Questionnaire answers · AI topics · Article 3 · Article 43(4)

How to answer model change and versioning questions in a supplier questionnaire

The short answer

Say what you record when a model, a prompt or a data source changes, and when a change sends a system back for a new classification. For a high-risk system the Act has a name for the change that matters, a substantial modification (Article 3(23)), and it brings a new conformity assessment (Article 43(4)). Complipath (complipath.io) keeps the record these answers rest on.

What they usually ask

  1. Q1“How do you version your models?”
  2. Q2“Do you notify customers of model changes?”
  3. Q3“How do you test a change before release?”
  4. Q4“What happens to your compliance when a model changes?”

An example answer, part by part

An illustration for an invented product, not a real supplier's answer, to the question: Do you notify customers of model changes?

Direct answerYes, partly or no first
Yes, for changes to the model behind a feature.
ControlWhat you actually do
A change of model or model version is announced in the changelog and by email to account owners before it reaches production.
ScopeWhich AI systems
All features that call a language model.
EvidenceWhat you can show
The changelog entry and the email of 14 September 2026 for the last model change.
ExceptionsBe honest
Prompt wording changes that pass the release tests are listed in the changelog and not emailed.

Example. Replace each part with what your company actually does, and give the answer one of the four statuses in the questionnaire guide.

What counts as proof

  • Your changelog or release notes, with the dates.
  • The test report of the change.
  • For a high-risk system, the record of whether a change was assessed as a substantial modification, and why.

Common mistakes

  • Answering for the company. Article 6 classifies systems, not companies.
  • "Yes" with no evidence. If you cannot attach it, the status is Partially implemented or Planned.
  • A policy title as the control. It says nothing about what happens to an output.
  • Mixing up the roles. Article 50(1) is a provider duty; Article 26 is the deployer's. Which one you are is set per system: see provider or deployer.
  • Not applicable with no reason. The reason is the classification.
  • Dropping the exception. The summary that leaves out "unless" is the one that is wrong.

What the law says

Article 3, point (23): a substantial modification is a change after placing on the market or putting into service that was not foreseen or planned in the initial conformity assessment and that affects compliance with Chapter III, Section 2, or modifies the intended purpose.

Article 43(4)

a high-risk system that has been through a conformity assessment goes through a new one after a substantial modification, unless, for a system that continues to learn, the change was pre-determined at the initial assessment and is part of the technical documentation.

Read Article 43 on EUR-Lex ↗

What Complipath does

  • Risk classification Answers go through rules in code, never a language model, so the same answers always give the same result. Rules decide. AI only drafts. A person confirms.
  • Regulatory change monitoring Checks the provisions your confirmed records cite against amending acts, and emails you per affected system
  • Audit log Who did what, and when. No one can edit or delete a line, an owner included; only deleting the whole workspace removes it
  • Export (PDF, JSON, spreadsheet) The whole register as a spreadsheet, as JSON or as a PDF, with the exact law texts it was assessed against

Rules decide. AI only drafts. A person confirms.

What it does not do yet

  • Conformity assessment (Article 43) Not supported We found no support for this in what we have built. The same search found the number in one file — a comment using it as an example of the Official Journal's citation form — and the words in six, every one of them quoting Article 6(1), point (b)'s third-party condition, an Article 5 sentence or a section name. No template, no column, no limb.
  • Post-market monitoring (Article 72) Not supported We found no support for this in what we have built. MVP searched 245 shipped source files, 44 migrations, 14 obligation templates, 15 export columns and 12 Annex IV limbs, on the article number and on the provision's own words: nothing on any of the five.
  • Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.

Questions

Is every model update a substantial modification?

No. Under Article 3, point (23) it is a change not foreseen in the initial conformity assessment that affects compliance with the high-risk requirements or modifies the intended purpose. A planned, documented update of a system that continues to learn is not one, under Article 43(4). The definition concerns high-risk systems.

Does Complipath track our model changes?

Not by itself. Complipath keeps each confirmed classification as it was and records who confirmed it and when; it watches amending acts for the provisions your records cite. A change to your own model is yours to record, and to re-run through the classification when it changes what the system does.

Read next
Answer your next questionnaire with proof.No account needed. Every answer cites the article it rests on.