Regulatory method, device, and equipment for data compliance risk and storage medium
By storing business parameters and risk identification algorithms in regulatory devices, data compliance risks are acquired and analyzed, and risk events are generated and processed. This solves the problems of low efficiency in data compliance risk assessment and insufficient centralized management, and achieves efficient centralized management.
Patent Information
- Application Number
- CN202510167972.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-12-26
- Estimated Expiration
- 2045-02-17
AI Technical Summary
Existing technologies have low efficiency in assessing data compliance risks and poor centralized management, making it impossible to centrally manage data compliance risks across different business scenarios.
By storing business parameters and risk identification algorithms of the business to be regulated in the regulatory equipment, the system obtains the data to be analyzed from each regulatory agency, uses the risk identification algorithm to conduct compliance risk analysis, generates risk events and sends them to the target regulator for processing, and generates a risk assessment report.
It enables centralized management of data compliance risks for multiple businesses and institutions under supervision, thereby improving the efficiency of data compliance risk assessment.
Smart Images

Figure CN119622753B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, in particular to a data compliance risk supervision method and device, a supervision equipment and a storage medium. BACKGROUND
[0002] At present, for data compliance supervision, data compliance risks are identified, and a certain data processing flow or a certain data is matched with compliance rules to determine whether the flow exists compliance risks. However, this method can only identify compliance risks for one flow or one data at a time, for example, it can only determine whether a data collection flow exists compliance problems, and cannot centrally manage data compliance risks in different business scenarios, thus the compliance risk judgment efficiency is low and the centralization management degree is poor. SUMMARY
[0003] Therefore, the present application aims to provide a data compliance risk supervision method, device, supervision equipment and storage medium to solve the problem of low compliance risk judgment efficiency and poor centralization management degree in the prior art.
[0004] To achieve the above-mentioned purpose, the technical scheme adopted by the embodiments of the present application is as follows:
[0005] In a first aspect, the present application provides a data compliance risk supervision method applied to a supervision equipment, wherein the supervision equipment stores at least one first business parameter corresponding to a to-be-supervised business and a risk identification algorithm corresponding to each to-be-supervised business, wherein each to-be-supervised business corresponds to at least one to-be-supervised institution, and the method comprises:
[0006] According to the first business parameter of each to-be-supervised business, obtaining the to-be-analyzed data corresponding to the to-be-supervised business in each to-be-supervised institution;
[0007] According to the risk identification algorithm corresponding to each to-be-supervised business, performing compliance risk analysis on the to-be-analyzed data corresponding to the to-be-supervised business in each to-be-supervised institution to obtain the risk identification result of the to-be-supervised business in each to-be-supervised institution;
[0008] According to the risk identification result, determining a target to-be-supervised business in a target to-be-supervised institution that exists non-compliance risks, and generating a risk event according to the first business parameter of the target to-be-supervised business, the institution parameter of the target to-be-supervised institution and the risk identification result corresponding to the target to-be-supervised business.
[0009] In an optional implementation, the generating a risk event according to the first business parameter of the target business to be supervised, the institution parameter of the target institution to be supervised, and the risk identification result corresponding to the target business to be supervised comprises:
[0010] inputting the first business parameter of the target business to be supervised and the risk identification result into a pre-stored preplan generation model for processing to obtain a risk preplan for the risk event;
[0011] generating an event view corresponding to the risk event according to the first business parameter of the target business to be supervised, the institution parameter of the target institution to be supervised, and the risk identification result, and determining a risk operation user according to the institution parameter of the target institution to be supervised and the risk identification result;
[0012] generating the risk event according to the risk preplan, the event view, the risk operation user, the risk identification result, the first business parameter of the target business to be supervised, and the institution parameter of the target institution to be supervised.
[0013] In an optional implementation, the supervising device further stores a corresponding relationship between a supervisor's authority and an institution to be supervised, and the method further comprises:
[0014] determining a target supervisor according to the target institution to be supervised corresponding to the risk event and the corresponding relationship;
[0015] sending the risk event to the target supervisor so that the target supervisor processes the risk event;
[0016] obtaining a processing result corresponding to the risk event uploaded by the target supervisor, and deleting the risk event in a case where the processing result indicates that the risk event is processed successfully.
[0017] In an optional implementation, the method further comprises:
[0018] obtaining an evaluation instruction; the evaluation instruction comprises an evaluation time range and a second business parameter of at least one business to be evaluated, wherein each business to be evaluated corresponds to at least one institution to be evaluated;
[0019] for each business to be evaluated, obtaining a risk identification result corresponding to each institution to be evaluated and processing data of a risk event in the evaluation time range according to the second business parameter;
[0020] According to the risk identification result corresponding to each of the to-be-evaluated institutions, the processing data of the risk events, and a preset evaluation model within the evaluation time range, a risk evaluation report for each of the to-be-evaluated businesses and / or each of the to-be-evaluated institutions within the evaluation time range is generated.
[0021] In an optional implementation, the risk identification algorithm is generated by the following steps:
[0022] Obtaining rule information corresponding to at least one rule uploaded by a user;
[0023] According to a preset semantic analysis model, the rule information is subjected to semantic analysis to obtain a risk point corresponding to each of the rules;
[0024] According to a preset risk identification model, each of the risk points is processed to obtain a risk identification algorithm corresponding to each of the risk points;
[0025] In response to a binding operation of the user, an association relationship between each of the risk identification algorithms and each of the to-be-regulated businesses is generated.
[0026] In an optional implementation, after the rule information is subjected to semantic analysis according to the preset semantic analysis model to obtain a risk point corresponding to each of the rules, the method further includes:
[0027] A correlation graph between each of the risk points and each of the rules is generated.
