Risk Management Maturity Assessment Method for Strengthening the Resilience of the Intralogistics Service Process in Warehouse 4.0 (RMMAM-W4.0)
Featured Application
Abstract
1. Introduction
- It proposes a conceptual framework for a risk management maturity model that covers the full range of risk sources specific to the cyber-socio-technical environment of Warehouse 4.0, rather than limiting the assessment solely to technical or digital dimensions.
- It introduces a cross-mapping mechanism linking the results of the maturity assessment with six resilience components of the intralogistics handling process, making it possible to transform a maturity profile into a resilience profile and, on this basis, to identify the risk management areas requiring priority reinforcement—thereby combining the model’s diagnostic function with its developmental and benchmarking functions.
- The practical applicability of the proposed method is demonstrated through an illustrative case study based on data collected from a highly automated AS/RS-class warehouse, showing that an aggregated maturity index may mask a significant imbalance in the resilience profile; the case demonstrates usability but is not intended as full empirical validation of the method, and it formulates concrete improvement recommendations on this basis.
2. Theoretical Background
2.1. Principles for Formulating Maturity Models
2.2. Risk Management Maturity Models
3. Methodology
- RQ1: Which risk categories should be taken into account in the risk management maturity assessment so that it corresponds to the specificity of the cyber-socio-technical environment of Warehouse 4.0?
- RQ2: Which dimensions and levels of risk management maturity should constitute the structure of the assessment model, in accordance with applicable risk management standards for cyber-socio-technical systems?
- RQ3: Which dimensions of intralogistics service process resilience should be developed through mature risk management in Warehouse 4.0?
- RQ4: How should the risk management maturity dimensions be linked to the intralogistics service process resilience dimensions, so as to identify, on this basis, the risk management areas requiring strengthening from the perspective of process resilience?
- RQ5: How can the results of the matrix juxtaposition of the maturity dimensions and the resilience dimensions be used to formulate recommendations aimed at strengthening the resilience of the intralogistics service process against the operational risks that occur?
- Risk categories denote ordered groups of disruption sources specific to the functioning of Warehouse 4.0. Their purpose is to determine which types of risk should be taken into account in the risk management maturity assessment. These categories form a map of the risk sources characteristic of Warehouse 4.0. Risk categories do not constitute independent maturity dimensions or resilience metrics; rather, they indicate against which disruption sources the maturity of risk management practices should be assessed. In the proposed method, a risk is assumed to be assigned to the category that best describes the dominant source of the disruption, rather than its operational effect.
- Risk management maturity dimensions denote the assessment areas describing the degree of development of risk management practices in Warehouse 4.0. They constitute the core of the method, as they determine what is subject to assessment and in which areas a maturity level can be assigned. These dimensions should relate to the key risk management functions. It is critical that they do not describe types of risk, but rather the manner in which the organisation manages those risks.
- Intralogistics service process resilience components denote the functional constituents of resilience that should be strengthened through mature risk management. Within the method, they perform an interpretive function, making it possible to assess whether a given level of risk management maturity translates into the process’s capacity to maintain an acceptable level of performance under disruption conditions. Resilience components are categories used to interpret the consequences of mature or immature risk management for the continuity of the intralogistics service process.
4. Results
4.1. Layer 1—Warehouse 4.0 Risk Source Map
4.2. Layer 2—Risk Management Maturity Assessment Model
- Normalisation. The sum of the weights assigned to all assessed dimensions must equal one:
- 2.
- No zero weights. Due to the structuring function of the risk source map (Layer 1), no dimension should receive a weight of wi = 0—this would mean the complete omission of a given area from the aggregated assessment, which would be contrary to the assumption of assessment completeness. It is recommended to adopt a minimum weight threshold (e.g., wi ≥ 0.05), set individually by the organisation.
- 3.
- Substantive basis of the weights. The weights should reflect the warehouse’s actual risk exposure in a given area, rather than being assigned arbitrarily. As criteria for weight assignment, managers should take into account: the degree of process automation and digitisation, the criticality of a given dimension for the continuity of intralogistics service, the organisation’s past incident history, and the organisation’s strategic priorities in the area of risk management.
- 4.
- Structured weight-setting procedure. In order to limit subjectivity, it is recommended that weights not be set arbitrarily, but using a structured comparison method (e.g., pairwise comparison of dimensions, rank scoring, or an expert workshop), and that the process of setting them be documented and reproducible (auditable).
- 5.
- Periodic verification. The weights are not fixed—they should be reviewed cyclically (e.g., once a year or after a significant technological or organisational change), so that they reflect the current risk profile of the warehouse.
4.3. Layer 3—Intralogistics Service Process Resilience Components
- NIST SP 800-160 Vol. 2 Rev. 1 (Developing Cyber-Resilient Systems) [28], where system resilience is defined through the capabilities to anticipate, withstand, recover and adapt,
- ISO 22316:2017 (Security and resilience—Organizational resilience) [27], which identifies resilience as the organisation’s capacity for absorption and adaptation in a changing environment.
- The literature on business process resilience, which distinguishes phases before, during and after a disruption.
4.4. Cross-Mapping Matrix of Maturity and Resilience Dimensions
- Assignment of contribution coefficients. For each column of the matrix (each resilience dimension j), the managerial team assigns a coefficient cij ∈ [0, 1] to each dimension marked in that column as ● or ◐, whereby the sum of the coefficients within a given column must equal 1: Σi cij = 1. Dimensions marked ● should receive a clearly higher coefficient than dimensions marked ◐, reflecting the difference in association strength established in the matrix. Empty cells have no assigned values and are not included in the sum of coefficients. The method does not impose specific values for cij—analogously to the weights wi from Layer 2, their determination is left to the team implementing the assessment, subject to the normalisation principle.
