Risk assessment method and related equipment

By adopting a risk assessment method with clear data format in enterprise risk control scenarios and storing target risk samples in plain text, the problem of low processing efficiency caused by diverse data formats is solved, and efficient data processing and reuse are achieved, thereby improving the transparency of risk control data and resource utilization.

CN120996548APending Publication Date: 2025-11-21HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410628503.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-05-20
Publication Date
2025-11-21

AI Technical Summary

Technical Problem

In enterprise risk control scenarios, due to numerous business processes and long data links, the data generated by various risk assessment models are in diverse formats, resulting in low data processing efficiency and difficulty in sharing and processing.

Method used

A risk assessment method based on clear data format is adopted. Target risk samples are stored in plain text and data processing is performed using these samples, enabling flexible application and reuse of data and reducing waste of storage and processing resources.

Benefits of technology

It improves data processing efficiency in risk assessment scenarios, simplifies data processing procedures, enhances data transparency and reusability, and reduces resource waste.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120996548A_ABST
    Figure CN120996548A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a risk assessment method, and the method comprises the steps: obtaining a target risk sample according to a first data object or a first risk index when carrying out the risk assessment of a first risk, and carrying out the risk assessment based on the target risk sample. The data form of the target risk sample is clear and is specifically used for recording the risk result of the first data object about the first risk index. Therefore, the data processing in the risk assessment process can be realized based on the clear and fixed data form in the target risk sample, so that the data use is facilitated, and the data processing efficiency in the risk assessment scene is improved. Besides, the data form of the risk sample can be flexibly applied to various risk assessment scenes, so that the data granularity and the applicable scene in the data form of the risk sample are clear, and the universality is high.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of business processing technology, specifically to a risk assessment method and related equipment. Background Technology

[0002] In actual business management, companies often need to conduct risk assessments based on business data in order to control risks.

[0003] Currently, in scenarios such as enterprise risk control, due to numerous business processes and long data links, it is usually necessary to build different risk assessment models for different business areas. The data generated by each risk assessment model has a variety of formats, making it difficult to share data and making data processing difficult. This results in a long risk assessment process and low data processing efficiency. Summary of the Invention

[0004] This application provides a risk assessment method that enables data processing during the risk assessment process based on relatively clear data formats, thereby facilitating data use and improving data processing efficiency in risk assessment scenarios. This application also provides corresponding apparatus, devices, computer-readable storage media, and computer program products.

[0005] The first aspect of this application provides a risk assessment method, the method comprising: obtaining a first assessment instruction, the first assessment instruction being used to instruct a risk assessment of a first risk; obtaining a target risk sample based on a first data object or a first risk indicator, the target risk sample being used to record the risk result of the first data object with respect to the first risk indicator, the first risk being related to the first data object and the first risk indicator; and obtaining a first assessment result of the first risk based on the target risk sample.

[0006] In the first aspect, when conducting a risk assessment of the first risk, a target risk sample can be obtained based on the first data object or the first risk indicator, and the risk assessment can be performed based on the target risk sample. The data format of this target risk sample is relatively clear, specifically used to record the risk results of the first data object regarding the first risk indicator. Therefore, data processing in the risk assessment process can be achieved based on the relatively clear and fixed data format in the target risk sample, thereby facilitating data use and improving data processing efficiency in risk assessment scenarios.

[0007] Furthermore, since risk assessment can be conducted based on data objects and risk indicators in various risk assessment scenarios, the risk sample data format can be flexibly applied to a variety of risk assessment scenarios. Therefore, the data granularity and applicable scenarios in the risk sample data format are relatively clear, and its versatility is strong.

[0008] In one possible implementation of the first aspect, the target risk sample is stored in plaintext.

[0009] In this possible implementation, since the data format and definition of the risk samples are relatively reasonable and clear, the data content and attribute fields in the risk samples can be stored in plaintext instead of in non-plaintext fields. This eliminates the need for escaping when using risk samples for risk assessment, thereby improving data processing efficiency.

[0010] Furthermore, each time a new risk sample is generated during a risk assessment, the new risk sample can be stored in plaintext in the computing device cluster, thereby enabling it to be reused in other subsequent risk assessment scenarios. This effectively improves the assessment efficiency of subsequent risk assessment scenarios and reduces the waste of storage and processing resources.

[0011] In one possible implementation of the first aspect, the method further includes: obtaining a second assessment instruction, which instructs a risk assessment of a second risk, the second risk being different from the first risk; if, according to the second assessment instruction, it is determined that the second risk is related to a first data object and a first risk indicator, then obtaining a stored target risk sample; and obtaining a second assessment result of the second risk based on the target risk sample.

[0012] In this possible implementation, when assessing the second risk, if it is determined that the second risk is related to the first data object and the first risk indicator, since the target risk sample is stored in plaintext, the stored target risk sample can be retrieved through the first data object or the first risk indicator. This allows for the acquisition of the stored target risk sample, and based on the target risk sample, a second assessment result for the second risk can be obtained. Therefore, the target risk sample can be reused in the risk assessment scenario for the second risk, effectively improving the assessment efficiency of various risk assessment scenarios and reducing the waste of storage and processing resources.

[0013] In one possible implementation of the first aspect, obtaining a target risk sample based on a first data object or a first risk indicator includes: determining a first data object related to the first risk and / or a first risk indicator related to the first risk; matching the first data object with a data object recorded in each of at least one risk sample, and / or matching the first risk indicator with a risk indicator recorded in each of at least one risk sample, wherein a risk sample is used to record the risk outcome of the data object with respect to the risk indicator; and determining the target risk sample based on the matching result.

[0014] In this possible implementation, a target risk sample can be queried from at least one risk sample based on a first data object and / or a first risk indicator. As can be seen, the risk sample can be reused in multiple risk assessment scenarios, effectively improving the assessment efficiency of multiple risk assessment scenarios and reducing the waste of storage and processing resources.

[0015] In one possible implementation of the first aspect, obtaining a target risk sample based on a first data object or a first risk indicator includes: identifying a first data object related to the first risk; acquiring data to be processed, the data to be processed including business data of the first data object; and processing the data to be processed according to specified rules to generate the target risk sample.

[0016] In this possible implementation, the specified rule can be regarded as the calculation rule of the first risk indicator. Therefore, the data to be processed can be processed by specifying the rule to obtain the risk result of the first data object with respect to the first risk indicator, that is, to generate the target risk sample.

[0017] In one possible implementation of the first aspect, the specified rules include a first rule and a second rule; processing the data to be processed according to the specified rules to generate a target risk sample includes: processing the data to be processed according to the first rule to generate indicator data about intermediate indicators; and processing the indicator data of intermediate indicators according to the second rule to generate a target risk sample.

[0018] In this possible implementation, considering that the specified rules may be complex, or that information on intermediate indicators that users need to know may be generated during the process of processing the data based on the specified rules, or that the intermediate indicators can be reused, in order to improve data processing efficiency, facilitate users' understanding of the data status of intermediate indicators, and facilitate the reuse of relevant intermediate indicator data, the indicator data of intermediate indicators can be generated and stored.

[0019] In one possible implementation of the first aspect, after generating indicator data about intermediate indicators, the method further includes: outputting the indicator data of intermediate indicators.

[0020] In this possible implementation, intermediate indicator data can be output to the user based on the user's needs.

[0021] In one possible implementation of the first aspect, the data to be processed is stored through a first data layer, the target risk sample is stored through a second data layer, the first assessment result is stored through a third data layer, the data in the first data layer can be transmitted to the second data layer, and the data in the second data layer can be transmitted to the third data layer.

