LP DDQ Document Workflow: Answers, Evidence, and Approvals
Build an LP DDQ workflow with an approved answer library, evidence registry, subject-matter owners, version control, confidentiality tiers, and audit-ready delivery.
An LP due diligence questionnaire brings together investment, operations, compliance, legal, finance, tax, technology, cybersecurity, ESG, and service-provider information. The main risk is not that the manager lacks words. It is that answers become inconsistent, stale, unsupported, or broader than the evidence permits.
A strong LP DDQ workflow treats every material response as a governed claim connected to an owner, source, approval, audience, and review date. It lets the investor-relations team respond efficiently without bypassing specialists or copying confidential material into uncontrolled files. To establish broader governance across all LP materials, explore our investor document management guide.
Disclosure: VDR Directory is affiliated with the SendNow team. Controlled sharing can help distribute a final DDQ or supporting document, while larger fundraising processes may need an investor portal or VDR with group permissions, versioning, Q&A, and archive controls. This guide is not legal, compliance, investment, tax, or regulatory advice.
Intake: capture the request before answering
Create a record with:
- investor organization and contacts;
- fund or strategy under review;
- questionnaire name and version;
- format and return method;
- due date and time zone;
- NDA or confidentiality status;
- investor advisers who need access;
- requested supporting documents;
- unusual representations or certifications;
- internal relationship owner; and
- approval and delivery status.
Store the original questionnaire. For syndication programs and bespoke investor reviews, ensure questionnaires align with our co-investment data room checklist to prevent disclosure conflicts between direct and fund vehicles. Do not overwrite it during drafting. If the investor sends a revised version, compare and record changes.
Triage urgent requests. A short deadline does not justify an unreviewed answer, but the team can identify high-risk questions early and agree on extensions or phased delivery.
Classify questions
For institutional managers executing institutional buyouts, review how DDQ responses connect to fund milestones in our private equity data room workflow.
Route questions by domain and risk:
| Domain | Typical owner | Common evidence |
|---|---|---|
| Firm and ownership | Legal / management | Organizational chart, governing records |
| Strategy and performance | Investment / finance | Track-record methodology, fund reports |
| Team and governance | Management / HR / compliance | Bios, committees, policies |
| Operations | COO / operations | Process narratives, control reports |
| Compliance and conflicts | CCO / legal | Policies, filings, registers |
| Valuation | Valuation committee / finance | Policy, committee terms, sample reporting |
| Risk | Risk owner / investment | Framework, limits, monitoring |
| Service providers | Operations / finance | Agreements, assurance reports, oversight |
| Cybersecurity and privacy | Security / privacy / legal | Policies, assessments, incident process |
| ESG / responsible investment | Designated owner | Policy, methodology, portfolio examples |
| Tax and structure | Tax / legal | Structure charts, memoranda, forms |
| Business continuity | Operations / technology | Plans and test summaries |
Label questions that require legal privilege review, personal data, confidential service-provider documents, or investor-specific terms.
Build an approved answer library
The library should store reusable answer modules, not complete questionnaires copied forever. For each answer record:
- question concept and keywords;
- approved response;
- applicable firm, strategy, fund, vehicle, and jurisdiction;
- owner and approver;
- source documents;
- effective date and next review;
- confidentiality tier;
- known limitations or required customization; and
- change history.
One answer can have variants. The cybersecurity overview given before an NDA may be high level, while a restricted investor room may contain a current independent report. A new fund may not have the same terms or service providers as a predecessor.
Do not let the library become a graveyard of polished but stale text. Expire answers automatically or flag them when supporting evidence changes.
Create an evidence registry
Connect claims to documents. The registry can include:
| Claim | Evidence | Owner | Period | Audience | Review date |
|---|---|---|---|---|---|
| Assets under management | Finance calculation and methodology | CFO | As of stated date | NDA investors | Quarterly |
| Team size | HR roster with approved scope | HR | As of stated date | General | Monthly |
| Security control | Policy and assessment evidence | Security | Current scope | Restricted | On material change |
| Valuation governance | Policy and committee charter | Valuation owner | Current version | NDA investors | Annual |
| ESG integration | Approved policy and examples | ESG owner | Strategy-specific | General/restricted | Annual |
The registry prevents an answer from citing a document that has expired or does not cover the relevant entity. It also helps reviewers identify gaps honestly.
