A compliance risk early warning detection method for bank-enterprise direct connection cross-border payment
By synchronously collecting and processing transaction data of cross-border payments between banks and enterprises, and generating transaction risk levels, the system solves the problems of data fragmentation and reliance on manual intervention in direct cross-border payment systems between banks and enterprises. This enables efficient and accurate risk identification and early warning, ensuring the compliance and security of cross-border payments.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-02
- Publication Date
- 2026-03-27
AI Technical Summary
In existing cross-border payment systems that directly connect banks and enterprises, data fragmentation leads to a lack of a comprehensive perspective in risk identification, a high reliance on manual intervention, resulting in low efficiency and a high risk of false alarms and missed alarms, making it difficult to meet the real-time early warning needs of transactions with a scale of tens of millions.
By acquiring the original transaction sequence of cross-border payments between banks and enterprises, simultaneously collecting transaction object information and fund flow data, generating transaction pattern components and risk warning parameters, and combining adaptive fusion processing, dynamically generating transaction risk levels and providing real-time warnings.
It achieves deep integration of multi-source data, improves the accuracy of risk identification, reduces the rate of missed and false alarms, significantly shortens the risk response time, provides accurate and efficient compliance risk early warning tools, and ensures the security of cross-border payment business.
Smart Images

Figure CN121235701B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of financial technology, in particular to a compliance risk early warning detection method for bank-enterprise direct connection cross-border payment. BACKGROUND
[0002] Under the background of global economic integration and deep integration of digital finance, bank-enterprise direct connection cross-border payment has become the core mode for foreign trade enterprises and multinational groups to carry out cross-border payment settlement due to its seamless system connection and automatic transaction processing, which has significantly improved the payment efficiency and account management convenience.
[0003] The existing bank-enterprise direct connection system cannot effectively integrate multi-source information such as transaction object credit data and fund flow level data with the bank regulatory system and external data service providers, and the risk identification lacks a panoramic perspective. The dependence on manual intervention is high, and a large number of compliance audits in the traditional mode rely on manual completion, which not only is inefficient, but also is prone to false positives and false negatives due to subjective judgment bias, making it difficult to meet the real-time early warning needs of millions of transactions. SUMMARY
[0004] The purpose of the present application is to provide a compliance risk early warning detection method for bank-enterprise direct connection cross-border payment to solve the technical problems raised in the background.
[0005] To achieve the above purpose, the present application provides the following technical solutions:
[0006] The compliance risk early warning detection method for bank-enterprise direct connection cross-border payment comprises:
[0007] Obtaining the original transaction sequence of bank-enterprise cross-border payment, synchronously collecting transaction object information, fund flow data and error correlation regulatory parameter sequence;
[0008] Obtaining transaction mode components according to the original transaction sequence;
[0009] Generating preliminary risk early warning parameters according to the transaction mode components and error correlation regulatory parameter sequence;
[0010] Obtaining the cumulative number of payment transactions, generating early warning threshold factors and risk weight factors based on the cumulative number of transactions and fund flow data;
[0011] Through adaptive fusion processing of preliminary risk early warning parameters, early warning threshold factors and risk weight factors, transaction risk levels are generated;
[0012] Judging whether the transaction risk level is less than the preset level;
[0013] If it is less than, it is judged that the corresponding transaction risk level is within a safe range;
[0014] If greater than, it is judged that the transaction corresponding to the transaction risk level is risky, and a warning information is generated according to the transaction risk level.
[0015] Preferably, the step of obtaining the transaction mode component according to the original transaction sequence comprises:
[0016] Obtaining a classification segmentation sequence according to the original transaction sequence, and obtaining a transaction data grouping according to the classification segmentation sequence;
[0017] Obtaining a transaction field set according to the transaction data grouping, wherein the transaction field set comprises transaction amount information, payment purpose information, and instruction initiation time information;
[0018] Obtaining a transaction feature segment according to the transaction amount information, the payment purpose information, and the instruction initiation time information, and splitting the transaction data according to a fixed time window to obtain transaction time sequence feature information;
[0019] Obtaining a feature correlation index according to the transaction time sequence feature information and an error correlation supervision parameter sequence;
[0020] Obtaining risk feature evaluation information corresponding to the transaction amount information, the payment purpose information, and the instruction initiation time information according to the feature correlation index;
[0021] Obtaining the transaction mode component according to the risk feature evaluation information corresponding to the transaction amount information, the payment purpose information, and the instruction initiation time information and a preset screening standard.
