A research and development expense allocation risk-oriented auditing method and system
By constructing a risk-coupled network model and a dynamic audit scheduling scheme, the limitations of existing R&D expense allocation audit methods have been overcome, enabling risk monitoring and resource optimization throughout the entire lifecycle of R&D projects, and improving the scientific nature and timeliness of audits.
Patent Information
- Application Number
- CN202511461513.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-14
- Publication Date
- 2026-02-10
- Estimated Expiration
- 2045-10-14
AI Technical Summary
Existing audit methods for R&D expense allocation lack targeted analysis of project characteristics and risks, making it difficult to identify abnormal nodes, build a model of the correlation between risks, and make it difficult to flexibly adjust audit plans to meet the time and risk tolerance requirements of different projects, resulting in low audit efficiency and waste of resources.
By acquiring multi-dimensional feature data and audit constraints, a risk-coupled network model is constructed, a risk-oriented audit rule set is generated, audit path planning is performed, the audit node sequence and time arrangement are optimized, a dynamic audit scheduling scheme is generated, and the execution of the risk prevention and control strategy set is automatically triggered when the risk monitoring detects that the standard has been exceeded.
It enables full-lifecycle and all-round risk monitoring of R&D expense allocation, improves the pertinence and efficiency of audits, can respond to risks in a timely manner, meet enterprises' needs for precise and efficient audits, and optimize resource allocation.
Smart Images

Figure CN120931102B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of research and development audit, in particular to a research and development expense allocation risk-oriented audit method and system. BACKGROUND
[0002] In the process of enterprise research and development activities, the rationality and compliance of research and development expense allocation directly affect the accuracy of enterprise financial data, the progress of research and development projects and the efficiency of resource allocation. With the increasing complexity of research and development projects, the types of expenses involved in the project period are increasingly diverse, covering personnel salaries, equipment procurement, material consumption, external collaboration and other dimensions. The flow of expenses presents the characteristics of multiple nodes, cross-stage and dynamic changes, which makes the research and development expense allocation audit face many challenges.
[0003] The research and development expense allocation audit usually adopts traditional sampling audit or process audit method. Such methods often take fixed audit process and unified evaluation standard as the core, and lack of targeted consideration of the characteristics and potential risks of research and development projects. In terms of audit data acquisition, the traditional method usually only focuses on the voucher records and financial statement data of expense payment, and fails to fully integrate multi-dimensional characteristic data such as stage division information, task execution progress and resource input ratio of research and development projects, resulting in a single audit perspective and difficulty in fully capturing abnormal nodes and risk hidden dangers in the expense allocation process.
[0004] From the perspective of risk control, the existing audit method lacks effective analysis of the risk correlation of different stages of research and development projects. The risk types existing in different stages of research and development projects, such as project establishment, implementation and completion, are different, and there may be transmission and coupling effect between the risks of different stages, for example, unreasonable resource allocation in the implementation stage may lead to cost overrun risk in the completion stage. The traditional audit method usually evaluates the risks of each stage separately, cannot build a correlation model between risks, and thus it is difficult to achieve early warning and precise control of risks.
[0005] In the process of developing audit scheme, the traditional audit method fails to fully consider the constraints of audit time window and risk tolerance. Different research and development projects have different requirements for audit period, some urgent projects need to complete the audit work in a short time, while some high-risk projects need to set a lower risk tolerance to ensure the quality of audit. The traditional method cannot flexibly adjust the audit path according to these dynamic constraints, which may cause problems such as waste of audit resources, low efficiency of audit and insufficient coverage of audit, and cannot meet the needs of enterprises for precise, efficient and dynamic research and development expense allocation audit. SUMMARY
[0006] The present application aims to provide a research and development expense allocation risk-oriented audit method and system to solve the problems raised in the background.
[0007] To achieve the above object, the application provides a research and development expense allocation risk-oriented auditing method, which comprises the following steps:
[0008] Obtaining multi-dimensional characteristic data of a research and development project and auditing constraint conditions, wherein the multi-dimensional characteristic data comprises project stage division data, expense flow direction data and risk index data, and the auditing constraint conditions comprise time window constraints and risk tolerance constraints;
[0009] Constructing a risk coupling network model based on the project stage division data and the risk tolerance constraints, and generating a risk-oriented auditing rule set through the risk coupling network model;
[0010] Planning an auditing path according to the expense flow direction data and the risk-oriented auditing rule set, and outputting an initial auditing scheme, wherein the initial auditing scheme comprises an auditing node sequence and a risk monitoring threshold;
[0011] Taking the time window constraints as an optimization target, performing time sequence optimization processing on the auditing node sequence, and obtaining a dynamic auditing scheduling scheme;
[0012] Performing risk transmission analysis based on the dynamic auditing scheduling scheme, and generating a risk prevention and control strategy set, wherein the risk prevention and control strategy set comprises a multi-level risk disposal scheme and an emergency response mechanism;
[0013] In the process of research and development expense allocation auditing, the execution of the risk prevention and control strategy set is triggered according to the risk monitoring threshold.
[0014] Preferably, constructing a risk coupling network model based on the project stage division data and the risk tolerance constraints comprises the following steps:
[0015] Extracting stage characteristics from the project stage division data, and obtaining key activity characteristics and resource consumption characteristics of each stage;
[0016] Labeling the key activity characteristics according to the risk tolerance constraints, and forming a stage risk characteristic set with weights;
[0017] Constructing a multi-layer network topology structure comprising the stage risk characteristic set, wherein a network node represents a research and development activity, and an edge weight represents a risk transmission intensity;
[0018] Calculating a risk transmission path through the multi-layer network topology structure, and generating the risk coupling network model.
