Business risk assessment method, device, computer equipment and storage medium

By constructing a risk knowledge graph and data mining algorithm, the impact of risk events in the risk transmission path is quantified, which solves the problem of insufficient quantification of risk attenuation effect in existing technologies and realizes accurate assessment and management of enterprise business risks.

CN119721689BActive Publication Date: 2025-09-30PING AN TECH (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411779433.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-03
Publication Date
2025-09-30
Estimated Expiration
2044-12-03

AI Technical Summary

Technical Problem

Existing technologies fail to effectively quantify the risk attenuation effect in identifying enterprise risk transmission paths, resulting in inaccurate risk assessment results and affecting the qualitative characterization of enterprise business risks.

Method used

By constructing a risk knowledge graph, using graph search algorithms to obtain risk transmission paths, combining data mining algorithms to analyze related risk event information, quantifying the impact of risk events, and using risk event impact assessment models to simulate evolution, we can ultimately obtain a comprehensive risk value.

Benefits of technology

It achieves accurate risk assessment of corporate business, facilitates enterprises to conduct qualitative risk management, and improves the accuracy and reliability of risk assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119721689B_ABST
    Figure CN119721689B_ABST
Patent Text Reader

Abstract

The embodiments of the present application belong to the field of data processing and relate to a business risk assessment method, apparatus, computer equipment, and storage medium. The method comprises the following steps: constructing a risk knowledge graph based on business data; obtaining risk transmission paths from the risk knowledge graph based on a graph search algorithm; obtaining associated risk event information from a database based on the risk transmission paths, and analyzing the associated risk event information using a data mining algorithm to obtain risk event impact information; quantifying the risk event impact information and training a risk event impact assessment model based on the quantified risk event impact indicator data; performing risk simulation evolution based on the risk transmission paths and the risk event impact assessment model to obtain risk event impact results; and performing risk analysis based on the risk event impact results to obtain a comprehensive risk value. The present application enables accurate risk assessment of an enterprise's business.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data processing technology, specifically to the field of financial technology, and in particular to a business risk assessment method, device, computer equipment and storage medium. Background Art

[0002] In the field of FinTech, enterprise risk identification is a critical step in ensuring stable business development. With the rapid development of technologies like big data and artificial intelligence, knowledge graphs, as a powerful tool, are being widely used in enterprise risk management, particularly in identifying risk transmission pathways. However, traditional risk transmission pathway identification methods often focus solely on the existence of pathways, ignoring the crucial characteristic that risks gradually decay during transmission.

[0003] In real-world business scenarios, risks often do not exist in isolation, but rather are transmitted through a variety of complex entity relationships. These relationships may involve different departments and business processes within the enterprise, as well as the external market environment and partners.

[0004] However, when dealing with complex relationships between multi-level entities, effectively quantifying the risk attenuation effect along these paths presents a key technical challenge. As risks are transmitted, their intensity and impact gradually diminish due to various factors, such as time, distance, and the effectiveness of control measures. If this attenuation effect cannot be accurately quantified, the identification of risk transmission paths will fail to accurately reflect the actual risk situation, significantly impacting the qualitative assessment of a company's business risks and hindering its healthy development. Summary of the Invention

[0005] The purpose of the embodiments of the present application is to provide a business risk assessment method, apparatus, computer equipment and storage medium to solve the problem of being unable to effectively and accurately assess the risks of an enterprise's business.

[0006] In order to solve the above technical problems, the present application provides a business risk assessment method, which adopts the following technical solutions:

[0007] Acquire business data and construct a risk knowledge graph based on the business data;

[0008] Obtaining risk transmission paths in the risk knowledge graph based on a graph search algorithm;

[0009] Acquire associated risk event information in a database according to the risk transmission path, and analyze the associated risk event information according to a data mining algorithm to obtain risk event impact information;

[0010] Quantifying the risk event impact information and training a risk event impact assessment model based on the quantified risk event impact indicator data;

[0011] Perform risk simulation evolution according to the risk transmission path and the risk event impact assessment model to obtain risk event impact results;

[0012] Conduct risk analysis based on the impact of the risk event to obtain a comprehensive risk value.

[0013] Furthermore, the step of obtaining business data and constructing a risk knowledge graph based on the business data specifically includes:

[0014] Preprocessing the business data to obtain standard business data, and extracting risk event entities and risk event attribute information from the standard business data;

[0015] Performing a causal relationship analysis on the risk event entity and the risk event attribute information to obtain a causal relationship result;

[0016] Determine whether the causal relationship result is a causal relationship;

[0017] If the causal relationship result is that the causal relationship exists, converting the risk event entity and the risk event attribute information into a knowledge graph node and a knowledge graph edge based on a knowledge representation method;

[0018] The risk knowledge graph is constructed based on the knowledge graph nodes and the knowledge graph edges.

[0019] Furthermore, the step of obtaining the risk transmission path in the risk knowledge graph based on the graph search algorithm specifically includes:

[0020] Obtaining risk entities and risk entity relationships from the risk knowledge graph;

[0021] Constructing a risk transmission model based on the risk entities and the risk entity relationships;

[0022] Conducting a transmission path search in the risk knowledge graph based on a graph search algorithm to obtain an initial risk transmission path;

[0023] Calculate the risk value of the initial risk transmission path according to the transmission rules and weights defined by the risk transmission model;

[0024] Determining whether the risk value is greater than or equal to a preset risk threshold;

[0025] If the risk value is greater than or equal to the preset risk threshold, the initial risk transmission path is marked as the risk transmission path.

[0026] Furthermore, the step of obtaining associated risk event information from a database according to the risk transmission path, and analyzing the associated risk event information according to a data mining algorithm to obtain risk event impact information specifically includes:

[0027] Perform a matching query in the database according to the risk transmission path to obtain associated risk event information related to the target risk event;

[0028] Performing association rule mining on the associated risk event information according to an association rule mining algorithm to obtain risk event association rules and risk event association strength;

[0029] Constructing a risk event association network based on the risk event association rules and risk event association strengths;

[0030] Performing low-dimensional vector representation learning on the risk event association network to obtain a risk event embedding vector;

[0031] Clustering the risk event embedding vectors according to a preset clustering algorithm to obtain risk event clusters;

[0032] The risk event impact degree and the risk event loss scale are calculated according to the risk event clusters, and the risk event impact degree and the risk event loss scale are used as the risk event impact information.

[0033] Furthermore, the step of quantifying the risk event impact information and training a risk event impact assessment model based on the quantified risk event impact indicator data specifically includes:

[0034] Quantifying the risk event impact information according to preset quantitative indicator rules to obtain the risk event impact indicator data;

[0035] The pre-built initial impact assessment model is trained according to the risk event impact indicator data to obtain the risk event impact assessment model.

