Account risk identification method and device, equipment, medium and program product
By obtaining the identity and transaction information of the target account and associated accounts, combined with risk scoring identification methods, the problem of insufficient supervision of transactions between sub-accounts and master accounts is solved, more accurate risk identification and supervision are achieved, and the security of fund transactions is improved.
Patent Information
- Application Number
- CN202510809174.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-17
- Publication Date
- 2025-09-23
AI Technical Summary
In cash management services, fund transactions between sub-accounts and the main account cannot be effectively supervised, resulting in the inability to accurately identify the risk situation of the account.
By obtaining the identity information and transaction information of the target account and related accounts, the identity risk score and transaction risk score are determined respectively. The risk information of the account is determined by combining the two scores. The internal and external data of the financial institution are used to obtain information to improve identification accuracy.
It improves the accuracy and efficiency of risk identification of target accounts, enhances the ability to monitor suspicious transactions in sub-accounts, and ensures the security of fund transactions.
Smart Images

Figure CN120689055A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of big data, and specifically to an account risk identification method, apparatus, equipment, medium and program product. Background Art
[0002] Cash management services refer to comprehensive, integrated fund management services, including bookkeeping, clearing, transfers, and settlement, that banks provide to meet the fund management needs of enterprises, leveraging their own fund settlement and product development platforms. Within these services, enterprises can open one or more sub-accounts based on their master account (settlement account), and transfer funds between the master account and sub-accounts, as well as between sub-accounts.
[0003] Since most sub-accounts are virtual accounts or internal accounts, and not the bank's real settlement accounts, the fund transactions between the main account and the sub-accounts cannot be effectively supervised, and the risk situation of the account cannot be accurately identified. Summary of the Invention
[0004] In view of the above problems, the present application provides an account risk identification method, apparatus, device, medium and program product.
[0005] According to a first aspect of the present application, an account risk identification method is provided, comprising: respectively obtaining first identity information and first transaction information of a target account, and second identity information and second transaction information of an associated account, wherein the transaction operation authority of the associated account belongs to the subject of the target account; determining a first identification result based on the first identity information and the second identity information; in response to the first identification result satisfying a target condition, determining a second identification result based on the first transaction information and the second transaction information; and determining risk information of the target account based on the first identification result and the second identification result.
[0006] According to an embodiment of the present application, the first identification result includes a first risk score that characterizes the identity risk situation of the target account, and the second identification result includes a second risk score that characterizes the transaction risk situation of the target account; determining the risk information of the target account based on the first identification result and the second identification result includes: determining the risk information of the target account based on the first risk score and the second risk score.
[0007] According to an embodiment of the present application, the target condition includes: the first risk score falls within a preset risk range.
[0008] According to an embodiment of the present application, the first identity information and the second identity information both include multiple categories of information, the categories of information contained in the first identity information and the second identity information are consistent and the total number of categories is the same; based on the first identity information and the second identity information, a first identification result is determined, including: from the multiple categories of information of the first identity information, determining the number of categories with the same content as the corresponding category information in the second identity information as the target category number; determining a first risk score based on a first ratio of the target category number to the total category number.
[0009] According to an embodiment of the present application, a second identification result is determined based on the first transaction information and the second transaction information, including: determining a transaction behavior data set based on the first transaction information and the second transaction information; the transaction behavior data set includes the transaction behavior of the target account and the transaction behavior of the associated accounts; calculating the number of transaction behaviors in the transaction behavior data set that meet the preset abnormal transaction behavior to obtain the target transaction behavior number; determining a second risk score based on a second ratio of the target transaction behavior number to the total number of transaction behavior data sets.
[0010] According to an embodiment of the present application, respectively obtaining the first identity information and first transaction information of the target account, and the second identity information and second transaction information of the associated account, includes: within a target period, respectively obtaining the first identity information and first transaction information of the target account, and the second identity information and second transaction information of the associated account.
[0011] According to an embodiment of the present application, the target account is a settlement account of a financial institution, and obtaining the first identity information and first transaction information of the target account, and obtaining the second identity information and second transaction information of the associated account, includes: using the internal data of the financial institution to obtain the first identity information and first transaction information based on the target account, and obtaining the second transaction information based on the associated account; using external data from channels other than the financial institution to obtain the second identity information based on the associated account.