[0019] Preferably, planning an auditing path according to the expense flow direction data and the risk-oriented auditing rule set comprises the following steps:
[0020] The cost flow data is clustered by project stage to obtain a cost distribution hotspot area;
[0021] The cost distribution hotspot area is matched with the risk-oriented audit rule set to determine a key audit area;
[0022] An optimal audit path is searched in the key audit area using a graph traversal algorithm to form an audit node sequence;
[0023] The risk values of each audit node are calculated according to the risk transmission intensity of the risk coupling network model, and the risk monitoring threshold is set.
[0024] Preferably, the audit node sequence is subjected to timing optimization processing, including:
[0025] An audit task timing constraint model is established, which includes task execution duration constraints and task dependency relationship constraints;
[0026] An audit scheduling optimization objective function is constructed based on the time window constraints;
[0027] A heuristic search algorithm is used to optimize the audit scheduling optimization objective function under the premise of meeting the timing constraint model;
[0028] The dynamic audit scheduling scheme including task execution timing and resource allocation scheme is output.
[0029] Preferably, risk transmission analysis is performed based on the dynamic audit scheduling scheme, including:
[0030] The risk state of the current audit node is marked in the risk coupling network model;
[0031] The process of risk transmission along the network edges is simulated to predict the risk impact range and time;
[0032] A risk disposal priority list is generated according to the node attributes on the risk transmission path;
[0033] The multi-level risk disposal scheme is constructed in combination with the risk disposal priority list and the resource allocation scheme.
[0034] Preferably, generating the emergency response mechanism includes:
[0035] Abnormal fluctuation signals in the risk coupling network model are monitored, and when the fluctuation amplitude exceeds a preset threshold, an emergency response process is started, and a pre-stored emergency handling template is matched according to the abnormal fluctuation characteristics;
[0036] The resource allocation strategy in the dynamic audit scheduling scheme is dynamically adjusted.
[0037] Preferably, the multi-level risk management scheme includes:
[0038] The Level 1 response plan takes measures to block the direct source of risk;
[0039] The secondary response plan implements mitigation strategies for the indirect risk impact;
[0040] The Level 3 response plan establishes a risk isolation buffer zone;
[0041] Information sharing and data coordination should be maintained between response plans at all levels.
[0042] Preferably, triggering the execution of the risk control strategy set includes:
[0043] Risk indicator data of audit nodes are collected in real time, and the collected data is compared and analyzed with the risk monitoring threshold. When an abnormal risk indicator is detected, the corresponding risk handling plan is automatically matched.
[0044] Record the risk management process and update the risk coupling network model.
[0045] Preferably, updating the risk-coupled network model includes:
[0046] Collect state change data during the risk management process, recalculate the risk transmission strength of network nodes, and adjust the edge weight parameters in the network topology.
[0047] The risk-oriented audit rule set is optimized based on the updated network model.
[0048] Preferably, the present invention also includes a risk-oriented audit system for R&D expense allocation, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor, when executing the computer program, implements the steps of the above-described risk-oriented audit method for R&D expense allocation.
[0049] Compared with the prior art, the beneficial effects of the present invention are:
[0050] This risk-oriented audit method for R&D expense allocation breaks through the limitations of traditional audit methods by integrating multi-dimensional characteristic data of R&D projects with audit constraints, providing a more scientific and comprehensive solution for R&D expense allocation audits. At the data utilization level, this method is no longer limited to single financial data, but incorporates project phase division data, expense flow data, and risk indicator data into the audit data system. It can analyze the expense allocation process from the perspective of the entire project lifecycle, more comprehensively reflecting the actual situation of R&D expense allocation. This helps auditors discover abnormal expense nodes that are difficult to detect using traditional methods, improving the completeness and effectiveness of audit data.
[0051] In terms of risk analysis and rule construction, the risk coupling network model, built based on project phase segmentation data and risk tolerance constraints, can effectively uncover the correlation and coupling effects between risks at different stages of R&D projects. The risk-oriented audit rule set generated by this model fully reflects the phase characteristics and risk tolerance differences of R&D projects. This makes the audit rules no longer uniform and fixed standards, but a dynamic rule system that matches the actual risk situation of the project. Auditors can use this rule set to more accurately identify high-risk audit areas, avoid ineffective investment of audit resources in low-risk areas, optimize the allocation of audit resources, and improve the pertinence and accuracy of audit work.
[0052] In the audit plan development and optimization phase, audit path planning is conducted based on cost flow data and risk-oriented audit rule sets. This allows for the design of audit paths around key nodes in the cost flow, ensuring that the audit work focuses on the core aspects of cost allocation, reducing unnecessary audit processes, and improving audit efficiency. Simultaneously, by using time window constraints as an optimization target, the execution sequence of audit nodes is optimized. This allows for flexible adjustment of the execution order and timing of audit nodes according to the audit time requirements of different R&D projects. While meeting time constraints, this maximizes the coverage and depth of the audit work, avoiding issues of decreased audit quality or low audit efficiency due to time limitations, making the audit plan more flexible and adaptable.
[0053] In terms of risk prevention and response, risk transmission analysis based on a dynamic audit scheduling scheme can clearly present the transmission path and impact level of risks at each stage of R&D projects. This helps auditors predict risk development trends in advance, thereby generating a risk prevention strategy set that includes multi-level risk handling plans and emergency response mechanisms. This multi-level risk handling plan can take corresponding measures for different levels of risks, avoiding excessive or insufficient risk response measures. The emergency response mechanism provides auditors with clear response procedures and operational guidelines when sudden risk events occur, helping to quickly control the spread of risks, reduce the impact of risks on the rationality of R&D expense allocation, and improve the risk management capabilities of audit work.
