Skip to content
Chapter 01 · First edition

The Shape of Manufacturing Risk

Why the risk picture moves every time the business does

Approx. 12 minute read The Manufacturing Risk Handbook

Understand why manufacturing risk behaves as an interconnected system, why ordinary commercial change moves the risk picture, and how the six pillars and nine dependencies reveal concentration.

Calder Precision Components is a composite scenario. It is not a real business, and no single manufacturer or client sits behind it. It combines patterns that recur across growing manufacturing SMEs to show how otherwise sensible decisions can interact.

Eighteen months ago Calder was a sixty-person subcontract machining business, steady turnover, a broad customer base, nothing on the risk register that would keep a director awake. Then three things happened, each of them a good decision on its own.

A major automotive tier-one awarded Calder a three-year supply contract. It was the kind of win the business had chased for years, and it took turnover from a spread of forty customers to one account representing over a third of it. To deliver the volume, Calder bought a five-axis machining centre, a serious piece of capital equipment that became the only machine in the building capable of running the new parts to tolerance. And because the new centre needed programming and maintenance nobody on the existing team could do, Calder brought in one specialist engineer who now holds, largely in his own head, the knowledge that keeps the contract running.

None of that was reckless. It was ambitious, well-financed, and exactly what growth is meant to look like. But look at what it produced. One customer now represents over a third of revenue. One machine now represents the entire capacity for the product line that customer buys. One person now represents the only route to keeping that machine running. Three separate decisions, each sound in isolation, have created a concentrated chain of dependencies that did not exist eighteen months earlier.

Calder's insurance schedule has not changed in that time. Neither has its risk assessment. The business that exists today and the business described on last year's renewal are no longer quite the same business, and nobody made a decision to let that happen. It simply accumulated, one contract, one machine and one hire at a time.

That is the shape of manufacturing risk. This chapter sets out why it behaves the way it does, and introduces the framework the rest of this handbook uses to examine it.

1. Why manufacturing risk behaves differently

Manufacturing risk is not a list of hazards waiting to be priced. It is the product of a system, and systems behave differently to lists.

A manufacturing business links production processes, physical assets, contractual commitments, and specialist knowledge into a single operating chain. Pull on any one link and the others move with it. A new customer contract changes liability exposure and delivery pressure at the same time. New machinery changes both capacity and the skills needed to run it. A single supplier decision can alter your exposure to a whole region you had never previously thought about. Nothing on a manufacturing shop floor sits in isolation, which means nothing in a manufacturing risk profile does either.

The physical assets involved tend to carry more weight than they do elsewhere too. A specialist machine is rarely a commodity item that can be replaced from a catalogue within days. It may be built to order, imported, or dependent on an installation and commissioning process that takes months before it produces a single usable part. The capital tied up in plant, and the lead time behind replacing it, both sit well above what most other sectors carry as a matter of course.

For a manufacturer, recovery may involve replacing specialist machinery, restoring a certified process, recommissioning equipment and proving output to a customer’s required standard. The physical asset may be only the beginning of the recovery journey. The gap between disruption and recovery is measured in production days, customer commitments and cash—not only in the cost of replacing property.

Supply chains in manufacturing tend to run tight rather than resilient, particularly where just-in-time delivery or single-source materials are part of the model. A disruption two tiers upstream, at a supplier you may not even hold a direct relationship with, can stop your own production line just as effectively as a fire in your own building.

And some of the consequences of what happens on a shop floor today do not surface for years. An exposure created now, a process change, a material substitution, a piece of equipment run without the right guarding, can produce a claim or a liability that lands on a desk long after the decision that caused it has been forgotten. Manufacturing risk does not always announce itself at the point it is created.

None of this makes manufacturing uniquely dangerous. It makes it interconnected, and interconnected systems need to be understood as systems, not audited as checklists.

2. Change is the trigger

Where risk review is tied mainly to insurance renewal or an annual management cycle, the formal picture may be updated only once a year. Manufacturing risk does not wait for that calendar. It moves when the business does.