[0022] Preferably, the step of generating a preliminary risk warning parameter according to the transaction mode component and the error correlation supervision parameter sequence comprises:
[0023] Obtaining a preset supervision parameter mapping table, disassembling constituent elements of the transaction mode component, and extracting matched supervision parameters to form a subset by comparing the elements with the corresponding parameters in the preset supervision parameter mapping table;
[0024] Obtaining completeness of mandatory fields and field content format compliance of each subset according to the associated supervision parameter subset, and generating compliance feature requirements according to the completeness of the mandatory fields and the field content format compliance;
[0025] Comparing an actual feature description of the transaction mode component with the compliance feature requirements corresponding to the associated supervision parameter subset to obtain a mode compliance deviation;
[0026] Obtaining a corresponding risk expression according to the mode compliance deviation, and generating a preliminary risk description according to the risk expression;
[0027] The preliminary risk description is matched with a risk situation in a risk level corresponding table, a risk quantification identifier corresponding to the matched situation is extracted, and a preliminary risk coefficient is calculated according to the risk quantification identifier;
[0028] According to the preliminary risk coefficient and the parameter dynamic adjustment description, a revised preliminary risk coefficient is generated in combination with the latest change information of the supervision parameter, and a preliminary risk warning parameter is obtained according to the revised preliminary risk coefficient.
[0029] Preferably, the cumulative number of payment businesses is obtained, and the step of generating the warning threshold factor and the risk weight factor based on the cumulative number and the fund flow direction data comprises:
[0030] The cumulative number of payment businesses and the transaction time stamp are obtained according to the bank-enterprise direct connection transaction log, each transaction record in the transaction log is traversed, the total number of records is counted to obtain the cumulative number, and the time field in each record is extracted to obtain the transaction time stamp;
[0031] The transaction time stamps are classified into corresponding time windows according to a preset time interval, and the number of transaction records in each window is counted to obtain the transaction frequency per unit time;
[0032] According to the account receiving sequence in the fund flow direction data, the transit account level and the number of nodes passed by the fund are marked in combination with the account flow trajectory, and fund flow level data is obtained;
[0033] The cumulative number and the transaction frequency per unit time are compared with the same type of data in the threshold reference data set, and the threshold reference corresponding to the matching data is extracted as the warning threshold factor;
[0034] According to the complexity of the fund flow level data and the frequency of supervision parameter update, the proportion of each level is determined according to the specification to generate the risk weight factor.
[0035] Preferably, the step of generating the transaction risk level by adaptively fusing the preliminary risk warning parameter, the warning threshold factor and the risk weight factor comprises:
[0036] A standardized risk parameter is obtained according to the preliminary risk warning parameter and the parameter normalization standard, different dimension indicators in the preliminary risk warning parameter are converted into numerical values in a unified range according to the dimension conversion requirements of each risk indicator in the parameter normalization standard;
[0037] The indicator values in the standardized risk parameter are extracted, the threshold value range of the same type of indicator in the warning threshold factor is correspondingly searched, the threshold value interval in which the indicator values are located is recorded, and a threshold value comparison result is obtained;
[0038] According to the proportion of each dimension in the risk weight factor, the risk information of different dimensions in the threshold value comparison result is integrated to generate weighted risk information;
[0039] According to the adjustment experience of the same kind of risk in the historical early warning results, the details of the weighted risk information are optimized according to the specification, and the dynamic revised risk information is obtained;
[0040] The core risk indicators in the dynamic revised risk information are compared with the risk grade division range to determine the corresponding grade interval, and the grade interval attribution information is obtained;
[0041] According to the corresponding relationship between the grade interval attribution information and the grade name, the interval attribution is converted into the transaction risk grade.
[0042] Preferably, the step of obtaining the corresponding risk expression according to the mode compliance deviation, and generating the preliminary risk description according to the risk expression, comprises:
[0043] According to the mode compliance deviation and the deviation feature disassembly standard, the deviation detail data is obtained;
[0044] According to the deviation detail data and the risk expression corresponding table, the basic risk expression data is obtained;
[0045] The preset expression association logic is obtained, and the associated risk expression data is obtained according to the basic risk expression data and the preset expression association logic;
[0046] The preset deviation integrity check list is obtained, and the complete risk expression data is obtained according to the associated risk expression data and the preset deviation integrity check list;
[0047] The repeated expressions in the structured risk description data are removed, the coherence and conciseness of the expressions are adjusted according to the description simplification standard, and the preliminary risk description is generated.
[0048] Preferably, according to the complexity of the fund flow level data and the frequency of the regulatory parameter update, the proportion distribution of each level is determined according to the specification to generate the risk weight factor, and the step comprises:
[0049] According to the fund flow level data, the account node sequence is obtained, the number of transfer accounts, account attributes and flow interval information in the account node sequence are extracted, and the level detail data is integrated.
[0050] According to the level detail data, the level complexity representation data is obtained;
[0051] The frequency interval data and the statistical record of the regulatory parameter update frequency are obtained, and the frequency interval data and the statistical record of the regulatory parameter update frequency are classified into the corresponding interval according to the time span in the frequency segmentation standard, and the frequency interval data is formed;
[0052] According to the frequency interval data, the update influence description data is obtained;
[0053] According to the hierarchical complex representation data and the update influence description data, initial proportion data is obtained;
[0054] According to the initial proportion data and the factor generation specification, risk weight factors are obtained.