[0054] During the audit process, risk monitoring thresholds trigger the execution of a set of risk control strategies, enabling dynamic risk response in the audit work. When a risk indicator at a certain point in the audit exceeds a set threshold, the corresponding risk control strategy can be automatically activated, eliminating reliance on auditors' subjective judgment and manual operation. This reduces the impact of human factors on the audit response speed, ensuring timely risk management and further improving the timeliness and reliability of the audit work. Furthermore, this method is applied throughout the entire process of R&D expense allocation auditing, from data acquisition, rule construction, and scheme optimization to risk control, forming a complete closed-loop audit system. This system continuously improves the quality and efficiency of R&D expense allocation auditing, better meeting enterprises' needs for standardized R&D expense management and precise risk control, helping enterprises optimize R&D resource allocation and ensuring the smooth progress of R&D projects. Attached Figure Description
[0055] Figure 1 This is a schematic diagram illustrating the working principle of the risk-oriented audit method for R&D expense allocation described in this invention.
[0056] Figure 2 Flowchart for constructing a risk-coupled network model;
[0057] Figure 3 This is a flowchart for audit path planning. Detailed Implementation
[0058] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0059] Please see Figure 1This invention provides a risk-oriented audit method and system for R&D expense allocation. The method integrates multi-dimensional feature data and audit constraints to achieve efficient risk identification and prevention. The method acquires multi-dimensional feature data of R&D projects, including project phase division data, expense flow data, and risk indicator data, while also acquiring audit constraints such as time window constraints and risk tolerance constraints. A risk-coupled network model is constructed based on the project phase division data and risk tolerance constraints. This model generates a risk-oriented audit rule set to guide subsequent audit processes. Audit path planning is performed based on expense flow data and the risk-oriented audit rule set, outputting an initial audit plan containing an audit node sequence and risk monitoring thresholds. Using the time window constraint as an optimization objective, time-series optimization processing is performed on the audit node sequence to obtain a dynamic audit scheduling plan. Risk transmission analysis is performed based on the dynamic audit scheduling plan to generate a risk prevention and control strategy set containing multi-level risk handling plans and emergency response mechanisms. During the R&D expense allocation audit process, the system automatically triggers the execution of the risk prevention and control strategy set based on the risk monitoring thresholds, ensuring real-time risk management.
[0060] Example 1: See Figure 2 When extracting phase features from project phase data, data preprocessing techniques are used to clean and standardize the original project phase data. This data typically comes from an enterprise's project management information system or financial software and includes phase markers, time nodes, and activity records for the project lifecycle. The data cleaning process needs to address issues such as missing values, outliers, and inconsistent formats. For example, interpolation methods are used to fill in missing time node data, or a rule engine is used to unify the differences in phase naming across different systems. Standardization transforms various types of data into a unified dimension and unit, facilitating subsequent feature extraction algorithms. For instance, time data is standardized to a timestamp format, and text-described activity records are transformed into structured activity tags using natural language processing techniques.
[0061] When extracting key activity features, pattern recognition algorithms are used to analyze the activity sequences within a stage, identifying representative key activity patterns. For example, sequence pattern mining techniques can be used to discover frequently occurring activity combinations, or clustering algorithms can be used to categorize similar activities. Resource consumption feature extraction focuses on analyzing resource input data at each stage, including the distribution of human resource workload, material resource consumption curves, and the expenditure rhythm of financial resources. This data is typically obtained from the company's resource management system, and time series analysis methods are used to identify peaks, troughs, and trends in resource consumption. The results of feature extraction are stored in the form of feature vectors. Each stage corresponds to a feature vector containing multiple dimensions. These vectors not only contain numerical data but may also include coded representations of categorical data.
[0062] The process of forming a weighted set of stage-specific risk features requires labeling the key activity features of each stage with risk levels based on a pre-defined risk assessment framework. This framework is typically built upon industry standards, historical audit experience, or expert knowledge bases, and includes a series of risk indicators and corresponding threshold ranges. Risk level labeling is an iterative quantitative process. For example, each key activity feature is scored based on its deviation from the normal range, frequency of occurrence, and potential impact, and then the scores are mapped to discrete risk levels, such as high risk, medium risk, or low risk. Weight assignment considers multiple factors, including the risk level itself, the activity's criticality within the project, and the probability of historical risk events. Weight calculation may employ multi-criteria decision-making methods such as the analytic hierarchy process (AHP) or entropy weighting. The final stage-specific risk feature set is a structured data table, where each record contains a stage identifier, activity feature, risk level, and weight value.
[0063] When constructing a multi-layered network topology, the basic elements of the network must first be defined. Network nodes represent specific activities within a research and development project, and node attributes include activity type, stage, resource demand intensity, and risk characteristic value. Network edges represent the relationships between activities, and edge weights represent the strength or probability of risk propagation between different activities. The network topology design adopts a hierarchical approach, for example, using project stages as the higher-level network and specific activities within a stage as the lower-level network. Layers are connected through inclusion relationships, and nodes within the same layer are connected through temporal relationships, resource dependencies, or information flow relationships. The initial values of edge weights can be determined by analyzing risk propagation cases in historical project data, such as calculating the conditional probability of risk events occurring sequentially between two activities, or quantifying the correlation strength using expert scoring methods. Network topologies are typically stored and visualized using graph databases or specialized network analysis software. Calculating risk propagation paths is the core step in generating a risk-coupled network model. This process is based on path search algorithms in graph theory, starting from the risk source node and traversing the entire network topology to find all possible risk propagation routes. When implementing the algorithm, it's necessary to consider path search strategies. For example, depth-first search can be used to discover potential risks along long paths, or breadth-first search can be used to quickly identify high-risk areas. Path evaluation criteria include not only path length but, more importantly, the cumulative effect of the weights of each edge along the path, i.e., the overall risk propagation value. The calculated result of the risk propagation path is a set of paths, each accompanied by its total risk value, a list of key nodes it passes through, and an estimated propagation time. This path information is integrated into the risk coupling network model, enabling the model to dynamically reflect the propagation trend of risks in the project.
