Skip to main content

Ask an ODD team what's changed about their questionnaire process over the past two years, and AI comes up almost immediately: automated drafting, gap detection, natural-language search across years of prior responses. Ask what's changed about the risk picture that process actually produces, and the answer tends to be a good deal more careful. That gap between the two answers is worth sitting with, because it's roughly where the current AI-in-DDQ conversation goes wrong.

Every DDQ and RFP platform on the market now markets some version of AI capability, and the workflow gains behind the marketing are often genuine. But a due diligence questionnaire, however it's drafted, reviewed or cross-referenced, still rests on the same foundation it always has: what a manager chooses to tell you, framed the way they choose to tell it. AI changes a great deal about how that information gets assembled, checked and searched. It changes very little about whether it's true. This piece sets out, as precisely as we can, where that line actually falls.

What AI Genuinely Changes About the DDQ Workflow

The improvements are real, and worth naming clearly rather than waving away. Applied to the mechanics of the questionnaire process, AI-assisted tools can:

  • Pre-populate responses from a manager's existing evidence library — drawing on policy documents, prior questionnaires and supporting materials already on file, rather than an analyst or IR team rebuilding answers from scratch each cycle.
  • Flag inconsistencies within and across responses — surfacing where an answer in one section contradicts another, or where a current response has quietly drifted from what the same manager said eighteen months earlier.
  • Summarise dense supporting documentation — turning a fifty-page business continuity plan or valuation policy into a structured summary an analyst can review in minutes rather than hours, with the source material still available to check.
  • Search across long-form, historical responses in natural language — letting an analyst ask “what has this manager said about key-person risk over the last three cycles” and get a direct answer instead of manually cross-referencing PDFs.
  • Highlight gaps and ambiguous answers — identifying questions left partially answered or phrased vaguely enough to warrant a follow-up, before a human reviewer ever opens the document.

Put together, this is a genuine and meaningful efficiency gain. It compresses the time between sending a questionnaire and having a properly reviewed response in hand, and it frees analyst time that used to go on document assembly and formatting. For a function that is, per our own research and conversations across the industry, consistently under-resourced rather than under-motivated, that time matters.

None of it, however, changes what kind of evidence a questionnaire response is.

What AI Does Not Change

A questionnaire, AI-assisted or not, is still self-reported data. An AI tool applied to a manager's response can check that response for internal consistency, compare it against prior cycles, and flag where language is vague or a question has been skipped. What it cannot do is verify that the answer reflects what's actually happening inside the manager's operations, because the only evidence it has to work with is the text the manager chose to provide. If a risk isn't disclosed, there is nothing in the questionnaire for any tool, AI-assisted or otherwise, to find.

This is worth being specific about, because it maps onto exactly the three categories of risk we've written about elsewhere as the ones a questionnaire-led process structurally misses. Financial stress, of the kind that shows up in revenue concentration or a thinning cash position relative to operational expense, is not something a manager typically volunteers in a DDQ, and no amount of AI analysis applied to the questionnaire itself changes that; it requires independent financial statement analysis, which is a different discipline entirely. Cyber exposure works the same way: a manager can describe their security controls accurately and still be running systems with an exposed external attack surface that only independent technical scanning would reveal. An AI tool reading the narrative answer has no way to see the infrastructure behind it. And reputational or personnel risk, the kind that tends to surface first in trade press or legal filings rather than a formal disclosure, sits outside the questionnaire altogether until a manager chooses to address it, by which point continuous media monitoring will typically have already picked it up.

AI-assisted DDQ tools also don't remove the judgement calls that sit at the centre of operational due diligence. Whether a governance structure is adequate for a fund of a given size and complexity, whether a stated succession plan is credible, whether a valuation policy's stated methodology actually gets applied in practice, none of these are pattern-matching problems a language model resolves on an analyst's behalf. They're assessments that still require someone who understands the manager, the strategy and the regulatory context to make a call, and to be able to explain that call to an investment committee or a regulator afterwards.

That last point deserves its own emphasis, because it's becoming more relevant, not less. In July 2026, the EU's three European Supervisory Authorities (EBA, EIOPA and ESMA) issued a joint statement calling for enhanced governance and consistent supervision of the ICT and cyber risks that frontier AI models introduce into the financial sector. An early sign that regulatory attention is shifting from what AI systems produce to how financial firms govern their use of AI at all. An ODD function is a reasonable place to expect that scrutiny to extend next. An ODD process that can't clearly explain how an AI-assisted step reached its output, and what a human reviewer did with that output, is building a governance gap into the very process meant to identify governance gaps elsewhere.

The Real Risk: Mistaking Faster for More Thorough

The genuine efficiency gains above create a specific and easy-to-miss risk of their own: speed can be mistaken for rigour. A tool that returns a clean, well-formatted, internally consistent questionnaire review in minutes can create a false sense that more scrutiny has happened than actually has, particularly if a team lets the AI-assisted first pass substitute for, rather than support, an analyst's own judgement on the material.

This is not an argument against the technology. It's an argument for being precise about what it has and hasn't done. An AI-assisted tool that checks a response for internal consistency and flags a gap has done useful, legitimate work. It has not verified the manager's financial position, tested their external attack surface, or confirmed there's no adverse coverage sitting in a specialist trade publication that hasn't reached mainstream news yet. Treating “the AI reviewed it” as equivalent to “this has been independently verified” is the single easiest way for this technology to make an ODD programme feel more thorough while actually leaving the same blind spots in place, just processed faster.

What to Ask Before Adopting an AI-Assisted DDQ Tool

For teams evaluating this category of tool, a few questions tend to separate genuine capability from a well-marketed autocomplete function.

  • Does it flag inconsistencies against a manager's own historical responses and supporting documents, or only within the single questionnaire in front of it?
  • Is its output explainable, in a form a compliance function or an investment committee can actually interrogate, rather than a confidence score with no visible reasoning?
  • Does adopting it free analyst time toward independent verification work, financial, cyber, reputational, or does it simply produce a faster version of the same self-reported document?
  • Given the sensitivity of the material involved, how is manager data handled, and is any of it used to train models outside the firm's own environment?

Where This Leaves ODD Teams

AI-assisted DDQ tools, including the capability built into Thomas Murray's own Orbit Diligence platform, address a real and specific problem: the questionnaire workflow itself has been slow, manual and repetitive, and that's worth fixing. Used well, they let ODD teams move faster through drafting, review and gap analysis, and redirect the time saved toward the parts of the job that still require human judgement and independent evidence.

What they don't do is change the underlying argument we've made elsewhere: that a self-reported questionnaire, however efficiently it's produced and reviewed, needs to sit alongside independent financial, cyber and media signals to give allocators a genuinely current view of manager risk. An AI-assisted DDQ is a better version of the same instrument. It is not a substitute for the multi-signal monitoring that catches what no version of the questionnaire, however well built, was ever designed to see.

For a fuller view of how questionnaire data fits alongside financial, cyber and media monitoring in a modern ODD framework, Thomas Murray's Operational Due Diligence: A Playbook for Asset Owners and Allocators covers the fundamentals in full.


Curious what AI-assisted questionnaire review looks like inside a broader ODD programme? Speak to our team about Orbit Diligence, or explore how Orbit Diligence and Orbit Risk work together to see workflow efficiency and independent monitoring in the same entity record.


Operational Due Diligence

Operational Due Diligence

Automate your operational due diligence with Orbit Risk technology. 

Get ongoing monitoring of your investment managers, track adverse media, and receive cyber risk alerts as they happen.

Learn more