Platform guide

Alternative data due diligence questionnaires, question by question

The FISD questionnaire topic by topic, with the evidence each question calls for, and how Neudata and Eagle Alpha handle questionnaires once vendors have answered them.

Updated 5 October 20267 min read

A due diligence questionnaire, or DDQ, is one of the documents through which a fund's compliance team decides whether the fund may use a vendor's data at all. This guide walks through the standard questionnaire published by FISD topic by topic, says what evidence each topic calls for, and shows how a company-data vendor that collects from public sources can answer the sourcing, MNPI, personal data and web collection questions from documents it already publishes. Every statement about FISD, Neudata and Eagle Alpha was checked against the pages linked here on 4 October 2026.

Fokals is delivered direct, by REST API and as bulk files, and a fund's compliance team receives its documents with the data. The Fokals documents appear below as a worked example of how a company-data vendor answers; a vendor answers each buyer's questionnaire for itself.

Which questionnaires exist

FISD is the Financial Information Services Division of the Software & Information Industry Association, described on the SIIA site as a forum for the financial information industry. Its Alternative Data Council, founded in January 2019, publishes standards that it says are entirely voluntary. The council's page lists a compliance DDQ, a version that adds questions on generative AI, a shorter DDQ for trial data and a DDQ for expert network research providers dated May 2026. Beside them sit a vendor tear sheet for assessing a dataset quickly and a set of notes on web data collection. The page also lists Eagle Alpha and Neudata among the tools and services that follow all or part of the standards.

Neudata and Eagle Alpha work with vendors' answers. Neudata's compliance page describes a store of risk assessments and questionnaires that vendors have supplied, with answers flagged for follow-up, and daily monitoring of vendors for litigation, regulation and news. Its March 2021 press release described collecting questionnaires from vendors and on demand, storing each for client access and updating them periodically. Eagle Alpha's Surveyor page describes a workflow that tracks questionnaires, flags risks when answers change and holds records for examinations by the Securities and Exchange Commission, and its vendor page says a vendor presents its data in a standard format using a questionnaire and metadata.

What the questionnaire is trying to establish

The preface of FISD's DDQ says investment managers use data to inform trading in public and private securities, so they must weigh securities law, and that the answers will likely be material to their decision. It names five kinds of information a manager does not want to receive or build on: material non-public information; information held under a duty of confidence; information the vendor is barred from disclosing; information gained through misappropriation, deception, breach of law or breach of duty; and personal information.

It also asks for documents with the answers: a description of the data, a data dictionary or schema, a small sample of under 100 rows from more than three months earlier, the terms of any upstream contracts that show the right to resell or license the data, and consent terms where data comes from individuals or their devices. Fokals sends sample data for the companies a buyer names on request, with the data dictionary and methodology, and every observation in it carries its dated record.

Sourcing questions

The product section asks whether the vendor collects the data itself or buys it, and for terms that show a right to resell. It gives a checklist of collection methods that runs from web scraping, apps and third-party aggregators to government sources, financial transactions, satellites and surveys. It asks who provides the underlying information, what diligence the vendor does on whether those suppliers may supply it, whether contracts exist with primary providers, and whether a dependency such as an expiring upstream licence or a change in a website's terms could affect the buyer's use.

How a company-data vendor answers. Fokals collects the data itself, from first-party company sources and public records, and processes it in-house: what companies publish on their own websites and careers pages, what they announce and what they file. The sourcing statement sets out the inputs. On the checklist that means web collection, which the questionnaire defines to include crawling, and public sources.

MNPI questions

Three questions ask whether the data contains or may derive from MNPI, whether the vendor's other activities expose it to MNPI, and whether any of the data is otherwise confidential, for example because the licence sits under a non-disclosure agreement. A further question asks what diligence the vendor performs and whether it has used reasonable best efforts to confirm that inputs did not come from a breach of duty, a breach of contract or deception.

How a company-data vendor answers. The sourcing statement says each input is public when it is seen: company publications and public records. The evidence is in the data, because every record names its source and the time it was observed. A compliance team can test the claim by opening the source link of a sample of rows in Job Postings and Company News and confirming that each is a public page, a feed item or a regulatory disclosure.

Personal data questions

The questionnaire asks whether the vendor or its sources collect covered personal information, meaning anything that could identify or be associated with a natural person, and how the vendor knows. If so, an appendix asks whether people were told and consented to commercialisation, for the evidence, whether the data is de-identified and what diligence is done on upstream sources. Another appendix asks whether the vendor monitors browsing habits or processes location or mobile device data.

