30 Days Gen AI Risk Trial -Start Now
Skip to main content

Compliance decisions

NIS2 supplier checks for employee AI

NIS2 is a directive implemented through national law. First establish the entity, sector, size and relevant jurisdiction, then assess the AI supplier’s role and risks under the applicable requirements. Article 21 includes direct-supplier security, but a generic AI subscription does not establish the customer’s or vendor’s legal status.

For Security leaders, legal teams and procurement at potentially covered EU entities

Aona field notesC22
Scope before supplier scoring
Entity + country + service

The dossier separates legal applicability from evidence about a proposed AI supplier.

Synthetic company, staffing figures, supplier and proposed use. No actual national-law classification, supplier audit or test result is represented.

01

Identify the entity and national framework

Record the legal entity, activities, countries of establishment and relevant service delivery. NIS2 includes sector, size and other scope conditions; the applicable national implementation and any relevant sector-specific rules must be checked. Do not assume a group brand has one uniform status across all entities.

The fictional dossier concerns an EU manufacturing entity considering staff AI drafting. It deliberately leaves the actual national-law determination with the legal owner. The exercise provides the facts and questions needed for that decision, not an invented ruling that the company is essential or important.

Source context: NIS2: Directive (EU) 2022/2555

02

Define what the supplier can affect

Identify the service, data access, integration and business dependency. A standalone drafting account differs from an AI feature with broad access to a shared repository. Include the direct supplier and relevant onward dependencies rather than treating the brand displayed to the employee as the whole supply chain.

For the example, staff propose copying internal support material into an external assistant. The first evaluation can use invented text without a repository connection. That reduces the initial data exposure but does not, by itself, settle supplier security or NIS2 applicability.

Source context: NIS2: Directive (EU) 2022/2555

03

Ask for evidence related to the risk

Article 21 includes security-related aspects of relationships with direct suppliers and service providers. It directs attention to supplier-specific vulnerabilities, overall product quality and cybersecurity practices, including secure development procedures. Assess the evidence against the service actually used.

Useful questions address vulnerability handling, security updates, access control, incident cooperation, continuity and the data/connection boundary. A questionnaire score is not proof that those practices operate. Identify what a document establishes, what a technical test can show and which facts remain unverified.

Source context: NIS2: Directive (EU) 2022/2555

04

Connect supplier findings to the entity’s measures

NIS2’s risk-management approach also addresses incident handling, business continuity, effectiveness assessment, training, access and other measures. A supplier review should identify how its findings affect the entity’s own controls and responsibilities, not simply record a pass or fail badge.

The directive requires appropriate and proportionate measures, with relevant factors including exposure, size, likelihood and severity. Keep the reasoning specific to the proposed use. Do not state that every supplier must hold an invented NIS2 certificate or that one AI security product satisfies the entire framework.

Source context: NIS2: Directive (EU) 2022/2555

05

Keep local-law uncertainty actionable

The worked dossier assigns separate legal, procurement and security questions. If applicability remains unresolved, record the exact missing fact or authority to check. If a supplier control is unverified, identify the evidence owner and the permitted interim scope, such as an invented-data evaluation.

Review changes to the supplier, integrations, data or operational dependency. Keep the applicable national-law conclusion linked to the supplier evidence, while preserving the difference between a source-based legal requirement, a fictional example and an observed test result.

Source context: NIS2: Directive (EU) 2022/2555

Put it into practice

NIS2 AI supplier dossier

A fictional manufacturing company evaluates an external drafting service. The dossier keeps the applicability decision separate from supplier-control evidence.

Synthetic company, staffing figures, supplier and proposed use. No actual national-law classification, supplier audit or test result is represented.

Two parallel questions
01

Applicability

Entity, activities, country and national law

02

Supplier risk

Service, access, vulnerabilities and dependency

03

Decision

Actual scope, controls, owners and evidence

NIS2 AI supplier dossier
Dossier fieldPopulated fictional factEvidence or decision needed
Entity and establishmentExample Components SAS, established in France, 300 staff in the exercise.Legal owner verifies the actual sector, size/group rules and French implementing requirements.
Proposed serviceExternal AI drafting for internal support instructions.Business owner records the task, users and permitted data.
Connection and dataInitial proposal includes repository access; first evaluation removes that connection.Security verifies actual permissions and data paths before any real deployment.
Supplier securityNo verified development, vulnerability or incident evidence exists in the fictional proposal.Procurement obtains service-specific evidence and assigns follow-up questions.
Continuity and dependencyManual drafting is available in the example.Operational owner assesses real outage effects rather than assuming the fallback settles risk.
Applicable dutiesEntity/national-law conclusion is not established by this exercise.Record the actual legal basis and any sector-specific interaction before claiming compliance.
Interim decisionUse invented instructions only while material questions are resolved.Do not represent the teaching evaluation as approval for real company data.

Work through your review

Use the checks to organise the evidence you need. Your selections stay in this tab.

