Scrutineer.ai

Scrutineer · Vendor risk

Due diligence questionnaire software and DDQ automation

A due diligence questionnaire arrives with a deadline and a few hundred questions, and the sections that stall it are always the same ones: information security, compliance, business continuity, cloud and third parties. Those answers are claims about controls, and a control has a state.

Scrutineer answers them from your mapped evidence, so each response carries the date the control was last tested rather than the wording someone approved for a different counterparty last year.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with DDQ

The standard DDQ everyone answers has not changed since 2021, and the controls it asks about have

The ILPA Due Diligence Questionnaire 2.0 is the closest thing private markets have to a standard document, and in 2026 it is still the November 2021 edition. Counting the numbered items in the published PDF gives 422 questions across 20 sections. Section 18, which covers cyber and information security, business continuity and disaster recovery, is 27 of them. Section 13, compliance and internal controls, is another 30. So roughly one question in seven is a control question, and it is that seventh that ages. Section 4 asks about investment strategy and the answer reads the same in March and in November. Question 18.6.1 asks you to describe your penetration testing including frequency, and that answer stops being true the moment the testing does. ILPA has added material around the core document, a DEI Monitoring Questionnaire in 2023 and a PRI Climate Module in 2025, but the security questions are the 2021 ones. Everybody is answering current control questions out of a document older than most of the controls.

An answer library is the right tool for seventeen sections and the wrong tool for one

Every product in this category is built on the same idea. Keep approved answers in a library, match the incoming question to the nearest stored answer, draft, review, send. For fund terms, track record narrative, team biographies and legal structure that is exactly right, because the answer is a fact about the firm and it does not change because a different investor asked. It breaks on the control sections, because there the stored sentence is a claim about a state. "Sensitive data is encrypted at rest and in transit" was true when it was approved. The library has no way to know the key rotation job has been failing for six weeks. The failure mode is not a wrong answer, which somebody would catch. It is a confidently reused answer that was right in 2024, sent to a counterparty who will attach it to a contract. The fix is not a better library. It is answering those questions from the control record instead of from prose.

A DDQ is not a security questionnaire, which is why the same answer gets written three times

They arrive from different people on different cycles. A DDQ is a whole-firm document, sent by an investor, an acquirer or a counterparty's procurement team, and it asks about ownership, financials, strategy, terms, compliance and security together. A security questionnaire is a controls-only document, sent by a customer's security reviewers, and it shows up as a SIG, a CAIQ, a HECVAT or a bespoke spreadsheet. Most firms answer them in separate tools owned by separate teams, which is how one encryption control ends up described three different ways in three systems, and how a diligence reviewer finds the discrepancy before you do. The overlap is the useful part: the roughly 57 control questions in an ILPA DDQ ask for the same evidence as the security domains of a SIG and the control set of a CAIQ. Answer that evidence once and every downstream questionnaire becomes a re-render rather than a new project.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Answers the information security, business continuity, cloud and third-party sections of a DDQ from your mapped control evidence, with the date each control was last tested attached to the answer
  • Reuses one control library across the ILPA DDQ, SIG, CAIQ, HECVAT and bespoke enterprise questionnaires, so the same evidence serves all of them
  • Flags the questions where the stored answer is older than the control behind it, before the response goes out
  • Keeps the attachments a DDQ asks for in one place: SOC 2 report, ISO 27001 certificate, penetration test summary, BCP and DR plans, insurance certificates
  • Tracks the third-party and cloud provider list an ILPA DDQ Appendix D asks for, and what assurance you actually hold on each name in it
  • Records who approved each control answer and when, which is the part a counterparty comes back to when something turns out to be wrong
  • Maps one control to every framework a DDQ names, so question 18.1.1, whether your policy follows an internationally recognized standard, has a citation behind it
  • Leaves strategy, track record and fund terms to the people who own them, rather than pretending an answer library can verify a performance table
DDQ readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

DDQ section reference

Which DDQ answers can be automated, and which ones expire

Every DDQ software comparison runs the same axis, vendor against feature list, which tells you nothing about the document sitting on your desk. This table runs the other way, section by section through the ILPA Due Diligence Questionnaire 2.0, on the question that decides whether automation helps at all: what kind of thing is the answer, and how long does it stay true. Scrutineer answers the rows where the evidence is a control record. It does not answer the rows where the evidence is a fund.

DDQ section What the answer actually is Where the true answer lives What an answer library gets wrong How long it stays true
Firm and fund general information (ILPA 1.0, 2.0) A fact about the entity: assets, offices, registrations, ownership Your own records, and Form ADV if you are a registered adviser Very little. This is the job a library is good at Until the fact changes, usually a year or more
Investment strategy and process (4.0, 8.0) A description of how the firm invests The people who run the strategy Very little, though a human still has to read it against this fund Until the strategy changes
Track record (14.0) Numbers, in a prescribed template, as of a stated date The fund accounting system Everything. A recycled performance table is a compliance problem, not a shortcut Until the next quarter end
Fund terms and legal (12.0, 17.0) What the documents say The LPA and the side letters Very little, provided the library is versioned to the right fund Until the documents are amended
Compliance and internal controls (13.0, 30 questions) A claim that a program exists and is supervised The compliance manual, the testing calendar and the last review Restates the policy and skips the evidence that the testing ran Until the next review cycle, often a quarter
Cyber and information security (18.1 to 18.8, 18.15) A claim about the current state of a control The control record: policy approval date, last penetration test, last vulnerability scan, encryption settings, training completion Re-sends a sentence that was true in 2024 as a 2026 answer, with nothing flagged As long as the control holds, which can be days
Business continuity and disaster recovery (18.10 to 18.12) A claim that a plan exists and has been exercised The plan document, plus the date and result of the last test Confirms the plan and quietly drops the test date, which is the part actually being asked Until the next required exercise, typically annual
Cloud and third-party providers (18.13, 18.14, Appendix D) A list, plus the assurance you hold on every name in it Your vendor inventory and the SOC 2 or ISO certificate held for each Answers from the vendor list as it stood the day the answer was written Until a vendor is added, dropped, or its report expires
ESG and DEI (19.0, 20.0) Policy statements, plus metrics in a template The responsible investment policy and the diversity data collection Little on the policy text, a lot on the metrics, which are as-of-date figures Until the next data collection cycle