- Determination of the process resilience profile. Based on the assessed maturity levels L1, …, L7 and the assigned coefficients, the level of each resilience dimension Cj is calculated as a weighted average of the maturity levels of the dimensions that shape it:where Cj denotes the resulting level of resilience dimension j on a 1–5 scale, consistent with the maturity level scale. The levels L1, …, L7 used in this step are the same values that were individually assessed for each dimension in Layer 2—unlike the aggregated index Mw, calculated there as a single combined measure for the entire risk management system, the Cj formula deliberately refers to the levels of individual dimensions, in order to preserve the ability to indicate which of them require strengthening. Repeating this calculation for all six dimensions (R1–R6) gives the process resilience profile (C1, …, C6), which complements the maturity profile obtained in Layer 2.
- Identification of areas requiring strengthening. The resilience profile makes it possible to identify the resilience dimensions with a relatively lower Cj level compared with the others, and, through the cross-mapping matrix, to identify which specific maturity dimensions (especially those marked ●) are responsible for this lower result. This identification is comparative in nature within the profile itself—it makes it possible to determine which resilience dimensions of the intralogistics service process are less developed than the others in a given warehouse, and thus which risk management dimensions should be strengthened first in order to raise the level of dimensions R1–R6.
4.5. Case Study
4.5.1. Risk Management Maturity Assessment
4.5.2. Assignment of Weights wi and Calculation of the Aggregated Index Mw
4.5.3. Assignment of Coefficients cij and Calculation of the Resilience Profile
4.5.4. Recommendations Aimed at Increasing the Resilience of the Intralogistics Service Process
5. Discussion
5.1. The Risk Management Assessment Model in the RMMA-W4.0 Method Compared with Other Risk Management Models
5.2. Discussion of the Results Obtained from the Implementation of the RMMA-W4.0 Method at a Real Facility
5.2.1. The Added Value of the Method’s Three-Layer Structure
5.2.2. The Discrepancy Between Technical and Organisational Maturity
5.2.3. Implications for Managers of Warehouse 4.0 Facilities
5.2.4. Study Limitations and Directions for Further Research
5.2.5. Boundary Conditions for the Aggregation Index and the Influence of External Supply Chain Disruptions
6. Conclusions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Acknowledgments
Conflicts of Interest
Appendix A
| Dimension | Level 1—Reactive | Level 2—Basic | Level 3—Standardized | Level 4—Predictive | Level 5—Adaptive |
|---|---|---|---|---|---|
| D1. Identification of the criticality of Warehouse 4.0 processes and resources | The criticality of processes and resources is not formally defined. The significance of system elements becomes apparent only after a disruption occurs. | Selected processes or resources have been identified as significant, but there is no consistent method for assessing their criticality or linking it to process resilience. | Critical processes and resources (systems, data, infrastructure, automation, personnel) are formally identified and assessed in terms of their impact on the continuity of intralogistics service. | The criticality of processes and resources is monitored and updated based on operational data, technological changes, and the results of disruption analyses and resilience tests. | Criticality assessment is dynamic and used to design process resilience, prioritize investments, and adaptively manage resources under variability and disruptions. |
| D2. Identification and classification of Warehouse 4.0 risks | Risks are identified mainly after incidents. The most visible failures or operational disruptions are primarily recognized. | A basic risk register exists, covering selected digital, infrastructure, operational, organizational, and human risks, but the classification is neither complete nor regularly updated. | Risks are systematically identified and classified according to adopted risk classes. They are linked to stages of the intralogistics service process, critical resources, and disruption scenarios. | Risk identification is supported by data, KPI/KRI monitoring, incident analysis, reviews of technological changes, and warning signals from digital systems and infrastructure. | Risk classification is dynamically updated with changes in the process, technology, data, automation, and the operational environment. It includes emergent risks and scenarios of complex disruptions. |
| D3. Analysis and assessment of the impact of risk on the intralogistics service process | The impact of risk is assessed intuitively, most often qualitatively and without reference to measurable process parameters. | For selected risks, a basic assessment of likelihood and consequences is conducted, but without a full link to the resilience of the intralogistics service process. | Risks are analysed in terms of their impact on SLA, throughput, backlog, picking quality, system availability, infrastructure availability, and recovery time. | Impact analysis is supported by operational data, scenario analysis, simulations, tests under disrupted conditions, and residual risk assessment. | Risk impact assessment is conducted in a predictive and adaptive manner. The results of analyses are used to anticipate resilience gaps, plan proactive actions, and optimize process resilience. |