[0055] Preferably, according to the feature correlation index, the step of obtaining risk feature evaluation information corresponding to transaction amount information, payment purpose information, and instruction initiation time information comprises:
[0056] According to the feature correlation index and the information dimension division standard, dimensionally correlated data is obtained.
[0057] According to the dimensionally correlated data, transaction amount related correlation content is obtained, and according to the transaction amount related correlation content, correlation performance and correlation strength of the amount and other transaction elements are obtained, and the amount correlation feature data is generated according to the correlation performance and the correlation strength.
[0058] According to the purpose correlation segment in the dimensionally correlated data and the purpose feature extraction standard, purpose correlation feature data is obtained.
[0059] According to the time correlation segment in the dimensionally correlated data and the time feature extraction standard, time correlation feature data is obtained.
[0060] According to the amount correlation feature data, the purpose correlation feature data, and the time correlation feature data, information risk element data is obtained.
[0061] According to the information risk element data, risk feature evaluation information is obtained.
[0062] Preferably, the step of obtaining information risk element data according to the amount correlation feature data, the purpose correlation feature data, and the time correlation feature data comprises:
[0063] According to the amount correlation feature data, amount risk element data is obtained.
[0064] According to the purpose correlation feature data, purpose risk element data is obtained.
[0065] According to the time correlation feature data, time risk element data is obtained.
[0066] According to the amount risk element data, the purpose risk element data, and the time risk element data, information risk element data is generated.
[0067] Preferably, the step of generating information risk element data according to the amount risk element data, the purpose risk element data, and the time risk element data comprises:
[0068] According to the amount risk element data, structured amount risk element data is obtained.
[0069] acquire structured time risk element data according to time risk element data;
[0070] acquire structured time risk element data according to time risk element data;
[0071] correspond the structured amount risk element data, the structured use risk element data and the structured time risk element data to a transaction amount, a payment use and an instruction initiation time respectively, and generate sub-information risk element data according to the transaction amount, the payment use and the instruction initiation time.
[0072] The application has the advantages that: the application realizes deep integration of multi-source data by synchronously collecting transaction sequences, object information, fund flow directions and supervision parameters and combining sub-dimension structured processing, solves the problem of data fragmentation, and lays a high-quality data foundation for risk assessment. With the help of feature correlation index to mine the implicit correlation of amount, use and time, combined with mode compliance deviation quantification risk, and with the help of dynamically generated early warning threshold and weight factor, the risk identification accuracy is greatly improved, the false negative and false positive rates are reduced, and hidden risks in complex cross-border payments can be accurately captured. The whole process is automatically processed to replace traditional manual review, and end-to-end closed loop is realized from data extraction, feature analysis to early warning generation, which significantly shortens the risk response time and reduces the labor cost. Through incremental learning and dynamic parameter adjustment, the system can adapt to the update of supervision policy and the change of transaction mode in real time, and enhance the long-term applicability of the system.
[0073] Finally, the application provides a precise and efficient compliance risk early warning tool for financial institutions and enterprises, helps to prevent money laundering, sanctions violations and other risks, and ensures the compliance and safety of cross-border payment business. BRIEF DESCRIPTION OF DRAWINGS
[0074] Figure 1 The method flowchart of an embodiment of the application is shown.
[0075] The implementation, functional features and advantages of the application will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION
[0076] It should be understood that the specific embodiments described herein are only used to explain the application and not to limit the application.
[0077] As shown in the drawings, the application provides a compliance risk early warning detection method for bank-enterprise direct connection cross-border payment, which comprises: Figure 1
[0078] S1, acquiring an original transaction sequence of bank-enterprise cross-border payment, synchronously collecting transaction object information, fund flow data and error-related supervision parameter sequence;
[0079] S2, acquiring a transaction mode component according to the original transaction sequence;
[0080] S3, generating a preliminary risk warning parameter according to the transaction mode component and the error correlation supervision parameter sequence;
[0081] S4, obtaining the cumulative number of payment services, and generating a warning threshold factor and a risk weight factor based on the cumulative number and the fund flow data;
[0082] S5, processing the preliminary risk warning parameter, the warning threshold factor and the risk weight factor through adaptive fusion to generate a transaction risk level;
[0083] S6, judging whether the transaction risk level is less than a preset level;
[0084] If it is less than, it is judged that the corresponding transaction risk level is in a safe range;
[0085] If it is greater than, it is judged that the corresponding transaction risk level has a risk, and warning information is generated according to the transaction risk level.
[0086] As described above in steps S1-S6, since a variety of complex transaction data and supervision requirements are involved in cross-border payment, how to efficiently extract valuable risk information from transaction data and dynamically adjust risk assessment according to real-time data has become a core problem that financial institutions urgently need to solve in cross-border payment. The traditional risk assessment method often relies on static rules and manual review, lacks flexibility and timeliness, and cannot effectively process large-scale real-time payment data.
[0087] The present application builds a compliance risk warning detection method for bank-enterprise direct connection cross-border payment, aiming to use data analysis technology to monitor potential risks in the process of bank-enterprise cross-border payment in real time, provide accurate warning information based on data correlation and risk assessment model, and further provide compliance guarantee for financial institutions and related enterprises. Specifically, through the risk identification and warning mechanism, the potential financial transaction risks are effectively identified and evaluated, so as to ensure the compliance and safety of cross-border payment operation.
