A compliance risk management system and method for investment advisory services based on operational behavior chains
By forming a continuous operational behavior chain and combining it with a risk identification model and blockchain evidence storage, the problems of missing data collection and delayed risk warning in the securities investment advisory compliance system have been solved, enabling precise risk control and efficient auditing of investment advisory staff behavior.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZHEJIANG BEICAI ZHISHEN NETWORK TECH CO LTD
- Filing Date
- 2026-04-27
- Publication Date
- 2026-05-26
AI Technical Summary
Existing securities investment advisory compliance systems suffer from deficiencies or unreliability in the collection of operational behavior data, resulting in delayed risk warnings and a disconnect between operational behavior and business data, making it difficult to achieve end-to-end risk control.
The operation behavior collection module forms a continuous time-series chain of operation behaviors. Combined with the risk warning module and the correlation tracing module, the blockchain notarization module ensures that the data is tamper-proof. The machine learning algorithm is used to train the securities investment advisory compliance risk identification model to identify single behavior risks and verify their correlation, and generate a risk tracing report.
It enables accurate identification of risks associated with individual and combined behaviors of securities investment advisors, shortens early warning response time, improves investigation efficiency, enhances data credibility, and establishes a closed-loop risk tracing chain.
Smart Images

Figure CN122089476A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of risk identification technology, and in particular to an investment advisory compliance risk management system and method based on operational behavior chains. Background Technology
[0002] In the securities investment advisory industry, compliance risks arising from securities investment advisor employees (such as circumventing regulations by deleting records, data leaks due to non-compliant terminal operations, and unauthorized product recommendations after logging in from different locations) require end-to-end control. Currently, the industry's compliance systems generally suffer from the following core issues: Operational behavior data collection is incomplete or unreliable. Existing systems only focus on business data (such as communication records and order information), ignoring employee operational behavior data (such as login terminal information, data deletion / modification operations, and operation sequence), making it difficult to detect early warning signs of risks such as "frequent record deletion" and "non-compliant terminal login"; moreover, operational behavior records are mostly stored in centralized systems, which are at risk of being tampered with or deleted.
[0003] Risk warnings are delayed. Problems are typically only traced after violations have occurred (such as customer complaints or regulatory inspections), making it difficult to identify risks in advance based on operational behavior. This is considered "post-event remediation" rather than "pre-event warning."
[0004] Operational actions are disconnected from business operations. This means that operational data and business data are stored separately, making it difficult to clarify the relationship between "abnormal operation → business impact → risk consequences" during audits, resulting in a broken tracing chain.
[0005] Currently, no effective solution has been proposed for improving the risk management of investment advisory compliance in securities trading using relevant technologies. Summary of the Invention
[0006] This application provides an investment advisory compliance risk management system and method based on operational behavior chains, which at least addresses the problem of how to improve the risk management effectiveness of investment advisory compliance in securities trading in related technologies.
[0007] In a first aspect, embodiments of this application provide an investment advisory compliance risk management system based on operational behavior chains, the risk management system including an operational behavior collection module, a risk warning module, and a correlation tracing module; The operation behavior acquisition module is used to collect operation behavior data of securities investment advisors and form a continuous, uninterrupted operation behavior chain based on the operation behavior data. The risk warning module is used to identify the individual behavioral risks of the securities investment advisor based on the operational behavior chain and through a trained securities investment advisor compliance risk identification model, and to verify the correlation between the individual behavioral risks through time series analysis to obtain the combined behavioral risks of the securities investment advisor. The associated traceability module is used to acquire associated business data related to the operational behavior chain, and integrate the operational behavior chain, the associated business data and the risk identification results to generate a risk traceability report for the securities investment advisor employee.
[0008] In some embodiments, the operation behavior collection module is used to collect operation behavior data of securities investment advisors on employee operation terminals, wherein the operation behavior data includes login behavior data, data operation behavior data, and business operation behavior data; The operation behavior collection module is used to connect the scattered operation behavior data received on the compliance system server according to the employee ID and operation behavior timestamp to form a continuous and uninterrupted chain of operation behaviors of the securities investment advisor employee.
[0009] In some embodiments, the association tracing module is used to obtain corresponding associated business data from the business system server using the unique identifier of the operation behavior chain as an index; The associated tracing module is used to integrate the operational behavior chain, the associated business data, and the risk identification results on the compliance system server according to the continuous time sequence of the operational behavior chain, and generate a risk tracing report for the securities investment advisor employee.