| D4. Assessment of vulnerabilities, risk monitoring, and effectiveness of control mechanisms | Vulnerabilities are recognized only after a disruption, and monitoring is reactive. The assessment of safeguards and operational data is ad hoc and informal. | Selected vulnerabilities and basic process indicators (KPIs) have been identified, but there is no systematic assessment of control effectiveness or comprehensive monitoring of risk and resilience. | A formal assessment of vulnerabilities, single points of failure, and the effectiveness of safeguards is conducted. KPIs and KRIs related to risk, system availability, data quality, and process performance are monitored. | The effectiveness of control mechanisms is tested and audited, and monitoring enables early warning of disruptions through trend analysis, alerts, and the use of operational data. | Vulnerability assessment and monitoring are continuous and predictive. The system detects changes in the risk profile, and control mechanisms are proactively improved based on data and resilience test results. |
| D5. Risk treatment, response planning, and maintaining continuity of operations | Actions addressing risk are taken after an incident and are improvised. The response is based on employee experience, without formal procedures. | Basic mitigating actions and selected emergency procedures have been defined, but they are incomplete, rarely tested, and not linked to resilience priorities. | Risk treatment is formally planned. Response scenarios, escalation procedures, and business continuity plans exist and are linked to risk mitigation actions and process maintenance. | Actions are selected based on an assessment of effectiveness and residual risk. Response procedures are tested, and the warehouse has the ability to switch the process to emergency or degraded mode and to detect the need for such a switch early. | Risk treatment and continuity of operations are continuously improved. The organization adaptively maintains the process despite complex disruptions, integrating resilience actions with the development of warehouse technology and architecture. |
| D6. Management of responsibility, competencies, and risk communication | Responsibility for risk is informal. Risk knowledge depends on individual employees, and communication during a disruption is uncoordinated. | Selected roles and basic communication channels have been defined. Training is provided, but it does not systematically cover emergency work, HMI, degraded mode, and disruption scenarios. | Roles, responsibilities, competencies, and communication channels are formally defined. Employees are trained in Warehouse 4.0 risks, system operation, emergency procedures, and cooperation between operations, IT, and maintenance. | Competencies and communication are regularly tested during exercises, simulations, and incident reviews. Employee readiness to work in emergency mode and the ability to interpret signals from systems are monitored. | Competence and communication management is based on continuous improvement. The organization develops a culture of risk awareness, multitasking, human–automation cooperation capabilities, and rapid team learning after incidents. |
| D7. Review, learning, and improvement of risk management | Lessons after incidents are formulated on an ad hoc basis and are rarely translated into lasting changes in procedures or control mechanisms. | Basic reviews of selected incidents and periodic documentation updates are conducted, but improvement actions are not systematically linked to resilience gaps. | There is a formal process for risk review, incident analysis, updating the risk register, correcting procedures, and planning improvement actions. | The results of reviews, tests, audits, and incident analyses are used to assess the effectiveness of risk management, update scenarios, and reduce identified resilience gaps. | Improvement of risk management is continuous and systemic. Maturity assessment results are used for strategic strengthening of process resilience, designing technological and organizational changes, and building resilience-by-design. |
References
- Laine, V.; Valdez-Banda, O.; Goerlandt, F. Risk Maturity Model for the Maritime Authorities: A Delphi Study to Design the R-Mare Matrix Model. WMU J. Marit. Aff. 2024, 23, 137–163. [Google Scholar] [CrossRef] [Scilit]
- Tubis, A.A.; Werbińska-Wojciechowska, S. Risk Management Maturity Model for Logistic Processes. Sustainability 2021, 13, 659. [Google Scholar] [CrossRef] [Scilit]
- Proença, D.; Borbinha, J. Maturity Models for Information Systems—A State of the Art. Procedia Comput. Sci. 2016, 100, 1042–1049. [Google Scholar] [CrossRef] [Scilit]
- Andersen, E.S.; Jessen, S.A. Project Maturity in Organisations. Int. J. Proj. Manag. 2003, 21, 457–461. [Google Scholar] [CrossRef] [Scilit]
- Kohlegger, M.; Maier, R.K.; Thalmann, S. Understanding Maturity Models Results of a Structured Content Analysis. In Proceedings of the I-KNOW ’09 and I-SEMANTICS ’09, Graz, Austria, 2–4 September 2009. [Google Scholar]
- Pöppelbuß, J.; Röglinger, M. What Makes a Useful Maturity Model? A Framework of General Design Principles for Maturity Models and Its Demonstration in Business Process Management. In Proceedings of the European Conference on Information Systems, Helsingi, Finland, 9–11 June 2011. [Google Scholar]
- Van Looy, A. Business Process Maturity: A Comparative Study on a Sample of Business Process Maturity Models; vom Brocke, J., Liechtenstein, V., Eds.; Springer: Berlin/Heidelberg, Germany, 2014. [Google Scholar]
