Intelligent Root Cause Diagnosis Methods and Systems for Operational Risks in Financial Services

By collecting and analyzing data on operational risk events in financial services, a dynamic event correlation network is constructed. Root cause reasoning rules are then used to solve the problems of subjectivity and insufficient coverage in traditional methods, enabling accurate location and efficient management of the root causes of operational risk events.

CN120655396BActive Publication Date: 2025-10-28CHENGDU BINGJIAN INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511165702.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-20
Publication Date
2025-10-28
Estimated Expiration
2045-08-20

AI Technical Summary

Technical Problem

Traditional methods for diagnosing the root causes of operational risk events in financial services rely on human experience analysis and simple rule matching. These methods are highly subjective, inefficient, and unable to quickly address complex operational risk events. Furthermore, fixed rules cannot cover the ever-changing forms of risk and cannot accurately identify the true root cause of the event.

Method used

Collect operational risk event data, extract features to generate event feature sets, construct a dynamic event association network, use a preset root cause reasoning rule set to perform causal path weight iterative calculation, deeply explore the causal relationship behind the event, and accurately locate the root cause node.

Benefits of technology

By delving into the causal relationships behind events, the root causes of operational risk events can be accurately identified, improving the efficiency and accuracy of operational risk management in financial services and avoiding the subjectivity and limitations of traditional methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120655396B_ABST
    Figure CN120655396B_ABST
Patent Text Reader

Abstract

This application provides a method and system for intelligent root cause diagnosis of operational risks in financial services. First, it collects a dataset of operational risk events containing various information generated by these events within the financial service system. Next, it extracts features from the operational risk event dataset to generate an event feature set containing multiple characteristics. Then, it constructs a dynamic event association network based on the event feature set, identifying nodes and their impact strength parameters. Finally, it uses a pre-defined set of root cause inference rules to iteratively calculate causal path weights on the network, locating the root cause node set. Finally, it generates a root cause diagnosis result based on the root cause node set, including root cause type identifiers, impact path descriptions, and the contribution of associated features, thereby improving the accuracy and efficiency of root cause diagnosis for operational risks in financial services.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of risk control technology, and more specifically, to a method and system for intelligent diagnosis of the root causes of operational risks in financial services. Background Technology

[0002] In the financial services sector, operational risk events occur frequently, causing significant economic losses and reputational damage to financial institutions. Traditional methods for diagnosing the root causes of operational risk events primarily rely on manual experience analysis and simple rule matching. While manual experience analysis can dissect events based on the knowledge and experience of professionals, it suffers from high subjectivity and inefficiency, making it difficult to quickly address a large number of complex operational risk events. Moreover, manual analysis often focuses on surface phenomena and fails to delve into the deeper connections behind the events. Simple rule matching methods identify root causes based on pre-defined fixed rules. However, the financial services environment is complex and ever-changing, with operational risk events manifesting in various forms and influenced by diverse factors. Fixed rules cannot cover all situations. For novel or highly concealed operational risk events, rule matching methods are often ineffective, failing to accurately identify the true root cause and thus hindering financial institutions from developing effective risk control measures. Summary of the Invention

[0003] In view of this, the purpose of this application is to provide an intelligent diagnostic method and system for the root causes of operational risks in financial services.

[0004] According to a first aspect of this application, a method for intelligent diagnosis of the root causes of operational risks in financial services is provided, the method comprising:

[0005] Collect a set of operational risk event data generated when an operational risk event occurs in the financial service system. The set of operational risk event data includes event occurrence time information, business operation link identifiers, system interaction log fragments, and manual operation records.

[0006] Feature extraction is performed on the operational risk event dataset to generate an event feature set, which includes business process features, system interaction features, personnel operation features, and environmental impact features.

[0007] A dynamic event association network is constructed based on an event feature set. The nodes of the dynamic event association network include event nodes and feature nodes in the event feature set. The directed edges between nodes represent the influence strength parameters of feature nodes on event nodes.

[0008] By using a pre-defined set of root cause reasoning rules to iteratively calculate the causal path weights of a dynamic event association network, and by analyzing the transitivity of node influence strength parameters, the root cause node set of operational risk events can be located.

[0009] Generate root cause diagnostic results based on the root cause node set, including root cause type identifiers, descriptions of influencing paths, and contributions of associated features.

[0010] According to a second aspect of this application, an intelligent root cause diagnosis system for operational risks in financial services is provided. The intelligent root cause diagnosis system for operational risks in financial services includes a machine-readable storage medium and a processor. The machine-readable storage medium stores machine-executable instructions. When the processor executes the machine-executable instructions, the intelligent root cause diagnosis system for operational risks in financial services implements the aforementioned intelligent root cause diagnosis method for operational risks in financial services.

[0011] According to a third aspect of this application, a computer-readable storage medium is provided, wherein computer-executable instructions are stored therein, and when the computer-executable instructions are executed, the aforementioned intelligent root cause diagnosis method for operational risks in financial services is implemented.

[0012] Based on any of the above aspects, the technical effect of this application is as follows:

[0013] By collecting operational risk event data sets containing multi-dimensional information such as event occurrence time and business operation step identifiers, feature extraction is performed on the operational risk event data sets to generate event feature sets containing features of various aspects such as business processes and system interactions. Based on the event feature sets, a dynamic event association network is constructed, clearly representing the relationship and influence strength between events and features with nodes and directed edges, intuitively presenting the complex association structure of operational risk events. Using a preset root cause reasoning rule set, causal path weight iterative calculation is performed on the dynamic event association network. Through transitivity analysis of node influence strength parameters, the causal relationships behind the events can be deeply explored, and the root cause node set of operational risk events can be accurately located, avoiding the subjectivity and limitations of traditional methods. Root cause diagnosis results containing detailed information are generated based on the root cause node set, effectively improving the level and efficiency of operational risk management in financial services. Attached Figure Description

[0014] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0015] Figure 1 A flowchart illustrating the intelligent diagnostic method for the root causes of operational risks in financial services provided in an embodiment of this application is shown.

[0016] Figure 2 This illustration shows a schematic diagram of the component structure of an intelligent event root cause diagnosis system for financial service operation risks, provided in an embodiment of this application, for implementing the above-described intelligent event root cause diagnosis method for financial service operation risks. Detailed Implementation

[0017] The embodiments of this application are described below with reference to the accompanying drawings. It should be understood that the embodiments described below with reference to the accompanying drawings are exemplary descriptions for explaining the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions of the embodiments of this application.

[0018] Those skilled in the art will understand that, unless otherwise stated, the singular forms “a,” “an,” “the,” and “the” used herein may also include the plural forms. It should be further understood that the terms “comprising” and “including” as used in embodiments of this application mean that the corresponding feature can be implemented as the presented feature, information, data, step, operation, element, and / or component, but do not exclude implementation as other features, information, data, step, operation, element, component, and / or combinations thereof supported by the art. It should be understood that when an element is said to be “connected” or “coupled” to another element, the element may be directly connected or coupled to the other element, or it may mean that the element and the other element are connected through an intermediate element. Furthermore, “connected” or “coupled” as used herein may include wireless connection or wireless coupling, and the term “and / or” as used herein indicates at least one of the items defined by the term; for example, “A and / or B” may be implemented as “A,” or as “B,” or as “A and B.”

[0019] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings. The technical solutions of the embodiments of this application and the technical effects produced by the technical solutions of this application will be explained below through the description of several exemplary embodiments. It should be noted that the following embodiments can be referenced, borrowed from, or combined with each other, and the same terms, similar features, and similar implementation steps in different embodiments will not be described again.

[0020] Figure 1 This illustration shows a flowchart of the intelligent root cause diagnosis method and system for operational risks in financial services provided in an embodiment of this application. It should be understood that in other embodiments, the order of some steps in the intelligent root cause diagnosis method for operational risks in financial services in this embodiment can be shared according to actual needs, or some steps can be omitted or maintained. The detailed steps of the intelligent root cause diagnosis method for operational risks in financial services include:

[0021] Step S110: Collect the operational risk event data set generated when an operational risk event occurs in the financial service system. The operational risk event data set includes event occurrence time information, business operation link identifier, system interaction log fragments, and manual operation records.

[0022] In this embodiment, the scenario is a risk event related to the "redemption of multi-channel linked wealth management products". When this risk event occurs, the data collection mechanism is first activated. The event occurrence time information is obtained through the system's built-in clock module, for example, recorded as the specific moment the event occurred.

[0023] The business operation step identifier is a unique identifier pre-defined for each step during the business process design. It covers multiple steps, including initiating a redemption request for a wealth management product, identity verification, credit limit verification, fund deduction, return calculation, redemption confirmation, and fund arrival notification. Each step's identifier consists of a specific combination of characters, including information such as the step category and the business line to which it belongs. For example, the identifier for a certain step may consist of a business line code and a step sequence number.

[0024] The system interaction log fragments originate from communication records between multiple systems involved in this business, including the front-end trading system, the back-end core accounting system, the risk control system, and the data storage system. These log fragments record in detail the requests and responses between systems, including the request type, the parameters carried, the response status, and the processing time. For example, when the front-end trading system sends a redemption request to the core accounting system, the log will record the initiator of the request, the recipient, the financial product code included in the request, the redemption amount, and the preliminary processing result returned by the core accounting system.

[0025] Manual operation records cover all actions taken by staff during the redemption process, including customer information entered by tellers, verification of customer qualifications by auditors, and authorization actions by authorized personnel. These records are captured and stored by the system in real time, including information such as the operator's identification, the specific content of the operation, the object of the operation, and the result of the operation. For example, when auditors review the redemption materials submitted by customers, the system records the auditor's number, the name of the reviewed materials, the result of approval or rejection, and any remarks added during the review process.

[0026] Step S120: Extract features from the operational risk event data set to generate an event feature set, which includes business process features, system interaction features, personnel operation features, and environmental impact features.