[0010] In some embodiments, the risk management system includes a blockchain evidence storage module; The blockchain evidence storage module is used to package the risk tracing report generated on the compliance system server, the operational behavior chain, and the risk identification result into an evidence storage data package. The blockchain evidence storage module is used to package the received evidence storage data packet, employee ID, evidence storage timestamp and blockchain node signature into a blockchain data block on the blockchain node server, and synchronize it to all blockchain nodes to complete distributed storage.
[0011] In some embodiments, the risk management system includes a risk feature library construction module; The risk feature database construction module is used to build a securities industry-specific risk feature database in the compliance system server. The risk feature database includes single-behavioral risk, combined-behavioral risk, and risk warning threshold. The single-behavioral risk corresponds to one type of operational behavioral risk feature of a securities investment advisor, and the combined-behavioral risk corresponds to at least two types of operational behavioral risk features of securities investment advisors.
[0012] In some embodiments, the risk warning module includes a risk determination submodule and a closed-loop execution warning submodule; The risk assessment submodule is used in the compliance system server to take the operation behavior chain and the securities industry-specific risk feature library as model inputs, identify the single behavior risk of the securities investment advisor employee through the trained securities investment advisor compliance risk identification model, and verify the correlation between the single behavior risks through time series analysis to obtain the combined behavior risk of the securities investment advisor employee. The risk assessment submodule is used to obtain the compliance risk warning level of the securities investment advisor employee in the compliance system server based on the single behavior risk, the combined behavior risk, and the risk warning threshold in the risk feature library.
[0013] In some embodiments, the closed-loop execution early warning submodule is used in the compliance system server to trigger the execution of corresponding risk warning notifications and operation permission controls based on the compliance risk warning level of the securities investment advisor employee, and automatically generate risk warning execution logs.
[0014] In some embodiments, the closed-loop execution early warning submodule is used in the compliance system server to trigger the execution of corresponding risk warning notifications and operation permission controls based on the compliance risk warning level of the securities investment advisor employee. If the compliance risk warning for the securities investment advisor is a Level 2 warning, a risk warning notification will be sent to the securities investment advisor's direct supervisor to restrict the securities investment advisor's data operation permissions. If the compliance risk warning for the securities investment advisor is at Level 1, a risk warning notification will be sent to the securities investment advisor's direct supervisor and the investment advisor compliance department, and the securities investment advisor's high-risk operation privileges will be immediately revoked.
[0015] In some embodiments, the risk management system further includes a model building module; Using labeled historical data on violations in the securities industry, a securities investment advisory compliance risk identification model based on machine learning algorithms is trained to obtain a trained securities investment advisory compliance risk identification model. The machine learning algorithm includes the random forest algorithm.
[0016] Secondly, embodiments of this application provide a method for managing compliance risks of investment advisors based on operational behavior chains. The method is executed based on the system described in the first aspect above, and the method includes: Collect operational behavior data of securities investment advisors and form a continuous, uninterrupted chain of operational behaviors based on the operational behavior data; Based on the operational behavior chain, the individual behavioral risks of the securities investment advisors are identified through a trained securities investment advisor compliance risk identification model. The correlation between the individual behavioral risks is verified through time series analysis to obtain the combined behavioral risks of the securities investment advisors. Obtain the associated business data related to the operational behavior chain, and integrate the operational behavior chain, the associated business data, and the risk identification results to generate a risk tracing report for the securities investment advisor employee.
[0017] Compared to related technologies, this application provides a compliance risk management system and method for investment advisors based on operational behavior chains. The system includes: an operational behavior collection module for collecting operational behavior data of securities investment advisors and forming a continuous, uninterrupted operational behavior chain based on the data; a risk warning module for identifying individual operational risks of securities investment advisors based on the operational behavior chain using a trained securities investment advisor compliance risk identification model, and verifying the correlation between individual operational risks through time-series analysis to obtain the combined operational risks of securities investment advisors; and a correlation tracing module for acquiring related business data associated with the operational behavior chain, integrating the operational behavior chain, related business data, and risk identification results to generate a risk tracing report for securities investment advisors. This system achieves a time-series chaining of data related to the login, data operations, and business operations of securities investment advisors, effectively identifying not only individual operational risks but also combined operational risks. Furthermore, the closed-loop tracing link of operational behavior, business data, and risks effectively improves subsequent audit efficiency and solves the problem of how to improve the risk management effect of investment advisor compliance in securities trading. Attached Figure Description
[0018] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings: Figure 1 This is a structural block diagram of an investment advisory compliance risk management system based on an operational behavior chain, according to an embodiment of this application. Figure 2 This is a schematic diagram of the internal structure of an electronic device according to an embodiment of this application. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of this application clearer, the application is described and illustrated below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application. All other embodiments obtained by those skilled in the art based on the embodiments provided in this application without inventive effort are within the scope of protection of this application.
