Al-driven enterprise risk management system and method
Through the AI-driven enterprise risk management system, the defects of responsibility judgment and path construction in the existing technology are solved, the dynamic adaptability of responsibility levels and the precise identification of behavioral conflicts are achieved, and the decision-making support capabilities and structural performance of enterprise risk management are improved.
Patent Information
- Application Number
- CN202510563380.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-08-08
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing enterprise risk management system has defects in responsibility judgment, behavioral intervention identification, path construction and result display, which is difficult to reflect the impact of actual intervention density on the responsibility level, lacks the ability to judge behavioral direction conflicts and timely overlap, and there is redundancy or logical conflict in path generation, which is difficult to support the needs of multi-dimensional analysis, affecting the company's response speed and handling accuracy to emergencies.
Using an AI-driven enterprise risk management system, through the responsibility weight analysis module, behavior conflict identification module, path filtering generation module and sequence priority module, we identify the intervention time period of the responsible subject, determine the responsibility level, identify behavior conflicts, filter and reorganize the paths, combine the coverage density sorting, generate priority path sequences, and build a stage-based enterprise responsibility risk path map.
The hierarchical mapping of responsibility division is realized, the accuracy and immediacy of conflict perception is improved, the structural effectiveness and logical rationality of paths are enhanced, the decision-making support for risk processing and the structural expression of results are enhanced, and the subdivided depth of enterprise risk identification and decision-making support for path planning are enhanced.
Smart Images

Figure CN120450435A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of enterprise risk management, and in particular to an AI-driven enterprise risk management system and method. Background Art
[0002] The technical field of enterprise risk management encompasses a range of strategies, processes, and tools organizations employ in the face of uncertainty. These strategies aim to identify, assess, address, and monitor potential risks that could impact the achievement of a company's strategic objectives. Core elements include risk identification, risk assessment, risk response and control, risk communication, and ongoing risk monitoring. Enterprise risk management is widely used in financial risk management, compliance risk control, operational risk prevention, and reputational risk identification. It typically incorporates information technology to collect, model, and manage risk data. Through strategy formulation and execution, it helps organizations optimize resource allocation and steadily advance their goals within complex and volatile internal and external environments.
[0003] Among them, the AI-driven enterprise risk management system refers to a system that uses artificial intelligence technology to support key links in enterprise risk management, including classification analysis of historical risk data, judging potential risk events based on predictive models trained with structured and unstructured data, identifying legal and reputational risk hazards in contract texts or external reports based on natural language processing methods, establishing a dynamic association and identification mechanism for risk indicators through rule engines and knowledge graph logical reasoning, and prioritizing risks and generating disposal recommendations based on the training results of machine learning models to complete early warning and management support for enterprise risks, covering multiple technical matters from data collection and processing to intelligent reasoning, and mainly implemented through historical data analysis, semantic recognition, rule matching, and model reasoning.
[0004] Existing enterprise risk management processes fail to incorporate a detailed breakdown of the relationship between intervention duration and event stages in the responsibility assessment process. Responsibility levels are often set based on static processes, which fails to reflect the impact of actual intervention density on responsibility levels. This often leads to unclear cross-cutting responsibilities and significant assessment bias in multi-sector collaboration. Behavioral intervention identification primarily relies on static rules or single-point event comparisons, lacking the multi-dimensional ability to discern conflicting behavioral directions and overlapping timing sequences, leading to oversights in identifying conflicting relationships. Path construction often ignores the dynamics of responsibility levels, and path screening lacks a basis for behavioral exclusion. Generated paths often contain redundant interventions or logical conflicts, impacting actual execution efficiency. Path sorting often relies on preset rules or empirical parameters, with coverage density not systematically incorporated into the sorting mechanism. Priority sequence generation lacks objective indicators and is susceptible to human interference. In terms of results presentation, the path structure is limited to a flat process structure, making it difficult to integrate responsibility levels with behavioral trends. This makes it difficult for managers to quickly identify phase evolution patterns and risk trend aggregation areas through multi-dimensional analysis. For example, in enterprise operation scenarios where there are a large number of responsible parties and behavioral conflicts occur frequently, the existing display methods are insufficient to support the structural analysis needs of path scheduling and risk prediction, which restricts the company's response speed and processing accuracy to emergencies. Summary of the Invention
[0005] The purpose of the present invention is to solve the shortcomings of the prior art and propose an AI-driven enterprise risk management system and method.
[0006] In order to achieve the above objectives, the present invention adopts the following technical solutions: The AI-driven enterprise risk management system includes:
[0007] The responsibility weight analysis module obtains the time period of involvement of each responsible party in the risk event, and combines it with the event stage identifier to automatically determine the time density of the responsible party using AI to generate intelligent responsibility level mapping results;
[0008] The behavior conflict recognition module identifies the conflict relationship between behavior nodes, determines the direction of opposition between behaviors, detects time overlap, and generates a behavior conflict association table;
[0009] The path filtering generation module performs conflict filtering on the behavior paths based on the behavior conflict association table, and reorganizes the retainable paths in combination with the execution unit level content in the enterprise responsibility level mapping result to form a controllable path structure set;
[0010] The sequence prioritization module automatically calculates the coverage density of nodes in each path based on the controllable path structure set and combines AI to sort all paths by coverage density value to generate a priority path sequence set;
[0011] The risk path display module reads the node relationship structure in the priority path sequence set, constructs a path evolution structure according to the arrangement order of the responsible entities and behavior nodes in the path, decomposes each path into stage node groups, maps the corresponding responsibility levels and behavior trend directions, and forms a staged enterprise responsibility risk path map.
[0012] As a further solution of the present invention, the enterprise responsibility level mapping result includes the execution unit responsibility label, stage level distribution record, intervention time density, risk event node position, and time series action interval; the behavior conflict association table includes behavior opposition combination items, intervention overlap identifiers, exclusion structure mappings, conflict time segments, and behavior trend differences; the controllable path structure set includes intervention level combinations, conflict filtering paths, risk intervention controllable sequences, path behavior consistency indicators, and path reorganization mapping relationships; the priority path sequence set includes node coverage density values, path priority identifiers, path level judgment results, conflict analysis scores, and path sequence numbers; the staged enterprise responsibility risk path map includes a hierarchical structure of responsible entities, behavior node trend vectors, stage node grouping relationships, path evolution graph structures, and map visualization mapping results.
[0013] As a further solution of the present invention, the responsibility weight parsing module includes:
[0014] The execution unit extraction submodule obtains the original data sequence of the intervention risk event based on the enterprise multi-agent collaboration scenario, extracts the record items of the subject identity, task instruction number, and target label, screens all execution items with intervention behavior, and establishes the execution unit set corresponding to the event sequence number to generate the intervention behavior execution unit set.
[0015] The time node identification submodule analyzes the task timestamp and intervention behavior identifier in each execution unit according to the intervention behavior execution unit set, identifies the first time node and the termination node in the event sequence, calculates the time span and position number, and aligns the number with the corresponding time period index in the full process event sequence to generate an execution unit time period index pair;
[0016] The stage level generation submodule performs a joint comparison operation on each data according to the execution unit time period index pair, using the formula:
[0017]
[0018] Calculate the stage level label value L of the kth execution unit k , combined with the label level mapping rules, map the stage level of each execution unit to obtain the enterprise responsibility level mapping result, where T k Indicates the time span value of the kth execution unit, P kIndicates the stage number value corresponding to the kth execution unit, D k represents the event density fluctuation value in the time period of the kth execution unit, S k Indicates the standardized length value of the time period where the kth execution unit is located, C k Indicates the total value of the interaction between the kth execution unit and other units.
[0019] As a further solution of the present invention, the behavior conflict identification module includes:
[0020] The risk feature detection submodule collects a sequence table containing behavior codes, node types, and time tags based on the enterprise's internal behavior node records. It then screens the intervention trigger attributes and reaction response attributes of each behavior node to determine whether the intervention conditions are met. It then marks node behaviors that meet the criteria as risk items and generates a numerical value for the risk intervention behavior.
[0021] The direction trend learning submodule extracts the operation direction vector, time series transformation path and node distribution density of each behavior item according to the numerical value of the risk intervention behavior, using the formula:
[0022]
[0023] Calculate the behavior direction opposition value V r , compared with the direction opposition judgment standard value, screen the behavior combination that meets the direction opposition characteristics, and obtain the direction opposition combination identification value, where A r Indicates the operation direction vector value of the rth behavior item, B r Represents the direction vector value of the combined behavior term, M r It represents the sum of squares of the tangential offset values of the behavior item in the time series, E r represents the node density weight;
[0024] The behavior overlap identification submodule extracts the start and end time values and time series index values of each group of direction-opposing behaviors based on the direction-opposing combination identification value, calculates the overlapping length of the time series intervals of the combination items, compares the overlapping length with the overlap judgment standard length, selects the combination items whose overlapping length is not less than the time overlap threshold, and obtains the time overlap behavior combination quantity;
[0025] The conflict structure establishment submodule extracts the corresponding behavior combination relationship identifier, node index number and risk attribute value based on the time-coinciding behavior combination quantity, uniquely encodes the combination relationship, constructs a behavior relationship matrix, and makes a structural inclusion judgment for each combination relationship. The combination relationship that meets the exclusion conditions is included in the exclusion structure, establishes the coding association between the behavior nodes under the exclusion structure, and classifies the structure table according to the combination relationship structure rules to obtain the behavior conflict association table.
[0026] As a further solution of the present invention, the path filtering generation module:
[0027] The behavior path extraction submodule extracts all behavior paths of the enterprise's current risk processing based on the behavior conflict association table, combines the execution unit information of the behavior nodes in the path, screens the paths of potential conflicting behaviors, generates a structure list of all behavior nodes and associated paths, and obtains the original behavior path set;
[0028] The path conflict filtering submodule compares the behavior nodes in each path with the conflicting behavior nodes one by one according to the original behavior path set, filters the paths with conflicting relationships, and eliminates the paths that meet the conflict exclusion criteria to obtain a conflict-filtered behavior path set;
[0029] The path reorganization submodule is based on the behavioral path set after conflict filtering and combines the execution unit level in the enterprise responsibility level mapping result to reorganize the retained paths according to the intervention level matching relationship. It constructs a new behavioral path by adjusting the node order, inserting new nodes or modifying the path structure, and outputs a controllable path structure set.
[0030] As a further aspect of the present invention, the sequence prioritization module includes:
[0031] The responsibility node extraction submodule extracts all nodes in each behavior path based on the controllable path structure set, identifies the corresponding responsibility unit number and responsibility level value, aggregates and codes the responsibility level relationship within the same path, establishes a node level distribution matrix based on the path number, and obtains the path responsibility level distribution data;
[0032] The density sorting submodule extracts the node density value, node proportion value and node level difference value according to the path responsibility level distribution data, and compares and calculates the node coverage of each path using the formula:
[0033]
[0034] Calculate the coverage density value U of the mth path m , and perform sorting operations on all paths according to the density value to obtain the path coverage density sorting result, where N m Represents the node density value of the mth path, R m Indicates the average proportion of the responsibility level in the path, G m Indicates the difference value of the grade distribution in the path, Z m represents the path redundancy factor;
[0035] The level judgment submodule determines whether there is equality in the ranking value based on the path coverage density ranking result, extracts the conflict attribute value, intervention priority label and responsibility level span value of the corresponding behavior node for the path group with consistent ranking value, calculates the average level weight within the path group, establishes the path priority relationship, and constructs the priority index list to obtain the priority path sequence set.
[0036] As a further solution of the present invention, the risk path display module:
[0037] The node relationship construction submodule arranges the responsible entities and behavior nodes in each path based on the priority path sequence set, establishes the node relationship structure in the path, extracts the responsibility nodes and corresponding behavior types and hierarchical information in the path, constructs a node connection matrix according to the relationship between the responsibility hierarchy and the behavior direction, and generates the path node relationship structure;
[0038] The path decomposition submodule decomposes each path into multiple stage node groups based on the path node relationship structure, groups the behavior nodes according to the order and responsibility level in the path, maps the responsibility level and behavior trend of each stage node group, obtains the behavior evolution path of each stage, and generates a stage node group mapping structure;
[0039] The graph display submodule converts the decomposed path data into a graph form based on the stage node group mapping structure, arranges the nodes according to the hierarchy and development trend of the behavior nodes, and graphically displays the evolution structure of the path to form a staged corporate responsibility risk path graph.
[0040] The AI-driven enterprise risk management approach includes the following steps:
[0041] S1: Obtain the first intervention and termination nodes of all execution units, calculate the intervention length and match the stage number with the dense segment to generate the enterprise responsibility level mapping result;
[0042] S2: Based on the enterprise responsibility level mapping results, direction parameters and time series distribution are collected, overlapping intervention relationships are determined, and a behavior conflict association table is generated;
[0043] S3: excluding paths containing exclusion structures according to the behavior conflict association table, screening and combining level-continuous paths based on the enterprise responsibility level mapping result, and generating a controllable path structure set;
[0044] S4: Calculate the coverage density value of each path and sort them according to the controllable path structure set, extract the exclusion node level difference of the sorted consistent paths, build a judgment logic, and generate a priority path sequence set;
[0045] S5: Extract the order of responsibility nodes according to the priority path sequence set, construct a stage node group, detect the mapping relationship between direction parameters and levels, and generate a staged enterprise responsibility risk path map.
[0046] Compared with the prior art, the advantages and positive effects of the present invention are:
[0047] In the present invention, by identifying the intervention time period of the responsible subject in the risk event and combining the distribution law of the event stage, the hierarchical mapping of responsibility division is realized, the dynamic adaptability of responsibility orientation is strengthened, and based on the directional judgment and time overlap detection mechanism between behavior nodes, the structural intervention conflicts that may arise between behavior combinations are identified, and a dynamically updated behavior exclusion structure is constructed, which significantly improves the accuracy and immediacy of conflict perception. The intervention level and the conflict exclusion structure are integrated, and the path combination with behavioral consistency and intervention controllability is dynamically screened to improve the structural effectiveness and logical rationality of the risk handling path. The coverage density of the distribution of responsibility nodes in the path is used as a quantitative basis, and the priority sequence is sorted in combination with the behavior conflict information, which enhances the data-driven and evaluation power in the path screening process. The evolution of the responsibility level and the flow of behavior trends are used to construct a visual map, and the abstract path structure is decomposed into staged responsibility behavior structure blocks to achieve the linkage expression between multi-dimensional elements and the progressive analysis of the map level, thereby enhancing the segmentation depth of enterprise risk identification, the decision-making support for path planning and the structural expression of the result presentation. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] Figure 1 is a system flow chart of the present invention;
[0049] Figure 2 This is a flow chart of the responsibility weight parsing module of the present invention;
[0050] Figure 3 This is a flow chart of the behavior conflict identification module of the present invention;
[0051] Figure 4 This is a flow chart of the path filtering generation module of the present invention;
[0052] Figure 5 This is a flow chart of the sequence prioritization module of the present invention;
[0053] Figure 6 This is a flow chart of the risk path display module of the present invention. DETAILED DESCRIPTION
[0054] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0055] In the description of the present invention, it should be understood that the terms "length," "width," "up," "down," "front," "back," "left," "right," "vertical," "horizontal," "top," "bottom," "inside," "outside," and the like, indicating positions or relationships, are based on the positions or relationships shown in the accompanying drawings and are intended only to facilitate the description of the present invention and simplify the description. They do not indicate or imply that the devices or elements referred to must have a specific orientation, be constructed, or operate in a specific orientation. Therefore, they should not be construed as limiting the present invention. Furthermore, in the description of the present invention, "plurality" means two or more, unless otherwise expressly and specifically defined.