Good questions

Questions about DDQ

A DDQ is a formal written information request one organization sends another before or during a business relationship. It asks for documented, verifiable answers about ownership, financials, operations, compliance, security and governance. Investors send them to fund managers, enterprise buyers send them to vendors, and the answers are treated as representations you can be held to later.
DDQ software is a tool that helps you respond to due diligence questionnaires faster. Most products in the category work from a library of previously approved answers, matching each incoming question to the closest stored response and drafting from it. Scrutineer takes the control sections a different way, answering them from your live evidence rather than from stored prose.
An RFP asks you to win the work. A DDQ asks you to prove you are safe to do business with. An RFP is a sales document scored on fit, price and capability, so persuasion belongs in it. A DDQ is a risk document scored on accuracy and evidence, and a persuasive answer with no evidence behind it is the worst possible outcome.
Scope and sender. A security questionnaire covers controls only and comes from a customer security team, usually as a SIG, a CAIQ, a HECVAT or a bespoke spreadsheet. A DDQ covers the whole firm, including ownership, financials, strategy, terms, compliance and security, and comes from an investor, an acquirer or procurement. The control sections overlap almost entirely.
Published estimates put a first draft of a 100 question DDQ at roughly 4 to 5 hours, and the full coordinated effort across finance, legal, IT and compliance at 15 to 40 hours. Calendar time is usually 2 to 4 weeks, because most of it is waiting on subject matter experts rather than typing. The control sections are the usual bottleneck.
Counting the numbered items in the published ILPA Due Diligence Questionnaire 2.0 gives 422 questions across 20 sections, plus eight appendices of templates. Section 18, covering cyber and information security, business continuity and disaster recovery, holds 27 of them. Section 13, compliance and internal controls, holds 30.
Yes, and it is still the November 2021 edition. ILPA has not revised the core document since, though it added a DEI Monitoring Questionnaire in 2023 and published a PRI Climate Module with the PRI and the iCI in 2025. The security questions being answered in 2026 are the ones written in 2021.
The control sections. Information security, compliance and internal controls, business continuity and disaster recovery, cloud providers and third parties, roughly 57 of the 422 questions in an ILPA DDQ. Scrutineer does not answer investment strategy, track record or fund terms, because those are not control questions and no evidence library should pretend to verify them.
It answers a good part of it and leaves gaps. A SOC 2 Type II covers the control environment over a period, which satisfies questions about policy, access, encryption and monitoring. It does not by itself answer the DDQ questions about breach history in the last five years, penetration test frequency, portfolio company security, or the specific cloud and third-party assurance list.
Tie each answer to the control record rather than to a stored sentence, and show the date the control was last tested next to the response. Then staleness is visible instead of invisible. An answer library has no signal that anything changed, so the only thing keeping it honest is somebody remembering, which is the part that fails under deadline.
Commonly the SOC 2 report or ISO 27001 certificate, the information security policy, a penetration test summary, the business continuity and disaster recovery plans, insurance certificates, audited financials, the compliance manual and code of ethics, and an organizational chart. ILPA Appendix A is an explicit requested-documents list, and Appendix D covers third parties and technology tools.
Most vendors in this category do not publish a number, so the honest answer is the drivers rather than a figure. Price moves on seat count, questionnaire volume, whether AI drafting is on the entry tier or an upgrade, integration count, and whether a managed content service is bundled. Scrutineer publishes its plans and prices in full on the pricing page.
It depends on which half of the document is hurting. If the bottleneck is repeating firm facts and narrative across many investors, a strong answer library such as Responsive, Loopio or Ontra is the right shape. If the bottleneck is the security, compliance and continuity sections, a control-evidence tool fits better, because those answers need a current state rather than a stored sentence.
Not necessarily a second tool, but you do need the two to share one source of evidence. The control questions in a DDQ and the ones in a SIG or CAIQ ask for the same underlying facts. If they are answered from two libraries, the wordings drift apart and a diligence reviewer comparing your DDQ against your trust documentation will find the difference.
It is the DDQ sent to a supplier rather than to a fund manager, usually by procurement or third-party risk, covering corporate standing, financial viability, information security, data privacy, subprocessors and business continuity. Published guidance puts a full-scope version for a high-risk vendor at roughly 40 to 100 questions, with a 15 to 25 question version for lower tiers.
It can draft them automatically. Nothing should send them automatically. Every serious DDQ answer is a representation, so a named human approves it. The value of automation is in getting from a blank field to a cited draft, and in flagging the answers whose underlying control has moved since the last time anyone looked.

Keep reading

Guides that go deeper on this framework

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification