A method and system for assessing a risk event

CN115829330BActive Publication Date: 2026-09-08SHANDONG HAIYUN ASPHLAT CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211635466.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-19
Publication Date
2026-09-08
Estimated Expiration
2042-12-19

AI Technical Summary

Technical Problem

[0004]一些企业采取预警系统的方式来进行风险管理,但是只能在风险事件产生(即实际情况达到阈值)之后才能够触发风险分析,虽然能达到识别风险事件的效果,但无法对该风险事件对企业的影响做出客观的评价

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115829330B_ABST
    Figure CN115829330B_ABST
Patent Text Reader

Abstract

The application discloses a risk event evaluation method and system, and the evaluation method comprises the following steps: receiving real-time data inside and outside an enterprise; determining whether a trigger condition of each type of risk event is met according to an identification period and a risk identification index of the type of risk event and the real-time data; if yes, evaluating the risk event to obtain an evaluation score and an evaluation level of the risk event; and outputting risk event information. After a risk event is identified, the application quantitatively evaluates the risk event, which is beneficial for the enterprise to know the key influence and the severity of the influence brought by the risk in advance, timely and effectively formulate a risk response measure, and effectively prevent and control the risk and improve the risk management capability of the enterprise.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of risk management, and more specifically, to a method and system for assessing risk events. Background Technology

[0002] Currently, the international situation is complex and volatile. Domestic enterprises have moved beyond economies of scale to in-depth development, and their management is becoming more refined, information-based, and digital. Applying the COSO risk management framework and ISO 31000 risk management system to manage enterprise risks and increase the likelihood of achieving business objectives has become an increasingly popular choice for enterprises. The development speed in the field of risk management has significantly increased, with enterprises launching comprehensive risk management activities as well as specialized risk management activities for various fields. Many enterprises have established comprehensive risk event databases and other risk measures.

[0003] It is worth mentioning that businesses inevitably face risks in their operations, or rather, business operations are accompanied by risks. Risks bring not only losses but also gains to businesses. What businesses need is not to completely avoid risks, but to comprehensively and deeply identify risks, conduct objective risk analysis, and perform standardized risk assessments to help business decision-makers, management, and operational staff reduce the losses caused by risks and increase the likelihood of achieving business goals.

[0004] Some companies use early warning systems for risk management, but risk analysis can only be triggered after a risk event occurs (i.e., the actual situation reaches the threshold). Although it can identify risk events, it cannot make an objective assessment of the impact of the risk event on the company. Summary of the Invention

[0005] This application provides a risk event assessment method and system. After automatically identifying a risk event, the system performs a quantitative assessment of the risk event, which helps enterprises to know in advance the key impacts and severity of the impacts, and to formulate risk response measures in a timely and effective manner, thereby effectively preventing and controlling risks and improving the enterprise's risk management capabilities.

[0006] This application provides a method for assessing risk events, including:

[0007] Receive real-time data from both internal and external sources.

[0008] Based on the identification cycle and risk identification indicators for each type of risk event, and using real-time data, determine whether the triggering conditions for that type of risk event are met.

[0009] If so, the risk event is assessed to obtain an assessment score and assessment level.

[0010] Output risk event information.

[0011] Preferably, the risk event is assessed to obtain an assessment score and assessment level, specifically including:

[0012] Risk events are assessed based on their likelihood of occurrence and their consequences.

[0013] The assessment level of a risk event is determined based on the assessment score.

[0014] Preferably, the assessment score for a risk event also includes the speed of its occurrence and its vulnerability.

[0015] Preferably, the process includes the following steps before outputting the risk event information:

[0016] Multiple risk events are sorted according to their type, assessment score, and assessment level to obtain a list of risk events.

[0017] Preferably, the process includes the following steps before outputting the risk event information:

[0018] Risk maps are created based on risk event information, and these risk maps visualize each risk event.

[0019] and,

[0020] Output a risk map.

[0021] Preferably, the risk identification indicators include overall risk monitoring indicators for the enterprise and risk monitoring indicators for multiple business lines, with each business line risk monitoring indicator corresponding to a specific business detail.

[0022] Preferably, the risk event information includes the risk event number, risk event name, risk number, risk component, risk type, risk name, risk source, risk description, responsible department, responsible person, risk warning indicator, assessment score, assessment level, risk assessment standard, and setting parameters for each risk assessment indicator.