[0056] See also Figure 1 , AI-driven enterprise risk management system includes:
[0057] The responsibility weight parsing module obtains all execution units involved in risk events in the enterprise's multi-agent collaboration scenario, identifies the location nodes where they first appear and end in the time series, and uses the AI learning engine to jointly identify the intervention time length and stage level of each execution unit. Combined with the overall distribution trend of the enterprise event sequence, it automatically assigns stage level labels and generates enterprise responsibility level mapping results.
[0058] The behavior conflict identification module identifies the risk intervention characteristics of each behavior node within the enterprise, uses AI to learn the trend of behavior direction, and performs sequence overlap detection on behavior combinations with directional opposition characteristics. If the identified combination has intervention overlap over time, the corresponding behavior relationship is incorporated into the exclusion structure and a behavior conflict association table is output;
[0059] The path filtering generation module performs conflict filtering on all behavioral paths of the current enterprise risk processing based on the behavioral conflict association table. Combining the execution unit level content in the enterprise responsibility level mapping result, it reorganizes the retainable paths according to the intervention level matching relationship to form a controllable path structure set.
[0060] The sequence prioritization module automatically calculates the coverage density of nodes in each path based on the responsibility nodes and hierarchical relationships of each behavior sequence in the controllable path structure set, combined with AI, and sorts all paths by coverage density values. If the sorting values are consistent, it automatically analyzes behavior relationship conflicts, establishes a hierarchical judgment mechanism between paths, and generates a set of priority path sequences.
[0061] The risk path display module reads the node relationship structure in the priority path sequence set, constructs the path evolution structure according to the arrangement order of the responsible entities and behavior nodes in the path, decomposes each path into stage node groups, maps the corresponding responsibility levels and behavior trend directions, and displays the structure in the form of a graph to form a staged enterprise responsibility risk path graph.
[0062] The results of enterprise responsibility level mapping include execution unit responsibility labels, stage level distribution records, intervention time density, risk event node positions, and time series action intervals. The behavior conflict association table includes behavior opposition combination items, intervention overlap identifiers, exclusion structure mappings, conflict time segments, and behavior trend differences. The controllable path structure set includes intervention level combinations, conflict filtering paths, risk intervention controllable sequences, path behavior consistency indicators, and path reorganization mapping relationships. The priority path sequence set includes node coverage density values, path priority identifiers, path level judgment results, conflict analysis scores, and path sequence numbers. The staged enterprise responsibility risk path map includes the hierarchical structure of responsible entities, behavior node trend vectors, stage node grouping relationships, path evolution graph structures, and map visualization mapping results.
[0063] See also Figure 2 , the responsibility weight parsing module includes:
[0064] The execution unit extraction submodule obtains the original data sequence of the intervention risk event based on the enterprise multi-agent collaboration scenario, extracts the record items of the subject identity, task instruction number, and target label, screens all execution items with intervention behavior, and establishes the execution unit set corresponding to the event sequence number to generate the intervention behavior execution unit set.
[0065] Based on the enterprise multi-agent collaboration scenario, it is necessary to first obtain the original data sequence related to the intervention risk event, including task assignment records, personnel behavior records and event flow logs. In this process, by retrieving the record items indexed by event identifiers in the log system, it is extracted whether each subject has intervention behavior in the event sequence, and its associated task instruction number, subject identity and operation target are identified. Then, the extracted subject behavior is filtered, and those behavior records completed after the instruction is issued and before the operation target is changed are retained to ensure that the filtered ones are valid intervention behaviors. In the example, let the event sequence number be E1001, and a subject A receives task T05 on December 1, 2024, and performs an operation on target G12 at 14:20 on the same day. Then its behavior meets the definition standard of intervention behavior. At the same time, the execution unit information is extracted as {subject ID: A, task number: T05, target label: G12}. After looping through this step in all event records, the initial set of execution units is constructed. During the execution process, for the "screening" behavior The specific process is to set the operation time threshold interval. For example, only behavior records within 1 hour after the event instruction is issued are considered valid. Records less than 1 hour are retained, and those exceeding 1 hour are excluded. In this process, the judgment threshold is set to 60 minutes. If a subject behavior occurs 75 minutes after the task instruction is issued, it will not be collected. The judgment threshold is set based on the fact that in the collaborative operation of multiple cross-functional departments in the enterprise, the average response time from task issuance to first response is 53 minutes. Combined with the maximum stable cycle fluctuation value of 7 minutes in the operation preparation and approval response links of this type of event, 60 minutes is set as the effective boundary of intervention response. At the same time, this value fluctuates with different instruction types. For immediate response tasks (such as system alarm processing), it can be reduced to 30 minutes, and for non-urgent process instructions (such as document approval), it can be extended to 90 minutes. Therefore, this setting has structural stability and dynamic adjustment capabilities. Its rationality comes from the time sensitivity analysis of the matching of cross-scenario task response time and behavior start time. Table 1 lists the sample behavior data and the status after screening.
[0066] Table 1 Example table for intervention behavior screening
[0067] Event Number Subject ID Task Number Operation time (minutes) Whether to collect E1001 First T05 45 yes E1002 Second T06 78 no E1003 C T07 59 yes
[0068] Table 1 lists the time when different subjects' intervention behaviors occur and whether the set effective intervention conditions are met. The operation time is measured in minutes and is calculated relative to the time when the task instruction is issued. The basis for judging the effectiveness of the intervention behavior is whether the operation time is less than or equal to the threshold of 60 minutes.
[0069] The time node identification submodule analyzes the task timestamp and intervention behavior identifier in each execution unit based on the intervention behavior execution unit set, identifies the first time node and the termination node in the event sequence, calculates the time span and position number, and aligns the number with the corresponding time period index in the full process event sequence to generate an execution unit time period index pair;
[0070] Based on each data in the intervention behavior execution unit set, its embedded timestamp field and intervention behavior label field are analyzed. First, the original timestamp data of the task start time and end time are obtained, and its position index in the entire event sequence is calculated. The specific calculation method is to convert the behavior time into a relative index number in the event sequence. For example, taking the event sequence start time 0:00 on December 1, 2024 as the starting point, if a behavior occurs at 14:00 on December 1, its index position is 14. If the end time is 17:00, the end index is 17. The corresponding time span of the behavior is 3 hours. The time span value is obtained by subtracting the start index from the end index. Let the start index be 1 4, the end index is 17, then the time span is 17-14=3, then the above index value is bound to the length of the whole process event sequence, if the total length of the event sequence is 72 hours, the system will standardize the index position into a segment identification value, for example, the start index 14 is mapped to stage 1, and the end index 17 is mapped to stage 2. The mapping rule is divided into intervals according to the total length of the event sequence, that is, every 12 hours is a stage, then 14 is the second stage, 17 is the second stage, here the mapping does not cross the stage, the stage number is unified as P=2, the judgment logic set in the "judgment" action is that when a certain index value is divided by 12, the integer obtained determines the stage number to which it belongs. The specific value is determined by the formula Get, calculated as above The obtained stage number is 2. Through this method, the time node index is given clear segmentation information, thereby establishing an index pair, which is used as the basic index input for subsequent stage level identification and further generates the execution unit time period index pair.
