Questionnaire answers · Security · Article 15(5)
How to answer access control questions in a supplier questionnaire
Written by Yobel TzegaiLast reviewed 9 October 2026Checked against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744
The short answer
Say who can reach the customer's data and the AI system and how access is granted, reviewed and removed. Then show the access list. The GDPR asks that a person acting under your authority processes personal data only on the controller's instructions (GDPR Article 32(4)), and a high-risk system must resist attempts by unauthorised third parties to alter its use or outputs (Article 15(5) of the AI Act). Complipath (complipath.io) keeps the record these answers rest on.
What they usually ask
- Q1“Who at your company can access our data?”
- Q2“How is access granted and removed?”
- Q3“Do you use multi-factor authentication?”
- Q4“Who can change the AI model or its configuration?”
An example answer, part by part
An illustration for an invented product, not a real supplier's answer, to the question: Who can change the AI model or its configuration?
- Direct answerYes, partly or no first
- Two named engineers, through the deployment pipeline only.
- ControlWhat you actually do
- Changes go through a reviewed pull request, and the pipeline refuses a deploy without approval.
- ScopeWhich AI systems
- The model configuration and the prompt templates. Customer settings are changed by the customer's own admins.
- EvidenceWhat you can show
- The access list and the review log of the last three model changes.
- ExceptionsBe honest
- Emergency access is granted for one incident at a time and logged.
Example. Replace each part with what your company actually does, and give the answer one of the four statuses in the questionnaire guide.
What counts as proof
- DOCThe access list: who can reach customer data and the AI system, and why.
- DOCThe record of the last access review.
- DOCThe setting that requires multi-factor authentication.
Common mistakes
- ✗Answering for the company. Article 6 classifies systems, not companies.
- ✗"Yes" with no evidence. If you cannot attach it, the status is Partially implemented or Planned.
- ✗A policy title as the control. It says nothing about what happens to an output.
- ✗Mixing up the roles. Article 50(1) is a provider duty; Article 26 is the deployer's. Which one you are is set per system: see provider or deployer.
- ✗Not applicable with no reason. The reason is the classification.
- ✗Dropping the exception. The summary that leaves out "unless" is the one that is wrong.
What the law says
- GDPR Article 32(4): the controller and the processor ensure that any natural person acting under their authority who has access to personal data does not process them except on the controller's instructions, unless Union or Member State law requires it.
- Under Article 28(3), point (b), the people authorised to process the data are bound to confidentiality.
Article 15(5)- a high-risk system is resilient against attempts by unauthorised third parties to alter its use, outputs or performance by exploiting system vulnerabilities.
- The measures for AI-specific vulnerabilities include, where appropriate, measures to prevent, detect, respond to, resolve and control for data poisoning, model poisoning, adversarial examples or model evasion, confidentiality attacks and model flaws.
Read Article 15 on EUR-Lex ↗ - Article 15 is in Chapter III, Section 2, which applies from 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III and from 2 August 2028 under Article 6(1) and Annex I (Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744).
- The GDPR articles were read from its Official Journal text (OJ L 119, 4.5.2016) on 9 October 2026; the GDPR is not in the pinned corpus behind the rest of this site.
What Complipath does
- ✓Named owners A person behind every system and every duty
- ✓Audit log Who did what, and when. No one can edit or delete a line, an owner included; only deleting the whole workspace removes it
- ✓Two-factor sign-in A code from your phone after the email link, which the owner can require for everyone
Rules decide. AI only drafts. A person confirms.
What it does not do yet
- ✗Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.
- ✗Audit pack Coming soon One file for an auditor: every system, its classification, evidence, the audit log and a fingerprint. Not available yet.
Questions
Does Complipath control access to our systems?
Complipath does not do your security work. It keeps the evidence and answers with a source. Inside Complipath itself, sign-in takes a code from your phone after the email link, which the owner can require for everyone, and the audit log records who did what and when.
Does the AI Act say anything about access control?
Not in an article. Article 15(5) asks a high-risk system to resist attempts by unauthorised third parties to alter its use, outputs or performance. Recital 115 mentions cyber and physical access controls for general-purpose AI models with systemic risk. The GDPR's Article 32(4) is the closer rule for people who access personal data.
Answer your next questionnaire with proof.No account needed. Every answer cites the article it rests on.