[0020] Obviously, the accompanying drawings described below are merely some examples or embodiments of this application. Those skilled in the art can apply this application to other similar scenarios based on these drawings without any inventive effort. Furthermore, it is understood that although the efforts made in this development process may be complex and lengthy, for those skilled in the art related to the content disclosed in this application, any changes to design, manufacturing, or production based on the technical content disclosed in this application are merely conventional technical means and should not be construed as insufficient disclosure of the content of this application.
[0021] In this application, the reference to "embodiment" means that a specific feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment that is mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described in this application may be combined with other embodiments without conflict.
[0022] Unless otherwise defined, the technical or scientific terms used in this application shall have the ordinary meaning understood by one of ordinary skill in the art to which this application pertains. The terms “a,” “an,” “an,” “the,” and similar words used in this application do not indicate quantity limitation and may indicate singular or plural. The terms “comprising,” “including,” “having,” and any variations thereof used in this application are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or device that includes a series of steps or modules (units) is not limited to the listed steps or units, but may also include steps or units not listed, or may include other steps or units inherent to these processes, methods, products, or devices. The terms “connected,” “linked,” “coupled,” and similar words used in this application are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. “Multiple” used in this application refers to two or more. “And / or” describes the relationship between related objects, indicating that three relationships may exist; for example, “A and / or B” can represent: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following objects are in an "or" relationship. The terms "first," "second," and "third" used in this application are merely to distinguish similar objects and do not represent a specific ordering of the objects.
[0023] This application provides an investment advisory compliance risk management system based on operational behavior chains. Figure 1This is a structural block diagram of an investment advisory compliance risk management system based on an operational behavior chain, according to an embodiment of this application. Figure 1 As shown, the risk management system includes an operational behavior collection module, a risk warning module, and a correlation tracing module. The operation of the risk management system requires the use of four types of hardware devices: employee operation terminals (such as computers and mobile phones), compliance system servers (securities investment advisory compliance departments), blockchain node servers (institutional nodes and regulatory nodes), and business system servers. The operation behavior collection module is used to collect operation behavior data of securities investment advisors and form a continuous, uninterrupted chain of operation behaviors based on the operation behavior data. Specifically, the operation behavior collection module is used to collect operation behavior data of securities investment advisors on employee operation terminals. The operation behavior data includes login behavior data, data operation behavior data, and business operation behavior data. It should be noted that the data collection dimensions for the operational behavior data of securities investment advisors should be configured, and the three types of operational data to be collected should be clearly defined: login behavior data (such as terminal IP, geographical location, device fingerprint, login time, login status, etc.), data operation behavior data (such as the type, time, and operation object of deleted / modified / exported records, etc.), and business operation behavior data (such as recommended product name, file type sent, communication initiator, operation duration, etc.).
[0024] Specifically, the operation behavior collection module is used to connect the scattered operation behavior data received on the compliance system server according to the employee ID and operation behavior timestamp to form a continuous and uninterrupted chain of operation behaviors of securities investment advisors.
[0025] It should be noted that the collection and generation of operational behavior chains require the combined operation of employee terminals and the compliance system server. First, operational behavior data is collected in real time through employee terminals (computers via a client, mobile phones via an app): upon login, device fingerprints (such as MAC address and device model), IP addresses, and geographic locations (via IP location interface) are automatically obtained; when performing data operations (such as deleting chat history) or business operations (such as recommending funds), the operation type, timestamp, and operation object ID (such as customer ID and record ID) are recorded simultaneously. Second, the compliance system server receives the scattered operational data uploaded by the terminals and strings them together according to "employee ID + timestamp" to form an uninterrupted operational behavior chain (e.g., "Employee A - 09:00 (compliance terminal login) - 09:15 (export customer B communication records) - 09:20 (delete customer B's original communication records) - 09:30 (recommend high-risk product C)"). A unique identifier (such as employee ID + date + random code) is generated for each behavior chain.