[0027] In the case of operational risk events related to "multi-channel linked wealth management product redemption", when extracting features from the collected operational risk event data set, it is necessary to focus on four aspects: business process, system interaction, personnel operation, and environmental impact.

[0028] First, to extract the characteristics of the business process, it is necessary to sort out the process nodes of the entire wealth management product redemption business, analyze the sequence and dependencies between each node, and the deviations between the actual execution process and the standard process. For example, analyze whether the flow from the initiation of the redemption request to the identity verification and credit limit verification stages conforms to the preset process sequence, and whether the execution time of each stage is within the standard range.

[0029] To identify system interaction characteristics, it's necessary to extract information such as interaction frequency, response latency, and error code occurrences between different systems from system interaction log fragments. For example, this involves counting the number of interactions between the front-end transaction system and the core accounting system per unit time, calculating the response latency for each interaction, and the frequency and location distribution of different types of error codes.

[0030] The extraction of personnel operation characteristics revolves around the operator's operation sequence, permission matching, and operation compliance. For example, based on the operator's operation records, the order of their operations is compiled to determine whether the operator's permissions match the permissions required by the object being operated on, and whether the operation process complies with preset compliance rules.

[0031] Extracting environmental impact characteristics requires considering external environmental factors at the time of the operational risk event. These factors may include network conditions, system load, market volatility, and policy changes. For example, it's necessary to record information such as network bandwidth usage, system server CPU utilization, market interest rate fluctuations, and any relevant financial policy adjustments at the time of the event.

[0032] Step S121: Perform process node parsing on the business operation link identifiers in the operation risk event dataset, extract the execution order of the business links involved in the operation risk event and the dependencies between links, and generate a business process node sequence.

[0033] In the scenario of "multi-channel linked wealth management product redemption," when parsing the process nodes of business operation links, the first step is to obtain all business operation link identifiers related to the redemption event. These identifiers are extracted in chronological order of business occurrence, and then the specific content and nature of each link are determined by parsing the information in the identifiers.

[0034] For example, the identifiers can be used to identify steps such as "redemption request initiation," "identity verification," "credit limit verification," "funds deduction," "profit calculation," "redemption confirmation," and "funds arrival notification." Next, the execution order of these steps is analyzed to determine that "redemption request initiation" is the starting point of the entire process. "Identity verification" is mandatory afterward, and only after successful identity verification can the "credit limit verification" step proceed, and so on.

[0035] Meanwhile, the dependencies between the analysis steps are analyzed. For example, the "funds deduction" step depends on the result of the "credit limit verification" step. Funds can only be deducted after the credit limit verification confirms that the customer has sufficient redeemable shares. Through the above analysis process, these steps are arranged in chronological order and according to their dependencies to generate a sequence of business process nodes.

[0036] Step S122: Calculate the execution time interval parameter of adjacent business links based on the business process node sequence, and generate the process deviation index in the business process characteristics by combining the standard execution time of each business link. The process deviation index is used to represent the degree of deviation between the actual execution time and the standard execution time.

[0037] After obtaining the sequence of business process nodes, for the "multi-channel linked wealth management product redemption" business, the execution time interval parameter between adjacent business steps is calculated. For each pair of adjacent steps in the sequence, such as the "identity verification" step and the "credit limit verification" step, the end time of the "identity verification" step and the start time of the "credit limit verification" step are obtained, and the difference between the two is the execution time interval parameter between these two steps.

[0038] Each business process has a preset standard execution time, which is determined based on historical business data and business specifications. For example, the standard execution time for the "identity verification" process is a fixed length, and the "credit limit verification" process also has its corresponding standard execution time.

[0039] When calculating the process deviation index, for each business step, the actual execution time of that step is subtracted from its standard execution time to obtain the time deviation value. Then, the time deviation value is compared with the standard execution time; the ratio is the process deviation index for that step. For example, if the actual execution time of the "credit limit verification" step is longer than the standard execution time, then its process deviation index is positive, and the larger the value, the greater the deviation; if the actual execution time is shorter than the standard execution time, then it is negative.

[0040] Step S123: Extract the interaction behavior sequence from the system interaction log fragments in the operational risk event dataset, identify the request and response interaction records between system components, and generate system interaction features including interaction frequency, response delay, and error code distribution.

[0041] In the scenario of "multi-channel linked wealth management product redemption," when extracting the interaction behavior sequence from system interaction log fragments, the log fragments are first filtered to retain log content related to the redemption event. Then, these logs are sorted in chronological order to identify the request-response interaction records between system components.

[0042] For example, logs can be used to identify interactions such as the front-end trading system sending a risk assessment request to the risk control system, and the risk control system returning the assessment result; the core accounting system querying the data storage system for client holdings information, and the data storage system returning the queried data. These interaction records are then arranged chronologically to form a sequence of interactive behaviors.

[0043] Next, calculate the interaction frequency, which is the number of interactions between the same system components per unit of time. For example, count the number of interactions between the front-end transaction system and the core accounting system within one hour.

[0044] Response latency refers to the time taken from when the system sends a request to when it receives a response. For each interaction record, the difference between the request sending time and the response receiving time is calculated to obtain the response latency for each interaction. Then, these response latencies are statistically analyzed to obtain their distribution characteristics, such as the maximum value, minimum value, and median.

[0045] Generating error code distributions requires identifying error code records in the interaction sequence, such as error codes returned by the angel system or query failure error codes returned by the data storage system. The frequency of different error code types and their positions within the interaction sequence are then counted to form the error code distribution.

[0046] Step S1231: Standardize the log format of the system interaction log fragments in the operational risk event data set, extract the interaction behavior sequence containing requester identifier, responder identifier, request type, request timestamp and response timestamp from the standardized system interaction log, and arrange them in ascending order of request timestamp to form a time-series interaction behavior sequence.

[0047] In the scenario of "multi-channel linked wealth management product redemption," system interaction log fragments may come from different systems, and the log formats of each system may differ. Therefore, it is necessary to first standardize the log format. For example, this includes standardizing the representation format of dates and times in the logs, standardizing the naming rules for requester and responder identifiers, and standardizing the description method of request types.

[0048] After standardization, information such as requester identifier, responder identifier, request type, request timestamp, and response timestamp are extracted from the logs. For example, the requester identifier might be "Front-end Transaction System 01", the responder identifier might be "Core Accounting System 03", the request type might be "Redemption Share Inquiry", and the request and response timestamps are accurate to milliseconds.

[0049] The extracted information is combined into basic units of an interaction behavior sequence, and then these units are arranged in ascending order of request timestamps to form a temporal interaction behavior sequence. This sequence clearly demonstrates the temporal order of interactions between systems.

[0050] Step S1232: The number of interactions between the same requester identifier and the responder identifier in the time sequence of statistical time interaction behavior is used as the interaction frequency parameter. The unit time is determined based on the time granularity of the event occurrence time information.

[0051] In the scenario of "multi-channel linked wealth management product redemption", the time granularity is based on the event occurrence time information. For example, if the event occurs in the morning of a certain day, the time granularity may be determined to be half an hour. Then, in the time sequence of interactive behaviors, the interaction records with the same requester identifier and responder identifier are found.

[0052] For example, for the interaction records between the requester identified as "Front-end Transaction System 01" and the responder identified as "Core Accounting System 03", the number of interactions between the two in each half-hour period is counted. This number is the interaction frequency parameter for that unit of time. Through the above statistics, we can know how the frequency of interaction between different system components changes over time.

[0053] Step S1233: Calculate the response delay parameter for each interaction in the time-series interaction sequence. The response delay parameter is the difference between the response timestamp and the request timestamp. Calculate the distribution characteristics of the response delay parameter, which include the maximum value, minimum value, and median.

[0054] For each interaction in the time-series of interactive behaviors, in the "multi-channel linked wealth management product redemption" scenario, obtain its request timestamp and response timestamp. For example, in a certain interaction, the request timestamp is a specific moment, and the response timestamp is a slightly later moment; the difference between the two is the response latency parameter of that interaction.

[0055] By statistically analyzing the response latency parameters of all interactive behaviors, we can identify the maximum value (the longest response latency), the minimum value (the shortest response latency), and the median (the value in the middle after sorting all response latency parameters by magnitude). These distribution characteristics can reflect the overall situation and fluctuation range of the system's interactive response speed.

[0056] Step S1234: Identify error code records in the temporal interaction behavior sequence, count the occurrence frequency of different error code types and their position distribution in the interaction behavior sequence, and generate an error code distribution histogram and the corresponding cumulative occurrence probability curve.

[0057] Carefully identify error code records within the time-series of interactions in the "multi-channel linked wealth management product redemption" process. Examples include error codes returned by the order system and "connection timeout" error codes returned by the data storage system.

[0058] For the identified error codes, they are categorized and statistically analyzed by type, recording the frequency of each error code type. Simultaneously, the position of each error code within the interaction sequence is marked, indicating in which interaction the error code appeared.

[0059] Based on the statistical results, an error code distribution histogram is generated. The horizontal axis of the histogram represents the error code type, and the vertical axis represents the frequency of occurrence, visually displaying the occurrence frequency of different error codes. Then, based on the location distribution of error codes, a cumulative occurrence probability curve is plotted. This cumulative occurrence probability curve reflects the cumulative probability of error codes occurring up to a certain position in the interaction behavior sequence.

[0060] Step S1235: Perform feature fusion on the distribution characteristics of the interaction frequency parameter, response delay parameter, and error code distribution histogram, and perform feature vectorization processing according to the system interaction dimension to generate system interaction features. The dimension of the system interaction features is consistent with the dimension of the system interaction features in the event feature set.

[0061] In the scenario of "redemption of multi-channel linked wealth management products", the distribution characteristics (maximum, minimum, median) of the interaction frequency parameters and response delay parameters obtained above, as well as the information contained in the error code distribution histogram, are fused together.