[0071] The stage level generation submodule performs a joint comparison operation on each data according to the execution unit time period index pair, using the formula:
[0072]
[0073] Calculate the stage level label value L of the kth execution unit k , combined with the label level mapping rules, map the stage level of each execution unit to obtain the enterprise responsibility level mapping result, where T k Indicates the time span value of the kth execution unit, P k Indicates the stage number value corresponding to the kth execution unit, D krepresents the event density fluctuation value in the time period of the kth execution unit, S k Indicates the standardized length value of the time period where the kth execution unit is located, C k Indicates the total value of the interaction between the kth execution unit and other units;
[0074] According to the aforementioned execution unit time period index pair, a joint comparison operation is performed on each data. In the acquisition method, D k The value is the event density fluctuation value within the time period of a certain execution unit, which is defined as the second-order difference value of the event triggering frequency change per unit time. Its collection method is to record the number of event triggering times per hour, and compare the current hour with the previous hour and the next hour to obtain the change gradient. For example, if the event is triggered 4 times in the 12th hour, 3 times in the 11th hour, and 5 times in the 13th hour, D is obtained. k
[0075] =(5-4)-(4-3)=-1, its value indicates the degree of trend turning point; C k is the count value of interaction events within the unit. For example, if subject A interacts with other subjects B and C 3 times and 2 times respectively in the 12th stage, then C k =3+2=5; S k It is the inverse of the proportion of events in this stage to the total events. If there are 15 triggers in this stage and the total number is 90, then Substitute the parameters into the formula:
[0076] Take T k =3,P k =2,D k =-1, S k =6, C k =5, the calculation formula is as follows:
[0077] Step 1, D k +1=-1+1=0;
[0078] Step 2,
[0079] Step 3, T k +P k =3+2=5;
[0080] Step 4: The numerator is 5×0=0 and the denominator is S k +C k =6+5=11;
[0081] The final result is
[0082] This value will be mapped to the level label range, and the mapping standard is set as follows: k ∈[0,1), then the attribute level is 1; if Lk ∈[1,2), then it belongs to level 2; if L k ∈[2,3), it belongs to level 3; and so on, each unit interval is set as a level, and the corresponding level upper limit does not exceed 5. The basis for this setting is that the system performs distribution statistics on nearly 600 execution unit sample data, observes the degree of aggregation of its formula output values in a continuous interval, and compares it with the actual responsibility level division system to ensure that the output results corresponding to the level mapping have hierarchical stability and sensitive responsiveness. This setting value varies with D k with C k The fluctuation amplitude changes significantly, that is, when the event trend is unstable (D k Large) or increased interaction complexity (C k When L k The value decreases, reflecting that the responsibility level tends to a lower range, while when the trend is stable and the interaction frequency is moderate, L k The numerical value is improved, pointing to a higher level, and further generating the corporate responsibility level mapping results.
[0083] See also Figure 3 , the behavior conflict recognition module includes:
[0084] The risk feature detection submodule collects a sequence table containing behavior codes, node types, and time tags based on the enterprise's internal behavior node records. It then screens the intervention trigger attributes and reaction response attributes of each behavior node to determine whether the intervention conditions are met. It then marks node behaviors that meet the criteria as risk items and generates a numerical value for the risk intervention behavior.
[0085] Based on the internal behavior node records of the enterprise, the original sequence table containing behavior codes, node types and time tags is obtained. First, the original behavior node data is deconstructed, and the behavior code field, behavior trigger timestamp field and behavior node type identifier in each record are extracted. Each record is annotated and classified into active behavior nodes and response behavior nodes. Among them, if the response delay time attached to the behavior node is less than 2 seconds, it is judged as a response behavior. If the behavior time interval is greater than 10 seconds, it is marked as an independent active behavior. Based on this standard, the node behavior types are divided. Next, for the trigger attribute items in the behavior node, the intervention condition label field and the behavior occurrence environment label field are collected respectively to determine whether it contains the three types of intervention features: instruction coverage, resource occupation, and authority crossing. If at least one of the three types of intervention items is "yes", Mark, the behavior node is marked as "potential risk behavior". For example, in a certain node, the behavior code is T102, the behavior time is 10:32:01, the behavior type is a write operation, and the permission is marked as "shared resources", then this behavior and another shared behavior may constitute a resource competition relationship, and further determined to be a "resource occupation" intervention behavior. In this stage, combined with the behavior frequency value, if the frequency value of a behavior node is greater than 1.5 times the average behavior frequency (based on the system statistical mean of 15 times, the threshold is 22.5 times), it is determined to be a "high-frequency behavior", and the system marks its risk level as a medium-risk behavior. Finally, combined with the intervention flag items of multiple dimensions, the behavior nodes that meet any intervention judgment condition are screened out one by one to form a risk behavior set and obtain the numerical value of the risk intervention behavior.
[0086] The direction trend learning submodule extracts the operation direction vector, time series transformation path and node distribution density of each behavior item based on the numerical value of the risk intervention behavior, using the formula:
[0087]
[0088] Calculate the behavior direction opposition value V r , compared with the direction opposition judgment standard value, screen the behavior combination that meets the direction opposition characteristics, and obtain the direction opposition combination identification value, where A r Indicates the operation direction vector value of the rth behavior item, B r Represents the direction vector value of the combined behavior term, M r It represents the sum of squares of the tangential offset values of the behavior item in the time series, E r represents the node density weight;
[0089] According to the numerical value of the risk intervention behavior, the operation direction vector, time series transformation path and node distribution density of each behavior item are extracted. The direction vector is calculated by collecting the target position transformation direction of the action before and after the behavior instruction. The operation direction is the coordinate change direction of the logical variable before and after the behavior in the two-dimensional structure. For example, if behavior A moves from coordinates (2,3) to (5,7) in the two-dimensional structure, the direction vector is (3,4). The direction difference is further calculated as the absolute value of the difference in the module lengths of the two direction vectors. The tangential offset value of the direction is measured by the angular offset in the time series path of each node. If the behavior moves upward by 30 degrees, -40 degrees, and 10 degrees on the three nodes respectively, the tangential offset is a total of 80 degrees. The node distribution density takes the average number of node behaviors every 10 seconds. By analyzing the above three indicators, the behavior combination with directional opposition relationship is identified. Specific numerical values are brought in for example. If the direction vector of behavior A is A r =6, behavior B is B r =2, the corresponding tangential offset value is M r =36, the node density weight is E r =1, then
[0090]
[0091] in,
[0092] A r The direction vector of behavior A is derived from the offset distance of the target coordinates before and after the behavior;
[0093] B r The direction vector representing the combined behavior B is obtained in the same way;
[0094] M r The sum of the square values of all tangential change angles during the behavior time period;
[0095] E r Indicates the unit time density value of the behavior node, which is obtained by calculating the behavior value every 10 seconds;
[0096] Table 2 Behavior direction vector and density parameter table
[0097] Behavior Number Direction vector (unit: unit length) Tangential offset value (unit: degree) Node density (unit: nodes / 10 seconds) 1 6 36 1 2 3 49 2 3 7 25 1
[0098] As shown in Table 2, there are large directional differences and high tangential variations among multiple behaviors. rIf the value is greater than a threshold of 8 (this value is set by analyzing the directional differences and tangential offset comparisons of multiple groups of behavior combinations to ensure accurate distinction between behavior combinations with strong and weak directional oppositions. This threshold is based on experimental data. During the behavior combination comparison process, all behavior combinations greater than 8 showed strong interference conflict characteristics), it is determined to be a directional opposition combination, and the final directional opposition combination identification value is obtained. By combining the squared directional vector difference term with the sum of squared tangential offsets, the dynamic path change characteristics of the behavior are introduced, and normalized by node density, the robustness of directional opposition judgment is enhanced and the sensitivity of behavior combination judgment is improved. This result shows that the significance of directional opposition combinations can serve as important basic data for subsequent behavior overlap judgment.
[0099] The behavior overlap identification submodule extracts the start and end time values and time series index values of each group of directional opposing behaviors based on the directional opposing combination identification value, calculates the overlapping length of the time series intervals of the combination items, compares the overlapping length with the overlap judgment standard length, and selects the combination items whose overlapping length is not less than the time overlap threshold to obtain the number of time overlap behavior combinations;
[0100] Based on the directional opposition combination identification value, the start and end time values and time series index values of each group of directional opposition behaviors are extracted. First, the start and end time of each behavior node are extracted to obtain the time span of each directional opposition combination. On this basis, the time overlap of each pair of combined behaviors is calculated. If the time intervals of the two behaviors intersect, the overlap length is further calculated. The calculation formula for the overlap length is as follows:
[0101]
[0102] in,
[0103] L o Indicates the length of overlap time;
[0104] and are the end time and start time of the first group of behaviors respectively;
[0105] and is the end time and start time of the second group of behaviors;
[0106] By calculating the length of the overlapping time, if the overlapping length is not less than a set threshold, such as a threshold of 5 seconds (set according to the behavior type and scenario requirements), the behavior combination is considered to have overlapping interference. For example, if the time range of behavior 1 is [10:00:00, 10:00:10] and the time range of behavior 2 is [10:00:05, 10:00:15], the overlapping time length is 5 seconds, which meets the set overlap threshold. Finally, the number of time-overlapping behavior combinations is obtained, and subsequent conflict structure judgment and processing are carried out, ultimately obtaining a set of behavior combinations that meet the overlap judgment criteria.
[0107] The conflict structure establishment submodule extracts the corresponding behavior combination relationship identifier, node index number and risk attribute value based on the amount of temporal overlapping behavior combinations, uniquely encodes the combination relationship, constructs a behavior relationship matrix, and makes a structural inclusion judgment for each combination relationship. Combination relationships that meet the exclusion conditions are included in the exclusion structure, establishes the coding association between behavior nodes under the exclusion structure, and classifies the structure table according to the combination relationship structure rules to obtain the behavior conflict association table;
[0108] Based on the amount of temporally overlapping behavior combinations, the corresponding behavior combination relationship identifiers, node index numbers, and risk attribute values are extracted. First, a unique identifier is assigned to each overlapping behavior combination, for example, behavior combination 1-2, behavior combination 2-3, and so on. A number is assigned to the combination based on its temporal overlap and risk attribute value. Subsequently, the node index numbers of all behavior combinations are associated with the risk attribute to construct a matrix structure containing information on all behavior combinations. Each row represents an overlapping combination behavior, and each column contains data items such as the combination identifier, temporal overlap length, and risk level. The following structure table is used to store behavior conflict data:
[0109] Table 3 Behavior conflict data table
[0110] Behavioral combination identifier Start time End Time Overlap duration (unit: seconds) Risk Level 1-2 10:00:00 10:00:10 5 Medium risk 2-3 10:00:05 10:00:15 10 High risk 1-3 10:00:02 10:00:08 6 High risk
[0111] As shown in Table 3, both behavior combinations AB and BC exhibit significant temporal overlap, and the overlap duration exceeds the threshold. Therefore, their risk levels are categorized as medium and high risk. The overlap threshold is set at 10 seconds because it takes into account the impact of temporal conflicts between behavior nodes. If the overlap duration of two behaviors is less than 10 seconds, it generally does not cause a serious interference conflict with the system. Therefore, 10 seconds is set as the demarcation point. The "high risk" level is determined based on the type of behavior node and its interactions. If a behavior node is of a higher priority or has a significant impact on the system (such as data writing or resource usage), it is considered a high-risk behavior.
[0112] Next, based on this data structure, the behavior combination relationships are structured and encoded to construct an exclusion structure. If the overlap duration between two behavior combinations meets the preset exclusion conditions (for example, the overlap time exceeds 10 seconds and the risk level is "high risk"), the relationship between the two behavior combinations is included in the exclusion structure, and an exclusion relationship is established between the behavior nodes. Finally, all behavior combinations included in the exclusion relationship are placed in the final behavior conflict association table, which is used to identify and record behavior conflicts and serve as the basis for behavior adjustments in subsequent decision-making and control.
[0113] See also Figure 4 , path filtering generation module:
[0114] The behavior path extraction submodule extracts all behavior paths of the enterprise's current risk management based on the behavior conflict association table. It combines the execution unit information of the behavior nodes in the path to screen the paths of potential conflicting behaviors, generates a structure list of all behavior nodes and associated paths, and obtains the original behavior path set.
[0115] When extracting the enterprise's current risk handling behavior path based on the behavior conflict association table, it is first necessary to decompose each conflict record in the behavior conflict association table, extract the behavior node number, conflict type identifier and the identification field of the path, and compare the path records in the enterprise database one by one. For example, in enterprise A, the path with behavior path number P01 contains nodes N12 and N17. According to the conflict table, there is an operation exclusion relationship between the two. Therefore, the path needs to be identified as a conflict path, and then the complete path structure is marked and extracted. All nodes in the path are sorted by timestamp to construct a path vector, and then the vector matching method is used to extract the path vector. The execution unit information associated with each behavior path is obtained. The execution unit information should include parameters such as responsibility level, intervention time, and behavior intensity. Here, the behavior path P05 of enterprise B is taken as an example. It contains 5 nodes, namely N01 to N05, and the node responsibility levels are 2, 3, 1, 3, and 2, respectively. The intervention times are 1.5h, 2.0h, 1.0h, 2.5h, and 1.8h, respectively. During the extraction process, it is necessary to establish a relationship mapping matrix between nodes and paths, and construct a two-dimensional array for combined analysis. Through the above process, the original behavior path set is finally obtained. Its structure consists of three types of fields: node sequence, time sequence, and responsibility level of each path.
[0116] The path conflict filtering submodule compares the behavior nodes in each path with the conflicting behavior nodes one by one based on the original behavior path set, filters the paths with conflicting relationships, and eliminates the paths that meet the conflict exclusion criteria to obtain the conflict-filtered behavior path set;
[0117] According to the original behavior path set, to determine whether there is a conflict in the path, a cyclic detection operation must be performed on all nodes in each path. First, a path is extracted from the set, such as path P07, which contains nodes N03, N08, N11, and N14. Each node must be compared with the records in the behavior conflict association table one by one. If there is a conflict mark between any two nodes in the path, the entire path must be determined as an unusable path. Here, if N08 and N11 have a time overlap and an opposite direction relationship in the conflict table, P07 will be eliminated. The conflict identification layout can be set in the specific screening process. When it is detected that the value of two nodes in the path is 1 in the conflict matrix, the Boolean state of the path is set to 0 to indicate an invalid path, otherwise it is retained. For example, the threshold path validity is set to ≥1. If there is one group of conflicts in the entire path, the validity value is 0, which does not meet the condition and is excluded. The next path is processed. Taking path P12 as an example, none of its node groups are successfully paired with the nodes in the conflict table, so it is retained to the next stage. Through the above screening process, a set of paths with compliant structures and no node conflicts can be obtained, and finally a set of behavioral paths after conflict filtering is obtained.
[0118] The path reorganization submodule reorganizes the retained paths according to the intervention level matching relationship based on the conflict-filtered behavioral path set and the execution unit level in the enterprise responsibility level mapping result. It constructs new behavioral paths by adjusting the node order, inserting new nodes, or modifying the path structure, and outputs a controllable path structure set.
