KlarComply
HomeKnowledge › The AI supplier questionnaire

AI questions in supplier questionnaires: what is asked and how to answer

What prompts a company to engage with the AI Act is often not a regulator, but a questionnaire from a business customer's procurement team: around twelve questions, a ten-day deadline. This page sets out what is on it — and what you should have ready before it arrives.

By , Founder of KlarComply · Reviewed on

Infographic: The supplier questionnaire: four questions, two minutes — The AI compliance question rarely comes from a regulator — it comes from your biggest customer. With a deadline.
The key points of this article as a graphic — feel free to share or download it.

Why these questions are arriving now

Three developments have converged. First, the transparency obligations of the AI Act have applied since 2 August 2026, and larger organisations pass their own duties down the supply chain. Second, management systems and audits require that the involvement of service providers be documented. Third, the customer's legal team has worked out that your AI use touches their data.

The effect: such questionnaires also turn up on smaller contracts, not only in large-account business. And unlike a market surveillance authority, they do not announce themselves.

Why this, and not the regulator, is the real deadline

An authority opens with a request for information and allows time to remedy. A procurement team sets a deadline and then awards the contract. Not having the documents rarely loses you the work outright — but it starts a round of follow-up questions that costs three weeks, and it puts you behind the competitor who answered.

The twelve questions that actually come up

The wording varies. The substance repeats. In the order they usually appear:

1. “Who is responsible for AI use in your organisation?”

Usually near the top, and the only one you cannot produce at short notice. Answer with a name, a function and the date of appointment. How to scope the role is on appointing an AI lead.

2. “Do you maintain a register of the AI systems you use?”

Answer with yes, the number of entries and the date of the last review. Do not attach the register unasked — it shows your whole tooling landscape. Offer an extract instead. Structure and fields are on building an AI inventory.

3. “Do you have an internal policy on AI use?”

Yes, with the date of the current version and its version number. Whether to hand over the policy itself is a judgement call; a table of contents usually suffices. Structure is on writing an internal AI policy.

4. “How do you ensure AI literacy among your staff?”

This question aims at Article 4 of the AI Act. Answer with the system, not with a number: basic training for everyone who uses AI, deeper training for the responsible person, an annual refresher, onboarding for new joiners, all recorded with date and content. Background on the AI literacy obligation.

5. “Do you deploy high-risk AI systems within the meaning of the regulation?”

Answer yes or no only if you have actually assessed it. An unchecked “no” is an assurance you cannot stand behind. The clean form is: “No. Assessed on [date] against Article 5, Annex III and Article 6(3); the classifications are documented in our AI register.” The method is on classifying AI risk.

6. “How do you label AI-generated content?”

State the rule and give an example: chat windows, AI images, synthetic voices. Free labels in three languages are on our AI labels page; the reach and the limits of the duty are on labelling under Article 50.

7. “Are our data entered into AI systems?”

The most sensitive question on the form, because a wrong answer surfaces later. Answer with detail: which categories, into which tools, on what contractual basis, with which setting for model improvement. A blanket “no” is right only if you can control it.

8. “Do you have data processing agreements with your AI providers?”

Yes or no per tool, with the provider and the contracting entity named. Background on ChatGPT at work.

9. “Are your inputs used to train the models?”

Check this per tool in the contractual terms and in the account settings, not from memory. The answer differs between product lines from the same provider.

10. “Is there an approval process for new AI tools?”

Yes, with a short description: who requests, who decides, which checks, what turnaround. Structure on the approval process for AI tools.

11. “How do you handle AI-related incidents?”

Describe the reporting route, the data protection assessment and the documentation. If you commit to informing the customer, check the deadline before you sign up to it. The procedure is on customer data in an AI tool.

12. “Do your subcontractors use AI?”

The most underestimated question of the twelve. Article 4 of the AI Act expressly covers persons dealing with AI systems on your behalf. In practice you solve this with a contract clause and a short enquiry to the relevant service providers, not by training somebody else's staff.

The documents you have to be able to produce

Six documents cover the whole questionnaire. Keep them together in one folder, with the date in the file name.

DocumentCoversHand it over?
Letter appointing the AI leadQuestion 1An extract with the name and duties is enough
AI registerQuestions 2, 5, 8, 9An extract, not the full register
AI policyQuestions 3, 6, 7, 10, 11Table of contents, the document itself on request
Training recordQuestion 4Summary without the list of names
Classification documentationQuestion 5Summary with the assessment date
Supplier overview with the AI clauseQuestion 12Confirmation is usually enough

The evidence folder that saves a week

Put these six documents in one folder once, together with a one-page standard answer that covers all twelve questions in your own words. On the next questionnaire you copy from it instead of researching from scratch.

Update that page once a quarter — the same occasion on which you review the register anyway.

How to answer when something is missing

This is the most important section, because it covers the most common case. Three routes are open and only one of them works.

Three drafting traps

  1. “We do not use AI.” That statement is almost always untrue today. AI sits inside office suites, translation tools, customer service systems and spelling checkers. Give that assurance and overlook one tool and you have made a false declaration. Answer instead: “We use AI solely as a deployer, in the following areas: …”
  2. “We will inform you without delay.” With no deadline that is indeterminate; with too short a deadline it is unworkable. Check what you can actually achieve organisationally before you sign it.
  3. “All our staff are trained.” Only commit to that if you can evidence it for everyone, including the people who started last week. Safer: “All AI-using staff receive documented basic training; new joiners within their first [X] weeks.”