[0028] In an optional implementation, the method further includes:
[0029] According to a preset risk classification model, each of the risk points is processed to obtain a risk type corresponding to each of the risk points;
[0030] According to a rule score corresponding to each of the risk points and a risk score of the risk point, a risk score of the risk point is calculated; the risk score represents a risk level of the risk point.
[0031] In a second aspect, the application provides a data compliance risk monitoring device, applied to a monitoring device, wherein the monitoring device stores a first business parameter corresponding to at least one to-be-regulated business and a risk identification algorithm corresponding to each of the to-be-regulated businesses, each of the to-be-regulated businesses corresponds to at least one to-be-regulated institution, and the device includes:
[0032] An obtaining module, configured to obtain, according to the first business parameter of each of the to-be-regulated businesses, to-be-analyzed data corresponding to the to-be-regulated business in each of the to-be-regulated institutions;
[0033] The analysis module is configured to perform compliance risk analysis on the to-be-analyzed data corresponding to the to-be-regulated business in each of the to-be-regulated institutions according to the risk identification algorithm corresponding to each of the to-be-regulated businesses, and obtain a risk identification result of the to-be-regulated business in each of the to-be-regulated institutions.
[0034] The generation module is configured to determine a target to-be-regulated business in a target to-be-regulated institution having non-compliance risk according to the risk identification result, and generate a risk event according to a first business parameter of the target to-be-regulated business, an institution parameter of the target to-be-regulated institution, and the risk identification result corresponding to the target to-be-regulated business.
[0035] In a third aspect, the present application provides a supervision device, comprising a processor and a memory, wherein the memory stores a computer program capable of being executed by the processor, and the processor can execute the computer program to implement the method according to any one of the preceding embodiments.
[0036] In a fourth aspect, the present application provides a computer-readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the method according to any one of the preceding embodiments.
[0037] The method, device, supervision device and storage medium provided by the embodiments of the present application can store at least one first business parameter corresponding to a to-be-regulated business and a risk identification algorithm corresponding to each to-be-regulated business in the supervision device, and each to-be-regulated business corresponds to at least one to-be-regulated institution. The supervision device can obtain to-be-analyzed data corresponding to the to-be-regulated business in each to-be-regulated institution according to the first business parameter of each to-be-regulated institution, and then perform compliance risk analysis on the to-be-analyzed data corresponding to the to-be-regulated business in each to-be-regulated institution according to the risk identification algorithm corresponding to each to-be-regulated business, thereby obtaining a risk identification result of the to-be-regulated business in each to-be-regulated institution. On this basis, the supervision device can determine a target to-be-regulated business in a target to-be-regulated institution having non-compliance risk according to the risk identification result, and generate a risk event according to a first business parameter of the target to-be-regulated business, an institution parameter of the target to-be-regulated institution, and the risk identification result corresponding to the target to-be-regulated business. Through the method, the supervision device can simultaneously supervise the data compliance risk of multiple to-be-regulated businesses and multiple to-be-regulated institutions, thereby centrally managing the data compliance risk of different business scenarios, improving the degree of central management, and improving the judgment efficiency of the data compliance risk.
[0038] In order to make the above objectives, characteristics and advantages of the present application more apparent and easy to understand, the following preferred embodiments are described in detail below, and the accompanying drawings are referred to. BRIEF DESCRIPTION OF DRAWINGS
[0039] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiments will be briefly introduced as follows. It should be understood that the following drawings only show some of the embodiments of the present application, and therefore should not be regarded as a limitation on the scope, and for those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.
[0040] Figure 1 A block schematic diagram of a supervision device provided by the embodiments of the present application is shown;
[0041] Figure 2 A flow schematic diagram of a data compliance risk supervision method provided by the embodiments of the present application is shown;
[0042] Figure 3 A functional module diagram of a data compliance risk supervision device provided by the embodiments of the present application is shown.
[0043] Figure legend: 10 - supervision device; 100 - memory; 110 - processor; 120 - communication module; 200 - acquisition module; 210 - analysis module; 220 - generation module. DETAILED DESCRIPTION
[0044] The technical solutions of the embodiments of the present application will be described clearly and completely in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. The components of the embodiments of the present application described and shown in the drawings herein can be arranged and designed in various different configurations.
[0045] Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the claimed present application, but only represents selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of the present application.
[0046] It should be noted that the terms "first", "second", and so on are merely used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "contain" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such a process, method, article or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of another identical element in the process, method, article or device including the element.
[0047] Figure 1 The block schematic diagram of the regulatory device 10 provided by the embodiments of the present application is shown in Figure 1 The regulatory device 10 includes a memory 100, a processor 110 and a communication module 120. The memory 100, the processor 110 and the communication module 120 are directly or indirectly electrically connected to each other to realize the transmission or interaction of data. For example, these elements can be electrically connected to each other through one or more communication buses or signal lines.
[0048] The memory 100 is used to store computer programs or data that can be executed by the processor. The memory 100 can be, but is not limited to, a random access memory (RAM), a read only memory (ROM), a programmable read only memory (PROM), an erasable programmable read only memory (EPROM), an electrically erasable programmable read only memory (EEPROM) and the like.
[0049] The processor 110 is used to read / write the data or computer programs stored in the memory, and execute the computer programs to realize the data compliance risk monitoring method provided by the embodiments of the present application.
[0050] The communication module 120 is used to establish a communication connection between the regulatory device and other communication terminals through a network, and is used to transmit and receive data through the network.
[0051] Optionally, the supervisory device can store first business parameters corresponding to at least one to-be-supervised business, and risk identification algorithms corresponding to each to-be-supervised business, and each to-be-supervised business corresponds to at least one to-be-supervised institution.
