System and method for generating compliance report

Through big data and artificial intelligence technology, compliance evidence is automatically extracted and analyzed and compliance reports are generated, which solves the problems of inefficient and incomplete coverage of compliance reports in the existing technology, and achieves efficient and automated compliance report generation.

CN119940927APending Publication Date: 2025-05-06SUZHOU SHUCHANG CHUANGHE TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510022321.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-07
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The existing technology faces challenges such as high manpower and material consumption, complex data collection, dynamic regulatory requirements, and full participation of stakeholders when generating compliance reports, resulting in inefficient report generation and incomplete coverage.

Method used

Using big data and artificial intelligence means, through standardized analysis modules, data collection and processing modules and data analysis application modules, compliance evidence is automatically extracted and reported. The system monitors enterprise operation data, extracts compliance-related data based on algorithm rules, and realizes automatic saving and rapid report generation.

Benefits of technology

It improves the degree of automation of compliance report generation and extensive data coverage, reduces the need for manual intervention, improves report generation efficiency, and ensures full coverage of regulatory requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119940927A_ABST
    Figure CN119940927A_ABST
Patent Text Reader

Abstract

The invention discloses a compliance report generation system and method, which can monitor data streams in an enterprise operation process, extract compliance-related data based on algorithm rules for analysis, realize automatic storage and collection of compliance evidence data, and prompt and match a rectification scheme when finding compliance potential risk points. The compliance report can be quickly generated as required, the automation degree is high, the data coverage is wide, and the compliance report generation efficiency is high.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a compliance report generation system and method, and in particular to a compliance report generation system and method with high automation, complete coverage and simple operation. Background Art

[0002] Compliance is a goal that companies must adhere to in their daily operations. A compliance report is a report submitted by a company to the regulatory authorities to prove that it meets compliance requirements. The report needs to submit various relevant materials to prove that regulatory requirements have been met and that the specifications (or evidence) have been met. For example, the data protection specification requires regular backup of core data, so the compliance report needs to submit a backup plan and various execution records to prove that the backup work is performed regularly.

[0003] There are many difficulties in generating compliance reports. The complexity and rapid changes in the legal and regulatory environment require enterprises to have professional compliance personnel to cope with them. The high cost of compliance is especially for enterprises with limited resources. The complexity of data collection requires a large amount of data collection for compliance reports, which is a complex and time-consuming process. The dynamic nature of regulatory requirements and the constant changes in the regulatory environment require enterprises to be able to adapt agilely, which is a challenge for enterprises. The full participation of stakeholders is required. The preparation of compliance reports requires the full participation of stakeholders, which may sometimes be difficult to achieve. These difficulties together constitute the challenges that enterprises need to overcome when generating compliance reports. The most troublesome step in this process, which consumes the most manpower and material resources, is the collection of these evidences. For example, in the compliance department of a leading financial company, each compliance report requires multiple people to prepare for a month, and it is not just the people in the compliance department who participate. People in other departments responsible for compliance also need to submit the information related to the part of the work they are responsible for, and finally generate a complete compliance report. In addition, due to the workload, many inspections are carried out by random inspections. For example, when checking whether users have violated the rules by directly jumping across the bastion host, the inspection person-month faces tens of millions of operation records per month. During the inspection process, only a small number of samples can be randomly selected for spot checks, and the number of samples selected is less than 1%. This type of inspection cannot see the full picture and is likely to allow illegal operations to escape supervision.

[0004] The most commonly used method is a manual operation-based solution. This type of solution is to arrange specific people to analyze the specifications, collect evidence, and seek help from other relevant personnel within the company when necessary. The biggest problem with this type of solution is that it consumes a lot of manpower and material resources. Whether it is evidence extraction or report generation, it will consume a lot of man-hours. Therefore, it is necessary to propose an improvement to overcome the defects of the existing technology. Summary of the invention

[0005] The purpose of the present invention is to solve the problems in the prior art and use big data and artificial intelligence to complete evidence extraction and report generation. The system monitors a large number of related business processes in the background, finds evidence related to compliance reports through log analysis, state change discovery and other means, and automatically saves them; when necessary, it will quickly and automatically generate compliance reports according to the requirements of the regulations.

