
  4. Has the company screened its customers, suppliers, and counterparties against sanctions lists?
  5. Are there competition law concerns, including past infringement findings or ongoing scrutiny?
  6. Can you provide copies of the key compliance policies currently in force?
  7. Have there been compliance breaches in the last three years, and how were they remediated?
  8. What ongoing reporting obligations does the company have to regulators or government bodies?
  9. Has the company received formal or informal correspondence from a regulator in the last three years?
  10. Is the company in scope of the UK’s failure-to-prevent-fraud offence, which took effect on 1 September 2025 and imposes strict liability on large organisations where an associated person commits a specified fraud offence for the organisation’s benefit, and if so, what prevention procedures are in place (SRA)?

5. Commercial matters and material contracts — questions 41–50

  1. Who are the major customers, and what proportion of revenue does each represent?
  2. Is there significant customer concentration, and what would happen if a major customer left?
  3. Who are the key suppliers, and are there dependencies on any single supplier?
  4. Do material contracts contain change-of-control clauses that could be triggered by this transaction?
  5. What termination rights exist in material contracts, and on what notice period?
  6. Are there exclusivity arrangements that restrict who the company can trade with?
  7. How is pricing set, and are there long-term pricing commitments that limit flexibility?
  8. What service levels or performance guarantees apply, and has the company met them?
  9. Are there joint ventures, partnerships, or strategic alliances that affect how the business operates?
  10. Are there disputes, claims, or terminated contracts that could affect ongoing trading relationships?

6. Employment and pensions — questions 51–60

  1. What is the current workforce structure, by headcount, location, and function?
  2. Who are the key employees whose departure would materially affect the business?
  3. Are standard employment contracts used, and do they include appropriate restrictive covenants?
  4. What incentive schemes, bonuses, or equity arrangements are in place for employees?
  5. How many contractors or consultants are engaged, and are they correctly classified?
  6. Are there ongoing or threatened employment disputes, tribunal claims, or grievances?
  7. Has the company undertaken redundancy exercises in the last two years, and were they properly conducted?
  8. What pension arrangements are in place, and are there funding deficits or historic liabilities?
  9. Is any part of the workforce unionised, and are there collective agreements in place?
  10. What retention risks exist among senior management, and are retention arrangements planned?

7. Intellectual property and technology — questions 61–70

  1. What registered trade marks, patents, or designs does the company own, and are renewals up to date?
  2. Is IP ownership clearly documented, particularly for IP created by employees or contractors?
  3. Do employment and contractor agreements include valid IP assignment clauses?
  4. What software licences does the business rely on, and are they properly maintained?
  5. Does the company use open-source software, and has licence compliance been reviewed?
  6. Are there development agreements with third parties affecting ownership of jointly created IP?
  7. Can you describe the core IT architecture and the systems the business depends on daily?
  8. Are any critical systems legacy platforms nearing end of support or replacement?
  9. What technology dependencies exist on third-party vendors or platforms?
  10. Are there ongoing or threatened IP disputes, infringement claims, or licensing disagreements?

8. Cybersecurity and data protection — questions 71–80

43% of UK businesses identified a cyber security breach or attack in the past year, equivalent to roughly 612,000 organisations, per the government’s Cyber Security Breaches Survey. UK GDPR requires notifying the ICO within 72 hours of becoming aware of a notifiable breach, which is why this section carries real weight.

  1. Is the company compliant with UK GDPR and the Data Protection Act 2018 across all processing activities?
  2. Does the company maintain a current data map showing what personal data is held and why?
  3. What information security policies are in place, and when were they last reviewed?
  4. What access controls govern who can view or change sensitive systems and data?
  5. Has the company experienced cyber incidents or data breaches in the last three years?
  6. When was the last penetration test or vulnerability assessment carried out, and what were the findings?
  7. What backup and disaster recovery arrangements protect critical data and systems?
  8. Does the company have a documented incident response plan, and has it been tested?
  9. What due diligence is carried out on data processors and other third parties handling personal data?
  10. Does the company transfer personal data internationally, and what safeguards apply to those transfers?

