Standardize risk assessment system
The normative risk assessment system addresses compliance challenges by using a web crawler and language processing model to analyze semantic matching between internal and external regulations, ensuring timely compliance with evolving legal requirements.
Patent Information
- Application Number
- TW115200854
- Authority / Receiving Office
- TW · TW
- Patent Type
- Utility models
- Current Assignee / Owner
- Filing Date
- 2026-01-26
- Publication Date
- 2026-07-11
- Estimated Expiration
- 2036-01-25
AI Technical Summary
Financial institutions face challenges in ensuring compliance with constantly changing external regulations due to the dynamic nature of legal requirements, necessitating a system to assess and enforce internal norms effectively.
A normative risk assessment system that includes a storage unit and processing unit, utilizing a web crawler to fetch the latest external specifications, compare them with internal data, and analyze semantic matching using a language processing model to generate a risk analysis result, indicating the level of compliance.
The system ensures timely compliance by identifying and addressing potential violations proactively, thereby reducing the risk of non-compliance with updated regulations.
Smart Images

Figure IMG-2_DRAW_115200854-A0305-14-0001-1 
Figure IMG-2_DRAW_115200854-A0305-14-0002-2 
Figure IMG-2_DRAW_04_A0101_DRAWINGS_1
Abstract
Description
Standardize risk assessment system Technical Field
[0001] This invention relates to an assessment system, specifically a normative risk assessment system suitable for assessing whether there is a risk of non-compliance with an enterprise's internal norms. Prior Technology
[0002] As financial markets and regulatory systems continue to evolve, financial institutions must ensure that their internal operating procedures, management systems, and risk control measures comply with all regulations (including domestic and international laws, administrative rules, and other guidelines) issued by competent authorities. However, external regulations are not static but are frequently updated due to policy changes, industry developments, or risk events. When external regulations change, financial institutions must re-examine whether their existing internal regulations comply with the updated legal requirements.
[0003] Therefore, how to effectively enforce compliance with laws and regulations in the face of constantly changing external norms has become a crucial issue that urgently needs to be addressed. Summary of the Invention
[0004] Therefore, the purpose of this new invention is to provide a normative risk assessment system that helps ensure compliance with laws and regulations.
[0005] This novel specification risk assessment system includes a storage unit and a processing unit electrically connected to the storage unit. The storage unit stores a web crawler program, an external specification database, and an internal specification database. The external specification database contains multiple external specification documents, and the internal specification database contains multiple internal specification documents. The processing unit is configured to: run the web crawler program to perform a crawling process, wherein the crawling process includes: crawling a pre-defined target website to obtain a crawling result corresponding to the target website and containing the latest external specification data; selecting, based on the crawling result, a matching external specification data from the external specification data corresponding to the latest external specification data; comparing the latest external specification data with the matching external specification data to generate a specification comparison result, wherein the specification comparison result indicates the textual differences between the latest external specification data and the matching external specification data; selecting, from the internal specification data, at least one related internal specification data that has a semantic relationship with the latest external specification data; and using a language processing model, analyzing the semantic matching degree between the related internal specification data and the latest external specification data based on the specification comparison result and the related internal specification data, and generating and outputting a specification risk analysis result indicating a violation risk level, wherein the violation risk level is negatively correlated with the semantic matching degree between the related internal specification data and the latest external specification data.
[0006] In some implementations of this novel standardized risk assessment system, the crawling process includes crawling the target website according to a preset upper limit for request frequency and an upper limit for download speed.
[0007] In some implementations of this novel regulatory risk assessment system, the system is applicable in conjunction with a target server providing the target website. The crawling process further includes: when multiple crawling requests are sent to the target server and multiple error responses are received from the target server, the interval between the last transmission of the crawling request and the next transmission of the crawling request is progressively increased.
[0008] In some implementations of this novel regulatory risk assessment system, the system is designed to be used in conjunction with a management terminal. The processing unit is further configured to: determine whether the violation risk level indicated by the regulatory risk analysis result is greater than or equal to a preset notification risk threshold; and if the determination is yes, generate and transmit a regulatory risk notification related to the relevant internal regulatory documents and the latest external regulatory documents to the management terminal based on the regulatory risk analysis result.