[0052] It should be understood that, Figure 1 The structure shown is only a structural schematic diagram of the supervisory device, and the supervisory device can further include more or fewer components than Figure 1 or have a different configuration from Figure 1 The components shown in the above can be implemented in hardware, software, or a combination thereof. Figure 1
[0053] Next, the above Figure 1 The supervisory device shown is an execution subject, and the data compliance risk supervisory method provided by the embodiments of the present application is exemplarily introduced in combination with the flowchart.
[0054] Specifically, Figure 2 A flowchart of the data compliance risk supervisory method provided by the embodiments of the present application is shown in FIG. 2. Figure 2 The method can be implemented through steps S20-S22.
[0055] In step S20, according to the first business parameters of each to-be-supervised business, to-be-analyzed data corresponding to the to-be-supervised business in each to-be-supervised institution is obtained.
[0056] Optionally, the supervisory device can obtain the to-be-analyzed data in real time.
[0057] Optionally, the first business parameters can include attribute parameters of the to-be-supervised business and institution parameters of the to-be-supervised institution corresponding to the to-be-supervised business.
[0058] In one possible implementation manner, the first business parameters can include a business name of the to-be-supervised business, an institution name of the corresponding to-be-supervised institution, a system name of the related system, a data table name and a field name corresponding to the to-be-supervised business, a to-be-analyzed data collection path, and the like.
[0059] Optionally, the to-be-supervised business can be a data processing flow, a management personnel operation flow or management activity, data itself, and the like. For example, the to-be-supervised business can be a data collection flow, a data analysis flow, a data transmission flow, personal privacy data, cross-border data, an overreach situation of a management personnel, and the like.
[0060] Optionally, according to the specific to-be-supervised business, the to-be-analyzed data can include log data, network data, business data itself, management data, and legal and regulatory data, and the like.
[0061] In this embodiment, the electronic device can query the data of the corresponding regulatory agency in the association system according to the data collection path to be analyzed in the first service parameter, and obtain the corresponding to-be-analyzed data according to the data table name and the field name.
[0062] For example, if the to-be-regulated service is a data collection process for personal privacy data, the to-be-analyzed data can include all log data, management data, etc. in the process of collecting personal privacy data of each user by the corresponding to-be-regulated agency.
[0063] In this embodiment, the user can configure the first service data of the to-be-regulated service that needs to be supervised according to the actual application situation in advance, and store it in the supervision device.
[0064] Step S21, according to the risk identification algorithm corresponding to each to-be-regulated service, the to-be-analyzed data corresponding to each to-be-regulated service in each to-be-regulated agency is analyzed for compliance risk, and the risk identification result of each to-be-regulated service in each to-be-regulated agency is obtained.
[0065] Optionally, the risk identification algorithm can be generated in advance and stored in the electronic device.
[0066] It can be understood that, since the risks in each to-be-regulated service may be different, the risk identification algorithm corresponding to each to-be-regulated service may also be different.
[0067] Optionally, considering that the format of the to-be-analyzed data obtained directly may not be consistent with the format that can be identified by the risk identification algorithm, in order to ensure the smooth execution of the compliance risk analysis, the electronic device can also convert the format of the to-be-analyzed data obtained into a format that can be identified by the preset risk identification algorithm.
[0068] Optionally, in order to avoid the interference of possible duplicate data, the electronic device can also perform data cleaning operations such as data screening on the data.
[0069] In this embodiment, the electronic device can determine the risk identification result of the to-be-regulated service in each to-be-regulated agency through the compliance risk analysis.
[0070] Optionally, the risk identification result can include whether the to-be-regulated service in the to-be-regulated agency has an unregulated risk, a specific risk point, a risk level, etc.
[0071] Optionally, the risk level refers to the severity of the unregulated risk, including high risk, medium risk, and low risk.
[0072] In step S22, the target to-be-regulated business in the target to-be-regulated institution with non-compliance risks is determined according to the risk identification result, and a risk event is generated according to the first business parameter of the target to-be-regulated business, the institution parameter of the target to-be-regulated institution, and the risk identification result corresponding to the target to-be-regulated business.
[0073] Optionally, the supervision device can generate a corresponding risk event after determining the target to-be-regulated institution and the target to-be-regulated business with non-compliance risks, so that the user can handle the risks in time.
[0074] In one example, if the to-be-regulated business includes a data collection process and a data transmission process, and the data collection process and the data transmission process correspond to the to-be-regulated institution 1 and the to-be-regulated institution 2, the electronic device can obtain the first to-be-analyzed data corresponding to the data collection process and the second to-be-analyzed data corresponding to the data transmission process in the to-be-regulated institution 1, and the third to-be-analyzed data corresponding to the data collection process and the fourth to-be-analyzed data corresponding to the data transmission process in the to-be-regulated institution 2.
[0075] In this example, the supervision device can perform compliance risk analysis on the first to-be-analyzed data and the third to-be-analyzed data according to the risk identification algorithm corresponding to the data collection process, and perform compliance risk analysis on the second to-be-analyzed data and the fourth to-be-analyzed data according to the risk identification algorithm corresponding to the data transmission process, thereby obtaining the risk identification result of the data collection process and the data transmission process in the to-be-regulated institution 1, and the risk identification result of the data collection process and the data transmission process in the to-be-regulated institution 2.
[0076] In this example, if the risk identification result of the second to-be-analyzed data is non-compliance, it can be determined that the data transmission process in the to-be-regulated institution 1 has non-compliance risks, and therefore the supervision device can generate a risk event for the data transmission process in the to-be-regulated institution 1 according to the first business parameter of the data transmission process, the institution parameter of the to-be-regulated institution 1, and the risk identification result corresponding to the second to-be-analyzed data.