[0088] The original transaction sequence of bank-enterprise cross-border payment is obtained from the payment platform, which contains the basic information of each transaction, such as transaction amount, payment purpose, initiator and receiver, etc. Then the transaction object information is synchronously collected, including the account information and identity information of the payer and the payee. In addition, fund flow data needs to be collected to clearly show the path and link of each transaction fund flow, ensure that the source and destination of the fund can be traced, and prevent illegal activities such as money laundering.
[0089] The original transaction sequence is processed by a feature extraction algorithm to extract the transaction pattern components. The transaction pattern components refer to the key feature components in the transaction data, mainly including transaction amount, payment purpose, transaction time, transaction object, etc. Through these components, the basic characteristics and patterns of the transaction can be revealed.
[0090] By comparing the transaction patterns and error supervision data, preliminary risk warning parameters are obtained to provide data support for subsequent risk level assessment. By dynamically capturing the risk characteristics in the transaction, accurate quantitative description of the transaction risk can be provided.
[0091] The warning threshold factor and risk weight factor are determined by analyzing the cumulative number of payment transactions and fund flow data. First, all transaction records in bank-enterprise cross-border payment are counted to calculate the cumulative number of payment transactions. Then, according to the fund flow data, the path of each transaction fund flow and the involved account nodes are analyzed to obtain the hierarchical data of fund flow.
[0092] The final transaction risk level is generated by combining the preliminary risk warning parameters with the warning threshold factor and risk weight factor through an adaptive fusion processing algorithm. The adaptive fusion algorithm is a dynamic processing method based on data flow and real-time feedback mechanism. By continuously optimizing the parameters and weights in the fusion process, the final risk level can more accurately reflect the actual risk of the transaction.
[0093] The generated transaction risk level is judged to determine whether the level is lower than the preset safety level. If the risk level is less than the preset safety range, it is considered that the transaction is within the safety range; if the risk level is greater than the safety range, it is considered that the transaction has risks
[0094] In one embodiment, the step of obtaining transaction pattern components from the original transaction sequence comprises:
[0095] S201, obtaining a classification segmentation sequence from the original transaction sequence, and obtaining a transaction data grouping according to the classification segmentation sequence;
[0096] S202, obtaining a transaction field set from the transaction data grouping, wherein the transaction field set includes transaction amount information, payment purpose information, and instruction initiation time information;
[0097] S203, obtaining transaction feature segments from the transaction amount information, payment purpose information, and instruction initiation time information, and splitting transaction data according to a fixed time window to obtain transaction time sequence feature information;
[0098] S204, obtaining a feature correlation index according to the transaction time sequence feature information and an error-related supervision parameter sequence;
[0099] S205, obtaining risk feature evaluation information corresponding to the transaction amount information, the payment purpose information, and the instruction initiation time information according to the feature correlation index;
[0100] S206, obtaining a transaction mode component according to the risk feature evaluation information corresponding to the transaction amount information, the payment purpose information, and the instruction initiation time information and a preset screening standard.
[0101] As described in steps S201-S206, the original transaction data is classified and segmented, and the original transaction data is converted into a manageable and analyzable subset, thereby reducing the complexity of subsequent processing. Traditional methods process transaction data roughly and ignore the internal category differences, resulting in inaccurate analysis. In terms of technical implementation, the original transaction sequence is analyzed first, the transaction data is divided into several categories according to predetermined classification standards such as amount interval, payment purpose, and time range, and then a classification and segmentation sequence is generated and further grouped accordingly.
[0102] According to the transaction data grouping, key fields are extracted to provide basic data for feature extraction and pattern analysis. The key information of the transaction is crucial for transaction pattern recognition. Extracting these fields can effectively carry out transaction analysis. Traditional methods rely on simple summary data or single dimension indicators, ignoring the interaction between dimensions, resulting in blind risk assessment. In terms of technical implementation, the transaction amount, payment purpose, instruction initiation time, and other key fields are extracted from each group of transaction data. These field values represent the core features of the transaction, and ensure that each transaction feature set has high consistency.
[0103] According to the extracted transaction fields, transaction feature segments are generated and transaction data is split, and transaction time sequence features are analyzed to reveal timeliness and trend characteristics. Transactions contain time series information, and by splitting through a time window, the pattern differences in different time periods can be found, revealing potential risk features. Existing technologies usually ignore transaction time sequence features and fail to use time series data for risk analysis. In terms of technical implementation, the transaction data is split into multiple time segments according to a fixed time window, each segment representing transaction behavior in a specific time period, and then the transaction data in each time period is combined with the amount, purpose, and other information to generate transaction time sequence features.
