Corporate & Financial
Basic corporate details, ownership, financial health indicators, insurance coverage, and bankruptcy or litigation history required to assess business continuity risk and financial stability.
A VDDQ reduces onboarding risk by documenting a vendor’s controls and liabilities, supports regulatory compliance, and centralizes information for contract negotiations and audits. It creates consistent evaluation criteria across vendors and preserves evidence of due diligence decisions for legal and audit teams.
Multiple teams use VDDQs to assess vendors before contracting or at renewal.
Responses should be consolidated and retained by the owning department for audit and contract management.
An individual with corporate authority (C-level, VP, or delegated signatory) who can certify answers on behalf of the vendor and bind the organization to the representations in the questionnaire.
A named security or privacy lead who can verify technical responses, confirm control implementations, and supply supporting evidence such as SOC 2 or penetration test reports.
Basic corporate details, ownership, financial health indicators, insurance coverage, and bankruptcy or litigation history required to assess business continuity risk and financial stability.
Information security practices, encryption standards, access control, vulnerability management, and third-party testing such as penetration tests or SOC 2 reports to evaluate cyber risk.
Data types processed, storage locations, data transfer mechanisms, data retention policies, and privacy program details including GDPR, CCPA, and HIPAA where applicable.
Business continuity, disaster recovery plans, system uptime commitments, and backup processes to measure service availability and recovery capabilities.
Regulatory certifications, export controls, sanctions screening, licensing status, and contractual exceptions that affect compliance and enforceability.
Names of critical subcontractors, flow-down obligations, and controls over downstream providers to identify concentration or cascading risks.
| Field | Configuration |
|---|---|
| Required Fields | Set key fields mandatory with validation |
| Attachments | Accept PDF, DOCX; require filename pattern |
| Authentication | Use email + SMS code or stronger |
| Audit Trail | Capture IP, timestamp, and actions |
Choose platforms that preserve audit logs, support attachments, and meet your authentication needs.
Ensure the selected delivery method aligns with compliance needs such as HIPAA, contractual terms, and evidence retention policies.
Request responses within 15 business days to prevent onboarding delays
Require supporting documents within the same response period
Schedule a full questionnaire refresh yearly for critical vendors
Require vendor to notify buyer within 30 days of material changes
Set internal SLA for review within 10 business days of receipt
Buyer sends questionnaire and sets due date
Vendor completes questionnaire and uploads evidence
Security and legal validate responses
Authorized signer certifies and procurement closes review
| Criteria | VDDQ | RFI | Security Questionnaire | Contract Addendum |
|---|---|---|---|---|
| Primary Purpose | risk assessment | general info | technical controls | contract terms |
| Detail Level | high | low | high | medium |
| Binding Status | non-binding | non-binding | non-binding | binding |
| Typical Use | onboarding | sourcing | security review | contract negotiation |
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies | Varies | Varies | Varies |
| Bulk Send | Yes | Yes | Yes | Yes | Varies |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | Varies | Varies |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies | Varies | Varies |
A mid-market investment firm standardized vendor questionnaires across portfolios to reduce variance in answers
A healthcare provider required BAAs and SOC 2 reports for vendors handling PHI