[0026] The risk management system also includes a risk feature database construction module; The risk feature library construction module is used to build a securities industry-specific risk feature library in the compliance system server. The risk feature library includes single behavior risk, portfolio behavior risk and risk warning threshold. Single behavior risk corresponds to one type of operational behavior risk feature of a securities investment advisor, and portfolio behavior risk corresponds to at least two types of operational behavior risk features of securities investment advisors.
[0027] It should be noted that building the risk feature database needs to be executed on the compliance system server. The securities industry-specific risk feature database includes single-behavior risks (such as "deleting ≥5 chat records in a single day", "login from non-compliant terminals (unregistered devices)") and combined-behavior risks (such as "login from a different location (geographical difference from the commonly used IP address ≥500 kilometers) + sending high-risk product information within 1 hour", "deleting original records immediately after data export"), and configures corresponding risk warning thresholds (such as a level-one warning triggered by combined-behavior risks, and a level-two warning triggered by 3 cumulative instances of single-behavior risks).
[0028] The risk warning module is used to identify the individual behavioral risks of securities investment advisors based on the operational behavior chain and through a trained securities investment advisor compliance risk identification model. It also verifies the correlation between individual behavioral risks through time series analysis to obtain the combined behavioral risks of securities investment advisors. Specifically, the risk warning module includes a risk assessment submodule and a closed-loop execution warning submodule; The risk assessment submodule is used in the compliance system server to take the operational behavior chain and the securities industry-specific risk feature library as model inputs. Through the trained securities investment advisor compliance risk identification model, it identifies the individual behavioral risks of securities investment advisors and verifies the correlation between individual behavioral risks through time series analysis to obtain the combined behavioral risks of securities investment advisors. Based on the individual behavioral risks, combined behavioral risks and risk warning thresholds in the risk feature library, it obtains the compliance risk warning level of securities investment advisors.
[0029] It's important to explain the specific workflow of the risk assessment submodule. First, the model's input data includes: real-time operational behavior chains and a securities industry-specific risk feature database. Second, the model's assessment logic differs from general credit scoring models, employing a two-dimensional approach of "feature matching + temporal correlation." This means first matching single-behavioral risks using risk features, then verifying the correlation between behaviors through temporal analysis to determine if combined behavioral risks exist (e.g., whether "login from a different location" and "high-risk recommendation" occurred consecutively within one hour). Third, the model's output includes: risk warning level (Level 1 / Level 2 / No Risk) and risk details (e.g., triggered risk features, behavioral chain fragments, and related business predictions).
[0030] The closed-loop execution early warning submodule is used in the compliance system server to trigger corresponding risk warning notifications and operation permission controls based on the compliance risk warning level of securities investment advisors, and automatically generate risk warning execution logs. The triggering of corresponding risk warning notifications and operation permission controls includes: If a securities investment advisor's compliance risk warning is at level two, a risk warning notification will be sent to the securities investment advisor's direct supervisor to restrict the securities investment advisor's data operation permissions. If a securities investment advisor's compliance risk warning is at Level 1, a risk warning notification will be sent to the securities investment advisor's direct supervisor and the investment advisor compliance department, immediately granting the securities investment advisor's high-risk operation privileges.
[0031] It's important to explain the specific workflow of the closed-loop execution early warning submodule. First, risk warning notification: Level 2 warnings are sent to the employee's immediate supervisor; Level 1 warnings, after being sent to the supervisor, are simultaneously sent to the compliance department. The notification includes the employee's ID, details of the risky behavior, a screenshot of the behavior chain, and a preliminary assessment of related business activities (e.g., "suspected cover-up of illegal recommendations"). Second, operation permission control: When a Level 1 warning is triggered, the employee's high-risk operation permissions (e.g., product recommendations, data export) are immediately frozen, requiring approval from the compliance department before being unfrozen. Level 2 warnings only restrict permissions (e.g., data export requires supervisor approval), without freezing basic operations, achieving a closed loop of "early warning equals control." Third, log generation: Early warning execution logs are automatically generated, including the notification recipient, control permission type, execution time, and operator (automatically marked by the system).
[0032] The correlation and traceability module is used to obtain related business data associated with the operational behavior chain, and integrate the operational behavior chain, related business data and risk identification results to generate a risk traceability report for securities investment advisors.