[0023] This application also provides a risk event assessment system, including a data receiving module, a judgment module, an assessment module, and an output module;

[0024] The data receiving module is used to receive real-time data from both internal and external sources within the enterprise.

[0025] The judgment module is used to determine whether the triggering conditions of each type of risk event are met based on real-time data, according to the identification cycle and risk identification indicators of each type of risk event.

[0026] The assessment module is used to evaluate risk events and obtain assessment scores and assessment levels for each risk event.

[0027] The output module is used to output risk event information.

[0028] Preferably, the evaluation module includes a score acquisition module and a grade acquisition module;

[0029] The scoring module is used to obtain an assessment score for a risk event based on its probability of occurrence and its impact.

[0030] The rating module is used to determine the rating of a risk event based on the assessment score.

[0031] Preferably, the evaluation system further includes a sorting module and / or a map drawing module;

[0032] The sorting module is used to sort multiple risk events according to their type, assessment score, and assessment level to obtain a list of risk events;

[0033] The map drawing module is used to draw risk maps based on risk event information, and the risk maps enable the visualization of each risk event.

[0034] Other features and advantages of this application will become clear from the following detailed description of exemplary embodiments with reference to the accompanying drawings. Attached Figure Description

[0035] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments of the present application and, together with their description, serve to explain the principles of the present application.

[0036] Figure 1 A flowchart of the risk event assessment method provided for this application;

[0037] Figure 2 A structural diagram of the risk event assessment system provided for this application. Detailed Implementation

[0038] Various exemplary embodiments of the present application will now be described in detail with reference to the accompanying drawings. It should be noted that, unless otherwise specifically stated, the relative arrangement, numerical expressions, and values ​​of the components and steps set forth in these embodiments do not limit the scope of the present application.

[0039] The following description of at least one exemplary embodiment is merely illustrative and is in no way intended to limit the scope of this application and its application or use.

[0040] Techniques, methods, and equipment known to those skilled in the art may not be discussed in detail, but where appropriate, they should be considered part of the specification.

[0041] In all the examples shown and discussed herein, any specific values ​​should be interpreted as merely exemplary and not as limitations. Therefore, other examples of exemplary embodiments may have different values.

[0042] This application provides a method and system for assessing risk events. After identifying a risk event, the system performs a quantitative assessment of the event, which helps enterprises to understand the key impacts and severity of the risks in advance, and to formulate risk response measures in a timely and effective manner, thereby effectively preventing and controlling risks and improving the enterprise's risk management capabilities.

[0043] It should be noted that this application utilizes risk event models (such as artificial intelligence models) to assess risk events. Before training the risk event model, it is necessary to establish an enterprise data warehouse and, based on the enterprise data warehouse, establish risk classification standards, risk identification indicators, risk assessment standards, and risk level assessment standards.

[0044] The establishment of an enterprise data warehouse, especially in the commodity industry, involves two parts: First, operational data collected from enterprise information systems such as Customer Relationship Management (CRM), Enterprise Resource Planning (ERP), financial systems, and Office Automation (OA) systems, including but not limited to customer data, procurement and sales contract and execution data, inventory data, and production data. Second, external data, including but not limited to market supply data for raw materials and finished products, consumption data, spot price data, and futures market price and trading volume / open interest data. Data collection can be achieved through manual input, API integration, web scraping, and other technical means.

[0045] Specifically, as an example, the enterprise's internal data is obtained through API interfaces via system integration. This includes obtaining supplier and customer access data, credit limit data, payment terms and cash flow data through integration with the CRM system, obtaining purchase and sales contract data, pricing data, logistics data, payment and receipt data, invoice data, inventory data, and other data through integration with the ERP system, and obtaining production plans, production data, raw material and finished product inventory data through integration with the MES system.

[0046] External data for enterprises can be connected to the National Bureau of Statistics, futures exchanges, and other organizations via API interfaces to obtain macroeconomic data, futures market transaction, position, and price data. Alternatively, data can be connected to built-in interfaces provided by third-party data service providers to obtain industry data and spot market price data through import and export. Dynamic spot market data, such as factory capacity, output, operating rate, inventory, sales price, and transaction data, can also be obtained through manual data collection by frontline personnel.

