
What a hedge fund or family office due diligence questionnaire actually asks about your IT
8 September 2026
Due diligence season doesn't really end for firms in financial services, it just changes name depending on who's asking. Investors doing operational due diligence before allocating capital. Insurers underwriting a cyber policy. A family office's principal asking pointed questions before signing anything. An institutional client running a vendor review before onboarding. Different forms, same underlying question: can you actually show us how this is managed, not just tell us it's fine.
IT and security sit right in the middle of that. Most of what gets asked about your technology setup isn't exotic. It's a fairly predictable set of questions, and firms who can answer them quickly, with evidence rather than reassurance, get through the process faster and look more credible doing it. Here's what actually shows up, and what's changing about how much weight it now carries.
What's typically asked
Strip away the specific wording and most due diligence questionnaires are asking variations on the same handful of things:
- Do you hold independent certification for information security (ISO 27001, Cyber Essentials Plus), or is your security posture self-assessed?
- What's your process for detecting, containing and reporting a security incident, and how fast do you tell affected parties?
- When was your disaster recovery plan last actually tested, not just documented?
- Who has access to what data, and how is that access reviewed and removed when someone leaves?
- What third parties and subcontractors sit behind your own systems, and have you assessed their risk too?
- What's your cyber insurance coverage, and does it match your actual exposure?
- How do staff get trained on security, and how often?
- If you or your provider use AI tools, what governs what data can go into them?
None of this is unusual to ask. What's changed is how specific the follow-up questions have got, and how little patience allocators, insurers and boards now have for vague answers.
Why family offices see a slightly different version of this
A family office asking these questions isn't running a formal institutional process, there's often no compliance team drafting the questionnaire. It's usually the principal, or someone close to them, asking in plain language because their own reputation and capital are directly on the line. That tends to make the questions blunter, not softer. "What happens if you get hacked" is the family office version of "describe your incident response procedure," and it deserves the same quality of answer, just without the jargon.
Why this is getting sharper, not softer
Two regulatory developments this year are pushing the questions further still.
In March 2026, the FCA, PRA and Bank of England jointly published new rules (PS26/2 from the FCA, with the PRA's parallel PS7/26) requiring firms to report operational incidents and notify regulators about "material third party arrangements," meaning suppliers whose failure could seriously disrupt the business or harm clients. The three regulators built this as a single, coordinated regime deliberately, so a dual-regulated firm only has to make one submission rather than separate reports to each. The rules come into force in March 2027, but firms have a twelve month window now to get ready, and that preparation work runs straight through their supplier relationships. If your fund or family office is going to have to map and report its material third parties from next year, the questions to those third parties, including whoever runs your IT, start getting asked well before the deadline, not after it.
Separately, the Cyber Security and Resilience Bill, currently at Committee Stage in the House of Lords as of this month, is creating a new regulated category for managed service providers, alongside data centres and large-scale IT operators. It hasn't passed yet, but the direction is clear enough that any firm relying on an outsourced IT provider is right to start asking that provider whether they're preparing for it.
Put together, these two things mean the questions in a due diligence pack aren't just a compliance exercise on your side any more. They're a preview of what your own regulator is going to expect you to already know about your suppliers.
What actually holds up under scrutiny
The firms that get through due diligence with the least friction tend to have the same handful of things ready before they're asked, rather than scrambling once the questionnaire lands:
- A current, independently issued certificate (ISO 27001 or Cyber Essentials Plus), not a statement of intent to get one
- A one-page incident response summary showing timelines, not just a policy document nobody's read since it was written
- Evidence a disaster recovery test actually happened this year, with a date and an outcome
- A subcontractor or subprocessor list, so nobody's surprised by what sits behind the service
- A cyber insurance certificate that's current and actually matches the cover the business needs
- A short, plain answer to what AI tools are approved for use and what data can go into them
None of this needs to be elaborate. It needs to exist, be current, and be something you can hand over the same day it's requested, rather than promise to pull together by the end of the week.
What a weak answer actually costs you
The cost isn't usually a flat "no." It's slower. A follow-up email. A second call to clarify. A deal that quietly loses momentum while the questionnaire sits half-answered. For a fund raising capital or an insurer setting a premium, that delay is the actual price, not a dramatic rejection, just friction that a well-prepared firm doesn't pay.
Where we come in
We help clients on both sides of this. For firms preparing their own due diligence pack, we help pull together the evidence, certification and answers investors and insurers are actually asking for. And because Maple itself is ISO 27001 and Cyber Essentials Plus accredited, we're also the answer to a lot of these questions when a client's own due diligence process turns to their IT provider.
If a due diligence request has landed on your desk and the honest answer is "we'd need a few days to pull that together," that's worth a conversation before the next one arrives.
Sources:
FCA Policy Statement PS26/2, Operational Incident and Third Party Reporting.
Bank of England / PRA PS7/26 (companion statement).
UK Parliament, Cyber Security and Resilience Bill progress page.