[0033] Specifically, the association tracing module is used to retrieve the corresponding associated business data from the business system server using the unique identifier of the operation behavior chain as an index; The correlation and tracing module is used to integrate the operational behavior chain, related business data and risk identification results in a continuous time sequence on the compliance system server to generate a risk tracing report for securities investment advisors.
[0034] It's important to note that the correlation and tracing between operational behavior data and business data requires execution on both the compliance system server and the business system server. First, using the unique identifier of the operational behavior chain as an index, the system connects to the business system server to retrieve related business data (e.g., for the "recommended product" operation, retrieve customer purchase order records and customer risk assessment levels; for the "delete communication records" operation, retrieve the backup communication content before deletion and the corresponding customer's subsequent complaint records). Second, the "operational behavior chain + related business data" are integrated along a timeline to generate a risk tracing report, clearly defining the "operational motivation (e.g., deleting records to cover up illegal recommendations) - business process (e.g., recommending products that do not match the risk level) - potential risks (e.g., customer financial loss risk)." In this way, auditors can retrieve the tracing report with a single click by entering the employee ID, warning time, or risk behavior type through the compliance system, and can view operational behavior recordings (synchronously collected by the terminal screen recording component) and original business data vouchers.
[0035] In some embodiments, the risk management system also includes a blockchain evidence storage module; The blockchain evidence storage module is used to package risk tracing reports generated on the compliance system server, along with operational behavior chains and risk identification results, into an evidence storage data package. The blockchain evidence storage module is used to package the received evidence storage data packet, employee ID, evidence storage timestamp, and blockchain node signature into a blockchain data block on the blockchain node server, and synchronize it to all blockchain nodes to complete distributed storage.
[0036] It should be noted that blockchain data notarization needs to be performed on both the compliance system server and the blockchain node server. First, the compliance system server packages the operation behavior chain data (including unique identifier, behavior details, and timestamp), risk assessment results, early warning execution logs, and traceability report summaries into a notarization data package, and then uses the SHA-256 algorithm to generate a data digest. Secondly, the blockchain node server (including institutional nodes and regulatory nodes) receives the evidence storage data packet, packages it with the employee ID, evidence storage timestamp, and node signature into a blockchain data block, and synchronizes it to all nodes to complete distributed storage; and generates evidence storage certificate (including block height and hash value), which supports regulatory agencies or inspectors to query and verify the integrity of the data through the hash value, ensuring that the operation behavior record cannot be tampered with.
[0037] For example, if employee F logs into the system using an unregistered mobile phone (non-compliant terminal), deletes three communication records with client G within one hour, and recommends high-risk stocks, the system, through its securities industry-specific risk assessment logic, identifies the combined risk of "non-compliant terminal login + short-term deletion of records + high-risk recommendation," triggering a Level 1 warning. Employee F's product recommendation privileges are immediately frozen, and their direct supervisor and compliance department are simultaneously notified. The compliance department, through the tracing module, discovers that the deleted communication records contain the phrase "guaranteed returns," and client G has already submitted a purchase order. Based on this, a violation investigation is initiated. The evidenced behavioral data and warning execution logs serve as the basis for the judgment, a process distinct from general assessments and simple notification models.
[0038] The risk management system provided by the above embodiments of this application achieves the following technical effects: 1. More precise risk assessment: The securities industry-specific risk feature library and customized model can accurately identify scenario-based risk combinations such as "login from a different location + high-risk recommendation", with a false judgment rate of less than 5%, solving the problem that general assessments cannot meet the compliance requirements of the securities industry; 2. Implement a closed-loop early warning system: The integrated "notification + access control" model ensures that the response time for a Level 1 early warning is ≤10 seconds and high-risk permissions can be frozen immediately, preventing the risk from escalating due to "notification without control" and reducing uncontrolled violations by more than 80%. 3. Full coverage of operational behaviors: For the first time, it achieves full-dimensional collection of login, data operation, and business operation, forming an uninterrupted behavior chain and solving the problem of "missed operation data collection" in the existing system; 4. Closed-loop traceability: Operational behavior is deeply linked to business data, which can clearly define the complete chain of "abnormal operation → business impact → risk consequences", improving audit efficiency by 70% (previously, it required manual integration of data from multiple systems, but now traceability reports can be generated with one click). 5. Enhanced data credibility and authority: Operational behavior data is stored on the blockchain for verification by regulatory agencies, significantly increasing the difficulty of tampering.