[0077] The method provided by the embodiments of the present application can store at least one first service parameter corresponding to a to-be-supervised service and a risk identification algorithm corresponding to each to-be-supervised service in the supervision device, and each to-be-supervised service corresponds to at least one to-be-supervised institution. Then, the supervision device can obtain to-be-analyzed data corresponding to the to-be-supervised service in each to-be-supervised institution according to the first service parameter of each to-be-supervised institution, and then perform compliance risk analysis on the to-be-analyzed data corresponding to the to-be-supervised service in each to-be-supervised institution according to the risk identification algorithm corresponding to each to-be-supervised service, so as to obtain a risk identification result of the to-be-supervised service in each to-be-supervised institution. On this basis, the supervision device can determine a target to-be-supervised service in a target to-be-supervised institution that has a non-compliance risk according to the risk identification result, and generate a risk event according to the first service parameter of the target to-be-supervised service, the institution parameter of the target to-be-supervised institution, and the risk identification result corresponding to the target to-be-supervised service. Through the method, the supervision device can simultaneously supervise the data compliance risk of multiple to-be-supervised services and multiple to-be-supervised institutions, so that the data compliance risk of different business scenarios can be centrally managed, the central management degree is improved, and the judgment efficiency of the data compliance risk is also improved.
[0078] Optionally, before supervising the data compliance risk, the supervision device needs to generate a risk identification algorithm first, and bind the to-be-supervised service with the risk identification algorithm.
[0079] In a possible implementation manner, when generating the risk identification algorithm, it is necessary to determine possible risk points first.
[0080] Specifically, the supervision device can obtain rule information corresponding to at least one rule uploaded by a user, and perform semantic analysis on the rule information according to a preset semantic analysis model to obtain risk points corresponding to each rule, so as to process each risk point according to a preset risk identification model to obtain a risk identification algorithm corresponding to each risk point.
[0081] Optionally, the rule can be some laws and regulations, rules and regulations for the to-be-supervised service, or a rule defined by the user according to actual application conditions.
[0082] In a possible implementation manner, the rule can include laws and regulations, industry standards, internal systems, and treaty obligations. The laws and regulations are laws and regulations with legal effect. The industry standards refer to standards, norms, guidelines, etc. set by industry organizations or social groups. The internal system refers to a data management system formulated by a data management subject. The treaty obligation refers to a treaty, norm, guideline, etc. jointly observed or advocated by domestic and foreign organizations or association groups.
[0083] In a possible implementation manner, the rule information can include a rule name, a rule type, an issuing authority, a rule introduction, and a rule clause.
[0084] Optionally, the electronic device can perform semantic analysis on the rule information according to a natural language processing algorithm, to obtain the risk points corresponding to each rule.
[0085] Optionally, the risk identification model can be a model generated by machine learning on the risk point description information.
[0086] Optionally, the risk identification algorithm can include an algorithm name, an input data format, an output data format, and specific risk identification logic.
[0087] Optionally, since different risks can exist in different to-be-regulated businesses, that is, different risk points can exist corresponding to different to-be-regulated businesses, the user also needs to determine the risk points corresponding to the to-be-regulated businesses, to bind the to-be-regulated businesses and the risk identification algorithms corresponding to the risk points.
[0088] Specifically, the regulation device can also generate an association relationship between each risk identification algorithm and each to-be-regulated business in response to a binding operation of the user.
[0089] In this embodiment, one to-be-regulated business can correspond to multiple risk identification algorithms, and each risk identification algorithm can be used to identify a risk point that can exist in the to-be-regulated business.
[0090] In an example, the data collection process can have the risk points of not obtaining personal consent when collecting personal information, not performing the notification obligation when collecting personal information, and collecting personal information beyond the scope, and therefore the data collection process can be bound with the personal information authorization identification algorithm, the personal information processing notification content identification algorithm, and the personal information collection range identification algorithm, to identify these risk points.
[0091] The data compliance risk regulation method provided in the embodiments of this application can be used to determine the corresponding risk points and the risk identification algorithms corresponding to the risk points by the regulation device according to the rule information uploaded by the user, and therefore, compared with the prior art in which the user needs to identify the risk points and configure the risk identification algorithms by himself, the method can further reduce the labor cost and improve the management efficiency.
[0092] Optionally, to facilitate the user to understand the relationship between the risk points and the rules and simplify the positioning process of the risk points or the rules, the regulation device can also generate an association graph between each risk point and each rule after obtaining the risk points corresponding to each rule.
[0093] In this embodiment, the regulation device can generate the association graph by using the knowledge graph technology.
[0094] It can be understood that, based on this, the user can associate and search the risk points and the rules through the association graph, and also can understand the relationship between the risk points and the rules through the visual presentation of the association graph.
[0095] Optionally, in order to further refine the related information of the risk points, the supervision device can also classify each risk point and calculate a risk score of each risk point.
[0096] Specifically, the supervision device can also process each risk point according to a preset risk classification model, obtain a risk type corresponding to each risk point, and calculate a risk score of the risk point according to the rule score corresponding to each risk point and the risk score of the risk point, respectively; the risk score represents the risk level of the risk point.
[0097] Optionally, the risk classification model can be a model generated by machine learning technology.
[0098] Optionally, the risk type can include a first type and a second type, and the second type can be a sub-type of the first type.
[0099] In one example, the risk type can be as shown in Table 1.
[0100] Table 1: Risk Type Table
[0101]
[0102] Optionally, the supervision device can calculate the risk score according to the rule score associated with the risk point and the consequence score corresponding to the risk point.
[0103] In one possible implementation manner, the risk score G can be calculated by the following formula:
[0104] G=ax+by
[0105] Wherein, x represents the rule score associated with the risk point, y represents the consequence score corresponding to the risk point, a and b represent the rule weight and the consequence weight, respectively, and the sum of a and b is 1.