The contract clauses that arrive with the questionnaire

An addendum to the framework agreement often follows the form. Four clauses repay careful reading before you sign:

What you do not need — even when it is asked for

Certification to ISO/IEC 42001 is occasionally requested. For small and mid-sized companies it is usually disproportionate: a five-figure cost and several months. Answer honestly with no, and produce your documentation instead. In practice certification is almost never made a knock-out criterion — it is a bonus point, not a requirement.

The same applies to “AI compliance seals” from providers with no accreditation. Such a mark confirms nothing that your own documentation does not evidence better. There is no official EU seal for AI conformity. Anyone selling you one is selling an invention.

What you should be asking your own suppliers

The questionnaire runs in both directions. Having given assurances on AI compliance, you have to put the same questions to your own service providers — otherwise the assurance rests on nothing. Four questions are enough for the providers who work with your customers' data:

  1. Do you use AI systems in delivering our services? If so, which and for what?
  2. Do data we entrust to you reach third-party AI tools? On what contractual basis?
  3. Is our content used for model improvement?
  4. Do you label AI-generated content that you create for us?

The fourth is the one most often missing. If an agency generates photorealistic images for you and you publish them, the disclosure duty under Article 50(4) falls on you as the deployer, not on the agency. Settle in the contract who applies the label, and spot-check that they do.

If you are established outside the EU

Two of the twelve questions change shape for you, and both are worth pre-empting rather than answering defensively.

There is no separate EU registration to obtain for either. The duty simply applies where the output lands.

Preparation in half a day

  1. Gather the six documents and establish which are missing.
  2. Give each missing item a realistic date — and hold it.
  3. Draft the one-page standard answer, in your own language.
  4. Decide who in the company answers questionnaires. Two people answering without coordination produce contradictions, and contradictions get noticed.
  5. Set a quarterly date to review the standard answer and the register together.

The KlarComply dashboard produces exactly these six documents automatically — register, policy, training records with verifiable IDs, labelling rule, all in the evidence file. From €49 a month; for a business with 35 staff: Team Plus, €199. All plans: klarcomply.com/en/#angebot.

Which of the points asked about are already in place takes two minutes to establish with the free quick check — it is built around exactly these questions.

Frequently asked questions

What do business customers ask about AI compliance?

Twelve points recur: the responsible person, the AI register, the internal policy, training status, use of high-risk systems, labelling, handling of customer data, data processing agreements, whether inputs are used for training, the approval process, incident handling, and AI use by subcontractors.

What do we do if we cannot meet individual points?

State the position and a specific date. Dressing it up is risky, because the answer is a contractual assurance and it surfaces at the first follow-up question. Leaving it blank is scored as no. A gap with a date a few weeks out is almost always acceptable in the evaluation.

Should we hand over our AI register?

Usually not in full — it shows your entire tooling landscape. Give the number of entries and the date of the last review, and offer an extract for the areas relevant to the contract. That is sufficient in nearly every case.

Do we need ISO/IEC 42001 certification?

For small and mid-sized companies, usually not. It costs a five-figure sum and several months and is rarely made a knock-out criterion. Answer honestly with no and produce your own documentation. There is no official EU seal for AI conformity.

Can we state that we do not use AI?

Only if it is true, and today it rarely is. AI sits inside office suites, translation services, spelling checkers and customer service systems. An incorrect assurance is contractually risky. Phrase it positively instead, naming the areas in which you use AI as a deployer.

Does the enquiry extend to our service providers?

Usually yes, and many questionnaires ask expressly. Article 4 of the AI Act covers persons using AI on your behalf. In practice you handle it with a contract clause and a short enquiry to the providers who work with the customer's data.

Who is responsible for labelling if an agency produces the content?

You are. The disclosure duty under Article 50(4) falls on the deployer, meaning the company that uses and publishes the content. The agency can do the work; the responsibility stays with you. Put it in the contract and spot-check it.

How long does preparation take?

If the foundations are in place — named person, register, policy, training record, classifications, supplier overview — about half a day for the evidence folder and the standard answer. If the foundations are missing, the questionnaire is not the problem. It is the symptom.

Where does your company stand?

The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.

Start the quick check — free
Read on AI literacy obligation → Building an AI inventory → Labelling AI content (Art. 50) → The AI Act for SMEs → Writing an AI policy → AI in hotels → AI in the beauty salon → Appointing an AI lead → ChatGPT at work and the GDPR → Approving AI tools → Finding shadow AI → AI and employee representation → Classifying AI risk → Customer data in an AI tool → Penalties under Article 99 → Trade secrets and AI tools → AI in physiotherapy practices → AI in dental practices → AI in tax and accounting firms → AI in hair salons → AI in advertising agencies → AI for estate agents → AI in car repair shops → AI in trades businesses → AI in law firms → DPO requirements → Records of processing → DPA (Art. 28) → Data breach & 72 hours → GDPR staff training → US tools & transfers →
Sources:
Article 4 EU AI Act — AI literacy, including persons acting on your behalf
Article 26 EU AI Act — obligations of deployers
Article 50 EU AI Act — transparency obligations
Article 28 GDPR — processor
Regulation (EU) 2024/1689 — official consolidated text, EUR-Lex
European Commission — AI Act Service Desk
Reviewed on 2 August 2026 · Reflects the Digital Omnibus · This article is general information and not legal advice.