Create a account for said nephew
Edit the local policy via gpedit.msc
When Happy with Said Changes (PS , to turn off any internet access i've found it's better to just point IE to a bogus proxy server , and then just make sure you hide the Network Tab in IE that available in the policy
After you're happy with said changes go to C:\WINDOWS\system32\GroupPolicy
1)Give your nephew the right to read and read + execute the file
2)In the directory Users you will see a a .pol file , give your nephew rights to this file
If at any time , you want to edit the policy just log in as admin , give the admin/yourself full control to said files , edit the group policy and then remove admin/yourself from those 2 files .
Altough it takes some effort the first time round after that , you'll have a nice spyware free boxen