[0106] Optionally, the specific values of a and b can be set by the user according to the actual application situation.
[0107] Optionally, the risk score can represent the risk level.
[0108] In one possible implementation manner, a score interval can be set, and different score intervals correspond to low risk, medium risk and high risk, respectively.
[0109] Optionally, after determining the risk type and the risk score of each risk point, the risk type and the risk score can be bound to the risk point as attribute information of the risk point.
[0110] In this embodiment, the supervisory device can perform compliance risk analysis on the to-be-analyzed data corresponding to the to-be-supervised business in each to-be-supervised institution through the risk identification algorithm, and directly output whether the to-be-analyzed data exists non-compliance risk.
[0111] In one example, the result can be represented by 0 and 1, for example, 0 represents that there is non-compliance risk, and 1 represents that there is no non-compliance risk. In this embodiment, the supervisory device can determine the risk point that may exist at this time according to the risk identification algorithm outputting the result of existing non-compliance risk, and determine the corresponding risk type and risk score, i.e. risk level, according to the risk point.
[0112] In addition, the risk identification result can also include risk consequences, rule information associated with the risk point, and cases related to the risk point.
[0113] Optionally, the risk score can also be used to determine whether to issue a risk warning.
[0114] In one possible implementation manner, if the supervisory device determines that the to-be-supervised business in a certain to-be-supervised institution exists non-compliance risk, and the risk score represents that the risk level is high risk, the supervisory device needs to issue risk warning information to the related risk operation user or the to-be-supervised institution.
[0115] Optionally, the risk warning information can include information of the to-be-supervised business, the risk identification result, and the risk determination time.
[0116] It can be understood that the information of the to-be-supervised business here refers to the record corresponding to the to-be-supervised institution in the first business information of the to-be-supervised business.
[0117] Optionally, after determining the risk identification result of the to-be-supervised business in each to-be-supervised institution, the supervisory device can also generate a risk event for a target to-be-supervised institution and a target to-be-supervised business existing non-compliance risk.
[0118] In this embodiment, the electronic device can generate a risk event according to the first business parameter of the target to-be-supervised business, the institution parameter of the target to-be-supervised institution, and the risk identification result corresponding to the target to-be-supervised business.
[0119] Specifically, the supervisory device can input the first business parameter and the risk identification result of the target to-be-supervised business into the pre-stored pre-event generation model for processing, and obtain a risk pre-event for the risk event.
[0120] Optionally, the preplan generation model can be generated in advance according to a machine learning technique.
[0121] Optionally, the risk preplan refers to a recommended processing mode for the risk event.
[0122] In this embodiment, the supervision device can generate an event view corresponding to the risk event according to the first business parameter of the target business to be supervised, the agency parameter of the target agency to be supervised, and the risk identification result, and determine a risk operation user according to the agency parameter of the target agency to be supervised and the risk identification result.
[0123] Optionally, the agency parameter can include a user parameter in the target agency to be supervised, an agency identifier of the target agency to be supervised, an agency type, and the like.
[0124] Optionally, the risk operation user can be a user in the target agency to be supervised who operates the non-compliant target business to be supervised, or can be a person responsible for the target business to be supervised in the target agency to be supervised, which can be determined according to actual conditions.
[0125] Optionally, the event view can intuitively present related data of the risk event in the form of a view, such as a to-be-supervised agency, a to-be-supervised business, a risk point, and the like corresponding to the risk event. In this embodiment, the supervision device can generate a risk event according to the risk preplan, the event view, the risk operation user, the risk identification result, the first business parameter of the target business to be supervised, and the agency parameter of the target agency to be supervised.
[0126] In one possible implementation manner, the risk event can be represented as a risk record.
[0127] In this embodiment, the risk event can include a risk preplan, an event view, a risk operation user, a risk identification result, a parameter corresponding to a target business to be supervised in a target agency to be supervised, and an event code.
[0128] Optionally, the parameter corresponding to the target business to be supervised in the target agency to be supervised refers to a record corresponding to the target agency to be supervised in the first business information of the target business to be supervised, and the supervision device can determine the parameter according to the first business parameter of the target business to be supervised and the agency parameter of the target agency to be supervised.
[0129] Optionally, the supervision device can also generate an event code corresponding to the risk event according to preset coding generation logic to uniquely identify the risk event.
[0130] It can be understood that the risk event refers to a matter record that needs to be processed, and the event view refers to a monitoring view that can be displayed on a display screen. It can be understood that after the risk event is generated, a corresponding supervisor needs to process the risk event.
[0131] In this embodiment, the supervisory device can also store the correspondence between the supervisory authority of each supervisory authority and the to-be-supervised organization. It can be understood that the supervisory authority of different supervisory authorities is different, so the correspondence between the supervisory authority of each supervisory authority and the to-be-supervised organization can actually form a hierarchical supervision relationship between the supervisory authority and the to-be-supervised organization.
[0132] In one example, if the authority of supervisory authority A is greater than the authorities of supervisory authority B, supervisory authority C and supervisory authority D, and a superior-subordinate relationship is formed between supervisory authority A and supervisory authority B, supervisory authority C and supervisory authority D, and supervisory authority B corresponds to supervising to-be-supervised organization 1, supervisory authority C corresponds to supervising to-be-supervised organization 2, and supervisory authority D corresponds to supervising to-be-supervised organization 3, then supervisory authority A corresponds to supervising to-be-supervised organization 1, to-be-supervised organization 2 and to-be-supervised organization 3.
[0133] Optionally, based on this, the supervisory device can determine the target supervisory authority according to the correspondence between the target supervisory organization corresponding to the risk event and the correspondence after generating the risk event, and send the risk event to the target supervisory authority, so that the target supervisory authority processes the risk event.
