Compliance and Responsibility
In responding to the demands of the capital market as well as its customers, employees, and other stakeholders, the KION Group is committed to upholding its company values of integrity, collaboration, courage, and excellence, as well as the principles outlined in the Group-wide KION Group Code of Compliance (KGCC).
As part of the KION Group, STILL shares these values and is committed to ensuring complete compliance with all legislation, regulations, and codes of conduct. STILL’s comprehensive compliance management system is based on the KGCC, which sets out guidelines for ethical, value-driven, and lawful business conduct. The KGCC also provides a binding framework for interactions between colleagues, as well as with customers, business partners, and the public.
As a German business, the KION GROUP AG is primarily subject to German law. At the same time, the KION Group must comply with any national legislation in force at its sites around the world. In cases where national law differs from German law, the KGCC defines the appropriate course of action. The Group’s compliance and legal departments are also available as the designated point of contact for all legal questions.
The KGCC is published in 24 languages and is updated as necessary—including with new topics and new priorities—in order to best reflect the prevailing legal and business situation. External parties can access the KGCC on the KION Group website.
Responsibility for the Group-wide compliance management system lies with the Executive Board of KION Group AG. The Chief Compliance Officer heads up the compliance department and works together with the compliance team to improve the compliance management system, provide advice and information on compliance matters, resolve compliance breaches, and organize appropriate training. Each Operating Unit has a dedicated full-time compliance officer, who reports directly to the Chief Compliance Officer and supports the management of the relevant Operating Unit in meeting compliance standards. Local and regional compliance officers are appointed to ensure that the subsidiaries conduct their operations in line with legislative and regulatory requirements.
Effective Compliance Management System
The compliance management system is continually reviewed and refined to ensure it remains fit for purpose. It is based on the IDW PS 980 auditing standard developed by the Institute of Public Auditors in Germany (IDW) and focuses on the prevention of compliance breaches. The anti-corruption element is designed to prevent, uncover, track, and sanction all forms of corruption within the company. Under the system, the Group audit department conducts regular audits and ad-hoc checks to ensure that compliance standards are being upheld across the KION Group AG and its consolidated subsidiaries.
As in previous years, the topics of anti-corruption, data protection and IT security, foreign trade and export controls, action against money laundering, fraud prevention—notably in relation to cybercrime—D&O liability, and management responsibility remained key focal areas in 2023. Anti-discrimination, whistleblower protection, and fostering a speak-up culture—or company culture in which questions and concerns can be openly expressed—were also key aspects in the year under review.
The KION Group is committed to combating all forms of corruption and bribery. To this end, it follows a “prevent, detect, respond” approach. In the reporting year, no confirmed cases of anti-competitive or anti-trust behavior were registered and there were no confirmed cases of active corruption by KION Group employees.
2023 | 2022 | 2021 |
---|---|---|
0 | 0 | 0 |
Multiple Reporting Channels
Actual or suspected cases of non-compliance can be reported in person, by telephone, mail, or email, or via an online form. All KION Group employees—as well as external stakeholders—also have access to an online form and hotline where they can report potential compliance breaches around the clock, including anonymously if they so wish. The whistleblowing system is available worldwide, but is tailored as closely as possible to local conditions. The integrated case management system is designed to ensure that all incoming information is reviewed and that each individual case is processed systematically in line with the provisions in the EU Whistleblowing Directive. This system guarantees confidentiality and protection against retaliation.
The KION Group Compliance Committee is a cross-functional body made up of managers from the Corporate Compliance, Internal Audit, and Legal departments. This committee oversees the processing of reports of potential breaches and related investigations and confers on sanctions in the case of identified compliance violations.
The Compliance Committee at STILL in Germany provides employees with another independent point of contact that they can turn to when seeking advice or reporting potential violations. Anyone that experiences or observes any form of discrimination or harassment can report this behavior to their designated committee—including in complete confidence. Similar contact points are also available at sites across the EMEA region in line with relevant national regulations. Compliance representatives are in place in all countries where STILL operates and can be contacted at any time.