- Poeppelbuss, J.; Niehaves, B.; Simons, A.; Becker, J. Maturity Models in Information Systems Research: Literature Search and Analysis. Commun. Assoc. Inf. Syst. 2011, 29, 27. [Google Scholar] [CrossRef] [Scilit]
- Kosieradzka, A.; Smagowicz, J. Concept for a Pilot Study to Verify a Maturity Model in the Area of Public Crisis Management. Zesz. Nauk. Politech. Pozn. Organ. I Zarządzanie 2018, 77, 127–143. (In Polish) [Google Scholar] [CrossRef] [Scilit]
- Chrapko, M. CMMI. Improving Processes in an Organisation; Polish Scientific Publishing House: Warsaw, Poland, 2010. (In Polish) [Google Scholar]
- Bititci, U.S.; Garengo, P.; Ates, A.; Nudurupati, S.S. Value of Maturity Models in Performance Measurement. Int. J. Prod. Res. 2015, 53, 3062–3085. [Google Scholar] [CrossRef] [Scilit]
- Becker, J.; Knackstedt, R.; Pöppelbuß, J. Developing Maturity Models for IT Management. Bus. Inf. Syst. Eng. 2009, 1, 213–222. [Google Scholar] [CrossRef] [Scilit]
- Salah, D.; Paige, R.; Cairns, P. An Evaluation Template for Expert Review of Maturity Models. In Product-Focused Software Process Improvement; Jedlitschka, A., Kuvaja, P., Kuhrmann, M., Männistö, T., Münch, J., Raatikainen, M., Eds.; PROFES 2014; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 2014; Volume 8892, pp. 318–321. [Google Scholar]
- Helgesson, Y.Y.L.; Höst, M.; Weyns, K. A Review of Methods for Evaluation of Maturity Models for Process Improvement. J. Softw. Evol. Process 2012, 24, 436–454. [Google Scholar] [CrossRef] [Scilit]
- Cooke-Davies, T.J.; Arzymanow, A. The Maturity of Project Management in Different Industries. Int. J. Proj. Manag. 2003, 21, 471–478. [Google Scholar] [CrossRef] [Scilit]
- Thordsen, T.; Murawski, M.; Bick, M. How to Measure Digitalization? A Critical Evaluation of Digital Maturity Models. In Responsible Design, Implementation and Use of Information and Communication Technology; Hattingh, M., Matthee, M., Smuts, H., Pappas, I., Dwivedi, Y., Mäntymäki, M., Eds.; I3E 2020; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 2020; Volume 12066, pp. 358–369. [Google Scholar]
- Adekunle, S.A.; Aigbavboa, C.; Ejohwomu, O.; Ikuabe, M.; Ogunbayo, B. A Critical Review of Maturity Model Development in the Digitisation Era. Buildings 2022, 12, 858. [Google Scholar] [CrossRef] [Scilit]
- Hillson, D. Towards a Risk Maturity Model. Int. J. Proj. Bus. Risk Manag. 1997, 1, 35–45. [Google Scholar]
- Cavalcante de Souza Feitosa, I.S.; Ribeiro Carpinetti, L.C.; de Almeida-Filho, A.T. A Supply Chain Risk Management Maturity Model and a Multi-Criteria Classification Approach. Benchmarking Int. J. 2021, 28, 2636–2655. [Google Scholar] [CrossRef] [Scilit]
- Oliva, F.L. A Maturity Model for Enterprise Risk Management. Int. J. Prod. Econ. 2016, 173, 66–79. [Google Scholar] [CrossRef] [Scilit]
- Hoseini, E.; Hertogh, M.; Bosch-Rekveldt, M. Developing a Generic Risk Maturity Model (GRMM) for Evaluating Risk Management in Construction Projects. J. Risk Res. 2021, 24, 889–908. [Google Scholar] [CrossRef] [Scilit]
- Karunarathne, B.V.G.; Kim, B.-S. Risk Management Application-Level Analysis in South Korea Construction Companies Using a Generic Risk Maturity Model. KSCE J. Civ. Eng. 2021, 25, 3235–3244. [Google Scholar] [CrossRef] [Scilit]
- Salawu, R.A.; Abdullah, F. Assessing Risk Management Maturity of Construction Organisations on Infrastructural Project Delivery in Nigeria. Procedia-Soc. Behav. Sci. 2015, 172, 643–650. [Google Scholar] [CrossRef] [Scilit]
- Serpell, A.; Ferrada, X.; Rubio, L.; Arauzo, S. Evaluating Risk Management Practices in Construction Organizations. Procedia-Soc. Behav. Sci. 2015, 194, 201–210. [Google Scholar] [CrossRef] [Scilit]
- Wibowo, A.; Taufik, J. Developing a Self-Assessment Model of Risk Management Maturity for Client Organizations of Public Construction Projects: Indonesian Context. Procedia Eng. 2017, 171, 274–281. [Google Scholar] [CrossRef] [Scilit]
- ISO 31000:2018; Risk Management—Guidelines. ISO: Geneva, Switzerland, 2018.
- ISO 22316:2017; Security and Resilience—Organizational Resilience—Principles and Attributes. ISO: Geneva, Switzerland, 2017.
- Ross, R.; Pillitteri, V.; Graubart, R.; Bodeau, D.; McQuaid, R. Developing Cyber-Resilient Systems: A Systems Security Engineering Approach; NIST Special Publication 800-160, Volume 2, Revision 1; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2021. [CrossRef] [Scilit]
- Tubis, A.A.; Rohman, J. Intelligent Warehouse in Industry 4.0—Systematic Literature Review. Sensors 2023, 23, 4105. [Google Scholar] [CrossRef] [Scilit]
- Fuchs, D.; Kuys, B.; Eisenbart, B.; Gericke, K. A Systematic Literature Review on Emerging Technology Risks in Industry 4.0/5.0: Identification, Clustering and Developing Mitigation Strategies. Proc. Des. Soc. 2025, 5, 299–308. [Google Scholar] [CrossRef] [Scilit]
- Rodríguez-García, M.; Kembro, J.H.; Betts, K.; Ponce-Cueto, E. Managing Technology-Related Disruptions and Vulnerabilities in Highly Automated Warehouse Systems: An Integrative Review and Research Agenda. Int. J. Prod. Res. 2026, 64, 1676–1708. [Google Scholar] [CrossRef] [Scilit]
- Tubis, A. The New Paradigm of Risk in Internal Transport Supporting Logistics 4.0 System; Springer: Berlin/Heidelberg, Germany, 2024. [Google Scholar]
- Tubis, A.A. Digital Maturity Assessment Model for the Organizational and Process Dimensions. Sustainability 2023, 15, 15122. [Google Scholar] [CrossRef] [Scilit]
- Tubis, A.A.; Werbińska-Wojciechowska, S. Reliable and Resilient Logistics Systems; Elsevier: Amsterdam, The Netherlands, 2025. [Google Scholar]
- ISO 22301:2019; Security and Resilience—Business Continuity Management Systems—Requirements. ISO: Geneva, Switzerland, 2019.