9. Operations, supply chain, and property — questions 81–90

  1. What are the company’s operating locations, and which are owned versus leased?
  2. What processes are critical to service delivery, and what would happen if they failed?
  3. Are there single points of failure in the supply chain, and what mitigation is in place?
  4. What business continuity plans exist, and have they been tested in the last two years?
  5. What disaster recovery arrangements apply to physical premises and operations?
  6. How is inventory managed, and what is the current stock level relative to demand?
  7. What quality control processes are in place, and have there been recent quality failures?
  8. What property does the company own, and are there charges, restrictions, or disputes affecting title?
  9. What are the key terms of material leases, including break clauses and rent review dates?
  10. What capital investment is required over the next two years to maintain current operations?

10. ESG, litigation, insurance, and enterprise risk — questions 91–100

Organisations with a turnover of £36 million or more must publish an annual modern slavery statement under section 54 of the Modern Slavery Act 2015, and the Home Office updated its statutory guidance in March 2025, raising expectations for the level of detail expected (Latham & Watkins).

  1. What environmental liabilities or historic contamination issues affect the company’s sites?
  2. How does the company measure and report emissions, and what targets has it set?
  3. Does the company meet the £36 million turnover threshold requiring a modern slavery statement, and is its most recent statement aligned with the March 2025 government guidance?
  4. Are there outstanding workplace health and safety matters or enforcement notices?
  5. What governance arrangements oversee ESG risk at board level?
  6. Is the company currently a party to litigation, arbitration, or a formal dispute?
  7. Are there threatened claims that have not yet resulted in formal proceedings?
  8. What insurance policies are in place, and are cover levels adequate for the risks faced?
  9. What insurance claims has the company made in the last three years, and were they settled in full?
  10. Are there material risks not otherwise disclosed that could affect the value or operation of the business?

How to prepare effective DDQ responses

PracticeWhy it matters
Answer the exact question askedA common failure mode is replying with a general company description rather than addressing the specific point raised. If a question asks whether a policy covers subcontractors, the answer needs to say so directly, not describe the policy in general terms.
Link every material answer to evidenceReference the exact contract clause, page number, or document name rather than attaching files through a separate email thread that gets lost later. This keeps the questionnaire itself as the audit trail.
Explain exceptions and qualificationsAvoid answering “yes” to a control question when it only applies to part of the organisation, one subsidiary, or one region. State the boundary of the answer clearly rather than letting it be assumed.
Use one approval processEvery answer should pass through the same three stages: owner, reviewer, approved version. Nothing should go out that hasn’t been checked by someone other than the person who wrote it.

How to manage a due diligence questionnaire in a virtual data room

Running a DDQ manually, through email attachments and shared drives, gets unmanageable once you’re past a handful of questions. A due diligence data room gives the exercise a structured home, with permissions, version control, and a Q&A workflow built around exactly this kind of process.

Due diligence questionnaire software vs a virtual data room

The two categories of tool solve different problems. Dedicated due diligence questionnaire software focuses on reusable answer libraries, automation, scoring, and recurring third-party assessments, useful for a business responding to dozens of similar DDQs a year.

A virtual data room focuses on protected evidence, transaction-specific Q&A, granular permissions, version control, and auditability, which is what a live deal or fund investment actually needs. Some transactions use both: a DDQ platform to draft answers, and a VDR to host the evidence and run the formal Q&A exchange.

Match the DDQ structure to the data room index

Line up the ten DDQ categories in this guide with the numbered folders in the data room index, so each question points to a specific folder rather than a general instruction to “see the data room.” That makes cross-referencing considerably faster for whoever’s reviewing responses.