[0047] These basic data can be collected in two ways: scheduled collection and real-time collection. Data from the enterprise's internal information system integration and futures market data can be collected in real-time, while data from the enterprise's MES production system and third-party data service providers can be collected periodically.

[0048] Risk classification standards are used to categorize risk events into a specific risk type, which helps companies to summarize and analyze risk events.

[0049] The risk indicators in this application can be divided into risk identification indicators and risk assessment indicators. Risk identification indicators are used to identify risk events, while risk assessment indicators are used to conduct risk assessments. The risk indicators can be constructed by processing data items selected from the enterprise data warehouse using built-in general functions, mathematical algorithms, SQL, and other methods within the information system, generating indicators that can be directly used for risk identification and risk assessment.

[0050] Risk identification indicators, similar to commonly used early warning indicators, are used to identify when a company's performance in a certain area reaches a threshold and triggers a warning. In risk identification, these indicators can be divided into overall corporate risk monitoring indicators and risk monitoring indicators for multiple business lines. Each business line risk monitoring indicator corresponds to a specific business detail. Overall risk monitoring indicators include annual metrics for the scale of the company's derivative business, net risk exposure, net derivative positions, total credit exposure, total sales volume, and maximum loss limit. These indicators can be further broken down according to physical or virtual organizational structures. Business line risk monitoring indicators include metrics such as accounts receivable from a single supplier or customer, payment terms, loss limits for a single hedging scheme, and contract execution delivery dates, payment terms, and invoice dates. Each business line risk monitoring indicator monitors the risk of each individual transaction.

[0051] Risk assessment indicators are metrics used to evaluate the degree of risk of a risk event that has already occurred. For a detailed explanation, please see the section on risk assessment standards.

[0052] Risk assessment standards include both quantitative and qualitative criteria. Qualitative criteria leverage the experience gained in production and operational practices, while quantitative indicators facilitate the summarization of experience and their efficient, timely, and accurate application through information systems. For risk assessment indicators, the parameters involved are described in a tiered manner, and the descriptions of each parameter and its various levels can be user-defined. Risk assessment indicators include indicators of the probability of a risk event occurring and indicators of its impact and consequences, preferably including the speed of occurrence and vulnerability of the risk event.

[0053] The Illustrative Impact Scale (I-Scale) is a standard used to assess the impact of a risk event. It includes actual profit or loss, and the expected amount of loss. Table 1 shows an example.

[0054] Table 1

[0055]

[0056] Table 1 uses the degree of loss as an example for illustration. The degree of loss is an assessment standard used to evaluate the impact of a risk event. This dimension of risk is divided into 5 levels, with a higher value indicating a higher risk level. When the impact of a risk event reaches 100% (the threshold), it is rated as level 5, representing an extreme risk description. For example, if a company's annual risk budget is 5 million yuan, and the company's cumulative loss for the year reaches 5 million yuan, it is rated as an extreme level 5 risk according to the I standard, indicating that the impact of the risk is significant and unbearable for the company.

[0057] Enterprises can choose the degree of loss or the degree of exceeding the scale limit as the I standard.

[0058] The Illustrative Likelihood Scale (L-scale) is a standard used to assess the likelihood of a risk event occurring. It includes metrics such as probability, likelihood, frequency of occurrence per year, and frequency of occurrence over several years. Table 2 provides an example.

[0059] Table 2

[0060]

[0061]

[0062] Table 2 uses annual frequency as an example. Annual frequency is an assessment standard used to evaluate the likelihood of a risk event occurring. This dimension has five risk levels, with higher values ​​indicating higher risk. A risk event occurring once every two years is rated level 5, representing an extreme probability. For example, regarding the indicator of a major safety accident for a company, if a company experiences a major safety accident within two years, it is rated as an extreme level 5 risk according to the L standard, indicating an extremely high probability of such a major safety accident, which the company cannot afford.

[0063] Companies can choose the probability or annual frequency in Table 2 as the L standard.

[0064] The Illustrative Vulnerability Scale (V-Scale) is a standard used to assess vulnerability to risk events. It includes factors such as the existence of contingency plans and the company's leverage percentage. Table 3 provides an example.

