Best DDQ software: 8 due diligence tools
Eight DDQ tools compared on what each is built for, where its answers come from and which publish a price, plus the 57 questions libraries get wrong.
By the Scrutineer team
September 2026 · 8 min read
Try it while you read
No account, nothing to install.
Pick a framework or a vendor and run a scrutiny. You get per-control statuses, the evidence behind each one, and a prioritized gap list.
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
The best DDQ software depends on which half of the questionnaire is actually costing you time. Responsive, Loopio and Ontra are the strongest answer libraries, and a library is the right tool for firm facts, fund terms and narrative. For the information security, compliance and business continuity sections, a library is the wrong shape, because those answers are claims about controls that change while the library keeps repeating the last approved sentence.
Below is what each of the eight tools in this category is built for, where its answers come from, whether it publishes a price, and where it stops. Then the parts of a due diligence questionnaire that no library can keep honest.
What is the best DDQ software?
There is no single answer, because DDQ tools split into two jobs that look identical on a feature list. One job is retrieving and re-serving text your firm has already approved. The other is producing an answer about the current state of a control. Almost every product on the market does the first well and treats the second as a special case of the first.
The split matters more than any feature comparison, so the table runs on it.
| Tool | Built for | Where the answers come from | Publishes pricing | Where it stops |
|---|---|---|---|---|
| Responsive | Enterprise RFP, RFI and DDQ response teams working at volume | A governed answer library, with AI drafting layered over it | No, sales gated | The library is exactly as current as the last person who maintained it |
| Loopio | Mid-market and enterprise proposal and response teams | Answer library with review cycles and subject matter expert assignment | No, sales gated | Content maintenance becomes a standing job somebody has to own |
| Ontra | Private markets fund managers, investor relations and capital formation | A precedent library of approved investor answers, plus AI first drafts | No. Quoted by module, entity range and AI credits | Built around the fundraising cycle rather than around a control record |
| DiligenceVault | Both sides: asset managers on Pulse, allocators on Spark | Structured content library with ILPA and AIMA templates | Yes, tiers are on its pricing page | Investment diligence workflow, which is not the same thing as security evidence |
| Arphie | Teams that want AI-native drafting with visible reasoning | AI over connected documents and past answer history | No | A stale source document still produces a confident, stale answer |
| AutoRFP.ai | Smaller teams that want AI and integrations without tier gating | AI drafting over an answer library | No, though it positions on all-inclusive tiers | Same library dependency as the larger platforms |
| SiftHub | B2B SaaS presales and solutions engineering | Generation from connected live knowledge rather than a static library | No | Tuned to the sales motion. Connected knowledge is not a tested control |
| Scrutineer | The security, compliance, continuity and third-party sections | The control record: mapped controls, evidence and the date each was last tested | Yes, in full | Does not answer strategy, track record or fund terms, and does not issue attestations |
One note on the pricing column, because it is the column buyers care about and the one that is mostly empty. DiligenceVault is the outlier that publishes tiers: Pulse Core at 300 dollars a month and Pulse Growth at 750 for asset managers, Spark Digital at 1,000 and Spark Pro at 3,000 for allocators, with enterprise quoted (checked on its pricing page in September 2026, and worth confirming before you budget). Everyone else is sales gated. Third-party reviews float annual figures for Responsive and Loopio in the low five figures, but those come from competitors' comparison posts rather than from the vendors, so treat them as rumor and ask.
What is the difference between a DDQ and an RFP?
An RFP asks you to win the work. A DDQ asks you to prove you are safe to do business with. That difference decides what good writing looks like in each. An RFP is scored on fit, price and capability, so a persuasive answer is a better answer. A DDQ is a risk document scored on accuracy and evidence, and a persuasive answer with nothing behind it is the worst outcome available, because it becomes a representation somebody can hold you to.
This is why tools built primarily for proposals struggle on the diligence half. They are optimized to make the answer read well. Diligence reviewers are optimized to find the one that does not hold up.
How long does it take to complete a DDQ?
Published estimates put a first draft of a 100 question DDQ at roughly 4 to 5 hours of writing, and the full coordinated effort across finance, legal, IT and compliance at 15 to 40 hours. Calendar time is usually 2 to 4 weeks. Almost none of that is typing. It is waiting on the person who knows when the last penetration test ran, and on the person who can confirm which cloud providers are in scope this quarter.
That is the real reason DDQ automation sells. It is also why automation that only speeds up the typing produces a smaller gain than the demo suggests.