[0039] In some embodiments, the risk management system also includes a model building module; Using labeled historical data on violations in the securities industry, a compliance risk identification model for securities investment advisors based on machine learning algorithms (such as random forest algorithm) is trained to obtain a trained compliance risk identification model for securities investment advisors.
[0040] It should be noted that training customized machine learning models for the securities industry (such as the random forest algorithm) requires inputting historical operational behavior data from the securities industry (with "normal / abnormal" labels), rather than general credit data. The model's ability to identify scenario-based risks in real-time operational behavior chains must be trained, and the model's accuracy must reach over 95%.
[0041] It should be further noted that the above modules can be functional modules or program modules, and can be implemented through software or hardware. For modules implemented through hardware, the above modules can reside in the same processor; or the above modules can be located in different processors in any combination.
[0042] This application provides a method for managing compliance risks of investment advisory services based on an operational behavior chain. The method is executed based on the system provided in the above embodiment and includes the following steps: Collect operational behavior data from securities investment advisors and form a continuous, uninterrupted chain of operational behaviors based on the data. Based on the operational behavior chain, the individual behavioral risks of securities investment advisors are identified through a trained securities investment advisor compliance risk identification model. The correlation between individual behavioral risks is verified through time series analysis to obtain the combined behavioral risks of securities investment advisors. Acquire related business data associated with the operational behavior chain, and integrate the operational behavior chain, related business data, and risk identification results to generate a risk tracing report for securities investment advisors.
[0043] It should be noted that the steps shown in the above process or in the flowchart of the accompanying figures can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases the steps shown or described may be executed in a different order than that shown here.
[0044] This embodiment provides an electronic device including a memory and a processor. The memory stores a computer program, and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.
[0045] Optionally, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor and the input / output device is connected to the processor.
[0046] Optionally, the electronic device may further include a processor, memory, network interface, display screen, and input device connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with external terminals via a network connection. When the computer program is executed by the processor, it implements a compliance risk management method for investment advisory services based on an operational behavior chain. The display screen may be an LCD screen or an e-ink screen. The input device may be a touch layer covering the display screen, buttons, a trackball, or a touchpad mounted on the device's casing, or an external keyboard, touchpad, or mouse.
[0047] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementations, and will not be repeated here.
[0048] Furthermore, in conjunction with the investment advisory compliance risk management method based on operational behavior chains in the above embodiments, this application embodiment can provide a storage medium for implementation. This storage medium stores a computer program; when executed by a processor, the computer program implements any of the investment advisory compliance risk management methods based on operational behavior chains in the above embodiments.
[0049] In one embodiment, Figure 2 This is a schematic diagram of the internal structure of an electronic device according to an embodiment of this application, such as... Figure 2 As shown, an electronic device is provided, which can be a server, and its internal structure diagram can be as follows. Figure 2 As shown, the electronic device includes a processor, a network interface, internal memory, and non-volatile memory connected via an internal bus. The non-volatile memory stores the operating system, computer programs, and a database. The processor provides computing and control capabilities, the network interface communicates with external terminals via a network, the internal memory provides the environment for the operating system and computer programs to run, the computer programs are executed by the processor to implement a compliance risk management method for investment advisors based on an operational behavior chain, and the database stores data.
[0050] Those skilled in the art will understand that Figure 2 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the electronic device to which the present application is applied. A specific electronic device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0051] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0052] Those skilled in the art should understand that the technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments have been described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0053] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.
Claims
1. A compliance risk management system for investment advisors based on operational behavior chains, characterized in that, The risk management system includes an operational behavior collection module, a risk early warning module, and a correlation tracing module; The operation behavior acquisition module is used to collect operation behavior data of securities investment advisors and form a continuous, uninterrupted operation behavior chain based on the operation behavior data. The risk warning module is used to identify the individual behavioral risks of the securities investment advisor based on the operational behavior chain and through a trained securities investment advisor compliance risk identification model, and to verify the correlation between the individual behavioral risks through time series analysis to obtain the combined behavioral risks of the securities investment advisor. The associated traceability module is used to acquire associated business data related to the operational behavior chain, and integrate the operational behavior chain, the associated business data and the risk identification results to generate a risk traceability report for the securities investment advisor employee.
2. The risk management system according to claim 1, characterized in that, The operation behavior collection module is used to collect operation behavior data of securities investment advisors on employee operation terminals, wherein the operation behavior data includes login behavior data, data operation behavior data, and business operation behavior data. The operation behavior collection module is used to connect the scattered operation behavior data received on the compliance system server according to the employee ID and operation behavior timestamp to form a continuous and uninterrupted chain of operation behaviors of the securities investment advisor employee.
