Establishing secure connection…Loading editor…Preparing document…

Vendor Due Diligence Questionnaire

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

VENDOR DUE DILIGENCE QUESTIONNAIRE AND AGREEMENT

WHEREAS Client Name: (hereafter "Client") seeks to retain or continue the services of Vendor Name: (hereafter "Vendor"); and

WHEREAS the Client requires assurance regarding Vendor's legal, financial, operational and compliance posture prior to entering into or renewing contractual arrangements; and

WHEREAS Vendor represents and warrants that the responses provided in this Questionnaire are true, complete and accurate, and understands that such responses will be relied upon by the Client in connection with contractual negotiations and ongoing relationship management.

1. Vendor Identification

2. Scope of Work

Describe the products, services or deliverables Vendor will provide under any contemplated agreement. Include key milestones, deliverables and service levels.

3. Corporate & Ownership

Is the Vendor publicly traded?

4. Compliance & Regulatory

Anti-Bribery/Anti-Corruption policy in place?

Has the Vendor or any officer been subject to regulatory enforcement, criminal conviction, or material civil penalty in the past 10 years?

5. Data Protection & Security

Does Vendor process personal data on behalf of Client?

Does Vendor transfer data across national borders?

6. Insurance

7. Subcontracting & Third Parties

Will Vendor engage subcontractors in the performance of services?

8. Business Continuity & Incident Response

Does Vendor maintain a documented business continuity or disaster recovery plan?

9. Financial & Reputation

Has the Vendor filed for bankruptcy, been insolvent, or had material debt restructuring in the past 5 years?

10. Conflicts, Sanctions & Litigation

Are any principals, officers or the entity subject to trade sanctions, watchlists or export controls?

11. References

12. Payment Terms

Agreed fee or estimated value of services: $

Late payment charge (percentage per month)

Payment Terms Clause: Vendor shall submit invoices in accordance with the agreed schedule. Client will pay undisputed amounts within the agreed payment period. Disputed amounts may be withheld pending resolution, but undisputed portions must be paid. Late payments shall accrue interest at the rate specified above, subject to applicable law.

13. Term and Termination

Term Start Date:    Term End Date:

Either party may terminate for convenience upon days' prior written notice. Termination for material breach shall be effective upon written notice if the breach is not remedied within thirty (30) days following receipt of written notice, unless a shorter remedy period is required by applicable law.

14. Confidentiality

Each party shall treat as Confidential Information all non-public information disclosed by the other party in connection with the relationship. Confidential Information shall not be used except for performance under the agreement and shall not be disclosed to third parties except to those employees, agents or subcontractors who have a need to know and who are bound by obligations of confidentiality no less protective than those set out herein. Confidential obligations shall survive termination for a period of five (5) years, or longer where such information constitutes trade secrets under applicable law.

15. Governing Law

This Agreement and any dispute arising out of or relating to it shall be governed by the laws of:

16. Entire Agreement

This Questionnaire, together with any subsequently executed agreement between the parties and any referenced schedules, constitutes the entire agreement with respect to Vendor due diligence and supersedes all prior communications, representations or agreements, whether oral or written, concerning the subject matter hereof. Any amendment must be in writing and signed by authorized representatives of both parties.

17. Representations and Certification

By signing below, Vendor certifies that all information provided in this Questionnaire is true, complete and accurate to the best of its knowledge, that the signatory is authorized to bind Vendor, and that Vendor will promptly notify Client of any material change to the information provided. Vendor acknowledges that materially false statements or omissions may constitute breach and may provide grounds for termination and legal remedies.

Client — Printed Name:

By:

Date:

Vendor — Printed Name:

By:

Date:

Enter text✕

What a Vendor Due Diligence Questionnaire Is and When It Applies

A Vendor Due Diligence Questionnaire (VDDQ) is a structured questionnaire used by organizations to evaluate a third party’s operational, security, compliance, financial, and contractual posture before or during a supplier relationship. Typical VDDQs collect information about governance, data handling and protection, regulatory compliance, insurance, subcontractors, continuity planning, and incident history. The completed VDDQ helps procurement, legal, security, and vendor risk teams decide whether to onboard, continue, or remediate issues with a supplier and creates a documented audit trail for future reviews and compliance obligations.

Why a Vendor Due Diligence Questionnaire Matters

A VDDQ reduces onboarding risk by documenting a vendor’s controls and liabilities, supports regulatory compliance, and centralizes information for contract negotiations and audits. It creates consistent evaluation criteria across vendors and preserves evidence of due diligence decisions for legal and audit teams.

Why a Vendor Due Diligence Questionnaire Matters

Who Typically Completes or Reviews a VDDQ

Multiple teams use VDDQs to assess vendors before contracting or at renewal.

  • Procurement teams responsible for vendor selection and contract terms.
  • Information security teams evaluating controls, encryption, and incident response.
  • Compliance and legal teams reviewing regulatory obligations and contract clauses.

Responses should be consolidated and retained by the owning department for audit and contract management.

Who Can Sign and Certify the VDDQ

Authorized Officer

An individual with corporate authority (C-level, VP, or delegated signatory) who can certify answers on behalf of the vendor and bind the organization to the representations in the questionnaire.

Security Contact

A named security or privacy lead who can verify technical responses, confirm control implementations, and supply supporting evidence such as SOC 2 or penetration test reports.

Core Sections to Include in a Professional VDDQ

A complete questionnaire groups questions into functional areas to make review efficient and to align evidence requirements with internal risk thresholds.

Corporate & Financial

Basic corporate details, ownership, financial health indicators, insurance coverage, and bankruptcy or litigation history required to assess business continuity risk and financial stability.