The ILPA DDQ, and the 57 questions that age
The ILPA Due Diligence Questionnaire 2.0 is the closest thing private markets have to a standard, and in 2026 it is still the November 2021 edition. ILPA has added material around it, a DEI Monitoring Questionnaire in 2023 and a PRI Climate Module released with the PRI and the iCI in 2025, but the core document has not been revised.
Counting the numbered items in the published PDF gives 422 questions across 20 sections, plus eight appendices of templates. Section 18, which covers cyber and information security, business continuity and disaster recovery, is 27 of them. Section 13, compliance and internal controls, is another 30. So about one question in seven is a control question.
Those 57 behave differently from the other 365. Section 4 asks about investment strategy, and the answer reads the same in March and in November. Question 18.6.1 asks you to describe your penetration testing including its frequency, and that answer stops being true the moment the testing schedule slips. Question 18.15 asks whether sensitive data is encrypted at rest and in transit. Question 18.13 and 18.14 ask whether your cloud data and your third-party-held data are subject to independent security assessments, which is a question about a list that changes every time procurement signs something.
An answer library treats all of these the same way it treats your office addresses. It stores the approved sentence and re-serves it. It has no signal that the key rotation job has been failing for six weeks, or that the pen test scheduled for June never happened. The failure mode is not a wrong answer, which someone would catch on review. It is a sentence that was genuinely true in 2024, sent out in 2026 with full confidence, to a counterparty who will attach it to an agreement.
Do you need DDQ software if you already answer security questionnaires?
You do not necessarily need a second tool, but you do need the two to share one source of evidence. The control questions in a DDQ ask for the same underlying facts as the security domains of a SIG or the control set of a CAIQ. If they are answered out of two separate libraries owned by two separate teams, the wordings drift, and a diligence reviewer comparing your DDQ against your security documentation will find the difference before you do.
The practical fix is to answer the control questions once, from mapped evidence, and let both documents render from that. This is what security questionnaire automation does for the controls-only case, and what due diligence questionnaire software has to do for the wider document. The overlap is large enough that maintaining it twice is a choice, not a requirement.
How much does DDQ software cost?
Almost nobody publishes, so the useful answer is the drivers rather than a number. Price in this category moves on five things: how many seats you need, how many questionnaires you process a year, whether AI drafting sits on the entry tier or behind an upgrade, how many integrations you need, and whether a managed content service is bundled in. That last one is the biggest swing, because it converts a software line into a services line.
Watch for the tools that meter AI usage as credits, because usage grows with exactly the thing you bought the tool to handle. A meter that charges more every time your diligence volume goes up is billing you for success.
What a DDQ tool cannot do for you
Three things, and they are worth knowing before the demo.
It cannot verify a performance table. Track record answers come out of the fund accounting system as of a stated date, and a recycled table is a compliance problem rather than a shortcut. No library should be allowed near that section.
It cannot make an unattested control attested. A SOC 2 Type II report answers a good part of section 18, but not all of it. It does not cover breach history over the last five years, penetration testing frequency, portfolio company security practices, or the specific cloud and third-party assurance list the DDQ asks you to enumerate. If you are still building that evidence base, SOC 2 compliance software is the upstream problem to solve first, because the DDQ answer is downstream of the control.
It cannot approve the answer. Every serious DDQ response is a representation, so a named human signs off, and the documents that follow the questionnaire still get circulated for signature on the resulting agreements. What automation should buy you is the distance from a blank field to a cited draft, plus a flag on every answer whose underlying control has moved since anyone last looked at it.
How to choose between them
Start by counting where your last three DDQs actually stalled. If the delay was in re-writing firm narrative for the fourth investor this quarter, buy the strongest answer library you can afford and staff the content maintenance properly, because an unmaintained library is worse than no library. Ontra and DiligenceVault are the two shaped specifically for private funds; Responsive and Loopio are the general-purpose heavyweights; Arphie, AutoRFP and SiftHub are the AI-native challengers aimed at smaller teams.
If the delay was waiting on security, compliance and continuity answers, more library will not help, because the bottleneck is not retrieval. It is that nobody can confirm the current state of the control without going and looking. That is a questionnaire evidence problem, and it is solved by holding the controls and their test dates in one place so the answer is a lookup rather than an investigation.
Most firms above a certain size end up needing both, run off one shared set of control facts. The mistake is buying one and assuming it covers the other.
See Scrutineer scrutinize your posture
Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.