[0006] The present invention provides a compliance report generation system, including a specification parsing module, a data collection and processing module and a data analysis application module; the specification parsing module is used to parse the enterprise compliance standards, and the parsed enterprise compliance standards are scenarios that can be quantified and analyzed; the data collection and processing module is used to collect enterprise operation data and parse the data and collect compliance evidence data; the data analysis application module generates evidence discovery and extraction rules based on the scenarios parsed by the specification parsing module, and passes the evidence discovery and extraction rules to the data collection and processing module for compliance evidence data collection; the data analysis application module also analyzes and processes the compliance evidence data collected by the data collection and processing module, generates a compliance report and provides a real-time compliance monitoring panel.

[0007] As a detailed technical solution, the specification parsing module is the top layer of the system, the data collection and processing module is the bottom layer of the system, and the data analysis application module is the middle layer of the system that connects the specification parsing module and the data collection and processing module in series.

[0008] As a detailed technical solution, the specification parsing module, data collection and processing module and data analysis application module all include a computer processor with data processing capabilities, a memory with data storage capabilities and an input and output device for data input and output.

[0009] The present invention also provides a compliance report generation method, comprising the following steps: S1, compliance specification analysis: analyzing the enterprise compliance-related standards and specifications to form a compliance business scenario that can be quantified and analyzed; S2, formulating enterprise compliance evidence discovery and extraction rules: generating enterprise compliance evidence discovery and extraction rules based on the compliance business scenario formed in step S1; S3, operation data collection and compliance evidence data collection: collecting enterprise operation data and performing analysis and parsing, and discovering, extracting and preserving compliance evidence data related to enterprise compliance according to the enterprise compliance evidence discovery and extraction rules generated in step S2; S4, compliance evidence data analysis and processing: analyzing and processing the compliance evidence data to determine the completion of the compliance business scenario formed in step S1, analyzing and discovering potential compliance risk points and matching rectification plans; S5, compliance report generation: generating a compliance report based on the compliance evidence data analysis and processing and providing a real-time compliance monitoring panel.

[0010] As a preferred technical solution, the corporate compliance-related standards and specifications in step S1 include international standards, national standards, industry standards, corporate standards and system requirements related to corporate compliance.

[0011] As a preferred technical solution, the enterprise compliance evidence discovery and extraction rules generated in step S2 are matching rules automatically generated by the system based on the log format.

[0012] As a preferred technical solution, the enterprise operation data in step S3 includes monitoring data, operation logs, business processes and company policies.

[0013] As a preferred technical solution, step S4 analyzes and processes the compliance evidence data using a large language model.

[0014] As a preferred technical solution, the compliance report is generated on demand in step S5, and the compliance report is generated according to user requirements.

[0015] As a preferred technical solution, the compliance report generated in step S5 is specifically as follows: starting from the compliance business scenario, the corresponding compliance evidence data is listed according to each compliance business scenario, and the compliance evidence data is used to prove the achievement of the compliance business scenario; if it is found that the achievement of a compliance business scenario cannot be judged based on the compliance evidence data, the corresponding scenario will be output to relevant personnel for further processing; after the achievement of all compliance business scenarios is supported by compliance proof data, content is generated according to the compliance clauses corresponding to the compliance business scenario to form a complete compliance report.

[0016] A compliance report generation system and method of the present invention can monitor the data flow during the operation of an enterprise, extract compliance-related data based on algorithm rules for analysis, automatically save and collect compliance evidence data, and provide prompts and match rectification plans when potential compliance risk points are found. Compliance reports can be quickly generated on demand, with a high degree of automation, wide data coverage, and high efficiency in generating compliance reports. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 A system block diagram of a specific implementation of a compliance report generation system of the present invention; Figure 2 The present invention is a flowchart of a compliance report generation method. DETAILED DESCRIPTION

[0018] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0019] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. The singular forms "a", "said" and "the" used in the embodiments of the present invention and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings, and "multiple" generally includes at least two, but does not exclude the inclusion of at least one.

[0020] It should be understood that the term "and / or" used in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.

