.png)
In brief: In May 2026, CATL's Debrecen plant became the world's first RSCI-certified battery factory, and with it sustainability due diligence has arrived in Hungary too — anyone who wants to stay in the big automotive chains will sooner or later have to pass the same sieve. Regulatory pressure comes from three layers at once (the domestic ESG law, EU and German supplier expectations, and RSCI), but in practice compliance is largely a data-management question: the same data has to be retrievable many times, for many purposes, in auditable and protected form. This article shows where data gets stuck in daily operations, and how autonomous AI agents take that burden off.
In May 2026, CATL's battery plant in Debrecen became the world's first RSCI-certified battery factory. In the April audit it scored 86 out of 100, with no major non-conformities. The certification sends a message to the entire domestic supplier base: sustainability due diligence has arrived in Hungary, and anyone who wants to stay in the big automotive chains will sooner or later have to pass through the same sieve.
For logistics and procurement managers, this carries a concrete stake. Failing to comply is no longer a theoretical risk but a direct business loss: dropping out of tenders, rising insurance costs, lost green financing. In practice, compliance largely stands or falls on whether a company can produce its own supplier data when it's asked for. Beyond the sustainability content, this is first and foremost a data-management task.
Regulatory pressure doesn't stem from a single piece of legislation, but from three layers that act at once.
The first is the domestic ESG law (Act CVIII of 2023), which, through a phased rollout, obliges large companies to carry out sustainability and social due diligence on their supply chains and to report in detail. The law extends the obligations gradually, and through supplier reporting it reaches smaller companies too.
The second is EU and German supplier pressure. Germany's supply-chain law (LkSG) and the EU's CSDDD directive cascade down to Hungarian small and medium-sized enterprises through the large buyers. An automotive supplier may not be a direct subject of the German law, but its customer is — and the customer passes the expectation on.
The third — and this is the sharpest one in the automotive sector — is the RSCI (Responsible Supply Chain Initiative). It was launched by the German Association of the Automotive Industry (VDA) in 2021, with the involvement of fourteen leading players including Audi, Volkswagen, Mercedes-Benz and BMW. RSCI is an assessment built on strict on-site audits, examining full compliance in corporate social responsibility, occupational safety and environmental protection. The label that can be earned is valid for 36, 30 or 9 months depending on the result, and for suppliers it is effectively equivalent to a license to operate in the big automotive chains.
The results of an RSCI audit can be shared with different customers on a web-based platform, and this is precisely what lets a supplier avoid repeated audits. They are vetted once, the result is stored in a structured form, and from then on every interested buyer receives the same credible report.
This logic holds for the whole of ESG compliance. The difficulty isn't that the data has to be gathered once, but that the same data has to be dug out again and again: for a customer questionnaire, an audit, bank financing, an official data submission. Anyone handling this by email and in separate spreadsheets starts the collection over with every request.
Seen from the supplier's side, the same burden shows up in reverse. A large buyer has to request, validate and store data from hundreds of suppliers in auditable form. Manual collection is enormous administration for both parties, and this is exactly where the process stalls when there's no system behind it.
And there's one more consideration that's discussed less often. This data is sensitive: supplier contracts, performance figures, certificates. What you gather for sustainability compliance has to be kept in a protected, access-controlled place. Scattered solutions — documents stored in inboxes and shared folders — are exactly what can't provide this: access is untraceable, files can be forwarded, and after the fact it's nearly impossible to say where a document ended up. ESG data collection is therefore also a data-security task, not just a reporting one.
Regulation on its own is still just a framework. In practice, compliance is decided by how data moves within the company day to day — and that typically gets stuck in the same few places.
The first is the question of the channel. If supplier certificates come in by email and in shared spreadsheets, no one has a single view of who has already submitted data and who hasn't, and the request starts over every round. The orderly alternative is a supplier portal where the partner uploads their own data and certificates, based on permissions, in one place.
The second is retrievability. When an audit arrives, email-based operations kick off a hunt through inboxes and folders to find who certified what and when. The problem isn't that a single email can't be found, but that the data runs across several people's inboxes on multiple threads, and there's always one thread that gets lost somewhere. In many places people save emails into separate folders just to have a traceable trail, because searching the mailbox is hopeless. In a system tied into a process, by contrast, every step is recorded with a timestamp, in one place, auditably — so at the moment of the audit the data simply comes up.
The third is change tracking. Regulatory expectations and customer questionnaires change constantly, and in email-based operations everyone has to be contacted again with every change. If forms and approval chains can be adjusted without coding, introducing a new questionnaire isn't a months-long development but a few settings.
Compliance in 2026 is hard partly because of the strict expectations, but at least as much because the same data has to be produced for many purposes, many times over, in auditable form. CATL's certification carries this message too: certification isn't the end of the process but the entry ticket into the big chains, and anyone who wants to get in has to keep their data orderly, protected and retrievable at any time.
This capability decides whether a request is a few clicks or a week-long project. Anyone who records their supplier data once, in a structured way, and works from the same source for every audit, questionnaire and financing request is freed from repetitive administration.
Fluenta One uses autonomous AI agents for this work. The ESG data-collection agent doesn't just receive and file suppliers' data: it actually extracts the content from scanned certificates, old PDFs and multilingual data sheets, and turns it into structured, searchable data. So the supplier doesn't have to squeeze everything into a rigid template — the system interprets what comes in. From this, the tender-ready Scope 3 report is assembled in a uniform form, and the agent also sends a reminder to anyone who hasn't uploaded yet.
The compliance-monitoring agent records every change and approval, analyzes the audit trail, and flags regulatory deviations. It works mainly proactively: it gives advance notice when a certificate is nearing expiry and launches the renewal in time, before the gap becomes a problem. It's continuously visible which supplier is missing a data point or has one about to expire, even before an audit or a payment brings it to the surface. What to do in such a case is up to the company; the system's job is to make sure not a single shortfall goes unnoticed. On its own side, the company doesn't spend its time hunting the report together, but steps in at the decision points where it's actually needed.
The system also doesn't burden everyone equally. It classifies suppliers by risk profile, and the depth of monitoring adjusts to this: a critical partner with access to sensitive data gets a stricter, even quarterly review, while a low-risk, infrequent supplier gets a basic check. The assessment looks at five criteria at once — from financial stability through data security to legal compliance — and if a supplier's situation changes, the classification updates on its own. This way, resources go where the real risk is, rather than being spread evenly across every partner.
The agents fit alongside existing ERP, TMS and WMS systems, with two-way sync. The data stays the company's throughout and can be exported in a structured form at any time. The software provides the framework and the solution; the company has to add the operational discipline — the success of day-to-day operations comes from the two together.
The next customer questionnaire, bank data request or automotive audit isn't a question of whether it's coming, only when. Anyone who keeps their supplier data orderly by then finds it's an afternoon's work; anyone who has it scattered faces weeks of firefighting.
In a short demo we'll look at where your company stands now and what you can do while there's still time. Request a demo →