[0064] The generation of the risk-coupled network model is not a one-time static process, but a dynamic mechanism that requires continuous updates. After the initial model construction, it will be continuously optimized as the audit process progresses and new data is input. The model update mechanism involves real-time adjustments to network nodes and edges. For example, when the audit finds that the risk characteristics of an activity have changed, the attribute values of the corresponding nodes need to be updated, and the weights of their associated edges need to be recalculated. The model optimization algorithm may use incremental learning techniques, performing local recalculation only on the changed parts to improve update efficiency. The final risk-coupled network model is a complex network data structure containing complete topological information, node attributes, edge weights, and risk transmission paths.
[0065] There are close data dependencies and logical connections between phase feature extraction and various stages of network construction. The quality of feature extraction directly affects the accuracy of risk labeling, while the completeness of the risk feature set determines the representativeness of the network topology. In actual system implementation, these steps are usually encapsulated into a configurable data processing pipeline, allowing adjustments to parameters and algorithm selection based on the characteristics of different types of R&D projects. For example, the phase divisions and risk characteristics of software development projects and high-tech R&D projects may differ significantly, and the system needs sufficient flexibility to adapt to these differences. The entire implementation process emphasizes data-driven and model-based decision-making, transforming fuzzy management experience into precise computational models, thereby improving the scientific rigor and objectivity of auditing the risk allocation of R&D expenses.
[0066] Example 2: See Figure 3 When clustering expense flow data by project stage, the raw expense data needs to be preprocessed and structured first. This data comes from the company's financial management system, project accounting units, or procurement records, and includes the time, amount, purpose classification, and corresponding project stage identifier of the expenses. Data preprocessing involves data cleaning, format standardization, and supplementation of related information, such as unifying the coding system of expense items, correcting time zone differences in timestamps, and associating and matching expense records scattered across different systems using project IDs. Clustering analysis uses unsupervised machine learning algorithms to group the processed expense data. Algorithm selection considers data characteristics and business needs. For example, k-means clustering is commonly used for numerical expense data, while k-prototypes is used for mixed data containing categorical data. Clustering dimensions include expense amount, frequency of occurrence, expenditure object, and time distribution characteristics. Identification of expense distribution hotspots is based on the location and density of the center point of each cluster in the clustering results. High-density clusters with high amounts are marked as hotspots, which usually correspond to key nodes or concentrated resource investment phases in project execution.
[0067] The process of risk-based audit rule set matching for cost distribution hotspots is a multi-condition screening and prioritization process. The risk-based audit rule set exists in the form of executable rules, developed by audit experts based on industry standards, corporate internal control requirements, and historical risk cases. The rule matching engine compares the characteristics of each hotspot with the rule conditions using methods including exact matching, range matching, and fuzzy matching. For example, a rule might define "material procurement costs exceeding the budget by 30% in a certain period and concentrated within one week" as a high-risk signal; the system will automatically scan for data in hotspots that meet this condition. The result of risk matching is a list of key audit areas. This list not only marks the location of the areas but also includes the matched rule number, risk level, and preliminary risk assessment description. The list is sorted by risk severity, providing input for subsequent audit path planning.
[0068] When using graph traversal algorithms to search for the optimal audit path in critical audit areas, it is necessary to abstract the audit areas and their relationships into a graph data structure. Nodes in the graph represent individual audit areas or specific audit points within those areas, and edges represent the reachability relationships and transfer costs between audit points. The choice of graph traversal algorithm considers the audit objectives and constraints. For example, Dijkstra's algorithm is used to find the shortest path when the objective is to minimize the total audit time, while a heuristic search algorithm is used to explore the optimal solution when the objective is to maximize risk coverage. The search process for the optimal audit path is a dynamic optimization process. The algorithm needs to comprehensively consider multiple factors such as path length, node risk value, and audit resource constraints. Multiple candidate paths are generated and evaluated during the search process. The final sequence of audit nodes is an ordered list of audit tasks, specifying the access order, expected dwell time, and main audit content for each node. This sequence provides the basic framework for subsequent time-series optimization.
[0069] Calculating the risk value of each audit node based on the risk transmission strength of the risk-coupled network model is a quantitative calculation process based on network analysis. The calculation considers not only the node's own risk characteristics but also its position and connectivity within the network. During the calculation, network node attributes corresponding to each audit node are extracted from the risk-coupled network model, including the node's risk level, the weights of its incoming and outgoing edges, and the risk status of its connected neighboring nodes. Network centrality indicators such as betweenness centrality and eigenvector centrality are used to measure the node's importance in the entire risk propagation network. The specific calculation of the risk value may employ a weighted summation model or a probabilistic graphical model, merging the node's own risk indicators and network transmission indicators into a comprehensive risk score. This score reflects the node's relative importance and potential impact on the overall risk. The setting of risk monitoring thresholds is based on the statistical distribution of historical audit data and risk tolerance constraints. Quantile methods or statistical process control methods are used to determine the critical values for different risk levels. Threshold settings consider business characteristics and risk preferences, typically divided into multiple levels such as early warning thresholds and action thresholds.