[0104] By analyzing the relationship between transaction time sequence features and regulatory parameters, a feature correlation index is generated to provide a basis for subsequent risk assessment. The implicit correlation between time sequence features and regulatory parameters can reveal potential risk signals, and the feature correlation index can be used as a comprehensive reference standard. Traditional methods ignore the dynamic impact of regulatory parameters and cannot adjust the risk assessment model in real time. In terms of technical implementation, the transaction time sequence features are matched with the corresponding regulatory parameters, and a weighted average or correlation coefficient calculation method is used to generate the feature correlation index. This index reflects the correlation between transaction behavior and regulatory parameters and the compliance risk.
[0105] According to the characteristic correlation index, specific risk characteristics are extracted, risk assessment basis is provided for transaction mode component identification, potential risks are judged by correlating transaction characteristics with regulatory parameter relationships, the index is converted into specific evaluation information, which can provide quantitative basis for risk processing. Traditional methods only perform single-dimensional evaluation, which is difficult to fully consider multiple factors. In technical implementation, the characteristic correlation index is used to analyze the risk of transaction amount, payment purpose, instruction initiation time and other dimensions respectively, and risk evaluation information of each transaction is generated.
[0106] Through analysis of risk characteristic evaluation information combined with preset screening standards, transaction mode components are obtained, transaction characteristic information obtained in the early stage is integrated, and transaction mode components are identified to support subsequent risk early warning and compliance monitoring. Traditional methods rely on simple rule matching and lack in-depth analysis of complex transaction modes. In technical implementation, transaction risk characteristics are comprehensively evaluated, combined with risk level thresholds, regulatory requirements and other preset screening standards, and the mode components of each transaction are identified. These components represent different modes of transaction behavior, providing basic data for risk prediction and compliance monitoring.
[0107] In one embodiment, the step of generating a preliminary risk early warning parameter according to the transaction mode component and the error-related regulatory parameter sequence comprises:
[0108] S301, a preset regulatory parameter mapping table is obtained, the constituent elements of the transaction mode component are disassembled, and the corresponding relationship between the elements and the parameters in the preset regulatory parameter mapping table is matched to extract the matching regulatory parameters to form a subset;
[0109] S302, according to the associated regulatory parameter subset, the completeness of the mandatory fields and the compliance of the field content format of each subset are obtained, and the compliance feature requirements are generated according to the completeness of the mandatory fields and the compliance of the field content format;
[0110] S303, the actual characteristic description of the transaction mode component is compared with the compliance feature requirements corresponding to the associated regulatory parameter subset, and the mode compliance deviation is obtained;
[0111] S304, according to the mode compliance deviation, the corresponding risk expression is obtained, and the preliminary risk description is generated according to the risk expression;
[0112] S305, the preliminary risk description is matched with the risk situation in the risk level corresponding table, and the risk quantization identifier corresponding to the matching situation is extracted;
[0113] S306, according to the preliminary risk coefficient and the parameter dynamic adjustment description, the latest change information of the regulatory parameter is combined to generate a revised preliminary risk coefficient, and then the preliminary risk early warning parameter is obtained according to the revised preliminary risk coefficient.
[0114] As described in steps S301-S306 above, the application realizes the compliance risk early warning detection of bank-enterprise direct connection cross-border payment by generating preliminary risk early warning parameters. Specifically, by gradually processing the transaction mode components and error-related regulatory parameter sequences, compliance risk early warning information is generated to effectively identify potential risks and provide early warning, ensuring the compliance of payment transactions and avoiding legal and financial risks.
[0115] The preset regulatory parameter mapping table is obtained and the regulatory parameter subset is extracted by disassembling the transaction mode components. The transaction mode components and the contents in the regulatory parameter mapping table are closely related. The transaction mode itself represents the characteristics of different payment scenarios (such as amount, time, purpose, etc.), and the regulatory parameter mapping table provides the standards that need to be concerned in compliance checking (such as the compliance requirements set by the regulatory agency). Therefore, obtaining the mapping table and disassembling the constituent elements of the transaction mode components can help extract relevant data from the regulatory requirements and form the basic data set for compliance checking. The prior art usually only focuses on a single transaction element (such as amount or time), ignoring the comprehensive relationship of each dimension of the transaction. This step comprehensively considers each dimension of the transaction (such as amount, payment purpose, time, etc.) by disassembling the transaction mode components, thereby providing more comprehensive and accurate compliance evaluation. Specifically, first, the original transaction data is parsed to extract key elements such as transaction amount, payment purpose, and initiation time, ensuring that each dimension is fully considered. Then, a preset regulatory parameter mapping table is obtained, which defines compliance requirements related to transaction elements, such as the upper limit of the amount, the compliance of the payment purpose, etc. Finally, according to the elements of each transaction mode component, the corresponding compliance requirements in the mapping table are matched to extract relevant regulatory parameters and form a regulatory parameter subset for subsequent compliance checking.
