Questionnaire answers · Security · Article 15(5)

How to answer vulnerability management questions in a supplier questionnaire

The short answer

Say how you find vulnerabilities in the AI features, how fast you fix them by severity and how you track them, and show the record. A high-risk AI system must be resilient against attackers exploiting system vulnerabilities, including the AI-specific ones Article 15(5) names, and the GDPR asks for a process to test the security measures regularly (GDPR Article 32(1), point (d)). Complipath (complipath.io) keeps the record these answers rest on.

What they usually ask

  1. Q1“How do you identify vulnerabilities in the AI features?”
  2. Q2“How fast do you fix critical vulnerabilities?”
  3. Q3“Do you track AI-specific vulnerabilities such as data poisoning?”
  4. Q4“Do you have a vulnerability disclosure policy?”

An example answer, part by part

An illustration for an invented product, not a real supplier's answer, to the question: Do you track AI-specific vulnerabilities such as data poisoning?

Direct answerYes, partly or no first
Yes. Data poisoning, adversarial inputs and prompt manipulation are on our threat list for the AI features.
ControlWhat you actually do
Each new data source is reviewed before training, and adversarial test inputs run on every model release.
ScopeWhich AI systems
The two features that use a trained model. The rule-based features are covered by the general scan.
EvidenceWhat you can show
The threat list and the test report of the last release, dated 15 September 2026.
ExceptionsBe honest
None.

Example. Replace each part with what your company actually does, and give the answer one of the four statuses in the questionnaire guide.

What counts as proof

  • The vulnerability register: each finding, its severity, its owner and its status.
  • The scan or test schedule and the last report.
  • For a high-risk system, the test logs and reports in its technical documentation (point 2(g) of Annex IV).

Common mistakes

  • Answering for the company. Article 6 classifies systems, not companies.
  • "Yes" with no evidence. If you cannot attach it, the status is Partially implemented or Planned.
  • A policy title as the control. It says nothing about what happens to an output.
  • Mixing up the roles. Article 50(1) is a provider duty; Article 26 is the deployer's. Which one you are is set per system: see provider or deployer.
  • Not applicable with no reason. The reason is the classification.
  • Dropping the exception. The summary that leaves out "unless" is the one that is wrong.

What the law says

Article 15(5)
  • a high-risk system is resilient against attempts by unauthorised third parties to alter its use, outputs or performance by exploiting system vulnerabilities.
  • The measures for AI-specific vulnerabilities include, where appropriate, measures to prevent, detect, respond to, resolve and control for data poisoning, model poisoning, adversarial examples or model evasion, confidentiality attacks and model flaws.
Read Article 15 on EUR-Lex ↗

Point 2(g) of Annex IV: the technical documentation includes the validation and testing procedures and the metrics used, with the test logs and all test reports, dated and signed by the responsible persons.

GDPR Article 32(1): taking into account the state of the art, the costs, the nature, scope, context and purposes of processing and the risk, the controller and the processor implement appropriate technical and organisational measures, including as appropriate pseudonymisation and encryption, the ongoing confidentiality, integrity, availability and resilience of processing systems, the ability to restore availability and access after an incident, and a process for regularly testing the measures.

  • Article 15 is in Chapter III, Section 2, which applies from 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III and from 2 August 2028 under Article 6(1) and Annex I (Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744).
  • The GDPR articles were read from its Official Journal text (OJ L 119, 4.5.2016) on 9 October 2026; the GDPR is not in the pinned corpus behind the rest of this site.

What Complipath does

  • Obligations per system Confirming a classification creates the obligations that follow from it, each with an owner, a status and a place for evidence
  • Named owners A person behind every system and every duty
  • Evidence management A file linked to the requirements it proves, with the passage and its page
  • Audit log Who did what, and when. No one can edit or delete a line, an owner included; only deleting the whole workspace removes it

Rules decide. AI only drafts. A person confirms.

What it does not do yet

  • Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.
  • Full risk-management lifecycle Not supported Article 9 is listed as a duty with its date. There is no risk register to run the cycle in.

Questions

Does Complipath scan our systems for vulnerabilities?

Complipath does not do your security work. It keeps the evidence and answers with a source. It keeps the requirement, its owner and the file that proves it, such as the latest scan report, with the passage and its page.

Which AI-specific attacks does the AI Act name?

Article 15(5) names data poisoning, model poisoning, adversarial examples or model evasion, confidentiality attacks and model flaws, and asks for measures to prevent, detect, respond to, resolve and control for them where appropriate. It applies to high-risk systems; for others it is a useful list, not a duty.

Read next
Answer your next questionnaire with proof.No account needed. Every answer cites the article it rests on.