[0012] The second aspect of the present application provides an account risk identification device, including: an acquisition module, used to respectively obtain first identity information and first transaction information of a target account, and second identity information and second transaction information of an associated account, wherein the transaction operation authority of the associated account belongs to the subject of the target account; a first determination module, used to determine a first identification result based on the first identity information and the second identity information; a second determination module, used to determine a second identification result based on the first transaction information and the second transaction information in response to the first identification result satisfying a target condition; and a third determination module, used to determine the risk information of the target account based on the first identification result and the second identification result.
[0013] The third aspect of the present application provides an electronic device, comprising: one or more processors; a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the above method.
[0014] The fourth aspect of the present application further provides a computer-readable storage medium having a computer program or instructions stored thereon, which implements the steps of the above method when the computer program or instructions are executed by a processor.
[0015] The fifth aspect of the present application further provides a computer program product, comprising a computer program or instructions, which implement the steps of the above method when executed by a processor. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] The above contents and other objects, features and advantages of the present application will become more apparent through the following description of the embodiments of the present application with reference to the accompanying drawings, in which:
[0017] Figure 1 A diagram schematically illustrates an application scenario of the account risk identification method, apparatus, device, medium, and program product according to an embodiment of the present application;
[0018] Figure 2 The following schematically shows a flow chart of a method for identifying account risk according to an embodiment of the present application;
[0019] Figure 3 A schematic diagram illustrating the principle of first identity information and second identity information according to an embodiment of the present application is shown;
[0020] Figure 4 A schematic diagram of a structure of an account risk identification device according to an embodiment of the present application is shown; and
[0021] Figure 5 A block diagram of an electronic device suitable for implementing the account risk identification method according to an embodiment of the present application is schematically shown. DETAILED DESCRIPTION
[0022] Hereinafter, embodiments of the present application will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the present application. In the detailed description below, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present application. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present application.
[0023] The terms used herein are only for describing specific embodiments and are not intended to limit the present application. The terms "comprise," "include," etc. used herein indicate the presence of features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0024] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0025] When expressions such as "at least one of A, B, and C, etc." are used, they should generally be interpreted in accordance with the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).
[0026] In the technical solution of this application, the user information involved (including but not limited to user personal information, user image information, user device information, such as location information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) are all information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with relevant laws, regulations and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0027] In some examples, cash management services are comprehensive financial services that include fund settlement services. Cash management services support corporate clients opening bank settlement accounts or dedicated internal accounts for cash management services (e.g., master accounts). Within the master account, one or more sub-accounts can be opened, and funds can be transferred between the master account and sub-accounts, and between sub-accounts. Furthermore, the relationship between the master account and sub-accounts is not limited to the relationship between the head office and subsidiaries of the same group. This applies to scenarios such as auctions, e-commerce platform acquisition, and social entertainment platform top-ups, posing significant transaction risks.
[0028] Since sub-accounts are not required to be opened at the same bank as the head account, banks are unable to verify the identity of sub-account customers and sub-accounts are not included in the scope of suspicious transaction monitoring. Financial transactions between the head account and sub-accounts cannot be effectively supervised, and the risk situation of the account cannot be accurately identified.
[0029] In view of this, an embodiment of the present application provides an account risk identification method.
[0030] Figure 1 The application scenario diagram of the account risk identification method, apparatus, device, medium and program product according to the embodiments of the present application is schematically shown.
[0031] like Figure 1 As shown, the application scenario 100 according to this embodiment may include the field of financial technology. A network 104 is used as a medium for providing a communication link between a first terminal device 101, a second terminal device 102, a third terminal device 103, and a server 105. The network 104 may include various connection types, such as wired or wireless communication links or fiber optic cables.
[0032] A user may use a first terminal device 101, a second terminal device 102, or a third terminal device 103 to interact with a server 105 via a network 104 to receive or send messages, etc. Various communication client applications may be installed on the first terminal device 101, the second terminal device 102, or the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (for example only).
[0033] The first terminal device 101 , the second terminal device 102 , and the third terminal device 103 may be various electronic devices having display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, and the like.
[0034] The server 105 may be a server that provides various services, such as a background management server (for example only) that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103. The background management server may analyze and process received data such as user requests, and feed back processing results (e.g., web pages, information, or data obtained or generated based on user requests) to the terminal devices.
[0035] It should be noted that the account risk identification method provided in the embodiment of the present application can generally be executed by the server 105. Accordingly, the account risk identification device provided in the embodiment of the present application can generally be set in the server 105. The account risk identification method provided in the embodiment of the present application can also be executed by a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105. Accordingly, the account risk identification device provided in the embodiment of the present application can also be set in a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105.
[0036] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.
[0037] The following will be based on Figure 1 The scene described by Figures 2 to 5 The account risk identification method according to the embodiment of the present application is described in detail.