[0065] Table 3

[0066]

[0067]

[0068] Table 3 uses market vulnerability as an example for illustration. The market vulnerability standard is an assessment standard used to evaluate the vulnerability of risk events. This dimension of risk is divided into 5 levels, with higher values ​​indicating higher risk levels. When the leverage ratio is greater than 5, it is rated as level 5, which is an extreme level of risk. For example, using the leverage of a company's copper risk component as a vulnerability indicator, if the leverage ratio of the company's copper futures and spot business is greater than 5, it is rated as an extreme level 5 risk on the V standard dimension, indicating that this type of transaction has extremely high vulnerability when the risk occurs, and the company cannot withstand it.

[0069] Companies can choose market vulnerability or risk contingency plans and response capabilities from Table 3 as V criteria.

[0070] The illusory speed scale (S-scale) is a standard used to assess the speed at which risk events occur. It includes the number of days it takes for a 10% price fluctuation to occur, the number of days it takes for a loss to materialize, and so on. Table 4 provides an example.

[0071] Table 4

[0072]

[0073]

[0074] Table 4 uses the speed of market risk occurrence as an example. The speed of market risk occurrence is an assessment standard used to evaluate the rate at which risk events occur. This dimension has five risk levels, with higher values ​​indicating higher risk. When the market risk index for a risk event is less than 5 days, it means that the market is experiencing significant fluctuations in the short term, and is rated as level 5, representing an extreme speed of occurrence. For example, if the number of days used to measure a 10% market fluctuation in the copper market is used as the speed of occurrence indicator, and the current copper market price fluctuates by more than 10% within 5 days, it is rated as an extreme level 5 risk according to the S standard, indicating that such events occur extremely quickly and are difficult for the company to withstand.

[0075] Companies can choose the speed at which market risks occur or the speed at which events occur as the S standard.

[0076] Enterprises can choose risk assessment indicators based on their own circumstances. From the perspective of simplifying risk management, the I and L standards can be adopted. For commodity enterprises, it is better to use four indicators because they are greatly affected by commodity prices, exchange rates, and interest rates, which leads to market risks having a significant impact on the company's operations. Increased market risks will also lead to increased credit risks, operational risks, and liquidity risks. Therefore, the S and V standards are particularly important for commodity enterprises.

[0077] Risk level assessment criteria: Risk assessment scores R = I*L or I*L*V*S are obtained through risk assessment indicators. Different assessment levels correspond to different ranges of risk assessment scores. The description of each assessment level helps users understand the principles behind risk level setting and scoring criteria. Table 5 provides an example.

[0078] Table 5

[0079]

[0080] The basic assessment score R = I standard score * L standard score can be widely used for risk scoring of various types of enterprise risks. As enterprises develop and their businesses expand, especially in the commodity industry where they are greatly affected by fluctuations in market prices, exchange rates, and interest rates at the raw material, finished product, procurement, and sales ends, these fluctuations are crucial to enterprise profitability. Market risk mainly involves price and position holdings, so it is necessary to add dimensions to the risk assessment for analysis. The V standard is the assessment standard for enterprise vulnerability, and the S standard is the assessment standard for the speed of occurrence. Expanding from market risk to credit risk, operational risk, liquidity risk, etc., the V and S standards can also be widely used to assess the risk level of risk events.

[0081] Therefore, the risk level assessment standard can be divided into: Risk Score R = I*L*V*S or I*L, with 5 risk levels, where a larger value represents a higher risk level. In the example in Table 5, the assessment score is obtained by multiplying the scores of the four dimensions, i.e., Assessment Score R = I standard score * L standard score * V standard score * S standard score. When R is greater than 256, it represents a level 5 major risk level; greater than 100 and less than or equal to 256 is a level 4 important risk level; greater than 70 and less than or equal to 100 is a level 3 general risk level; greater than 30 and less than or equal to 70 is a level 2 lower risk level; and less than or equal to 30 is a level 1 extremely low risk level.

[0082] For example: In a risk assessment of market risk due to net risk exposure, a company's risk budget is 100 million yuan, and the current potential loss is over 80 million yuan. Therefore, the I standard - impact consequences rating is 4. An event where the annual loss exceeds the risk budget has already occurred within the past two years, and the company is facing this risk again. Therefore, the L standard - probability of occurrence rating is 5. Regarding the company's use of funds in futures and spot markets, market price fluctuations of 3% result in a 1.5% fluctuation in the company's profit and loss. Therefore, the V standard - vulnerability rating is 3. Recently, spot and futures market prices have fluctuated significantly, with consecutive limit-up and limit-down situations. The price fluctuation range in the last 5 days is greater than 12%. Therefore, the S standard - speed of occurrence rating is 5. The risk score R = 4 * 5 * 3 * 5 = 300, the risk score R is greater than 256, the risk rating is 5, a major risk event. This event should be given special attention and serious consideration in the risk response.