Every one of the following is an ordinary commercial decision, made for good reasons, that also changes what the business is exposed to the day it happens, not the day the policy comes up for renewal:

Buying new machinery, particularly anything that becomes the sole means of producing a product line. Winning or losing a major contract, especially one that concentrates revenue or introduces liability terms nobody has read closely. Automating a process or connecting equipment to a network for the first time. Moving premises, adding a site, or extending an existing one. Exporting for the first time, or entering a market with a different legal and product liability environment. Acquiring another business, and inheriting whatever risk history comes with it. Growing headcount quickly, or coming to rely more heavily on agency and contract labour. Changing a critical supplier, bringing a process in-house, or sending one out.

Calder's three decisions all sit on that list. None of them would have prompted a phone call to a broker under most renewal cycles, because none of them looked, on their own, like an insurance event. Together, they were the most significant change to the business's risk profile in years, and the business carried on trading against a risk picture that had already moved without anyone deciding it should.

The practical implication is straightforward. Waiting for renewal to review what has changed means running for up to twelve months on a risk picture that no longer describes the business. A machine bought in January and a contract signed in June sit unreviewed until the following March, by which point both have been operating, unexamined, for the best part of a year. A stronger operating discipline is to treat significant change itself as the trigger for review.

3. The six pillars

To make a system this interconnected reviewable, it helps to break it into parts that leadership can actually interrogate, without pretending those parts operate independently. That is what the six pillars are for. Each one asks a single leadership question. None of them is taught in full here. Chapters Three to Eight take the six pillars in turn. Chapter Nine examines how the manufacturer works with advisers, and Chapter Ten turns the framework into a practical operating rhythm. This is the map, not the territory.

Growth & Change. Has the business’s understanding of risk moved with its decisions, growth and operating model?

Operational Resilience. What could stop production or delivery, how quickly would the effect spread, and how would the business recover?

Financial Exposure. Which losses, commitments or interruptions could the business not absorb, and what assumptions support the protection it believes it has?

People & Workforce. Which capabilities, decisions, relationships or authorisations depend on particular people, and can workforce change be absorbed safely?

Claims & Defensibility. Could the business demonstrate what it knew, decided, controlled and did if externally scrutinised?

Emerging Risk. What is changing around or through the business, how could it reach operations, and what would trigger action?

Calder's situation touches at least four of the six before a single insurance question is asked: Growth & Change, because the contract and the machine both moved the business on from what its risk arrangements assume. Operational Resilience, because one machine now carries a product line. People & Workforce, because one engineer now carries the machine. Financial Exposure, because a third of turnover now sits with a single customer. That overlap is not a coincidence. It is the normal shape of a real exposure, and it is the reason the next section exists.

4. Dependencies and concentration

A pillar tells you where to look. A dependency tells you what you would actually lose.

Across the six pillars, nine categories of dependency turn up again and again in manufacturing businesses: a major customer or connected customer group, a contract or manufacturing programme, a site used for production, storage or testing, a technology, including a critical machine, production line or process, a digital system or piece of operational technology, a specialist person holding skill or authority that sits nowhere else, a supplier or subcontractor, a particular material, component or approved specification, and a country, region or transport route the business depends on to move goods or materials.

Most businesses can point to one or two of these without much thought. A director will usually know, roughly, who their biggest customer is or which machine would hurt most to lose. Fewer have ever mapped where several of the nine sit on top of one another, because that picture only appears when someone deliberately draws the connections rather than considering each dependency on its own.

The more serious exposures tend to sit exactly where several dependencies overlap on the same point of failure, as they do at Calder. The customer, the machine and the specialist engineer are three separate dependency categories, but they concentrate around one contract. Lose any one of the three and the other two become far less valuable, because none of them functions without the others. That is concentration, and it is very easy to build without ever intending to, one sensible decision at a time.

Identifying a dependency is not, on its own, a problem to fix. Every manufacturer depends on people, machines and customers. The question worth asking is whether the dependency has been identified at all, and whether anyone has tested what happens if it is removed.