[0021] As used herein, the words "if" and "if" may be interpreted as "at the time of" or "when" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrases "if it is determined" or "if (stated condition or event) is detected" may be interpreted as "when it is determined" or "in response to determining" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)", depending on the context.

[0022] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a product or system including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such a product or system. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the product or system including the elements.

[0023] like Figure 1 The figure shows a specific implementation of a compliance report generation system of the present invention. A compliance report generation system of this embodiment includes a specification parsing module, a data collection and processing module, and a data analysis application module.

[0024] The specification parsing module is used to parse the enterprise compliance standards, and the parsed enterprise compliance standards are scenarios that can be quantified and analyzed. The specification parsing module analyzes international standards, national standards, industry standards and enterprise standards, and parses each clause into a scenario that can be quantified and analyzed. The specification parsing module of this embodiment parses the following clauses of the "Standard for Information System Backup Capability of Securities and Futures Business Institutions": used to resist major disasters such as earthquakes. When a major disaster such as an earthquake occurs in the city where the information system of the business institution is located, it may cause the unavailability of urban infrastructure such as electricity and communications, and serious damage to office buildings, computer rooms and information systems. Under normal circumstances, it is necessary to switch to an off-site disaster backup center to resume operation. The "Standard" puts forward the requirements for major disaster response capabilities at the highest level six. Considering that after a major disaster occurs, it is necessary to arrange staff to go to the off-site disaster backup center, enable the backup system, and resume business operations, the "Standard" requires that the system recovery work be completed within 7 days. The sixth level of major disaster response capabilities requires: 1. The information system recovery time objective RTO is less than 7 days; 2. The information system recovery point objective RPO is less than 12 hours; 3. The backup system has the processing capacity to meet business needs. After analysis, the following 7 compliance business scenarios are formed: (1) Establish a disaster recovery plan: This is a document that contains detailed steps to respond to major disasters and ensure that information systems can be restored and operated in a timely manner after a disaster.

[0025] (2) Arrange a disaster backup center: You need to select and rent a disaster backup center with a relatively safe location and complete facilities, and build a backup system there.

[0026] (3) Regularly back up data: Critical data needs to be backed up regularly and stored in a disaster backup center to ensure data security.

[0027] (4) Testing the disaster recovery plan: The feasibility of the disaster recovery plan needs to be tested regularly to ensure that business operations can be smoothly restored when a major disaster occurs.

[0028] (5) Ensure that the backup system has the processing power to meet business needs: The backup system needs to have sufficient processing power to meet business needs and ensure that the business can operate normally during the recovery period.

[0029] (6) Establish an emergency response mechanism: An emergency response mechanism needs to be established, including preparations in terms of personnel, equipment, and processes, to ensure a rapid response when a major disaster occurs.

[0030] (7) Establish a disaster recovery team: It is necessary to establish a disaster recovery team to ensure that they can quickly assemble and collaborate to complete disaster recovery work when a disaster occurs.

[0031] The seven compliance business scenarios formed are more operational and controllable than the original text.

[0032] The data collection and processing module is used to collect enterprise operation data, analyze the data, and collect compliance evidence data. The collected enterprise operation data includes monitoring data, logs, processes, company policies, etc. While collecting data, the data collection and processing module also analyzes the data and discovers, extracts, and saves evidence based on the rules pushed by the upper layer.

[0033] The data analysis application module generates evidence discovery and extraction rules based on the scenarios analyzed by the specification parsing module, and passes the evidence discovery and extraction rules to the data collection and processing module to collect compliance evidence data; the data analysis application module also analyzes and processes the compliance evidence data collected by the data collection and processing module, generates a compliance report and provides a real-time compliance monitoring panel.

[0034] In a compliance report generation system of this embodiment, the specification analysis module is the top layer of the system, the data collection and processing module is the bottom layer of the system, and the data analysis application module is the middle layer of the system that connects the specification analysis module and the data collection and processing module in series. The specification analysis module, the data collection and processing module, and the data analysis application module all include a computer processor with data processing capabilities, a memory with data storage capabilities, and an input and output device for data input and output.