[0022] In this possible implementation, to better process data at each stage of risk assessment, data layering can be implemented for clearer data management. Specifically, this possible implementation proposes a clear data layering architecture, defining the data stored in each data layer and its related functions. This allows for layered management of data in risk assessment scenarios, facilitating the effective management and accumulation of valid data at each data layer through its corresponding data management modules. For example, the business data of data objects can be stored in the bottom first data layer, while risk samples can be stored and managed through the middle second data layer. This allows for the flexible application of risk samples from the second data layer in the upper third data layer for risk assessment in various risk assessment scenarios, making upper-layer data processing and assembly more flexible.

[0023] In one possible implementation of the first aspect, the target risk sample further includes a first dimension; obtaining a first assessment result of the first risk based on the target risk sample includes: obtaining first risk measurement data based on the target risk sample, the first risk measurement data being used to record the risk measurement result under the first dimension, the risk measurement result being used to describe the degree of risk; obtaining a first assessment result of the first risk based on the first risk measurement data.

[0024] In this possible implementation, the target risk sample can be risk data at the data object level, while the first risk measurement data is a higher-level risk information obtained by integrating the target risk sample based on the first dimension.

[0025] This allows for the efficient generation of higher-level detailed tables and / or summary tables, etc., based on the first risk measurement data. For example, since the first risk measurement data has already been summarized based on dimensional information, that is, risk measurement has already been performed based on dimensional information, the summary table in the first assessment results can be obtained quickly and efficiently based on the first risk measurement data.

[0026] A second aspect of this application provides a risk assessment apparatus that functions to implement the method described in the first aspect or any possible implementation of the first aspect. This function can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the described function, such as an interface module and a processing module.

[0027] A third aspect of this application provides a computing device cluster including at least one computing device, the at least one computing device including a processor and a memory, the memory of the at least one computing device storing computer-executable instructions that can run on the processor, and when the computer-executable instructions are executed by the processor, the processor executes a method as described in the first aspect or any possible implementation of the first aspect.

[0028] The fourth aspect of this application provides a computer-readable storage medium storing one or more computer-executable instructions, wherein when the computer-executable instructions are executed by a processor, the processor performs a method as described in the first aspect or any possible implementation thereof.

[0029] The fifth aspect of this application provides a computer program product that stores one or more computer-executable instructions, wherein when the computer-executable instructions are executed by a processor, the processor executes a method as described in the first aspect or any possible implementation thereof.

[0030] A sixth aspect of this application provides a chip system including a processor for supporting the processor in implementing the functions involved in the first aspect or any possible implementation thereof. In one possible design, the chip system may further include a memory for storing necessary program instructions and data. This chip system may be composed of chips or may include chips and other discrete devices.

[0031] The technical effects of the second to sixth aspects or any of their possible implementations can be found in the first aspect or the technical effects of its related possible implementations, and will not be repeated here. Attached Figure Description

[0032] Figure 1 This is a schematic diagram of a traditional risk control process provided in the embodiments of this application;

[0033] Figure 2 This is an exemplary schematic diagram of the system framework provided in the embodiments of this application;

[0034] Figure 3 This is a schematic diagram of an embodiment of the risk assessment method provided in this application;

[0035] Figure 4 This is an exemplary schematic diagram of data in the risk assessment process provided in the embodiments of this application;

[0036] Figure 5 This is another exemplary schematic diagram of data in the risk assessment process provided in the embodiments of this application;

[0037] Figure 6This is a schematic diagram illustrating an exemplary scenario of risk sample reuse provided in the embodiments of this application;

[0038] Figure 7 This is a schematic diagram of an embodiment of the risk assessment device provided in this application;

[0039] Figure 8 This is a schematic diagram of the structure of a computing device provided in an embodiment of this application;

[0040] Figure 9 This is a schematic diagram of a computing device cluster provided in an embodiment of this application;

[0041] Figure 10 This is a schematic diagram of a computing device cluster provided in an embodiment of this application. Detailed Implementation

[0042] The embodiments of this application are described below with reference to the accompanying drawings. The terminology used in the implementation section of this application is for explaining specific embodiments only and is not intended to limit the scope of this application.

[0043] As will be known to those skilled in the art, with the development of technology and the emergence of new scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0044] In this application, "at least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. The terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate; this is merely a way of distinguishing objects with the same attributes in the embodiments of this application. Furthermore, the terms “comprising” and “having”, and any variations thereof, are intended to cover non-exclusive inclusion, such that a process, method, system, product, or apparatus that comprises a series of units is not necessarily limited to those units, but may include other units not expressly listed or inherent to those processes, methods, products, or apparatus.

[0045] 1. Risk Assessment

[0046] Risk assessment refers to the quantitative evaluation of the potential impact or loss caused by an event or thing.

[0047] Risk assessment can be an evaluation of the threats, vulnerabilities, impacts, and the potential risks arising from the combined effect of information assets (i.e., the set of information contained in data objects) to information assets.

[0048] 2. Data Objects

[0049] Data objects can have types, attributes, and attribute content.

[0050] In different business scenarios, the specific type of data object can be varied.

[0051] For example, data objects can specifically be business, entities, things, events, services, locations, etc.

[0052] For example, in a company's data analysis system, business data can be stored, with each piece of business data describing a specific business transaction. Specifically, business data A might be detailed data of a contract, in which case the data object of business data A is the contract; business data B might be detailed data of a project, in which case the data object of business data B is the project; and business data C might be business information of a service point, in which case the data object of business data C is the service point.

[0053] As can be seen, the type and specific content of data objects can be determined according to the actual scenario.

[0054] 3. Key Risk Index (KRI)

[0055] Key risk indicators are statistical indicators that represent changes in a specific risk area and can be monitored regularly. They are commonly used risk indicators in risk assessment scenarios.

[0056] In actual business management, companies often need to conduct risk analysis based on business data in order to control risks.

[0057] Currently, the commonly used risk control processes in enterprises are as follows: Figure 1 As shown.

[0058] This approach employs a chimney-style design, and will be illustrated using risk A and risk B as examples.

[0059] Users retrieve data A to be processed from the data integration area based on the risk A to be assessed, and process the data A according to the corresponding key risk indicator (KRI) A and data model A to obtain risk results A of various types. To facilitate the storage of risk results A with diverse data types and structures, risk results are currently typically stored using non-plaintext fields such as the general C field.

[0060] In this context, the "general C field" refers to the attribute fields (such as data object, KRI, risk outcome, dimension, occupation, gender, and other business attributes) of rows or columns in the table storing the risk results of risk A. These attributes are described using general fields like C1, C2, and C3, without specifying the specific business attributes. These general C fields are non-plaintext fields. This allows for the unified storage of data from various business types using a single, generic table format. However, because the business attributes corresponding to rows or columns are only recorded as general fields like C1, C2, and C3, simply consulting this table does not reveal the specific attributes of the data described in each row or column. For example, it's unclear whether a row describes a data object or a KRI, resulting in opaque attribute information for the data recorded in the table. Therefore, after obtaining the table containing the risk results of risk A, it is necessary to query the corresponding escape table based on other information related to the table or information about risk A in order to determine the attribute fields of the rows or columns of the table, thereby obtaining the complete information of the table, and obtaining risk assessment results such as detailed tables and summary tables of risk A based on the table.

[0061] As can be seen, because the attribute fields of the rows or columns in the table storing the risk results of risk A are non-plaintext fields, the attribute information of the data recorded in the table is opaque. Therefore, when assessing risk B, the risk results of risk A cannot be reused through this table; instead, the entire risk assessment process for risk B must be executed. Thus, in traditional risk assessment methods, personalized data processing is required for each risk assessment scenario. This data processing process is relatively complex (e.g., it requires storing data in non-plaintext fields and then escaping them), resulting in low data processing efficiency.

[0062] Based on this, the embodiments of this application provide a risk assessment method that can realize data processing in the risk assessment process based on relatively clear data, thereby facilitating data use and improving data processing efficiency in risk assessment scenarios.

[0063] The method described in this application embodiment can be applied to a computing device cluster, which may include one or more computing devices.