[0119] When reorganizing the path structure based on the behavioral path set after conflict filtering, the responsibility level mapping result needs to be called at the same time. First, the level sequence identifier of the filtered path needs to be extracted. For example, the path P15 contains four nodes N21, N24, N27, and N30, and their corresponding levels are 1, 2, 3, and 2. According to the intervention level matching standard, if the level difference between adjacent nodes is greater than 1, the nodes need to be rearranged or an intermediate node needs to be inserted. For example, the reorganization benchmark difference is set to 1. In P15, the level difference between nodes N21 and N24 is 1, and the order can be retained. The level difference between N24 and N27 is also 1, but the level difference between N27 and N30 is 1, which remains unchanged. The overall sequence does not need to be adjusted. If the other path The node level sequence in path P16 is 3, 1, 2, 2. If the level difference between the first and second nodes is 2, an adjustment is required. The node with level 2 can be moved to the middle to form a structure of 3, 2, 1, 2. The execution time of each node is then calculated to confirm whether the adjustment causes a logical conflict. If the original execution time intervals are 1 hour, 1.2 hours, 0.8 hours, and 1.5 hours, the timestamps of the adjusted nodes need to be reallocated. For example, the timestamps can be adjusted to 1 hour, 1 hour, 1 hour, and 1.5 hours using the equal division method. This method constructs a path structure sequence with consistent path levels, generates new path reorganization vectors, and stores them as new paths after uniform numbering. Finally, a controllable path structure set is established.
[0120] See also Figure 5 , the sequence prioritization module includes:
[0121] The responsibility node extraction submodule extracts all nodes in each behavior path based on the controllable path structure set, identifies the corresponding responsibility unit number and responsibility level value, aggregates and codes the responsibility level relationship within the same path, establishes a node level distribution matrix based on the path number, and obtains the path responsibility level distribution data;
[0122] Based on the behavior paths provided in the controllable path structure set, first extract all the behavior node numbers, node types and responsibility unit labels contained in each path. For example, path P1 contains nodes N1 to N8, and the corresponding responsibility units of the nodes are X, Y, X, Q, X, Y, Q, X. On this basis, identify the responsibility level value corresponding to each node. The responsibility level is provided by the enterprise responsibility level mapping result. For example, if the X unit is level 3, the Y unit is level 2, and the Q unit is level 1, then the responsibility level sequence of path P1 is [3, 2, 3, 1, 3, 2, 1, 3]. Then, construct the responsibility level sequence according to the order of the nodes in the path. Level distribution matrix, the matrix uses the behavior path number as the row index and the responsibility level value as the element. For example, if the path P2 contains the node level [2, 2, 3, 3, 2], then its matrix is [2, 2, 3, 3, 2]. All paths construct the level distribution structure in this way, and then construct a mapping table with the number of each path and the corresponding level sequence to form a path-level relationship pair list, for example (P1, [3, 2, 3, 1, 3, 2, 1, 3]), (P2, [2, 2, 3, 3, 2]), and then integrate the list into a structure mapping matrix for subsequent analysis. The path responsibility level distribution data is obtained through the above operations.
[0123] The density sorting submodule extracts the node density value, node proportion value and node level difference value based on the path responsibility level distribution data, and compares and calculates the node coverage of each path using the formula:
[0124]
[0125] Calculate the coverage density value U of the mth path m , and perform sorting operations on all paths according to the density value to obtain the path coverage density sorting result, where N m Represents the node density value of the mth path, R m Indicates the average proportion of the responsibility level in the path, G m Indicates the difference value of the grade distribution in the path, Z m represents the path redundancy factor;
[0126] Based on the path responsibility level distribution data, the structural parameters of each path are extracted one by one. First, the node density value is obtained, that is, the node number density per unit path length, which is defined as the total number of nodes divided by the total path length. For example, path P1 contains 8 nodes and the path length is 100, so its node density is 0.08; the level proportion value is the proportion of nodes with the most common responsibility level in the path. For example, level 3 appears 4 times in P1, accounting for 0.5 of the total number of nodes 8; the level difference value is defined as the difference between the maximum and minimum levels divided by the number of nodes. For example, in the level distribution [3, 2, 3, 1, 3, 2, 1, 3], the maximum is 3 and the minimum is 1, with a difference of 2, and a total of 8 nodes, so the level difference value is 2 / 8 = 0.25; the path redundancy factor is defined as the number of logically duplicated or functionally duplicated nodes in the path divided by the number of path nodes The ratio of the total number of nodes, where logically repeated nodes refer to nodes that perform the same function, target, or instruction but are repeatedly set in the path. For example, if there are multiple node numbers with exactly the same target instructions (such as executing "regulatory audits" at the same time) in the path, they are considered repeated nodes. The identification criteria are that the task attribute label, operation type identifier, and referenced upstream node number in the node code are completely consistent; this factor is mainly used to measure the density of repeated behaviors in the path. Its value is affected by the degree of deduplication of node tasks in the path. If effective behavior merging is not performed during the task allocation process, the factor will increase with the increase in the number of nodes. It is generally recommended to set it between 0.1 and 0.5. If it exceeds 0.5, it means that there is a significant redundancy risk in the path. Structural adjustment operations need to be introduced in the path optimization stage to avoid task conflicts or resource waste. Substituting the proposed values into the formula for calculation, Table 4 shows some path calculation data:
[0127] Table 4 Path coverage density calculation data table
[0128] Path number Node density (Nm) Ratio of grade (Rm) Grade difference value (Gm) Path redundancy factor (Dm) P1 0.72 0.60 0.30 0.40 P2 0.65 0.70 0.25 0.50 P3 0.88 0.55 0.40 0.30 P4 0.73 0.68 0.35 0.45
[0129] As shown in Table 4, the node density of path P3 is 0.88, the level ratio is 0.55, the level difference is 0.4, and the redundancy factor is 0.3. Substituting them into the formula:
[0130]
[0131] The results show that path P3 has certain priority ranking conditions in terms of structural density and hierarchical stability, and the path coverage density ranking results are obtained.
[0132] The level judgment submodule determines whether the ranking values are equal based on the path coverage density ranking results. For the path groups with consistent ranking values, it extracts the conflict attribute values, intervention priority labels, and responsibility level span values of the corresponding behavior nodes. It calculates the average level weight within the path group, establishes the path priority relationship, and constructs a priority index list to obtain the priority path sequence set.
[0133] Based on the path coverage density sorting results, determine whether there is a path group with completely consistent sorting values. For example, if the sorting values of paths P1 and P4 are both 1.05, they are considered to be the same sorted path group. Extract all behavior nodes in the path and search whether there is a direct conflict mark in the behavior conflict association table. If there is, such as nodes N3 and N7 marked as conflict type "mutually exclusive", mark the path as a high conflict level, defined as value 2, and no conflict is marked as 1; then extract the level span value of the path, that is, the difference between the maximum level and the minimum level. For example, if the path level distribution is [3, 2, 2, 3, 1], The span is 3-1=2; the behavior priority is numbered according to the behavior type, with master control as 1, coordination as 2, feedback as 3, and monitoring as 4. If the behavior type of each node in the path is [master control, feedback, coordination, master control], the corresponding number is [1, 3, 2, 1], and the average value is (1+3+2+1) / 4=1.75; the above three indicator values are respectively brought into the priority judgment mechanism, first comparing the conflict level value, then the level span value, and if they are still consistent, then comparing the priority average value, constructing a priority matrix and performing sorting, and finally establishing a priority index list to obtain a priority path sequence set.