[0036] Furthermore, the step of performing risk simulation evolution according to the risk transmission path and the risk event impact assessment model to obtain the risk event impact result specifically includes:

[0037] Constructing a risk transmission network topology structure according to the risk transmission path;

[0038] Setting the risk event probability distribution according to the risk event impact assessment model;

[0039] Performing risk simulation evolution on the risk transmission network topology structure based on the Monte Carlo simulation method and the risk event probability distribution to obtain the risk status of the network nodes;

[0040] Calculate the cumulative risk impact based on the risk status of the network node to obtain a first impact assessment result;

[0041] Calculate the indirect impact of the risk based on the cascade time effect analysis method and the first impact assessment result to obtain a second impact assessment result;

[0042] The first impact assessment result and the second impact assessment result are integrated to obtain the risk event impact result.

[0043] Furthermore, the step of performing risk analysis based on the impact results of the risk event to obtain a comprehensive risk value specifically includes:

[0044] Constructing a risk event judgment matrix based on the analytic hierarchy process, and calculating risk event weight coefficients based on the risk event judgment matrix;

[0045] Acquire a risk path event set according to the risk transmission path;

[0046] The risk path event set is weighted and summed according to the risk event weight coefficient and the risk event impact result to obtain the comprehensive risk value.

[0047] In order to solve the above technical problems, the embodiment of the present application further provides a business risk assessment device, which adopts the following technical solution:

[0048] A graph construction module, used to obtain business data and construct a risk knowledge graph based on the business data;

[0049] A path acquisition module, configured to acquire risk transmission paths in the risk knowledge graph based on a graph search algorithm;

[0050] An impact analysis module is used to obtain related risk event information in a database according to the risk transmission path, and analyze the related risk event information according to a data mining algorithm to obtain risk event impact information;

[0051] A model training module is used to quantify the risk event impact information and train a risk event impact assessment model based on the quantified risk event impact indicator data;

[0052] A risk evolution module, configured to simulate and evolve the risk according to the risk transmission path and the risk event impact assessment model, and obtain the risk event impact result;

[0053] The risk analysis module is used to perform risk analysis based on the impact results of the risk event to obtain a comprehensive risk value.

[0054] In order to solve the above technical problems, the embodiment of the present application further provides a computer device, which adopts the following technical solution:

[0055] A computer device comprises a memory and a processor, wherein the memory stores computer-readable instructions, and the processor implements the steps of any of the above business risk assessment methods when executing the computer-readable instructions.

[0056] In order to solve the above technical problems, the embodiment of the present application further provides a computer-readable storage medium, which adopts the following technical solution:

[0057] A computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of any of the above business risk assessment methods.

[0058] Compared with the prior art, the embodiments of the present application have the following main beneficial effects: by acquiring business data, the present embodiment constructs a risk knowledge graph based on the business data; obtains the risk transmission path in the risk knowledge graph based on a graph search algorithm; obtains associated risk event information from a database based on the risk transmission path, and analyzes the associated risk event information based on a data mining algorithm to obtain risk event impact information; quantifies the risk event impact information, and trains a risk event impact assessment model based on the quantified risk event impact indicator data; performs risk simulation evolution based on the risk transmission path and the risk event impact assessment model to obtain risk event impact results; and performs risk analysis based on the risk event impact results to obtain a comprehensive risk value. This effectively and accurately assesses the risk of an enterprise's business, making it easier to qualitatively characterize the enterprise's risks based on the assessment results. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] In order to more clearly illustrate the solutions in this application, a brief introduction will be given below to the drawings required for use in the description of the embodiments of this application. Obviously, the drawings described below are some embodiments of this application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0060] Figure 1 is an exemplary system architecture diagram to which the present application may be applied;

[0061] Figure 2 A flowchart of an embodiment of a business risk assessment method according to the present application;

[0062] Figure 3 yes Figure 2 A flowchart of a specific implementation of step S10;

[0063] Figure 4 yes Figure 2 A flowchart of a specific implementation of step S20;

[0064] Figure 5 yes Figure 2 A flowchart of a specific implementation of step S30;

[0065] Figure 6 yes Figure 2 A flowchart of a specific implementation of step S40;

[0066] Figure 7 yes Figure 2 A flowchart of a specific implementation of step S50;

[0067] Figure 8 yes Figure 2 A flowchart of a specific implementation of step S60;

[0068] Figure 9 is a structural diagram of an embodiment of a business risk assessment device according to the present application;

[0069] Figure 10 It is a structural diagram of an embodiment of a computer device according to the present application. DETAILED DESCRIPTION

[0070] Unless otherwise defined, all technical and scientific terms used herein have the same meanings as commonly understood by those skilled in the art to which this application belongs. The terms used in the specification of the application are for the purpose of describing specific embodiments only and are not intended to limit this application. The terms "including" and "having" and any variations thereof in the specification and claims of this application and the above-mentioned drawings are intended to cover non-exclusive inclusions. The terms "first", "second", etc. in the specification and claims of this application or the above-mentioned drawings are used to distinguish different objects, not to describe a specific order.

[0071] References to "embodiments" herein mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it refer to unrelated or alternative embodiments that are mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0072] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings.

[0073] like Figure 1 As shown, system architecture 100 may include a terminal device 101, a network 102, and a server 103. Terminal device 101 may be a laptop computer 1011, a tablet computer 1012, or a mobile phone 1013. Network 102 is a medium for providing a communication link between terminal device 101 and server 103. Network 102 may include various connection types, such as wired or wireless communication links or fiber optic cables.

[0074] The user can use the terminal device 101 to interact with the server 103 via the network 102 to receive or send messages, etc. Various communication client applications can be installed on the terminal device 101, such as web browser applications, shopping applications, search applications, instant messaging tools, email clients, social platform software, etc.

[0075] The terminal device 101 can be various electronic devices with a display screen and supporting web browsing. In addition to the laptop computer 1011, tablet computer 1012 or mobile phone 1013, the terminal device 101 can also be an e-book reader, an MP3 player (Moving Picture Experts Group Audio Layer III), an MP4 (Moving Picture Experts Group Audio Layer IV) player, a laptop computer and a desktop computer, etc.

[0076] The server 103 may be a server that provides various services, such as a background server that provides support for web pages displayed on the terminal device 101 .

[0077] It should be noted that the business risk assessment method provided in the embodiment of the present application is generally executed by a server / terminal device, and accordingly, the business risk assessment device is generally set in the server / terminal device.

[0078] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.