[0035] like Figure 2 As shown, this embodiment also provides a compliance report generation method, comprising the following steps: S1. Compliance and Regulation Analysis: Analyze the enterprise's compliance-related standards and regulations to form compliance business scenarios that can be quantified and analyzed; S2. Formulate enterprise compliance evidence discovery and extraction rules: Generate enterprise compliance evidence discovery and extraction rules based on the compliance business scenario formed in step S1; S3. Operational data collection and compliance evidence data collection: Collect enterprise operational data and perform analysis and analysis, and discover, extract and save compliance evidence data related to enterprise compliance according to the enterprise compliance evidence discovery and extraction rules generated in step S2; S4. Compliance evidence data analysis and processing: Analyze and process the compliance evidence data to determine the completion status of the compliance business scenarios formed in step S1, analyze and discover potential compliance risk points and match rectification plans; S5. Compliance report generation: Compliance evidence data analysis and processing generates compliance reports and provides a real-time compliance monitoring panel.

[0036] Among them, the corporate compliance-related standards and specifications mentioned in step S1 include international standards, national standards, industry standards, corporate standards and system requirements related to corporate compliance.

[0037] The enterprise compliance evidence discovery and extraction rules generated in step S2 are matching rules automatically generated by the system based on the log format. In specific applications, the generation of enterprise compliance evidence discovery and extraction rules is completed by human and system AI. Human can provide the storage location of enterprise compliance-related standards and specifications, and the system AI automatically generates matching rules based on the log format. After the enterprise compliance evidence discovery and extraction rules are generated, they are pushed to the data collection and processing module for operation data collection and compliance evidence data collection in step S3.

[0038] The enterprise operation data in step S3 includes monitoring data, operation logs, business processes and company policies.

[0039] Step S4 uses a large language model to analyze and process the compliance evidence data. During the compliance evidence data analysis process, the main analysis objectives are: (1) determine whether the task of a certain scenario has been completed; (2) whether there are potential risk points in the company's operations; (3) if there are risks, how to rectify them. Relevant information will also be pushed to staff.

[0040] The generation of compliance reports in step S5 is performed on demand, and compliance reports are generated according to user requirements. The generation of compliance reports in step S5 is specifically as follows: starting from the compliance business scenario, the corresponding compliance evidence data is listed according to each compliance business scenario, and the compliance evidence data is used to prove that the compliance business scenario has been achieved; if it is found that the achievement of a compliance business scenario cannot be judged based on the compliance evidence data, the corresponding scenario will be output to relevant personnel for further processing; after the achievement of all compliance business scenarios is supported by compliance proof data, the content is generated according to the compliance clauses corresponding to the compliance business scenario to form a complete compliance report. The purpose of the real-time compliance monitoring panel in step S5 is to present the potential compliance risks discovered during the compliance evidence analysis and processing process. Relevant personnel can analyze and process the content of the real-time compliance monitoring panel to enhance the compliance of the company's operations.

[0041] Compared with the traditional manual compliance report generation, the compliance report generation system and method of the present invention has the following advantages: 1. Real-time data collection, quick response when needed: A compliance report generation system and method of the present invention continuously monitors the data streams generated by various operations, extracts and analyzes compliance-related data based on algorithms. If it is valid evidence, it will be retained. Once a compliance report is needed, a compliance report at the current time point can be generated quickly (in minutes), which is a leap forward compared to the traditional manual process of one month.

[0042] 2. High coverage completeness: The compliance report generation system and method of the present invention analyzes all relevant data, which is a full analysis mechanism without omissions or omissions. However, manual solutions will adopt spot checks due to cost considerations and cannot provide full coverage. Therefore, risks that can be discovered manually can definitely be discovered by our technology, but on the contrary, risks that can be discovered by our manual solutions may not be discovered by us.

[0043] 3. Good data security: After collecting data, the compliance report generation system and method of the present invention will only present data related to the compliance report, and can also perform desensitization if sensitive data is involved. Traditional manual solutions need to search for various sensitive data in the process of finding data, and because many people are involved, it is difficult to perform prior authority management, resulting in the inability to ensure data security.