[0062] For example, information such as the number of interactions per unit time in the interaction frequency parameter, the maximum, minimum, and median response latency, and the frequency of different error code types are integrated together. Then, according to the system interaction dimension, this information is converted into vector form, with each vector element corresponding to a feature information item.

[0063] Ensure that the dimensions of the generated system interaction features are consistent with the dimensions of the system interaction features in the event feature set, so that they can be smoothly integrated into the event feature set for unified processing later.

[0064] Step S124: Analyze the manual operation records in the operation risk event dataset, extract the operation sequence, permission level and operation compliance verification results of the operators, and generate personnel operation characteristics including operation proficiency parameters, permission matching parameters and compliance verification pass rate.

[0065] In the scenario of "multi-channel linked wealth management product redemption", when analyzing manual operation records, the first step is to extract relevant information about the operator from the records. This includes the operator's identification, the time of the operation, the object of the operation (such as the customer's redemption application form), the actions performed (such as review, authorization, data entry, etc.), and the result of the operation (such as approval, disapproval, success, failure, etc.).

[0066] Based on this information, the operator's operation sequence is compiled, which is a series of actions performed by the operator in chronological order. Simultaneously, the operator's permission level is queried to determine the scope of their operational permissions.

[0067] Then, each operation in the operation sequence undergoes compliance verification to determine whether it conforms to business specifications and operational procedures, and the verification results are recorded. Based on the execution status of the operation sequence, an operation proficiency parameter is calculated. The operator's permission level is compared with the required permissions of the operation object to obtain a permission matching parameter. The compliance verification pass rate is calculated based on the compliance verification results, and finally, the operator's operational characteristics are generated.

[0068] Step S1241: Perform structured parsing on the manual operation records in the operation risk event dataset, extract the operator identifier, operation time, operation object, operation action and operation result fields, and generate a structured operation record table.

[0069] In the scenario of "multi-channel linked redemption of wealth management products," specific parsing rules are used to extract key information from unstructured records when performing structured analysis of manual operation records. For example, the operator's employee number can be identified from a scanned copy of a paper record, the specific time of the operation can be extracted from the system log, the target of the operation can be determined as a customer's wealth management product redemption application, and it can be clarified whether the operation is "review" or "authorization," and whether the operation result is "approved" or "rejected."

[0070] The extracted fields, including operator identification, operation time, operation object, operation action, and operation result, are organized according to a preset table format to generate a structured operation record table. Each row in the table represents an operation record, and each column corresponds to a field, making the operation records clearer, more standardized, and easier for subsequent processing.

[0071] Step S1242: Sort the operation actions in the structured operation record table according to the operator identification and operation time to generate the operation sequence of the operator arranged in chronological order. The operation sequence includes the continuously executed operation actions and the corresponding operation objects.

[0072] In the scenario of "redemption of wealth management products through multiple channels", the structured operation record form is grouped according to the operator's identification, and the operation records of the same operator are grouped together.

[0073] Within each group, the operations are ordered according to their chronological order. For example, an operator first reviews customer A's redemption request, and then enters customer B's redemption request. These operations are then arranged in chronological order.

[0074] The generated operation sequence clearly shows the continuous actions performed by the operator over a period of time, as well as the corresponding operation objects for each action, such as the customer's redemption application form, related contract documents, etc.

[0075] Step S1243: Calculate the operation proficiency parameter based on the execution interval time of the operation actions in the operation sequence and the number of successful operation results. The operation proficiency parameter is negatively correlated with the average execution interval time and positively correlated with the number of successful operation results.

[0076] In the scenario of "multi-channel linked wealth management product redemption", for the operator's operation sequence, the execution interval time between each adjacent operation action is calculated, that is, the difference between the completion time of the previous operation and the start time of the next operation. Then, the average of these interval times is calculated to obtain the average execution interval time.

[0077] Simultaneously, the number of successful operations in the sequence is counted. The calculation of the operation proficiency parameter takes into account both the average execution interval and the number of successes. The shorter the average execution interval, the faster the operator's operation speed, and the higher the operation proficiency parameter; the more successes, the higher the operation proficiency parameter.

[0078] For example, if an operator has a short average execution interval and a high number of successful executions, their operational proficiency parameter is relatively high; conversely, it is low.

[0079] Step S1244: Query the preset permission level table corresponding to the operator identifier, obtain the operator's theoretical permission level, compare the theoretical permission level with the permission level required by the operation object, and calculate the permission matching degree parameter, which is the ratio of the theoretical permission level to the required permission level.

[0080] In the scenario of "multi-channel linked wealth management product redemption", the theoretical authority level of an operator can be obtained by querying a preset authority level table through the operator's identifier. For example, if the operator's theoretical authority level is a certain level, it represents the scope of operations that they can perform.

[0081] Next, determine the required permission level for the target object. For example, the required permission level for redemption authorization of high-risk financial products is a different level. Compare the operator's theoretical permission level with the required permission level for the target object, and calculate the ratio between the two. This ratio is the permission matching parameter.

[0082] If the ratio is 1, it means the permissions are fully matched; if the ratio is greater than 1, it means the operator's permissions are higher than the required permissions; if the ratio is less than 1, it means the permissions are insufficient.

[0083] Step S1245: Call the preset operation compliance verification rule library, perform compliance verification on each operation action in the operation sequence, record the number of compliant operations and the number of non-compliant operations, and calculate the compliance verification pass rate, which is the ratio of the number of compliant operations to the total number of operations.

[0084] In the scenario of "multi-channel linked redemption of wealth management products," a pre-defined operational compliance verification rule base is invoked. This rule base contains rules such as business specifications and process requirements that various operational actions must comply with. For example, for the "review" operation, the rule base may stipulate that the reviewer must see the customer's complete identity materials and proof of holding the wealth management product before conducting the review, and the review time shall not exceed a fixed duration; for the "authorization" operation, the rule base may require the authorizing personnel to verify that the result of the previous review step has passed before authorizing, and the authorizing personnel's permission level must not be lower than the permission level required for this operation.

[0085] When performing compliance checks on each action in the operation sequence, each action is compared with the corresponding rule in the rule base. For example, if there is an "audit" action record in the operation sequence, the check will examine whether the audit action was performed after the customer's identity materials and proof of possession were complete, and whether the audit time was within the specified time limit. If both conditions are met, the audit action is deemed compliant; if either condition is not met, it is deemed non-compliant.

[0086] For each operation in the operation sequence, the above method is used for verification, and the number of compliant operations and the number of non-compliant operations are recorded separately. The total number of operations is the sum of the number of compliant and non-compliant operations. Finally, the number of compliant operations is divided by the total number of operations to obtain the compliance verification pass rate.

[0087] Step S1246: Normalize the operation proficiency parameter, permission matching parameter, and compliance verification pass rate according to the personnel operation dimension to generate personnel operation features. Each component of the personnel operation features corresponds to the operation proficiency parameter, permission matching parameter, and compliance verification pass rate, respectively.

[0088] In the scenario of "multi-channel linked wealth management product redemption", since the range of values ​​for operation proficiency parameters, permission matching parameters and compliance verification pass rate may be different, normalization processing is required according to the personnel operation dimension in order to facilitate subsequent feature fusion and analysis.

[0089] For example, the original value range of the operation proficiency parameter might be 0 to a relatively large value, the value range of the permission matching parameter might be 0 to 2, and the value range of the compliance verification pass rate might be 0 to 1. During normalization, the value of each parameter is mapped to the range of 0 to 1. Specifically, for the operation proficiency parameter, the current value of the parameter is subtracted from its possible minimum value, and then divided by the difference between its maximum and minimum values; for the permission matching parameter, if its value is greater than 1, it is normalized to 1, otherwise the original value is kept unchanged; the compliance verification pass rate itself is within the range of 0 to 1, and can be directly used as the normalized value.

[0090] After normalization, these three parameters are combined into a vector to generate personnel operation characteristics. The first component of the vector corresponds to the normalized operation proficiency parameter, the second component to the normalized permission matching parameter, and the third component to the normalized compliance verification pass rate.

[0091] Step S125: Integrate business process features, system interaction features, and personnel operation features, and combine them with external environmental factors recorded when the operational risk event occurs to generate environmental impact features. Then, perform feature splicing processing on the business process features, system interaction features, personnel operation features, and environmental impact features according to preset dimension weights to generate an event feature set.

[0092] In the scenario of "multi-channel linked wealth management product redemption", the first step is to integrate the generated business process characteristics, system interaction characteristics, and personnel operation characteristics. The business process characteristics may include multiple process deviation indicators, the system interaction characteristics are a multi-dimensional vector, and the personnel operation characteristics are also a three-dimensional vector.

[0093] Next, environmental impact characteristics are generated by recording external environmental factors at the time of the operational risk event. These external environmental factors include network conditions, system load, market volatility, and policy change information. For example, network conditions can be reflected by indicators such as network bandwidth utilization, network latency, and packet loss rate; system load can be represented by indicators such as server CPU utilization, memory usage, and disk I / O speed; market volatility can be reflected by indicators such as the volatility of market indices related to financial products and the rate of change in trading volume; and policy change information can be quantified by whether new policies have been introduced, and whether policies restrict or encourage the redemption of such financial products. These indicators are integrated to form environmental impact characteristics, which are also presented in the form of a multi-dimensional vector.

[0094] Then, the business process features, system interaction features, personnel operation features, and environmental impact features are concatenated according to preset dimension weights. The preset dimension weights are determined based on the importance of each feature in historical risk event analysis; for example, business process features may be assigned higher weights, while environmental impact features may be assigned relatively lower weights. During concatenation, the feature vectors are arranged and combined according to their weight ratios to form an event feature set.

[0095] Step S130: Construct a dynamic event association network based on the event feature set. The nodes of the dynamic event association network include event nodes and feature nodes in the event feature set. The directed edges between nodes represent the influence strength parameters of feature nodes on event nodes.

