How KION Group Manages Risk in a Global Forklift Supply Chain
In this episode of Rozmowy Logistyków, Adam Sobolewski talks with Jakub Watęborski of KION Group about managing risk in a global supply chain. They discuss what a supplier risk management team is responsible for, what tools it uses, and what decisions a manufacturing company can make as a result.
RISK ISN'T JUST A THREAT — IT'S A DEVIATION FROM PLAN IN EITHER DIRECTION
The formal definition of risk in financial management sounds surprisingly neutral: a positive or negative deviation from the assumed scenario — though in business practice we almost always mean the negative side. KION Group (brands Linde, Still, Fenwick, Dematic — a manufacturer of forklifts and warehouse automation systems, around 40,000 employees, a dozen-plus manufacturing plants globally) manages risk from a procurement perspective, focused on production continuity: what could stop a production line or delay building an automated warehouse for a customer.
WHY PROCUREMENT, NOT TIER 1-2-3, IS THE FIRST LINE OF DEFENSE
Unlike automotive — where mapping the supply chain down to tier 2, tier 3 (suppliers' suppliers) is already standard — KION Group's supplier base consists largely of smaller, local companies with varying levels of operational maturity. In practice, the team pragmatically focuses mainly on tier-1 suppliers, because that's where there's still the most room to improve collaboration and effectiveness — deeper mapping requires scale and negotiating leverage that a smaller client simply doesn't have with a given supplier. Semiconductors are the exception: here, ready-made market tools exist (Silicon Expert from distributor Arrow) that, given a component number, map the entire supply chain down to the fifth or sixth tier — because that data is publicly available and doesn't require a direct partnership with every link in the chain.
HOW REACTION SPEED BECOMES A COMPETITIVE ADVANTAGE
A concrete example of the value of deep chain mapping: during two consecutive hurricanes in the US (Helene and Milton), the world's only mine producing 99%-pure quartz, a key raw material for semiconductors, was flooded. KION's team knew about it the day after the event, even though the real impact on semiconductor availability wouldn't show up for another 3-6 months — that was enough to secure inventory before the market started fighting over it en masse. Risk management, then, isn't just about avoiding crises, it's about building a time advantage over competitors who will only react once shortages become widely felt.
COMPLIANCE RISK CAN HAVE PURELY OPERATIONAL CONSEQUENCES
Regulations on things like forced labor in the supply chain aren't purely a legal matter — a container ship carrying parts for Porsche cars was held in a US port for a month on suspicion that its components contained materials produced through forced Uyghur labor. This shows that compliance risk and operational risk are far more intertwined than they appear at first glance.
WHAT A COMPANY WITHOUT A BUDGET FOR A DEDICATED RISK TEAM CAN DO
Risk management doesn't require expensive tools or a separate team — what matters is organizational awareness and what gets set as the goal: if the only KPI for procurement is cost savings, that alone practically invites concentration risk with a single supplier. Basic steps available to any company: identify risk concentration (do key components come from one supplier at one location), consider dual sourcing where possible, and — most important and cheapest — build close relationships with key suppliers, even when you aren't their most important customer. Even a mid-sized company can benefit from an information exchange with a supplier where both sides gain something, with no need to invest in expensive analytical tools.
WHY THE BUSINESS CASE FOR RISK MANAGEMENT IS HARD TO BUILD
Effective preventive risk management has a paradoxical trait: when it works well, nothing happens — which makes it hard to empirically demonstrate how many crises were avoided. The most effective argument in a business case is pointing to specific, documented past situations (e.g. detecting a supplier's weak financial rating 12 months before its bankruptcy, which gave time to find an alternative and avoid losses in the tens of millions of euros) — much like insurance, where the value of the investment is hard to assess until the risk it protected against actually materializes.
DIVERSIFICATION HAS LIMITS — YOU NEED TO KNOW THE SHARED FAILURE POINTS
Having two suppliers of the same component doesn't protect against risk if both rely on the same second-tier sub-supplier or the same raw material (e.g. rare-earth metals, 90% sourced from China) — in that situation, the number of suppliers in your portfolio doesn't matter, because they'll all be hit at the same time. What matters is a combination of short-term actions (rehearsed scenarios and procedures — who does what in the first 24-72 hours after a cyberattack on an important supplier) and long-term ones (business continuity planning, working to raise security standards at suppliers) — deliberately preparing a plan B ahead of time, instead of firefighting in the middle of a crisis.
Want to apply this to your supply chain?
Let's talk about the challenges in your organization and find where the biggest potential for EBITDA improvement is.
Get in Touch







