Due Diligence Readiness

DDQ completion tracking across vendor assessments — identify gaps, monitor section-level progress, and surface high-risk areas before procurement sign-off.

DDQ Questions

60

across 6 sections

Avg Completion

72%

all vendors

Vendors Assessed

115

active evaluations

High-Risk Flags

23

require follow-up

DDQ Sections

Data Sourcing & Provenance

12 Qs
Completion78%
  • Where is raw data originally sourced from?
  • Is data lineage documented end-to-end?
  • Are third-party sub-processors disclosed?
  • How often are source agreements reviewed?

Privacy & PII Handling

10 Qs
Completion65%
  • Is PII anonymised or pseudonymised before delivery?
  • What consent mechanisms cover end-user data?
  • Are data subject access requests supported?
  • How long is personal data retained?

Security & Infrastructure

10 Qs
Completion82%
  • Is SOC 2 Type II certification current?
  • Are penetration tests performed annually?
  • What encryption standards protect data at rest?
  • Is a formal incident response plan maintained?

Methodology & Quality

10 Qs
Completion71%
  • How is data accuracy validated before delivery?
  • What QA checks run on each production batch?
  • Are methodology changes documented and versioned?
  • Is back-test or survivorship bias addressed?

Delivery & Integration

8 Qs
Completion76%
  • What delivery formats and APIs are supported?
  • Is historical backfill available on request?
  • What SLAs govern data freshness and uptime?
  • Are webhook or streaming options offered?

Business Continuity & Legal

10 Qs
Completion58%
  • Is there a documented business continuity plan?
  • What happens to data access if the vendor exits the market?
  • Are indemnification clauses included in contracts?
  • How are regulatory changes incorporated?

Risk Distribution

42

Low Risk

38

Medium Risk

23

High Risk

12

Critical Risk

Top Unanswered Questions

1

Full data lineage documentation

58%
2

Independent third-party audit report

54%
3

Formal incident response plan

47%
4

Sub-processor disclosure list

45%
5

PII anonymisation methodology

42%
6

Business continuity / disaster recovery plan

39%
7

Historical backfill availability

36%
8

Regulatory change monitoring process

34%
9

Data retention and deletion policy

31%
10

SLA breach remediation terms

28%

Due Diligence Questionnaire Tracking for Alternative Data Vendors

Vedex tracks DDQ completion rates across 60 standardised questions spanning data provenance, privacy, security, methodology, delivery, and legal risk. Procurement teams use this view to identify vendor readiness gaps before signing data licensing agreements. Each section maps to industry-standard due diligence frameworks used by institutional buyers of alternative data.

Risk-Based Vendor Assessment Methodology

Vendors are classified into Low, Medium, High, and Critical risk tiers based on unanswered DDQ questions and the severity weighting of each section. Common gaps such as missing data lineage documentation, absent third-party audits, and incomplete incident response plans are surfaced to help compliance teams prioritise follow-up. The goal is to reduce procurement cycle time while maintaining rigorous oversight of alternative data supply chains.