Free tool

Vendor due diligence questionnaire builder

Pick the sections that matter for this vendor and generate a clean, professional due diligence questionnaire in seconds. Copy or download the finished DDQ.

Who this is for and what it solves

Who this is for
  • Procurement and vendor management teams onboarding new suppliers
  • Compliance and risk leads standardising DDQs across the business
  • Founders and ops leads running their first formal vendor reviews
Problem it solves

Most DDQs are copy-pasted from an old Word doc and either ask nothing useful or ask 200 irrelevant questions. This builds a proportionate DDQ for each vendor in under a minute.

Sections to include
DDQ preview
6 sections · 26 questions · 13 documents

Company details

Confirm you are dealing with the legal entity you think you are.

  1. Registered company name and Companies House number.
  2. Registered address and any trading addresses.
  3. Ultimate parent company, if any.
  4. Primary contact name, role, email and phone.
  5. VAT registration number.
Documents requested: Certificate of incorporation, Latest Companies House filing summary

Financial standing

Sense-check the vendor can deliver over the contract term.

  1. Turnover for the last two full financial years.
  2. Confirmation of no ongoing insolvency or CVA proceedings.
  3. Number of full-time employees.
  4. Are more than 25% of your revenues concentrated with a single client?
Documents requested: Most recent filed accounts, Bank reference letter (on request)

Insurance

Confirm cover is in place at the levels your contract requires.

  1. Public liability cover level and insurer.
  2. Employers' liability cover level and insurer.
  3. Professional indemnity cover level, basis (claims-made / occurrence) and insurer.
  4. Renewal date of each policy.
  5. Any cyber liability cover in place, if applicable.
Documents requested: Public liability certificate, Employers' liability certificate, Professional indemnity certificate, Cyber liability certificate (if held)

Health and safety

Establish the vendor's H&S maturity before any on-site work.

  1. Do you hold an SSIP-accredited scheme (CHAS, Constructionline, SafeContractor, Achilles)?
  2. RIDDOR reportable incidents in the last 3 years.
  3. Named competent H&S adviser (internal or external).
  4. Is your H&S policy signed by a director and reviewed annually?
Documents requested: Health & safety policy, SSIP accreditation certificate (if held)

Information security

Screen the vendor's controls before they touch your systems or data.

  1. Do you hold Cyber Essentials, Cyber Essentials Plus or ISO 27001?
  2. Named information security lead.
  3. Do you use MFA on all administrative accounts?
  4. Do you have a documented incident response plan?
  5. Where is customer data physically hosted?
Documents requested: Cyber Essentials / ISO 27001 certificate, Information security policy

Client references

Get warm references before signature, not after.

  1. Two comparable client references with contact name, role and email.
  2. Brief description of the scope delivered for each reference.
  3. Contract length and value banding for each reference.
Documents requested: Case studies (optional)

How it works

  1. Step 1
    Set the vendor

    Add vendor and your organisation name so the finished DDQ is ready to send.

  2. Step 2
    Pick sections

    Toggle sections in or out based on the risk profile - data processors need more, one-off suppliers less.

  3. Step 3
    Send it out

    Copy or download the DDQ, or turn it into a live request in Credbase to track replies.

Questions and answers

Where this tool stops

A questionnaire is only useful if suppliers actually complete it.

A neat DDQ in Word is the easy bit. Sending it to every vendor, chasing the ones who ignore it and reviewing the answers alongside their live documents is where DDQ programmes stall.

Credbase sends the DDQ as a shareable form, files the answers against each vendor and keeps them next to the actual evidence documents.

This tool is a plain-English guide for teams handling third-party paperwork. It is not legal, insurance or compliance advice. Confirm specifics with the counterparty or your own adviser before you rely on any output.