[0064] The type of computing device is not limited here. For example, any computing device can be a terminal device, a server, a container, or a virtual machine, etc.

[0065] There are no restrictions on the type of terminal device.

[0066] For example, the terminal device can be one or more of the following: mobile phone, tablet, computer with wireless transceiver function, virtual reality (VR) terminal, augmented reality (AR) terminal, terminal in industrial control, terminal in self-driving, terminal in remote medical care, terminal in smart grid, terminal in transportation safety, terminal in smart city, terminal in smart home, terminal in Internet of Things (IoT), wearable device, robot, etc.

[0067] In the computing device cluster of this application embodiment, a data analysis system may be deployed to implement the risk assessment method of this application embodiment through the data analysis system.

[0068] In some examples, the data analysis system's functions include, but are not limited to, risk assessment; for example, it may also include functions such as operations management and other financial management functions.

[0069] like Figure 2 In the example shown, a user can send a risk assessment instruction to the data analysis system as needed, instructing the system to use the risk assessment method provided in this application embodiment to assess risks in various business scenarios and return the risk assessment results to the user.

[0070] In this application embodiment, the user can be understood as an individual, enterprise, or organization, or as an electronic device such as a client, account, network address, or subject represented by other forms of identification. The user's identification and specific form can be various.

[0071] The type of risk to be assessed can be determined based on the specific application scenario, and there can be many different situations, which are not limited here.

[0072] For example, in one scenario, the risk assessment could be an assessment of financial risks based on financial data in a financial context; in an operational context, the risk assessment could be an assessment of operational risks based on operational data; and in an information security context, the risk assessment could be a risk assessment based on information security data, that is, an assessment of information security risks in a specific network scenario.

[0073] Based on the aforementioned cluster of computing devices, such as Figure 3 As shown, the risk assessment method may include steps 301-303.

[0074] Step 301: Obtain the first evaluation instruction.

[0075] The first assessment instruction is used to instruct a risk assessment to be conducted on the first risk.

[0076] In this embodiment of the application, the first assessment instruction may be transmitted by the user to the computing device cluster through other devices such as client devices, or it may be collected by the computing device cluster through a web page or other applications, or it may be generated by the computing device cluster. For example, the computing device cluster may periodically trigger risk assessment operations.

[0077] The specific type and content of this first risk are not limited here.

[0078] For example, the type of the first risk can be financial risk. For instance, the specific content of the first risk can be one or more of the following: non-performing asset risk, credit risk, and debt default risk. It can also be a more granular risk, such as the risk of non-compliant income or the risk of untimely invoicing.

[0079] Step 302: Obtain the target risk sample based on the first data object or the first risk indicator.

[0080] The target risk sample is used to record the risk outcome of the first data object with respect to the first risk indicator. The first risk is related to the first data object and the first risk indicator.

[0081] In this embodiment of the application, risk sample data can be used to store risk outcome data for risk assessment.

[0082] In this risk sample, the data storage format is relatively fixed; specifically, it records the risk outcomes of data objects related to risk indicators. Different risk samples may contain different data objects and / or risk indicators.

[0083] As can be seen, the data granularity in each risk sample is clear, making it easy to determine the applicable risk assessment scenario for each risk sample and convenient to use.

[0084] In this way, when conducting risk assessments, the required risk samples in the current risk assessment scenario can be determined based on the corresponding data objects.

[0085] The following section uses the first risk and target risk samples as examples to illustrate the specific content of the risk samples and the corresponding acquisition methods.

[0086] In this embodiment of the application, the target risk sample is used to record the risk results of the first data object with respect to the first risk indicator.

[0087] The specific type of the first data object can be varied. In different risk assessment scenarios, the type of the first data object can take many forms. For example, in an enterprise risk assessment scenario, the first data object can include one or more of the following: contracts, projects, invoices, inventory, purchase orders, sites, etc.

[0088] The first data object may include one or more data objects. For example, the first data object may be a contract, or the first data object may be a project, or the first data object may include both a contract and a project.

[0089] The first data object in the target risk sample can be described by the identifier of the first data object and / or the identifier of the type of the first data object.

[0090] like Figure 4 In the example shown, one or more risk samples can be recorded using a risk sample table.

[0091] Each risk sample is stored row by row in the risk sample table.

[0092] Wherein, if the first row of the risk sample table is used to record the target risk sample, the first data object in the target risk sample includes contracts and projects, specifically, the first data object includes Contract 1 and Project 1. The first data object can be uniquely identified by a UCCID field, which can be obtained by calculating the specific number of all first data objects (e.g., Contract 1 and Project 1) using a hash algorithm.

[0093] Furthermore, the target risk sample may include an identifier of the type of the first data object. For example, such as... Figure 4 In the example shown, the type of the first data object in the target risk sample is identified as T002, and the type of the data object indicated by the number T002 is "contract + project". In this example, the type of the data object could also be indicated by a number such as T001 as "contract" and T003 as "project", etc.

[0094] The first risk indicator may include one or more key risk indicators.

[0095] In different risk assessment scenarios, the primary risk indicator can take many forms. For example, the primary risk indicator can be one or more of the following: annual gross profit margin, sales profit, cost ratio, etc.

[0096] In the target risk sample, the primary risk indicator can be uniquely identified through corresponding coding or other methods.

[0097] like Figure 4 In the example shown, the first row of the risk sample table is used to record the target risk sample, and the first risk indicator in the target risk sample is the key risk indicator coded as RRI002.

[0098] In this embodiment of the application, the first risk is related to the first data object and the first risk indicator.

[0099] Generally speaking, any risk to be assessed can be evaluated based on the risk outcomes of one or more data objects under multiple risk indicators.

[0100] For example, the risk to be assessed might be the risk of untimely business delivery. This risk can be assessed based on the risk indicators of multiple risk indicators, such as risk indicator 1 (untimely business approval), risk indicator 2 (untimely business contract signing), and risk indicator 3 (untimely business contract upload). The data objects involved in different risk indicators can be the same or different. For example, risk indicator 1 might correspond to projects, risk indicator 2 to contracts, and risk indicator 3 to contracts. Therefore, the correspondence between risk indicators and data objects can have various forms.

[0101] After receiving the first assessment instruction, a first data object or a first risk indicator related to the first risk can be identified, and a target risk sample can be obtained based on the first data object or the first risk indicator.

[0102] Based on the different correspondences between any two of the risks to be assessed, data objects, and risk indicators, obtaining a target risk sample according to the first data object or the first risk indicator may include any of the following situations:

[0103] 1) If there is a one-to-one correspondence between data objects and risk indicators, the target risk sample can be obtained based on the first data object corresponding to the first risk, or the target risk sample can be obtained based on the first risk indicator corresponding to the first risk.

[0104] In this example, since there is a one-to-one correspondence between data objects and risk indicators, that is, different risk indicators correspond to different data objects, the target risk sample can be uniquely determined based on either the first data object or the first risk indicator.

[0105] 2) If the relationship between the data object and the risk indicator is not one-to-one, but many-to-many or one-to-many, then the target risk sample can be obtained based on the first data object and the first risk indicator.

[0106] In this example, different risk indicators may correspond to the same data object, but the calculation methods for the data object may differ.

[0107] At this point, the target risk sample can only be uniquely determined based on the first data object and the first risk indicator.

[0108] There are several ways to determine the first data object or the first risk indicator related to the first risk.

[0109] In some examples, a pre-built table can be constructed, which can record the data objects associated with each risk and the risk indicators.

[0110] For example, the specified table can record data objects associated with the risk "non-compliant revenue" including both contracts and projects, and can also record data objects associated with the risk "insufficient inventory" including purchase orders.

[0111] Thus, if the primary risk is non-compliant revenue, then by querying the specified table, it can be determined that the primary data object may include contracts and projects.

[0112] In other examples, users can input the first data object or first risk indicator associated with the first risk, so that users can determine the first data object or first risk indicator that needs to be assessed based on the actual scenario requirements.