[0134] See also Figure 6 , risk path display module:
[0135] The node relationship construction submodule arranges the responsible entities and behavior nodes in each path based on the priority path sequence set, establishes the node relationship structure in the path, extracts the responsibility nodes and corresponding behavior types and hierarchical information in the path, constructs a node connection matrix according to the relationship between responsibility hierarchy and behavior direction, and generates the path node relationship structure;
[0136] First, the responsible parties and behavior nodes within a path need to be arranged and organized to construct the node relationship structure for each path. Specifically, all paths are extracted from the set of prioritized path sequences. The responsibility nodes and behavior nodes within each path are then arranged sequentially. Each node contains the behavior type, the identity of the responsible party, and its responsibility level. The node relationships within a path are arranged sequentially according to responsibility level, behavior type, and path order, forming a connected structure. For a practical implementation scenario, consider a simple path consisting of nodes 1, 2, and 3, where node 1 marks the start of behavior a, node 2 marks behavior b, and node 3 marks behavior c. The connections between these nodes need to be determined based on the actual responsibility hierarchy and behavior priority within the enterprise. For example, if node 1 has a "medium" responsibility level, node 2 has a "high" responsibility level, and node 3 has a "low" responsibility level, then the node relationship structure will be arranged from lowest to highest responsibility. During implementation, the nodes within each path need to be arranged in ascending or descending order of responsibility level to ensure that the execution order of each behavior is reasonable and consistent with the actual enterprise responsibility system.
[0137] Through this organizational approach, the responsibility hierarchy and behavior types of each path are fully mapped and described, forming a clear node relationship structure that can provide effective information for subsequent behavior analysis. Ultimately, this node relationship structure provides the basic data for generating the path's responsibility node relationship diagram. For example, in actual business, a behavioral path may involve multiple departments, each responsible for different nodes based on their division of responsibilities. In this case, the system displays the distribution of responsibilities for each node based on the node relationship structure. In this way, when visualizing the path, the system can clearly show the behaviors for which each responsible party is responsible, further improving the controllability and transparency of the path.
[0138] The path decomposition submodule decomposes each path into multi-stage node groups based on the path node relationship structure, groups the behavior nodes according to the order and responsibility level in the path, maps the responsibility level and behavior trend of each stage node group, obtains the behavior evolution path of each stage, and generates the stage node group mapping structure;
[0139] Further analysis of the path requires decomposing each path into multiple phase node groups. Phase node groups are divided based on the association between the behavior nodes and the responsibility level within the path. For each path, the system first groups the behavior nodes according to the order of the behavior nodes within the path. Each phase node group includes the execution phase of the behavior and the corresponding responsibility level. During the decomposition process, the system maps the responsibility level of each phase node and arranges the relationships between the phase node groups based on the chronological order of the path. For example, a specific path is decomposed into three phase node groups: Phase 1 (high responsibility level), Phase 2 (low responsibility level), and Phase 3 (medium responsibility level). During implementation, although Phase 2 is in the middle of the path, due to its lower responsibility level, the assigned phase node group is adjusted appropriately based on the type of behavior.
[0140] For example, assuming a path consists of three stage nodes, and each stage node has a corresponding responsibility level, the system will first divide these nodes reasonably based on the type of behavior (such as "high", "medium", and "low") and the order of the stages, and assign them to the various responsible units within the system. When the execution path is displayed, you can see how the responsibility level and behavior type of the stage node group match, and how these nodes are constructed in sequence to build the path. This decomposition method makes the responsibilities of different departments clearly visible, and it is also convenient to adjust the execution of the path according to different situations.
[0141] Through the mapping relationship between behavior and responsibility levels, each behavior in the path can be accurately located to its corresponding responsibility node and execution stage, thus providing clear data support for subsequent risk assessment, responsibility tracking, etc.
[0142] The graph display submodule converts the decomposed path data into a graph based on the stage node group mapping structure. It arranges nodes according to the hierarchy and development trend of the behavior nodes, and graphically displays the evolutionary structure of the path to form a staged corporate responsibility risk path graph.
[0143] After decomposing the path, the path data needs to be converted into a graph for display. By mapping the decomposed stage node groups onto the graph, the system can form a complete path evolution graph. The graph is constructed by mapping each stage node to a node in the graph, connecting the nodes with edges based on the order of behaviors and the hierarchy of responsibility. The hierarchy of each node in the graph corresponds to the level of responsibility for its behavior, and the edges connecting these nodes represent the execution order of the behaviors. For example, if a path contains three stage node groups, the graph will display a path from "high" to "low," with the responsibility level and behavior direction of each stage node distinguished by color or shape in the graph. This allows the system to visualize the path evolution process through the graph, helping enterprise managers intuitively understand the responsibility allocation at each node, the order of behavior, and the evolution of the path.
[0144] Assuming the nodes of a path are behavior a with "high" responsibility, behavior b with "medium" responsibility, and behavior c with "low" responsibility, the system arranges each node in descending order of responsibility, using different colors or shapes on the map to represent nodes at different levels of responsibility. This map clearly identifies the execution order and hierarchical structure of the behaviors. In practical applications, this map not only helps companies quickly understand the role of each responsible party in the path, but also enables dynamic risk assessment at each stage, providing decision makers with more actionable, visual path data.
[0145] The AI-driven enterprise risk management approach includes the following steps:
[0146] S1: Obtain the first intervention and termination nodes of all execution units, calculate the intervention length and match the stage number with the dense segment to generate the enterprise responsibility level mapping result;
[0147] S2: Based on the results of the enterprise responsibility level mapping, direction parameters and time series distribution are collected to determine the overlapping intervention relationship and generate a behavior conflict association table;
[0148] S3: Eliminate the paths containing exclusion structures according to the behavioral conflict association table, filter and combine the hierarchical continuous paths based on the enterprise responsibility level mapping results, and generate a set of controllable path structures;
[0149] S4: Based on the set of controllable path structures, the coverage density value of each path is calculated and sorted. The exclusion node level difference of the sorted consistent paths is extracted to build a judgment logic and generate a set of priority path sequences.
[0150] S5: Extract the order of responsibility nodes based on the priority path sequence set, construct the stage node group, detect the mapping relationship between direction parameters and levels, and generate a staged enterprise responsibility risk path map.
[0151] The above are merely preferred embodiments of the present invention and do not limit the present invention in any other form. Any technician familiar with the profession may use the technical content disclosed above to change or modify it into an equivalent embodiment with equivalent changes and apply it to other fields. However, any simple modification, equivalent change and modification made to the above embodiment based on the technical essence of the present invention without departing from the content of the technical solution of the present invention shall still fall within the scope of protection of the technical solution of the present invention.
Claims
1. AI-driven enterprise risk management system, characterized by: The system comprises: The responsibility weight analysis module obtains the time period of involvement of each responsible party in the risk event, and combines it with the event stage identifier to automatically determine the time density of the responsible party using AI to generate intelligent responsibility level mapping results; The behavior conflict recognition module identifies the conflict relationship between behavior nodes, determines the direction of opposition between behaviors, detects time overlap, and generates a behavior conflict association table; The path filtering generation module performs conflict filtering on the behavior paths based on the behavior conflict association table, and reorganizes the retainable paths in combination with the execution unit level content in the enterprise responsibility level mapping result to form a controllable path structure set; The sequence prioritization module automatically calculates the coverage density of nodes in each path based on the controllable path structure set and combines AI to sort all paths by coverage density value to generate a priority path sequence set; The risk path display module reads the node relationship structure in the priority path sequence set, constructs a path evolution structure according to the arrangement order of the responsible entities and behavior nodes in the path, decomposes each path into stage node groups, maps the corresponding responsibility levels and behavior trend directions, and forms a staged enterprise responsibility risk path map.