[0009] In some implementations of this novel normative risk assessment system, the storage unit also stores a semantic vector knowledge base suitable for use in conjunction with retrieval enhancement generation technology. The processing unit is further configured to: segment the normative comparison result into multiple text segmentation results; perform word embedding on each text segmentation result to generate a word embedding result that indicates the semantics of the text segmentation result using a vector; and add these word embedding results to the semantic vector knowledge base.
[0010] The advantages of this novel system are as follows: This regulatory risk assessment system can obtain the latest external regulatory information from the target website through crawling. After generating a regulatory comparison result based on the latest and matching external regulatory information, it uses a language processing model to analyze the semantic matching degree between the relevant internal regulatory information and the latest external regulatory information based on the comparison result. This generates and outputs a regulatory risk analysis result indicating the level of violation risk. Therefore, this regulatory risk assessment system can effectively perform compliance procedures to avoid violation risks when external regulations change. Simple Explanation of the Diagram
[0011] Other features and benefits of this invention will be clearly presented in the embodiments with reference to the drawings.
[0012] Figure 1 is a block diagram illustrating an embodiment of the novel normative risk assessment system, as well as a target server and a management user terminal suitable for use in conjunction with this embodiment.
[0013] Figure 2 is a flowchart illustrating, by way of example, how a standard risk assessment method is implemented in this embodiment. Implementation
[0014] Before this invention is described in detail, it should be noted that the term "electrically connected" in this patent specification is used to describe the coupled relationship between hardware (such as electronic systems, devices, apparatuses, units, modules, and components). Unless otherwise defined, "electrically connected" generally refers to "wired electrical connections" that are physically connected to each other through conductor / semiconductor materials, and "radio connections" that achieve wireless data transmission using wireless communication technologies (such as, but not limited to, wireless networks, Bluetooth, electromagnetic induction, etc.). On the other hand, unless otherwise defined, "electrically connected" also generally refers to "direct electrical connections" that are directly coupled to each other, and "indirect electrical connections" that are indirectly coupled to each other through other hardware.
[0015] Before this invention is described in detail, it should be noted that the term "unit" in this patent specification refers to hardware, not software. For example, "processing unit" refers to hardware with data processing capabilities. Furthermore, the term "unit" in this patent specification can refer to a single piece of hardware with a specific function, or it can refer to a group of hardware with similar functions. For example, "processing unit" can refer to a single processor with data processing capabilities, but it can also refer to a collection of processors.
[0016] Referring to Figure 1, one embodiment of this novel regulatory risk assessment system 1 belongs to a financial institution (e.g., a bank), and is suitable for assessing whether the financial institution's internal regulations are "insufficient to comply with external regulations." The internal regulations are, for example, the financial institution's own internal operating rules, and the external regulations are, but are not limited to, domestic or foreign laws, administrative rules, implementing regulations, and other guidelines.
[0017] The risk assessment system 1 is applicable in conjunction with a target server 2 that provides a target website 20 and a management terminal 3 belonging to the financial institution.
[0018] The target server 2 is, for example, a financial regulatory authority, whether domestic or foreign. The target website 20 is, for example, the official website of the financial regulatory authority, and will publish the latest external regulations (such as revised legal provisions) from time to time.
[0019] The management terminal 3 is, for example, a laptop or desktop computer, used by personnel working at the financial institution for operation.
[0020] In a similar implementation, the standard risk assessment system 1 can also be used in conjunction with multiple target servers 2 and management terminals 3. However, for ease of description, this embodiment will only use the target server 2 and the management terminal 3 in Figure 1 for illustration.
[0021] In this embodiment, the specification risk assessment system 1 is a server device, and the specification risk assessment system 1 includes a processing unit 11 that is electrically connected to the target server 2 and the management user terminal 3 via a network, and a storage unit 12 that is electrically connected to the processing unit 11.