[0113] In this embodiment of the application, the risk result of the first data object in the target risk sample with respect to the first risk indicator can be information such as the value under the first risk indicator obtained by processing the data of the first data object.

[0114] It is evident that there are multiple possible ways to measure risk outcomes.

[0115] For example, such as Figure 4 In the example shown, risk outcomes can be measured and statistically analyzed on scales such as quantity, amount, proportion, threshold, level, and weight.

[0116] And in Figure 4 In the example shown, the risk results in the target risk sample are used to describe the number of risks present in the first data object "Contract + Project" regarding the first key indicator KRI02.

[0117] In some examples, the target risk sample may include the risk outcome of the first data object with respect to the first risk indicator, and may also include dimensional information, but not information such as the attributes of the first data object.

[0118] In real-world scenarios, different data objects each have their own unique attribute information. For example, the attributes of a contract data object may include one or more of the following: information about the contracting parties, rights, obligations, and liabilities for breach of contract; while the attributes of an order data object may include one or more of the following: ordered goods, price, customer information, and order status. It is evident that the types and content of attribute information for different data objects often vary significantly. In traditional technologies, to enable tables to store attribute information for different data objects across various business scenarios, the attribute fields of the rows or columns in the table typically use only common non-plaintext fields (such as common C1-CN fields). Then, during the subsequent generation of detailed or summary tables, it is necessary to escape the attribute fields of the rows or columns in the table to obtain the plaintext attribute field information.

[0119] In this example, the target risk sample does not need to store diverse information such as the attributes of the first data object. The row and column attribute fields of the target risk sample are clear, for example, Figure 3 In the example shown, the attribute fields in the table storing risk samples are fixed, clear, and generic, including KRI, risk object, and risk outcome, and may also include dimensions. Therefore, this table format can be used to store risk samples for various risk scenarios without using generic non-plaintext fields such as C fields. For example, it is unnecessary to store the KRI, risk object, and risk outcome attribute fields in the table as C1, C2, and C3. Thus, the target risk sample can be stored in plaintext; that is, the attribute fields of the rows and columns of the table storing the target risk sample, as well as the content of the rows and columns, are all stored in plaintext using conventional data storage methods, without the need for generic non-plaintext fields.

[0120] In this way, in actual risk assessment scenarios, such as assessing the first risk, at least one risk sample stored in plaintext can be matched efficiently and conveniently, enabling the reuse of historically stored risk samples. This eliminates the need to repeatedly generate the same risk samples in different risk assessment scenarios, thereby improving the efficiency of risk assessment.

[0121] In this embodiment, the method of obtaining the target risk sample is not limited. For example, the target risk sample can be pre-generated and stored in a computing device cluster, and can be queried based on a first data object or a first risk indicator; or, the target risk sample can be generated based on a first data object and a first risk indicator after receiving a first assessment instruction.

[0122] The following provides illustrative examples of two possible methods for obtaining target risk samples.

[0123] 1. Generate a target risk sample based on the first data object and the first risk indicator.

[0124] Specifically, in some embodiments, step 302 includes:

[0125] Identify the first data object related to the first risk;

[0126] Obtain the data to be processed, which includes the business data of the first data object;

[0127] The data to be processed is processed according to the specified rules to generate a target risk sample.

[0128] There are multiple ways to determine the first data object corresponding to the first risk, and no limitation is made here.

[0129] For example, the first risk may correspond to a pre-configured first risk model, which records the first risk indicator and the first data object corresponding to the first risk.

[0130] Alternatively, the user can input the first data object corresponding to the first risk.

[0131] For example, the business data of the first data object may include the factual data of the first data object, such as the detailed data of the first data object.

[0132] The data to be processed may be obtained by the computing device cluster executing the embodiments of this application from other devices such as client devices, or it may be pre-stored in the computing device cluster, or it may be queried from the data pre-stored in the computing device cluster.

[0133] For example, the data to be processed can be the original detailed data about the first data object obtained from the user, or it can be the original detailed data that has been preprocessed, such as noise reduction, deduplication, or other abnormal data processing operations, to obtain the data to be processed.

[0134] After obtaining the data to be processed, it can be processed by specifying rules to obtain the risk result of the first data object with respect to the first risk indicator. The specified rules can be considered as the calculation rules for the first risk indicator.

[0135] For example, the specified rule may include conditions and operations, or it may include an algorithm.

[0136] The specific content of this rule can be pre-configured by the user according to the actual application scenario.

[0137] For example, in one scenario, the first data objects are invoices and contracts. The first risk indicator is untimely invoicing.

[0138] Then you can obtain the data to be processed, which includes the contract table and the invoice table.

[0139] The contract form records the theoretical invoice issuance time, while the invoice form records the actual invoice issuance time.

[0140] According to specified rules, contract tables and invoice tables can be linked to calculate the time interval between the actual invoicing time and the theoretical invoicing time, thereby obtaining a risk outcome regarding untimely invoicing. This risk outcome can record the number of invoices for which the time interval between the actual and theoretical invoicing times exceeds a specified time threshold, serving as the risk result.

[0141] As can be seen, since the specified rule is the calculation rule for the first risk indicator, after obtaining the data to be processed, the risk result of the first data object with respect to the first risk indicator can be inferred according to the specified rule, thereby generating the target risk sample.

[0142] Furthermore, in some embodiments, the specified rules include a first rule and a second rule;

[0143] The data to be processed is processed according to specified rules to generate a target risk sample, including:

[0144] The data to be processed is processed according to the first rule to generate indicator data about intermediate indicators;

[0145] The intermediate indicator data are processed according to the second rule to generate a target risk sample.

[0146] In this embodiment of the application, considering that the specified rules may be complex, or that information on intermediate indicators that users need to know may be generated during the process of processing the data to be processed based on the specified rules, or that the intermediate indicators can be reused, in order to improve data processing efficiency, facilitate users to understand the data status of intermediate indicators, and facilitate the reuse of relevant intermediate indicator data, the indicator data of intermediate indicators can be generated and stored.

[0147] In the actual processing steps, the specified rules can be divided into the first rule and the second rule.

[0148] Among these, the data to be processed can be processed according to the first rule to generate indicator data about intermediate indicators.

[0149] For example, such as Figure 5In the example shown, intermediate indicators can be pre-configured through an intermediate indicator definition table. Specifically, the intermediate indicator's number, name, and other identifiers can be configured in the intermediate indicator definition table, and the relevant attribute information of the intermediate indicator can also be configured.

[0150] For example, Figure 5 In the example shown, the intermediate indicator definition table can be configured with the indicator description, indicator period, corresponding data object category (e.g., business data object), corresponding data object type (e.g., project, contract), and indicator-related rules (e.g., first rule).

[0151] Figure 5 In the example shown, if the data to be processed is processed based on the first rule, the indicator data that needs to be generated and stored as intermediate indicators can be determined from the intermediate indicator definition table. Then, the data to be processed can be processed according to the first rule to obtain the intermediate indicator table.

[0152] This intermediate indicator table can record indicator data about intermediate indicators generated based on the data to be processed and the first rule.

[0153] Specifically, Figure 5 In the example shown, information such as the intermediate indicator number, the corresponding batch of data to be processed, the accounting period, the type of the related first data object, the number of the first data object, and the specific value of the intermediate indicator can be recorded.

[0154] Then, based on the indicator data of the intermediate indicators in the intermediate indicator table, and according to the second rule, the risk result of the first data object with respect to the first risk indicator can be further calculated to generate the target risk sample in the risk sample table.

[0155] exist Figure 5 In the example shown, risk samples can also be filtered based on batch.

[0156] For example, data collected at different time periods can be considered as different batches of data to be processed.

[0157] By processing the different batches of data according to the specified rules, we can obtain the intermediate indicator tables and candidate risk samples corresponding to each batch.

