Scrutineer · Vendor risk
Due diligence questionnaire software and DDQ automation
A due diligence questionnaire arrives with a deadline and a few hundred questions, and the sections that stall it are always the same ones: information security, compliance, business continuity, cloud and third parties. Those answers are claims about controls, and a control has a state.
Scrutineer answers them from your mapped evidence, so each response carries the date the control was last tested rather than the wording someone approved for a different counterparty last year.
Control-mapped findings · linked evidence · you decide what to remediate
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with DDQ
The standard DDQ everyone answers has not changed since 2021, and the controls it asks about have
The ILPA Due Diligence Questionnaire 2.0 is the closest thing private markets have to a standard document, and in 2026 it is still the November 2021 edition. Counting the numbered items in the published PDF gives 422 questions across 20 sections. Section 18, which covers cyber and information security, business continuity and disaster recovery, is 27 of them. Section 13, compliance and internal controls, is another 30. So roughly one question in seven is a control question, and it is that seventh that ages. Section 4 asks about investment strategy and the answer reads the same in March and in November. Question 18.6.1 asks you to describe your penetration testing including frequency, and that answer stops being true the moment the testing does. ILPA has added material around the core document, a DEI Monitoring Questionnaire in 2023 and a PRI Climate Module in 2025, but the security questions are the 2021 ones. Everybody is answering current control questions out of a document older than most of the controls.
An answer library is the right tool for seventeen sections and the wrong tool for one
Every product in this category is built on the same idea. Keep approved answers in a library, match the incoming question to the nearest stored answer, draft, review, send. For fund terms, track record narrative, team biographies and legal structure that is exactly right, because the answer is a fact about the firm and it does not change because a different investor asked. It breaks on the control sections, because there the stored sentence is a claim about a state. "Sensitive data is encrypted at rest and in transit" was true when it was approved. The library has no way to know the key rotation job has been failing for six weeks. The failure mode is not a wrong answer, which somebody would catch. It is a confidently reused answer that was right in 2024, sent to a counterparty who will attach it to a contract. The fix is not a better library. It is answering those questions from the control record instead of from prose.
A DDQ is not a security questionnaire, which is why the same answer gets written three times
They arrive from different people on different cycles. A DDQ is a whole-firm document, sent by an investor, an acquirer or a counterparty's procurement team, and it asks about ownership, financials, strategy, terms, compliance and security together. A security questionnaire is a controls-only document, sent by a customer's security reviewers, and it shows up as a SIG, a CAIQ, a HECVAT or a bespoke spreadsheet. Most firms answer them in separate tools owned by separate teams, which is how one encryption control ends up described three different ways in three systems, and how a diligence reviewer finds the discrepancy before you do. The overlap is the useful part: the roughly 57 control questions in an ILPA DDQ ask for the same evidence as the security domains of a SIG and the control set of a CAIQ. Answer that evidence once and every downstream questionnaire becomes a re-render rather than a new project.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Answers the information security, business continuity, cloud and third-party sections of a DDQ from your mapped control evidence, with the date each control was last tested attached to the answer
- Reuses one control library across the ILPA DDQ, SIG, CAIQ, HECVAT and bespoke enterprise questionnaires, so the same evidence serves all of them
- Flags the questions where the stored answer is older than the control behind it, before the response goes out
- Keeps the attachments a DDQ asks for in one place: SOC 2 report, ISO 27001 certificate, penetration test summary, BCP and DR plans, insurance certificates
- Tracks the third-party and cloud provider list an ILPA DDQ Appendix D asks for, and what assurance you actually hold on each name in it
- Records who approved each control answer and when, which is the part a counterparty comes back to when something turns out to be wrong
- Maps one control to every framework a DDQ names, so question 18.1.1, whether your policy follows an internationally recognized standard, has a citation behind it
- Leaves strategy, track record and fund terms to the people who own them, rather than pretending an answer library can verify a performance table
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
DDQ section reference
Which DDQ answers can be automated, and which ones expire
Every DDQ software comparison runs the same axis, vendor against feature list, which tells you nothing about the document sitting on your desk. This table runs the other way, section by section through the ILPA Due Diligence Questionnaire 2.0, on the question that decides whether automation helps at all: what kind of thing is the answer, and how long does it stay true. Scrutineer answers the rows where the evidence is a control record. It does not answer the rows where the evidence is a fund.
| DDQ section | What the answer actually is | Where the true answer lives | What an answer library gets wrong | How long it stays true |
|---|---|---|---|---|
| Firm and fund general information (ILPA 1.0, 2.0) | A fact about the entity: assets, offices, registrations, ownership | Your own records, and Form ADV if you are a registered adviser | Very little. This is the job a library is good at | Until the fact changes, usually a year or more |
| Investment strategy and process (4.0, 8.0) | A description of how the firm invests | The people who run the strategy | Very little, though a human still has to read it against this fund | Until the strategy changes |
| Track record (14.0) | Numbers, in a prescribed template, as of a stated date | The fund accounting system | Everything. A recycled performance table is a compliance problem, not a shortcut | Until the next quarter end |
| Fund terms and legal (12.0, 17.0) | What the documents say | The LPA and the side letters | Very little, provided the library is versioned to the right fund | Until the documents are amended |
| Compliance and internal controls (13.0, 30 questions) | A claim that a program exists and is supervised | The compliance manual, the testing calendar and the last review | Restates the policy and skips the evidence that the testing ran | Until the next review cycle, often a quarter |
| Cyber and information security (18.1 to 18.8, 18.15) | A claim about the current state of a control | The control record: policy approval date, last penetration test, last vulnerability scan, encryption settings, training completion | Re-sends a sentence that was true in 2024 as a 2026 answer, with nothing flagged | As long as the control holds, which can be days |
| Business continuity and disaster recovery (18.10 to 18.12) | A claim that a plan exists and has been exercised | The plan document, plus the date and result of the last test | Confirms the plan and quietly drops the test date, which is the part actually being asked | Until the next required exercise, typically annual |
| Cloud and third-party providers (18.13, 18.14, Appendix D) | A list, plus the assurance you hold on every name in it | Your vendor inventory and the SOC 2 or ISO certificate held for each | Answers from the vendor list as it stood the day the answer was written | Until a vendor is added, dropped, or its report expires |
| ESG and DEI (19.0, 20.0) | Policy statements, plus metrics in a template | The responsible investment policy and the diversity data collection | Little on the policy text, a lot on the metrics, which are as-of-date figures | Until the next data collection cycle |
Good questions
Questions about DDQ
Keep reading
Guides that go deeper on this framework
Best DDQ software compared
What each tool in the category is actually built for, where its answers come from, and where it stops.
Read the guideBest security questionnaire automation software
The controls-only cousin of the DDQ, and the tools that answer SIG, CAIQ and HECVAT sets.
Read the guideHow security questionnaire automation works
What can be answered from evidence, what still needs a human, and how to keep the two apart.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification