Most supplier compliance programs are still built around a document exchange: a supplier signs a certificate, completes a questionnaire, or issues a letter attesting that its sourcing meets a standard, and the buyer files that document as proof of diligence. The EU's new digital battery passport does not work that way, and it is worth every risk, procurement, and compliance leader's attention — not because most enterprises make batteries, but because it is the clearest working example yet of where supplier due diligence, across every sector, is heading next.
Under Regulation (EU) 2023/1542, every electric vehicle battery, light-means-of-transport battery, and industrial battery above 2 kWh placed on the EU market must carry a digital passport, accessible by QR code, from 18 February 2027. The passport is not a compliance certificate in digital form. It is a structured, queryable record of the battery's identity, manufacturer, material composition, carbon footprint, recycled content, performance, durability, state of health, and — critically — its supply chain due diligence status. A regulator, a buyer, or an end-of-life recycler can query that record directly. Nobody has to take a supplier's word for it, because the evidence is attached to the product itself.
Most supplier due diligence programs can produce a signed certificate. Far fewer can produce the underlying, verifiable evidence a regulator or a buyer would actually query. See how AI-powered vendor and supplier intelligence keeps that evidence current, not filed away after onboarding.
Explore the TPRM PlatformThe Passport That Doesn't Take Your Word For It
The due diligence obligations behind the passport are specific and demanding. Under Article 48 of the regulation, any economic operator placing a qualifying battery on the EU market must establish and operate a due diligence policy for the raw materials named in Annex X — cobalt, lithium, nickel, and natural graphite are called out explicitly — aligned with the OECD Due Diligence Guidance for Responsible Supply Chains of Minerals from Conflict-Affected and High-Risk Areas. That policy has to trace sourcing through every intermediate party between the mine or recycler and the finished battery, be verified by an accredited third-party notified body, and be retained for at least ten years. Annex XIII, Part C of the regulation is where that due diligence evidence surfaces in the passport itself; Part D carries the full material composition, including hazardous substances and recycled content.
There is a sequencing detail here that matters more than it first appears. The formal due diligence obligation technically applies from 18 August 2027, six months after the passport mandate itself. It would be easy to read that as breathing room. It isn't. The passport's data fields — the ones Annex XIII requires the due diligence evidence to populate — exist from day one of the February deadline. A battery manufacturer cannot wait until August 2027 to start mapping cobalt, lithium, nickel, and graphite sourcing back through its supplier network, because the passport it has to issue six months earlier already needs somewhere to put that data. The evidence-gathering work has to be running well before the obligation it satisfies formally takes effect — a pattern enterprises well outside the battery sector are about to become very familiar with.
Why This Is a Preview, Not an Outlier
It would be a mistake to treat the battery passport as a niche EV-sector compliance item. It is the most fully specified example so far of a regulatory pattern that is spreading across the EU's product and supply chain framework, and echoing well beyond it. The battery passport sits inside a broader Digital Product Passport initiative under the EU's Ecodesign for Sustainable Products Regulation, which is expected to extend similarly structured, traceable-data requirements to textiles, electronics, construction products, and other categories over the coming years — batteries are simply first because the underlying regulation was finalized earliest. In parallel, the EU's Corporate Sustainability Due Diligence Directive is pushing companies toward ongoing, evidence-backed supply chain due diligence as a continuous obligation rather than an annual filing exercise, echoing exactly the shift this article is describing for batteries specifically.
The direction of travel is not confined to Europe, either. U.S. critical minerals sourcing requirements tied to electric vehicle tax credits already demand documented, auditable supply chains for battery materials, not self-certification. Manufacturing and export-oriented economies — India's battery and EV localization push among them — are moving in the same direction as critical mineral security becomes a strategic priority as much as an environmental one. The common thread across all of these is a move away from a supplier's word, evidenced by a certificate the buyer stores and rarely revisits, toward a structured, queryable, and continuously verifiable record the buyer — or a regulator — can interrogate directly. Batteries happen to be the sector where that shift is furthest along and most precisely dated. It will not be the last.
The Seven-Link Supplier Evidence Chain
Whether the compliance requirement is a battery passport, a conflict-minerals disclosure, a forced-labor sourcing rule, or an ESG reporting obligation, the underlying evidence problem breaks down into the same seven links — and most supplier due diligence programs today are strong on the first two and structurally weak on the last five, which is exactly where a passport-style requirement exposes them.
Identify the Supplier
Start from every entity that touches the material or product — direct suppliers, sub-suppliers, and material processors, not just the Tier-1 contract counterparty.
Map the Material or Product
Identify which specific materials, components, or product lines a compliance requirement actually applies to, rather than treating the whole relationship as one risk.
Trace the Origin
Establish where the material was extracted, processed, or manufactured, and how many intermediate parties it passed through before reaching the enterprise.
Collect the Evidence
Gather the structured, verifiable documentation supporting the origin and composition claim — certificates of analysis, chain-of-custody records, verification reports.
Match to the Compliance Requirement
Confirm the evidence actually satisfies the specific regulatory field or disclosure it needs to support, rather than assuming one general certificate covers everything.
Monitor for Change
Track shifts in sourcing, ownership, certification status, or regulatory scope that would make previously collected evidence outdated or insufficient.
Maintain the Audit Trail
Retain a time-stamped, retrievable record of what evidence was collected, when, from whom, and how it was verified — ready on request, not reconstructed under deadline pressure.
Most enterprise supplier programs handle links one and two well — they know who their suppliers are and roughly what those suppliers provide. The chain typically frays starting at link three. Origin tracing beyond the direct, contracted supplier is where visibility usually stops, because most onboarding and questionnaire processes ask a supplier to describe its own operations, not to prove where its own inputs came from. A battery passport — or any Annex XIII-style disclosure — asks the enterprise to answer for the entire chain back to extraction, which means the origin-tracing gap that was previously invisible in a routine audit becomes a hard blocker to placing a product on the market at all.
Crest.Digital's Agentic AI continuously ingests supplier certifications, ownership structures, and sourcing documentation, matches them against what a specific regulatory disclosure actually requires, and flags gaps to a named compliance owner before a deadline forces the question.
Getting Evidence-Ready Before the Deadline Forces It
The battery passport deadline is still roughly eighteen months out at the time of writing, which is exactly the window in which most compliance programs either get ahead of a requirement or spend the final quarter scrambling to reconstruct evidence that should have been collected all along. Enterprises with any exposure to EV or industrial battery supply chains — manufacturers, Tier-1 and Tier-2 automotive suppliers, electronics OEMs, and the procurement teams that source from them — have a genuine window to build the evidence infrastructure now, at a manageable pace, rather than under deadline pressure in early 2027.
An Evidence-Ready Supplier Compliance Framework
- Tier suppliers by material exposure, not just spend. A low-spend supplier providing a regulated raw material carries more evidence obligation than a high-spend supplier providing an unregulated component.
- Map origin beyond the direct contract. Ask suppliers not just what they provide, but where their own inputs come from — and how many parties sit between them and the original source.
- Build a structured evidence repository, not a document archive. Origin, composition, and due diligence data need to be queryable against a specific requirement, not buried in a folder of PDFs.
- Verify through an accredited third party where the regulation requires it. Self-attestation will not satisfy an Annex XIII-style disclosure; notified-body verification is built into the requirement itself.
- Treat evidence as perishable. A certificate of origin from two years ago may no longer reflect a supplier's current sourcing — monitor for change rather than trusting a static file.
- Retain records for the full regulatory window. A ten-year retention requirement means the evidence infrastructure has to outlast most procurement teams' typical document-retention habits.
- Assign a named evidence owner per requirement. Origin tracing, verification, and monitoring need an accountable owner, not a shared responsibility that defaults to nobody.
- Start the mapping work before the obligation formally applies. As the battery passport's own six-month lag between passport and due diligence deadlines shows, the data has to exist before the rule requiring it does.
Where Continuous Monitoring and Agentic AI Fit
Manually tracing origin, collecting verification evidence, and monitoring for change across a multi-tier supplier base is achievable for a handful of critical materials with a focused project team. It does not scale across the hundreds of suppliers a typical manufacturer or electronics OEM carries, each with its own sub-supplier network that can shift without notice. This is precisely the kind of continuous, high-volume evidence work AI-driven supplier intelligence is built for: continuously ingesting supplier disclosures, certification updates, ownership changes, and sanctions or adverse-media signals, correlating them against what a specific compliance requirement actually asks for, and surfacing gaps to a named owner rather than waiting for an annual review to find them.