[0158] Then, from multiple batches of candidate risk samples, the candidate risk sample corresponding to the largest batch (i.e., the largest data volume) of unprocessed data can be selected as the target risk sample, and the intermediate indicator table corresponding to the largest batch of unprocessed data can be selected as the output intermediate indicator table.

[0159] In this way, since the indicator data of the intermediate indicator has been stored in the intermediate indicator table, users can easily view it. Furthermore, the indicator data of the intermediate indicator can also be used to calculate the risk results in other risk samples besides the target risk sample.

[0160] In some embodiments, after generating indicator data about intermediate indicators, the method further includes:

[0161] Output intermediate indicator data.

[0162] There are several ways to output this indicator data. For example, an intermediate indicator table containing intermediate indicator data can be displayed through the display device of the computing device cluster or an external display device of the computing device cluster. This intermediate indicator table can be displayed as an independent table or summarized into a table such as a detail table for unified display. Alternatively, the intermediate indicator data can be sent to other devices (such as client devices) through the computing device cluster.

[0163] 2. Query the target risk sample from at least one risk sample.

[0164] Specifically, in some embodiments, step 302 includes:

[0165] Identify the first data object and / or the first risk indicator related to the first risk;

[0166] Match the first data object with the data object recorded in each of the at least one risk samples, and / or match the first risk indicator with the risk indicator recorded in each of the at least one risk samples, wherein a risk sample is used to record the risk outcome of the data object with respect to the risk indicator;

[0167] The target risk sample is determined based on the matching results.

[0168] In this embodiment of the application, at least one risk sample may be stored in the computing device cluster.

[0169] The at least one risk sample may include historical risk samples generated in historical risk assessment scenarios, risk samples generated by user instructions, or risk samples automatically generated by the computing device cluster according to preset configurations, etc.

[0170] The risk sample may include the identifier of the corresponding risk object, the identifier of the corresponding risk object type, and the identifier of the corresponding risk indicator, so that after receiving the first assessment instruction and determining the first risk object and / or the first risk indicator of the first risk, the computing device cluster can determine the target risk sample from at least one risk sample based on the first data object and / or the first risk indicator. A risk sample is used to record the risk result of a data object with respect to the risk indicator. Different risk samples correspond to different data objects, or different risk samples correspond to different risk indicators.

[0171] Among these, the methods for matching risk samples can vary depending on the different correspondences between data objects and risk indicators.

[0172] In one example, where there is a one-to-one correspondence between data objects and risk indicators, the target risk sample can be determined by matching the first data object with the data object of at least one risk sample record, or by matching the first risk indicator with the risk indicator of at least one risk sample record. In this example, a risk sample whose recorded data object matches the first data object can be used as the target risk sample, or a risk sample whose recorded risk indicator matches the first risk indicator can be used as the target risk sample.

[0173] In another example, different risk indicators may correspond to the same data object, but different risk indicators may have different processing rules for the same data object. Therefore, it is necessary to match the first data object with the data objects recorded in at least one risk sample record, and to match the first risk indicator with the risk indicators recorded in at least one risk sample record, thus determining the target risk sample from the risk samples. In this example, a risk sample whose recorded data object matches the first data object and whose recorded risk indicator matches the first risk indicator can be used as the target risk sample.

[0174] Step 303: Based on the target risk sample, obtain the first assessment result for the first risk.

[0175] In this embodiment of the application, the data of the target risk sample can be assembled and further processed for risk measurement according to the needs of the actual risk assessment scenario, so as to obtain the first assessment result of the first risk.

[0176] The specific form of the first assessment result is not limited here.

[0177] In one example, the initial assessment result may include a detailed table of the initial risk.

[0178] The detailed table can assemble data based on the target risk sample and dimensional information. For example, the risk results in the target risk sample can be converted from rows to columns in the detailed table. In addition, other columns in the detailed table can include one or more pieces of information such as dimensional information and intermediate indicators.

[0179] In another example, the first assessment result may include a summary table of the first risk.

[0180] This summary table includes risk assessment results summarized according to different dimensions, such as risk amount and number of risks summarized according to different dimensions.

[0181] Based on the target risk sample, detailed tables and / or summary tables in the first assessment results can be generated directly; alternatively, based on the target risk sample, a risk measurement table can be generated, and then based on the risk measurement table, detailed tables and / or summary tables in the first assessment results can be obtained.

[0182] In some embodiments, the target risk sample further includes a first dimension, and step 303 includes:

[0183] Based on the target risk sample, the first risk measurement data is obtained. The first risk measurement data is used to record the risk measurement results under the first dimension. The risk measurement results are used to describe the degree of risk.

[0184] Based on the first risk measurement data, the first assessment result of the first risk is obtained.

[0185] In this embodiment of the application, the first dimension may include a general dimension of the data object, so as to facilitate subsequent aggregation and processing of risk samples based on the dimension.

[0186] In addition, in some examples, the first dimension may also include personalized dimensions determined based on the first risk object, etc.

[0187] The first risk measurement data can be integrated based on dimensions to measure the degree of risk under the first dimension.

[0188] Risk measurement results can take many different forms.

[0189] In some examples, risk measurement results may directly include risk outcomes.

[0190] In other examples, the risk measurement results can describe whether there is risk in the first dimension, as well as the severity of the risk.

[0191] like Figure 4 In the example shown, the first risk measurement data can be stored in a risk measurement data table, where each row of data represents a set of risk measurement data. Figure 4In the example shown, the first dimension includes representative locations. The first risk measurement data is used to describe which representative locations in a certain region have the risks described by the first risk indicator, and to describe the corresponding risk measurement results, specifically including the aggregated risk amount and the number of risks. The degree of risk can also be described by levels, etc.

[0192] It is understandable that the target risk sample can be risk data at the data object level, while the first risk measurement data is a higher-level risk information obtained by integrating the target risk sample based on the first dimension.

[0193] This allows for the efficient generation of higher-level detailed tables and / or summary tables, etc., based on the first risk measurement data. For example, since the first risk measurement data has already been summarized based on dimensional information, that is, risk measurement has already been performed based on dimensional information, the summary table in the first assessment results can be obtained quickly and efficiently based on the first risk measurement data.

[0194] In this embodiment, the first evaluation result can be output. For example, the first evaluation result can be displayed through a display device inside or outside the computing device cluster, or the computing device cluster can send the first evaluation result to the user's client device to instruct the user's client device to display the first evaluation result.

[0195] As can be seen, in this embodiment of the application, when assessing the first risk, a target risk sample can be obtained based on the first data object or the first risk indicator, and the risk assessment can be performed based on the target risk sample. The data format of the target risk sample is relatively clear, specifically used to record the risk results of the first data object regarding the first risk indicator. Therefore, data processing in the risk assessment process can be achieved based on the relatively clear and fixed data format in the target risk sample, thereby facilitating data use and improving data processing efficiency in risk assessment scenarios.

[0196] Furthermore, since risk assessment can be conducted based on data objects and risk indicators in various risk assessment scenarios, the risk sample data format can be flexibly applied to a variety of risk assessment scenarios. Therefore, the data granularity and applicable scenarios in the risk sample data format are relatively clear, and its versatility is strong.

[0197] Furthermore, in this embodiment of the application, since the data format and data definition of the risk samples are relatively reasonable and clear, the data content and attribute fields in the risk samples can be stored in plaintext instead of in non-plaintext fields. In this way, no escaping is required when using risk samples for risk assessment, thereby improving data processing efficiency.

[0198] Furthermore, each time a new risk sample is generated during a risk assessment, the new risk sample can be stored in plaintext in the computing device cluster, thereby enabling it to be reused in other subsequent risk assessment scenarios. This effectively improves the assessment efficiency of subsequent risk assessment scenarios and reduces the waste of storage and processing resources.