Use source-of-truth fields
Certain facts change frequently: AUM, personnel, office locations, service providers, fund status, portfolio counts, performance periods, incidents, litigation, and regulatory registrations. Store these facts in controlled fields with as-of dates and owners.
Generate or review answers against those fields. Do not update one DDQ and assume every sales deck, pitchbook, website, and data room now agrees. Material changes should trigger a cross-document review.
For performance, use the organization’s approved methodology and disclosures. Investor-specific calculations require review.
Drafting standards
Answer the question directly, then provide scoped explanation and evidence. A useful pattern is:
- Direct answer.
- Scope and as-of date.
- Process or control.
- Evidence or example.
- Limitation, exception, or planned remediation.
Avoid absolute language such as “never,” “fully secure,” “guaranteed,” or “no conflicts” unless counsel and evidence support it. Describe controls accurately: “The firm performs X at frequency Y under policy Z,” not “The firm has industry-leading controls.”
If a requested fact is unavailable, state what is available and when the gap may be resolved. Do not invent precision.
Tailor without creating inconsistency
Reusable answers save time, but every DDQ requires context review. Confirm:
- correct manager and fund entity;
- product and strategy;
- geography and investor type;
- current team and providers;
- date and reporting period;
- definitions and methodology;
- confidentiality status;
- investor-specific side letters or requirements; and
- requested format and word limits.
Track changes from the approved module. A subject-matter owner should review material deviations before delivery. Feed improvements back into the library rather than leaving them isolated in one questionnaire.
Approval workflow
A risk-based workflow may use:
- drafter or coordinator;
- subject-matter owner;
- compliance or legal reviewer for regulated, conflicts, performance, litigation, or disclosure questions;
- security or privacy reviewer for sensitive technical evidence;
- finance or tax reviewer for calculations;
- senior approver for certifications; and
- delivery owner.
Define thresholds. A date update to an approved office address may need a lighter review than a new answer about a cybersecurity incident or regulatory inquiry.
The final file should show version, as-of date, fund, and approval status internally. Remove internal comments and tracked changes from the investor copy.
Confidentiality tiers
Use tiers such as:
- public or website-level;
- prospective investor before NDA;
- NDA investor;
- restricted specialist review;
- LPAC or existing-investor only;
- clean-team or supervised review; and
- internal or privileged.
Map every answer and evidence document to a tier. Configure investor groups accordingly. Do not send security reports, personal information, contract terms, or privileged advice merely because a questionnaire requests them.
Where full evidence cannot be shared, offer an executive summary, redacted version, supervised review, or direct confirmation from an appropriate service provider when suitable.
Supporting-document room
Organize evidence using a stable index:
- 00 Guide and index
- 01 Firm and organization
- 02 Fund and strategy
- 03 Team and governance
- 04 Operations and finance
- 05 Compliance and legal
- 06 Valuation and risk
- 07 Service providers
- 08 Cybersecurity, privacy, and business continuity
- 09 ESG or responsible investment
- 10 Tax and structure
- 11 Investor-specific responses
Remove irrelevant sections. Keep one authoritative copy. Add description, entity, date, owner, confidentiality, and version metadata.
Use separate groups for each investor organization. Prevent cross-investor Q&A and document visibility.
Cybersecurity and privacy responses
Coordinate with the security and privacy owners. Common DDQ topics include governance, identity, encryption, vulnerability management, testing, incident response, business continuity, vendors, privacy roles, retention, transfers, and training.
Answer within the evidence scope. An independent report may cover specified systems and a defined period, not every affiliate or future control. Avoid sharing penetration-test exploit details, credentials, network diagrams, or unresolved vulnerabilities in a general room.
For incident questions, use the approved disclosure process. “No material incident” can involve legal judgment and a defined period; it should not be improvised by a coordinator.
Performance and track-record questions
Use approved figures, gross/net definitions, currency, vintage, realization status, time period, benchmark, and methodology. Reconcile the DDQ to pitchbooks, track-record schedules, financial statements, and regulatory disclosures.