[0116] The extracted regulatory parameter subset is checked for compliance, and whether the mandatory fields are complete, and whether the field content conforms to the specification. The compliance of each transaction item not only depends on the presence of the field, but also on whether the field content conforms to the relevant provisions. If the field content does not conform to the provisions, it may lead to the transaction failing to pass the compliance audit, or even triggering a risk warning. Therefore, checking the completeness and format compliance of each field is a key step to ensure transaction compliance. Traditional methods usually rely on simple field completeness checks, ignoring the compliance of field content format. In the present application, the completeness and content format of the field are comprehensively checked to ensure that each transaction item meets the regulatory requirements. In specific implementation, first, the mandatory field completeness check is performed to verify each regulatory parameter and check whether all mandatory fields have been filled in and the filled-in content is not empty. Then, the field format compliance check is performed to check whether the field content conforms to the predetermined format requirements, such as whether the amount field is a number, whether the time field conforms to the time format specification, etc. Finally, based on the check results, a parameter compliance result is generated to indicate whether each subset of fields is compliant. If non-compliant fields are found, it will affect the risk assessment.
[0117] The actual feature description of the transaction mode component is compared with the compliance feature requirement in the regulatory parameter subset, and the compliance deviation degree is calculated. Each transaction mode has its actual features, such as actual transaction amount, purpose and time, etc., and these features must conform to the relevant regulatory requirements. The compliance deviation degree measures the degree of deviation between the actual features and the compliance requirements. If the deviation degree is high, it means that the transaction has a high compliance risk. Traditional compliance checking methods only judge whether a certain field meets the regulations, without considering the gap between the actual data and the regulations. The present application can quantify the risk and provide more detailed compliance analysis by calculating the compliance deviation degree. The specific implementation process is as follows: first, the actual feature description is extracted from the transaction data, such as transaction amount, payment purpose, instruction initiation time, etc.; then, the extracted actual features are compared with the compliance requirements in the regulatory parameter subset, such as whether the transaction amount exceeds the limit, whether the payment purpose conforms to the regulations, etc.; finally, based on the comparison results, the compliance deviation degree of each element is calculated. The calculation method of the deviation degree can be to compare the difference between the actual value and the compliance requirement, or to quantify it through other scoring standards.
[0118] According to the compliance deviation, a risk expression corresponding to the compliance deviation is generated, and a preliminary risk description is formed, and a transaction with high compliance deviation often means high risk, so the corresponding risk expression is generated according to the deviation, which can help relevant personnel understand the risk characteristics of the transaction, so as to take appropriate measures to cope with it. The traditional method usually only gives the result of compliance check without further explaining the risk meaning behind the deviation, and by generating detailed risk expression, the present application can provide more intuitive and easier-to-understand risk information. In specific implementation, first, according to the calculated compliance deviation, a corresponding risk expression is generated by referring to a preset risk expression template, for example, a transaction with high deviation may be described as "high risk", and a transaction with low deviation may be described as "low risk"; then the generated risk expression is matched with the corresponding risk level, and finally a preliminary risk description is obtained, which can provide a basis for subsequent risk quantification.
[0119] According to the preliminary risk description, the risk situation in the risk level corresponding table is matched, and the corresponding risk quantification identifier is extracted, and the quantification of the risk can provide data support for subsequent processing. Through the quantification of the preliminary risk description, the specific risk level can be assigned to the transaction risk, which is convenient for formulating processing measures. The traditional method does not provide a perfect risk quantification system, resulting in lack of objectivity and standardization in risk assessment. Through the matching with the risk level corresponding table, the accuracy and operability of risk assessment can be improved. In the specific implementation process, first, according to the preliminary risk description, the risk level corresponding table is queried to find the risk situation that matches it; then according to the matched situation, the risk quantification identifier such as the specific score of the risk level or the risk index is extracted from the corresponding table.
[0120] According to the preliminary risk coefficient and the parameter dynamic adjustment instruction, a modified preliminary risk warning parameter is generated, and the preliminary risk warning parameter needs to be modified according to the actual situation to ensure that it is more in line with the current regulatory requirements. The dynamic adjustment instruction considers the latest regulatory information and can update the risk coefficient in real time to improve the accuracy of the warning. The traditional method does not have a real-time updating mechanism, so the warning parameter cannot adapt to the rapidly changing regulatory environment. The present application can ensure the timeliness and accuracy of risk warning by dynamically adjusting the risk warning parameter. In specific implementation, first, according to the risk quantification identifier, a preliminary risk coefficient is calculated; then according to the latest regulatory parameter change information, the preliminary risk coefficient is adjusted to generate a modified risk warning parameter.
[0121] In one embodiment, the cumulative number of payment services is obtained, and the steps of generating a warning threshold factor and a risk weight factor based on the cumulative number and the fund flow data include:
[0122] S401, obtain the cumulative number of payment services and transaction timestamps according to the bank-enterprise direct connection transaction log, traverse each transaction record in the transaction log, count the total number of records to obtain the cumulative number, and extract the time field in each record to obtain the transaction timestamp;
[0123] S402, classify the transaction timestamps into corresponding time windows according to a preset time interval, and count the number of transaction records in each window to obtain the transaction frequency per unit time;
[0124] S403, according to the account receiving sequence in the fund flow direction data, combine the account flow trajectory to mark the transit account level and node number passed by the fund, and obtain the fund flow level data;
[0125] S404, compare the cumulative number and transaction frequency per unit time with the same type of data in the threshold reference data set, and extract the threshold reference corresponding to the matching data as the early warning threshold factor;
[0126] S405, according to the complexity of the fund flow level data and the frequency of the regulatory parameter update, determine the proportion of each level according to the specification to generate the risk weight factor.