[0038] Figure 2 The following schematically shows a flow chart of an account risk identification method according to an embodiment of the present application.
[0039] like Figure 2 As shown, the account risk identification method of this embodiment includes operations S210 to S240, and the account risk identification method can be executed by a server.
[0040] In operation S210, first identity information and first transaction information of the target account, and second identity information and second transaction information of the associated account are obtained respectively, wherein the transaction operation authority of the associated account belongs to the subject of the target account.
[0041] In the embodiments of this application, the first identity information includes static information such as the target account's business registration and business qualifications. For example, information such as the target account's corporate name, contact information, registration date, registered capital, beneficial owners, legal representatives, shareholders, supervisors, and other key personnel is provided. Similarly, the second identity information includes static information such as the associated account's business registration and business qualifications. For specific examples, see the first identity information above.
[0042] In this embodiment of the present application, the first transaction information includes the target account's fund operation records, for example, the target account allocated a cumulative amount of X yuan to the associated account in a single day. The second transaction information includes the associated account's fund operation records, for example, the associated account transferred Y yuan to 10 off-site accounts within 10 minutes of receiving the funds.
[0043] In the embodiments of this application, the target account is a core fund management account (master account) with control authority over associated accounts. Associated accounts are subsidiary accounts (sub-accounts) controlled by the target account's principal. There can be multiple associated accounts; that is, a single target account can correspond to multiple associated accounts. Transaction operation authority for these multiple associated accounts belongs to the target account's principal. Here, the target account's principal refers to the legal entity that actually controls the target account.
[0044] In the embodiments of this application, the principals of the target account and the associated account can be the same or different. The principal of the target account, as the core controller of the account system (e.g., a group parent company or financial company), has the authority to allocate funds. The principals of the associated account can be the same entity (e.g., a branch) or independent legal entities (e.g., a subsidiary or affiliated company), with operations authorized by the target account principal through an agreement. Transaction authority for the associated account belongs to the principal of the target account.
[0045] For example, if the target account and the linked accounts are owned by the same entity, an e-commerce company (Entity A) opens a target account at a bank and has multiple linked accounts under it: "Entity A - North China Sales" and "Entity A - Supplier Payments." Ownership of funds in all linked accounts belongs to Entity A, and the counterparty sees the payer and payee as "Entity A." Transaction permissions for all linked accounts belong to the target account's entity.
[0046] For example, if the target account and the linked account are held by different entities, a group finance company (Entity B) may open linked accounts for its subsidiaries: "Subsidiary C - Procurement Account" (the actual entity is Subsidiary C, an independent legal entity) and "Subsidiary D - Payroll Account" (the actual entity is Subsidiary D, an independent legal entity). While the counterparty still sees the payer / recipient as the main account entity, Entity B, the funds actually belong to Subsidiary C or D. Trading permissions for all linked accounts belong to the target account's entity.
[0047] In operation S220 , a first recognition result is determined based on the first identity information and the second identity information.
[0048] In an embodiment of the present application, the first identification result may represent the risk information of the target account from the dimension of identity information. Specifically, the first identification result may represent the risk level of the target account.
[0049] In an embodiment of the present application, it is possible to query whether there are any abnormalities in the contents of the first identity information and the second identity information based on the first identity information and the second identity information. If there are any abnormalities, the first identification result may indicate that the target account has a higher risk.
[0050] For example, you can use the first identity information to check whether the target account's business registration, business qualifications, and other information are normal, and use the second identity information to check whether the business registration, business qualifications, and other information of the associated account are normal. The more abnormal content is, the higher the risk level corresponding to the first identification result.
[0051] In an embodiment of the present application, a first identification result can be determined by comparing the first identity information and the second identity information. Since the transaction operation authority of the linked account belongs to the subject of the target account, the higher the similarity between the first identity information and the second identity information, the higher the transaction risk between the target account and the linked account. When the content similarity between the first identity information and the second identity information is high, the first identification result may indicate that the target account has a higher risk.
[0052] In operation S230 , in response to the first recognition result satisfying the target condition, a second recognition result is determined based on the first transaction information and the second transaction information.
[0053] In an embodiment of the present application, the target condition can measure the risk level of the recognition result. If the first recognition result meets the target condition, it means that the risk level of the target account represented by the first recognition result is high.
[0054] In an embodiment of the present application, the second identification result may characterize the risk information of the target account from the dimension of transaction information. Specifically, the second identification result may characterize the risk level of the target account.