[0044] 4. The manual solution requires high capabilities of the relevant personnel, including understanding of regulations, data analysis capabilities, and evidence extraction methods, and the entry threshold is high. However, the compliance report generation system and method of the present invention completely replaces manual work with technology. Only in the initial stage of deployment, senior personnel set up the scenarios and rules, and the subsequent process is basically fully automatic and does not require manual intervention, which greatly reduces the requirements on human capabilities.

[0045] The above description is only a preferred embodiment of the present invention and is not intended to limit the scope of implementation of the present invention. That is, all equivalent changes and modifications made according to the content of the patent application scope of the present invention should belong to the technical scope of the present invention.

Claims

1. A compliance report generation system, characterized in that: It includes specification parsing module, data collection and processing module and data analysis application module; The specification parsing module is used to parse the enterprise compliance standards, and the parsed enterprise compliance standards are scenarios that can be quantified and analyzed; The data collection and processing module is used to collect enterprise operation data and analyze the data and collect compliance evidence data; The data analysis application module generates evidence discovery and extraction rules based on the scenarios analyzed by the specification analysis module, and transmits the evidence discovery and extraction rules to the data collection and processing module for compliance evidence data collection; The data analysis application module also analyzes and processes the compliance evidence data collected by the data collection and processing module, generates a compliance report and provides a real-time compliance monitoring panel.

2. A compliance report generation system according to claim 1, characterized in that: The specification parsing module is the top layer of the system, the data collection and processing module is the bottom layer of the system, and the data analysis application module is the middle layer of the system that connects the specification parsing module and the data collection and processing module in series.

3. A compliance report generation system according to claim 1 or 2, characterized in that: The specification parsing module, data collection and processing module and data analysis application module all include a computer processor with data processing capabilities, a memory with data storage capabilities and an input and output device for data input and output.

4. A compliance report generation method, characterized in that: The following steps are involved: S1. Compliance and Regulation Analysis: Analyze the enterprise's compliance-related standards and regulations to form compliance business scenarios that can be quantified and analyzed; S2. Formulate enterprise compliance evidence discovery and extraction rules: Generate enterprise compliance evidence discovery and extraction rules based on the compliance business scenario formed in step S1; S3. Operational data collection and compliance evidence data collection: Collect enterprise operational data and perform analysis and analysis, and discover, extract and save compliance evidence data related to enterprise compliance according to the enterprise compliance evidence discovery and extraction rules generated in step S2; S4. Compliance evidence data analysis and processing: Analyze and process the compliance evidence data to determine the completion status of the compliance business scenarios formed in step S1, analyze and discover potential compliance risk points and match rectification plans; S5. Compliance report generation: Compliance evidence data analysis and processing generates compliance reports and provides a real-time compliance monitoring panel.

5. A compliance report generation method according to claim 4, characterized in that: The corporate compliance-related standards and specifications described in step S1 include international standards, national standards, industry standards, corporate standards and system requirements related to corporate compliance.

6. A compliance report generation method according to claim 4, characterized in that: The enterprise compliance evidence discovery and extraction rules generated in step S2 are matching rules automatically generated by the system based on the log format.

7. A compliance report generation method according to claim 4, characterized in that: The enterprise operation data in step S3 includes monitoring data, operation logs, business processes and company policies.

8. A compliance report generation method according to claim 4, characterized in that: Step S4 analyzes and processes the compliance evidence data using a large language model.

9. A compliance report generation method according to claim 4, characterized in that: The compliance report is generated on demand in step S5, and is generated according to user requirements.

10. A compliance report generation method according to claim 1, characterized in that: The specific steps of generating a compliance report in step S5 are as follows: starting from the compliance business scenario, the corresponding compliance evidence data is listed according to each compliance business scenario, and the compliance evidence data is used to prove that the compliance business scenario has been achieved; if it is found that the achievement of a compliance business scenario cannot be judged based on the compliance evidence data, the corresponding scenario will be output to relevant personnel for further processing; after the achievement of all compliance business scenarios is supported by compliance evidence data, the content will be generated according to the compliance clauses corresponding to the compliance business scenario to form a complete compliance report.

Citation Information

Patent Citations

  • Automatic generation and analysis system for law compliance report based on artificial intelligence

    CN117522322A