[0079] Continue to refer Figure 2 , shows a flow chart of an embodiment of a method for business risk assessment according to the present application. The business risk assessment method comprises the following steps:

[0080] Step S10: Acquire business data and construct a risk knowledge graph based on the business data;

[0081] In this embodiment, business data refers to data related to the enterprise's business, including business entities, business-related information, and business process information. Business entities refer to various objects directly related to the enterprise's business, such as customers, products, orders, advertisements, and employees. Each business entity has unique attributes and characteristics. Business-related information describes the relationships between business entities, such as the relationship between customers and orders, the relationships between products, and the affiliation between employees and departments. Business process information records the various processes and steps in the enterprise's operations, such as sales, procurement, and production processes. The risk knowledge graph is a knowledge graph constructed based on risk event entities and risk event attribute information extracted from business data. This construction facilitates the subsequent acquisition of risk transmission pathways.

[0082] Step S20: obtaining a risk transmission path in the risk knowledge graph based on a graph search algorithm;

[0083] In this embodiment, a graph search algorithm is a type of algorithm used to find specific nodes or paths in graph-structured data, where the graph-structured data is a set of nodes (or vertices) and the edges connecting these nodes. The graph search algorithm can employ the A* algorithm, a heuristic search algorithm that uses the evaluation function f(n) = g(n) + h(n) to select the next node to visit to achieve path search, where g(n) is the actual cost from the source node to the current node, and h(n) is the estimated cost from the current node to the target node. Risk transmission paths are specific paths along which risks propagate or impact different risk entities. When a risk occurs on a particular entity, it propagates along these associations or relationships to other entities, forming risk transmission paths. These paths not only reveal the method and direction of risk transmission but also reflect the mutual influence and degree of correlation between different entities.

[0084] Step S30, obtaining associated risk event information from a database according to the risk transmission path, and analyzing the associated risk event information according to a data mining algorithm to obtain risk event impact information;

[0085] In this embodiment, the associated risk event information refers to historical risk event data related to the target risk event of the risk transmission path. The associated risk event information is obtained by matching the risk transmission path against a database, which can be a pre-established risk transmission path knowledge graph or knowledge database. The data mining algorithm utilizes an association rule mining algorithm. Association rule mining analyzes transaction records (or event records) within the associated risk event information to identify frequently occurring item sets (or event combinations) and the relationships between them, thereby enabling association analysis and effectively obtaining risk event impact information.

[0086] Step S40: quantify the risk event impact information and train a risk event impact assessment model based on the quantified risk event impact indicator data;

[0087] In this embodiment, risk event impact information includes the degree of risk event impact and the scale of risk event losses. The degree of risk event impact refers to the depth and breadth of the direct or indirect impact on a business entity after the risk event occurs, and the scale of risk event losses refers to the actual economic, financial, or material losses incurred by the business entity after the risk event occurs. The degree of risk event impact and the scale of risk event losses are quantified using pre-set quantitative indicator rules to generate risk event impact indicator data. This risk event impact indicator data is then used to train a risk event impact assessment model that calculates the impact score for each risk event.

[0088] Step S50: performing risk simulation evolution according to the risk transmission path and the risk event impact assessment model to obtain a risk event impact result;

[0089] In this embodiment, risk simulation evolution is performed based on the Monte Carlo simulation method. The Monte Carlo simulation method, also known as the random simulation method or statistical simulation method, is based on statistical sampling theory. It uses random numbers to conduct sampling experiments or random simulations on existing data of random variables to obtain a certain numerical characteristic of the statistical quantity and use it as the numerical solution to the problem to be solved. Based on the risk transmission path and the risk event impact assessment model, the risk simulation evolution is performed based on the Monte Carlo simulation method to obtain the risk status of the network node. Based on this network node risk status, the first impact assessment result of the cumulative risk impact and the second impact assessment result of the indirect risk impact are calculated. The first impact assessment result and the second impact assessment result are integrated to obtain the final risk event impact result.

[0090] Step S60: Perform risk analysis based on the impact of the risk event to obtain a comprehensive risk value.

[0091] In this embodiment, the risk event impact result is the impact result of the risk event on the risk transmission path. The risk analysis of the risk event impact result includes calculating the risk event weight coefficient and obtaining the risk path event set. The risk event weight coefficient is calculated based on the risk event judgment matrix. The risk event judgment matrix refers to the risk event pairwise judgment matrix, which is also called a pairwise comparison matrix or judgment matrix. The risk event pairwise judgment matrix is ​​a matrix tool used in the Analytic Hierarchy Process (AHP) to compare the relative importance of different risk events at the same level. By comparing the relative importance of different risk events at the same level, weights are assigned to these risk events, and then a weighted sum calculation is performed based on the assigned weights to obtain the comprehensive risk value of the risk event.

[0092] This embodiment acquires business data and constructs a risk knowledge graph based on the business data; uses a graph search algorithm to obtain risk transmission paths from the risk knowledge graph; obtains associated risk event information from a database based on the risk transmission paths, analyzes the associated risk event information using a data mining algorithm to obtain risk event impact information; quantifies the risk event impact information and trains a risk event impact assessment model based on the quantified risk event impact indicator data; performs risk simulation evolution based on the risk transmission paths and the risk event impact assessment model to obtain risk event impact results; and performs risk analysis based on the risk event impact results to obtain a comprehensive risk value. This effectively and accurately assesses the risk of an enterprise's business, facilitating qualitative risk assessment of the enterprise based on the assessment results.

[0093] refer to Figure 3 In some optional implementations of this embodiment, step S10 includes the following steps:

[0094] Step S101: pre-processing the business data to obtain standard business data, and extracting risk event entities and risk event attribute information from the standard business data;

[0095] In this embodiment, preprocessing of business data includes data cleaning (removing duplicate data, handling missing values, correcting erroneous data, etc.) and data conversion (converting business data into a standard format). Natural language processing (NLP) technology or rule matching methods are used to extract risk event entities (such as transaction anomalies, customer defaults, etc.) and related risk event attribute information (such as event time, location, and amount involved) from standard business data.

[0096] Step S102: performing a causal relationship analysis on the risk event entity and the risk event attribute information to obtain a causal relationship result;

[0097] In this embodiment, the causal relationship between risk event entities is analyzed based on natural language processing technology, wherein the causal relationship refers to the existence of a causal connection between two events or states, that is, one event (cause) leads to the occurrence of another event (result). Pre-written rules or patterns can be used to identify trigger words and iconic expressions in causal relationships. The rules can be based on language dependency features such as word meaning, grammar, and syntactic structure. By identifying causal conjunctions (such as "because", "so", "due to", etc.), causal analysis can also be performed on risk event entities and risk event attribute information based on causal analysis algorithms such as Bayesian networks, thereby effectively obtaining causal relationship results.