How a company-data vendor answers. Fokals data is company-level throughout. A leadership change is stored as the role concerned and the direction. A job description is cleaned of email addresses, phone numbers and personal profile links before it is stored. The free-text fields that are delivered, such as the title and excerpt of an item in Company News, hold the company's own published words, so read a sample before deciding how your own policy treats them. Intent is built from what a company itself does in public, so the browsing, cookie and device questions of the appendix do not arise.

Web collection conduct

For a vendor that crawls, the web scraping appendix is the longest part. It asks whether the vendor uses proxies, CAPTCHA solvers or third-party scraping providers, whether it has considered published web collection guidelines and how it follows them, whether it reviews the terms of the sites it reads, whether it reads pages that robots.txt disallows, whether the sites can identify and contact it, whether it uses several or anonymised IP addresses or onion routing, and whether it reads sites that require a tick-box, a login or a CAPTCHA.

FISD's separate notes cover terms of service, proxies, request volume, robots.txt, copyright, privacy, competition, CAPTCHAs and cease and desist letters. The volume note lists delays between requests, throttling, limits on concurrent requests and following a crawl-delay directive. The proxy note recommends that site owners can reach the collector, directly or through the operator of the proxy. The robots.txt note treats the file as a request that, absent other obligations, a collector may choose to honour, and adds that a collector that looks for it and follows it can point to that as respect for the operator's wishes.

The Fokals documents answer these questions in full. Collection reads public company pages and public records, follows the opt-out instructions that site owners publish, and identifies itself to the sites it reads. The crawler page explains what the collector reads and how an operator can opt out, and the sourcing statement and methodology set out the conduct a compliance team asks about. Company questions, such as legal staffing, outside counsel and any claims or orders in the past five years, are answered by each vendor in its own questionnaire.

Generative AI questions

The version of the FISD questionnaire with generative AI questions adds an appendix. It asks which tools are used to produce the data, whether they are public or internal versions, how they are used, whether personal data, MNPI or confidential information is put into them and under what controls, whether outputs are reviewed for accuracy and bias, and how the tools were trained. A vendor that labels records with a model answers from its labelling documentation. The Fokals methodology records that labels and scores are produced under named, frozen versions and that label accuracy is graded by hand for each version.

Keeping answers current

An answer set is dated. FISD's form asks for the effective date of the answers, and Neudata's April 2023 article argues for diligence triggered by events, not only at signature and renewal. For a vendor that versions its data, the version is a natural trigger.

Each Fokals label and score belongs to a named, frozen version, a change that breaks compatibility arrives as a new version announced at least 90 days ahead, and the methodology carries a version number and an effective date. When the version or the date changes, read the answers again. The wider tests a scout applies are in what alternative data scouts look for, and the compliance page lists the public documents.

Frequently asked questions

What is an alternative data due diligence questionnaire?

A due diligence questionnaire is a structured list of questions that a fund sends a data vendor before licensing its data. It covers where the data comes from, whether it contains material non-public information or personal data, how it is collected from websites or other sources, and what rights the vendor has to sell it. The vendor answers and attaches documents such as a data dictionary and a small sample.

Is there a standard DDQ for alternative data?

Yes. FISD's Alternative Data Council, founded in 2019, publishes a compliance questionnaire, a version with generative AI questions added, a shorter one for trial data and one for expert network research providers, and its page says adoption is voluntary. Neudata and Eagle Alpha both describe services that collect and monitor vendors' questionnaires.

What documents should a vendor send with a DDQ?

The FISD questionnaire asks for a document describing the data, a data dictionary or schema, a sample of fewer than 100 rows from more than three months earlier, terms from upstream contracts that show the right to resell or license the data, and consent terms where data comes from individuals or their devices. A vendor sends those that exist for its data.

What does a DDQ ask about web scraping?

The FISD appendix asks whether the vendor uses proxies, CAPTCHA solvers or third-party scraping providers, and whether it reads pages that robots.txt disallows. It also asks whether sites can identify and contact the crawler, whether the vendor uses anonymised or multiple IP addresses, whether it reads sites that require a login, a tick-box or a CAPTCHA, and whether it reviews site terms and has considered published guidelines.

How often should a vendor's DDQ be updated?

The FISD questionnaire asks for an effective date on its answers but sets no refresh interval. Neudata's April 2023 article argues for diligence triggered by events, not only at signature and renewal, and Eagle Alpha's Surveyor sends alerts when a questionnaire changes. A new methodology or label version from the vendor is a reasonable trigger to read the answers again.

What this page says about the products it names was checked against their public documentation on 4 October 2026. Product and company names are trademarks of their owners. Fokals is not affiliated with them or endorsed by them.