← Back to the observatory
Practice

A client sends you an AI Act questionnaire: how to answer it

A guide for the vendor, not the buyer. What these questionnaires ask, what you can answer today, what needs prior work, and three answers worth avoiding.

A large client has sent you a questionnaire about the AI Act and the deal is on hold until you send it back. Almost everything published about these questionnaires is written for the sender — what to ask your AI vendor — and almost nothing for the receiver. This page is for the second case.

First: two questions decide the rest of the questionnaire

Before answering anything, two things must be settled, because they determine which obligations apply to you and therefore what you answer in twenty of the forty questions.

  • Are you a provider or a deployer? A provider develops the system and places it on the market under its own name. A deployer uses it under its authority. The same product can make you both depending on the module, and if you integrate a third-party model and sell it under your brand, you are the provider of that system even if you did not train the model.
  • Does your system fall under Annex III? For recruitment software, Annex III point 4 covers targeted job advertising, filtering applications, evaluating candidates and decisions on promotion or termination. Falling there is what triggers the high-risk regime.

Answering the questionnaire without settling these two first produces answers that contradict each other across sections. It is the most common mistake and the one that lands worst in the client review.

What a procurement questionnaire on the AI Act usually asks

The form varies, the substance repeats. In the questionnaires we have seen, questions group into five blocks: inventory of AI systems and their intended purpose; risk classification and its justification; the role you take in the value chain; governance measures, including human oversight and the Article 4 literacy duty; and documentary evidence you can supply.

What you can answer today and what needs prior work

Much of the questionnaire can be answered from what you already know about your product, with no project at all: what each system does, on what data, who decides in the end and what human controls exist. What is usually missing is documentary: the intended purpose written down, the reasoning for why you do or do not fall under Annex III, and a register of which evidence you have and which you do not. That gap between knowing it and having it written is what stretches answers from two days to three weeks.

Three answers worth avoiding

  • We comply with the AI Act. It is a claim with no verifiable content and the first one a legal team asks you to substantiate. Better to say what you classified, on what criteria, and what evidence you hold.
  • We are AI Act certified. There is no conformity certification against the Regulation you can obtain today in the sense a client would understand. Claiming it is a bigger problem than having nothing.
  • Silence in an uncomfortable box. An unexplained gap reads as not having looked. A this does not apply, and here is why, or a this is in progress, with this date, scores far better than a blank.

How long this actually takes

If the product is clear, the inventory and preliminary classification of a normal HR-tech catalogue close in days, not months. What stretches is gathering evidence that did not exist and agreeing internally on the role you take. Our experience with this scope is 7 to 10 working days, and the bottleneck is almost never the analysis: it is getting product and legal to sign the same description of the system.

What this work is not

Answering a procurement questionnaire is not a conformity audit, not a certification and not legal advice. It is preparing, with technical judgement and traceability, the answers your client needs in order to approve you as a vendor. If someone offers you an AI Act certification, ask who issues it and against which harmonised standard.

Primary sources and material consulted

  1. 1Reglamento (UE) 2024/1689, Anexo III (sistemas de alto riesgo)
  2. 2Reglamento (UE) 2024/1689, artículo 3 (definiciones de proveedor y responsable del despliegue)
  3. 3Reglamento (UE) 2024/1689, artículo 4 (alfabetización en materia de IA)

Change record

Initial version published on the date shown. Regulatory corrections are incorporated and recorded here.

Continue reading