[0098] Step S103, determining whether the causal relationship result is a causal relationship;

[0099] In this embodiment, the causal relationship result includes the existence of a causal relationship and the non-existence of a causal relationship. By analyzing the causal relationship result, it is possible to effectively identify whether the causal relationship result indicates the existence of a causal relationship.

[0100] Step S104: if the causal relationship result is that the causal relationship exists, converting the risk event entity and the risk event attribute information into a knowledge graph node and a knowledge graph edge based on a knowledge representation method;

[0101] In this embodiment, based on a preset knowledge representation method (such as RDF (Resource Description Framework)), risk event entities and attribute information are converted into knowledge graph nodes and edges, where nodes represent risk event entities or attributes, and edges represent causal relationships or other association relationships between them.

[0102] Step S105: If the causal relationship result is that the causal relationship does not exist, the risk event entity and the risk event attribute information are marked as having no causal relationship;

[0103] In this embodiment, corresponding non-causal relationship tags can be added to risk event entities and risk event attribute information that do not have a causal relationship, so as to effectively distinguish risk event entities and risk event attribute information that do not have a causal relationship.

[0104] Step S106: construct the risk knowledge graph based on the knowledge graph nodes and the knowledge graph edges.

[0105] In this embodiment, the converted nodes and edges are integrated into a complete risk knowledge graph through a knowledge graph construction tool. The steps for constructing a risk knowledge graph include: creating a new graph database in the knowledge graph construction tool and configuring the database connection parameters, such as host name, port number, user name, and password; defining the node type based on the type and attributes of the risk event entity, and defining the edge type and the type and value range of the relationship attribute based on the relationship between the entities; using the import function or API provided by the tool to import the converted node and edge data into the graph database, and checking whether the graph database contains all the expected nodes and edges, and verifying whether the attributes of the nodes and edges are correct. After verification, the construction of the risk knowledge graph is completed.

[0106] This embodiment preprocesses the business data to obtain standard business data, extracts risk event entities and risk event attribute information from the standard business data, performs causal relationship analysis on the risk event entities and the risk event attribute information to obtain a causal relationship result, determines whether the causal relationship result indicates the existence of a causal relationship, and if so, converts the risk event entities and the risk event attribute information into knowledge graph nodes and knowledge graph edges based on a knowledge representation method; and constructs the risk knowledge graph based on the knowledge graph nodes and knowledge graph edges. This effectively obtains a risk knowledge graph constructed based on the risk event entities and risk event attribute information of the business data, facilitating the subsequent acquisition of risk transmission paths.

[0107] refer to Figure 4 In some optional implementations of this embodiment, step S20 includes the following steps:

[0108] Step S201: Obtain risk entities and risk entity relationships from the risk knowledge graph;

[0109] In this embodiment, the risk entity refers to the subject facing the risk, which can be an enterprise, an individual, a project, an asset, etc. The risk entity relationship includes the association relationship between risk entities (such as equity relationship, guarantee relationship, supply chain relationship, etc.), the relationship between risk events and risk entities (such as a company facing risk due to a certain event), and risk attributes (such as the type, level, and scope of impact of the risk).

[0110] Step S202: constructing a risk transmission model based on the risk entities and the risk entity relationships;

[0111] In this embodiment, the risk transmission model is used to define the rules and weights for risk transmission between entities. This can be done based on the entities and relationships in the risk knowledge graph. For example, when a company incurs credit risk, its subsidiaries may face risk due to their equity relationships. When a company provides guarantees for other companies, if the guaranteed company defaults, the guaranteeing company may also face risk due to the guarantee relationship. Based on the risk transmission rules and actual circumstances, each relationship is assigned a weight that represents the likelihood or intensity of risk transmission along that relationship. This weight can be determined through historical data analysis. The nodes, edges, and weights in the risk knowledge graph are imported into the model to define the risk transmission algorithm and process.

[0112] Step S203: searching for a transmission path in the risk knowledge graph based on a graph search algorithm to obtain an initial risk transmission path;

[0113] In this embodiment, the graph search algorithm uses the A* algorithm. This algorithm determines the starting entity for risk transmission, typically the source of the risk event, and sets the search endpoint, which can be a specific risk entity or a set of risk entities that meet certain conditions. The A* algorithm then searches the risk knowledge graph from this starting point until it reaches the endpoint or traverses all possible paths. All found transmission paths are recorded as initial risk transmission paths. These paths consist of a series of connected risk entities and the relationships between them.

[0114] Step S204: Calculate the risk value of the initial risk transmission path according to the transmission rules and weights defined by the risk transmission model;

[0115] In this embodiment, the transmission rules and corresponding weights of the relationships between risk entities are obtained from the risk transmission model. The risk value can be expressed as a function of all risk entities and their relationship weights on the path. For example, risk value = Σ(entity risk value * relationship weight), where Σ represents summation. The entity risk value can be determined based on the entity's risk type and level, which can be determined based on a preset risk entity mapping table. The relationship weight reflects the possibility or intensity of risk transmission between entities and can be pre-set. For each recorded risk transmission path, its risk value is calculated according to the defined risk value calculation formula to obtain the risk value of the initial risk transmission path.

[0116] Step S205, determining whether the risk value is greater than or equal to a preset risk threshold;

[0117] In this embodiment, the preset risk threshold is a judgment threshold set according to historical data. By comparing the calculated risk value with the preset risk threshold, it is effectively determined whether the risk value is greater than or equal to the preset risk threshold.

[0118] Step S206: If the risk value is greater than or equal to the preset risk threshold, marking the initial risk transmission path as the risk transmission path;

[0119] In this embodiment, marking is performed by adding a corresponding risk transmission path identifier to the initial risk transmission path. The risk transmission path identifier may be a specific number or text field information.

[0120] Step S207: If the risk value is less than the preset risk threshold, the initial risk transmission path is marked as a non-risk transmission path.

[0121] In this embodiment, the marking process is performed by adding a corresponding non-risk transmission path identifier to the initial risk transmission path. The non-risk transmission path identifier may be a specific number or text field information.

[0122] This embodiment obtains risk entities and risk entity relationships from the risk knowledge graph; constructs a risk transmission model based on the risk entities and risk entity relationships; searches for transmission paths in the risk knowledge graph based on a graph search algorithm to obtain an initial risk transmission path; calculates the risk value of the initial risk transmission path based on the transmission rules and weights defined in the risk transmission model; determines whether the risk value is greater than or equal to a preset risk threshold; if the risk value is greater than or equal to the preset risk threshold, marks the initial risk transmission path as the risk transmission path; if the risk value is less than the preset risk threshold, marks the initial risk transmission path as a non-risk transmission path. This effectively extracts the risk transmission path from the risk knowledge graph based on the transmission rules and weights of risks in risk entities, facilitating the subsequent acquisition of associated risk event information.