- Salhieh, L.; Alswaer, W. A Proposed Maturity Model to Improve Warehouse Performance. Int. J. Product. Perform. Manag. 2022, 71, 3724–3746. [Google Scholar] [CrossRef] [Scilit]
- Salhieh, L. Warehouse Maturity Level and Operational Efficiency. LogForum 2024, 20, 533–544. [Google Scholar] [CrossRef] [Scilit]
- Dellana, S.; Rowe, W.J.; Liao, Y. A Scale for Measuring Organizational Risk Management Maturity in the Supply Chain. Benchmarking Int. J. 2022, 29, 905–930. [Google Scholar] [CrossRef] [Scilit]
- Čech, M.; Januška, M. Evaluation of Risk Management Maturity in the Czech Automotive Industry: Model and Methodology. Amfiteatru Econ. 2020, 22, 824–845. [Google Scholar] [CrossRef] [Scilit]
- Neumann, W.P.; Winkelhaus, S.; Grosse, E.H.; Glock, C.H. Industry 4.0 and the Human Factor—A Systems Framework and Analysis Methodology for Successful Development. Int. J. Prod. Econ. 2021, 233, 107992. [Google Scholar] [CrossRef] [Scilit]
- Rangel Luzuriaga, E.W. A Moderated Model of Digital Transformation in SMEs: Digital Competencies, Digital HRM, and Organizational Culture. Ceniiac 2025, 1, e0010. [Google Scholar] [CrossRef] [Scilit]





| Structural Element | Characteristics |
|---|---|
| Object of assessment | The boundaries of the object of assessment must be precisely defined in order to avoid ambiguous interpretation of results. |
| Assessment dimensions | Components of the assessed object for which requirements corresponding to successive maturity levels are defined. |
| Maturity levels | A scale, typically comprising four or five levels, progressing from a baseline state to an advanced state. |
| Transition criteria between levels | Criteria distinguishing successive levels, which should be unambiguous and verifiable. |
| Rules for aggregation and interpretation of results | Rules determining whether the model generates a single synthetic score, a staged classification, or a differentiated profile. |
| Assessment mode | The manner in which the assessment is conducted—self-assessment, expert panel, document analysis, or a combination of these methods. |
| Model | Sector | No of Levels | Assessment Methods | Dimensions/Assessment Areas |
|---|---|---|---|---|
| SCRM [19] | Supply chain (any sector) | 4 | Theoretical model + fuzzy TOPSIS-Class (multi-criteria classification) |
|
| ERM [20] | Enterprises (enterprise risk management), | 5 | Factor analysis, cluster analysis, multinomial logistic regression |
|
| GRMM—[22] | Construction (companies and construction projects) | Point-based scale | Expert survey; Maturity Score (MS), Ambition Score (AS), Importance Score (IS) indicators |
|
| RM3—[23] | Construction (road projects) | 4 | Fuzzy synthetic evaluation (trapezoidal membership functions, defuzzification) |
|
| Hillson-based maturity model [24] | Construction (clients and contractors) | 4 | Questionnaire validated by expert panels; average of respondents’ scores |
|
| RM [25] | Public construction (government units) | 4 | Delphi method (attribute selection and validation) + AHP (attribute weighting) |
|
| LRMM—[2] | Logistics processes / supply chain | 5 | Descriptive assessment via maturity matrix + global maturity index (weighted average) |
|
| RQ | Addressed in | Result Presented in |
|---|---|---|
| RQ1 | Section 4.1—Warehouse 4.0 Risk Source Map | Figure 4, Table 7 |
| RQ2 | Section 4.2—Risk Management Maturity Assessment Model | Figure 5, Table 8 |
| RQ3 | Section 4.3—Intralogistics Service Process Resilience Components | Table 10 |
| RQ4 | Section 4.4—Cross-Mapping Matrix of Maturity and Resilience Dimensions | Table 11 |
| RQ5 | Section 4.5—Case Study (application of the cross-mapping matrix to the assessed facility) | Tables 12–17 |
| Stage | Research Methods |
|---|---|
| Stage 1 |
|
| Stage 2 |
|
| Stage 3 |
|
| Stage 4 |
|
| Stage 5 |
|
| Methodological Assumption | Description of the Assumption | Significance for the Construction of the Method |
|---|---|---|
| The method is not a digital maturity assessment method for Warehouse 4.0 | The subject of the method is not the assessment of the level of digitisation and the use of Logistics 4.0 technologies as such. Digital technologies are treated as an element of the cyber-socio-technical warehouse environment, which can simultaneously strengthen the intralogistics service process and generate new vulnerabilities. | Makes it possible to avoid equating a high technological level of the warehouse with high resilience of the intralogistics service process. |
| The core of the method is the risk management maturity model | The main element of the method is a maturity model based on risk management dimensions and a five-level maturity scale, with the assessment focused on the maturity of risk management practices. | Enables a structured assessment of the degree of development of risk management practices in Warehouse 4.0. Allows the method to be built around the risk management process. |
| The risk source map defines the scope of the assessment | The method distinguishes risk sources relevant to Warehouse 4.0, which form a map structuring the scope of identification and analysis of risks characteristic of the intralogistics service process. | Allows verification of whether the risk management maturity assessment covers the full spectrum of disruptions that may affect the continuity of the intralogistics service process. |
| The resilience dimensions constitute the interpretive layer of the method | The method adopts six dimensions of intralogistics service process resilience, covering the pre-disruption, in-disruption and post-disruption phases. This means that anticipation and absorption of disruptions are equally relevant as response, operation in degraded mode, adaptation and recovery of operations. | Enables the interpretation of the risk management maturity level through the lens of its impact on process resilience, while also allowing process resilience to be assessed more broadly than merely through the time needed to return to the pre-incident state. |
| The method adopts a continuous mode of results interpretation | Each maturity dimension and each resilience dimension is assessed individually on a five-level scale. The result of the assessment is a profile, not a single aggregated stage-based classification. | Preserves the visibility of the uneven development of individual dimensions, instead of masking it behind a single synthetic score. |
| The method has a diagnostic-prescriptive character | The method serves not only to determine the current level of risk management maturity but also—through the cross-mapping matrix—to identify areas requiring strengthening from the perspective of process resilience and to formulate improvement recommendations within the maturity dimensions. | Justifies the use of the cross-mapping matrix results for designing actions aimed at strengthening the resilience of the intralogistics service process. |
