Glossary

Due diligence questionnaire (DDQ)

The questionnaire a buyer sends a data vendor to check sourcing, rights, personal data and MNPI. What it asks, which standard forms exist and how to answer with documents.

Updated 5 October 20262 min read

A due diligence questionnaire (DDQ) is a structured list of questions that a buyer sends to a vendor, manager or counterparty before a contract, to check how it operates and what risks it carries. For alternative data it covers sourcing, the right to use the data, personal data and material non-public information.

What a data DDQ asks

  • Sourcing: what the sources are, how they are collected and whether any login, paywall or confidential feed is used.
  • Rights: whether the vendor may collect and sell the data, and under what terms of use.
  • Personal data: whether any is collected, and how it is removed.
  • Material non-public information: whether any input comes from insiders or under confidentiality.
  • Controls: how definitions change, how errors are corrected and how much notice a customer gets.
  • Delivery: formats, cadence and what happens if a feed stops.

Standard forms

FISD, the Financial Information Services Division of the Software & Information Industry Association, runs an Alternative Data Council that publishes a compliance due diligence questionnaire for alternative data and a shorter one for trial data. Funds also use forms of their own, so a vendor can expect to answer in writing, and more than once.

Answering with documents

A complete answer cites a document the vendor publishes and keeps current: a sourcing statement, a methodology and a data dictionary. Buyers file the completed questionnaire with the documents it cites, and ask again when sourcing or definitions change.

In Fokals data

Fokals publishes a sourcing and compliance statement, a methodology and a data dictionary, and the compliance page brings them together. They state that sourcing is first-party company sources and public records, that processing is in-house, that delivery is at company level and that every input is public when observed.

Each record carries the time it was observed. Label and score versions are frozen, and a breaking change comes with at least 90 days' notice, which answers the controls questions with a stated policy.

Frequently asked questions

What does a data vendor due diligence questionnaire ask?

It asks where the data comes from, how it is collected, whether the vendor has the right to collect and sell it, whether any personal data or material non-public information is involved, how definitions and errors are managed, and how the data is delivered and secured. Buyers use the answers to decide whether a dataset can be used in investment decisions.

Is there a standard alternative data DDQ?

There is no single mandatory form, but the FISD Alternative Data Council publishes a shared compliance questionnaire, with a shorter version for trial data. Many funds start from it and add their own questions. Keep your answers in a form you can reuse, and date them.

How is a DDQ different from a security questionnaire?

A security questionnaire tests a vendor's technical controls, such as access, encryption and incident response. A DDQ is wider. It also covers sourcing, legal rights, compliance procedures and, for data vendors, material non-public information. Buyers often send both, and some questions overlap.