[0055] In an embodiment of the present application, it is possible to query whether there are any abnormalities in the contents of the first transaction information and the second transaction information based on the first transaction information and the second transaction information. If there are any abnormalities, the second identification result may indicate that the target account has a higher risk.
[0056] For example, when the transaction amount corresponding to the transaction behavior in the first transaction information does not match the operating scale of the target account, or the transaction amount corresponding to the transaction behavior in the second transaction information does not match the operating scale of the associated account, the risk level corresponding to the second identification result is high.
[0057] For example, when the transaction behavior in the first transaction information indicates that the funds in the target account are quickly inflows and outflows without leaving any balance, or when the transaction behavior in the second transaction information indicates that the funds in the associated account are quickly inflows and outflows without leaving any balance, the risk level corresponding to the second identification result is high.
[0058] In an embodiment of the present application, in response to the first identification result not meeting the target condition, it is indicated that the risk level of the target account in the identity information dimension is low. In this case, the risk level of the target account can be determined to be low, reducing the computational complexity of the subsequent risk identification process.
[0059] In operation S240 , risk information of the target account is determined according to the first identification result and the second identification result.
[0060] In an embodiment of the present application, the first recognition result can represent the risk information of the target account from the perspective of identity information, and the second recognition result can represent the risk information of the target account from the perspective of transaction information. After determining the first recognition result and the second recognition result, the risk information of the target account can be determined based on the first recognition result and the second recognition result. It can be understood that the risk information of the target account ultimately obtained can reflect the risk level of the target account from both the perspective of identity information and transaction information.
[0061] Through the embodiments of the present application, by incorporating the second identity information and second transaction information of the associated account into the scope of suspicious transaction monitoring and combining the target account information with the associated account information for risk identification, the accuracy of target account risk identification can be improved. By using the first identification result satisfying the target condition as a precondition, and further determining the second identification result when the first identification result indicates a higher risk level, the accuracy of target account risk identification can be increased, and the identification efficiency of the account risk identification method of the present application can also be improved.
[0062] In some embodiments, the first identification result includes a first risk score that characterizes the identity risk situation of the target account, and the second identification result includes a second risk score that characterizes the transaction risk situation of the target account; determining the risk information of the target account based on the first identification result and the second identification result includes: determining the risk information of the target account based on the first risk score and the second risk score.
[0063] In an embodiment of the present application, the first risk score may represent the identity risk of the target account, with a higher first risk score indicating a higher risk level for the target account. The second risk score may represent the transaction risk of the associated account, with a higher second risk score indicating a higher risk level for the target account.
[0064] In an embodiment of the present application, risk information of a target account is determined based on the first risk score and the second risk score. The risk information of the target account includes the risk score of the target account.
[0065] For example, the value obtained by multiplying the first risk score by the preset first weight can be added to the value obtained by multiplying the second risk score by the preset second weight, and the resulting value can be determined as the risk score of the target account. If the first risk score is 60, the second risk score is 80, the first weight is 0.4, and the second weight is 0.6, the risk score of the target account is 60*0.4+80*0.6=72.
[0066] For example, a higher value of the first risk score and the second risk score can be determined as the risk score of the target account. If the first risk score is 60 and the second risk score is 80, the risk score of the target account is 80.
[0067] For example, the first risk score and the second risk score can be added together to determine the target account's risk score. If the first risk score is 60 and the second risk score is 80, the target account's risk score is 60 + 80 = 140.
[0068] Through the embodiments of the present application, the first identification result is quantified by the first risk score, the second identification result is quantified by the second risk score, and the risk information of the target account is determined based on the first risk score and the second risk score, which can improve the accuracy of the risk information of the determined target account.
[0069] In some embodiments, the target condition includes: the first risk score falls within a preset risk range.
[0070] In an embodiment of the present application, the preset risk interval may be a pre-set numerical interval.
[0071] For example, 60-100 is set as the preset risk interval. When the first risk score is 70, the first risk score falls into the preset risk interval. At this time, the first recognition result meets the target condition.
[0072] According to the embodiments of the present application, by determining whether the first recognition result meets the target condition based on a preset risk interval, the accuracy of the first recognition result determination can be improved, thereby improving the accuracy of subsequent account risk identification methods.
[0073] In some embodiments, the first identity information and the second identity information both include multiple categories of information, the categories of information contained in the first identity information and the second identity information are consistent and the total number of categories is the same; based on the first identity information and the second identity information, a first identification result is determined, including: from the multiple categories of information in the first identity information, determining the number of categories with the same content as the corresponding category information in the second identity information as the target category number; determining a first risk score based on a first ratio of the target category number to the total category number.