[0022] In this embodiment, the processing unit 11 is a processor implemented with integrated circuitry and possessing data processing and instruction transmission / reception functions. However, in different embodiments, the processing unit 11 may also be a circuit assembly including a processor and a circuit board, or a collection of multiple processors. The storage unit 12 is a data storage device for storing digital data, such as a conventional hard disk or a solid-state drive. However, in different embodiments, the storage unit 12 may also be other types of data storage devices (e.g., memory cards, USB flash drives), or a collection of multiple data storage devices of the same or different types.
[0023] The actual implementation of the specification risk assessment system 1 in terms of computer hardware is not limited to this embodiment. For example, in other embodiments, the specification risk assessment system 1 may also be implemented as multiple server devices electrically connected to each other. In this case, the processing unit 11 may be implemented as a collection of multiple processors / circuit components respectively possessed by the server devices, and the storage unit 12 may be implemented as a collection of multiple storage devices respectively possessed by the server devices.
[0024] In this embodiment, the storage unit 12 stores a web crawler program P, an external specification database DB1, an internal specification database DB2, a semantic vector knowledge base DB3, and a language processing model M.
[0025] The web crawler program P is a software program that can be loaded and run by the processing unit 11, and includes, for example, a request frequency setting parameter and a download speed setting parameter.
[0026] The request frequency setting parameter defines an upper limit for the request frequency (e.g., once every five seconds). This upper limit represents the highest frequency at which the processing unit 11 sends multiple crawling requests to the website's server (e.g., the target website 20) during the crawling process using the web crawler program P. Specifically, these crawling requests may include, for example, an initial request to establish a crawling entry point, a content request to obtain the data to be crawled, a pagination request to obtain the next batch of crawled data, a link tracking request to expand the crawling scope, a status establishment request to establish access permissions, and a verification request to pass a security mechanism. It should be understood that the aforementioned crawling requests are techniques well known to those skilled in the art to which this invention pertains, and therefore their details are not elaborated here.
[0027] The download speed setting parameter is used to define a download speed limit, which represents the highest download speed (e.g., 200KB / s) that the processing unit 11 can receive from the website's server during the process of crawling the website through the web crawler program P.
[0028] The external specification database DB1 contains multiple external specification documents D1. Each external specification document D1, for example, indicates an external specification issued by the financial regulatory authority and includes, for example, a version identification information. In this embodiment, the version identification information is a last update time, indicating the date the external specification was published or implemented. However, in other embodiments, the version identification information may also be a version number, and is not limited to this embodiment.
[0029] The internal regulations database DB2 contains multiple internal regulations D2, each of which indicates, for example, an internal regulation established by the financial institution (such as, but not limited to, operational rules for money laundering prevention and combating financial terrorism).
[0030] The semantic vector knowledge base DB3 stores multiple canonical vector data D3, making it suitable for use in conjunction with Retrieval-Augmented Generation (RAG) technology. In this embodiment, these canonical vector data D3 correspond to the internal canonical data D2 in the internal canonical database DB2. More specifically, each canonical vector data D3 is implemented as a multidimensional vector with numerical features, and each canonical vector data D3 is the result of vectorizing its corresponding internal canonical data D2, indicating the semantics expressed by the corresponding internal canonical data D2.
[0031] The language processing model M is a pre-trained large language model (LLM) used for natural language understanding, reasoning, and decision-making based on input data, thereby performing natural language generation. The natural language processing model M can be implemented using, for example, GPT, LLaMA, or other existing models, but is not limited thereto. Additionally, in other embodiments, the language processing model M may be stored on an external server (not shown) suitable for electrical connection to the processing unit 11 via a network, and does not necessarily have to be stored in the storage unit 12 of the specification risk assessment system 1.
[0032] Referring to Figures 1 and 2, the following example illustrates how the normative risk assessment system 1 implements a normative risk assessment method.
[0033] First, in step S1, when the current time reaches a predetermined crawling time point of the day (e.g., but not limited to 3:00 AM), the processing unit 11 runs the web crawler program P to perform a crawling process. The crawling process includes: crawling the preset target website 20 to obtain a crawling result corresponding to the target website 20 and containing the latest external specification information.
