Skip to main content
Category: Third-Party Due Diligence

Integrity Due Diligence Questionnaire

Also known as: IDDQ, Integrity Due Diligence (IDD) Questionnaire, Ethics and Integrity Due Diligence Questionnaire, Integrity DDQ
Simply put

An Integrity Due Diligence Questionnaire is a structured set of questions a company sends to a person or organization it is considering doing business with, in order to gather facts and supporting documents about that party's integrity before entering into a relationship. It is one step in a broader integrity due diligence process rather than a complete assessment on its own. The information collected is intended to help the company understand potential risks associated with the counterpart.

Formal definition

An Integrity Due Diligence Questionnaire (IDDQ) is an evidence-gathering instrument used within an integrity due diligence (IDD) process to collect facts and supporting documentation from a prospective or existing business counterpart before, or during the periodic renewal of, a commercial relationship. It supports the assessment of an individual's or organization's integrity, and in some organizations its completion is a mandatory step required of counterparts. As a data-collection tool, the questionnaire is a single component of a larger due diligence workflow and does not by itself constitute a completed risk assessment, an integrity determination, or an entire third-party compliance program; the resulting analysis, verification, and decision-making occur in subsequent steps. The specific questions, mandatory scope, and use of results are defined by each organization's program and applicable requirements, which may vary by jurisdiction. This entry is educational and not a substitute for qualified legal or compliance advice.

Why it matters

Companies increasingly face integrity risks that originate not within their own operations but through the third parties they engage, agents, distributors, suppliers, joint-venture partners, and other commercial counterparts. Before entering into or renewing such relationships, an organization needs a reliable way to gather facts about a counterpart's integrity. The Integrity Due Diligence Questionnaire serves as that structured evidence-gathering instrument, collecting information and supporting documentation directly from the party under consideration so that potential risks can be identified and evaluated in subsequent steps.

The questionnaire matters because integrity due diligence is fundamentally about assessing an individual or organization's integrity before committing to a business relationship, and disciplined data collection is the foundation of that assessment. In some organizations, completion of the questionnaire is a mandatory step required of counterparts; for example, Petrobras describes providing the requested information and documents as one of its Integrity Due Diligence steps, and PMI treats due diligence as a mandatory process applied to commercial counterparts to help prevent risk. Structured, documented intake supports consistency and creates a record of the inquiry that was made.

It is equally important to recognize what the questionnaire does not do. An IDDQ is one component of a broader due diligence workflow, not a completed risk assessment, an integrity determination, or a standalone third-party compliance program. The verification of responses, analysis of the collected evidence, and the ultimate decision on whether to proceed occur in later stages. Treating a completed questionnaire as the end of the process, rather than the beginning, would overstate what this single tool can accomplish. This entry is educational and not a substitute for qualified legal or compliance advice.

Who it's relevant to

Compliance officers and third-party risk teams
These practitioners design the questionnaire, define its mandatory scope, and integrate it into the wider due diligence workflow. They rely on it to gather consistent, documented evidence from counterparts and are responsible for ensuring that verification and analysis follow, rather than treating a completed form as a finished risk assessment.
Ethics program managers
Because integrity due diligence concerns assessing a counterpart's integrity before entering a business relationship, ethics program managers use the questionnaire as one input into how the organization understands and manages the values-based and conduct risks presented by the parties it works with.
Legal and audit teams
These teams help ensure that the questionnaire's content and use align with applicable requirements, which may vary by jurisdiction, and that the collected records support the organization's ability to demonstrate the inquiry it performed. Questions about legal sufficiency and jurisdiction-specific obligations should be directed to qualified counsel.
Procurement and commercial functions
Personnel who onboard and renew relationships with suppliers, agents, and other commercial counterparts often administer or depend on the questionnaire. In organizations where completion is mandatory, they enforce that step as a precondition of engaging or continuing to work with a counterpart.
Learning and development staff
Training designers help business teams understand where the questionnaire fits in the due diligence process, how to collect and route responses, and, critically, that the tool is a single component of a larger system rather than a complete compliance program in itself.

Inside IDDQ

Counterparty Identification
Fields capturing the legal name, registration details, ownership structure, and beneficial owners of the third party being assessed, establishing who is actually being engaged and controlled by whom.
Business Rationale and Scope
Questions documenting the commercial purpose of the relationship, the nature of goods or services, and the scope of engagement, which help calibrate the level of scrutiny to the risk presented.
Anti-Bribery and Corruption Disclosures
Questions addressing government touchpoints, use of intermediaries or agents, political exposure, and prior enforcement or investigation history. These relate to obligations under frameworks such as the FCPA (U.S.) and the UK Bribery Act, which are jurisdiction-specific and apply based on the parties and conduct involved.
Ownership and Control Analysis
Requests for information on ultimate beneficial ownership, state ownership, and connections to public officials, intended to surface conflicts of interest and sanctions or politically exposed person (PEP) considerations.
Compliance Program Representations
Questions asking whether the counterparty maintains its own policies, code of conduct, or controls. These are self-reported representations and are one input among several, not independent verification.
Certifications and Attestations
Signed statements affirming the accuracy of responses and, in some cases, agreement to compliance-related contractual terms. Attestation supports accountability but does not by itself verify the underlying facts.