[0134] In this embodiment, the risk event can be sent to the target supervisory authority in the form of a to-be-processed matter.
[0135] It can be understood that, since the supervisory authority of different supervisory authorities is different, each supervisory authority can view the event view within the scope of its own authority.
[0136] Please continue to refer to the above example, supervisory authority B can view the event view corresponding to to-be-supervised organization 1, supervisory authority C can view the event view corresponding to to-be-supervised organization 2, supervisory authority D can view the event view corresponding to to-be-supervised organization 3, and supervisory authority A can view the event view corresponding to supervising to-be-supervised organization 1, to-be-supervised organization 2 and to-be-supervised organization 3.
[0137] Optionally, the target supervisory authority can process the risk event by referring to the risk plan and combining the actual situation, and upload the corresponding processing result after processing is completed. In this embodiment, the supervisory device can obtain the processing result corresponding to the risk event uploaded by the target supervisory authority, and delete the risk event in the case that the processing result indicates that the risk event processing is successful.
[0138] Optionally, the processing result can indicate whether the risk event is successfully processed, that is, whether the risk is successfully eliminated.
[0139] It can be understood that the supervisory device can delete the risk event in the case that the risk processing result indicates that the risk is successfully eliminated.
[0140] Optionally, in order to further centrally manage the various to-be-regulated businesses and the various to-be-regulated institutions, the supervision device can further evaluate the risk supervision situation in a period of time.
[0141] Optionally, the supervision device can evaluate the risk supervision situation of one or more to-be-regulated businesses in a period of time, or can evaluate the risk supervision situation of one or more to-be-regulated institutions in a period of time, which can be set according to specific circumstances.
[0142] In this embodiment, the supervision device can evaluate the risk supervision situation from multiple perspectives. For example, the risk supervision situation is evaluated from four dimensions of system specification, data processing, operation management, and supply chain management, and each dimension further includes multiple evaluation sub-dimensions.
[0143] For example, the system specification can include evaluation sub-dimensions such as personal information processing management system, personal information processing specification, and data security management system; the data processing can include evaluation sub-dimensions such as data collection, data processing / use, data transmission / provision, and data storage / deletion; the operation management can include evaluation sub-dimensions such as organization structure, personnel management, risk monitoring and disposal, risk assessment, emergency disposal, and compliance audit; and the supply chain management can include evaluation sub-dimensions such as qualification review, entrusted processing program, and entrusted processing agreement.
[0144] Optionally, different evaluation models can be generated in advance for different evaluation dimensions, for example, an evaluation model is generated for each evaluation sub-dimension, and then a corresponding evaluation model is selected for evaluation according to specific evaluation requirements. In this embodiment, the supervision device can first obtain an evaluation instruction.
[0145] Optionally, the evaluation instruction can be an evaluation instruction issued by the user according to actual requirements, or can be an evaluation instruction configured in the supervision device in advance and executed periodically, for example, the risk supervision situation of the data collection process is evaluated every other month.
[0146] Optionally, the evaluation instruction can include an evaluation time range and a second business parameter of at least one to-be-evaluated business, wherein each to-be-evaluated business corresponds to at least one to-be-evaluated institution.
[0147] Optionally, the second business parameter can include an institution parameter (such as an institution name) of a contained to-be-evaluated institution, a data acquisition path, a related system name, and the like.
[0148] In the embodiment, the supervision device can obtain, for each to-be-evaluated business, the risk identification result and the processing data of the risk event of each to-be-evaluated institution in the evaluation time range according to the second business parameter, and generate a risk evaluation report for each to-be-evaluated business and / or each to-be-evaluated institution in the evaluation time range according to the risk identification result, the processing data of the risk event, and a preset evaluation model.
[0149] Optionally, the risk identification result can include a risk identification result representing the existence of non-compliance risk and a risk identification result representing the non-existence of non-compliance risk.
[0150] Optionally, the processing data of the risk event can include processing duration, processing result, etc.
[0151] Optionally, the risk evaluation report can include a report name or a report number, an evaluation time range, an overall compliance risk situation, an evaluation result corresponding to each evaluation dimension, an evaluation time, and improvement suggestions.
[0152] In addition, the risk evaluation report can further include a detection coverage of data compliance risk, a total number of risk events, a risk event occurrence rate, a risk event processing success rate, a risk event processing efficiency or an average processing duration, etc.
[0153] Furthermore, the risk evaluation report can further include a horizontal comparison result between different to-be-supervised businesses or a horizontal comparison result between different to-be-supervised devices.
[0154] Optionally, after obtaining the risk evaluation report, the supervision device can send the risk evaluation report to a corresponding supervisor according to the to-be-supervised institution to which the risk evaluation report is directed, so that the supervisor issues specific rectification opinions to the corresponding to-be-supervised institution in combination with the improvement suggestions in the risk evaluation report and the actual situation.
[0155] In order to perform the corresponding steps in the above embodiments and various possible manners, an implementation manner of a data compliance risk supervision device is given below. Optionally, the data compliance risk supervision device can adopt the device structure of the supervision device shown in the above Figure 1 .
[0156] Further, please refer to Figure 3 , Figure 3A functional module diagram of a data compliance risk supervision device is provided for an embodiment of the present application. It should be noted that the data compliance risk supervision device provided in the embodiment has the same basic principles and technical effects as the above-described embodiments. For brief description, the part of the embodiment not mentioned can refer to the corresponding content in the above-described embodiments. The data compliance risk supervision device comprises an acquisition module 200, an analysis module 210, and a generation module 220.
[0157] The acquisition module 200 is configured to acquire the to-be-analyzed data corresponding to the to-be-supervised business in each to-be-supervised institution according to the first business parameter of each to-be-supervised business.