[0070] The overall implementation of audit path planning requires the collaborative work of multiple components. The clustering analysis module is responsible for identifying areas of concern from massive amounts of cost data; the rule matching module assigns risk meanings to these areas; the path search module connects discrete risk points into efficient audit routes; and the risk calculation module assigns corresponding monitoring standards to each audit point. System implementation needs to consider data interfaces and process connections between modules. For example, clustering results need to be passed to the rule matching engine in a standard format, and the path search algorithm needs to obtain the latest state data of the network model in real time. The entire planning process is not a one-time static operation, but a progressive process that can be dynamically adjusted as the audit progresses and new data is input. When new risk signals are discovered or cost data is updated during the audit, the system can re-execute path planning and generate a revised audit plan.
[0071] The quality and completeness of cost flow data directly impact the effectiveness of cluster analysis. In practical applications, a data quality monitoring mechanism is often needed to validate and complete the input data, triggering alerts and initiating data completion processes for substandard data. Rule maintenance in the risk matching process is another crucial aspect. Audit rules need to be revised regularly as regulations, policies, and business models evolve. The system should provide a rule management interface, allowing audit experts to easily add, modify, or deactivate specific rules. Parameter tuning for graph traversal algorithms needs to be tailored to specific audit scenarios. For example, the quantification standards for transfer costs and the design of heuristic functions require continuous optimization through case studies and experience. A dynamic adjustment mechanism for risk monitoring thresholds enables the system to adapt to the changing characteristics of different project types and audit stages, improving the accuracy and timeliness of risk identification. While significant manual intervention and parameter adjustments may be required in the early stages of system development, the system's automation and planning quality will gradually improve with the accumulation of audit cases and continuous optimization of the algorithm model. The entire implementation process embodies the concept of data-driven auditing, transforming traditional experience-based auditing into risk-based auditing based on data analysis, and improving the scientific nature and efficiency of auditing work through quantitative methods and computational models.
[0072] Example 3: The time-series constraint model includes task execution duration constraints and task dependency constraints. Task execution duration constraints are based on historical audit data or expert experience, setting the minimum and maximum completion times for each task. Task dependency constraints are determined by analyzing the logical order between audit nodes; for example, some audit tasks must be completed before they can begin, or multiple tasks can be executed in parallel but are limited by resources. When constructing the time-series constraint model, graph theory is used to represent audit tasks as nodes and dependencies as directed edges, forming a task network graph. The edge weights in the graph represent the waiting time or conversion cost between tasks. Model data comes from project plans, audit logs, and resource calendars. Constraints are automatically generated by parsing this data, such as extracting task order from the project Gantt chart and identifying conflict points from the resource allocation table.
[0073] An audit scheduling optimization objective function is constructed based on time window constraints. The time window constraint specifies the final deadline or milestone that the audit must complete. The optimization objective function is primarily aimed at minimizing total audit time or maximizing time utilization, while also considering factors such as resource balance and risk coverage. The mathematical expression of the objective function needs to quantify these indicators, for example, by defining a comprehensive scoring function to weigh different objectives. Assume the optimization objective function... To minimize the total delay penalty, it takes the following form:
[0074] ;
[0075] in: This represents the total penalty value. It refers to the number of audit tasks. It is a task The weighting coefficient reflects its importance. It is a task The actual completion time, It is a task The expected completion time of the function Calculate task delay time; the penalty is zero when the task is completed ahead of schedule or on time. Weighting coefficient. Based on the task risk level, high-risk tasks are given higher weight to ensure their timely completion, with an expected completion time. It is derived from time window constraints, such as by combining project deadlines and task dependencies.
[0076] A heuristic search algorithm is employed to optimize the audit scheduling objective function while satisfying the time-constrained model. The selection of the heuristic search algorithm considers the problem size and real-time requirements; for example, genetic algorithms or particle swarm optimization are used for large audit projects, while simulated annealing or tabu search are employed for small to medium-sized projects. The algorithm implementation requires encoding the audit scheduling scheme as feasible solutions, where each solution represents the task execution order and start time. The quality of the solutions is evaluated using a fitness function, which is directly related to the optimization objective, such as the total penalty value. The search process iteratively generates new solutions, exploring the solution space through crossover, mutation, or neighborhood operations. At the same time, it checks whether each solution satisfies temporal constraints, such as whether dependencies are violated or resources are exceeded. Algorithm parameters, such as population size and number of iterations, need to be optimized experimentally to balance convergence speed and solution quality.
[0077] The output includes a dynamic audit scheduling plan containing task execution sequences and resource allocation schemes. The task execution sequence specifies the planned start time, end time, and buffer time for each audit task. The resource allocation scheme specifies the manpower, tools, and budget required to execute the task. After the plan is generated, it is presented in a visual form, such as an interactive Gantt chart or timeline chart, to facilitate auditors' understanding and adjustment. The dynamic audit scheduling plan is adjustable. When the project schedule changes or new risks emerge, the system can re-run the optimization process to update the plan, such as inserting emergency audit tasks or reallocating resources. The update mechanism is based on incremental calculation to reduce re-optimization time. In the risk transmission analysis phase, risk status is marked based on the dynamic audit scheduling plan. The risk status of the current audit node is marked in the risk coupling network model. Risk status includes levels such as normal, observation, warning, and abnormal. Status determination is based on the comparison of real-time collected risk indicator data with thresholds, such as cost overrun rate, schedule deviation, or resource conflict degree. The status marking process is automated and implemented through a rule engine or machine learning classifier. The marking results are updated to the node attributes of the network model in real time. The process of simulating risk propagation along network edges is achieved using discrete event simulation technology. The simulation model is based on a risk-coupled network, defining the probability of occurrence and propagation delay of risk events. During simulation execution, starting from the current risk node, the risk propagation path and impact time are calculated according to the network edge weights and node states. The model outputs a risk impact range map, displaying potentially affected nodes and propagation timelines.