Common questions

Answers to the questions practitioners most commonly ask about IDDQ.

Does completing an integrity due diligence questionnaire mean a third party has been fully vetted and cleared?
No. The questionnaire is a self-reported information-gathering tool that represents one input into a due diligence process, not a conclusion. Responses are typically provided by the third party itself and require verification, corroboration against independent sources, and risk-based analysis. Treating a completed questionnaire as equivalent to a full clearance overstates what the instrument does. The depth of additional verification generally depends on the assessed risk level and should be determined in consultation with compliance and, where relevant, qualified legal counsel.
Is an integrity due diligence questionnaire the same thing as a compliance program's overall third-party risk management?
No. The questionnaire is a single component within a broader third-party risk management and due diligence framework. That framework may also include risk ranking, background and sanctions screening, adverse media checks, contractual anti-corruption representations, ongoing monitoring, and audit rights. Relying on the questionnaire alone does not satisfy the wider set of controls that programs are generally expected to maintain, and its role should be understood as informational rather than as a complete process.
Who should be responsible for reviewing and dispositioning completed questionnaires?
Review responsibility typically sits with the compliance function or a designated third-party risk team, often with escalation paths for higher-risk responses or red flags. Roles and thresholds vary by organization and by the assessed risk of the relationship. Because dispositioning decisions can touch on legal exposure, involving qualified legal counsel for elevated-risk cases is generally advisable. This entry is educational and not a substitute for professional advice on structuring internal responsibilities.
How should questionnaire content be tailored to different types of third parties?
Content is generally scaled and adjusted based on the nature of the relationship and the assessed risk it presents. A risk-based approach means that higher-risk categories may warrant more detailed questions, while lower-risk relationships may use an abbreviated set. Tailoring assumptions should be documented so that the rationale for the level of inquiry is clear. The specific questions used depend on the organization's risk assessment and applicable requirements, which can vary by jurisdiction.
How often should an integrity due diligence questionnaire be refreshed or re-issued?
Refresh cadence is typically risk-based rather than fixed, with higher-risk relationships often reviewed more frequently and updates triggered by events such as changes in ownership, scope, or emerging red flags. Because the questionnaire captures information at a point in time, periodic re-issuance is intended to keep the record current, though it does not by itself guarantee that intervening changes are detected. Organizations generally set intervals according to their own policies and applicable expectations.
What should happen when a questionnaire response reveals a red flag or an incomplete answer?
Red flags and gaps are generally handled through defined escalation and resolution procedures, which may include requesting clarification, seeking supporting documentation, conducting enhanced due diligence, or declining or conditioning the relationship. The appropriate response depends on the nature of the concern and the assessed risk. Documenting how flags were identified and resolved supports the record of the process. Where a response raises potential legal exposure, involving qualified legal counsel is generally advisable, and this guidance is educational rather than a substitute for such advice.

Common misconceptions

Completing an integrity due diligence questionnaire satisfies a company's third-party compliance obligations.
The questionnaire is a single information-gathering component within a broader third-party risk management process that generally also includes risk assessment, independent verification, screening, contractual controls, and ongoing monitoring. Reliance on the questionnaire alone is not the same as due diligence being complete.
The questionnaire is a training exercise or part of a training module.
It is a diligence and risk-screening instrument, distinct from training. A training module builds awareness and competence among personnel, whereas the questionnaire collects and evaluates information about an external counterparty. They serve different functions within a compliance program.
A truthful, signed questionnaire provides legal protection or guarantees the counterparty is low risk.
Responses are self-reported representations that may be incomplete or inaccurate, and no questionnaire guarantees prevention of misconduct or legal protection. Its value depends on how findings are verified, escalated, and acted upon, and outcomes vary by implementation and jurisdiction.

Best practices

Calibrate the depth and follow-up of the questionnaire to the assessed risk level of the relationship, applying enhanced scrutiny to higher-risk counterparties, government touchpoints, or higher-risk jurisdictions.
Treat questionnaire responses as self-reported inputs and corroborate material representations through independent verification and screening rather than relying on attestation alone.
Integrate the questionnaire into a documented end-to-end process that includes risk assessment, escalation criteria, contractual controls, and ongoing monitoring, so it functions as one component rather than a standalone control.
Define clear thresholds and escalation paths for red flags, ensuring flagged responses are reviewed by appropriate compliance and, where relevant, legal personnel.
Maintain records of completed questionnaires, verification steps, and decisions to support an auditable trail consistent with expectations described in guidance such as the DOJ Evaluation of Corporate Compliance Programs.
Refresh questionnaires periodically and upon trigger events, and involve qualified legal counsel where responses touch matters that vary by local law or carry potential liability.