Run the questionnaire through the VDR Q&A module

Assign questions to workstream owners

Route legal, financial, tax, HR, IT, and ESG questions to the team best placed to answer each one, rather than funnelling everything through a single generalist.

Link answers to supporting documents

Every response should reference the specific VDR folder or file it relies on, so a reviewer can check the underlying evidence without a separate request.

Apply review and approval statuses

Track each answer through draft, under review, approved, released, and follow-up required, so the current state of every question is visible at a glance.

Protect confidential supporting evidence

  • Granular permissions, limiting access by role or workstream
  • Restricted folders for the most sensitive documents
  • Watermarking, to trace where a document originated if it’s shared onward
  • Redaction of information that shouldn’t be disclosed at this stage
  • View-only access, blocking edits to disclosed documents
  • Download controls, limiting who can take a copy offline

Maintain a complete audit trail

An audit trail matters beyond good practice. If a dispute arises after completion, over a warranty claim or an alleged misrepresentation, the record of who asked what and what evidence was disclosed becomes evidence in itself.

A disciplined approach to data room management keeps that trail intact throughout, recording:

  • Who submitted each question
  • Who prepared and approved each answer
  • When supporting evidence was uploaded
  • Which version of a document was actually disclosed
  • When access permissions were changed

Choosing the best VDR for a DDQ-heavy process comes down to whether the platform’s permissions, Q&A workflow, and audit trail are genuinely built for this job, rather than document storage with a data room label attached.

Downloadable due diligence questionnaire templates

Common DDQ mistakes

MistakeWhy it matters
Sending an unmodified generic templateA template built for a private equity fund investment doesn’t fit a supplier review, and forcing it to do both wastes the recipient’s time on irrelevant questions.
Asking duplicate or overlapping questionsAdvisers working from different lists often ask the same thing twice in slightly different words, which slows the recipient down and clutters the review.
Accepting unsupported answersA “yes” without a document reference behind it isn’t evidence, and shouldn’t close out a question on a material point.
Mixing procurement and M&A terminologyCalling a supplier risk assessment a “vendor due diligence questionnaire” without clarifying which sense is meant confuses anyone reading the file later.
Managing responses through emailEmail threads fragment quickly, get forwarded selectively, and rarely capture a clean final version of who said what.
Failing to preserve the final response recordOnce a deal completes, disclosed answers and evidence often matter again, particularly if a warranty or indemnity claim surfaces later, so the record needs to survive well past completion.

Conclusion

A DDQ gives a transaction structure, but it doesn’t replace investigation, judgement, or follow-up. Questions need tailoring to the specific deal, fund, or supplier relationship in front of you, and every material answer needs evidence behind it, not just a confident yes.

Run through a virtual data room, the process gains something a spreadsheet or email chain can’t offer: controlled access, clear ownership, a searchable Q&A record, and an audit trail that still holds up if questions come back months after completion.

Frequently asked questions

What is a DDQ?

A structured set of questions one party sends to another to gather information, test claims, and identify risk before a transaction, investment, or contract goes ahead.

What is the difference between a DDQ and a due diligence checklist?

A DDQ contains specific questions requiring an answer and evidence. A due diligence checklist is an internal tracking tool used to monitor documents, workstreams, and progress toward completion.

Who completes a due diligence questionnaire?

The seller, target, fund manager, or supplier on the receiving end usually coordinates the response, drawing on finance, legal, HR, and IT to answer questions in their area.

How many questions should a DDQ contain?

There’s no fixed number. This guide’s 100-question checklist suits a substantial transaction, but a smaller deal or routine supplier review might reasonably use a subset of 20 to 40 relevant questions.

What documents should support DDQ responses?

Contracts, policies, financial statements, registers, certificates, and reports are the usual sources. Each material answer should reference the specific document it relies on.

Can a DDQ be managed in a virtual data room?

Yes. A VDR’s Q&A module, permissions, and audit trail suit running a DDQ well, particularly where evidence needs to stay controlled and every step needs to be traceable later.