[0078] A risk handling priority list is generated based on the node attributes along the risk transmission path. Node attributes include risk value, resource dependence, and business criticality. Priority calculation employs multi-attribute decision-making methods, such as weighted scoring or TOPSIS. The list is arranged in descending order of priority, with high-priority nodes corresponding to major risks or emergencies. Combining the risk handling priority list and resource allocation schemes, a multi-level risk handling plan is constructed. These plans differentiate response levels; for example, level one involves rapid blocking of direct risk sources, level two mitigates indirect impacts, and level three establishes a long-term isolation mechanism. The plan details action steps, responsible persons, and resource requirements to ensure operability. The integration of time-series optimization and risk transmission analysis reflects dynamism. Optimized scheduling plans are input into risk analysis, and the analysis results are fed back to adjust scheduling, forming a closed-loop management system. During system implementation, the time-series optimization module and the risk analysis module exchange data via API interfaces. Optimization algorithms and simulation models are deployed on a scalable computing platform, supporting large-scale project processing. The entire implementation process emphasizes practical applicability, using quantitative methods and simulation techniques to improve the scientific nature of audit scheduling and the efficiency of risk response.
[0079] Example 4: The generation of emergency response mechanisms and multi-level risk management plans is a dynamic and critical operational process. The effectiveness of this mechanism can be illustrated through a specific case study of a high-tech enterprise's new product development project. This project involves three main phases: hardware development, software programming, and system integration. During the audit, abnormal cost fluctuations were discovered in the hardware procurement phase. Monitoring abnormal fluctuation signals in the risk coupling network model relies on real-time data collectors deployed at various nodes of the project. These collectors continuously monitor risk indicators such as expense expenditure rate, budget execution deviation rate, and supplier concentration. When the daily expense expenditure in the hardware procurement phase exceeds 150% of the phase's average daily budget for three consecutive working days, the system detects that the fluctuation significantly exceeds a preset threshold (this threshold is typically set at 120% based on historical project data), thereby triggering the emergency response process.
[0080] The system automatically matches the current fluctuation characteristics (including fluctuation amplitude, duration, and scope of impact) with a pre-stored emergency response template library. This library contains standard response procedures for different types of anomalies (such as sudden expenditures, supplier changes, and specification adjustments). Upon matching a template for a "sudden expenditure" anomaly, the system dynamically adjusts the resource allocation strategy in the audit scheduling plan. Specific measures include temporarily assigning an auditor from the software programming phase to the hardware audit team, postponing the system integration phase document audit originally scheduled for the following day by 24 hours, and initiating an emergency procurement contract review process. Resource reallocation follows a priority principle, ensuring high-risk areas receive immediate attention, while buffer time settings minimize the impact on the overall audit progress.
[0081] The multi-tiered risk mitigation plan exhibits a tiered response. The first-tier plan targets the direct risk source—hardware procurement—by implementing blocking measures. The audit team immediately advised the procurement department to "suspend payments," requiring supplementary agreements and acceptance certificates for three outstanding payments exceeding 500,000 yuan, while simultaneously freezing subsequent operational permissions for the relevant purchase orders. The second-tier plan mitigates indirect risk impacts. The audit team simultaneously reviews expense records related to logistics, warehousing, and quality inspection associated with hardware procurement, assesses potential chain reactions, stress-tests project cash flow forecasts, and prepares contingency funding plans. The third-tier plan establishes a risk isolation buffer zone by reconfiguring project budget approval authority, elevating the approval level for large purchases from department manager to director level, and setting hard budget control points in the financial system to prevent risks from spreading to later stages of the project.
[0082] Table 1: Monitoring Data on Risk Transmission During Hardware Development Phase
[0083]
[0084] Referring to Table 1, information linkage and data sharing are maintained between the various levels of response plans. This is achieved through the establishment of a unified emergency command platform. Supplier qualification issues discovered during the Level 1 response are synchronized in real time to the Level 2 response team, enabling them to focus on the supplier's logistics and quality inspection records during the review of related processes. Budget control point data set in the Level 3 response plan are also fed back to the Level 1 response team as a basis for adjusting procurement limits. The platform uses distributed ledger technology to record all response actions, ensuring that operational traceability is tamper-proof. The effectiveness of the emergency response process is evaluated through changes in the risk transmission index, which integrates data from multiple dimensions such as cost deviation, scope of impact, and difficulty of response. When the system detects that the risk transmission index rises from 253 on day 3 to 389 on day 4, it automatically upgrades the response level from Level 2 to Level 3, triggering stricter isolation measures. The dynamic adjustment mechanism is not only reflected in resource allocation but also in the self-optimization of emergency plans. Based on the data collected during this emergency response, the system automatically updates the identification threshold and matching rules for "rush expenditure" anomalies, improving the sensitivity of future warnings for similar risks.
[0085] The establishment of a risk isolation buffer zone involved cross-departmental collaboration. The audit team, in conjunction with the finance and legal departments, formed a temporary monitoring group to implement a dual-signature system for subsequent expenditures during the hardware procurement phase. Each payment required joint approval from the project manager and the audit representative. Simultaneously, a virtual firewall was set up within the project management system to isolate high-risk procurement activities from other normal business operations, restricting their data flow and operational permissions to prevent risk spread. The entire emergency response process demonstrated a balance between contingency plan execution and dynamic adjustment. The system strictly adhered to pre-set emergency templates while flexibly adjusting the response intensity based on real-time monitoring data. In the handling of the hardware procurement risk event, the three-tiered response plan promptly cut off the risk transmission path. Subsequent auditing revealed that the abnormal fluctuation was mainly caused by an urgent technical change. After supplementing and improving the approval process, the project risk level gradually returned to normal. The full-process data generated from this emergency response was automatically included by the system as a new case template for optimizing future emergency decision-making.