[0034] Specifically, in this embodiment, the crawling process further includes crawling the target website 20 according to the preset request frequency limit and download speed limit. Thus, this embodiment not only avoids sending excessively frequent crawling requests to the target server 2 by using the request frequency limit, but also avoids excessively consuming the network bandwidth of the target server 2 by using the download speed limit, thereby adhering to the principle of courteous crawling.
[0035] In some embodiments, during the crawling process, the processing unit 11 first obtains crawling rule data (e.g., a robot.txt file) corresponding to the target website 20 from the target server 2, and then sets the request frequency setting parameter and the download speed setting parameter of the web crawler program P in real time according to the suggested request frequency and suggested transmission speed contained in the crawling rule data, and then crawls the target website 20 accordingly.
[0036] On the other hand, in a preferred embodiment of this crawling process, after the processing unit 11 sends a crawling request (e.g., one of the aforementioned crawling requests) to the target server 2, if the processing unit 11 receives an error response from the target server 2 corresponding to the crawling request (e.g., one of HTTP error status codes such as 403 / 404 / 405), the processing unit 11 resends the crawling request to the target server 2 at the end of a first interval. Then, if the processing unit 11 receives the error response from the target server 2 again after resending the crawling request, the processing unit 11 resends the crawling request to the target server 2 at the end of a second interval that is longer than the first interval, and so on. In other words, in a preferred embodiment, when the processing unit 11 receives the error response data from the target server 2 multiple times due to repeatedly sending the crawling request to the target server 2, the processing unit 11 gradually increases the interval between "the last time the crawling request was sent to the target server 2" and "the next time the crawling request was sent to the target server 2" to avoid sending useless crawling requests to the target server 2 too frequently.
[0037] On the other hand, in a preferred embodiment of this crawling process, when the processing unit 11 determines through the web crawler program P that the target website 20 contains reference specification data (e.g., a PDF file) for recording external specifications, the processing unit 11 also determines whether the reference specification data meets a qualified crawling condition, and only when it is determined to be yes, does the reference specification data become the latest external specification data and include it in the crawling result.
[0038] Specifically, the processing unit 11 determines whether the reference specification data meets the eligibility criteria for crawling by, for example, using the data name (e.g., file name) of the reference specification data. It then selects one piece of external specification data D1 from the external specification data D1 in the external specification database DB1 that substantially indicates the same external specification as the reference specification data, and compares the last update time of this piece of external specification data D1 with the publication time corresponding to the reference specification data (e.g., when it is presented on the target website 20). If the publication time corresponding to the reference specification data is later than the last update time of this piece of external specification data D1, it indicates that the external specification indicated by this piece of external specification data D1 is no longer the latest version and must be updated according to the reference specification data. In this case, the processing unit 11 determines that the reference specification data meets the eligibility criteria for crawling. Conversely, if the publication time of the reference specification data is not later than the last update time of one of the external specification data D1, it means that the external specification indicated by one of the external specification data D1 is still the latest version and does not need to be updated. In this case, the processing unit 11 determines that the reference specification data does not meet the eligibility crawling conditions. Therefore, this embodiment can avoid downloading duplicate data from the target server 2, thereby avoiding unnecessary consumption of the target server 2's traffic resources.
[0039] In step S2, the processing unit 11, based on the crawling result, selects a matching external specification document D1' from the external specification documents D1 in the external specification database DB1 that corresponds to the latest external specification document. In this embodiment, the processing unit 11 may, for example, compare the file name of the latest external specification document with the file name of the external specification documents D1 to select the matching external specification document D1' from the external specification documents D1, but is not limited thereto.
[0040] In step S3, the processing unit 11 performs a textual comparison between the latest external specification data and the matching external specification data D1' to generate a specification comparison result. The latest external specification data corresponds to the new version of the external specification published by the target website 20, while the matching external specification data D1' corresponds to the old version of the external specification database DB1 that needs to be updated. Furthermore, the processing unit 11 updates the external specification database DB1 based on the latest external specification data, so that the latest external specification data replaces the matching external specification data D1' in the external specification database DB1, becoming a new external specification data D1 in the external specification database DB1.
