DDQ Readiness: The IT and Security Evidence Investors Expect
Operational due diligence questionnaires keep getting more detailed on technology. Here is the evidence allocators expect, and how to have it ready before the request arrives.

Technology is now a core diligence topic
Allocators and their consultants treat technology and cybersecurity as operational risk, not a side note. A DDQ that once asked whether you had antivirus now asks how you detect, respond to, and recover from incidents, and wants proof.
The firms that move through diligence smoothly are not necessarily the ones with the most tools. They are the ones that can produce clear, current evidence on request.
What investors typically ask
While every questionnaire differs, most cover the same ground:
- Governance: Who is accountable for technology and security? Is there a written information security policy, and when was it last reviewed?
- Access control: Is multi-factor authentication enforced? How are joiners, movers, and leavers handled?
- Endpoint and network security: Are devices encrypted, patched, and monitored? Is there 24x7 detection and response?
- Vendor management: Which third parties hold firm or investor data, and how are they assessed?
- Business continuity: What are your recovery objectives, and when was recovery last tested?
- Incident response: Is there a documented plan? Has it been exercised?
- Training: Do staff receive security awareness and phishing training?
Policies are not evidence
A written policy is the starting point. Diligence teams increasingly ask for artifacts that show the policy is operating, such as:
- MFA enrollment and conditional access reports
- Patch compliance summaries over time
- Backup success logs and restore test results
- Security monitoring summaries and incident records
- Tabletop exercise notes
- Training completion records
If producing these requires your IT provider to run manual exports each time, every DDQ becomes a fire drill.
Build a standing evidence file
The most efficient approach is to keep evidence current year round:
- Map controls once. Align your controls to a recognized framework such as NIST CSF or CIS so answers stay consistent across questionnaires.
- Automate reporting. Schedule monthly reports on patching, MFA, backups, and security events.
- Test and record. Run restore tests and incident tabletop exercises on a calendar, and keep the write-ups.
- Maintain a response library. Store approved answers to common DDQ questions and update them after each review.
- Review quarterly. Confirm the evidence still reflects reality, especially after office moves, new systems, or staff changes.
Common gaps we see
- MFA enforced for email but not for remote access or admin accounts
- Backups that run but have never been restored
- Incident response plans that name people who have left the firm
- No record of who has access to which systems
Each is fixable, but far easier to fix before an allocator finds it.
The bottom line
DDQ readiness is an operating habit, not a one-time project. When reporting runs continuously, answering a questionnaire becomes a matter of pulling current documents rather than reconstructing history.
If a raise or allocator review is on your calendar, talk to our team. Explore our security governance and evidence support and reporting showcase. We can review your current evidence and identify gaps.