[0074] In an embodiment of the present application, the first identity information and the second identity information both include multiple categories of information. For example, these categories may include the address, registration date, registered capital, contact information, legal representative, shareholder, beneficial owner, and other categories of the account subject.
[0075] In an embodiment of the present application, category information corresponding to the same category in the first identity information and the second identity information is compared in sequence. When the category information in the same category is the same, the category belongs to the target category, all target categories are counted, and the number of target categories is determined.
[0076] Figure 3 A schematic diagram of first identity information and second identity information according to an embodiment of the present application is schematically shown.
[0077] like Figure 3 As shown, the first identity information includes 8 categories from category 1 to category 8, and the second identity information also includes 8 categories from category 1 to category 8. Category 1 in the first identity information and category 1 in the second identity information are the same category, and the same applies to other categories.
[0078] By sequentially comparing category 1 in the first identity information with category 1 in the second identity information, category 2 in the first identity information with category 2 in the second identity information, ..., category 8 in the first identity information with category 8 in the second identity information, we can see that category 2 in the first identity information and category 2 in the second identity information both correspond to category b, category 3 in the first identity information and category 3 in the second identity information both correspond to category c, and category 4 in the first identity information and category 4 in the second identity information both correspond to category d. There are 3 target categories and 8 total categories, so the first risk score can be determined as 3 / 8.
[0079] For example, Category 1 represents the account holder's address, Category 2 represents the registration date, Category 3 represents the registered capital, Category 4 represents the legal representative, Category 5 represents the contact information, and Category 6 represents the beneficial owner. If the category information in Category 2, Category 3, and Category 4 of the first identity information matches the category information in Category 2, Category 3, and Category 4 of the second identity information, respectively, then the registration date, registered capital, and legal representative of the target account holder are consistent with those of the linked account.
[0080] According to the embodiments of the present application, the first risk score is determined based on the number of identical categories in the first identity information and the second identity information, which can further improve the accuracy of the determined first risk score.
[0081] In some embodiments, determining a second identification result based on the first transaction information and the second transaction information includes: determining a transaction behavior data set based on the first transaction information and the second transaction information; the transaction behavior data set includes the transaction behavior of the target account and the transaction behavior of the associated accounts; calculating the number of transaction behaviors in the transaction behavior data set that meet the preset abnormal transaction behavior to obtain the target transaction behavior number; determining a second risk score based on a second ratio of the target transaction behavior number to the total number of transaction behavior data sets.
[0082] In an embodiment of the present application, a transaction behavior dataset is determined based on the first transaction information and the second transaction information. The transaction behavior dataset includes the transaction behavior of the target account and the transaction behavior of the associated accounts. The transaction behavior dataset also includes the transaction behavior of the target account and the associated accounts.
[0083] For example, a pre-defined abnormal transaction behavior includes a transaction amount that is inconsistent with the account holder's business scale. For example, an account has transactions where the cumulative transaction amount is n times the account holder's registered capital. Here, n is a pre-defined value.
[0084] For example, pre-defined abnormal trading behavior includes a small-amount test before an account is enabled. For example, a customer who made a single fund transfer of RMB a or more must have had at least one debit transaction of RMB b or less prior to that transaction. Here, a>b, with a and b being pre-defined values.
[0085] For example, abnormal trading behavior can include rapid inflows and outflows of funds from an account, with no balance remaining. On the day of the transaction, the ratio of the account's cumulative debit to credit balances is between 0.95 and 1.05, and the cumulative amount on each side is greater than or equal to C yuan. Here, C is a preset value.
[0086] For example, the preset abnormal transaction behavior includes frequent transactions between the target account and the associated account, or between the associated account and the associated account. The number of transactions between the target account and the associated account, or between the associated account and the associated account, is greater than or equal to d, and the cumulative amount is greater than or equal to e yuan. Here, d and e are both preset values.
[0087] For example, the default abnormal transaction behavior includes immediately transferring funds from linked accounts to the target account after they are collected. The ratio of the cumulative number of transactions received by the target account from linked accounts to the cumulative number of debit transactions from the target account is greater than or equal to f, and the ratio of the cumulative credit amount to the cumulative debit amount is between x and y. Here, f, x, and y are all preset values.
[0088] For example, a pre-defined abnormal trading behavior might include a large number of debit counterparties in transactions with a linked account, with transactions originating from across the country. Alternatively, a linked account might receive debit transactions from more than g counterparties, spanning more than h different regions. Here, g and h are both pre-defined values.