[0096] In the scenario of "multi-channel linked wealth management product redemption," when constructing a dynamic event association network, the nodes in the network are first identified. The operational risk event of this "multi-channel linked wealth management product redemption" is defined as an event node. Simultaneously, each specific feature contained in the business process features, system interaction features, personnel operation features, and environmental impact features of the event feature set is defined as a feature node. For example, in the business process features, "deviation degree of the quota verification process" and "deviation degree of the fund deduction process" are each treated as independent feature nodes; in the system interaction features, "interaction frequency between the front-end transaction system and the core accounting system" and "maximum response latency" are also treated as feature nodes.

[0097] Next, the influence strength parameter between each feature node and the event node is calculated. The magnitude of this influence strength parameter depends on the degree of influence of the feature represented by the feature node during the occurrence of the risk event. For example, if the "deviation degree of the credit limit verification process" is large, and this deviation directly leads to the anomaly in the redemption operation, then the influence strength parameter value between the feature node and the event node is relatively large; conversely, if a feature has a small impact during the occurrence of the event, then the corresponding influence strength parameter value is small.

[0098] Then, based on the calculated influence strength parameters, directed edges are established between feature nodes and event nodes. The direction of the directed edges points from the feature nodes to the event nodes, and the attributes of the edges are the corresponding influence strength parameters. Simultaneously, connections are established for the relationships between feature nodes. For example, the feature node "low operator permission matching degree" may be associated with the feature node "operation compliance verification failed," and connections and corresponding parameters can be established based on the degree of their association. Through this method, a dynamic event association network is constructed.

[0099] Step S131: Define each operational risk event in the operational risk event dataset as an event node in the dynamic event association network, and define each dimension feature in the event feature set as a feature node, forming a two-layer node structure containing an event node layer and a feature node layer.

[0100] In the scenario of "multi-channel linked wealth management product redemption", the operational risk event data set may contain multiple related operational risk events, such as multiple redemption failure events or redemption amount calculation errors that occur within the same time period. Each of the above events will be defined as an event node in a dynamic event association network. Each event node has its own unique identifier to distinguish different events.

[0101] Each dimension of the event feature set, such as the process deviation indicators in the business process features, the interaction parameters in the system interaction features, the three parameters in the personnel operation features, and the environmental indicators in the environmental impact features, will be defined as feature nodes. Each feature node also has its own specific name and identifier to clearly identify the feature it represents.

[0102] These nodes are organized hierarchically, forming a two-layer node structure: an event node layer and a feature node layer. The event node layer is located at the top and contains all event nodes; the feature node layer is located at the bottom and contains all feature nodes. This two-layer structure makes the network hierarchy clear and facilitates subsequent analysis of the relationship between feature nodes and event nodes.

[0103] Step S132: Calculate the initial value of the association strength between each feature node and the event node. The initial value of the association strength is determined based on the product of the frequency of occurrence and the degree of impact assessment of the feature corresponding to the feature node when the operational risk event occurs.

[0104] In the scenario of "multi-channel linked redemption of wealth management products", when calculating the initial value of the correlation strength between feature nodes and event nodes, the frequency of occurrence of the feature corresponding to each feature node when the operation risk event occurs is first counted. For example, the ratio of the number of times the feature "large deviation in the quota verification process" occurs in this and several related redemption risk events to the total number of events is the frequency of occurrence of this feature.

[0105] Then, the degree of impact of the feature is assessed to obtain an impact assessment value. The assessment considers the extent to which the feature contributes to the occurrence of the event. For example, if the feature "excessive delay in the response of the fund deduction system" directly causes the redemption funds to not arrive in time, then its impact assessment value will be high; while if a certain environmental factor feature has a small impact on the event, its assessment value will be low.

[0106] Finally, the frequency of occurrence of the feature node is multiplied by the impact assessment value, and the result is the initial value of the association strength between the feature node and the event node. For example, if the frequency of occurrence of "low operator compliance verification pass rate" is 0.6 and the impact assessment value is 0.8, then the initial value of the association strength between it and the corresponding event node is 0.6 multiplied by 0.8.

[0107] Step S1321: Count the number of times the feature corresponding to the feature node appears in all operational risk events in the operational risk event dataset, and calculate the occurrence frequency, which is the ratio of the occurrence frequency to the total number of operational risk events.

[0108] In the scenario of "multi-channel linked wealth management product redemption", for each feature node, all operational risk events in the operational risk event dataset are traversed, and the number of times the feature appears in these events is counted. For example, the feature "error code appears in the interaction between the front-end trading system and the core accounting system" appears 30 times out of 100 operational risk events in the dataset, so its occurrence count is 30.

[0109] The total number of operational risk events is the total number of operational risk events contained in the dataset, which is 100 in this case. Then, the frequency of occurrence is obtained by dividing the number of occurrences by the total number of operational risk events, i.e., 30 divided by 100. The result is the frequency of occurrence of this feature.

[0110] Step S1322: Collect root cause analysis reports of historical operational risk events, extract the number of root cause mentions related to the features corresponding to the feature nodes in the root cause analysis reports, and calculate the impact assessment value. The impact assessment value is positively correlated with the number of root cause mentions.

[0111] In the scenario of "multi-channel linked wealth management product redemption," root cause analysis reports of past operational risk events related to this type of redemption business are collected. These reports analyze in detail the root causes of the events, extracting the frequency of root cause mentions for each characteristic node. For example, in historical reports, the characteristic "large deviation in the quota verification process" was mentioned as a root cause 25 times; the characteristic "system response delay" was mentioned as a root cause 18 times.

[0112] The impact assessment value is positively correlated with the number of times the root cause is mentioned; that is, the more times it is mentioned, the greater its impact in causing the risk event, and the higher the corresponding impact assessment value. For example, the impact assessment value of the most frequently mentioned feature can be set as a baseline value, and the impact assessment values ​​of other features are calculated based on the ratio of their mention counts to the baseline value. If "large deviation in the credit limit verification process" is mentioned the most, at 25 times, and its impact assessment value is set to 0.9, then the impact assessment value of "system response delay" would be (18 / 25) multiplied by 0.9, yielding the corresponding result.

[0113] Step S1323: Standardize the occurrence frequency to obtain the standardized occurrence frequency.

[0114] In the scenario of "redemption of wealth management products through multiple channels", the frequency of occurrence of features corresponding to different feature nodes may be in different numerical ranges. In order to make them comparable and calculated on the same scale, the frequency of occurrence needs to be standardized.

[0115] For example, one feature has a frequency of 0.6, another has a frequency of 0.3, and yet another has a frequency of 0.8. During standardization, the maximum and minimum frequencies are first identified; let's say the maximum is 0.9 and the minimum is 0.1. Then, for each frequency, the standardized frequency is obtained by dividing (the frequency minus the minimum) by (the maximum minus the minimum). For instance, the standardized frequency for 0.6 is (0.6 - 0.1) divided by (0.9 - 0.1); the standardized frequency for 0.3 is (0.3 - 0.1) divided by (0.9 - 0.1), and so on.

[0116] Step S1324: Weight the impact assessment value to generate a weighted impact assessment value. Different type weights are assigned according to the feature type to which the feature node belongs: business process features are assigned the first type weight, system interaction features are assigned the second type weight, personnel operation features are assigned the third type weight, and environmental impact features are assigned the fourth type weight.

[0117] In the scenario of "multi-channel linked wealth management product redemption," different weights are assigned to each type of feature node based on its feature type (business process features, system interaction features, personnel operation features, and environmental impact features). For example, considering the characteristics of this type of business, business process features have a relatively large impact on risk events, so the first type is assigned a weight of 0.35; system interaction features are next, so the second type is assigned a weight of 0.3; personnel operation features are assigned a weight of 0.25; and environmental impact features are assigned a weight of 0.1.

[0118] Then, the impact assessment value of each feature node is multiplied by the type weight corresponding to its type to obtain the weighted impact assessment value. For example, if a node belonging to the business process feature has an impact assessment value of 0.8, then its weighted impact assessment value is 0.8 multiplied by 0.35 to obtain the corresponding result; if a node belonging to the personnel operation feature has an impact assessment value of 0.7, then its weighted impact assessment value is 0.7 multiplied by 0.25, and so on.

[0119] Step S1325: Multiply the standardized occurrence frequency by the weighted influence evaluation value to obtain the initial value of the association strength between the feature node and the event node. The initial value of the association strength ranges from zero to the maximum value of the type weight.

[0120] In the scenario of "redemption of multi-channel linked wealth management products", the standardized frequency of occurrence is multiplied by the weighted impact assessment value. For example, if the standardized frequency of occurrence of a certain feature node is 0.6 and the weighted impact assessment value is 0.28, then the result of multiplying the two is the initial value of the correlation strength between the feature node and the event node.

[0121] Since the normalized frequency ranges from 0 to 1, and the weighted impact assessment value ranges from 0 to the maximum value of the type weight (0.35 in this case), the initial value of the association strength ranges from zero to the maximum value of the type weight.

[0122] Step S133: Perform statistical analysis on the co-occurrence relationship between feature nodes, calculate the probability of any two feature nodes co-occurring in the same operational risk event data set as the co-occurrence correlation parameter, and generate undirected edges between feature nodes and their corresponding co-occurrence correlation parameters.

[0123] In the scenario of "multi-channel linked wealth management product redemption," statistical analysis is performed on the co-occurrence relationships between feature nodes. Co-occurrence refers to the situation where two feature nodes, representing the same feature, appear simultaneously in the same operational risk event. For example, the number of times the feature nodes "low operator permission matching degree" and "operation compliance verification failed" co-occur in the same operational risk event is counted.

[0124] Then, calculate the probability of their co-occurrence, that is, the number of co-occurrences divided by the total number of operational risk events in the operational risk event data set. The result obtained is the co-occurrence correlation degree parameter between these two feature nodes.

