Every deal runs on its own vocabulary. This glossary defines the terms behind RFPs, proposals, and modern sales workflows, in plain language, for the teams who live them.
A due diligence questionnaire (DDQ) is a structured set of questions a buyer or investor sends to assess a counterparty's risk before committing: financial standing, ownership, compliance, data handling, and operational controls. It is a risk check rather than a competitive evaluation.
A DDQ usually arrives after the commercial decision has effectively been made, which makes it feel like paperwork and makes it dangerous for exactly that reason. Nobody wins a deal on a DDQ, and plenty of deals stall on one, because the questions go to legal, finance, and security teams who have no stake in the deadline.
The delay compounds. A DDQ that takes three weeks to answer moves the contract into the next quarter, and a quarter-end that slips once tends to slip again. Sellers who treat it as the last administrative step rather than as a workstream to run in parallel lose weeks they never planned for. It sits alongside the NDA and the contract as one of the checks between agreement and signature.
The scope varies by who is asking. A corporate buyer focuses on operational and information risk: corporate structure and ownership, financial statements and stability, insurance, data protection and security practices, subcontractors, business continuity, and regulatory compliance. Anti-bribery, modern slavery, and sanctions screening are now standard in most regulated sectors.
Investors and fund allocators use the same instrument for a different purpose, covering governance, valuation policy, and operational controls. Financial services and healthcare buyers ask the most, and their questionnaires often run to several hundred questions with mandatory evidence attached to each answer.
An RFP asks what you would do and how much it costs, and it is scored competitively against other bidders. A DDQ asks what you are, and it is assessed against a risk threshold rather than against rivals. You do not beat anyone on a DDQ. You either clear the bar or you create a problem.
The practical consequence is tone. RFP answers argue. DDQ answers state facts, attach evidence, and avoid elaboration, because an expansive answer to a risk question invites a follow-up question. Where a control is not in place, say what compensating control exists rather than leaving the gap for the reviewer to interpret.
A software vendor closes a deal with a bank in March, subject to due diligence. The DDQ runs 240 questions across security, financial, and regulatory sections. Legal owns 40, finance 30, and the security lead the remainder. Because 180 of the answers exist from a similar questionnaire two quarters earlier, the vendor returns it in nine days rather than the six weeks it took the first time. The contract signs inside the quarter.
DDQ answers are the most reusable content a company owns and the most likely to be out of date, because the facts underneath them change quietly: a new subprocessor, a lapsed certification, a restructured entity. Reusing last year's answers without checking is how a supplier ends up making an inaccurate statement in a document a bank's compliance team keeps on file. Cobl keeps this material with the deal so the answers are produced against current facts rather than pulled from whichever file surfaced first.
Speed matters here, but accuracy is what the document is actually for. The two only conflict when the source of truth is a folder nobody owns.
Rarely one person. Legal covers structure and compliance, finance covers statements and insurance, security covers data handling, and operations covers continuity. Sales usually coordinates rather than answers, and the coordination is most of the work.
First time through, commonly three to six weeks for a substantial questionnaire, because answers have to be sourced from several teams and evidence located. Subsequent ones are much faster where the previous answers were kept and maintained.
A security questionnaire is narrower, covering information security and data protection specifically. A DDQ is broader and usually contains a security section alongside financial, legal, and operational ones. Many buyers send both, sometimes with overlapping questions.
You can decline to share genuinely confidential material, and buyers generally accept a reasoned position, particularly under an NDA with restricted circulation. Declining without explanation reads as a red flag, so state why and offer whatever alternative evidence exists.
Cobl reads the RFP and generates the full response set: go/no-go, answers, technical proposal, pricing, and slides, built on your own rules.