Security & Controls

Information security practices, encryption standards, access control, vulnerability management, and third-party testing such as penetration tests or SOC 2 reports to evaluate cyber risk.

Privacy & Data Handling

Data types processed, storage locations, data transfer mechanisms, data retention policies, and privacy program details including GDPR, CCPA, and HIPAA where applicable.

Operational Resilience

Business continuity, disaster recovery plans, system uptime commitments, and backup processes to measure service availability and recovery capabilities.

Compliance & Legal

Regulatory certifications, export controls, sanctions screening, licensing status, and contractual exceptions that affect compliance and enforceability.

Subcontractors & Supply Chain

Names of critical subcontractors, flow-down obligations, and controls over downstream providers to identify concentration or cascading risks.

Required Information Fields at a Glance

Vendor Legal Name: Full legal entity name
EIN / Tax ID: Employer identification number
Primary Contact: Name, role, phone
Service Description: Scope of services
Data Types Processed: PII, PHI, financial
Certifications: SOC 2, ISO 27001

Step-by-Step: How to Complete and Return a VDDQ

Use this sequential checklist to prepare, complete, and submit a Vendor Due Diligence Questionnaire accurately.

  • 01
    Gather Documents: Collect SOC reports, insurance, policies, and attachments.
  • 02
    Assign Owner: Designate a single respondent to coordinate answers.
  • 03
    Complete Fields: Answer each question clearly and attach evidence.
  • 04
    Certify & Submit: Authorized officer signs and returns to requester.

Typical Electronic Workflow for a VDDQ

A standard eSubmission workflow reduces friction and preserves an audit trail of responses and approvals.

  • Request: Buyer issues questionnaire and sets due date.
  • Respond: Vendor fills fields and uploads attachments.
  • Review: Internal teams validate responses and evidence.
  • Approve: Authorized signer certifies answers for final acceptance.

Recommended Digital Configuration for VDDQ Workflows

Configure the digital workflow to enforce version control, required fields, and signer authentication to reduce manual follow-up.

Field Configuration
Required Fields Set key fields mandatory with validation
Attachments Accept PDF, DOCX; require filename pattern
Authentication Use email + SMS code or stronger
Audit Trail Capture IP, timestamp, and actions

Technical Options for Sharing and Signing the VDDQ

Choose platforms that preserve audit logs, support attachments, and meet your authentication needs.

  • Email Link: Simple distribution via secure signing link
  • Portal Upload: Vendor submits via secure vendor portal
  • In-Person / Notary: Used when notarization or witnessed certification is required

Ensure the selected delivery method aligns with compliance needs such as HIPAA, contractual terms, and evidence retention policies.

Typical Timelines and Deadlines for VDDQ Responses

Organizations often set expectations for completion and follow-up responses to control onboarding timelines and mitigate gaps.

Initial Response Window:

Request responses within 15 business days to prevent onboarding delays

Evidence Submission:

Require supporting documents within the same response period

Annual Reassessment:

Schedule a full questionnaire refresh yearly for critical vendors

Interim Updates:

Require vendor to notify buyer within 30 days of material changes

Review SLA:

Set internal SLA for review within 10 business days of receipt

Key Milestones in the VDDQ Review Process

A milestone timeline clarifies responsibilities and expected handoffs during the evaluation.

01

Request Issued

Buyer sends questionnaire and sets due date

02

Vendor Response

Vendor completes questionnaire and uploads evidence

03

Internal Review

Security and legal validate responses

04

Final Approval

Authorized signer certifies and procurement closes review

Common Mistakes to Avoid When Preparing a VDDQ

  • Providing vague or incomplete answers that require repeated follow-up and slow onboarding.
  • Uploading undated or unsigned supporting documents which cannot prove current controls or coverage.
  • Failing to identify and document subcontractors or cloud providers introduces undisclosed supply chain risk.
  • Not aligning question scopes to contractual obligations, causing mismatches between representations and the contract.

Risks and Consequences of Inaccurate or Incomplete Responses

Contractual Risk: Indemnity exposure
Regulatory Risk: Fines or enforcement actions
Operational Risk: Service interruption
Reputational Risk: Loss of trust
Insurance Gaps: Claim denials
Termination: Contract cancellation

How a VDDQ Compares with Similar Vendor Documents

Compare common vendor information requests to choose the right instrument for risk assessment and contracting.

Criteria VDDQ RFI Security Questionnaire Contract Addendum
Primary Purpose risk assessment general info technical controls contract terms
Detail Level high low high medium
Binding Status non-binding non-binding non-binding binding
Typical Use onboarding sourcing security review contract negotiation

eSignature Pricing Comparison for Managing VDDQs

Basic pricing and feature differences influence cost and scalability when sending VDDQs at volume; signNow is listed first for neutral comparison.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies Varies Varies Varies
Bulk Send Yes Yes Yes Yes Varies
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes Varies Varies
Envelope Cap No cap 100 envelopes/user/year Varies Varies Varies

Practical Examples of Vendor Due Diligence Use

Real-world examples show how VDDQs reduce onboarding time and surface material issues early.

Optica Ventures

A mid-market investment firm standardized vendor questionnaires across portfolios to reduce variance in answers

  • Focused on security and insurance controls
  • The result was faster reviews and a centralized repository for audit evidence that simplified quarterly compliance checks.

Fertility Centers of Illinois

A healthcare provider required BAAs and SOC 2 reports for vendors handling PHI

  • Used a checklist to validate evidence
  • This ensured HIPAA alignment and provided a defensible audit trail for regulators and internal risk teams.

Frequently Asked Questions About Vendor Due Diligence Questionnaires

Answers to common operational and legal questions about completing, validating, and storing VDDQs.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users