[0041] The specification comparison result indicates the textual differences between the latest external specification and the matching external specification D1'. More specifically, in this embodiment, the processing unit 11 first identifies one or more chapter titles (which may be in text or Arabic numerals) of each of the latest external specification and the matching external specification D1', and then compares the textual differences between the latest external specification and the matching external specification D1' on a chapter-by-chapter basis. Further, the specification comparison result may be implemented as a Word document and include a specification comparison table. The specification comparison table includes, for example, an old version specification field presenting the matching external specification D1', and a new version specification field arranged to the right of the old version specification field and presenting the latest external specification. The old version of the specification field may use strikethrough and a first font color (e.g., red) to display text in the matching external specification data D1' that has been deleted or replaced compared to the latest external specification data. The new version of the specification field may use underline and a second font color (e.g., green) to display text in the latest external specification data that has been added compared to the matching external specification data D1', but this is not a limitation.
[0042] In step S4, the processing unit 11 generates a comparison description result corresponding to the standard comparison result using the language processing model M based on the standard comparison result, and outputs the comparison description result.
[0043] More specifically, in this embodiment, the processing unit 11 inputs the specification comparison result and an analysis prompt into the language processing model M, so that the language processing model M can infer based on the specification comparison result according to the analysis prompt, thereby outputting the comparison explanation result. The analysis prompt is used to instruct the language processing model M to provide an explanation of the differences between the latest external specification data (equivalent to the new version of the external specification) and the matching external specification data D1' (equivalent to the old version of the external specification) based on the specification comparison result. For example, the analysis prompt could be something like "Translate the new and old regulations into Traditional Chinese and briefly describe the key adjustments of the new regulations compared to the old regulations." The comparison explanation result could be something like "The new version raises the applicable age threshold from 16 to 18 years old and adds the requirement for parental consent and age verification records to be kept for 5 years. The main changes are: (1) Minimum applicable age from 16 to 18 years old. (2) Those under 18 years old must obtain written consent from their legal guardian. (3) Age verification process and records must be kept for at least 5 years." However, this is not a limitation.
[0044] The comparison result is equivalent to a comparison report of the old and new standards, which is easy for relevant personnel to read. Furthermore, the processing unit 11 outputs the comparison result in the following ways: for example, by providing the comparison result to the storage unit 12 for storage, controlling a display (not shown) to display the comparison result, or by transmitting the comparison result to the management terminal 3.
[0045] In step S5, the processing unit 11 selects one or more related internal standard documents D2' from the internal standard documents D2 in the internal standard database DB2 that have a semantic relationship with the latest external standard document. Specifically, in this embodiment, the processing unit 11 inputs the latest external standard document and an internal standard retrieval prompt into the language processing model M, and uses retrieval enhancement generation technology to select related internal standard documents D2' that have a semantic relationship with the latest external standard document from the internal standard database DB2 through the language processing model M. The internal standard retrieval prompt may be, for example, "The following are external regulations; please help me find relevant internal regulations from the internal regulations knowledge base of the Namin branch in Malaysia," but is not limited to this.
[0046] It should be noted that this embodiment assumes that the processing unit 11 selects only a single related internal specification document D2' from the internal specification database DB2. However, in actual implementation, if the latest external specification document has semantic association with multiple internal specification documents D2 in the internal specification database DB2, the processing unit 11 may also select multiple related internal specification documents D2' in step S5.
[0047] In step S6, the processing unit 11 utilizes the language processing model M to analyze the semantic matching degree between the associated internal normative data D2' and the latest external normative data based on the normative comparison result and the associated internal normative data D2', and generates and outputs a normative risk analysis result indicating a violation risk level. The violation risk level is negatively correlated with the semantic matching degree between the associated internal normative data D2' and the latest external normative data; that is, the higher the semantic matching degree, the lower the violation risk level. Furthermore, in this embodiment, the violation risk level may indicate, for example, a low-risk level, a medium-risk level, or a high-risk level.
