Supplier Risk in Ireland: What NIS2 and the EU AI Act Are Really Asking
Supplier Risk in Ireland: What NIS2 and the EU AI Act Are Really Asking
There is a question moving through Irish organisations at the moment, and it rarely arrives in conversation. It turns up in a customer's security questionnaire, in an insurer's renewal pack, or in the pre-qualification documents for a public tender. The wording changes, the substance does not: who are the suppliers, what risk do they carry, and how does anyone know?
The first part is usually answerable. Somebody in procurement holds a list. The second part is where it slows down, and the third is where it stops altogether, because knowing something about a supplier and being able to evidence it are different problems.
Why the question is being asked now
Ireland has still not enacted the National Cyber Security Bill, the vehicle for bringing NIS2 into Irish law. In July the European Commission referred Ireland to the Court of Justice over the delay, alongside three other member states. Days before that, the NCSC published governance guidance for management boards, setting out what senior executives are expected to oversee once the regime is live.
The legislative gap has done nothing to reduce the pressure, because the pressure is not coming from a regulator. A manufacturer in scope of NIS2 sends a sixty-question assessment to its logistics provider. A bank's third-party risk team sends one to a software supplier with eleven staff. An insurer asks for evidence of supplier oversight before it will quote. None of those parties can fine anybody, and every one of them can stop a deal.
The EU AI Act adds a second line of questioning, though not the one most commentary suggests. The Digital Omnibus, given final Council approval in June, moved the high-risk obligations out to December 2027 for standalone systems and August 2028 for AI embedded in regulated products. Transparency duties took effect on 2 August 2026, and the AI literacy obligation has applied since February 2025. The practical point for most organisations is quieter than the headlines: almost nobody builds AI capability in house, so AI obligations arrive through the same suppliers already being assessed for everything else.
The gap between having a control and evidencing one
Article 21 of NIS2 sets out the risk management measures in scope entities are expected to have, and supply chain security sits among them. What the directive keeps returning to is proportionality and evidence. An organisation is expected to have chosen measures suited to its risk, and to demonstrate that it did.
The annual supplier questionnaire was built for a different pace. It made sense when supplier relationships lasted years, when software was procured rather than subscribed to, and when the answer a vendor gave in March was still broadly true in November. A questionnaire returned six months ago describes a supplier as it was, which is a reasonable thing to have and a poor thing to rely on.
Two changes have made that harder to defend. The first is speed. A business unit can onboard a SaaS vendor in an afternoon, and assessment cycles measured in weeks cannot keep up, so the supplier list in the risk register and the supplier list the organisation actually uses drift apart. The second is depth. Suppliers have suppliers. A vulnerability in a widely used library reaches an organisation through a vendor that never appeared on any register, and the questionnaire process has no way of seeing it.
SecurityScorecard's research puts a number on the resulting gap. Ninety percent of security leaders describe themselves as confident in their supply chain resilience, while twenty two percent of internal programmes monitor more than half the suppliers the organisation depends on. Both figures can hold at once, which is what makes the position uncomfortable rather than obviously wrong.
What a defensible answer looks like
Organisations handling this well have stopped treating supplier assessment as an event. The shift is from asking a vendor how it is doing to observing how it is doing, continuously, from the outside, and keeping the record.
That change makes several things possible at once. Suppliers can be ranked by current exposure rather than by assessment date, so attention goes to the vendor with an unpatched internet facing system this week rather than the one whose review happens to be due. Questionnaires become a way of confirming what monitoring already suggests rather than the primary source of truth. Onboarding stops being the bottleneck, because a baseline view of a new supplier exists before anyone sends a document.
The by product is what matters when the questionnaire lands. Supplier oversight becomes something with dates, evidence and a current position attached, rather than a policy statement and a folder of returned spreadsheets. The answer to "describe how third-party risk is managed" stops being a paragraph and becomes a report.
There is a second benefit that usually gets noticed before the compliance one. Supplier breaches remain one of the more reliable routes into an organisation, and the warning signs are frequently visible from outside well before anyone inside the supplier discloses anything. Watching for those signs across a supplier list is work that no assessment cycle was ever going to do.
Where this sits alongside what is already running
None of this replaces the questionnaire, and it does not make procurement due diligence redundant. Contractual obligations still need to be written and agreed. What continuous monitoring changes is the period between those events, which under an annual cycle is roughly all of the time.
It also changes what the board can be told. Article 21 makes management bodies answerable for supplier oversight, and NCSC guidance is explicit that boards need sufficient assurance rather than technical expertise. A letter grade does not give a board a decision. Supplier exposure expressed in terms of business impact does.
The organisations being asked these questions first are rarely the ones with the largest security budgets. They are the ones sitting in somebody else's supply chain, which in Ireland is most of us.
Join us on Tuesday 15th September
SecurityScorecard join Renaissance for an hour on the supplier question: who they are, what risk they carry, and how anyone proves it when a customer, an insurer or a board asks.
The session covers:
- What NIS2 Article 21 and the EU AI Act require on suppliers, in plain terms
- Which obligations apply in Ireland today and which are still ahead
- The supplier questions now appearing in customer questionnaires and insurance renewals
- Why an annual supplier review no longer holds up, and what replaces it
- How to spot which suppliers are at real risk today rather than which ones scored well six months ago
- How to explain supplier risk to a board in terms it will act on
The session is relevant whether the supply chain in question is your own or a customer's.
Register here: https://renaissance.renaissance.ie/c/457143/

