Scrutineer.ai
All posts
Comparison

Best DDQ software: 8 due diligence tools

Eight DDQ tools compared on what each is built for, where its answers come from and which publish a price, plus the 57 questions libraries get wrong.

By the Scrutineer team

September 2026 · 8 min read

Try it while you read

No account, nothing to install.

Pick a framework or a vendor and run a scrutiny. You get per-control statuses, the evidence behind each one, and a prioritized gap list.

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

The best DDQ software depends on which half of the questionnaire is actually costing you time. Responsive, Loopio and Ontra are the strongest answer libraries, and a library is the right tool for firm facts, fund terms and narrative. For the information security, compliance and business continuity sections, a library is the wrong shape, because those answers are claims about controls that change while the library keeps repeating the last approved sentence.

Below is what each of the eight tools in this category is built for, where its answers come from, whether it publishes a price, and where it stops. Then the parts of a due diligence questionnaire that no library can keep honest.

What is the best DDQ software?

There is no single answer, because DDQ tools split into two jobs that look identical on a feature list. One job is retrieving and re-serving text your firm has already approved. The other is producing an answer about the current state of a control. Almost every product on the market does the first well and treats the second as a special case of the first.

The split matters more than any feature comparison, so the table runs on it.

ToolBuilt forWhere the answers come fromPublishes pricingWhere it stops
ResponsiveEnterprise RFP, RFI and DDQ response teams working at volumeA governed answer library, with AI drafting layered over itNo, sales gatedThe library is exactly as current as the last person who maintained it
LoopioMid-market and enterprise proposal and response teamsAnswer library with review cycles and subject matter expert assignmentNo, sales gatedContent maintenance becomes a standing job somebody has to own
OntraPrivate markets fund managers, investor relations and capital formationA precedent library of approved investor answers, plus AI first draftsNo. Quoted by module, entity range and AI creditsBuilt around the fundraising cycle rather than around a control record
DiligenceVaultBoth sides: asset managers on Pulse, allocators on SparkStructured content library with ILPA and AIMA templatesYes, tiers are on its pricing pageInvestment diligence workflow, which is not the same thing as security evidence
ArphieTeams that want AI-native drafting with visible reasoningAI over connected documents and past answer historyNoA stale source document still produces a confident, stale answer
AutoRFP.aiSmaller teams that want AI and integrations without tier gatingAI drafting over an answer libraryNo, though it positions on all-inclusive tiersSame library dependency as the larger platforms
SiftHubB2B SaaS presales and solutions engineeringGeneration from connected live knowledge rather than a static libraryNoTuned to the sales motion. Connected knowledge is not a tested control
ScrutineerThe security, compliance, continuity and third-party sectionsThe control record: mapped controls, evidence and the date each was last testedYes, in fullDoes not answer strategy, track record or fund terms, and does not issue attestations

One note on the pricing column, because it is the column buyers care about and the one that is mostly empty. DiligenceVault is the outlier that publishes tiers: Pulse Core at 300 dollars a month and Pulse Growth at 750 for asset managers, Spark Digital at 1,000 and Spark Pro at 3,000 for allocators, with enterprise quoted (checked on its pricing page in September 2026, and worth confirming before you budget). Everyone else is sales gated. Third-party reviews float annual figures for Responsive and Loopio in the low five figures, but those come from competitors' comparison posts rather than from the vendors, so treat them as rumor and ask.

What is the difference between a DDQ and an RFP?

An RFP asks you to win the work. A DDQ asks you to prove you are safe to do business with. That difference decides what good writing looks like in each. An RFP is scored on fit, price and capability, so a persuasive answer is a better answer. A DDQ is a risk document scored on accuracy and evidence, and a persuasive answer with nothing behind it is the worst outcome available, because it becomes a representation somebody can hold you to.

This is why tools built primarily for proposals struggle on the diligence half. They are optimized to make the answer read well. Diligence reviewers are optimized to find the one that does not hold up.

How long does it take to complete a DDQ?

Published estimates put a first draft of a 100 question DDQ at roughly 4 to 5 hours of writing, and the full coordinated effort across finance, legal, IT and compliance at 15 to 40 hours. Calendar time is usually 2 to 4 weeks. Almost none of that is typing. It is waiting on the person who knows when the last penetration test ran, and on the person who can confirm which cloud providers are in scope this quarter.

That is the real reason DDQ automation sells. It is also why automation that only speeds up the typing produces a smaller gain than the demo suggests.