[0048] Specifically, in this embodiment, the processing unit 11 inputs the specification comparison result, the associated internal specification data D2', and a preset risk assessment prompt into the language processing model M, so that the language processing model M infers based on the risk assessment prompt, the specification comparison result, and the associated internal specification data D2', and outputs the specification risk analysis result.
[0049] The risk assessment prompt instructs the language processing model M to check whether the semantics of the associated internal normative document D2' can be fully and completely covered by the semantics of the latest external normative document, avoiding a situation where "the associated internal normative document D2' is not violated, but the latest external normative document is violated." It is worth noting that because the normative comparison result clearly indicates the textual differences between the latest external normative document and the matching external normative document D1', this comparison result helps the language processing model M focus on the differences between the latest external normative document and the matching external normative document D1' to make inferences, thereby accurately assessing whether the associated internal normative document D2' has the risk of violating the latest external normative document. In other words, compared to directly inputting the latest external normative document into the language processing model M, this embodiment uses the normative comparison result as the basis for inference, which helps the language processing model M to more accurately analyze the violation risk of the associated internal normative document D2'.
[0050] For example, suppose the latest external specification indicates that "verification records must be kept for more than 5 years." If the related internal specification D2' indicates that "verification records must be kept for more than 3 years," which is more lenient than the latest external specification, then it falls under the category of "not being covered by the latest external specification and not matching its semantics." However, if the related internal specification D2' indicates that "verification records must be kept for more than 7 years," which is more stringent than the latest external specification, then it falls under the category of "being covered by the latest external specification and matching its semantics." In one embodiment, the risk assessment prompt may be, for example, "Determine whether the bank's internal regulations are sufficient to cover the new external regulations and classify them as low, medium, or high risk based on urgency," but it is not limited to this.
[0051] It should be noted that, in some embodiments, steps S5 and S6 can be combined into a single step. More specifically, the internal regulation retrieval prompt and the risk assessment prompt can be combined into a single prompt, thereby instructing the language processing model M to select the relevant internal regulation document D2' from the internal regulation database DB2, and subsequently generate the regulation risk analysis result.
[0052] In step S7, the processing unit 11 determines whether the violation risk level indicated by the regulatory risk analysis result is greater than or equal to a preset notification risk threshold (e.g., the medium risk level). If the determination result is yes, the processing unit 11 generates a regulatory risk notification based on the regulatory risk analysis result and sends the regulatory risk notification to the management terminal 3. The regulatory risk notification indicates that the semantics of the associated internal regulatory document D2' is not fully covered by the semantics of the latest external regulatory document. Therefore, this embodiment can proactively alert relevant personnel to the potential risk that the associated internal regulatory document D2' fails to comply with the latest external regulatory document.
[0053] In step S8, the processing unit 11 performs chunking on the specification comparison result to generate multiple text chunk results, and performs word embedding on each text chunk result to generate a word embedding result that indicates the semantics of the text chunk result with a vector. The word embedding results are added to the semantic vector knowledge base DB3 so that the language processing model M can search the semantic vector knowledge base DB3 based on the user's question using retrieval enhancement generation technology, and generate a natural language response based on the word embedding results when the question content is related to the specification comparison result.
[0054] It is worth mentioning that, in this embodiment, the processing unit 11 divides the standardization comparison result into blocks based on specific symbols (such as periods, newline characters, and other symbols indicating the end of sentences) in the standardization comparison result. In this way, this embodiment can ensure the semantic integrity of each text block result, thereby preventing important sentences in the standardization comparison result from being cut out, which would cause the word embedding result to fail to fully indicate the semantics of the original sentence.
[0055] The above is an example of how the standard risk assessment system 1 in this embodiment implements the standard risk assessment method.
