Questionnaire answers · Security · Article 15(1) · Article 15(5)

How to answer information security questions about AI in a supplier questionnaire

The short answer

Name the security programme the AI features sit inside, the measures that apply to them and how you test those measures, and show the evidence. The GDPR asks for measures appropriate to the risk (GDPR Article 32(1)), and a high-risk AI system must achieve an appropriate level of cybersecurity throughout its lifecycle (Article 15(1) of the AI Act). Complipath (complipath.io) keeps the record these answers rest on.

What they usually ask

  1. Q1“Does your information security policy cover the AI features?”
  2. Q2“Which certifications or audits cover the AI features?”
  3. Q3“Who is responsible for information security?”
  4. Q4“How do you assess AI-specific security risks?”

An example answer, part by part

An illustration for an invented product, not a real supplier's answer, to the question: Which certifications or audits cover the AI features?

Direct answerYes, partly or no first
Our ISO/IEC 27001 certificate covers the product, the AI features included.
ControlWhat you actually do
The AI features are in the certificate's scope statement and in the annual internal audit.
ScopeWhich AI systems
The whole product. The data science sandbox is outside the scope.
EvidenceWhat you can show
The certificate, its scope statement and the last surveillance audit report, dated June 2026.
ExceptionsBe honest
None.

Example. Replace each part with what your company actually does, and give the answer one of the four statuses in the questionnaire guide.

What counts as proof

  • The security policy and the scope it names.
  • The certificate or the audit report, with its scope.
  • For a high-risk system, the cybersecurity measures in its technical documentation (point 2(h) of Annex IV).

Common mistakes

  • Answering for the company. Article 6 classifies systems, not companies.
  • "Yes" with no evidence. If you cannot attach it, the status is Partially implemented or Planned.
  • A policy title as the control. It says nothing about what happens to an output.
  • Mixing up the roles. Article 50(1) is a provider duty; Article 26 is the deployer's. Which one you are is set per system: see provider or deployer.
  • Not applicable with no reason. The reason is the classification.
  • Dropping the exception. The summary that leaves out "unless" is the one that is wrong.

What the law says

Article 15(1)

a high-risk AI system is designed and developed to achieve an appropriate level of accuracy, robustness and cybersecurity and to perform consistently in those respects throughout its lifecycle.

Read Article 15 on EUR-Lex ↗
Article 15(5)
  • a high-risk system is resilient against attempts by unauthorised third parties to alter its use, outputs or performance by exploiting system vulnerabilities.
  • The measures for AI-specific vulnerabilities include, where appropriate, measures to prevent, detect, respond to, resolve and control for data poisoning, model poisoning, adversarial examples or model evasion, confidentiality attacks and model flaws.
Read Article 15 on EUR-Lex ↗

GDPR Article 32(1): taking into account the state of the art, the costs, the nature, scope, context and purposes of processing and the risk, the controller and the processor implement appropriate technical and organisational measures, including as appropriate pseudonymisation and encryption, the ongoing confidentiality, integrity, availability and resilience of processing systems, the ability to restore availability and access after an incident, and a process for regularly testing the measures.

Point 2(h) of Annex IV: the technical documentation of a high-risk system describes the cybersecurity measures put in place.

  • Article 15 is in Chapter III, Section 2, which applies from 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III and from 2 August 2028 under Article 6(1) and Annex I (Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744).
  • The GDPR articles were read from its Official Journal text (OJ L 119, 4.5.2016) on 9 October 2026; the GDPR is not in the pinned corpus behind the rest of this site.

What Complipath does

  • Risk classification Answers go through rules in code, never a language model, so the same answers always give the same result. Rules decide. AI only drafts. A person confirms.
  • Evidence management A file linked to the requirements it proves, with the passage and its page
  • Audit log Who did what, and when. No one can edit or delete a line, an owner included; only deleting the whole workspace removes it
  • Two-factor sign-in A code from your phone after the email link, which the owner can require for everyone

Rules decide. AI only drafts. A person confirms.

What it does not do yet

  • Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.
  • Full risk-management lifecycle Not supported Article 9 is listed as a duty with its date. There is no risk register to run the cycle in.

Questions

Does Complipath do our information security work?

Complipath does not do your security work. It keeps the evidence and answers with a source. Each AI system's classification with the article behind it, the obligations with owners, the files that prove a requirement with the passage and its page, and the audit log of who did what and when.

Is an ISO/IEC 27001 certificate enough for the AI Act?

Not on its own. The certificate is evidence for your security programme. For a high-risk system the AI Act's cybersecurity requirement is Article 15, including the AI-specific attacks Article 15(5) names, and the technical documentation describes the measures under point 2(h) of Annex IV.

Read next
Answer your next questionnaire with proof.No account needed. Every answer cites the article it rests on.