[0083] Risk event models can be maintained qualitatively and evaluated quantitatively. Qualitative maintenance is used for manual maintenance of risk events. Quantitative evaluation automatically triggers risk events based on the risk event identification conditions in the risk event model. That is, when the triggering conditions are met, a risk event is automatically generated, and scores for each risk assessment indicator are obtained according to the risk assessment criteria, resulting in an assessment score and assessment level for the risk event. Risk event models primarily achieve risk event monitoring through quantitative evaluation. Table 6 provides examples of risk event parameters within the risk event model.

[0084] Table 6

[0085]

[0086] As shown in Table 6, the risk event model needs to establish relevant information about risk events, such as risk event description (including risk number, risk component, risk type, risk name, risk source, and risk description), responsible department (i.e., the department that owns the risk), responsible person (i.e., the risk owner), risk warning indicators, risk assessment standards, and setting parameters for risk assessment indicators of each dimension.

[0087] For example, in the risk event model regarding the total exposure market risk of aluminum, the risk number is MP001; the risk type is market risk; the risk source is increased aluminum price volatility; the risk description is the risk that the total exposure of aluminum will suffer significant losses due to large fluctuations in market prices exceeding the limit; the risk-owning department is the strategy department; the risk owner is Zhou Wei; the model is quantitative; the risk identification cycle is daily at 15:05; the risk identification warning indicator is the total exposure loss limit indicator; the I standard is the loss degree standard; the L standard is the probability standard; the V standard is the market vulnerability standard; and the S standard is the market risk occurrence speed standard.

[0088] Based on the above explanation, as Figure 1 As shown, the risk event assessment method provided in this application includes:

[0089] S110: Receives real-time data from both internal and external sources.

[0090] S120: Based on the identification cycle and risk identification indicators for each type of risk event, determine whether the triggering conditions for that type of risk event are met according to real-time data. If yes, proceed to S130; otherwise, return to S110.

[0091] The risk event model calls the identification cycle and risk identification indicators for each type of risk event to calculate the real-time data obtained, and automatically identifies the risk event when the threshold (i.e. the trigger condition) is reached.

[0092] S130: Assess risk events and obtain assessment scores and assessment levels for the risk events.

[0093] Once a risk event occurs, the risk assessment criteria and indicators set in the risk event model are followed up to obtain scores for two indicators, probability of occurrence (L) and impact consequences (I), or four indicators, probability of occurrence (L), impact consequences (I), occurrence speed (S), and vulnerability (V). Finally, the risk assessment score R of the risk event and the assessment level corresponding to the risk assessment score are determined.

[0094] S140: Output risk event information.

[0095] Once a risk event occurs and the risk assessment is completed, the risk event information will be promptly transmitted to the department and person in charge of the risk event to facilitate timely response to the risk event.

[0096] Preferably, before outputting the risk event information, the process further includes sorting multiple risk events according to their type, assessment score, and assessment level to obtain a risk event list and / or drawing a risk map based on the risk event information, whereby the risk map visualizes each risk event. The sorted risk event information and / or risk map are then output in step S140.

[0097] When a company generates multiple risk events, it creates a risk event list. These risk events can be ranked by risk type, risk event assessment, and assessment level, and a risk map can be created.

[0098] Table 7 provides an example of a risk event list obtained by sorting multiple risk events with risk number MP001.

[0099] Table 7

[0100]

[0101] Table 7 lists the information for each risk event, including the risk event number, risk event name, risk number, risk component, risk type, risk name, risk source, risk description, responsible department, responsible person, risk warning indicator, assessment score, assessment level, risk assessment standard, and setting parameters for each risk assessment indicator.

[0102] Based on the above description, this application also provides a risk event assessment system, which is applied to a risk event model. For example... Figure 2 As shown, the evaluation system includes a data receiving module 210, a judgment module 220, an evaluation module 230, and an output module 240.

[0103] The data receiving module 210 is used to receive real-time data from both inside and outside the enterprise.