All reports of suspected non-compliance are systematically verified and confirmed cases are followed up through effective control mechanisms such as regular or special audits. Disciplinary action is taken in all cases where misconduct is identified. If necessary, the compliance management system is also updated to prevent further breaches in future.
2023 | 2022 | 2021 |
---|---|---|
30 | 27 | 34 |
Training
In addition to clear compliance policies, STILL also offers extensive information, advice, and training. STILL’s compliance officers and representatives work hard to ensure that the company’s staff are always up-to-date and fully informed about compliance matters and understand the importance of upholding the company’s values. On joining the KION Group, all new employees are required to complete mandatory training in the KION Group Code of Compliance, either online or in-person in the case of staff without access to a work PC. Employees who are exposed to particular compliance risks due to their role—including sales and procurement staff—also attend regular in-person training sessions on specialist topics.
Classroom training (KION Group Code of Compliance, anti-corruption, anti-discrimination, conflicts of interest, whistleblower protection, speak-up culture) |
---|
E-learning course: KION Group Code of Compliance |
E-learning course: Avoiding Corruption in the KION Group—the General Principles of the ABC Policy |
E-learning course: Professional Conduct at KION—Promoting a Respectful Working Environment |
E-learning course: Preventing Money Laundering and Fraud at KION |
E-learning course: Avoiding Conflicts of Interest at KION |
E-learning course: KION Group—Preventing Anti-Competitive Practice |
E-learning course: General Data Protection |
E-learning course: Information Security Employee Awareness Training |
E-learning course: Role of Unconscious Bias in the Workplace |
E-learning course: Speak up—We’re Listening |
The aim of this program is to provide all KION Group employees with regular training on the most important topics (anti-corruption, avoiding conflicts of interest, antitrust and competition law, anti-money laundering, whistleblower protection, data protection, IT security, and human rights). Changes to legislation or internal regulations are also communicated through in-person training sessions, as are any lessons learned from the compliance management system. The training program was expanded in 2023 to include an e-learning course on unconscious bias, speak-up culture, and whistleblower protection. Following on from this, employees without access to a PC will receive in-person training on KION’s whistleblowing channels and whistleblower protection in 2024, specially designed for the target group.
2023 | 2022 | 2021 |
---|---|---|
79% | 100% | 100% |
Compliance Auditing for Business Partners
Before the KION Group enters into a new business relationship, external business partners must be audited and relevant documentation secured. The audit process establishes and verifies the financial background of the potential business partner and identifies any arguments against entering into a business relationship, e.g. the business appears on a sanction list or is the subject of negative reporting. In case of doubts, the KION Group may choose not to pursue its business dealings with a particular partner. External partner audits at the KION Group are, wherever possible, conducted on the basis of a risk assessment.
The basic audit is conducted using the Group’s business partner tool, which is maintained by the compliance department and designed to check customers and suppliers against compliance watch lists. The compliance department is responsible for running these checks, assessing the results, and taking any necessary action. In the case of external sales partners where the potential for corruption is higher—such as dealers, importers, distributors, agents, or integrators—the responsible compliance officer will conduct a multi-stage due diligence assessment prior to the start of a new business relationship. In addition to identifying potential risks in the relevant country based on subindices from reputable international organizations, this assessment obtains information from the sales partners via due diligence questionnaires, through audits conducted using the business partner tool, and/or via external due diligence providers. The results of the due diligence assessment are subsequently communicated to the responsible teams—for example, senior management—along with any recommended actions, such as tighter contractual terms including a right to audit clause or additional monitoring of payment streams.
Periodic risk analysis
The KION Group regularly conducts a systematic risk analysis to identify and evaluate corruption and bribery risks throughout the Group. Money laundering, tax compliance, cybersecurity, and human rights risks are also assessed, as are the risks of non-compliance with competition laws. Non-financial risks that arise on an ongoing basis are also screened, evaluated, and managed. Based on the results of this analysis, the Group devises suitable actions to eliminate any weaknesses in the relevant processes and control mechanisms. Key factors used in the risk analysis include the corruption perception index for the respective country, the size and structure of the local procurement or sales organization, and any contacts with public officials. The risk analysis has been completed for all STILL subsidiaries, with no significant compliance risks identified.