| The scope of the method concerns the operational level | The method focuses on the continuity and resilience of the intralogistics service process, not on the overall digital transformation strategy of the enterprise. Strategic and financial risks may constitute context but are not treated as core assessment areas. | Preserves the coherence of the method with the aim of the study, namely strengthening the resilience of the intralogistics service process under operational disruption conditions. |
| Layer Name | Characteristics | Function in the Model |
|---|---|---|
| Warehouse 4.0 risk source map | Covers the risk classes specific to the Warehouse 4.0 environment. This map does not constitute a separate maturity scale, but structures the scope of risks that should be taken into account in the assessment, preceding its execution. | Ensures the completeness of the assessment. Indicates against which disruption sources the maturity of risk management should be analysed, before proceeding to the assessment of the individual dimensions. |
| Risk management maturity assessment model | Covers the risk management maturity dimensions and a five-level maturity scale. The dimensions describe the key risk management areas, assessed using the scope determined by the risk source map. The model has an adaptive character, and the assessment carried out takes into account the weights assigned to each maturity dimension. | Constitutes the main assessment mechanism. Makes it possible to determine the level of maturity at which risk management practices in Warehouse 4.0 are situated. |
| Intralogistics service process resilience components | Covers the resilience components that should be strengthened through mature risk management. These components are not additional maturity dimensions, but interpretive categories that make it possible to assess whether risk management translates into process resilience. | Makes it possible to interpret the maturity assessment results through the lens of process resilience. By juxtaposing them with the maturity dimensions in the form of a relationship matrix, it enables the identification of areas requiring strengthening from the perspective of process resilience, providing the basis for further, in-depth analysis of resilience gaps. |
| Risk Source | Characteristics | Significance for the Risk Management Maturity Assessment |
|---|---|---|
| Digital risks | Include hazards arising from the dependence of the intralogistics service process on information systems, data, cybersecurity, connectivity, IT/OT integration, and the availability of WMS, WCS, ERP or TMS systems. They concern both the unavailability of systems and the loss of integrity, quality, timeliness or security of the data used to control the process. | Make it possible to assess whether risk management covers the vulnerabilities arising from the digitisation of the process, dependence on data, systems integration and cybersecurity. |
| Intralogistics infrastructure risks | Include hazards arising from the unavailability, failure or limited physical and technical fitness of the infrastructure supporting the intralogistics process, including automation, internal transport equipment, storage systems, sorters, conveyors, workstations, identification devices and power supply infrastructure. | Make it possible to assess whether risk management takes into account the process’s dependence on technical infrastructure, its availability, redundancy, maintenance, and the possibility of bypassing failures of critical resources. |
| Operational risks | Include hazards arising from the course and organisation of work itself at the individual stages of the intralogistics service process (receiving, storage, replenishment, picking, consolidation, packing, shipping, returns handling)—such as the variability and unpredictability of demand or order structure, a mismatch between operational capacity and load, errors in the design of flows and work sequences, and quality defects in goods received into the warehouse. These hazards materialise independently of the state of digital systems, infrastructure or human resources, and their effects on process performance (decline in throughput, failure to meet SLA, picking errors, growing backlog) are the subject of the impact assessment in dimension D3. | Make it possible to assess whether risk management takes into account hazards arising from the dynamics and design of the process itself—independently of digital, infrastructural, organisational or human sources—and whether the organisation identifies bottlenecks and alternative execution paths before they translate into a decline in the performance parameters measured in D3. |
| Organisational risks | Include hazards arising from the organisation of work, procedures, responsibility, communication, escalation, coordination between operations, IT and maintenance, testing of contingency plans, and learning after incidents. They concern the organisation’s preparedness to recognise, handle and limit the effects of disruptions. | Make it possible to assess whether risk management is embedded in the organisational structure, procedures, responsibility, communication and improvement mechanisms, rather than being limited solely to technical aspects. |
| Human risks and human–machine interaction risks | Include hazards arising from operator errors, lack of competencies, cognitive overload, incorrect interpretation of alarms, improper operation of HMI interfaces, excessive trust in automation, and limited staff capacity for manual, emergency or degraded-mode work. | Make it possible to assess whether risk management takes into account the role of the human being in the Warehouse 4.0 environment, in particular competencies, training, readiness for emergency work, and the quality of cooperation between operators and digital and automated systems. |
| Level Name | Level Characteristics |
|---|---|
| Level 1 Reactive | Risk management is ad hoc in nature and is triggered mainly after a disruption occurs. Risks, vulnerabilities and the effects of incidents are recognised primarily on the basis of employee experience and current operational problems. There is a lack of formal procedures, consistent risk assessment criteria, systematic monitoring, and linkage of actions to the resilience of the intralogistics service process. |