[0086] The effectiveness of an emergency response mechanism depends on the coordination of multiple elements. The coverage of the real-time monitoring system affects the timeliness of anomaly detection, the completeness of the contingency plan database determines the targeting of response measures, and the flexibility of resource allocation directly affects the efficiency of handling. In system design, different threshold parameters and response templates need to be preset for various risk scenarios, and matching accuracy needs to be continuously optimized through machine learning algorithms. The effectiveness of multi-level handling schemes depends on clear grading standards, smooth escalation mechanisms, and seamless connections between levels, which requires continuous refinement and improvement of operating procedures in actual operation. Embedding the emergency response mechanism and multi-level risk handling schemes into the audit process can achieve a shift from passive response to proactive prevention. Through structured and standardized response processes, the risk situation can be quickly controlled, minimizing losses. This mechanism is particularly suitable for scenarios with high uncertainty and rapid changes, such as R&D projects. Its value lies in establishing a systematic risk response capability, extending audit work from simple value verification to risk governance.
[0087] Example 5: The execution of the risk control strategy set is triggered by the continuous operation of the real-time data acquisition system. This system, integrated into the project financial software, procurement platform, and laboratory management system, collects key risk indicator data every five minutes, including the expenditure rate of material procurement costs, budget execution deviation rate, supplier on-time delivery rate, and laboratory resource utilization efficiency. The collected data flows through a distributed processing engine for preliminary cleaning and standardization, such as standardizing timestamp formats, correcting currency unit differences, and calculating derived indicators such as cumulative overspending ratio and trend change rate. The processed data is then pushed to the risk comparison and analysis module. The comparison and analysis module dynamically compares real-time indicator values with preset risk monitoring thresholds. These thresholds are dynamically adjusted according to the project stage. For example, during the formula development stage, the warning threshold for the material procurement cost deviation rate is set at 15%, and the action threshold is set at 25%. When the system detects that the procurement cost deviation rate suddenly jumps to 30% in a certain week and continues for three collection cycles, it is immediately marked as an abnormal event.
[0088] Anomaly detection triggers an automatic matching mechanism. The system first extracts features from the anomaly event, including deviation magnitude, duration, impact range, and related indicator patterns. Then, it performs similarity matching between these feature vectors and indices in a risk management solution library. The library contains dozens of pre-stored standard handling templates, each corresponding to a different risk scenario. For example, the template for "supplier concentration risk" includes steps such as suspending new contract signings and initiating alternative supplier assessments; the template for "accelerated budget execution" involves cash flow stress testing and adjustments to expenditure authorization. The matching algorithm uses a k-nearest neighbor classifier to calculate the Euclidean distance between the current anomaly feature and the feature vectors of each template. The three closest templates are selected as candidates, and a weighted vote is used to determine the final matching solution. Upon successful matching, the system automatically generates a handling task work order, assigns it to the corresponding responsible team, and triggers an alert notification to the project audit manager.
[0089] The risk management process is recorded through an audit log platform that uses blockchain technology to ensure the immutability of records. Each action is meticulously documented, including the trigger time, anomaly description, matching solution ID, executor, measures taken, start and end timestamps, and preliminary effect assessment. Log data is synchronized in real-time to the risk coupling network model update module, providing factual evidence for model optimization. For example, after a management plan is implemented, the system records the process of the procurement cost deviation rate decreasing from 30% to 18%, while simultaneously capturing changes in relevant indicators such as supplier delivery delay rates. The first step in updating the risk coupling network model is to collect status change data during the risk management process. This data comes from the audit log platform, project management system, and real-time monitoring streams, including changes in risk values at each node before and after management, the actual performance of edge transmission strength, newly emerging relationships, and the weakening or disappearance of existing relationships. Data collection covers the entire project lifecycle, extending beyond direct management nodes to upstream and downstream related activities. For example, regarding the management of procurement cost anomalies, the system simultaneously collects raw material inventory levels, production schedule adjustments, and financial cash flow data to comprehensively assess the cascading impact of management measures.
[0090] The recalculation of risk propagation intensity among network nodes employs a Bayesian update-based probabilistic model. This model takes historical propagation data and current state changes as input to re-estimate the conditional probability of risk propagation between nodes. The calculation process considers the effectiveness indicators of mitigation measures, such as the proportion of risk propagation actually suppressed after a certain blocking measure is implemented, thereby adjusting the weight parameters of the corresponding edges. Weight adjustments follow the gradient descent principle, gradually correcting based on prediction errors to avoid drastic fluctuations. Simultaneously, node attributes are updated with the mitigation results; for example, if a supplier's risk level drops from "high risk" to "medium," the base risk value of its corresponding node is lowered accordingly. Adjusting edge weight parameters in the network topology involves real-time operations on the graph database. The system identifies edges directly connected to the mitigation nodes using a graph traversal algorithm and reassigns values based on the new propagation intensity data. For indirectly connected edges, sensitivity analysis of simulated propagation paths is used for indirect adjustment. Changes in the topology are not only reflected in weights but also sometimes involve adding or deleting edges. For example, when a previously unknown risk propagation path is discovered during the mitigation process, the system automatically adds the corresponding edge to the graph and initializes its weight.