[0127] As described above in steps S401-S405, the present application generates early warning threshold factors and risk weight factors by in-depth analysis of cumulative number of cross-border payment services, transaction timestamps, fund flow direction data and regulatory parameters, to help risk monitoring accurately identify potential payment risks, and timely issue early warnings in abnormal transactions, thereby enhancing the security and compliance of payment.
[0128] In the bank-enterprise direct connection cross-border payment scenario, the fund flow crosses multiple accounts and regions, and the number of payment services is usually large, so the risk assessment of each transaction is crucial. In order to ensure payment compliance and reduce potential risks, it is necessary to deeply analyze transaction activities, especially focusing on transaction patterns, fund flow direction, transaction frequency and other key information. This technology can provide effective parameters reflecting transaction security by analyzing core factors such as cumulative number of payment services, transaction timestamps, fund flow level data, and generate risk early warning factors and weight factors. In practical application, the amount, purpose and payment time of cross-border payment are important basis for judging risk, the cumulative number and transaction frequency reflect the activity level of payment, and the fund flow level data reveals the fund flow trajectory. Through the extraction and analysis of these information, a complete and targeted risk early warning mechanism can be constructed, which not only improves the compliance of payment transaction, but also enhances the protection ability of the entire payment.
[0129] By analyzing the transaction log of bank-enterprise direct connection, the cumulative number of payment business and transaction timestamp are extracted as basic data. The transaction log is the basic data source for recording payment transaction activities, and each record contains transaction amount, payment purpose, initiation time and other key information. By traversing the log, the cumulative transaction number in the current time period can be calculated, and the transaction timestamp can be extracted. In technical implementation, first access the transaction log database of bank-enterprise direct connection, traverse each record, extract the specific time of transaction through the timestamp field, count the total number of records to get the cumulative number of transactions, and the transaction timestamp provides key support for subsequent time window division and transaction frequency statistics, for example, a bank has 5000 transactions in a day, through log analysis, the cumulative number of transactions is 5000 and the specific timestamp of each transaction (e.g. 2025-09-21 14:30:45) can be obtained.
[0130] The transaction timestamp is classified into the corresponding time window according to the preset time interval, and the transaction frequency in each window is obtained to provide support for risk assessment. In physical sense, payment transaction frequency is an important indicator for judging risk, and the frequency of business may imply abnormal risks such as money laundering, and the frequency can be calculated according to time window to assess business activity and provide quantitative basis for early warning. In technical implementation, timestamp data is grouped according to preset interval (e.g. hour, day, week), each transaction record is classified into the corresponding window, and the number of records in each window is counted to obtain the transaction frequency per unit time, for example, if the preset interval is one hour, the transaction of 2025-09-21 14:30:45 is classified into the 14:00-15:00 window, and finally the frequency per unit time is obtained.
[0131] By analyzing the flow of funds, tracking the flow of funds and level, the flow of funds level data is obtained to provide information on the complexity of fund flow for risk assessment. This data can reveal the trajectory of fund flow, especially the transit accounts and nodes in cross-border payment, which can identify abnormal fund paths or risky accounts and discover potential illegal activities such as money laundering. In technical implementation, through the account receiving sequence in the fund flow data, combined with the fund flow path of the account, each transit account and node is marked, the level is increased by one for each transit account, the account attributes and flow interval are recorded, the fund flow level diagram is constructed, and the level complexity features are extracted, for example, a certain fund passes through three transit accounts A, B and C to reach the receiving account, and the level data (level 1: A, level 2: B, level 3: C) is generated, and the account attributes and flow interval are recorded.
[0132] The accumulated number of pens and the transaction frequency per unit time are compared with the same data of the threshold benchmark data set, and the threshold benchmark corresponding to the matching data is extracted as the early warning threshold factor. In physical terms, the threshold benchmark is an important reference for risk early warning, which can determine whether the transaction is beyond the normal range. Abnormal cumulative number of pens or frequency may indicate risk. Comparing historical data with threshold benchmarks can accurately identify abnormalities and generate early warning threshold factors. In technical implementation, the current cumulative number of pens and transaction frequency are compared with the same data of the historical data set, the closest historical transaction record is found, and the corresponding threshold benchmark is extracted as the early warning threshold factor. For example, the current cumulative number of pens is 10,000, and the frequency is 500 pens per hour. After comparing the historical data, the matching normal frequency range (450-550 pens / hour) is extracted as the threshold benchmark.