[0158] It can be understood that the acquisition module 200 can be configured to perform the above step S20.
[0159] The analysis module 210 is configured to perform compliance risk analysis on the to-be-analyzed data corresponding to the to-be-supervised business in each to-be-supervised institution according to the risk identification algorithm corresponding to each to-be-supervised business, and obtain the risk identification result of the to-be-supervised business in each to-be-supervised institution.
[0160] It can be understood that the analysis module 210 can be configured to perform the above step S21.
[0161] The generation module 220 is configured to determine the target to-be-supervised business in the target to-be-supervised institution with non-compliance risk according to the risk identification result, and generate a risk event according to the first business parameter of the target to-be-supervised business, the institution parameter of the target to-be-supervised institution, and the risk identification result corresponding to the target to-be-supervised business.
[0162] It can be understood that the generation module 220 can be configured to perform the above step S22.
[0163] Optionally, the generation module 220 is further configured to input the first business parameter of the target to-be-supervised business and the risk identification result into a pre-stored plan generation model for processing to obtain a risk plan for the risk event; generate an event view corresponding to the risk event according to the first business parameter of the target to-be-supervised business, the institution parameter of the target to-be-supervised institution, and the risk identification result, and determine a risk operation user according to the institution parameter of the target to-be-supervised institution and the risk identification result; and generate the risk event according to the risk plan, the event view, the risk operation user, the risk identification result, the first business parameter of the target to-be-supervised business, and the institution parameter of the target to-be-supervised institution.
[0164] Optionally, the generation module 220 is further configured to determine the target regulator based on the target regulatory agency corresponding to the risk event and the corresponding relationship; send the risk event to the target regulator so that the target regulator can process the risk event; obtain the processing result corresponding to the risk event uploaded by the target regulator; and delete the risk event if the processing result indicates that the risk event has been successfully processed.
[0165] Optionally, the generation module 220 is further configured to obtain assessment instructions; the assessment instructions include an assessment time range and at least one second business parameter for a business to be assessed, wherein each business to be assessed corresponds to at least one institution to be assessed; for each business to be assessed, the risk identification results and risk event processing data corresponding to each institution to be assessed within the assessment time range are obtained according to the second business parameter; based on the risk identification results, risk event processing data, and preset assessment model corresponding to each institution to be assessed within the assessment time range, a risk assessment report is generated for each business to be assessed and / or each institution to be assessed within the assessment time range.
[0166] Optionally, the data compliance risk monitoring device further includes a risk module. Optionally, this risk module is used to: acquire rule information corresponding to at least one rule uploaded by the user; perform semantic analysis on the rule information according to a preset semantic analysis model to obtain risk points corresponding to each rule; process each risk point according to a preset risk identification model to obtain risk identification algorithms corresponding to each risk point; and generate the association between each risk identification algorithm and each business to be regulated in response to the user's binding operation.
[0167] Optionally, this risk module is also used to generate a correlation graph between each risk point and each rule.
[0168] Optionally, the risk module is also used to process each risk point according to a preset risk classification model to obtain the risk type corresponding to each risk point; calculate the risk score of each risk point according to the rule score corresponding to each risk point and the risk score of the risk point; the risk score represents the risk level of the risk point.
[0169] Optionally, the above modules can be stored in the form of software or firmware. Figure 1 The memory shown may be stored in or embedded in the operating system (OS) of the monitoring device, and may be controlled by... Figure 1 The processor executes the commands. Meanwhile, the data and program code required to execute these modules can be stored in memory.
[0170] The embodiment of the present application further provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the method for supervising data compliance risk provided by the embodiment of the present application.
[0171] In several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can also be implemented by other manners. The apparatus embodiment described above is only schematic, for example, the flow chart and block diagram in the drawings show the possible implementation architecture, function and operation of the apparatus, method and computer program product according to the embodiments of the present application. In this regard, each block in the flow chart or block diagram can represent a module, a program segment or a part of code, which contains one or more executable instructions for implementing the specified logic function. It should also be noted that, in some alternative implementation manners, the functions noted in the blocks can also occur in different order from that noted in the drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and they can also be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flow chart, and the combination of blocks in the block diagram and / or flow chart, can be implemented by a dedicated hardware-based system for implementing the specified function or action, or can be implemented by a combination of dedicated hardware and computer instructions.
[0172] In addition, each functional module in the embodiments of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0173] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.