[0089] In an embodiment of the present application, a second risk score is determined based on a second ratio of the number of target transaction behaviors to the total number of transaction behavior datasets. A higher second ratio indicates a higher second risk score, indicating a higher transaction risk for the target account.
[0090] In an embodiment of the present application, first status information of a target account and second status information of a related account are obtained. In response to the first recognition result satisfying a target condition, a third recognition result is determined based on the first status information and the second status information. Risk information of the target account is determined based on the first, second, and third recognition results.
[0091] In an embodiment of the present application, the first status information includes the operating status of the subject of the target account, and the second status information includes the operating status of the subject of the associated account. A third identification result is determined based on the first status information and the second status information. The third identification result includes a first threshold value and a second threshold value, where the first threshold value is less than 1 and the second threshold value is greater than 1.
[0092] In an embodiment of the present application, if the target account or the associated account's principal operating status is abnormal, such as "abnormal operation," "revoked," or "cancelled," the third identification result is determined to be the second threshold. If the target account and the associated account's principal operating status are normal, the third identification result is determined to be the first threshold.
[0093] In an embodiment of the present application, the first recognition result includes a first risk score, and the second recognition result includes a second risk score. The first risk score and the second risk score are respectively multiplied by the threshold corresponding to the third recognition result to obtain an updated first risk score and an updated second risk score. The risk information of the target account is determined based on the updated first risk score and the updated second risk score. The specific determination method is the same as that described above for determining the risk information of the target account based on the first risk score and the second risk score, and is not further described here.
[0094] According to the embodiments of the present application, by comparing the transaction behavior dataset with the preset abnormal transaction behavior and determining the second risk score based on the comparison result, the accuracy of the determined second risk score can be further improved.
[0095] In some embodiments, obtaining the first identity information and first transaction information of the target account, and the second identity information and second transaction information of the associated account, respectively, includes: obtaining the first identity information and first transaction information of the target account, and the second identity information and second transaction information of the associated account, respectively, within the target period.
[0096] In an embodiment of the present application, the first identity information and first transaction information of the target account, and the second identity information and second transaction information of the associated account are obtained respectively within a target period. The target period is a preset period of time, which may be one month.
[0097] For example, the first identity information and first transaction information of the target account and the second identity information and second transaction information of the associated account within one month are obtained respectively, and the subsequent steps of the account risk identification method are performed based on the obtained information.
[0098] Through the embodiments of the present application, different target periods can be configured for different financial institutions and actual situations, thereby improving the practicality of the account risk identification method of the present application.
[0099] In some embodiments, the target account is a settlement account of a financial institution, and obtaining the first identity information and first transaction information of the target account, and obtaining the second identity information and second transaction information of the associated account, includes: using the internal data of the financial institution to obtain the first identity information and first transaction information based on the target account, and obtaining the second transaction information based on the associated account; using external data from channels other than the financial institution to obtain the second identity information based on the associated account.
[0100] In the embodiments of this application, the target account is a settlement account at a financial institution. A settlement account is a formal account opened by an enterprise or individual at a bank for daily transactions such as fund collection, payment, transfer, deposit, and withdrawal. A settlement account must be opened in real name, requiring the provision of a business license, legal person ID card, and other information. Using the financial institution's internal data, the target account's primary identity information and primary transaction information can be retrieved. Since the transaction operation authority for the associated account belongs to the subject of the target account, the financial institution's internal data can be used to retrieve the associated account's secondary transaction information.
[0101] In the embodiments of the present application, since most of the associated accounts are virtual or internal accounts, financial institutions are usually unable to directly obtain their complete identity information. Therefore, external data from channels other than financial institutions can be used to introduce second identity information of the associated accounts from outside the financial institution through procurement, cooperation, independent collection, etc.
[0102] For example, the secondary identity information can be obtained by matching the unified social credit code and company name of the linked account with public data on the internet. The secondary identity information can also be obtained through third-party cooperative institutions. The secondary identity information can also be obtained through the official website of the entity that the linked account belongs to.
[0103] Through the embodiments of the present application, identity information and transaction information are obtained through internal data and external data respectively, which can improve the richness and accuracy of the obtained information, thereby improving the reliability of account risk identification in this embodiment.
[0104] Based on the above account risk identification method, this application also provides an account risk identification device. Figure 4 The device is described in detail.
[0105] Figure 4 The following schematically shows a structural block diagram of an account risk identification device according to an embodiment of the present application.