| Level 2 Basic | Risk management is partially documented and covers selected risks, procedures and actions to limit the effects of disruptions. The organisation has basic registers, instructions or indicators, but this approach is not yet complete, regularly updated, or fully linked to process criticality, disruption scenarios and resilience gaps. |
| Level 3 Standardised | Risk management is conducted according to adopted principles and covers the key risk classes of Warehouse 4.0. Risks are identified, classified and analysed in relation to the intralogistics service process, critical resources, business continuity parameters and disruption scenarios. Formal roles, procedures, control mechanisms, response plans and a basis for identifying resilience gaps are in place. |
| Level 4 Predictive | Risk management is supported by data, KPI/KRI monitoring, trend analysis, scenario testing, assessment of the effectiveness of control mechanisms, and early warning. The organisation is not limited to reacting to disruptions, but is able to identify symptoms of deteriorating process performance, assess residual risk, and anticipate potential resilience gaps before an incident fully escalates. |
| Level 5 Adaptive | Risk management is integrated with the continuous strengthening of the resilience of the intralogistics service process. The organisation dynamically updates its risk profile, adapting procedures, resources, competencies, technologies and control mechanisms to changing operating conditions, while developing a risk-awareness culture, the capacity for human–automation cooperation, and the dynamic prioritisation of resilience investments. The results of the maturity assessment are systematically used to reduce resilience gaps, design improvement actions, and build process resilience already at the stage of technological and organisational change. |
| Result Range | Maturity Level |
|---|---|
| 1.00–1.49 | Level 1—reactive |
| 1.50–2.49 | Level 2—basic |
| 2.50–3.49 | Level 3—standardised |
| 3.50–4.49 | Level 4—predictive |
| 4.50–5.00 | Level 5—adaptive |
| Resilience Dimension | Characteristics | Disruption Impact Phase | Example Assessment Metrics |
|---|---|---|---|
| R1. Anticipation of disruptions | The capability to identify symptoms of disruption before they lead to a significant deterioration in process performance. In Warehouse 4.0, this concerns, among others, the detection of anomalies in data, zone overload, declining system availability, deteriorating automation performance, or an increase in picking errors. | Before the disruption occurs | Anomaly detection time; number of disruptions detected before the process stops; availability of operational data; number of predictive alerts; share of critical resources covered by monitoring. |
| R2. Absorption of a disruption | The process’s capability to limit the impact of a disruption without an immediate loss of an acceptable level of service, thanks to buffers, redundancy, throughput reserves or alternative resources. | At the onset of the disruption | Minimum throughput maintained after the disruption; maximum permissible backlog; share of orders kept within SLA during the disruption; size of resource reserves; time to onset of the disruption’s impact. |
| R3. Response to a disruption | The capability to quickly initiate appropriate actions after identifying a disruption—recognising the nature of the event, escalation, task allocation, communication, and activation of contingency procedures. | During the disruption (initial phase) | Response time; escalation time; contingency procedure activation time1; number of tested scenarios; proportion of roles/teams notified in accordance with the procedure within the established time; proportion of procedure steps completed in accordance with the response checklist. |
| R4. Operation in degraded mode | The capability to continue the intralogistics service process under limited availability of systems, automation, data, personnel or infrastructure. | During the disruption (sustainment phase) | Percentage of throughput that can be maintained in degraded mode; switchover time to emergency mode1; number of processes with a documented manual workaround; share of staff trained for emergency work; error rate during degraded-mode operation. |
| R5. Adaptation of the process | The capability to reconfigure the process, resources and priorities in response to changed operating conditions—reallocating people and resources, changing the order sequence, or temporarily modifying operating rules. | During and after the disruption | Process reconfiguration time; number of available alternative execution paths; proportion of priority orders completed despite resource reallocation; reduction in cumulative performance loss. |
| R6. Recovery of operations | The capability to restore the intralogistics service process to an acceptable level of performance after a disruption, consistent with the adopted resilience thresholds (e.g., RTO, SLA, throughput, permissible backlog). | After the disruption has occurred | Process RTO; actual recovery time; backlog clearance time; SLA level after recovery; cumulative performance loss; number of corrective actions after the incident. |
| R1 Anticipation | R2 Absorption | R3 Response | R4 Degraded Mode | R5 Adaptation | R6 Recovery | |
|---|---|---|---|---|---|---|
| D1. Identification of criticality | ◐ | ● | ◐ | |||
| D2. Identification and classification of risks | ◐ | |||||
| D3. Analysis of risk impact | ◐ | ● | ||||
| D4. Vulnerability assessment and monitoring | ● | ◐ | ||||
| D5. Risk treatment and business continuity | ● | ● | ● | ◐ | ● | |
| D6. Competencies and communication | ● | ● | ||||
| D7. Review, learning and improvement | ◐* |
| Dimension | Level (Li) | Audit Finding |
|---|---|---|
| D1 | 3—Standardised | The facility’s critical resources—the mini-load stacker cranes, the conveyor network, the WMS server—have been identified and formally documented. However, the criticality assessment is not dynamically updated on the basis of current operational data or resilience test results. |
| D2 | 2—Basic | A basic risk register is maintained, covering mainly technical and infrastructural risks (stacker crane and conveyor failures). Organisational and human risks are not included in the register systematically or updated regularly. |
| D3 | 3—Standardised | The impact of disruptions on process parameters (throughput, picking time) is formally measured and analysed by the WMS system as part of the ongoing management of task queuing and resource allocation. |
| D4 | 4—Predictive | The WMS system detects symptoms of overload and potential bottlenecks before they fully escalate, including during peak periods (e.g., Black Friday). Monitoring is continuous in nature and supports early warning of disruptions. |