[0091] Optimizing the risk-oriented audit rule set based on the updated network model is an iterative learning process. The optimization engine analyzes changes in risk transmission patterns after the model update, identifying blind spots or outdated clauses in the original rules. Rule optimization employs rule mining algorithms to extract frequent transmission patterns and critical paths from the updated network structure, transforming them into new audit rules or conditions for modifying existing rules. For example, when the model shows that a minor supplier node suddenly becomes a risk hub, the system generates a new rule: "Monitor related transactions of this supplier." The optimized rule set is validated through A / B testing, first piloted in a small-scale audit task to compare the risk detection rates of the new and old rules. Once confirmed to be effective, it is rolled out nationwide. The system automatically executes a full-process trigger-handle-update cycle every 24 hours to ensure that risk control strategies remain synchronized with the actual risk situation of the project. In one audit, the system detected abnormal fluctuations in experimental equipment usage costs, automatically matched resource reallocation solutions, updated the network model after handling, showing changes in risk transmission paths, and then optimized the rule set to add clauses for checking cross-contamination. This dynamic adaptive mechanism shifts the audit work from static compliance checks to intelligent risk governance.
[0092] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.
[0093] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A risk-oriented audit method for R&D expense allocation, characterized in that, include: Obtain multi-dimensional characteristic data and audit constraints for R&D projects, wherein the multi-dimensional characteristic data includes project phase division data, cost flow data and risk indicator data, and the audit constraints include time window constraints and risk tolerance constraints; Based on the project phase division data and risk tolerance constraints, a risk coupling network model is constructed, and a risk-oriented audit rule set is generated through the risk coupling network model. Based on the cost flow data and risk-oriented audit rule set, an audit path is planned to output an initial audit plan, which includes an audit node sequence and risk monitoring thresholds. Using the time window constraint as the optimization objective, time-series optimization processing is performed on the audit node sequence to obtain a dynamic audit scheduling scheme. Based on the dynamic audit scheduling scheme, risk transmission analysis is performed to generate a risk prevention and control strategy set, which includes multi-level risk handling schemes and emergency response mechanisms. During the audit of R&D expense allocation, the execution of the risk control strategy set is triggered based on the risk monitoring threshold.
2. The risk-oriented audit method for R&D expense allocation as described in claim 1, characterized in that, Based on the project phase division data and risk tolerance constraints, a risk-coupled network model is constructed, including: The project phase division data is subjected to phase feature extraction to obtain the key activity features and resource consumption features of each phase. The key activity features are labeled with risk levels based on the risk tolerance constraints to form a weighted set of stage risk features; Construct a multi-layer network topology containing the aforementioned stage risk feature set, where network nodes represent R&D activities and edge weights represent the risk transmission intensity; The risk transmission path is calculated using the multi-layered network topology to generate the risk-coupled network model.
3. The risk-oriented audit method for R&D expense allocation as described in claim 2, characterized in that, Audit path planning is performed based on the aforementioned cost flow data and risk-oriented audit rule set, including: The cost flow data is clustered by project stage to obtain cost distribution hotspots. Based on the risk-oriented audit rule set, risk matching is performed on the cost distribution hotspot areas to identify key audit areas; A graph traversal algorithm is used to search for the optimal audit path in the critical audit area, forming the audit node sequence. The risk value of each audit node is calculated based on the risk transmission strength of the risk coupling network model, and the risk monitoring threshold is set.
4. The risk-oriented audit method for R&D expense allocation as described in claim 3, characterized in that, Perform timing optimization processing on the audit node sequence, including: Establish an audit task timing constraint model, which includes task execution duration constraints and task dependency constraints; Construct an audit scheduling optimization objective function based on the aforementioned time window constraints; A heuristic search algorithm is used to optimize the audit scheduling optimization objective function while satisfying the aforementioned time-series constraint model. The output includes the dynamic audit scheduling scheme, which contains the task execution sequence and resource allocation scheme.
5. The risk-oriented audit method for R&D expense allocation as described in claim 4, characterized in that, Risk transmission analysis is performed based on the aforementioned dynamic audit scheduling scheme, including: The risk status of the current audit node is marked in the risk-coupled network model; Simulate the process of risk propagation along network edges to predict the scope and duration of risk impact; Generate a risk handling priority list based on the node attributes along the risk transmission path; The multi-level risk management plan is constructed by combining the risk management priority list and resource allocation scheme.
6. The risk-oriented audit method for R&D expense allocation as described in claim 5, characterized in that, The generation of the emergency response mechanism includes: Monitor abnormal fluctuation signals in the risk coupling network model. When the fluctuation amplitude exceeds a preset threshold, initiate the emergency response process and match a pre-stored emergency handling template based on the abnormal fluctuation characteristics. The resource allocation strategy in the dynamic audit scheduling scheme is dynamically adjusted.
7. The risk-oriented audit method for R&D expense allocation as described in claim 6, characterized in that, The multi-level risk management plan includes: The Level 1 response plan takes measures to block the direct source of risk; The secondary response plan implements mitigation strategies for the indirect risk impact; The Level 3 response plan establishes a risk isolation buffer zone; Information sharing and data coordination should be maintained between response plans at all levels.
8. The risk-oriented audit method for R&D expense allocation as described in claim 7, characterized in that, The execution of the aforementioned risk control strategy set is triggered by: Risk indicator data of audit nodes are collected in real time, and the collected data is compared and analyzed with the risk monitoring threshold. When an abnormal risk indicator is detected, the corresponding risk handling plan is automatically matched. Record the risk management process and update the risk coupling network model.
9. The risk-oriented audit method for R&D expense allocation as described in claim 8, characterized in that, Updating the risk-coupled network model includes: Collect state change data during the risk management process, recalculate the risk transmission strength of network nodes, and adjust the edge weight parameters in the network topology. The risk-oriented audit rule set is optimized based on the updated network model.
10. A risk-oriented audit system for R&D expense allocation, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the risk-oriented audit method for R&D expense allocation as described in any one of claims 1 to 9.
Citation Information
Patent Citations
Audit plan generation method and device, equipment, storage medium and program product
CN119250282A
Data governance risk early warning method based on big data mining
CN120066862A