Questionnaire answers · Security · Article 15(5)
How to answer encryption questions in a supplier questionnaire
Written by Yobel TzegaiLast reviewed 9 October 2026Checked against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744
The short answer
Say what is encrypted in transit and at rest, with which keys and who holds them, and show the configuration. The GDPR names pseudonymisation and encryption among the measures to take as appropriate (GDPR Article 32(1), point (a)). No article of the AI Act requires encryption; for a high-risk system the cybersecurity it needs is set by Article 15. Complipath (complipath.io) keeps the record these answers rest on.
What they usually ask
- Q1“Is our data encrypted in transit and at rest?”
- Q2“Who manages the encryption keys?”
- Q3“Are the AI model's inputs and outputs encrypted?”
- Q4“Can your staff read our data?”
An example answer, part by part
An illustration for an invented product, not a real supplier's answer, to the question: Is our data encrypted in transit and at rest?
- Direct answerYes, partly or no first
- Yes. In transit with TLS, at rest with the database provider's disk encryption.
- ControlWhat you actually do
- Encryption is on by default in the database configuration and cannot be switched off by a user.
- ScopeWhich AI systems
- Every customer table and every backup. Logs are encrypted at rest the same way.
- EvidenceWhat you can show
- The configuration screen and the provider's encryption documentation, read on 1 October 2026.
- ExceptionsBe honest
- None.
Example. Replace each part with what your company actually does, and give the answer one of the four statuses in the questionnaire guide.
What counts as proof
- DOCThe configuration that turns encryption on, for each store of customer data.
- DOCThe key management record: where the keys are and who can use them.
- DOCThe provider's documentation for what it encrypts, with the date it was read.
Common mistakes
- ✗Answering for the company. Article 6 classifies systems, not companies.
- ✗"Yes" with no evidence. If you cannot attach it, the status is Partially implemented or Planned.
- ✗A policy title as the control. It says nothing about what happens to an output.
- ✗Mixing up the roles. Article 50(1) is a provider duty; Article 26 is the deployer's. Which one you are is set per system: see provider or deployer.
- ✗Not applicable with no reason. The reason is the classification.
- ✗Dropping the exception. The summary that leaves out "unless" is the one that is wrong.
What the law says
GDPR Article 32(1): taking into account the state of the art, the costs, the nature, scope, context and purposes of processing and the risk, the controller and the processor implement appropriate technical and organisational measures, including as appropriate pseudonymisation and encryption, the ongoing confidentiality, integrity, availability and resilience of processing systems, the ability to restore availability and access after an incident, and a process for regularly testing the measures.
Article 15(5)- the AI Act asks a high-risk system to be resilient against attempts by unauthorised third parties to alter its use, outputs or performance.
- It names AI-specific attacks, among them confidentiality attacks.
- The word encryption appears once in the Regulation, in recital 69 on data protection, and in no article.
Read Article 15 on EUR-Lex ↗ - Article 15 is in Chapter III, Section 2, which applies from 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III and from 2 August 2028 under Article 6(1) and Annex I (Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744).
- The GDPR articles were read from its Official Journal text (OJ L 119, 4.5.2016) on 9 October 2026; the GDPR is not in the pinned corpus behind the rest of this site.
What Complipath does
- ✓Evidence management A file linked to the requirements it proves, with the passage and its page
- ✓Audit log Who did what, and when. No one can edit or delete a line, an owner included; only deleting the whole workspace removes it
- ✓Two-factor sign-in A code from your phone after the email link, which the owner can require for everyone
Rules decide. AI only drafts. A person confirms.
What it does not do yet
- ✗Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.
- ✗Audit pack Coming soon One file for an auditor: every system, its classification, evidence, the audit log and a fingerprint. Not available yet.
Questions
Does Complipath encrypt our systems for us?
Complipath does not do your security work. It keeps the evidence and answers with a source. It records what you answer for each AI system and links the file that proves it, such as the encryption configuration, with the passage and its page.
Does the AI Act require encryption?
No article of the AI Act requires it; the word appears once, in recital 69 on data protection, among measures that may help. For a high-risk system Article 15 asks for an appropriate level of cybersecurity, and the GDPR names encryption among the measures in Article 32(1), point (a).
Answer your next questionnaire with proof.No account needed. Every answer cites the article it rests on.