5. How InduX examines risk

Every chapter in this handbook, and the InduX Risk360 review itself, works through the same sequence:

CHANGE → EXPOSURE → DEPENDENCY → IMPACT → CONTROL → DEFENSIBILITY → RESPONSE

Start with what changed. Work out what exposure that change created or shifted. Identify which dependencies sit behind that exposure. Establish what the impact would actually be under a credible disruption, including 30 days without the dependency. Look at what controls currently exist against it. Check whether the business could produce evidence that those controls are real, not assumed. Only then decide on a response, which may or may not involve insurance at all.

Run Calder's contract win through it. The change is the new three-year agreement. The exposure includes the liability and delivery terms Calder signed, and the capacity now committed to one customer. The dependencies are the customer, the machining centre, and the engineer, sitting on top of each other. The impact of losing any one of the three, tomorrow, is a production stoppage on the highest-value line in the business, with no fallback capacity and no second person who can run the machine. The controls worth checking are whether the contract terms were reviewed before signature, whether the machine has a maintenance and breakdown plan, and whether the engineer's knowledge has been documented anywhere. The defensibility question is whether any of that could be evidenced to a customer, an insurer or a court if it mattered.

And the response, once all of that is understood, is rarely a single action. For Calder it might mean cross-training a second operator on the new machine, having the contract's liability clauses reviewed before the next renewal comes round, documenting the engineer's maintenance and programming knowledge properly for the first time, and only after that, if a genuine financial gap remains, adjusting insurance arrangements to reflect a business that looks nothing like the one on last year's schedule.

Insurance sits at the end of that sequence, as one possible response among several. It is rarely the first thing to fix, and it is never the only thing that needs fixing.

6. Why insured does not automatically mean protected

Holding an insurance policy confirms that certain risks may be covered subject to its wording, limits, exclusions, conditions and the circumstances of a loss. It does not establish that declared values remain accurate, that the period allowed for recovery is sufficient, that the evidence required for a claim exists, or that every material exposure facing the business is insured.

Chapter Five examines financial exposure, including underinsurance, recovery assumptions and the distinction between funding a loss and preventing one. Chapter Seven examines the evidence and response capability required when an incident, claim or other challenge occurs.

7. How to use this handbook

This is a director's working framework, not a legal manual, an insurance policy guide, or a compliance checklist. Nothing in it replaces regulated advice, and nothing in it should be read as a complete statement of the law in any area it touches.

What it is built to do is give a manufacturing leadership team a shared way of talking about risk that starts from the business itself, not from an insurance product. Each chapter from here takes one pillar and works through it properly. You do not need to read them in order. The most useful way to use this handbook is to start with whatever has actually changed in your business recently, find the chapter that covers it, and work through the sequence above against your own operation.

8. Five board questions

What has changed in this business in the last twelve months that nobody has formally reviewed?

Where do two or more dependencies, a customer, a machine, a site, a person, a supplier, currently sit on top of each other?

What assumption about this business's resilience has never actually been tested?

If we had to prove tomorrow that a specific risk had been properly managed, what evidence would we produce, and does it exist?

Which of our current arrangements were sized for the business as it was, rather than the business as it is now?

9. One immediate exercise

Pick the single most consequential change your business has made in the last twelve months. It might be a contract, a machine, an acquisition, a site move, or a person. Work it through the sequence in this chapter: what changed, what exposure it created, which dependencies sit behind it, what the credible impact would be across the first 30 days if it became unavailable, what controls exist, whether you could evidence them, and what response actually follows.

That one exercise, done properly on one change, will tell you more about where to focus than a general review of everything at once. Risk360 applies the same sequence to help a manufacturer identify where further review may be most valuable.

Continue the journey

Put this chapter into context

Follow the connected pillar and change pages, then test the dependency against your own operation.

Test the dependency

Use Risk360

Use Risk360 to identify which recent business change may have created a concentrated dependency capable of producing the greatest 30-day operational or financial impact.

Optional next step

Discuss a live decision

If this chapter touches a contract, investment, continuity or protection decision already in motion, InduX can help frame the questions that need resolving.

This handbook is general information for manufacturing leadership. It is not legal, regulatory, insurance or professional advice and does not replace advice based on the circumstances of a particular business.