[0174] The above descriptions are only the preferred embodiments of the present application, and are not intended to limit the present application. The present application can have various modifications and changes for those skilled in the art. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A method of supervising data compliance risk, characterized in that, The method is applied to a supervision device, wherein the supervision device stores first business parameters corresponding to at least one to-be-supervised business and risk identification algorithms corresponding to each to-be-supervised business, wherein each to-be-supervised business corresponds to at least one to-be-supervised agency, and the method comprises the following steps: acquiring to-be-analyzed data corresponding to the to-be-supervised business in each to-be-supervised agency according to first business parameters of each to-be-supervised business respectively; the first business parameters comprise a business name of the to-be-supervised business, an agency name of a corresponding to-be-supervised agency, a system name of a related system, a data table name and a field name corresponding to the to-be-supervised business, and a to-be-analyzed data acquisition path; the to-be-analyzed data comprises log data, network data, business data, management data, and legal and regulatory data; performing compliance risk analysis on the to-be-analyzed data corresponding to the to-be-supervised business in each to-be-supervised agency according to risk identification algorithms corresponding to each to-be-supervised business respectively, to obtain risk identification results of the to-be-supervised business in each to-be-supervised agency; each to-be-supervised business corresponds to multiple risk identification algorithms, and each risk identification algorithm is used to identify one risk point; the risk identification algorithm is generated through the following steps: acquiring rule information corresponding to at least one rule uploaded by a user; performing semantic analysis on the rule information according to a preset semantic analysis model, to obtain risk points corresponding to each rule, and generating an association graph between each risk point and each rule; processing each risk point according to a preset risk identification model, to obtain a risk identification algorithm corresponding to each risk point; generating an association relationship between each risk identification algorithm and each to-be-supervised business in response to a binding operation of a user; determining a target to-be-supervised business in a target to-be-supervised agency in which there exists a non-compliance risk according to the risk identification results, and generating a risk event according to first business parameters of the target to-be-supervised business, agency parameters of the target to-be-supervised agency, and risk identification results corresponding to the target to-be-supervised business; the step of generating a risk event according to the first business parameters of the target to-be-supervised business, the agency parameters of the target to-be-supervised agency, and the risk identification results corresponding to the target to-be-supervised business comprises: inputting the first business parameters of the target to-be-supervised business and the risk identification results into a pre-stored plan generation model for processing, to obtain a risk plan for the risk event; generating an event view corresponding to the risk event according to the first business parameters of the target to-be-supervised business, the agency parameters of the target to-be-supervised agency, and the risk identification results, and determining a risk operation user according to the agency parameters of the target to-be-supervised agency and the risk identification results; generating the risk event according to the risk plan, the event view, the risk operation user, the risk identification results, the first business parameters of the target to-be-supervised business, and the agency parameters of the target to-be-supervised agency; Obtain a processing result corresponding to the risk event uploaded by a target supervisor, and delete the risk event in a case where the processing result indicates that the risk event is successfully processed.
2. The method of claim 1, wherein, The supervision device further stores a correspondence between a supervisor authority of each supervisor and a supervised organization, and the method further includes: Determining a target supervisor according to a target supervised organization corresponding to the risk event and the correspondence; Sending the risk event to the target supervisor so that the target supervisor processes the risk event.
3. The method of claim 1, wherein, The method further includes: Obtaining an evaluation instruction; the evaluation instruction includes an evaluation time range and a second business parameter of at least one to-be-evaluated business, wherein each to-be-evaluated business corresponds to at least one to-be-evaluated organization; According to the second business parameter, obtaining, for each to-be-evaluated business, a risk identification result corresponding to each to-be-evaluated organization and processing data of a risk event in the evaluation time range; According to the risk identification result corresponding to each to-be-evaluated organization, the processing data of the risk event, and a preset evaluation model, generating a risk evaluation report for each to-be-evaluated business and / or each to-be-evaluated organization in the evaluation time range.
4. The method of claim 1, wherein, The method further includes: Processing each risk point according to a preset risk classification model to obtain a risk type corresponding to each risk point; According to a rule score corresponding to each risk point and a risk score of the risk point, calculating the risk score of the risk point; the risk score represents a risk level of the risk point.
5. A device for supervising data compliance risks, characterized in that, The device is applied to a supervision device, and the supervision device stores a first business parameter corresponding to at least one to-be-supervised business and a risk identification algorithm corresponding to each to-be-supervised business, wherein each to-be-supervised business corresponds to at least one to-be-supervised organization, and the device includes: An obtaining module, configured to obtain, according to the first business parameter of each to-be-supervised business, to-be-analyzed data corresponding to the to-be-supervised business in each to-be-supervised organization; the first business parameter includes a business name of the to-be-supervised business, an organization name of a corresponding to-be-supervised organization, a system name of a related system, a data table name and a field name corresponding to the to-be-supervised business, and a to-be-analyzed data collection path; the to-be-analyzed data includes log data, network data, business data, management data, and legal and regulatory data; An analysis module, configured to perform compliance risk analysis on the to-be-analyzed data corresponding to the to-be-supervised business in each to-be-supervised organization according to the risk identification algorithm corresponding to each to-be-supervised business, to obtain a risk identification result of the to-be-supervised business in each to-be-supervised organization; each to-be-supervised business corresponds to a plurality of risk identification algorithms, and each risk identification algorithm is used to identify one risk point. The risk module is configured to acquire rule information corresponding to at least one rule uploaded by a user, perform semantic analysis on the rule information according to a preset semantic analysis model, obtain risk points corresponding to each rule, generate an association graph between each risk point and each rule, process each risk point according to a preset risk identification model, obtain a risk identification algorithm corresponding to each risk point, and generate an association relationship between each risk identification algorithm and each to-be-regulated business in response to a binding operation of the user. The generation module is configured to determine a target to-be-regulated business in a target to-be-regulated institution with non-compliance risk according to the risk identification result, and generate a risk event according to a first business parameter of the target to-be-regulated business, an institution parameter of the target to-be-regulated institution, and a risk identification result corresponding to the target to-be-regulated business. The generation module is further configured to input the first business parameter of the target to-be-regulated business and the risk identification result into a pre-stored plan generation model for processing, to obtain a risk plan for the risk event, generate an event view corresponding to the risk event according to the first business parameter of the target to-be-regulated business, the institution parameter of the target to-be-regulated institution, and the risk identification result, and determine a risk operation user according to the institution parameter of the target to-be-regulated institution and the risk identification result, generate the risk event according to the risk plan, the event view, the risk operation user, the risk identification result, the first business parameter of the target to-be-regulated business, and the institution parameter of the target to-be-regulated institution. The generation module is further configured to acquire a processing result corresponding to the risk event uploaded by a target supervisor, and delete the risk event in a case where the processing result indicates that the risk event is successfully processed.
6. A supervisory device, characterized by The computer program is executed by the processor to implement the method of any one of claims 1-4.
7. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the method of any one of claims 1-4.
Citation Information
Patent Citations
Electric power operation site safety intelligent management and control system
CN118966809A
Compliance inspection system and method for enterprise business process
CN119378993A