2. The AI-driven enterprise risk management system according to claim 1, characterized in that: The enterprise responsibility level mapping result includes the execution unit responsibility label, stage level distribution record, intervention time density, risk event node position, and time series action interval. The behavior conflict association table includes behavior opposition combination items, intervention overlap identifiers, exclusion structure mappings, conflict time segments, and behavior trend differences. The controllable path structure set includes intervention level combinations, conflict filtering paths, risk intervention controllable sequences, path behavior consistency indicators, and path reorganization mapping relationships. The priority path sequence set includes node coverage density values, path priority identifiers, path level judgment results, conflict analysis scores, and path sequence numbers. The staged enterprise responsibility risk path map includes the responsible entity hierarchical structure, behavior node trend vectors, stage node grouping relationships, path evolution graph structure, and map visualization mapping results.
3. The AI-driven enterprise risk management system according to claim 1, characterized in that: The responsibility weight parsing module includes: The execution unit extraction submodule obtains the original data sequence of the intervention risk event based on the enterprise multi-agent collaboration scenario, extracts the record items of the subject identity, task instruction number, and target label, screens all execution items with intervention behavior, and establishes the execution unit set corresponding to the event sequence number to generate the intervention behavior execution unit set. The time node identification submodule analyzes the task timestamp and intervention behavior identifier in each execution unit according to the intervention behavior execution unit set, identifies the first time node and the termination node in the event sequence, calculates the time span and position number, and aligns the number with the corresponding time period index in the full process event sequence to generate an execution unit time period index pair; The stage level generation submodule performs a joint comparison operation on each data according to the execution unit time period index pair, using the formula: Calculate the stage level label value L of the kth execution unit k , combined with the label level mapping rules, map the stage level of each execution unit to obtain the enterprise responsibility level mapping result, where T k Indicates the time span value of the kth execution unit, P k Indicates the stage number value corresponding to the kth execution unit, D k represents the event density fluctuation value in the time period of the kth execution unit, S k Indicates the standardized length value of the time period where the kth execution unit is located, C k Indicates the total value of the interaction between the kth execution unit and other units.
4. The AI-driven enterprise risk management system according to claim 1, characterized in that: The behavior conflict identification module includes: The risk feature detection submodule collects a sequence table of behavior codes, node types, and time tags based on the enterprise's internal behavior node records. It then screens the intervention trigger attributes and reaction response attributes of each behavior node to determine whether the intervention conditions are met. It then marks the node behaviors that meet the criteria as risk items and generates a numerical value for the risk intervention behavior. The direction trend learning submodule extracts the operation direction vector, time series transformation path and node distribution density of each behavior item according to the numerical value of the risk intervention behavior, using the formula: Calculate the behavior direction opposition value V r , compared with the direction opposition judgment standard value, screen the behavior combination that meets the direction opposition characteristics, and obtain the direction opposition combination identification value, where A r Indicates the operation direction vector value of the rth behavior item, B r Represents the direction vector value of the combined behavior term, M r It represents the sum of squares of the tangential offset values of the behavior item in the time series, E r represents the node density weight; The behavior overlap identification submodule extracts the start and end time values and time series index values of each group of direction-opposing behaviors based on the direction-opposing combination identification value, calculates the overlapping length of the time series intervals of the combination items, compares the overlapping length with the overlap judgment standard length, selects the combination items whose overlapping length is not less than the time overlap threshold, and obtains the time overlap behavior combination quantity; The conflict structure establishment submodule extracts the corresponding behavior combination relationship identifier, node index number and risk attribute value based on the time-coinciding behavior combination quantity, uniquely encodes the combination relationship, constructs a behavior relationship matrix, and makes a structural inclusion judgment for each combination relationship. The combination relationship that meets the exclusion conditions is included in the exclusion structure, establishes the coding association between the behavior nodes under the exclusion structure, and classifies the structure table according to the combination relationship structure rules to obtain the behavior conflict association table.
5. The AI-driven enterprise risk management system according to claim 1, characterized in that: The path filtering generation module: The behavior path extraction submodule extracts all behavior paths of the enterprise's current risk processing based on the behavior conflict association table, combines the execution unit information of the behavior nodes in the path, screens the paths of potential conflicting behaviors, generates a structure list of all behavior nodes and associated paths, and obtains the original behavior path set; The path conflict filtering submodule compares the behavior nodes in each path with the conflicting behavior nodes one by one according to the original behavior path set, filters the paths with conflicting relationships, and eliminates the paths that meet the conflict exclusion criteria to obtain a conflict-filtered behavior path set; The path reorganization submodule is based on the behavioral path set after conflict filtering and combines the execution unit level in the enterprise responsibility level mapping result to reorganize the retained paths according to the intervention level matching relationship. It constructs a new behavioral path by adjusting the node order, inserting new nodes or modifying the path structure, and outputs a controllable path structure set.
6. The AI-driven enterprise risk management system according to claim 1, characterized in that: The sequence prioritization module includes: The responsibility node extraction submodule extracts all nodes in each behavior path based on the controllable path structure set, identifies the corresponding responsibility unit number and responsibility level value, aggregates and codes the responsibility level relationship within the same path, establishes a node level distribution matrix based on the path number, and obtains the path responsibility level distribution data; The density sorting submodule extracts the node density value, node proportion value and node level difference value according to the path responsibility level distribution data, and compares and calculates the node coverage of each path using the formula: Calculate the coverage density value U of the mth path m , and perform sorting operations on all paths according to the density value to obtain the path coverage density sorting result, where N m Represents the node density value of the mth path, R m Indicates the average proportion of the responsibility level in the path, G m Indicates the difference value of the grade distribution in the path, Z m represents the path redundancy factor; The level judgment submodule determines whether there is equality in the ranking value based on the path coverage density ranking result, extracts the conflict attribute value, intervention priority label and responsibility level span value of the corresponding behavior node for the path group with consistent ranking value, calculates the average level weight within the path group, establishes the path priority relationship, and constructs the priority index list to obtain the priority path sequence set.
7. The AI-driven enterprise risk management system according to claim 1, characterized in that: The risk path display module: The node relationship construction submodule arranges the responsible entities and behavior nodes in each path based on the priority path sequence set, establishes the node relationship structure in the path, extracts the responsibility nodes and corresponding behavior types and hierarchical information in the path, constructs a node connection matrix according to the relationship between the responsibility hierarchy and the behavior direction, and generates the path node relationship structure; The path decomposition submodule decomposes each path into multiple stage node groups based on the path node relationship structure, groups the behavior nodes according to the order and responsibility level in the path, maps the responsibility level and behavior trend of each stage node group, obtains the behavior evolution path of each stage, and generates a stage node group mapping structure; The graph display submodule converts the decomposed path data into a graph form based on the stage node group mapping structure, arranges the nodes according to the hierarchy and development trend of the behavior nodes, and graphically displays the evolution structure of the path to form a staged corporate responsibility risk path graph.
8. An AI-driven enterprise risk management method, characterized by: The method is used to implement the AI-driven enterprise risk management system according to any one of claims 1 to 7, comprising the following steps: S1: Obtain the first intervention and termination nodes of all execution units, calculate the intervention length and match the stage number with the dense segment to generate the enterprise responsibility level mapping result; S2: Based on the enterprise responsibility level mapping results, direction parameters and time series distribution are collected, overlapping intervention relationships are determined, and a behavior conflict association table is generated; S3: excluding paths containing exclusion structures according to the behavior conflict association table, screening and combining level-continuous paths based on the enterprise responsibility level mapping result, and generating a controllable path structure set; S4: Calculate the coverage density value of each path and sort them according to the controllable path structure set, extract the exclusion node level difference of the sorted consistent paths, build a judgment logic, and generate a priority path sequence set; S5: Extract the order of responsibility nodes according to the priority path sequence set, construct a stage node group, detect the mapping relationship between direction parameters and levels, and generate a staged enterprise responsibility risk path map.
Citation Information
Cited By
Dynamic network attack and defense deduction system integrating multiple view angles
CN120675817A