[0123] refer to Figure 5 In some optional implementations of this embodiment, step S30 includes the following steps:

[0124] Step S301: performing a matching query in the database according to the risk transmission path to obtain associated risk event information related to the target risk event;

[0125] In this embodiment, the database can be a pre-established risk transmission path knowledge graph or knowledge database, which includes information such as risk events, risk entities, the relationships between them, and the risk transmission path. Based on the identified risk transmission path, query conditions are defined, including the starting risk event, the risk entities and relationships along the path, etc. A matching query is performed in the database to find associated risk event information related to the target risk event, and all matching associated risk event information is extracted.

[0126] Step S302: performing association rule mining on the associated risk event information according to an association rule mining algorithm to obtain risk event association rules and risk event association strengths;

[0127] In this embodiment, the associated risk event information is first preprocessed to obtain standardized and valid associated risk event information. This preprocessing includes data deduplication, data cleaning, and format unification. An association rule mining algorithm is then used to mine the associated risk event information, identifying the association rules and association strengths between risk events. This association rule mining algorithm can employ the Apriori algorithm.

[0128] Step S303: constructing a risk event association network based on the risk event association rules and risk event association strengths;

[0129] In this embodiment, the structure of the risk event association network is defined based on the mined association rules and association strengths. This structure includes nodes (representing risk events) and edges (representing the associations between risk events). By creating a node for each risk event in the network graph and creating edges between nodes based on the association rules and association strengths, the risk event association network is effectively constructed, where the edge weights can represent the association strength.

[0130] Step S304: performing low-dimensional vector representation learning on the risk event association network to obtain a risk event embedding vector;

[0131] In this embodiment, a network embedding algorithm is used to learn a low-dimensional vector representation for each risk event within the risk event association network, thereby obtaining a risk event embedding vector. The network embedding algorithm can employ the Node2Vec algorithm. A low-dimensional risk representation model is trained using the Node2Vec algorithm and the risk event association network. The embedding vector for each risk event is then extracted from the trained low-dimensional risk representation model to obtain a risk event embedding vector. This embedding vector is typically a fixed-dimensional, continuous, real-valued vector that captures the structure and relationship information of risk events within the network.

[0132] Step S305: clustering the risk event embedding vectors according to a preset clustering algorithm to obtain risk event clusters;

[0133] In this embodiment, the DBSCAN clustering algorithm can be used to cluster risk event embedding vectors. Two key parameters of the DBSCAN algorithm are determined: eps (neighborhood radius) and minPts (minimum number of included points). For each point in the risk event embedding vector, the algorithm checks whether it has been visited. If the point has not been visited, the following steps are performed: a. Calculate the number of points in the eps neighborhood of the point. b. If the number of points in the neighborhood is greater than or equal to minPts, mark the point as a core point and create a new cluster. c. Recursively expand the cluster, adding all points in the neighborhood of the core point to the cluster and marking them as visited. d. If the number of points in the neighborhood is less than minPts, mark the point as a noise point. For each newly created core point, check whether the points in its neighborhood are also core points. If so, add these points and the points in their neighborhood to the cluster and mark them as visited. Repeat this process until the cluster cannot be expanded any further, effectively obtaining clustered risk event clusters.

[0134] Step S306 : Calculate the risk event impact degree and the risk event loss scale according to the risk event clusters, and use the risk event impact degree and the risk event loss scale as the risk event impact information.

[0135] In this embodiment, for each risk event cluster, the impact of the risk event can be obtained by averaging the impact of all risk events within the cluster. The impact can be a quantitative indicator, such as the probability of the event occurring, the scope of the impact, or the duration of the impact. The loss scale of the risk event can be obtained by averaging the loss scale of all risk events within the cluster. The loss scale can be a financial indicator, such as direct economic loss, indirect economic loss, or total loss.

[0136] This embodiment obtains associated risk event information related to the target risk event by performing a matching query in the database based on the risk transmission path; performs association rule mining on the associated risk event information according to an association rule mining algorithm to obtain risk event association rules and risk event association strength; constructs a risk event association network based on the risk event association rules and risk event association strength; performs low-dimensional vector representation learning on the risk event association network to obtain risk event embedding vectors; clusters the risk event embedding vectors according to a preset clustering algorithm to obtain risk event clusters; calculates the risk event impact degree and risk event loss scale based on the risk event clusters, and uses the risk event impact degree and risk event loss scale as the risk event impact information. This effectively calculates risk event impact information, including the risk event impact degree and loss scale, based on the risk event association rules and association strength, to facilitate subsequent training of a risk event impact assessment model.

[0137] Continue to refer Figure 6 In some optional implementations of this embodiment, step S40 includes the following steps:

[0138] Step S401: quantify the risk event impact information according to a preset quantification index rule to obtain the risk event impact index data;

[0139] In this embodiment, the preset quantitative index rules include direct economic losses, indirect economic losses, environmental impact, social impact, etc. According to the quantitative index rules, the risk event impact information is converted into a series of quantitative index data, thereby obtaining risk event impact index data.

[0140] Step S402 : training a pre-built initial impact assessment model according to the risk event impact indicator data to obtain the risk event impact assessment model.

[0141] In this embodiment, a risk event sample set is first obtained, comprising multiple risk events. Key features of each risk event in the sample set are extracted to obtain a feature vector for each risk event. An initial impact assessment model is constructed using the analytic hierarchy process (AHP). The feature vectors of the risk events are input into the initial impact assessment model and trained to map the feature vectors of each risk event into a corresponding impact score. This initial impact assessment model is then trained using risk event impact indicator data to obtain a risk event impact assessment model capable of outputting an impact score for each risk event.

[0142] This embodiment quantifies the risk event impact information according to preset quantitative indicator rules to obtain the risk event impact indicator data; and trains a pre-built initial impact assessment model based on the risk event impact indicator data to obtain the risk event impact assessment model. This effectively produces a risk event impact assessment model that can accurately assess the impact score of each risk event.

[0143] Continue to refer Figure 7 In some optional implementations of this embodiment, step S50 includes the following steps:

[0144] Step S501, constructing a risk transmission network topology structure according to the risk transmission path;

[0145] In this embodiment, each entity or system potentially affected by a risk is defined as a node in the network. A node can be a specific asset, department, process, or system component. Based on the identified risk transmission paths, connections (i.e., edges) are established between network nodes. These connections indicate that risks can be transmitted from one node to another through these paths. All nodes and connections are combined together to form a risk transmission network topology.

