Questionnaire answers · Security · Article 15(5) · Article 55(1)

How to answer penetration testing questions in a supplier questionnaire

The short answer

Say when the product was last tested, by whom, whether the AI features were in scope and what happened to the findings, and offer the summary. The AI Act does not use the words penetration test. The GDPR asks for a process for regularly testing the security measures (GDPR Article 32(1), point (d)). The AI Act asks a high-risk system to resist the attacks Article 15(5) names. Complipath (complipath.io) keeps the record these answers rest on.

What they usually ask

  1. Q1“When was your last penetration test?”
  2. Q2“Were the AI features in scope?”
  3. Q3“Who performed the test?”
  4. Q4“Can we see the findings and their status?”

An example answer, part by part

An illustration for an invented product, not a real supplier's answer, to the question: Were the AI features in scope?

Direct answerYes, partly or no first
Yes. The last test, in August 2026, covered the AI drafting feature and its API.
ControlWhat you actually do
Each annual test plan lists the AI features, and a release with a new AI feature triggers a scoped retest.
ScopeWhich AI systems
The web application, the API and the AI drafting feature. The model provider's own systems were not tested by us.
EvidenceWhat you can show
The tester's executive summary and our findings register, dated 30 August 2026.
ExceptionsBe honest
Two medium findings were open on the summary's date, each with an owner and a fix date.

Example. Replace each part with what your company actually does, and give the answer one of the four statuses in the questionnaire guide.

What counts as proof

  • The tester's executive summary, with scope and date.
  • The findings register with each finding's status.
  • For a general-purpose AI model with systemic risk, the documented adversarial testing (Article 55(1), point (a)).

Common mistakes

  • Answering for the company. Article 6 classifies systems, not companies.
  • "Yes" with no evidence. If you cannot attach it, the status is Partially implemented or Planned.
  • A policy title as the control. It says nothing about what happens to an output.
  • Mixing up the roles. Article 50(1) is a provider duty; Article 26 is the deployer's. Which one you are is set per system: see provider or deployer.
  • Not applicable with no reason. The reason is the classification.
  • Dropping the exception. The summary that leaves out "unless" is the one that is wrong.

What the law says

GDPR Article 32(1): taking into account the state of the art, the costs, the nature, scope, context and purposes of processing and the risk, the controller and the processor implement appropriate technical and organisational measures, including as appropriate pseudonymisation and encryption, the ongoing confidentiality, integrity, availability and resilience of processing systems, the ability to restore availability and access after an incident, and a process for regularly testing the measures.

Article 15(5)
  • a high-risk system is resilient against attempts by unauthorised third parties to alter its use, outputs or performance by exploiting system vulnerabilities.
  • The measures for AI-specific vulnerabilities include, where appropriate, measures to prevent, detect, respond to, resolve and control for data poisoning, model poisoning, adversarial examples or model evasion, confidentiality attacks and model flaws.
Read Article 15 on EUR-Lex ↗
Article 55(1), point (a)
  • a provider of a general-purpose AI model with systemic risk performs model evaluation with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing; Annex XI gives red teaming as an example.
  • Article 55 is in Chapter V, which applies from 2 August 2025 (Article 113, third paragraph, point (b)).
Read Article 55 on EUR-Lex ↗
  • Article 15 is in Chapter III, Section 2, which applies from 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III and from 2 August 2028 under Article 6(1) and Annex I (Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744).
  • The GDPR articles were read from its Official Journal text (OJ L 119, 4.5.2016) on 9 October 2026; the GDPR is not in the pinned corpus behind the rest of this site.

What Complipath does

  • Evidence management A file linked to the requirements it proves, with the passage and its page
  • Obligations per system Confirming a classification creates the obligations that follow from it, each with an owner, a status and a place for evidence
  • Audit log Who did what, and when. No one can edit or delete a line, an owner included; only deleting the whole workspace removes it

Rules decide. AI only drafts. A person confirms.

What it does not do yet

  • Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.
  • Full risk-management lifecycle Not supported Article 9 is listed as a duty with its date. There is no risk register to run the cycle in.

Questions

Does Complipath run penetration tests?

Complipath does not do your security work. It keeps the evidence and answers with a source. The test summary is a file you link to the requirement it proves, and the record keeps the passage and its page.

Is a penetration test the same as red teaming an AI model?

Not quite. A penetration test usually targets the application and its infrastructure. Red teaming in Annex XI is an example of the adversarial testing Article 55(1), point (a) requires of general-purpose AI models with systemic risk, and it targets the model's behaviour. A questionnaire may ask for either, so say which one you did.

Read next
Answer your next questionnaire with proof.No account needed. Every answer cites the article it rests on.