# NIS2 AI supplier dossier

A fictional manufacturing company evaluates an external drafting service. The dossier keeps the applicability decision separate from supplier-control evidence.

Synthetic company, staffing figures, supplier and proposed use. No actual national-law classification, supplier audit or test result is represented.

Source: https://aona.ai/resources/guides/nis2-employee-ai-supplier-review/
Sources checked: 2026-09-21

## Two parallel questions

### Applicability

Entity, activities, country and national law

### Supplier risk

Service, access, vulnerabilities and dependency

### Decision

Actual scope, controls, owners and evidence

| Dossier field | Populated fictional fact | Evidence or decision needed |
| --- | --- | --- |
| Entity and establishment | Example Components SAS, established in France, 300 staff in the exercise. | Legal owner verifies the actual sector, size/group rules and French implementing requirements. |
| Proposed service | External AI drafting for internal support instructions. | Business owner records the task, users and permitted data. |
| Connection and data | Initial proposal includes repository access; first evaluation removes that connection. | Security verifies actual permissions and data paths before any real deployment. |
| Supplier security | No verified development, vulnerability or incident evidence exists in the fictional proposal. | Procurement obtains service-specific evidence and assigns follow-up questions. |
| Continuity and dependency | Manual drafting is available in the example. | Operational owner assesses real outage effects rather than assuming the fallback settles risk. |
| Applicable duties | Entity/national-law conclusion is not established by this exercise. | Record the actual legal basis and any sector-specific interaction before claiming compliance. |
| Interim decision | Use invented instructions only while material questions are resolved. | Do not represent the teaching evaluation as approval for real company data. |

## Review checklist

- [ ] Resolve jurisdiction and entity facts
  Identify actual national implementation, sector, size/group and service-specific conditions.
- [ ] Evaluate the direct supplier
  Ask for relevant secure-development, vulnerability, incident and access-control evidence.
- [ ] Document scope and follow-up
  Separate the legal conclusion, supplier evidence and observed control results with accountable owners.

## Included example files

- nis2-ai-supplier-dossier.md
- nis2-ai-supplier-dossier.csv

## Source references

- NIS2: Directive (EU) 2022/2555: https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng (2026-09-21)

Use the worksheet within the relevant legal, contractual and technical scope. It is not a certification or a record of an installed-product test.