[0146] Step S502: setting a risk event probability distribution according to the risk event impact assessment model;

[0147] In this embodiment, the risk event impact assessment model is used to obtain characteristics such as the type, scale, and frequency of occurrence of the risk event. These characteristics will be used to determine the probability distribution of the risk event. Based on the characteristics of the risk event, an appropriate probability distribution type (such as normal distribution, Poisson distribution, exponential distribution, etc.) is selected to ensure that the selected distribution accurately reflects the probability of the risk event. In this embodiment, the above-mentioned probability distribution type can adopt the normal distribution. By setting the parameters of the selected probability distribution (such as mean, variance, shape parameters, etc.), the probability distribution of the risk event is obtained. Among them, these parameters will be used to generate a random sample of risk events.

[0148] Step S503: performing risk simulation evolution on the risk transmission network topology structure based on the Monte Carlo simulation method and the risk event probability distribution to obtain the risk status of the network nodes;

[0149] In this embodiment, the steps of risk simulation evolution based on the Monte Carlo simulation method include initializing the network state: before the simulation begins, the risk state of the network node is initialized to zero or a certain baseline value; generating risk event samples: randomly generating a series of risk event samples based on a set risk event probability distribution; simulating the risk transmission process: for each generated risk event sample, simulating its transmission process in the network, and calculating the accumulation and evolution of risk at each node based on the network topology and node properties (such as risk tolerance and recovery capacity); updating the network state: during the simulation process, updating the risk state of the network node in real time based on the results of risk transmission; repeating the simulation process: repeating the above simulation process multiple times, regenerating risk event samples and updating the network state each time; recording and analyzing results: after the simulation ends, recording the network state, node risk level, and other information within each time step, and performing statistical analysis on this information to understand the evolution pattern and trend of risk in the network. After multiple Monte Carlo simulations, the network node risk state of each network node at different time steps can be obtained. These states can be expressed as node risk value, risk level, or risk distribution, etc.

[0150] Step S504, calculating the cumulative risk impact according to the risk status of the network node to obtain a first impact assessment result;

[0151] In this embodiment, based on the risk status data of each node in the risk transmission network topology, the current risk level of each node is obtained. For all nodes in the network, based on their risk status and importance in the network (such as node connectivity, centrality, etc.), the cumulative impact of the risk in the entire network is calculated. The cumulative impact can be calculated by traversing the network and taking a weighted sum of the risk status of each node, wherein the weight in the weighted summation step can be determined according to the risk status of the network node. Based on the calculation result of the cumulative impact, the first impact assessment result of the risk event is obtained, and the first impact assessment result can be expressed as a specific numerical value, risk level or risk distribution, etc.

[0152] Step S505: Calculate the indirect risk impact based on the cascaded time-effect analysis method and the first impact assessment result to obtain a second impact assessment result;

[0153] In this embodiment, a cascading failure analysis method is used to study the correlations and chain reactions between risk events. This cascading failure analysis analyzes the correlations and dependencies between nodes in a network, identifying risk paths that may trigger chain reactions. Based on the identified correlations and chain reactions, the indirect impact of the risk event on the network is calculated. This indirect impact can include the spread of node failures, the number of affected nodes, the depth of risk propagation, and other factors. Based on the calculated indirect impact, a secondary impact assessment result for the risk event is obtained. This secondary impact assessment result can be expressed as a specific numerical value, risk level, or risk distribution.

[0154] Step S506: Fusing the first impact assessment result and the second impact assessment result to obtain the risk event impact result.

[0155] In this embodiment, a weighted average method can be used to merge the first impact assessment result and the second impact assessment result. The weighted average can be calculated based on the preset first impact weight and the second impact weight. The first impact weight and the second impact weight can be determined based on the relative importance of direct impact and indirect impact through expert judgment, historical data, or other methods to assign different weights to the first impact assessment result and the second impact assessment result. According to the weighted average method, the first impact assessment result and the second impact assessment result are weighted and summed to obtain a risk event assessment result that describes the overall impact of the risk event. The risk event assessment result can be expressed as a comprehensive risk value, risk level, or risk distribution, etc.

[0156] This embodiment constructs a risk transmission network topology structure according to the risk transmission path; sets the risk event probability distribution according to the risk event impact assessment model; performs risk simulation evolution on the risk transmission network topology structure based on the Monte Carlo simulation method and the risk event probability distribution to obtain the risk status of the network nodes; calculates the cumulative risk impact according to the network node risk status to obtain a first impact assessment result; calculates the indirect risk impact based on the cascade time analysis method and the first impact assessment result to obtain a second impact assessment result; and integrates the first impact assessment result and the second impact assessment result to effectively obtain a risk event impact result that comprehensively considers the cumulative risk impact and the indirect risk impact of the risk event, so as to facilitate subsequent risk analysis and processing.

[0157] Continue to refer Figure 8 In some optional implementations of this embodiment, step S60 includes the following steps:

[0158] S601, constructing a risk event judgment matrix based on the analytic hierarchy process, and calculating risk event weight coefficients based on the risk event judgment matrix;

[0159] In this embodiment, basic and related information about each risk event is obtained from a pre-established risk event database. For each risk event, the overall impact assessment results are obtained from the risk event database. The analytic hierarchy process (AHP) is then used to construct a pairwise risk event judgment matrix. The eigenvector corresponding to the maximum eigenvalue of the judgment matrix is ​​calculated. These eigenvectors are normalized by dividing each row by the sum of the elements in that row to obtain a normalized judgment matrix. The normalized judgment matrix is ​​then summed row-wise to obtain the weight of each risk event. These weights are then normalized to obtain the risk event weight coefficient for each risk event.

[0160] S602, obtaining a risk path event set according to the risk transmission path;

[0161] In this embodiment, a risk path event set is formed by following the risk conduction path in the risk conduction network and determining the risk events on each path.

[0162] S603: Perform weighted sum calculation on the risk path event set according to the risk event weight coefficient and the risk event impact result to obtain the comprehensive risk value.

[0163] In this embodiment, each risk event impact result is multiplied by the corresponding risk event weight coefficient, and then all the results are added together to obtain a comprehensive risk value.

[0164] This embodiment constructs a risk event judgment matrix based on the hierarchical analysis method, and calculates the risk event weight coefficient based on the risk event judgment matrix; obtains a risk path event set according to the risk transmission path; and performs a weighted sum calculation on the risk path event set according to the risk event weight coefficient and the risk event impact result, thereby effectively obtaining a comprehensive risk value that further considers the weight of the risk event in terms of risk, so as to provide reliable judgment information for the enterprise to conduct risk qualitative analysis.

[0165] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing related hardware via computer-readable instructions. The computer-readable instructions can be stored in a computer-readable storage medium, and when the program is executed, it can include the processes in the above-described method embodiments. The aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).