[0056] It should be noted that steps S1 to S8 and the flowchart in Figure 2 of this embodiment are merely illustrative of one possible implementation of the novel regulatory risk assessment method. It should be understood that even if steps S1 to S8 are combined, split, or rearranged in order, if the resulting process performs the same function in the same manner as this embodiment and yields the same result, it still falls under the category of an implementable form of the novel regulatory risk assessment method. Therefore, steps S1 to S8 and the flowchart in Figure 2 of this embodiment are not intended to limit the scope of implementation of this invention.
[0057] In summary, by implementing this regulatory risk assessment method, the regulatory risk assessment system 1 can obtain the latest external regulatory information from the target website 20 through the crawling process. After generating the regulatory comparison result based on the latest external regulatory information and the matching external regulatory information D1', the language processing model M analyzes the semantic matching degree between the related internal regulatory information D2' and the latest external regulatory information based on the regulatory comparison result, thereby generating and outputting the regulatory risk analysis result indicating the level of violation risk. Therefore, the regulatory risk assessment system 1 can effectively perform compliance procedures to avoid violation risks when external regulations change, thus effectively achieving the purpose of this novel system.
[0058] However, the above description is merely an embodiment of this invention and should not be construed as limiting the scope of implementation of this invention. Any simple equivalent changes and modifications made in accordance with the scope of the patent application and the contents of the patent specification shall still fall within the scope of this invention.
[0059] 1: Standardize the risk assessment system 11: Processing Unit 12: Storage Unit 2: Target server 20: Target Website 3: Management and User Terminal P: Web crawler program DB1: External Standards Database DB2: Internal Standards Database DB3: Semantic Vector Knowledge Base M: Language Processing Model D1: External Specifications D1': Match external specification data D2: Internal Standards Documents D2': Related internal specification documents D3: Standardized Vector Data S1~S8: Steps
Claims
1. A regulatory risk assessment system, comprising: a storage unit storing a web crawler program, an external regulatory database, and an internal regulatory database, the external regulatory database containing multiple external regulatory documents, and the internal regulatory database containing multiple internal regulatory documents; and a processing unit electrically connected to the storage unit, and configured to: run the web crawler program to perform a crawling process, wherein... The crawling process includes: crawling a pre-defined target website to obtain crawling results corresponding to the target website and containing the latest external standard data; selecting a matching external standard data from the external standard data that corresponds to the latest external standard data based on the crawling results; comparing the latest external standard data with the matching external standard data to generate a standard comparison result, wherein the standard comparison result indicates the textual differences between the latest external standard data and the matching external standard data; selecting at least one related internal standard data that has a semantic relationship with the latest external standard data from the internal standard data; and using a language processing model, analyzing the semantic matching degree between the related internal standard data and the latest external standard data based on the standard comparison result and the related internal standard data, and generating and outputting a standard risk analysis result indicating a violation risk level, wherein the violation risk level is negatively correlated with the semantic matching degree between the related internal standard data and the latest external standard data.
2. The standardized risk assessment system as described in claim 1, wherein, The crawling process involves crawling the target website based on a preset request frequency limit and a download speed limit.
3. The standardized risk assessment system as described in Request 1 is suitable for use in conjunction with a target server providing the target website; wherein, The crawling process also includes: when multiple crawling requests are sent to the target server and an error response is received from the target server multiple times, gradually increasing the interval between the last transmission of the crawling request and the next transmission of the crawling request.
4. The standardized risk assessment system as described in Request 1 is suitable for use in conjunction with a management terminal; wherein, The processing unit is also used to: determine whether the violation risk level indicated by the standard risk analysis result is greater than or equal to a preset notification risk threshold, and when the determination result is yes, generate and transmit a standard risk notification related to the associated internal standard information and the latest external standard information to the management terminal based on the standard risk analysis result.
5. A standardized risk assessment system as described in claim 1, wherein, The storage unit also stores a semantic vector knowledge base suitable for use with retrieval enhancement generation technology. The processing unit is also used to: divide the canonical comparison result into blocks to generate multiple text block results, perform word embedding on each text block result to generate a word embedding result that indicates the semantics of the text block result with a vector, and add such word embedding results to the semantic vector knowledge base.