[0125] For any two feature nodes, calculate the co-occurrence correlation degree parameter in the above manner. According to the calculation results, establish an undirected edge between the two feature nodes with a co-occurrence probability greater than zero. The undirected edge has no direction, indicating that the association between the two feature nodes is mutual, and use the co-occurrence correlation degree parameter as the attribute of the undirected edge.

[0126] Step S134: Sort the event nodes according to the event occurrence time information, calculate the transfer probability parameter between the event nodes with adjacent timestamps, and generate a time-series directed edge between the event nodes and the corresponding transfer probability parameter.

[0127] In the scenario of "multi-channel linked financial product redemption", obtain the event occurrence time information corresponding to each event node, that is, the timestamp. Then, sort the event nodes in the order of the timestamps to form a time series. For example, if event A occurs at time point t1, event B occurs at time point t2, and event C occurs at time point t3, and t1 < t2 < t3, then the sorting of the event nodes is the event A node, the event B node, and the event C node.

[0128] Calculate the transfer probability parameter between the event nodes with adjacent timestamps. This transfer probability parameter represents the likelihood of the impact transfer of the event represented by the previous event node on the event represented by the subsequent event node. For example, analyze whether the occurrence of event A will increase the likelihood of the occurrence of event B, and determine the transfer probability parameter from the event A node to the event B node by statistically analyzing the probability of event B occurring after event A in historical data.

[0129] According to the calculated transfer probability parameter, establish a time-series directed edge between adjacent event nodes. The direction of the directed edge is from the event node that occurs first to the event node that occurs later, and use the transfer probability parameter as the attribute of the directed edge.

[0130] Step S135: Perform network fusion processing on the directed edges between event nodes and feature nodes, the undirected edges between feature nodes, and the time-series directed edges between event nodes, and construct a dynamic event association network by combining the initial value of the association strength, the co-occurrence correlation degree parameter, and the transfer probability parameter. The dynamic event association network can perform dynamic updates of nodes and edges with the addition of new operational risk event data.

[0131] In the scenario of "multi-channel linked wealth management product redemption", the directed edges between event nodes and feature nodes, the undirected edges between feature nodes, and the time-series directed edges between event nodes are fused into a network. This means that these edges and their corresponding parameters (initial value of association strength, co-occurrence association degree parameter, and transit probability parameter) are integrated into the same network structure, so that the network can fully reflect the various associations between event nodes and feature nodes.

[0132] When new operational risk event data is added, the dynamic event association network can be dynamically updated accordingly. For example, when a new operational risk event is added, an event node can be added; new features contained in the event will create corresponding feature nodes; the association between the new node and the original nodes will be recalculated and added to the network, and the parameters of the original edges may also be adjusted according to the new data.

[0133] Step S140: Use the preset root cause reasoning rule set to perform causal path weight iterative calculation on the dynamic event association network, and locate the root cause node set of the operational risk event through the transitivity analysis of the node influence intensity parameter.

[0134] In the scenario of "multi-channel linked wealth management product redemption," the pre-defined root cause reasoning rule set contains a series of rules for determining causal relationships and identifying impact paths. These rules are used to analyze the dynamic event correlation network to identify causal paths that may lead to the risk event of this operation.

[0135] Causal path weight iterative calculation refers to calculating the weight values ​​of each possible causal path step by step, and continuously optimizing these weight values ​​through multiple iterations to more accurately reflect the degree of influence between nodes. During the iteration process, the weight values ​​can be adjusted based on the results of each calculation until the weight values ​​tend to stabilize or reach the preset number of iterations.

[0136] By analyzing the transitivity of node influence strength parameters, we can trace the transmission path and effect of influence strength in dynamic event association networks. For example, the influence strength parameter of a feature node on an event node can be transmitted to other related nodes through the association relationships between nodes, thereby affecting the role of these nodes in the event. By analyzing the above transitivity, we can determine which nodes play a key root cause role in the entire network, thus locating the set of root cause nodes for operational risk events.

[0137] Step S141: Extract root cause inference meta-rules from a preset root cause inference rule set, which include causal relationship descriptions, influence threshold conditions, and path constraint rules. The root cause inference meta-rules are used to guide the causal path search direction in dynamic event association networks.

[0138] In the scenario of "redemption of multi-channel linked wealth management products", the pre-set root cause reasoning rule set is a large and complex rule system. When extracting root cause reasoning meta-rules from it, it is necessary to select those rules that can clearly describe causal relationships, set impact thresholds, and specify path constraints.

[0139] The causal relationship description section clarifies the potential causal connections between different nodes, such as "excessive system response delay may cause redemption request processing failure" or "mismatched operator permissions may lead to operational errors." The influence threshold condition specifies the minimum value that the influence strength parameter must reach; only when this threshold is exceeded is the causal relationship between nodes considered significant. The path constraint rules restrict the search scope and direction of causal paths, such as "causal paths must follow the chronological order of business processes" and "skipping paths that cross multiple unrelated stages are not allowed."

[0140] Step S142: Based on the causal relationship description in the root cause reasoning meta-rules, identify potential causal path starting nodes in the dynamic event association network. The starting nodes are feature nodes or upstream event nodes that are directly associated with operational risk events.

[0141] In the dynamic event association network of the "multi-channel linked wealth management product redemption" scenario, the potential starting points of causal paths are identified based on the causal relationship description in the root cause reasoning meta-rules. First, feature nodes directly associated with the operational risk events of "multi-channel linked wealth management product redemption" are identified. These feature nodes may include the "core accounting system response delay" feature node in system interaction features, the "operator permission mismatch" feature node in personnel operation features, etc.

[0142] Simultaneously, upstream event nodes are also identified. These are nodes corresponding to other related events that may have influenced the operation before the risk event occurred. For example, prior to this redemption event, a "system data synchronization anomaly" event occurred; the node corresponding to this event could be a potential starting point of the causal path. Through this identification process, all possible starting points are determined.

[0143] Step S143: Perform path traversal along the directed edge direction for each starting node, and calculate the cumulative influence strength parameter of each node in the candidate causal path. The cumulative influence strength parameter is the sum of the product of the association strength parameter and the transmission probability parameter of each edge on the path.

[0144] In the scenario of "multi-channel linked wealth management product redemption", for each identified starting node, path traversal is performed according to the direction indicated by the directed edges in the dynamic event association network. During the traversal, multiple candidate causal paths can be formed.

[0145] For each candidate causal path, the cumulative influence strength parameter of each node needs to be calculated. During calculation, starting from the starting node, the association strength parameter and transit probability parameter of each edge on the path are obtained sequentially. These two parameters are multiplied to obtain the influence value of that edge on the next node. Then, these influence values ​​are summed sequentially to obtain the cumulative influence strength parameter of each node.

[0146] For example, for a candidate causal path starting from the "System Data Synchronization Anomaly" event node, passing through the "Core Accounting System Data Error" feature node, and then to the "Redemption Request Processing Failure" event node, first calculate the product of the association strength parameter and the transmission probability parameter of the edge from "System Data Synchronization Anomaly" to "Core Accounting System Data Error", then calculate the product of the association strength parameter and the transmission probability parameter of the edge from "Core Accounting System Data Error" to "Redemption Request Processing Failure". Add these two products together to obtain the cumulative impact strength parameter of the "Redemption Request Processing Failure" event node.

[0147] Step S1431: Starting from the starting node of the candidate causal path, initialize the cumulative influence strength parameter to the initial value of the association strength of the starting node.

[0148] In the scenario of "multi-channel linked wealth management product redemption", for each candidate causal path, we start from its starting node. The starting node may be a feature node or an upstream event node. In order to calculate the cumulative influence strength parameter of each node on the path, we first initialize the cumulative influence strength parameter by setting its value to the initial value of the association strength of the starting node.

[0149] For example, if the starting node is the "core accounting system response delay" feature node, and the initial value of the association strength of this node is a parameter value obtained through previous calculations, then the initial value of the cumulative influence strength parameter will be set to this parameter value.

[0150] Step S1432: Traverse the first directed edge in the candidate causal path, obtain the association strength parameter and the propagation probability parameter corresponding to the directed edge, and calculate the influence propagation value of the directed edge, wherein the influence propagation value is the product of the association strength parameter and the propagation probability parameter.

[0151] In the scenario of "multi-channel linked wealth management product redemption", after initializing the cumulative impact strength parameter, the first directed edge in the candidate causal path is traversed. By querying the attribute information of the directed edge in the dynamic event association network, the corresponding association strength parameter and transmission probability parameter are obtained.

[0152] For example, the first directed edge points from the "Core Accounting System Response Delay" feature node to the "Redemption Request Queue Backlog" feature node, with an association strength parameter of A and a propagation probability parameter of B. The propagation value of this directed edge is the product of A and B, i.e., A × B. This propagation value reflects the degree of influence the starting node has on the next node through this directed edge.

[0153] Step S1433: Add the influence transmission value to the current cumulative influence strength parameter, update the cumulative influence strength parameter, and use it as the cumulative influence strength parameter of the first intermediate node in the candidate causal path.

[0154] In the scenario of "multi-channel linked wealth management product redemption", after calculating the influence transmission value of the first directed edge, it is added to the current cumulative influence strength parameter (that is, the initial value of the association strength of the starting node).

[0155] For example, if the initial association strength of the starting node "Core Accounting System Response Delay" is C, and the influence propagation value of the first directed edge is A×B, then the sum is C+A×B. This result will be used as the cumulative influence strength parameter of the first intermediate node (such as the "Redemption Request Queue Backlog" feature node) in the candidate causal path. Through the above update, the calculation of the cumulative influence strength parameter of the first intermediate node is completed.

[0156] Step S1434: Continue traversing the next directed edge in the candidate causal path, repeatedly obtain the association strength parameter and the transmission probability parameter and calculate the influence transmission value, accumulate it to the cumulative influence strength parameter, and update the cumulative influence strength parameter of the subsequent intermediate nodes in the candidate causal path in turn.