[0166] It should be understood that although the steps in the flowcharts of the accompanying drawings are shown in sequence as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some of the steps in the flowcharts of the accompanying drawings may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.

[0167] Further references Figure 9 , as a response to the above Figure 1 In order to realize the method shown in the figure, the present application provides an embodiment of a business risk assessment device. Figure 1 Corresponding to the method embodiment shown, the device can be specifically applied to various electronic devices.

[0168] like Figure 9 As shown, the business risk assessment device 700 of this embodiment includes: a graph construction module 701, a path acquisition module 702, an impact analysis module 703, a model training module 704, a risk evolution module 705, and a risk analysis module 706. Among them:

[0169] A graph construction module 701 is used to obtain business data and construct a risk knowledge graph based on the business data;

[0170] A path acquisition module 702 is configured to acquire risk transmission paths in the risk knowledge graph based on a graph search algorithm;

[0171] Impact analysis module 703, configured to obtain associated risk event information from a database according to the risk transmission path, and analyze the associated risk event information according to a data mining algorithm to obtain risk event impact information;

[0172] A model training module 704 is configured to quantify the risk event impact information and train a risk event impact assessment model based on the quantified risk event impact indicator data;

[0173] The risk evolution module 705 is configured to simulate and evolve the risk according to the risk transmission path and the risk event impact assessment model to obtain the risk event impact result;

[0174] The risk analysis module 706 is used to perform risk analysis based on the impact results of the risk event to obtain a comprehensive risk value.

[0175] This embodiment, by employing the aforementioned business risk assessment device, can acquire business data, construct a risk knowledge graph based on the business data, obtain risk transmission paths from the risk knowledge graph based on a graph search algorithm, obtain associated risk event information from a database based on the risk transmission paths, analyze the associated risk event information using a data mining algorithm to obtain risk event impact information, quantify the risk event impact information, and train a risk event impact assessment model based on the quantified risk event impact indicator data, perform risk simulation evolution based on the risk transmission paths and the risk event impact assessment model to obtain risk event impact results, and perform risk analysis based on the risk event impact results to obtain a comprehensive risk value. This effectively and accurately assesses the risk of an enterprise's business, facilitating qualitative risk assessment of the enterprise based on the assessment results.

[0176] To solve the above technical problems, the present application also provides a computer device. Figure 10 , Figure 10 This is a basic structural block diagram of the computer device in this embodiment.

[0177] The computer device 8 includes a memory 81, a processor 82, and a network interface 83 that are interconnected through a system bus. It should be noted that the figure only shows a computer device 8 with components 81-83, but it should be understood that it is not required to implement all the components shown, and more or fewer components can be implemented instead. Among them, those skilled in the art can understand that the computer device here is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.

[0178] The computer device may be a desktop computer, notebook computer, PDA, cloud server, etc. The computer device may interact with the user via a keyboard, mouse, remote control, touchpad, or voice control device.

[0179] The memory 81 includes at least one type of readable storage medium, including flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 81 may be an internal storage unit of the computer device 8, such as the hard disk or memory of the computer device 8. In other embodiments, the memory 81 may also be an external storage device of the computer device 8, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash memory card, etc. equipped on the computer device 8. Of course, the memory 81 may also include both the internal storage unit of the computer device 8 and its external storage device. In this embodiment, the memory 81 is generally used to store the operating system and various application software installed on the computer device 8, such as computer-readable instructions of the business risk assessment method. In addition, the memory 81 can also be used to temporarily store various types of data that have been output or are to be output.

[0180] In some embodiments, the processor 82 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip. The processor 82 is generally used to control the overall operation of the computer device 8. In this embodiment, the processor 82 is used to execute computer-readable instructions stored in the memory 81 or process data, such as computer-readable instructions for executing the business risk assessment method.

[0181] The network interface 83 may include a wireless network interface or a wired network interface. The network interface 83 is generally used to establish a communication connection between the computer device 8 and other electronic devices.

[0182] By employing the aforementioned computer device, this embodiment can acquire business data, construct a risk knowledge graph based on the business data, acquire risk transmission paths from the risk knowledge graph based on a graph search algorithm, acquire associated risk event information from a database based on the risk transmission paths, analyze the associated risk event information using a data mining algorithm to obtain risk event impact information, quantify the risk event impact information, and train a risk event impact assessment model based on the quantified risk event impact indicator data, perform risk simulation evolution based on the risk transmission paths and the risk event impact assessment model to obtain risk event impact results, and perform risk analysis based on the risk event impact results to obtain a comprehensive risk value. This effectively and accurately assesses the risk of an enterprise's business, facilitating qualitative risk assessment of the enterprise based on the assessment results.

[0183] The present application also provides another embodiment, namely, providing a computer-readable storage medium, which stores computer-readable instructions, and the computer-readable instructions can be executed by at least one processor to enable the at least one processor to perform the steps of the business risk assessment method as described above.

[0184] By using the aforementioned computer-readable storage medium, this embodiment can acquire business data, construct a risk knowledge graph based on the business data, acquire risk transmission paths from the risk knowledge graph based on a graph search algorithm, acquire associated risk event information from a database based on the risk transmission paths, analyze the associated risk event information using a data mining algorithm to obtain risk event impact information, quantify the risk event impact information, and train a risk event impact assessment model based on the quantified risk event impact indicator data, perform risk simulation evolution based on the risk transmission paths and the risk event impact assessment model to obtain risk event impact results, and perform risk analysis based on the risk event impact results to obtain a comprehensive risk value. This effectively and accurately assesses the risk of an enterprise's business, facilitating qualitative risk assessment of the enterprise based on the assessment results.

[0185] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present application.

[0186] Obviously, the embodiments described above are only some of the embodiments of the present application, rather than all of the embodiments. The preferred embodiments of the present application are given in the accompanying drawings, but they do not limit the patent scope of the present application. The present application can be implemented in many different forms. On the contrary, the purpose of providing these embodiments is to make the understanding of the disclosure of the present application more thorough and comprehensive. Although the present application has been described in detail with reference to the aforementioned embodiments, for those skilled in the art, it is still possible to modify the technical solutions described in the aforementioned specific embodiments, or to make equivalent replacements for some of the technical features therein. Any equivalent structure made using the contents of the present application specification and the accompanying drawings, directly or indirectly used in other related technical fields, is also within the scope of patent protection of the present application.

[0187] The non-Company software tools or components appearing in the embodiments of this application are merely examples and do not represent actual use.