This is also where the questionnaire-versus-evidence distinction, already reshaping other corners of third-party risk, applies directly to supply chain compliance. A questionnaire tells a compliance team what a supplier said about its sourcing. Structured, continuously monitored evidence tells the team what the supplier can actually prove — the same shift already underway across vendor due diligence more broadly, and the same distinction between documentation and provable evidence explored in why AI compliance is moving from documentation to evidence. A battery passport is simply the most codified, deadline-bound version of that same argument: proof, not paperwork.
What AI does not replace is the judgment call sitting at the end of the chain. Whether a supplier's origin evidence is sufficient, whether a documented gap requires escalation or remediation, and whether to continue, pause, or exit a sourcing relationship remain decisions for a named compliance or procurement owner — informed by a complete, current evidence picture an AI-led workflow assembles, not made by it. That human-in-the-loop structure is also what makes an evidence-based compliance program defensible under an actual regulatory audit: not that AI cleared every supplier automatically, but that every gap was surfaced, reviewed, and acted on, with the reasoning preserved in the same audit trail the regulation demands. The same origin-and-ownership tracing logic extends naturally to the fourth-party mapping described in the next TPRM frontier being the vendor's vendor — a supplier's sub-supplier network is, in effect, exactly that problem wearing a raw-materials label.
Frequently Asked Questions
The EU battery passport is a digital record, accessible via a QR code, required under Regulation (EU) 2023/1542 for every electric vehicle battery, light-means-of-transport battery, and industrial battery above 2 kWh placed on the EU market from 18 February 2027. It carries structured data on the battery's identity, manufacturer, material composition, carbon footprint, recycled content, performance and durability, state of health, and supply chain due diligence — replacing a patchwork of paper certificates and supplier declarations with a single, standardized, machine-readable record tied to that specific battery model or batch.
Under Article 48 of Regulation (EU) 2023/1542, economic operators placing qualifying batteries on the EU market must establish and operate a due diligence policy for the raw materials listed in Annex X — cobalt, lithium, nickel, and natural graphite are named explicitly — aligned with the OECD Due Diligence Guidance for Responsible Supply Chains of Minerals from Conflict-Affected and High-Risk Areas. That policy has to trace sourcing from the mine or recycler through every intermediate supplier, verify it through a notified third-party body, and retain the supporting records for at least ten years. The battery passport's Annex XIII, Part C fields are where that due diligence evidence gets disclosed.
A compliance certificate is typically a signed, point-in-time attestation — a supplier states that its sourcing meets a standard, and the buyer files the document. A battery passport is structured, traceable data tied to a specific product: material origin, composition, and due diligence status that a regulator, buyer, or recycler can query directly rather than trust on the strength of a signature. The shift is from evidence the enterprise collected and stored to evidence the enterprise can produce, verify, and update as sourcing or composition changes — closer to an always-current record than a document filed away after onboarding.
Yes. The obligation attaches to any battery placed on the EU market, regardless of where the manufacturer, its suppliers, or its raw material sources are located — a battery producer in Asia or North America selling into the EU, or a global automaker sourcing battery packs for EU-bound vehicles, carries the same passport and due diligence obligations as an EU-based manufacturer. Non-EU enterprises with EU-facing supply chains need the same origin, composition, and due diligence evidence as EU manufacturers do, and the mapping work to assemble it does not start at the border.
AI-assisted vendor intelligence can continuously ingest supplier certifications, origin documentation, ownership and sanctions screening results, and regulatory filings, then match them against what a specific compliance requirement — such as Annex XIII's due diligence and material composition fields — actually asks for, flagging gaps before an audit or a regulator's request surfaces them first. It can also monitor for supplier-side changes, such as a shift in raw material source or a lapsed certification, that would make previously collected evidence stale. What stays with a named compliance or procurement owner is the judgment call: whether a supplier's evidence is sufficient, whether a gap requires escalation, and whether to accept, remediate, or exit a sourcing relationship.