Do not select only favorable examples without required context. Hypothetical, extracted, predecessor, or composite performance may require specific explanation. Route investor-specific analyses through compliance and legal review.
Preserve the exact delivered schedule and source snapshot.
ESG and responsible-investment questions
State the actual process and scope. Distinguish firm policy, fund commitment, investment-stage assessment, ownership practice, portfolio reporting, and regulatory disclosure. Avoid claiming universal integration if some strategies or asset classes are excluded.
Define metrics, boundaries, estimation, frequency, and assurance. Provide examples that are approved and representative. Review terminology against current legal and regulatory guidance in relevant jurisdictions.
Service-provider evidence
Investors may request administrator, auditor, custodian, prime broker, bank, legal, technology, and outsourced-provider information. Confirm current appointments and exact entities.
Third-party reports and contracts may have distribution restrictions. Verify permission before sharing. A bridge letter or provider portal may be more appropriate than uploading a restricted report.
Describe oversight performed by the manager rather than relying only on provider reputation.
Manage Q&A after delivery
Create an investor-specific channel. Triage follow-ups to owners. Link answers to the submitted DDQ and evidence. If a follow-up reveals an incorrect or outdated response, correct it promptly, identify the affected documents, and decide whether other investors received the same error.
Add approved new answers to the library with scope and review dates. Do not copy an investor-specific concession into the standard module.
Delivery controls
Before delivery:
- confirm the authorized recipient and NDA;
- verify final approval;
- remove comments, hidden sheets, tracked changes, and metadata;
- check links and attachments;
- confirm confidentiality markings;
- use the approved channel;
- set expiry or revocation where appropriate;
- record exactly what was sent and when; and
- preserve a final copy and evidence index.
SendNow Word document sharing may suit a limited approved response package. A multi-document or multi-investor fundraising process may require an investor data room with granular organization groups and Q&A.
Change management
Trigger a review when there is a new fund, strategy, entity, office, senior hire or departure, service provider, regulatory status, litigation matter, security incident, policy, valuation method, performance period, or material ESG change.
Maintain an impact list of active DDQs, room documents, pitchbooks, website claims, filings, and investor notices. One corrected answer is not sufficient if the same claim exists elsewhere.
Metrics that improve the workflow
Track:
- turnaround time by domain;
- questions answered from approved modules;
- modules past review date;
- material deviations;
- evidence gaps;
- review cycles;
- missed deadlines;
- corrections after delivery; and
- repeated investor questions.
Use metrics to fix bottlenecks, not to pressure reviewers to approve riskier answers. Quality and traceability are the primary outcomes.
Archive and retention
Preserve the original questionnaire, working version according to policy, final delivered response, approvals, source snapshot, evidence list, delivery record, and follow-up Q&A. Store investor-specific and privileged material separately.
Apply fund, regulatory, contract, privacy, and legal-hold requirements. Revoke portal access when the process ends and delete redundant working copies under the approved schedule.
LP DDQ workflow checklist
- Intake records fund, investor, due date, NDA, and format.
- Questions are routed to named subject-matter owners.
- Approved modules have scope, evidence, and review dates.
- Current facts have sources and as-of dates.
- Material deviations receive approval.
- Confidentiality tiers control answer and document access.
- Performance, conflicts, incidents, and certifications receive specialist review.
- Final files are sanitized and delivered through an approved channel.
- Follow-up Q&A updates the evidence and answer libraries.
- Final response, approvals, delivery, and sources are archived.
Sources and verification notes
- Institutional Limited Partners Association DDQ and resources: https://ilpa.org/
- U.S. Securities and Exchange Commission, private funds: https://www.sec.gov/investment/private-funds
- SEC Investment Adviser Public Disclosure: https://adviserinfo.sec.gov/
- NIST Cybersecurity Framework 2.0: https://www.nist.gov/cyberframework
- NIST Privacy Framework: https://www.nist.gov/privacy-framework
Use the current version of any industry questionnaire and verify regulatory guidance for the relevant manager, fund, investor, and jurisdiction. This workflow does not determine required disclosures.