[0199] The following example, using a target risk sample, illustrates the reuse of risk samples.

[0200] In some embodiments, after storing the target risk sample, the method further includes:

[0201] Obtain a second assessment instruction, which is used to instruct a risk assessment to be conducted on a second risk, which is different from the first risk;

[0202] If, according to the second assessment instruction, it is determined that the second risk is related to the first data object and the first risk indicator, then the stored target risk sample is obtained;

[0203] Based on the target risk sample, a second assessment result for the second risk is obtained.

[0204] As can be seen, in this embodiment of the application, when assessing the second risk, if it is determined that the second risk is related to the first data object and the first risk indicator, since the target risk sample is stored in plaintext, the stored target risk sample can be queried through the first data object or the first risk indicator, thereby obtaining the stored target risk sample, and obtaining the second assessment result of the second risk based on the target risk sample.

[0205] If there is a one-to-one correspondence between the data object and the risk indicator, the stored target risk sample can be retrieved based on either the first data object or the first risk indicator. If different risk indicators correspond to the same data object, the stored target risk sample can be retrieved by matching the first data object and the first risk sample.

[0206] like Figure 6 The diagram shown illustrates an exemplary scenario for reusing risk samples.

[0207] exist Figure 6 In the example shown, the data objects related to risk A and risk B are both data object A and the related risk indicators are the same. Therefore, the assessment results of risk A (detail table A and summary table A) and the assessment results of risk B (detail table B and summary table B) can both be generated by reusing risk sample A and risk measurement data A generated based on risk sample A.

[0208] As can be seen, the target risk sample stored in plaintext can be conveniently queried based on the first data object and / or the first risk indicator, thereby enabling the reuse of the target risk sample in multiple risk assessment scenarios related to the first data object and the first risk indicator, thus effectively improving the assessment efficiency in multiple risk assessment scenarios and reducing the waste of storage and processing resources.

[0209] In some embodiments, data stratification can be implemented to better process data at each stage of risk assessment, thereby enabling clearer data management.

[0210] In some embodiments, the data layer may include one or more of a first data layer, a second data layer, and a third data layer.

[0211] Specifically, the data to be processed is stored in the first data layer, the target risk sample is stored in the second data layer, the first assessment result is stored in the third data layer, the data in the first data layer can be transmitted to the second data layer, and the data in the second data layer can be transmitted to the third data layer.

[0212] In this embodiment of the application, data layering is the logical division of storage space such as databases to obtain multiple data layers, and different data layers can be managed by their respective data management modules.

[0213] Taking a database as an example, data layering in the database can be achieved through the database schema, thereby creating data management module 1, data management module 2, and data management module 3, and allocating a first data layer to data management module 1, a second data layer to data management module 2, and a third data layer to data management module 3. The hierarchy of the third data layer, second data layer, and first data layer is from top to bottom.

[0214] Each data management module can read data from the assigned data layer and, according to the hierarchical order of the data layers from bottom to top, realize the data transmission between different data layers.

[0215] Specifically, data management module 2 can obtain access to the first data layer through data management module 1 to read data from the first data layer (e.g., querying data to be processed), that is, enabling data from the first data layer (e.g., data to be processed) to be transmitted to the second data layer. Similarly, data management module 3 can obtain access to the second data layer through data management module 2 to read data from the second data layer (e.g., querying risk samples from the second data layer), that is, enabling data from the second data layer (e.g., target risk samples) to be transmitted to the third data layer.

[0216] Below, in conjunction with Figure 4 and Figure 5Examples are provided to illustrate the first data layer, the second data layer, and the third data layer, respectively.

[0217] 1. First data layer:

[0218] The first data layer can be considered as a data integration layer or a probe layer.

[0219] This first data layer can include business data from different data objects. For example, for data objects, it can include factual data about different data objects. For instance, such as... Figure 4 In the example shown, the first data layer may include detailed data for each of the data objects such as orders, contracts, invoices, and inventory.

[0220] As can be seen in this example, the first data layer can be used to implement data integration. Specifically, data acquisition can be performed in the first data layer, and the acquired raw data can also be preprocessed, such as noise reduction, deduplication, or other abnormal data processing operations, in order to obtain the data to be processed and store it.

[0221] 2. Second Data Layer:

[0222] The second data layer can be considered a risk sample layer, used to store at least one risk sample.

[0223] The risk sample may include data objects and the risk results of the data objects with respect to the corresponding risk indicators, and may also include dimensional information, but not information such as the attributes of the data objects.

[0224] In real-world scenarios, different data objects each have their own unique attribute information. For example, the attributes of a contract data object may include one or more of the following: information about the contracting parties, rights, obligations, and liabilities for breach of contract; while the attributes of an order data object may include one or more of the following: ordered goods, price, customer information, and order status. It is evident that the types and content of attribute information for different data objects often vary significantly, typically requiring a more general non-plaintext data structure for storage.

[0225] In this example, the risk sample does not need to store diverse information such as the attributes of the data object. Therefore, the risk sample can be stored in plaintext instead of using more common non-plaintext fields.

[0226] The dimension information can include the common dimensions corresponding to each data object.

[0227] This dimensional information can be obtained from a pre-configured dimension table. For example, in some examples, regions, departments, etc., can be pre-configured in the dimension table as general dimensions. In this case, the risk sample can include general dimensions, as well as personalized dimensions determined according to the risk object.

[0228] like Figure 4 In the example shown, data to be processed can be read from the first data layer to the second data layer to generate risk samples and store them in the second data layer. Different risk samples can be stored in the same risk sample table, where each risk sample can be a row in the risk sample table.

[0229] Figure 5 In the example shown, the second data layer may also include intermediate indicator definition tables and other data such as intermediate indicator tables. These intermediate indicator definition tables and other data are used to generate risk samples. For a detailed description of the intermediate indicator definition tables and other data, please refer to the above-mentioned implementation examples related to intermediate indicators, which will not be repeated here.

[0230] 3. Third Data Layer:

[0231] The third data layer is used to store risk measurement data and risk assessment results such as detailed tables and summary tables.

[0232] For example, such as Figure 4 In the example shown, target risk samples can be read from the second data layer to the third data layer, thereby generating risk measurement data based on the target risk samples. The risk measurement data can be reused in risk assessment scenarios of risk A, risk B, and risk C to obtain and output detailed table A and summary table A for risk A, detailed table B and summary table B for risk B, and detailed table C and summary table C for risk C.

[0233] For example, detailed table A and summary table A, detailed table B and summary table B for risk B, and detailed table C and summary table C for risk C can be displayed through internal or external display devices of the computing device cluster. Alternatively, the computing device cluster can send the data of detailed table A and summary table A, detailed table B and summary table B, and detailed table C and summary table C to the user's client device to instruct the user's client device to display detailed table A and summary table A, detailed table B and summary table B, and detailed table C and summary table C.

[0234] As can be seen, this application proposes a clear data layering architecture and defines the data stored in each data layer and its related functions. This allows for layered management of data in risk assessment scenarios, facilitating the effective management and accumulation of valid data at each data layer through its corresponding data management module. For example, the business data of data objects can be stored in the bottom first data layer, while risk samples can be stored and managed through the middle second data layer. This allows for the flexible application of risk samples from the second data layer in the upper third data layer for risk assessment in various risk assessment scenarios, making upper-layer data processing and assembly more flexible.

[0235] The risk assessment method provided by the embodiments of this application has been described above from multiple aspects. The risk assessment device provided by the embodiments of this application will be described below with reference to the accompanying drawings.

[0236] like Figure 7 As shown, this application embodiment provides a risk assessment device 70, which includes:

[0237] Interface module 701 is used to obtain a first assessment instruction, which is used to instruct a risk assessment of the first risk;

[0238] Processing module 702 is used for:

[0239] Based on the first data object or the first risk indicator, a target risk sample is obtained. The target risk sample is used to record the risk results of the first data object with respect to the first risk indicator. The first risk is related to the first data object and the first risk indicator.