| D5 | 2—Basic | No documented business continuity plans or defined capacity buffers for storage aisles were found. Physical emergency access to rack slots above 20 m in height is significantly limited, which reduces the capacity to quickly implement actions to limit the effects of stacker crane failures. |
| D6 | 2—Basic | The “goods-to-person” working model limits staff’s direct contact with the physical storage environment. A low level of crew preparedness for manual or emergency work in the event of automation unavailability was found. |
| D7 | 2—Basic | No formalised incident-review process or systematic updating of procedures based on lessons learned from disruptions was found. Improvement actions, where they occur, are ad hoc in nature. |
| Dimension | Weight (wi) | Justification for Weight Assignment |
|---|---|---|
| D1 | 0.15 | The high value of the invested infrastructure (an AS/RS-class system covering 23,064 m2) justifies an above-average weight—incorrect identification of critical resources would carry a high cost. |
| D2 | 0.10 | A lower weight than the other dimensions, but above the adopted minimum threshold (0.05)—the structuring function of this dimension is important, but risk classification itself has a smaller direct impact on business continuity than the operational dimensions. |
| D3 | 0.15 | The process’s strong dependence on task queuing by the WMS means that even a minor disruption quickly translates into the throughput of the entire facility—hence the elevated weight. |
| D4 | 0.15 | The high degree of automation and dependence on the WMS system justify an above-average weight—monitoring mechanisms are a key element of risk management here. |
| D5 | 0.20 | The highest weight in the set. Limited physical emergency access to rack slots above 20 m in height means an exceptionally high exposure to the risk of being unable to limit the effects of a stacker crane failure—this is the area of greatest criticality for this particular type of facility. |
| D6 | 0.15 | The “goods-to-person” model limits staff’s natural familiarity with manual work—the elevated weight reflects the risk arising from the crew’s low readiness to take over automation tasks. |
| D7 | 0.10 | A lower weight, above the minimum threshold—the improvement mechanism is important in the long term, but does not constitute a direct source of risk exposure at the given moment of assessment. |
| Dimension | wi | Li | wi · Li |
|---|---|---|---|
| D1 | 0.15 | 3 | 0.45 |
| D2 | 0.10 | 2 | 0.20 |
| D3 | 0.15 | 3 | 0.45 |
| D4 | 0.15 | 4 | 0.60 |
| D5 | 0.20 | 2 | 0.40 |
| D6 | 0.15 | 2 | 0.30 |
| D7 | 0.10 | 2 | 0.20 |
| Mw | 2.60 |
| R1 Anticipation | R2 Absorption | R3 Response | R4 Degraded Mode | R5 Adaptation | R6 Recovery | |
|---|---|---|---|---|---|---|
| D1. Identification of criticality | 0.20 (◐) | 0.35 (●) | - | - | 0.25 (◐) | - |
| D2. Identification and classification of risks | 0.20 (◐) | - | - | - | - | - |
| D3. Analysis of risk impact | - | 0.20 (◐) | - | - | 0.50 (●) | - |
| D4. Vulnerability assessment and monitoring | 0.60 (●) | - | 0.20 (◐) | - | - | - |
| D5. Risk treatment and business continuity | - | 0.45 (●) | 0.40 (●) | 0.50 (●) | 0.25 (◐) | 0.70 (●) |
| D6. Competencies and communication | - | - | 0.40 (●) | 0.50 (●) | - | - |
| D7. Review, learning and improvement | - | - | - | - | - | 0.30 (◐) |
| Sum | 1.00 | 1.00 | 1.00 | 1.00 | 1.00 | 1.00 |
| Resilience Dimension | Calculation | Cj |
|---|---|---|
| R1 | 0.20·3 + 0.20·2 + 0.60·4 | 3.40 |
| R2 | 0.35·3 + 0.20·3 + 0.45·2 | 2.55 |
| R3 | 0.20·4 + 0.40·2 + 0.40·2 | 2.40 |
| R4 | 0.50·2 + 0.50·2 | 2.00 |
| R5 | 0.25·3 + 0.50·3 + 0.25·2 | 2.75 |
| R6 | 0.70·2 + 0.30·2 | 2.00 |
| Resilience Dimension | Cj | Descriptive Level |
|---|---|---|
| R1 | 3.40 | standardised |
| R2 | 2.55 | standardised |
| R3 | 2.40 | basic |
| R4 | 2.00 | basic |
| R5 | 2.75 | standardised |
| R6 | 2.00 | basic |
| Model | Evaluation Object | Dimension Setting | Output Form | Resilience Correlation Ability |
|---|---|---|---|---|
| RMMA-W4.0 (this article) | Warehouse 4.0 (cyber-socio-technical warehouse) | 7 risk management dimensions (D1–D7), 5 levels each | Weighted quantitative score + qualitative cross-mapping with 6 resilience dimensions | Direct, via a qualitative cross-mapping matrix onto 6 resilience dimensions (R1–R6) |
| [2] | Logistics processes (general) | 5 areas: knowledge, risk assessment, process risk management, cooperation at risk, risk monitoring | Two-stage assessment; global maturity index | None—focuses on risk management maturity, not process resilience |
| [36] | Warehouse (general performance, not risk-specific) | De Bruin 6-phase model (scope/design/populate/test/deploy/maintain) | Delphi expert panel | None—addresses operational maturity, not risk or resilience |
| [37] | Warehouse (3PL) | Operational dimensions (e.g., putaway, picking) related to efficiency | Survey; continuous and categorical variables | None—examines maturity–efficiency association, not resilience |
| [19] | Supply chain (SCRM) | 3 dimensions: Risk Management Orientation, ERM Integration, SC Risk Collaboration | Fuzzy TOPSIS classification into predefined levels | Indirect–via risk management integration, no separate resilience dimension |
| [38] | Supply chain (SCRM) | 3 main dimensions + sub-dimensions; 25-item instrument | EFA/CFA; cluster analysis (leaders/followers/laggards) | None—addresses SC risk management maturity, not process resilience |
| [39] | Tier-1 suppliers, automotive sector | Expert-panel-weighted criteria (Delphi + Likert scale) | Self-assessment questionnaire | None |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the author. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Tubis, A.A. Risk Management Maturity Assessment Method for Strengthening the Resilience of the Intralogistics Service Process in Warehouse 4.0 (RMMAM-W4.0). Appl. Sci. 2026, 16, 8954. https://doi.org/10.3390/app16188954
Tubis AA. Risk Management Maturity Assessment Method for Strengthening the Resilience of the Intralogistics Service Process in Warehouse 4.0 (RMMAM-W4.0). Applied Sciences. 2026; 16(18):8954. https://doi.org/10.3390/app16188954
Chicago/Turabian StyleTubis, Agnieszka A. 2026. "Risk Management Maturity Assessment Method for Strengthening the Resilience of the Intralogistics Service Process in Warehouse 4.0 (RMMAM-W4.0)" Applied Sciences 16, no. 18: 8954. https://doi.org/10.3390/app16188954
APA StyleTubis, A. A. (2026). Risk Management Maturity Assessment Method for Strengthening the Resilience of the Intralogistics Service Process in Warehouse 4.0 (RMMAM-W4.0). Applied Sciences, 16(18), 8954. https://doi.org/10.3390/app16188954