2023 | 2022 | 2021 |
---|---|---|
100% | 100% | 100% |
Data Protection and Information Security
Data protection and information security are both top priorities at STILL and the company complies with the relevant policies in place across the KION Group. This includes the Data Protection Policy, which sets out technical and organizational measures to protect personal data, and KION’s Information Security Policy, which focuses on safeguarding the confidentiality, integrity, and availability of information, as well as protecting the KION Group against related attacks. There are also a series of Group-wide operating agreements and mandatory standards in place covering topics such as IT security in the workplace and the management of IT systems, email, and internet usage. Samples and templates to facilitate the day-to-day handling of personal data and sensitive business information are also available. The Operating Units are each responsible for implementing the central requirements of these policies and standards. Staff members responsible for data protection and the coordination of data protection activities in the individual subsidiaries report to their respective senior management team. At Group level, the Group Data Protection Officer reports to the Chief Compliance Officer, and the KION Group Chief Information Security Officer reports to the KION Group Chief Information Officer who reports to the Executive Board of KION Group AG.
Protecting sensitive personal data is also an important responsibility, so secure and effective processes and systems have therefore been put in place to protect this information and ensure compliance with the relevant legislation. All staff are given training and receive regular updates via the Group intranet to ensure that they understand and remain up to date with basic data protection principles, their reporting obligations, and the Group-wide compliance reporting system.
There were around 63 million attacks on the KION Group’s IT network during the year under review, all of which were averted. Key to this success are continual efforts to identify vulnerabilities across the Group’s IT and operational technology infrastructure. Regular training on IT security issues, global anti-phishing campaigns, a monthly video series published on the Group intranet, and instructions for keeping IT infrastructure secure also play an important role in maintaining IT security standards.
Information Security Management System
At the end of 2022, the KION Group began the rollout of an Information Security Management System (ISMS), with the aim of further protecting sensitive information and ensuring the Group remains competitive in the industry. The ISMS is based on the standards set out in ISO 27001 (for the establishment, implementation, maintenance, and continuous improvement of documented information security management processes) and applies across the Group. A documentation policy has also been drawn up, which sets out the requirements for maintaining information security standards.
The KION Group regularly analyzes potential or existing threats to its information security. Where these risk analyses identify an IT security risk or deviation from KION Group security standards, the risk is described and an appropriate course of action defined. The residual risk is also assessed and, on this basis, the risk owner decides whether or not to accept this risk. Residual risks continue to be reassessed on a regular basis and the decision to accept them reaffirmed.
The Group audit department conducts regular IT audits, including information security checks.
In April and May 2023, the KION Group headquarters in Frankfurt am Main, Germany, also became the first Group location to complete a TISAX1 assessment. The STILL GmbH subsidiaries in Berlin and Hanover became the first STILL companies to pass the audit in November 2023, and are thus officially TISAX certified for the next three years.
In each case, these companies were found to be at a high degree of readiness in the first assessment, and the TISAX label was granted without conditions. As part of the assessment process, the site had to provide the auditors with around 200 different pieces of evidence, including information security standards, standard procedures, security plans, KPIs, and more.
The aim now—alongside plans to incorporate further sites into the ISMS over the course of the year—is to maintain these high information security standards and ensure that the system components continue to prove effective in day-to-day operations. Among other activities, this will include conducting regular internal audits and checks, managing information security risks, and planning and introducing improvements and other measures.
2023 | 2022 | 2021 |
---|---|---|
1 | 0 | 1 |
Footnotes:
[1] TISAX® is a cross-company assessment and exchange mechanism for promoting information security in the automotive industry. It is designed to ensure the security, integrity, and availability of data required for manufacturing processes and vehicle operations.