[0106] like Figure 4 As shown, the account risk identification device 400 of this embodiment includes an acquisition module 410 , a first determination module 420 , a second determination module 430 and a third determination module 440 .
[0107] Acquisition module 410 is configured to respectively acquire the first identity information and first transaction information of the target account, and the second identity information and second transaction information of the associated account, wherein the transaction operation authority of the associated account belongs to the principal of the target account. In one embodiment, acquisition module 410 may be configured to perform operation S210 described above and will not be further described here.
[0108] The first determination module 420 is configured to determine a first recognition result based on the first identity information and the second identity information. In one embodiment, the first determination module 420 may be configured to execute the operation S220 described above, which will not be described in detail herein.
[0109] The second determination module 430 is configured to determine a second recognition result based on the first transaction information and the second transaction information in response to the first recognition result satisfying the target condition. In one embodiment, the second determination module 430 may be configured to perform the operation S230 described above, which will not be described in detail here.
[0110] The third determination module 440 is configured to determine the risk information of the target account based on the first identification result and the second identification result. In one embodiment, the third determination module 440 may be configured to execute the operation S240 described above, which will not be described in detail here.
[0111] According to embodiments of the present application, any multiple of the acquisition module 410, first determination module 420, second determination module 430, and third determination module 440 may be combined into a single module, or any one of these modules may be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules may be combined with at least part of the functionality of other modules and implemented in a single module. According to embodiments of the present application, at least one of the acquisition module 410, first determination module 420, second determination module 430, and third determination module 440 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application-specific integrated circuit (ASIC), or may be implemented in hardware or firmware through any other reasonable means of circuit integration or packaging, or may be implemented in any one of the three implementation methods of software, hardware, and firmware, or any appropriate combination of any of these. Alternatively, at least one of the acquisition module 410 , the first determination module 420 , the second determination module 430 , and the third determination module 440 may be at least partially implemented as a computer program module, which may perform corresponding functions when executed.
[0112] Figure 5 A block diagram of an electronic device suitable for implementing the account risk identification method according to an embodiment of the present application is schematically shown.
[0113] like Figure 5 As shown, an electronic device 500 according to an embodiment of the present application includes a processor 501, which can perform various appropriate actions and processes based on a program stored in a read-only memory (ROM) 502 or a program loaded from a storage unit 508 into a random access memory (RAM) 503. The processor 501 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or a related chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 501 may also include onboard memory for caching purposes. The processor 501 may include a single processing unit or multiple processing units for performing different actions of the method flow according to the embodiment of the present application.
[0114] Various programs and data required for the operation of the electronic device 500 are stored in the RAM 503. The processor 501, ROM 502, and RAM 503 are connected to each other via a bus 504. The processor 501 performs various operations of the method flow according to the embodiment of the present application by executing the programs in the ROM 502 and / or RAM 503. It should be noted that the programs may also be stored in one or more memories other than the ROM 502 and the RAM 503. The processor 501 may also perform various operations of the method flow according to the embodiment of the present application by executing the programs stored in the one or more memories.
[0115] According to an embodiment of the present application, electronic device 500 may further include an input / output (I / O) interface 505, which is also connected to bus 504. Electronic device 500 may also include one or more of the following components connected to I / O interface 505: an input section 506 including a keyboard, mouse, etc.; an output section 507 including devices such as a cathode ray tube (CRT), liquid crystal display (LCD), and speakers; a storage section 508 including a hard disk; and a communication section 509 including a network interface card such as a LAN card or modem. Communication section 509 performs communication processing via a network such as the Internet. A drive 510 is also connected to I / O interface 505 as needed. Removable media 511, such as a magnetic disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed in drive 510 as needed, so that computer programs read from the removable media can be installed into storage section 508 as needed.
[0116] This application also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments, or may exist independently and not be incorporated into the device / apparatus / system. The computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiments of this application is implemented.
[0117] According to an embodiment of the present application, a computer-readable storage medium may be a non-volatile computer-readable storage medium, such as, but not limited to, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present application, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present application, a computer-readable storage medium may include the ROM 502 and / or RAM 503 described above and / or one or more memories other than ROM 502 and RAM 503.
[0118] The embodiments of the present application also include a computer program product, which includes a computer program containing program code for executing the method shown in the flowchart. When the computer program product is executed in a computer system, the program code is used to enable the computer system to implement the account risk identification method provided in the embodiments of the present application.
[0119] The computer program executes the above functions defined in the system / device of the embodiment of the present application when the computer program is executed by the processor 501. According to the embodiment of the present application, the system, device, module, unit, etc. described above can be implemented by a computer program module.