[0240] Based on the target risk sample, obtain the first assessment result for the first risk.

[0241] Optionally, the target risk sample is stored in plaintext.

[0242] Optionally, the interface module 701 is used to: obtain a second assessment instruction, which is used to instruct a risk assessment of a second risk, which is different from the first risk;

[0243] Processing module 702 is used for:

[0244] If, according to the second assessment instruction, it is determined that the second risk is related to the first data object and the first risk indicator, then the stored target risk sample is obtained;

[0245] Based on the target risk sample, a second assessment result for the second risk is obtained.

[0246] Optionally, the processing module 702 is used for:

[0247] Identify the first data object and / or the first risk indicator related to the first risk;

[0248] Match the first data object with the data object recorded in each of the at least one risk samples, and / or match the first risk indicator with the risk indicator recorded in each of the at least one risk samples, wherein a risk sample is used to record the risk outcome of the data object with respect to the risk indicator;

[0249] The target risk sample is determined based on the matching results.

[0250] Optionally, the processing module 702 is used for:

[0251] Identify the first data object related to the first risk;

[0252] Obtain the data to be processed, which includes the business data of the first data object;

[0253] The data to be processed is processed according to the specified rules to generate a target risk sample.

[0254] Optionally, the specified rules include a first rule and a second rule; the processing module 702 is used for:

[0255] The data to be processed is processed according to the first rule to generate indicator data about intermediate indicators;

[0256] The intermediate indicator data are processed according to the second rule to generate a target risk sample.

[0257] Optionally, interface module 701 is used to output indicator data of intermediate indicators.

[0258] Optionally, the data to be processed is stored through the first data layer, the target risk sample is stored through the second data layer, and the first assessment result is stored through the third data layer. Data from the first data layer can be transmitted to the second data layer, and data from the second data layer can be transmitted to the third data layer.

[0259] Optionally, the target risk sample may also include a first dimension;

[0260] Processing module 702 is used for:

[0261] Based on the target risk sample, the first risk measurement data is obtained. The first risk measurement data is used to record the risk measurement results under the first dimension. The risk measurement results are used to describe the degree of risk.

[0262] Based on the first risk measurement data, the first assessment result of the first risk is obtained.

[0263] Both the processing module and the interface module can be implemented in software or hardware. For example, the implementation of the processing module will be described below. Similarly, the implementation of the interface module can be referenced from that of the processing module.

[0264] As an example of a software functional unit, a processing module may include code running on a computing instance. A computing instance may include at least one of a physical host (computing device), a virtual machine, or a container. Furthermore, the aforementioned computing instance may be one or more. For example, a processing module may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed within the same region or in different regions. Further, the multiple hosts / virtual machines / containers used to run the code may be distributed within the same availability zone (AZ) or in different AZs, each AZ comprising one or more geographically proximate data centers. Typically, a region may include multiple AZs.

[0265] Similarly, multiple hosts / virtual machines / containers used to run this code can be distributed within the same Virtual Private Cloud (VPC) or across multiple VPCs. Typically, a VPC is set up within a region. Communication between two VPCs within the same region, as well as between VPCs in different regions, requires a communication gateway to be set up within each VPC to enable interconnection between VPCs.

[0266] As an example of a hardware functional unit, a processing module may include at least one computing device, such as a server. Alternatively, a processing module may be implemented using a central processing unit (CPU), an application-specific integrated circuit (ASIC), or a programmable logic device (PLD). The aforementioned PLD may be implemented using a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), a data processing unit (DPU), a neural network processing unit (NPU), a system-on-chip (SoC), an offload card, an accelerator card, or any combination thereof.

[0267] The processing module comprises multiple computing devices that can be distributed within the same region or in different regions. Similarly, the processing module can be distributed within the same Availability Zone (AZ) or in different AZs. Likewise, the processing module can be distributed within the same Virtual Private Cloud (VPC) or multiple VPCs. These computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, GALs, DPUs, NPUs, SoCs, offloading cards, and accelerator cards.

[0268] It should be noted that, in other embodiments, the processing module can be used to execute any step in the risk assessment method, and the interface module can be used to execute any step in the risk assessment method. The steps that the processing module and the interface module are responsible for implementing can be specified as needed. The processing module and the interface module respectively implement different steps in the risk assessment method to realize all the functions of the risk assessment device.

[0269] This application also provides a chip system including a processor and a power supply circuit. The power supply circuit supplies power to the processor, which executes the operational steps corresponding to the risk assessment method. For simplicity, further details are omitted here. The processor can be implemented using a GPU, or it can be implemented using computing devices such as a DPU, NPU, XPU, SoC, offload card, or accelerator card.

[0270] This application also provides a computing device 80. For example... Figure 8 As shown, the computing device 80 includes a bus 802, a processor 804, a memory 806, and a communication interface 808. The processor 804, the memory 806, and the communication interface 808 communicate with each other via the bus 802. The computing device 80 can be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in the computing device 80.

[0271] The 802 bus can be a Peripheral Component Interconnect Express (PCIe) bus, an Extended Industry Standard Architecture (EISA) bus, a Unified Bus (Ubus or UB), a Compute Express Link (CXL) bus, a Cache Coherent Interconnect for Accelerators (CCIX) bus, etc. The Unified Bus is also known as the Lingqu bus. Buses can be divided into address buses, data buses, control buses, etc. For ease of representation, Figure 8 The bus is represented by only one line, but this does not mean that there is only one bus or one type of bus. Bus 804 may include a path for transmitting information between various components of computing device 80 (e.g., memory 806, processor 804, communication interface 808). The unified bus may also be called the Lingqu bus.

[0272] The processor 804 may include any one or more computing devices such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP) or a digital signal processor (DSP), an ASIC, an FPGA, a CPLD, an NPU, a SoC, an offload card, or an accelerator card.

[0273] Memory 806 may include volatile memory, such as random access memory (RAM). Memory 806 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD). Furthermore, memory 806 may also be implemented using storage class memory (SCM), phase change memory (PCM), or other types of storage media.

[0274] It is worth noting that the same type of storage medium can be configured in the same computing device to realize the function of memory 806, or two or more types of storage media can be configured to realize the function of memory 806. This application does not limit this.

[0275] The memory 806 stores executable program code, and the processor 804 executes this executable program code to implement the functions of the aforementioned processing module and interface module, thereby realizing the risk assessment method. That is, the memory 806 stores instructions for executing the risk assessment method.

[0276] The communication interface 803 uses transceiver modules, such as, but not limited to, network interface cards and transceivers, to enable communication between the computing device 80 and other devices or communication networks.

[0277] As one possible implementation, the computing device 80 may also include a chip system, which includes a processor and a power supply circuit. The power supply circuit supplies power to the processor, and the processor executes the operational steps corresponding to the risk assessment method. For simplicity, further details are omitted here. The processor can be implemented using a GPU, or it can be implemented using computing devices or AI chips such as a DPU, NPU, XPU, SoC, offloading card, or accelerator card.

[0278] As one possible implementation, the computing device 80 may include multiple types of processors 804, meaning the computing device 80 is a heterogeneous device. For example, the computing device 80 may include a CPU and a GPU, and at least one of the processors 804 may execute the operation steps corresponding to the risk assessment method. For the sake of brevity, further details will not be elaborated here.

[0279] This application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.

[0280] like Figure 9 As shown, the computing device cluster includes at least one computing device 80. The memory 806 of one or more computing devices 80 in the computing device cluster may store the same instructions for executing risk assessment methods.

[0281] In some possible implementations, the memory 806 of one or more computing devices 80 in the computing device cluster may also store partial instructions for executing the risk assessment method. In other words, a combination of one or more computing devices 80 can jointly execute the instructions for executing the risk assessment method.