[0157] In the scenario of "multi-channel linked wealth management product redemption", after calculating the cumulative impact strength parameter of the first intermediate node, the next directed edge in the candidate causal path is traversed. For this directed edge, its association strength parameter and transmission probability parameter are also obtained, and the impact transmission value is calculated.

[0158] Next, the new impact propagation value is added to the cumulative impact strength parameter of the previous intermediate node, and the result is used as the cumulative impact strength parameter of the next intermediate node. Following this method, subsequent intermediate nodes in the candidate causal path are processed sequentially, continuously updating the cumulative impact strength parameter.

[0159] For example, the next directed edge after the "redemption request backlog" feature node points to the "funds deduction delay" feature node. The association strength parameter of this directed edge is D, the propagation probability parameter is E, and the impact propagation value is D×E. Adding this to the cumulative impact strength parameter C+A×B of the "redemption request backlog" feature node, we get C+A×B+D×E, which serves as the cumulative impact strength parameter of the "funds deduction delay" feature node.

[0160] Step S1435: When traversing to the endpoint node of the candidate causal path, add the cumulative influence strength parameter of the last intermediate node to the initial value of the association strength of the endpoint node to obtain the cumulative influence strength parameter of the candidate causal path. The cumulative influence strength parameter is used to reflect the overall influence degree from the starting node to the endpoint node.

[0161] In the scenario of "redemption of multi-channel linked wealth management products", when the endpoint of a candidate causal path is reached, it means that all directed edges on that path have been processed. The endpoint is usually an event node directly related to the risk event of the "redemption of multi-channel linked wealth management products" operation.

[0162] At this point, the cumulative impact strength parameter of the last intermediate node needs to be added to the initial value of the association strength of the endpoint node. This sum is the cumulative impact strength parameter of the candidate causal path. For example, if the last intermediate node is the "delayed fund deduction" feature node, its cumulative impact strength parameter is C+A×B+D×E, and the initial value of the association strength of the endpoint node "redemption failure" event node is F, then the cumulative impact strength parameter of the candidate causal path is C+A×B+D×E+F. This cumulative impact strength parameter comprehensively reflects the overall degree of influence along the entire path from the starting node to the endpoint node.

[0163] Step S144: Based on the influence threshold conditions in the root cause reasoning meta-rules, the cumulative influence intensity parameters are filtered, and candidate causal paths whose cumulative influence intensity parameters exceed the influence threshold conditions are retained, while invalid paths that do not reach the threshold are excluded.

[0164] In the scenario of "redemption of multi-channel linked wealth management products", the impact threshold condition in the root cause inference meta-rule is a pre-set standard used to determine whether the impact of candidate causal paths is significant enough. After obtaining the cumulative impact strength parameters of all candidate causal paths, each parameter is compared with the impact threshold condition.

[0165] If the cumulative impact strength parameter of a candidate causal path exceeds the impact threshold, it indicates that the path has a significant impact on operational risk events and is retained. Candidate causal paths whose cumulative impact strength parameter does not reach the impact threshold are considered invalid and excluded because their impact is small or insignificant. This screening process narrows down the range of causal paths, allowing focus on those paths that are more likely to be the root cause.

[0166] Step S145: Perform path constraint rule verification on the selected candidate causal paths to check whether they conform to the logical order of the business process, system interaction specifications, and the scope of personnel operation permissions, and eliminate abnormal paths that violate the constraint rules.

[0167] In the scenario of "multi-channel linked wealth management product redemption", the selected candidate causal paths still need to be verified by path constraint rules. Path constraint rules are formulated based on the logical sequence of business processes, system interaction specifications, and the scope of personnel operation permissions.

[0168] During the verification process, it is possible to check whether each candidate causal path conforms to the normal process logic of the "multi-channel linked wealth management product redemption" business. For example, whether the path involves "funds deduction" before "quota verification," which violates the above-mentioned business process order. At the same time, it is necessary to check whether the path conforms to the system interaction specifications, such as whether the information transmission between systems follows the preset protocol and format. In addition, it is also necessary to check whether the personnel operations involved in the path are within their authority and whether there are any unauthorized operations.

[0169] For candidate causal paths that violate the above constraints, they are identified as abnormal paths and eliminated, and only valid paths that comply with the constraints are retained.

[0170] Step S146: Mark the endpoint node of the candidate causal path that has passed the verification as a potential root cause node, count the occurrence frequency and average cumulative influence intensity parameter of each potential root cause node in all valid candidate causal paths, and generate a root cause node set. The root cause node set contains a preset number of potential root cause nodes with the highest occurrence frequency and the largest average cumulative influence intensity parameter.

[0171] In the scenario of "multi-channel linked wealth management product redemption", for valid candidate causal paths that pass verification, their endpoints are marked as potential root cause nodes. These endpoints may be different feature nodes or event nodes, all of which may be the root cause of the operational risk event.

[0172] Next, the frequency of each potential root cause node appearing in all valid candidate causal paths is calculated. The higher the frequency, the greater the likelihood that the node is the root cause. Simultaneously, the average cumulative influence strength parameter corresponding to each potential root cause node is calculated; this is the average of the cumulative influence strength parameters of the node across all appearing paths. The larger the average cumulative influence strength parameter, the higher the average impact of the node on operational risk events.

[0173] Finally, based on the frequency of occurrence and the average cumulative impact intensity parameter, a preset number of potential root cause nodes with the highest frequency of occurrence and the largest average cumulative impact intensity parameter are selected to form a root cause node set.

[0174] Step S150: Generate a root cause diagnosis result based on the root cause node set, which includes root cause type identifier, influence path description, and contribution of associated features.

[0175] In the scenario of "multi-channel linked wealth management product redemption," after obtaining the root cause node set, it is necessary to generate root cause diagnostic results based on this set. First, a root cause type identifier is determined for each root cause node to clarify the category of the root cause. Then, the impact path corresponding to each root cause node is described in detail, demonstrating how it leads to the occurrence of operational risk events. Simultaneously, the contribution of the associated features of each root cause node is calculated, illustrating the magnitude of the feature's role in the root cause formation process. Integrating this information forms a complete root cause diagnostic result.

[0176] Step S151: Perform type classification processing on each root cause node in the root cause node set, and match the preset root cause type identifier library according to the feature type or event type corresponding to the root cause node to generate a root cause type identifier for each root cause node. The root cause type identifier includes business process type, system interaction type, personnel operation type and environmental impact type.

[0177] In the scenario of "multi-channel linked wealth management product redemption", when classifying each root cause node in the root cause node set, the first step is to analyze the feature type or event type corresponding to that node. For example, if the root cause node is the feature node of "core accounting system response delay", its corresponding feature type is system interaction feature; if the root cause node is the feature node of "operator permission mismatch", its corresponding feature type is personnel operation feature.

[0178] Then, these feature types or event types are matched against a pre-defined root cause type identifier library. The root cause type identifier library stores the correspondence between feature types or event types and root cause type identifiers; for example, system interaction features correspond to system interaction class identifiers, personnel operation features correspond to personnel operation class identifiers, business process-related event types correspond to business process class identifiers, and environmental factor-related feature types correspond to environmental impact class identifiers. Through matching, a corresponding root cause type identifier is generated for each root cause node.

[0179] Step S152: For each root cause node, backtrack its corresponding candidate causal path, extract the event node sequence and feature node sequence in the candidate causal path, sort them according to time order and correlation strength parameter to generate influence path description text, the influence path description text includes node name, correlation strength parameter and path direction information.

[0180] In the scenario of "multi-channel linked wealth management product redemption", for each root cause node, all candidate causal paths corresponding to it are traced back. During the backtracking process, the event node sequence and feature node sequence in the candidate causal path are extracted. For example, the event node sequence may be "system data synchronization abnormal event - redemption request processing failure event", and the feature node sequence may be "core accounting system response delay feature - redemption request queuing backlog feature".

[0181] Then, these node sequences are sorted according to time sequence and correlation strength parameters. Time sequence ensures that the path descriptions conform to the order in which events occurred, while correlation strength parameter sorting highlights nodes with greater impact. Based on the sorting results, an impact path description text is generated, which clearly includes the name of each node, the correlation strength parameters between nodes, and the path direction information, clearly demonstrating how the root cause node affects the operational risk event through the actions of a series of nodes.

[0182] Step S153: Calculate the feature contribution of the feature node corresponding to the root cause node in the event feature set. The feature contribution is determined based on the weighted sum of the association strength parameter and the co-occurrence association degree parameter of the feature node in the dynamic event association network.

[0183] In the scenario of "multi-channel linked wealth management product redemption," for each root cause node in the root cause node set, it is necessary to identify its corresponding feature node. These feature nodes may come from one or more of the following: business process features, system interaction features, personnel operation features, or environmental impact features. For example, if a certain root cause node is related to "credit limit verification system response delay," then its corresponding feature node is the feature node related to the system response delay in the system interaction features.

[0184] Next, it is necessary to extract the association strength parameter between the feature node and the event node, as well as the co-occurrence association degree parameter between the feature node and other feature nodes from the dynamic event association network. The association strength parameter reflects the direct influence of the feature node on the event node, while the co-occurrence association degree parameter reflects the probability of the feature node co-occurring with other feature nodes, indirectly reflecting its influence in the entire event feature set.

[0185] The calculation of feature contribution requires weighting the association strength parameter and the co-occurrence association parameter and then summing them. The weights here are pre-set according to the feature type to which the feature node belongs. Different types of feature nodes have different weight values ​​to reflect the differences in importance of different types of features in the event.

[0186] Step S1531: Extract the association strength parameter between the feature node corresponding to the root cause node and the event node, and the co-occurrence association degree parameter between the feature node and other feature nodes from the dynamic event association network.

