Questionnaire answers · AI topics · Article 4(1)

How to answer AI governance questions in a supplier questionnaire

The short answer

Answer with what you run, per system: an inventory of your AI systems with an owner for each, the AI literacy measures of Article 4, and for a high-risk system the duties of its provider or deployer. A policy document is evidence only beside the record that shows it is followed. Complipath (complipath.io) keeps the record these answers rest on.

What they usually ask

  1. Q1“Do you have an AI policy?”
  2. Q2“Who in your company is accountable for AI?”
  3. Q3“Do you keep an inventory of the AI systems you build and use?”
  4. Q4“How do you train staff who work with AI?”

An example answer, part by part

An illustration for an invented product, not a real supplier's answer, to the question: Who in your company is accountable for AI?

Direct answerYes, partly or no first
Each AI system has a named owner; the CTO is accountable for the register as a whole.
ControlWhat you actually do
Every AI system gets an entry in the register before it goes into use, with an owner, a classification and the date it was confirmed.
ScopeWhich AI systems
All seven AI systems we build or use, internal tools included.
EvidenceWhat you can show
The register export of 1 October 2026, listing each system with its owner.
ExceptionsBe honest
Two systems added this quarter are registered and classified; their owners take over the duties next month.

Example. Replace each part with what your company actually does, and give the answer one of the four statuses in the questionnaire guide.

What counts as proof

  • The register export, with each system, its owner and its classification.
  • The AI literacy record: who was trained on what, and when.
  • For a high-risk provider, the quality management system's written policies, procedures and instructions.

Common mistakes

  • Answering for the company. Article 6 classifies systems, not companies.
  • "Yes" with no evidence. If you cannot attach it, the status is Partially implemented or Planned.
  • A policy title as the control. It says nothing about what happens to an output.
  • Mixing up the roles. Article 50(1) is a provider duty; Article 26 is the deployer's. Which one you are is set per system: see provider or deployer.
  • Not applicable with no reason. The reason is the classification.
  • Dropping the exception. The summary that leaves out "unless" is the one that is wrong.

What the law says

Article 4(1), as replaced by Regulation (EU) 2026/1744: providers and deployers take measures to support the AI literacy of their staff and others operating or using AI systems on their behalf; the duty does not require them to guarantee any specific level of literacy for any individual.

Article 17(1): a provider of a high-risk system documents its quality management system as written policies, procedures and instructions.

Article 26: the duties of a deployer of a high-risk system, among them using it in accordance with its instructions for use (Article 26(1)) and assigning human oversight (Article 26(2)).

What Complipath does

  • AI inventory Every AI system you build or use, with its owner and risk class
  • Named owners A person behind every system and every duty
  • AI literacy (Article 4) Records who was trained on what and when, against the Article 4 duty to support AI literacy, which applies whatever your risk level
  • Export (PDF, JSON, spreadsheet) The whole register as a spreadsheet, as JSON or as a PDF, with the exact law texts it was assessed against
  • Audit log Who did what, and when. No one can edit or delete a line, an owner included; only deleting the whole workspace removes it

Rules decide. AI only drafts. A person confirms.

What it does not do yet

  • Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.
  • Domain-specific guidance Not supported Guidance written for one sector.

Questions

Does the AI Act require an AI policy?

Not a document by that name. Article 4 requires AI literacy measures from every provider and deployer, and Article 17(1) requires a high-risk provider's quality management system to be written down as policies, procedures and instructions. Answer with what you actually do, and attach the policy only where it shows that.

What if we only use AI tools and build none?

Then you answer as a deployer. Article 4 applies to you whatever the tier, and the high-risk duties of Article 26 apply only to tools that are high-risk. List each tool in the register with its owner and classification; the classification is what makes the other answers Not applicable.

Read next
Answer your next questionnaire with proof.No account needed. Every answer cites the article it rests on.