3. The risk management system according to claim 1, characterized in that, The association tracing module is used to retrieve the corresponding associated business data from the business system server using the unique identifier of the operation behavior chain as an index. The associated tracing module is used to integrate the operational behavior chain, the associated business data, and the risk identification results on the compliance system server according to the continuous time sequence of the operational behavior chain, and generate a risk tracing report for the securities investment advisor employee.
4. The risk management system according to claim 3, characterized in that, The risk management system includes a blockchain evidence storage module; The blockchain evidence storage module is used to package the risk tracing report generated on the compliance system server, the operational behavior chain, and the risk identification result into an evidence storage data package. The blockchain evidence storage module is used to package the received evidence storage data packet, employee ID, evidence storage timestamp and blockchain node signature into a blockchain data block on the blockchain node server, and synchronize it to all blockchain nodes to complete distributed storage.
5. The risk management system according to claim 1, characterized in that, The risk management system includes a risk feature database construction module; The risk feature database construction module is used to build a securities industry-specific risk feature database in the compliance system server. The risk feature database includes single-behavioral risk, combined-behavioral risk, and risk warning threshold. The single-behavioral risk corresponds to one type of operational behavioral risk feature of a securities investment advisor, and the combined-behavioral risk corresponds to at least two types of operational behavioral risk features of securities investment advisors.
6. The risk management system according to claim 5, characterized in that, The risk warning module includes a risk assessment submodule and a closed-loop execution warning submodule; The risk assessment submodule is used in the compliance system server to take the operation behavior chain and the securities industry-specific risk feature library as model inputs, identify the single behavior risk of the securities investment advisor employee through the trained securities investment advisor compliance risk identification model, and verify the correlation between the single behavior risks through time series analysis to obtain the combined behavior risk of the securities investment advisor employee. The risk assessment submodule is used to obtain the compliance risk warning level of the securities investment advisor employee in the compliance system server based on the single behavior risk, the combined behavior risk, and the risk warning threshold in the risk feature library.
7. The risk management system according to claim 6, characterized in that, The closed-loop execution early warning submodule is used in the compliance system server to trigger the execution of corresponding risk warning notifications and operation permission controls based on the compliance risk warning level of the securities investment advisor employee, and automatically generate risk warning execution logs.
8. The risk management system according to claim 7, characterized in that, The closed-loop execution early warning submodule is used in the compliance system server to trigger the corresponding risk warning notification and operation permission control based on the compliance risk warning level of the securities investment advisor employee. If the compliance risk warning for the securities investment advisor is a Level 2 warning, a risk warning notification will be sent to the securities investment advisor's direct supervisor to restrict the securities investment advisor's data operation permissions. If the compliance risk warning for the securities investment advisor is at Level 1, a risk warning notification will be sent to the securities investment advisor's direct supervisor and the investment advisor compliance department, and the securities investment advisor's high-risk operation privileges will be immediately revoked.
9. The risk management system according to claim 1, characterized in that, The risk management system also includes a model building module; Using labeled historical data on violations in the securities industry, a securities investment advisory compliance risk identification model based on machine learning algorithms is trained to obtain a trained securities investment advisory compliance risk identification model. The machine learning algorithm includes the random forest algorithm.
10. A method for managing compliance risks in investment advisory services based on operational behavior chains, characterized in that, The method is performed based on the system according to any one of claims 1 to 9, and the method includes: Collect operational behavior data of securities investment advisors and form a continuous, uninterrupted chain of operational behaviors based on the operational behavior data; Based on the operational behavior chain, the individual behavioral risks of the securities investment advisors are identified through a trained securities investment advisor compliance risk identification model. The correlation between the individual behavioral risks is verified through time series analysis to obtain the combined behavioral risks of the securities investment advisors. Obtain the associated business data related to the operational behavior chain, and integrate the operational behavior chain, the associated business data, and the risk identification results to generate a risk tracing report for the securities investment advisor employee.
Citation Information
Patent Citations
Full-life-cycle auditing and tracking system and method
CN120374071A
Multi-dimensional space-time evidence chain analysis platform and method for sales data abnormal behavior recognition
CN120374175A
Enterprise employee behavior analysis and safety risk early warning monitoring method and system
CN120598342A
Banking business post authority management method, device, equipment and medium
CN121167710A