[0187] In the scenario of "multi-channel linked wealth management product redemption", the feature node corresponding to the root cause node is located by traversing the dynamic event association network. Then, the association strength parameter of the connection edge between the feature node and the event node is found. This parameter is calculated and stored when constructing the dynamic event association network. For example, the association strength parameter between the feature node "quota verification system response delay" and the node "redemption failure event".

[0188] Simultaneously, the connections between this feature node and all other feature nodes in the network are traversed, and the co-occurrence correlation parameter corresponding to each connection is extracted. For example, the co-occurrence correlation parameter between the feature node "quota verification system response delay" and the feature node "insufficient operator permissions" reflects the frequency with which these two features co-occur in similar historical events.

[0189] Step S1532: Based on the importance weight table of each dimension feature in the event feature set, obtain the dimension weight value of the dimension to which the feature node corresponding to the root cause node belongs. The dimension weight value is adjusted based on the accuracy feedback of historical root cause diagnosis results.

[0190] In the scenario of "multi-channel linked wealth management product redemption", the system pre-stores an importance weight table for each dimension of the event feature set. In this table, business process features, system interaction features, personnel operation features, and environmental impact features each correspond to different dimension weight values.

[0191] For example, the dimensional weight value of system interaction features may be higher than that of human operation features because, in this type of business, the stability of system interaction has a greater impact on the business outcome. When the feature node corresponding to the root cause node belongs to the system interaction feature dimension, the dimensional weight value corresponding to the system interaction feature is obtained from the weight table.

[0192] The dimensional weights are not fixed and are dynamically adjusted based on the accuracy of historical root cause diagnosis results. If a certain dimensional feature is proven to contribute significantly to the accuracy of root cause localization in multiple diagnoses, its dimensional weight will be increased accordingly; conversely, it will be decreased.

[0193] Step S1533: Perform dimensional weighting on the association strength parameter to generate a weighted association strength parameter, wherein the weighted association strength parameter is the product of the association strength parameter and the dimensional weight value.

[0194] In the scenario of "multi-channel linked wealth management product redemption", after obtaining the correlation strength parameter of the feature node corresponding to the root cause node and the dimension weight value of its respective dimension, the two are multiplied to obtain the weighted correlation strength parameter.

[0195] For example, if the association strength parameter between the feature node "credit limit verification system response delay" and the event node is a certain value, and the weight value of its corresponding system interaction feature dimension is another value, then the weighted association strength parameter is the product of these two values. This weighting process allows the association strength parameter to be adjusted based on the importance of its corresponding dimension, more reasonably reflecting the actual impact of the feature node.

[0196] Step S1534: Calculate the average co-occurrence correlation parameter between the feature node and all other feature nodes, and use it as the average co-occurrence correlation parameter.

[0197] In the scenario of "redemption of multi-channel linked wealth management products", the co-occurrence correlation parameters between this feature node and all other feature nodes are collected. For example, the feature node "credit limit verification system response delay" has co-occurrence correlation parameters with multiple feature nodes such as "identity verification failure" and "fund deduction error".

[0198] The average co-occurrence correlation parameter is obtained by summing these co-occurrence correlation parameters and then dividing by the total number of feature nodes (i.e., the number of other feature nodes participating in the co-occurrence calculation). This parameter comprehensively reflects the overall co-occurrence of the feature node with other feature nodes, avoiding the bias of a single co-occurrence correlation parameter.

[0199] Step S1535: Standardize and sum the weighted correlation strength parameter and the average co-occurrence correlation parameter according to a preset ratio to generate the feature contribution. The preset ratio is dynamically adjusted according to the different feature types.

[0200] In the scenario of "redemption of multi-channel linked wealth management products", the preset ratio is determined based on the type of feature node. For feature nodes of system interaction, a higher ratio may be assigned to the weighted association strength parameter, while for feature nodes of environmental impact, a higher ratio may be assigned to the average co-occurrence association degree parameter.

[0201] First, the weighted association strength parameter and the average co-occurrence association degree parameter are standardized to adjust their value ranges to the same interval, ensuring comparability when weighted summation. Then, the two standardized parameters are weighted and summed according to a preset ratio, and the result is the feature contribution of the feature node.

[0202] For example, if the preset ratio is 60% for the weighted association strength parameter and 40% for the average co-occurrence association degree parameter, then the standardized weighted association strength parameter is multiplied by 60%, and the standardized average co-occurrence association degree parameter is multiplied by 40%. The sum of the two is the feature contribution. The preset ratio will be dynamically adjusted according to different feature types to calculate the feature contribution more accurately.

[0203] Step S154: The root cause type identifier, the description text of the influencing path, and the feature contribution are structurally integrated to generate a root cause diagnosis result containing the root cause node name, root cause type identifier, description of the influencing path, and the contribution of associated features.

[0204] In the scenario of "multi-channel linked wealth management product redemption", the root cause type identifiers, influence path description texts, and feature contribution values ​​obtained earlier are structured and integrated. First, the name and corresponding root cause type identifier of each root cause node are compiled; then, the influence path description text of the root cause node is attached; at the same time, the contribution value of its associated features is indicated.

[0205] This information is arranged according to a preset structural format to form a unified and standardized root cause diagnosis result. This root cause diagnosis result fully presents the relevant information of each root cause node, enabling relevant personnel to clearly understand the root cause of operational risk events.

[0206] Figure 2 This application illustrates an intelligent root cause diagnosis system 100 for operational risks in financial services, comprising a processor 1001, a memory 1003, and program code stored in the memory 1003. The processor 1001 executes the program code to implement the steps of the intelligent root cause diagnosis method for operational risks in financial services.

[0207] Figure 2The illustrated intelligent root cause diagnostic system 100 for operational risks in financial services includes a processor 1001 and a memory 1003. The processor 1001 and memory 1003 are connected, for example, via a bus 1002. Optionally, the intelligent root cause diagnostic system 100 for operational risks in financial services may further include a transceiver 1004. The transceiver 1004 can be used for data interaction between this intelligent root cause diagnostic system for operational risks in financial services and other intelligent root cause diagnostic systems for operational risks in financial services, such as sending and / or receiving data. It should be noted that in actual scheduling, the transceiver 1004 is not limited to one, and the structure of this intelligent root cause diagnostic system 100 for operational risks in financial services does not constitute a limitation on the embodiments of this application.

[0208] The memory 1003 is used to store program code for executing the embodiments of this application, and its execution is controlled by the processor 1001. The processor 1001 is used to execute the program code stored in the memory 1003 to implement the steps shown in the foregoing method embodiments.

[0209] This application provides a computer-readable storage medium storing program code, which, when executed by a processor, can implement the steps and corresponding content of the aforementioned method embodiments.

[0210] It should be understood that although arrows indicate various operation steps in the flowcharts of the embodiments of this application, the order in which these steps are implemented is not limited to the order indicated by the arrows. Unless explicitly stated herein, in some implementation scenarios of the embodiments of this application, the implementation steps in each flowchart may be executed in other orders based on requirements. Furthermore, some or all steps in each flowchart may include multiple sub-steps or multiple stages depending on the actual implementation scenario. Some or all of these sub-steps or stages may be executed at the same time, and each sub-step or stage may also be executed at different times. In scenarios where execution times differ, the execution order of these sub-steps or stages can be flexibly configured based on requirements, and the embodiments of this application do not limit this.

[0211] The above description is only an optional implementation method for some implementation scenarios of this application. It should be noted that for those skilled in the art, other similar implementation methods based on the technical concept of this application, without departing from the technical concept of this application, also fall within the protection scope of the embodiments of this application.

