What Is the Difference Between DDQ, RFI, and RFQ?
Four documents, four jobs. An RFI explores what is available. An RFQ prices a clearly defined item. An RFP selects a supplier. A DDQ assesses whether approving that supplier is defensible. Three are procurement instruments; the DDQ is a risk instrument.
Source: What is a DDQ?
They get conflated because they arrive as long questionnaires, often from the same organisation, sometimes only weeks apart.
What do RFI, RFQ, RFP, and DDQ each do?
| RFI | RFQ | RFP | DDQ | |
|---|---|---|---|---|
| Question being asked | What exists? | What does this cost? | Who should we choose? | Is approving this defensible? |
| Stage | Earliest | Late, or standalone | Selection | After selection, before go-live |
| Requirements are | Loose | Fully specified | Defined but open on approach | Not applicable — controls are the subject |
| Primary owner | Procurement / business | Procurement | Procurement + business | Risk, compliance, vendor management |
| Decides on | Shortlist | Price | Supplier | Approval, and conditions |
| Recurs? | No | Sometimes | Rarely | Yes — on a review cycle |
| Evidence required | Little | Little | Some | Extensive |
Request for Information (RFI)
An RFI is a scoping exercise. The buyer knows they have a problem and wants to learn what the market offers before committing to requirements.
Answers are short, capabilities-focused, and non-binding. The outcome is usually a shortlist rather than a decision, and the questions tend to be broad: what does your product do, who else uses it, roughly what does it cost.
Because nothing is being decided, over-investing in an RFI is a common waste. The useful goal is to make the shortlist.
Request for Quotation (RFQ)
An RFQ asks for pricing on something already specified. Quantity, specification, and delivery terms are fixed; the variable is cost.
RFQs are most common for commodities and well-defined services. They appear less often in software, and when they do it is usually for a renewal or a defined seat count rather than a new platform decision.
If a buyer sends an RFQ, requirements are settled. Attempting to re-open the solution design at that point tends to read as non-responsive.
Request for Proposal (RFP)
An RFP defines a problem and asks suppliers to propose how they would solve it, at what price, with what evidence of capability.
This is the document where differentiation belongs. The buyer expects to be persuaded, and is comparing approaches, not just prices. Security and compliance sections usually appear here, and they are often the first place a fintech's evidence gets requested.
The full comparison against a DDQ is covered separately in DDQ vs RFP.
Due Diligence Questionnaire (DDQ)
A DDQ is not a procurement document at all. It is sent by the party that will carry regulatory responsibility for the relationship — a sponsor bank, a partner bank, a regulated buyer — to assess and document the controls behind the service.
Three properties set it apart:
- It usually arrives after the commercial decision. The parties intend to proceed; the DDQ determines whether they can.
- It demands evidence, not description. Most questions expect a narrative answer and a supporting document — a SOC 2 report, a policy, a penetration test.
- It recurs. Approval is not permanent. Relationships are re-reviewed, and material changes trigger fresh questions.
The sequence in practice
A full cycle rarely uses all four, but when it does the order is roughly:
- RFI — buyer explores the market, builds a shortlist
- RFP — buyer defines the problem, suppliers propose, one is selected
- RFQ — pricing confirmed against a settled specification (often folded into the RFP)
- DDQ — risk function assesses the selected supplier before go-live
- DDQ again — periodic re-review for as long as the relationship lasts
Step 5 is the one teams underestimate. The first DDQ feels like a one-off hurdle. It is the start of a recurring obligation.
Why the confusion is expensive
Misreading which document you are holding produces two predictable failures.
Answering a DDQ like an RFP. Persuasive, unevidenced copy lands in a risk file where every claim needs a source. Reviewers return it, and the delay hits revenue that is already committed.
Answering an RFP like a DDQ. Terse, heavily-caveated control statements are accurate but win nothing. The reader wanted a reason to choose you.
A quick diagnostic: look at who signed the covering email. Procurement or the business owner means you are being evaluated. Risk, compliance, or vendor management means you are being assessed — and every claim needs a source behind it.
Key takeaways
- RFI explores, RFQ prices, RFP selects, DDQ assesses risk
- The first three are procurement instruments; the DDQ is a risk instrument
- DDQs typically arrive after the commercial decision, so delays block committed revenue
- Only the DDQ recurs on a review cycle — which is what makes answer reuse valuable
- Check the sender's function before choosing register: evaluated, or assessed?
Describes common practice; terminology and sequencing vary between organisations and sectors. Not procurement or legal advice. Last updated 10 August 2026.
Related
- DDQ vs RFP — the two that overlap most
- DDQ automation: the complete guide
- Compliance glossary