Claims

1. A business risk assessment method, characterized in that: The steps include: Acquire business data and construct a risk knowledge graph based on the business data; Obtaining risk transmission paths in the risk knowledge graph based on a graph search algorithm; Acquire associated risk event information in a database according to the risk transmission path, and analyze the associated risk event information according to a data mining algorithm to obtain risk event impact information; Quantifying the risk event impact information and training a risk event impact assessment model based on the quantified risk event impact indicator data; Perform risk simulation evolution according to the risk transmission path and the risk event impact assessment model to obtain risk event impact results; Conduct risk analysis based on the impact of the risk event to obtain a comprehensive risk value; The step of acquiring associated risk event information in a database according to the risk transmission path, and analyzing the associated risk event information according to a data mining algorithm to obtain risk event impact information specifically includes: Perform a matching query in the database according to the risk transmission path to obtain associated risk event information related to the target risk event; Performing association rule mining on the associated risk event information according to an association rule mining algorithm to obtain risk event association rules and risk event association strength; Constructing a risk event association network based on the risk event association rules and risk event association strengths; Performing low-dimensional vector representation learning on the risk event association network to obtain a risk event embedding vector; Clustering the risk event embedding vectors according to a preset clustering algorithm to obtain risk event clusters; Calculating the risk event impact degree and the risk event loss scale based on the risk event clusters, and using the risk event impact degree and the risk event loss scale as the risk event impact information; The step of performing risk simulation evolution according to the risk transmission path and the risk event impact assessment model to obtain the risk event impact result specifically includes: Constructing a risk transmission network topology structure according to the risk transmission path; Setting the risk event probability distribution according to the risk event impact assessment model; Performing risk simulation evolution on the risk transmission network topology structure based on the Monte Carlo simulation method and the risk event probability distribution to obtain the risk status of the network nodes; Calculate the cumulative risk impact based on the risk status of the network node to obtain a first impact assessment result; Calculate the indirect impact of the risk based on the cascade time effect analysis method and the first impact assessment result to obtain a second impact assessment result; The first impact assessment result and the second impact assessment result are integrated to obtain the risk event impact result.

2. The business risk assessment method according to claim 1, characterized in that: The step of obtaining business data and constructing a risk knowledge graph based on the business data specifically includes: Preprocessing the business data to obtain standard business data, and extracting risk event entities and risk event attribute information from the standard business data; Performing a causal relationship analysis on the risk event entity and the risk event attribute information to obtain a causal relationship result; Determine whether the causal relationship result is a causal relationship; If the causal relationship result is that the causal relationship exists, converting the risk event entity and the risk event attribute information into a knowledge graph node and a knowledge graph edge based on a knowledge representation method; The risk knowledge graph is constructed based on the knowledge graph nodes and the knowledge graph edges.

3. The business risk assessment method according to claim 1, characterized in that: The step of obtaining the risk transmission path in the risk knowledge graph based on the graph search algorithm specifically includes: Obtaining risk entities and risk entity relationships from the risk knowledge graph; Constructing a risk transmission model based on the risk entities and the risk entity relationships; Conducting a transmission path search in the risk knowledge graph based on a graph search algorithm to obtain an initial risk transmission path; Calculate the risk value of the initial risk transmission path according to the transmission rules and weights defined by the risk transmission model; Determining whether the risk value is greater than or equal to a preset risk threshold; If the risk value is greater than or equal to the preset risk threshold, the initial risk transmission path is marked as the risk transmission path.

4. The business risk assessment method according to claim 1, characterized in that: The step of quantifying the risk event impact information and training the risk event impact assessment model based on the quantified risk event impact indicator data specifically includes: Quantifying the risk event impact information according to preset quantitative indicator rules to obtain the risk event impact indicator data; The pre-built initial impact assessment model is trained according to the risk event impact indicator data to obtain the risk event impact assessment model.

5. The business risk assessment method according to claim 1, characterized in that: The step of performing risk analysis based on the impact results of the risk event to obtain a comprehensive risk value specifically includes: Constructing a risk event judgment matrix based on the analytic hierarchy process, and calculating risk event weight coefficients based on the risk event judgment matrix; Acquire a risk path event set according to the risk transmission path; The risk path event set is weighted and summed according to the risk event weight coefficient and the risk event impact result to obtain the comprehensive risk value.

6. A business risk assessment device, characterized in that: include: A graph construction module, used to obtain business data and construct a risk knowledge graph based on the business data; A path acquisition module, configured to acquire risk transmission paths in the risk knowledge graph based on a graph search algorithm; An impact analysis module is used to obtain related risk event information in a database according to the risk transmission path, and analyze the related risk event information according to a data mining algorithm to obtain risk event impact information; A model training module is used to quantify the risk event impact information and train a risk event impact assessment model based on the quantified risk event impact indicator data; A risk evolution module, configured to simulate and evolve the risk according to the risk transmission path and the risk event impact assessment model, and obtain the risk event impact result; A risk analysis module is used to perform risk analysis based on the impact of the risk event and obtain a comprehensive risk value; The impact analysis module includes: a matching query unit, configured to perform a matching query in the database according to the risk transmission path to obtain associated risk event information related to the target risk event; A rule mining unit is used to perform association rule mining on the associated risk event information according to an association rule mining algorithm to obtain risk event association rules and risk event association strength; A network construction unit, configured to construct a risk event association network based on the risk event association rules and risk event association strengths; a representation learning unit, configured to perform low-dimensional vector representation learning on the risk event association network to obtain a risk event embedding vector; A risk clustering unit, configured to cluster the risk event embedding vectors according to a preset clustering algorithm to obtain risk event clusters; an information determining unit, configured to calculate the risk event impact degree and the risk event loss scale based on the risk event clusters, and use the risk event impact degree and the risk event loss scale as the risk event impact information; The risk evolution module includes: A structure construction unit, configured to construct a risk conduction network topology structure according to the risk conduction path; A probability setting unit, configured to set a risk event probability distribution according to the risk event impact assessment model; A simulation evolution unit, configured to perform risk simulation evolution on the risk transmission network topology structure based on a Monte Carlo simulation method and the risk event probability distribution, to obtain a network node risk state; A first impact assessment unit, configured to calculate a cumulative risk impact according to the risk status of the network node to obtain a first impact assessment result; A second impact assessment unit is configured to calculate the indirect impact of the risk based on the cascade time effect analysis method and the first impact assessment result to obtain a second impact assessment result; A structure fusion unit is used to fuse the first impact assessment result and the second impact assessment result to obtain the risk event impact result.

7. A computer device, characterized in that: The method comprises a memory and a processor, wherein the memory stores computer-readable instructions, and the processor implements the steps of the business risk assessment method according to any one of claims 1 to 5 when executing the computer-readable instructions.

8. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the business risk assessment method according to any one of claims 1 to 5.