Claims

1. A method for intelligent diagnosis of the root causes of operational risks in financial services, characterized in that, The method includes: Collect a set of operational risk event data generated when an operational risk event occurs in the financial service system. The set of operational risk event data includes event occurrence time information, business operation link identifiers, system interaction log fragments, and manual operation records. Feature extraction is performed on the operational risk event dataset to generate an event feature set, which includes business process features, system interaction features, personnel operation features, and environmental impact features. A dynamic event association network is constructed based on an event feature set. The nodes of the dynamic event association network include event nodes and feature nodes in the event feature set. The directed edges between nodes represent the influence strength parameters of feature nodes on event nodes. By using a pre-defined set of root cause reasoning rules to iteratively calculate the causal path weights of a dynamic event association network, and by analyzing the transitivity of node influence strength parameters, the root cause node set of operational risk events can be located. Generate root cause diagnostic results based on the root cause node set, including root cause type identifiers, descriptions of influencing paths, and contribution of associated features. The step of extracting features from the operational risk event dataset to generate an event feature set includes: The process node parsing process is performed on the business operation link identifiers in the operational risk event dataset to extract the sequential execution order and inter-link dependencies of the business links involved in the operational risk event, and to generate a business process node sequence. The execution time interval parameter of adjacent business links is calculated based on the sequence of business process nodes. The process deviation index in the business process characteristics is generated by combining the standard execution time of each business link. The process deviation index is used to represent the degree of deviation between the actual execution time and the standard execution time. The system interaction log fragments in the operational risk event dataset are processed to extract interaction behavior sequences, identify request and response interaction records between system components, and generate system interaction features including interaction frequency, response latency, and error code distribution. Analyze the manual operation records in the operational risk event dataset, extract the operation sequence, permission level and operation compliance verification results of the operators, and generate personnel operation characteristics including operation proficiency parameters, permission matching parameters and compliance verification pass rate; Integrate business process features, system interaction features, and personnel operation features, and combine them with external environmental factors recorded when operational risk events occur to generate environmental impact features. Then, perform feature splicing processing on business process features, system interaction features, personnel operation features, and environmental impact features according to preset dimension weights to generate an event feature set. The construction of a dynamic event association network based on event feature sets includes: Each operational risk event in the operational risk event dataset is defined as an event node in the dynamic event association network, and each dimension of the event feature set is defined as a feature node, forming a two-layer node structure containing an event node layer and a feature node layer. Calculate the initial value of the association strength between each feature node and the event node. The initial value of the association strength is determined based on the product of the frequency of occurrence of the feature corresponding to the feature node when the operational risk event occurs and the evaluation value of the degree of impact. Statistical analysis is performed on the co-occurrence relationship between feature nodes. The probability of any two feature nodes co-occurring in the same operational risk event dataset is calculated as the co-occurrence correlation parameter. Undirected edges between feature nodes and their corresponding co-occurrence correlation parameters are generated. The event nodes are sorted by time sequence based on the event occurrence time information, the transmission probability parameters between event nodes with adjacent timestamps are calculated, and the time sequence directed edges between event nodes and their corresponding transmission probability parameters are generated. The directed edges between event nodes and feature nodes, the undirected edges between feature nodes, and the time-series directed edges between event nodes are fused together. A dynamic event association network is constructed by combining the initial value of association strength, co-occurrence association degree parameter, and transit probability parameter. The dynamic event association network can dynamically update nodes and edges as new operational risk event data are added. The method of using a preset set of root cause reasoning rules to perform causal path weight iterative calculation on a dynamic event association network, and locating the root cause node set of operational risk events through transitivity analysis of node influence intensity parameters, includes: Root cause reasoning meta-rules are extracted from a pre-defined set of root cause reasoning rules. These rules include descriptions of causal relationships, influence threshold conditions, and path constraint rules. The root cause reasoning meta-rules are used to guide the causal path search direction in dynamic event association networks. Based on the causal relationship description in the root cause reasoning meta-rule, potential causal path starting nodes are identified in the dynamic event association network. The starting nodes are feature nodes or upstream event nodes that are directly associated with operational risk events. For each starting node, perform path traversal along the directed edge direction, and calculate the cumulative influence strength parameter of each node in the candidate causal path. The cumulative influence strength parameter is the sum of the product of the association strength parameter and the transmission probability parameter of each edge on the path. The cumulative influence intensity parameter is filtered based on the influence threshold condition in the root cause reasoning meta-rule. Candidate causal paths whose cumulative influence intensity parameter exceeds the influence threshold condition are retained, while invalid paths that do not reach the threshold are excluded. The selected candidate causal paths are validated for path constraint rules to check whether they conform to the logical order of business processes, system interaction specifications, and the scope of personnel operation permissions, and abnormal paths that violate the constraint rules are eliminated. The endpoint nodes of the candidate causal paths that pass the verification are marked as potential root cause nodes. The frequency of occurrence and average cumulative influence intensity parameter of each potential root cause node in all valid candidate causal paths are counted to generate a root cause node set. The root cause node set contains a preset number of potential root cause nodes with the highest occurrence frequency and the largest average cumulative influence intensity parameter.

2. The intelligent root cause diagnosis method for operational risks in financial services according to claim 1, characterized in that, The process of extracting interaction behavior sequences from system interaction log fragments in the operational risk event dataset, identifying request-response interaction records between system components, and generating system interaction features including interaction frequency, response latency, and error code distribution includes: The system interaction log fragments in the operational risk event dataset are processed to standardize the log format. The interaction behavior sequence containing requester identifier, responder identifier, request type, request timestamp and response timestamp is extracted from the standardized system interaction logs and arranged in ascending order of request timestamp to form a time-series interaction behavior sequence. The number of interactions between the same requester and responder identifiers in a statistical time-series interaction behavior sequence within a unit time is used as the interaction frequency parameter. The unit time is determined based on the time granularity of the event occurrence time information. Calculate the response latency parameter for each interaction in the time-series interaction sequence. The response latency parameter is the difference between the response timestamp and the request timestamp. Calculate the distribution characteristics of the response latency parameter, which include the maximum value, minimum value, and median. Identify error code records in a time-series interaction behavior sequence, count the occurrence frequency of different error code types and their positional distribution in the interaction behavior sequence, and generate an error code distribution histogram and the corresponding cumulative occurrence probability curve; The distribution characteristics of interaction frequency parameters, response delay parameters, and error code distribution histograms are fused together, and the features are vectorized according to the system interaction dimension to generate system interaction features. The dimension of the system interaction features is consistent with the dimension of the system interaction features in the event feature set.

3. The intelligent root cause diagnosis method for operational risks in financial services according to claim 1, characterized in that, The analysis of manual operation records in the operational risk event dataset extracts the operator's operation sequence, permission level, and operation compliance verification results, generating personnel operation characteristics that include operation proficiency parameters, permission matching parameters, and compliance verification pass rate, including: The manual operation records in the operational risk event dataset are processed by structured parsing to extract fields such as operator identification, operation time, operation object, operation action and operation result, and generate a structured operation record table. The operation actions in the structured operation record table are sorted sequentially according to the operator's identification and operation time to generate an operation sequence of the operator arranged in chronological order. The operation sequence includes the continuously executed operation actions and the corresponding operation objects. An operation proficiency parameter is calculated based on the execution interval time of the operation actions in the operation sequence and the number of successful operation results. The operation proficiency parameter is negatively correlated with the average execution interval time and positively correlated with the number of successful operation results. Query the preset permission level table corresponding to the operator identifier to obtain the operator's theoretical permission level, compare the theoretical permission level with the permission level required by the operation object, and calculate the permission matching degree parameter, which is the ratio of the theoretical permission level to the required permission level. The system calls a preset operation compliance verification rule library to perform compliance verification on each operation action in the operation sequence, records the number of compliant operations and the number of non-compliant operations, and calculates the compliance verification pass rate, which is the ratio of the number of compliant operations to the total number of operations. The operation proficiency parameter, permission matching parameter, and compliance verification pass rate are normalized according to the personnel operation dimension to generate personnel operation features. Each component of the personnel operation features corresponds to the operation proficiency parameter, permission matching parameter, and compliance verification pass rate, respectively.

4. The intelligent root cause diagnosis method for operational risks in financial services according to claim 1, characterized in that, The calculation of the initial value of the association strength between each feature node and the event node includes: The frequency of occurrence of the feature corresponding to the statistical feature node is calculated when all operational risk events occur in the operational risk event dataset. The frequency of occurrence is the ratio of the number of occurrences to the total number of operational risk events. Collect root cause analysis reports of historical operational risk events, extract the number of root cause mentions related to the features corresponding to the feature nodes in the root cause analysis reports, and calculate the impact assessment value. The impact assessment value is positively correlated with the number of root cause mentions. The frequency of occurrence is standardized to obtain the standardized frequency of occurrence. The impact assessment values ​​are weighted to generate a weighted impact assessment value. Different type weights are assigned according to the feature type to which the feature node belongs: business process features are assigned the first type weight, system interaction features are assigned the second type weight, personnel operation features are assigned the third type weight, and environmental impact features are assigned the fourth type weight. Multiplying the standardized frequency of occurrence by the weighted influence assessment value yields the initial value of the association strength between feature nodes and event nodes. The initial value of the association strength ranges from zero to the maximum value of the type weight.

5. The intelligent root cause diagnosis method for operational risks in financial services according to claim 1, characterized in that, The step of traversing the path along the directed edge direction for each starting node and calculating the cumulative influence strength parameter of each node in the candidate causal path includes: Starting from the starting node of the candidate causal path, initialize the cumulative influence strength parameter to the initial value of the association strength of the starting node; Traverse the first directed edge in the candidate causal path, obtain the association strength parameter and the transmission probability parameter corresponding to the directed edge, and calculate the influence transmission value of the directed edge, wherein the influence transmission value is the product of the association strength parameter and the transmission probability parameter; The influence propagation value is added to the current cumulative influence strength parameter to update the cumulative influence strength parameter, which is then used as the cumulative influence strength parameter of the first intermediate node in the candidate causal path. Continue traversing the next directed edge in the candidate causal path, repeatedly obtain the association strength parameter and the transmission probability parameter and calculate the influence transmission value, accumulate it to the cumulative influence strength parameter, and update the cumulative influence strength parameter of the subsequent intermediate nodes in the candidate causal path in turn. When traversing to the endpoint node of the candidate causal path, the cumulative influence strength parameter of the last intermediate node is added to the initial value of the association strength of the endpoint node to obtain the cumulative influence strength parameter of the candidate causal path. The cumulative influence strength parameter is used to reflect the overall influence degree from the starting node to the endpoint node.

6. The intelligent root cause diagnosis method for operational risks in financial services according to claim 1, characterized in that, The process of generating root cause diagnostic results based on the root cause node set, including root cause type identifiers, descriptions of influencing paths, and contribution values ​​of associated features, includes: Each root cause node in the root cause node set is classified into types. Based on the feature type or event type corresponding to the root cause node, a preset root cause type identifier library is matched to generate a root cause type identifier for each root cause node. The root cause type identifier includes business process type, system interaction type, personnel operation type, and environmental impact type. For each root cause node, backtrack its corresponding candidate causal path, extract the event node sequence and feature node sequence in the candidate causal path, sort them according to time order and correlation strength parameter to generate influence path description text, the influence path description text includes node name, correlation strength parameter and path direction information; Calculate the feature contribution of the feature node corresponding to the root cause node in the event feature set. The feature contribution is determined based on the weighted sum of the association strength parameter and the co-occurrence association degree parameter of the feature node in the dynamic event association network. The root cause type identifier, the description text of the influencing path, and the feature contribution are structured and integrated to generate root cause diagnosis results that include root cause node names, root cause type identifiers, descriptions of influencing paths, and contributions of associated features.

7. An intelligent root cause diagnosis system for operational risks in financial services, characterized in that, The method includes a processor and a computer-readable storage medium storing machine-executable instructions that, when executed by the processor, implement the intelligent root cause diagnosis method for operational risks in financial services as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Risk identification method and device

    CN116934338A

  • Artificial intelligence-based insurance customer fraud detection method and system

    CN120182014A