0 of 3 reviewed

Example files for this task

Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.

nis2-ai-supplier-dossier.mdInspect
# NIS2 AI supplier dossier

Synthetic company, staffing figures, supplier and proposed use. No actual national-law classification, supplier audit or test result is represented.

A fictional manufacturing company evaluates an external drafting service. The dossier keeps the applicability decision separate from supplier-control evidence.

| Dossier field | Populated fictional fact | Evidence or decision needed |
| --- | --- | --- |
| Entity and establishment | Example Components SAS, established in France, 300 staff in the exercise. | Legal owner verifies the actual sector, size/group rules and French implementing requirements. |
| Proposed service | External AI drafting for internal support instructions. | Business owner records the task, users and permitted data. |
| Connection and data | Initial proposal includes repository access; first evaluation removes that connection. | Security verifies actual permissions and data paths before any real deployment. |
| Supplier security | No verified development, vulnerability or incident evidence exists in the fictional proposal. | Procurement obtains service-specific evidence and assigns follow-up questions. |
| Continuity and dependency | Manual drafting is available in the example. | Operational owner assesses real outage effects rather than assuming the fallback settles risk. |
| Applicable duties | Entity/national-law conclusion is not established by this exercise. | Record the actual legal basis and any sector-specific interaction before claiming compliance. |
| Interim decision | Use invented instructions only while material questions are resolved. | Do not represent the teaching evaluation as approval for real company data. |

## Review steps

- Resolve jurisdiction and entity facts: Identify actual national implementation, sector, size/group and service-specific conditions.
- Evaluate the direct supplier: Ask for relevant secure-development, vulnerability, incident and access-control evidence.
- Document scope and follow-up: Separate the legal conclusion, supplier evidence and observed control results with accountable owners.

## Fictional evidence requests

- Legal: which national implementation and entity criteria govern Example Components SAS?
- Procurement: which legal supplier and service terms apply, including onward dependencies?
- Security: what access does the repository connection grant, and can the initial task run without it?
- Operations: what happens if the drafting service becomes unavailable or produces an incorrect result?

## Teaching disposition

Restrict this exercise to invented internal instructions with no repository connection. Obtain actual legal and supplier evidence before a real-data decision. No national law or supplier assurance has been invented for the scenario.

## Source and scope

Guide: https://aona.ai/resources/guides/nis2-employee-ai-supplier-review/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- NIS2: Directive (EU) 2022/2555: https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng
Download nis2-ai-supplier-dossier.md
nis2-ai-supplier-dossier.csvInspect
Dossier field,Populated fictional fact,Evidence or decision needed
Entity and establishment,"Example Components SAS, established in France, 300 staff in the exercise.","Legal owner verifies the actual sector, size/group rules and French implementing requirements."
Proposed service,External AI drafting for internal support instructions.,"Business owner records the task, users and permitted data."
Connection and data,Initial proposal includes repository access; first evaluation removes that connection.,Security verifies actual permissions and data paths before any real deployment.
Supplier security,"No verified development, vulnerability or incident evidence exists in the fictional proposal.",Procurement obtains service-specific evidence and assigns follow-up questions.
Continuity and dependency,Manual drafting is available in the example.,Operational owner assesses real outage effects rather than assuming the fallback settles risk.
Applicable duties,Entity/national-law conclusion is not established by this exercise.,Record the actual legal basis and any sector-specific interaction before claiming compliance.
Interim decision,Use invented instructions only while material questions are resolved.,Do not represent the teaching evaluation as approval for real company data.
Download nis2-ai-supplier-dossier.csv

Before you proceed

Keep these distinctions clear

A directive is not one identical national procedure
Check the applicable implementation and entity conditions.
A supplier score is not operating evidence
Tie the conclusion to the service-specific documents and tests actually reviewed.

Apply it to employee AI use

Bring your actual data path.

Aona can help evaluate employee-AI visibility and sensitive-input controls within supported installed scope.

It does not classify an entity under NIS2, certify a supplier or replace the broader risk-management programme.

Use the invented drafting task to assess one data-input boundary while the legal and supplier dossier is completed.

Review your use case

FAQ

Questions for this decision

Does NIS2 apply to every organisation using AI?
No. Check the directive’s scope and the applicable national implementation, including the actual entity, sector, size and relevant exceptions or sector-specific rules.
Must every AI supplier have a NIS2 certificate?
This guide establishes no such universal certificate requirement. Review the applicable law and the supplier-security evidence relevant to the service and risk.
Can removing a connector finish the supplier review?
No. It changes the data-access risk, but security practices, incidents, continuity, contractual responsibilities and legal applicability still need assessment.
Why is national-law status unresolved in the example?
The company is fictional. The dossier demonstrates the facts and questions to gather without inventing a French legal determination or implying that a teaching example is professional advice.

Evidence behind the guide

Sources and scope

Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.

  1. NIS2: Directive (EU) 2022/2555

    Directive scope and Article 21 risk-management and direct-supplier security considerations, implemented through applicable national law.

    law · checked 2026-09-21
NIS2 supplier checks for employee AI | Aona