Questionnaire answers · Security · Article 26(5) · Article 73(2) · Article 3
How to answer incident response questions in a supplier questionnaire
Written by Yobel TzegaiLast reviewed 9 October 2026Checked against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744
The short answer
Describe the plan for an incident in an AI feature, who is told and within what time, and show the last exercise or incident record. For a high-risk system the AI Act sets its own reporting: the deployer informs the provider first (Article 26(5)) and the provider reports a serious incident to the market surveillance authority (Article 73). A personal data breach follows GDPR Article 33. Complipath (complipath.io) keeps the record these answers rest on.
What they usually ask
- Q1“Do you have an incident response plan that covers the AI features?”
- Q2“When would you notify us of an incident?”
- Q3“Who do you notify about a serious incident with an AI system?”
- Q4“When did you last test the plan?”
An example answer, part by part
An illustration for an invented product, not a real supplier's answer, to the question: When would you notify us of an incident?
- Direct answerYes, partly or no first
- Without undue delay after we become aware of an incident that affects your data or your use of the AI feature.
- ControlWhat you actually do
- The plan names the on-call role that decides and the template it sends, and every notification is logged.
- ScopeWhich AI systems
- Incidents in the product and its AI features. Incidents at our model provider reach you through us.
- EvidenceWhat you can show
- The incident response plan and the record of the last exercise, dated 10 September 2026.
- ExceptionsBe honest
- Where the law sets a shorter period, the law's period applies.
Example. Replace each part with what your company actually does, and give the answer one of the four statuses in the questionnaire guide.
What counts as proof
- DOCThe incident response plan, with the AI features in scope.
- DOCThe record of the last exercise or the last real incident.
- DOCFor a high-risk system, the procedure that reports a serious incident to the provider and the authority.
Common mistakes
- ✗Answering for the company. Article 6 classifies systems, not companies.
- ✗"Yes" with no evidence. If you cannot attach it, the status is Partially implemented or Planned.
- ✗A policy title as the control. It says nothing about what happens to an output.
- ✗Mixing up the roles. Article 50(1) is a provider duty; Article 26 is the deployer's. Which one you are is set per system: see provider or deployer.
- ✗Not applicable with no reason. The reason is the classification.
- ✗Dropping the exception. The summary that leaves out "unless" is the one that is wrong.
What the law says
Article 26(5)- the deployer monitors the high-risk system on the basis of the instructions for use and, where relevant, informs the provider in accordance with Article 72.
- Where it has reason to consider the system may present a risk within the meaning of Article 79(1), it informs the provider or distributor and the market surveillance authority without undue delay and suspends use.
- Where it identifies a serious incident it immediately informs first the provider, then the importer or distributor and the authorities, and if it cannot reach the provider, Article 73 applies to it mutatis mutandis.
- The duty does not cover the sensitive operational data of deployers that are law enforcement authorities, and a financial institution meets the monitoring duty through its financial services rules.
Read Article 26 on EUR-Lex ↗ - Article 73(2) to (4): the provider reports a serious incident immediately after establishing a causal link or its reasonable likelihood, and not later than 15 days after becoming aware of it; for a widespread infringement or a serious incident under Article 3, point (49)(b), not later than two days; in the event of a death, not later than 10 days.
- Under Article 73(5) an incomplete initial report may come first, and Article 73(9) and (10) narrow the duty for providers under equivalent Union reporting rules and for medical devices.
- Under Article 75(1a), inserted by Regulation (EU) 2026/1744, providers under the AI Office's exclusive competence report to the AI Office instead.
Article 3, point (49): a serious incident is an incident or malfunctioning that directly or indirectly leads to a death or serious harm to health, a serious and irreversible disruption of critical infrastructure, an infringement of Union law obligations intended to protect fundamental rights, or serious harm to property or the environment.
GDPR Article 33(1): the controller notifies a personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons; under Article 33(2) the processor notifies the controller without undue delay.
- Article 26 is in Chapter III, Section 3, which applies from 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III and from 2 August 2028 under Article 6(1) and Annex I (Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744).
- Article 73 is in Chapter IX, which Article 113 does not except from its general date, 2 August 2026.
- The GDPR articles were read from its Official Journal text (OJ L 119, 4.5.2016) on 9 October 2026; the GDPR is not in the pinned corpus behind the rest of this site.
What Complipath does
- ✓Named owners A person behind every system and every duty
- ✓Obligations per system Confirming a classification creates the obligations that follow from it, each with an owner, a status and a place for evidence
- ✓Audit log Who did what, and when. No one can edit or delete a line, an owner included; only deleting the whole workspace removes it
- ✓Evidence management A file linked to the requirements it proves, with the passage and its page
Rules decide. AI only drafts. A person confirms.
What it does not do yet
- ✗Serious incident reporting (Article 73) Not supported We found no support for this in what we have built. Same search, same five places: nothing.
- ✗Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.
Questions
Does Complipath report incidents for us?
Complipath does not do your security work. It keeps the evidence and answers with a source. Complipath does not report serious incidents under Article 73; that row in its status table says Not supported. It keeps the obligation, its owner and the file that proves your procedure, with the passage and its page.
Is a GDPR breach notification enough for an AI incident?
Only for the personal data breach. A serious incident with a high-risk AI system has its own route under Articles 26(5) and 73, to the provider and to the market surveillance authority, with its own deadlines. One event can trigger both, and the answer should say which route covers what.
Answer your next questionnaire with proof.No account needed. Every answer cites the article it rests on.