BLOG · 2026-06-25
Supplier compliance: the risk that comes in through Procurement
Every supplier you onboard starts three regulatory clocks: GDPR, the AI Act and NIS2. Here's the real risk and how to keep it under control.
Quick summary
- Every time a company onboards a supplier that handles data, embeds AI or accesses its systems, it starts three regulatory regimes at once: GDPR (Article 28), the EU AI Act and the NIS2 Directive.
- Large procurement platforms handle the "what do I buy and who do I pay" flow well, but they do not produce the compliance artifact created at that very moment (the processing agreement, the AI risk classification, the security assessment).
- The most common mistake is believing the supplier's signed self-declaration is enough. All three regimes demand the same thing at heart: being able to prove you verified.
- The fix isn't another procurement suite. It's a supplier compliance layer anchored to the moment of onboarding.
Why is the biggest compliance risk in Procurement?
Because the supplier is the door through which regulatory risk enters the organisation, and almost nobody watches it from that angle.
When you contract a management SaaS, IT support with remote access, a marketing tool or a payroll provider, you aren't just closing a purchase. You're opening three legal fronts in the same act:
- Personal data. If the supplier processes data on your behalf, you're responsible for what they do with it. Governed by Article 28 of the GDPR.
- Artificial intelligence. If the tool embeds AI, you take on obligations as its deployer. Governed by Regulation (EU) 2024/1689 (the AI Act).
- Supply-chain cybersecurity. You widen your attack surface and have to answer for it. Governed by Directive (EU) 2022/2555 (NIS2).
Three clocks. All three start at the same instant: when someone clicks "add supplier".
Don't procurement platforms already solve this?
Not fully. Source-to-pay suites and procurement ERPs manage the transactional cycle well: request, approval, order, payment. But the regulatory document created in parallel — the processing agreement, the AI risk record, the security assessment — usually ends up in a spreadsheet, an email, or nowhere.
It isn't a flaw in the procurement software. It's a gap between three departments — Procurement, Legal and Security — that rarely share the same workflow.
What do the three regimes have in common?
They converge on one idea: having the document is not enough; you must be able to prove you ran the check.
- GDPR requires you to verify the supplier's guarantees before granting access to data.
- The AI Act requires you to classify and document the AI system you deploy.
- NIS2 demands real verification of your suppliers, not a signed questionnaire you file away unread.
Due diligence stops being good practice and becomes the evidence that defends — or condemns — you in an inspection.
How do you control it in practice?
With a single supplier record that, at onboarding, fires the three tracks in parallel, generates the documents, verifies for real (not just a self-filled form), and leaves an auditable trail with a risk traffic light. The supplier's entry door turned into a control.
In the following articles we break down each clock: the AI Act (the one almost nobody sees coming), GDPR Article 28 (the one already costing money) and NIS2 (the supply-chain one).
Keep reading
Was this article useful? Let's talk.