[0282] It should be noted that the memory 806 in different computing devices 80 within the computing device cluster can store different instructions, each used to execute a portion of the functions of the risk assessment device. That is, the instructions stored in the memory 806 of different computing devices 80 can implement the functions of one or more modules among the processing module and interface module.

[0283] In some possible implementations, one or more computing devices in a computing device cluster can be connected via a network. This network can be a wide area network (WAN), a local area network (LAN), or similar. Figure 10 One possible implementation is shown. For example... Figure 10 As shown, two computing devices 80A and 80B are connected via a network. Specifically, they are connected to the network through communication interfaces in each computing device. In this type of possible implementation, the memory 806 in computing device 80A stores instructions for executing the functions of the processing module. Simultaneously, the memory 806 in computing device 80B stores instructions for executing the functions of the interface module.

[0284] It should be understood that Figure 10 The functions of the computing device 80A shown can also be performed by multiple computing devices 80. Similarly, the functions of the computing device 80B can also be performed by multiple computing devices 80.

[0285] This application also provides another computing device cluster. The connection relationships between the computing devices in this computing device cluster can be similarly referred to... Figure 9 and Figure 10The connection method of the computing device cluster. The difference is that the memory 806 of one or more computing devices 80 in the computing device cluster can store the same instructions for executing the risk assessment method.

[0286] In some possible implementations, the memory 806 of one or more computing devices 80 in the computing device cluster may also store partial instructions for executing the risk assessment method. In other words, a combination of one or more computing devices 80 can jointly execute the instructions for executing the risk assessment method.

[0287] This application also provides a computer program product containing instructions. The computer program product may be a software or program product containing instructions, capable of running on a computing device or stored on any usable medium. When the computer program product is run on at least one computing device, it causes the at least one computing device to perform a risk assessment method, or a risk assessment method...

[0288] This application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computing device can store, or a data storage device such as a data center that includes one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to perform a risk assessment method, or instruct the computing device to perform a risk assessment method.

[0289] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of this application.

Claims

1. A risk assessment method, characterized in that, The method includes: Obtain a first assessment instruction, which instructs a risk assessment to be performed on the first risk; A target risk sample is obtained based on a first data object or a first risk indicator. The target risk sample is used to record the risk result of the first data object with respect to the first risk indicator. The first risk is related to the first data object and the first risk indicator. Based on the target risk sample, a first assessment result for the first risk is obtained.

2. The method according to claim 1, characterized in that, The target risk samples are stored in plaintext.

3. The method according to claim 2, characterized in that, The method further includes: Obtain a second assessment instruction, which instructs a risk assessment to be performed on a second risk, which is different from the first risk; If, according to the second assessment instruction, it is determined that the second risk is related to the first data object and the first risk indicator, then the stored target risk sample is obtained; Based on the target risk sample, a second assessment result for the second risk is obtained.

4. The method according to any one of claims 1-3, characterized in that, The step of obtaining the target risk sample based on the first data object or the first risk indicator includes: Identify a first data object and / or a first risk indicator related to the first risk; The first data object is matched with the data object recorded in each of the at least one risk samples, and / or the first risk indicator is matched with the risk indicator recorded in each of the at least one risk samples, wherein one risk sample is used to record the risk result of the data object with respect to the risk indicator; The target risk sample is determined based on the matching results.

5. The method according to any one of claims 1-3, characterized in that, The step of obtaining the target risk sample based on the first data object or the first risk indicator includes: Identify the first data object related to the first risk; Acquire the data to be processed, which includes the business data of the first data object; The data to be processed is processed according to the specified rules to generate the target risk sample.

6. The method according to claim 5, characterized in that, The specified rules include a first rule and a second rule; The step of processing the data to be processed according to specified rules to generate the target risk sample includes: The data to be processed is processed according to the first rule to generate indicator data about intermediate indicators; The intermediate indicator data are processed according to the second rule to generate the target risk sample.

7. The method according to claim 6, characterized in that, After generating the indicator data for the intermediate indicators, the following is also included: Output the indicator data of the intermediate indicator.

8. The method according to any one of claims 5-7, characterized in that, The data to be processed is stored through a first data layer, the target risk sample is stored through a second data layer, and the first assessment result is stored through a third data layer. Data from the first data layer can be transmitted to the second data layer, and data from the second data layer can be transmitted to the third data layer.

9. The method according to any one of claims 1-8, characterized in that, The target risk sample also includes a first dimension; The step of obtaining a first assessment result for the first risk based on the target risk sample includes: Based on the target risk sample, first risk measurement data is obtained. The first risk measurement data is used to record the risk measurement results under the first dimension. The risk measurement results are used to describe the degree of risk. Based on the first risk measurement data, a first assessment result for the first risk is obtained.

10. A risk assessment device, characterized in that, include: The interface module is used to obtain a first assessment instruction, which is used to instruct a risk assessment to be performed on the first risk. Processing module, used for: A target risk sample is obtained based on a first data object or a first risk indicator. The target risk sample is used to record the risk result of the first data object with respect to the first risk indicator. The first risk is related to the first data object and the first risk indicator. Based on the target risk sample, a first assessment result for the first risk is obtained.

11. The apparatus according to claim 10, characterized in that, The target risk samples are stored in plaintext.

12. The apparatus according to claim 11, characterized in that, The interface module is used to: obtain a second assessment instruction, the second assessment instruction being used to instruct a risk assessment of a second risk, the second risk being different from the first risk; The processing module is used for: If, according to the second assessment instruction, it is determined that the second risk is related to the first data object and the first risk indicator, then the stored target risk sample is obtained; Based on the target risk sample, a second assessment result for the second risk is obtained.

13. The apparatus according to any one of claims 10-12, characterized in that, The processing module is used for: Identify a first data object and / or a first risk indicator related to the first risk; The first data object is matched with the data object recorded in each of the at least one risk samples, and / or the first risk indicator is matched with the risk indicator recorded in each of the at least one risk samples, wherein one risk sample is used to record the risk result of the data object with respect to the risk indicator; The target risk sample is determined based on the matching results.

14. The apparatus according to any one of claims 10-12, characterized in that, The processing module is used for: Identify the first data object related to the first risk; Acquire the data to be processed, which includes the business data of the first data object; The data to be processed is processed according to the specified rules to generate the target risk sample.

15. The apparatus according to claim 14, characterized in that, The specified rules include a first rule and a second rule; The processing module is used for: The data to be processed is processed according to the first rule to generate indicator data about intermediate indicators; The intermediate indicator data are processed according to the second rule to generate the target risk sample.

16. The apparatus according to claim 15, characterized in that, The interface module is used to output the indicator data of the intermediate indicator.

17. The apparatus according to any one of claims 14-16, characterized in that, The data to be processed is stored through a first data layer, the target risk sample is stored through a second data layer, and the first assessment result is stored through a third data layer. Data from the first data layer can be transmitted to the second data layer, and data from the second data layer can be transmitted to the third data layer.

18. The apparatus according to any one of claims 10-17, characterized in that, The target risk sample also includes a first dimension; The processing module is used for: Based on the target risk sample, first risk measurement data is obtained. The first risk measurement data is used to record the risk measurement results under the first dimension. The risk measurement results are used to describe the degree of risk. Based on the first risk measurement data, a first assessment result for the first risk is obtained.

19. A computing device, characterized in that, The computing device includes a processor and memory; The processor is configured to execute instructions stored in the memory to cause the computing device to perform the method as described in any one of claims 1-9.

20. A computing device cluster, characterized in that, It includes at least one computing device, said at least one computing device including a processor and a memory; The processor is configured to execute instructions stored in the memory to cause the computing device cluster to perform the method as described in any one of claims 1-9.

21. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when run on a processor, causes the processor to perform the method as described in any one of claims 1-9.

22. A computer program product containing instructions, characterized in that, When the instructions are executed by the processor, the method described in any one of claims 1-9 is implemented.