[0104] The judgment module 220 is used to determine whether the triggering conditions of a risk event of that type are met based on real-time data, according to the identification cycle and risk identification indicators of each type of risk event.

[0105] The assessment module 230 is used to assess risk events and obtain assessment scores and assessment levels for the risk events.

[0106] Output module 240 is used to output risk event information.

[0107] Preferably, the evaluation module 230 includes a score acquisition module 2301 and a grade acquisition module 2302.

[0108] The score acquisition module 2301 is used to obtain an assessment score for a risk event based on the probability of its occurrence and its impact.

[0109] The rating acquisition module 2302 is used to determine the rating of a risk event based on the assessment score.

[0110] Preferably, the evaluation system further includes a sorting module 250 and / or a map drawing module 260.

[0111] The sorting module 250 is used to sort multiple risk events according to their type, assessment score, and assessment level to obtain a list of risk events.

[0112] The map drawing module 260 is used to draw risk maps based on risk event information, and the risk maps enable the visualization of each risk event.

[0113] This application can help enterprises establish a sound risk management system, enhance their risk management capabilities by relying on information technology and digitalization, improve the effectiveness and efficiency of enterprise operations, establish a reliable foundation for decision-making and planning, and ultimately increase the likelihood of the organization achieving its goals.

[0114] While specific embodiments of this application have been described in detail by way of examples, those skilled in the art should understand that the above examples are for illustrative purposes only and are not intended to limit the scope of this application. Those skilled in the art should understand that modifications can be made to the above embodiments without departing from the scope and spirit of this application. The scope of this application is defined by the appended claims.

Claims

1. A method for assessing risk events, characterized in that, include: Receive real-time data from both internal and external sources. Based on the identification cycle and risk identification indicators for each type of risk event, the real-time data is used to determine whether the triggering conditions for that type of risk event are met. If so, the risk event is assessed to obtain an assessment score and assessment level for the risk event; wherein, the assessment score is based on the probability of occurrence, the consequences of occurrence, the speed of occurrence, and the vulnerability of the risk event, and the assessment score is the product of the scores for the probability of occurrence, the consequences of occurrence, the speed of occurrence, and the vulnerability; wherein, the vulnerability index and the speed of occurrence index are designed for commodity enterprises. A risk map is drawn based on risk event information, and the risk map visualizes each risk event; Output risk event information and the aforementioned risk map.

2. The risk event assessment method according to claim 1, characterized in that, Before outputting risk event information, the following is also included: Multiple risk events are sorted according to their type, assessment score, and assessment level to obtain a list of risk events.

3. The risk event assessment method according to claim 1, characterized in that, The risk identification indicators include overall risk monitoring indicators for the enterprise and risk monitoring indicators for multiple business lines, with each business line risk monitoring indicator corresponding to a specific business detail.

4. The risk event assessment method according to claim 1, characterized in that, The risk event information includes risk event number, risk event name, risk number, risk component, risk type, risk name, risk source, risk description, responsible department, responsible person, risk warning indicator, assessment score, assessment level, risk assessment standard, and setting parameters for each risk assessment indicator.

5. A risk event assessment system, characterized in that, It includes a data receiving module, a judgment module, an evaluation module, a map drawing module, and an output module; The data receiving module is used to receive real-time data from both inside and outside the enterprise. The judgment module is used to determine whether the triggering conditions of the risk event of that type are met based on the real-time data, according to the identification cycle and risk identification indicators of each type of risk event. The assessment module is used to assess risk events and obtain assessment scores and assessment levels for the risk events. The assessment scores are based on the probability of occurrence, impact consequences, occurrence speed, and vulnerability of the risk event. The assessment score is the product of the scores for probability of occurrence, impact consequences, occurrence speed, and vulnerability. The vulnerability index and occurrence speed index are designed for commodity enterprises. The map drawing module is used to draw a risk map based on risk event information, and the risk map enables the visualization of each risk event; The output module is used to output risk event information and the risk map.

6. The risk event assessment system according to claim 5, characterized in that, It also includes a sorting module; The sorting module is used to sort multiple risk events according to their type, assessment score, and assessment level to obtain a list of risk events.

Citation Information

Patent Citations

  • Enterprise comprehensive risk management system and method based on COSO internal control framework

    CN110135724A