The ILPA DDQ, and the 57 questions that age

The ILPA Due Diligence Questionnaire 2.0 is the closest thing private markets have to a standard, and in 2026 it is still the November 2021 edition. ILPA has added material around it, a DEI Monitoring Questionnaire in 2023 and a PRI Climate Module released with the PRI and the iCI in 2025, but the core document has not been revised.

Counting the numbered items in the published PDF gives 422 questions across 20 sections, plus eight appendices of templates. Section 18, which covers cyber and information security, business continuity and disaster recovery, is 27 of them. Section 13, compliance and internal controls, is another 30. So about one question in seven is a control question.

Those 57 behave differently from the other 365. Section 4 asks about investment strategy, and the answer reads the same in March and in November. Question 18.6.1 asks you to describe your penetration testing including its frequency, and that answer stops being true the moment the testing schedule slips. Question 18.15 asks whether sensitive data is encrypted at rest and in transit. Question 18.13 and 18.14 ask whether your cloud data and your third-party-held data are subject to independent security assessments, which is a question about a list that changes every time procurement signs something.

An answer library treats all of these the same way it treats your office addresses. It stores the approved sentence and re-serves it. It has no signal that the key rotation job has been failing for six weeks, or that the pen test scheduled for June never happened. The failure mode is not a wrong answer, which someone would catch on review. It is a sentence that was genuinely true in 2024, sent out in 2026 with full confidence, to a counterparty who will attach it to an agreement.

Do you need DDQ software if you already answer security questionnaires?

You do not necessarily need a second tool, but you do need the two to share one source of evidence. The control questions in a DDQ ask for the same underlying facts as the security domains of a SIG or the control set of a CAIQ. If they are answered out of two separate libraries owned by two separate teams, the wordings drift, and a diligence reviewer comparing your DDQ against your security documentation will find the difference before you do.

The practical fix is to answer the control questions once, from mapped evidence, and let both documents render from that. This is what security questionnaire automation does for the controls-only case, and what due diligence questionnaire software has to do for the wider document. The overlap is large enough that maintaining it twice is a choice, not a requirement.

How much does DDQ software cost?

Almost nobody publishes, so the useful answer is the drivers rather than a number. Price in this category moves on five things: how many seats you need, how many questionnaires you process a year, whether AI drafting sits on the entry tier or behind an upgrade, how many integrations you need, and whether a managed content service is bundled in. That last one is the biggest swing, because it converts a software line into a services line.

Watch for the tools that meter AI usage as credits, because usage grows with exactly the thing you bought the tool to handle. A meter that charges more every time your diligence volume goes up is billing you for success.

What a DDQ tool cannot do for you

Three things, and they are worth knowing before the demo.

It cannot verify a performance table. Track record answers come out of the fund accounting system as of a stated date, and a recycled table is a compliance problem rather than a shortcut. No library should be allowed near that section.

It cannot make an unattested control attested. A SOC 2 Type II report answers a good part of section 18, but not all of it. It does not cover breach history over the last five years, penetration testing frequency, portfolio company security practices, or the specific cloud and third-party assurance list the DDQ asks you to enumerate. If you are still building that evidence base, SOC 2 compliance software is the upstream problem to solve first, because the DDQ answer is downstream of the control.

It cannot approve the answer. Every serious DDQ response is a representation, so a named human signs off, and the documents that follow the questionnaire still get circulated for signature on the resulting agreements. What automation should buy you is the distance from a blank field to a cited draft, plus a flag on every answer whose underlying control has moved since anyone last looked at it.

How to choose between them

Start by counting where your last three DDQs actually stalled. If the delay was in re-writing firm narrative for the fourth investor this quarter, buy the strongest answer library you can afford and staff the content maintenance properly, because an unmaintained library is worse than no library. Ontra and DiligenceVault are the two shaped specifically for private funds; Responsive and Loopio are the general-purpose heavyweights; Arphie, AutoRFP and SiftHub are the AI-native challengers aimed at smaller teams.

If the delay was waiting on security, compliance and continuity answers, more library will not help, because the bottleneck is not retrieval. It is that nobody can confirm the current state of the control without going and looking. That is a questionnaire evidence problem, and it is solved by holding the controls and their test dates in one place so the answer is a lookup rather than an investigation.

Most firms above a certain size end up needing both, run off one shared set of control facts. The mistake is buying one and assuming it covers the other.

See Scrutineer scrutinize your posture

Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.

Scrutinize on real evidence, not stale spreadsheets

Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and scores vendor risk continuously, and returns a readiness report with a prioritized gap list. AI scrutinizes, you decide.

Automated evidence · Per-control statuses · Prioritized gap list

Mapped controls · evidence-linked rationale for every status · an accredited auditor issues the attestation.