[0120] In one embodiment, the computer program may be stored on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may be transmitted and distributed in the form of a signal on a network medium, downloaded and installed via the communication portion 509, and / or installed from a removable medium 511. The program code contained in the computer program may be transmitted using any appropriate network medium, including but not limited to wireless, wired, or any suitable combination thereof.
[0121] In such an embodiment, the computer program can be downloaded and installed from the network via the communication section 509, and / or installed from the removable medium 511. When the computer program is executed by the processor 501, the above-mentioned functions defined in the system of the embodiment of the present application are performed. According to the embodiment of the present application, the systems, devices, means, modules, units, etc. described above can be implemented by computer program modules.
[0122] According to an embodiment of the present application, the program code for executing the computer program provided by the embodiment of the present application can be written in any combination of one or more programming languages. Specifically, these computer programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C" or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect via the Internet).
[0123] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of the boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0124] Those skilled in the art will appreciate that the features described in the various embodiments of this application may be combined and / or coupled in various ways, even if such combinations or couplings are not explicitly described in this application. In particular, the features described in the various embodiments of this application may be combined and / or coupled in various ways without departing from the spirit and teachings of this application. All such combinations and / or couplings fall within the scope of this application.
Claims
1. A method for identifying account risk, characterized in that: The method comprises: Obtaining first identity information and first transaction information of a target account, and second identity information and second transaction information of a linked account, respectively, wherein the transaction operation authority of the linked account belongs to the subject of the target account; determining a first identification result according to the first identity information and the second identity information; In response to the first recognition result satisfying a target condition, determining a second recognition result based on the first transaction information and the second transaction information; Determine risk information of the target account based on the first identification result and the second identification result.
2. The method according to claim 1, characterized in that The first identification result includes a first risk score representing an identity risk of the target account, and the second identification result includes a second risk score representing a transaction risk of the target account; The determining the risk information of the target account according to the first identification result and the second identification result includes: Determine risk information of the target account based on the first risk score and the second risk score.
3. The method according to claim 2, characterized in that The target condition includes: the first risk score falls within a preset risk range.
4. The method according to claim 2, characterized in that The first identity information and the second identity information both include multiple categories of information, the categories of information included in the first identity information and the second identity information are consistent, and the total number of categories is the same; The determining a first recognition result according to the first identity information and the second identity information includes: determining, from the plurality of category information of the first identity information, the number of categories having the same content as the corresponding category information in the second identity information as the target category number; The first risk score is determined according to a first ratio of the number of target categories to the total number of categories.
5. The method according to claim 2, characterized in that The determining a second identification result according to the first transaction information and the second transaction information includes: Determining a transaction behavior dataset based on the first transaction information and the second transaction information; the transaction behavior dataset includes the transaction behavior of the target account and the transaction behavior of the associated account; Calculating the number of transaction behaviors that meet preset abnormal transaction behaviors in the transaction behavior data set to obtain a target number of transaction behaviors; The second risk score is determined according to a second ratio of the number of target transaction behaviors to the total number of the transaction behavior data set.
6. The method according to claim 1, characterized in that The obtaining of the first identity information and the first transaction information of the target account, and the second identity information and the second transaction information of the associated account, respectively, includes: During a target period, first identity information and first transaction information of a target account, and second identity information and second transaction information of a linked account are obtained respectively.
7. The method according to claim 1, characterized in that The target account is a settlement account of a financial institution, and obtaining the first identity information and first transaction information of the target account and obtaining the second identity information and second transaction information of the associated account includes: Using the internal data of the financial institution, obtaining the first identity information and first transaction information based on the target account, and obtaining the second transaction information based on the associated account; The second identity information is obtained based on the associated account using external data from a channel other than the financial institution.
8. An account risk identification device, characterized in that: The device comprises: an acquisition module, configured to respectively acquire first identity information and first transaction information of a target account, and second identity information and second transaction information of a linked account, wherein the transaction operation authority of the linked account belongs to the subject of the target account; a first determining module, configured to determine a first recognition result based on the first identity information and the second identity information; a second determining module, configured to determine a second identification result based on the first transaction information and the second transaction information in response to the first identification result satisfying a target condition; A third determination module is configured to determine risk information of the target account based on the first identification result and the second identification result.
9. An electronic device comprising: one or more processors; a memory for storing one or more computer programs, It is characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program or instruction stored thereon, characterized in that: When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
11. A computer program product comprising a computer program or instructions, characterized in that When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.