BLOG · 2026-06-25
The supplier compliance layer: unifying GDPR, AI Act and NIS2 at onboarding
Three regimes, one moment. How a compliance layer controls GDPR, AI Act and NIS2 right at supplier onboarding.
Quick summary
- Onboarding a supplier starts three clocks at once — GDPR, AI Act, NIS2 — usually handled by three teams that don't talk to each other.
- The fix isn't another giant procurement platform, but a supplier compliance layer: a single record that fires the three tracks at onboarding, generates the documents, verifies for real and leaves an auditable trail.
- All three regimes converge on the same thing: proving the check, not just keeping the document.
- It's a preventive control: done at onboarding it's protection; done after the fine it's just damage.
What does it look like running?
Picture a procurement officer's or an advisor's screen. A new supplier arrives. Instead of three loose processes, there's one record firing three parallel tracks:
1. Onboarding and triage. Four data points: what the supplier does, whether it handles personal data, whether it embeds AI, whether it's critical to operations. The system classifies on its own: "processor + AI system + critical supplier". From there it generates three checklists without you deciding anything.
2. GDPR track. Generates the Article 28 processing agreement with the variables filled in, lists sub-processors, flags international transfers requiring assessment, and creates expiry alerts.
3. AI Act track. A questionnaire that classifies the AI system by risk level, generates the record entry, and flags whether the contract needs specific clauses.
4. Cyber track (NIS2). A security questionnaire plus an external technical check of the supplier's exposure, producing a traffic light. Not a self-filled declaration: a real check.
5. Output. A record with a single traffic light (green/amber/red), an auditable report and continuous monitoring: periodic re-assessment and alerts on changes to the contract, sub-processors or security posture.
In one sentence: the supplier's entry door, turned into a control.
Why unify instead of using three tools?
Because the risk is born at a single moment — onboarding — and is split across three teams. Three separate tools reproduce the same problem: nobody sees the full record. A single layer turns a fragmented, manual process into a coherent, demonstrable control.
Three takeaways
- Compliance is preventive or it isn't. At onboarding it's protection; after the fine, just damage.
- Having the document is no longer enough. You must prove the check. All three regimes converge there.
- The AI Act window is open now. Soon it will be mandatory and obvious; today it's still an edge for those who understand it.
Keep reading
Was this article useful? Let's talk.