[0133] According to the complexity of the fund flow level data and the frequency of updating the supervision parameters, the proportion of each level is determined according to the specification to generate a risk weight factor. The more complex the fund flow level is, the more frequent the supervision parameters are updated, and the higher the potential risk of the transaction is. By quantifying the impact of both on risk, the proportion can be allocated to generate a factor that accurately reflects the risk weight. In technical implementation, first, determine the complexity according to the number of transit accounts, account attributes, and flow intervals in the fund flow level data. Then, according to the supervision parameter update record, the number of updates per unit time is obtained to determine the frequency. Then, according to the preset specification, the impact of both on risk is converted into the proportion of each level, and finally integrated into a risk weight factor. For example, the fund flow level is 3 levels (high complexity), and the supervision parameters are updated 3 times a week (high frequency). According to the specification, the proportion of both is allocated and the corresponding risk weight factor is generated.
[0134] In one embodiment, the preliminary risk early warning parameters, the early warning threshold factor, and the risk weight factor are processed through adaptive fusion to generate the transaction risk level, comprising:
[0135] S501, obtaining standardized risk parameters according to the preliminary risk early warning parameters and parameter normalization standards, and converting different dimension indicators in the preliminary risk early warning parameters into numerical values in a unified range according to the dimension conversion requirements of each risk indicator in the parameter normalization standard;
[0136] S502, extracting the indicator values in the standardized risk parameters, corresponding to the threshold range of the same type of indicators in the early warning threshold factor, recording the threshold interval where the indicator values are located, and obtaining the threshold comparison result;
[0137] S503, integrating the risk information of different dimensions in the threshold comparison result according to the proportion of each dimension in the risk weight factor, and generating weighted risk information;
[0138] S504, combining the adjustment experience of the same risk in the historical early warning result, optimizing the detail expression of the weighted risk information according to the specification, and obtaining dynamic revised risk information;
[0139] S505, comparing the core risk indicators in the dynamic revised risk information with the risk grade division range, determining the corresponding grade interval, and obtaining grade interval attribution information;
[0140] S506, according to the corresponding relationship between the grade interval attribution information and the grade name, converting the interval attribution into a transaction risk grade.
[0141] As described in steps S501-S506, the application generates a transaction risk grade by adaptively fusing the preliminary risk early warning parameters with the early warning threshold factor and the risk weight factor, and further comprehensively evaluates the risk level of the transaction, thereby providing effective risk early warning information for financial institutions or relevant regulatory agencies.
[0142] In complex financial transaction scenarios such as cross-border payment and bank-enterprise direct connection, factors such as transaction amount, payment purpose, instruction initiation time have significant diversity, and traditional risk assessment methods are difficult to comprehensively and effectively integrate multiple information for assessment. To address this problem, the application proposes a technical solution for standardizing, weighting and revising different dimension risks, achieving more accurate and dynamic risk assessment.
[0143] According to the preliminary risk early warning parameters and the parameter normalization standard, the standardized risk parameters are obtained. In the technical implementation process, the preliminary risk early warning parameters may include indicators of different dimensions and numerical intervals, such as transaction amount represented in currency units, payment purpose in categorical data form, and time information in timestamp format. These parameters directly affect the accuracy of subsequent risk assessment, so the dimensions need to be unified according to the parameter normalization standard. The dimensions and units of different risk indicators differ greatly, and direct comparison or weighting may lead to inaccurate results. After the numerical values of each indicator are unified, the risk level of each indicator can be truly reflected in the subsequent weighting fusion process. Technically, standardization allows each indicator to be calculated and compared within the same numerical range, ensuring that different dimension risk information is processed under the same standard and avoiding bias caused by inconsistent dimensions.
[0144] The index value in the standardized risk parameter is extracted, the threshold value range of the same type index in the early warning threshold factor is searched, the threshold value interval in which the index value is located is recorded, and the threshold value comparison result is obtained. In the technical implementation, the standardized risk parameter is first extracted, and then compared with the related threshold value range in the early warning threshold factor. The early warning threshold factor is formed based on the past transaction data and historical risk assessment results, and contains risk level division and corresponding threshold value of different risk factors. The standardized risk parameter value is mapped to the corresponding threshold value interval, and the interval corresponding to each index value is recorded after comparison. The risk level interval of each index is determined, and the risk range is clarified. The simple standardized result cannot reflect the risk severity, and the specific risk level needs to be determined by comparing with the preset threshold value. Technically, by comparing the preset threshold value range, each standardized risk parameter can be clearly mapped to the corresponding risk level interval, ensuring that the evaluation result of each risk factor meets the actual risk division requirements.
[0145] According to the proportion of each dimension in the risk weight factor, the risk information of different dimensions in the threshold value comparison result is integrated to generate weighted risk information. In the technical implementation process, each dimension is weighted according to the preset risk weight factor, and the risk weight factor is determined according to historical data and industry standards, reflecting the importance of different dimensions to the overall risk assessment. Then, according to the proportion of each dimension in the overall assessment, the risk information is combined to generate weighted comprehensive risk information. The risk indicators of each dimension have different influences on the overall assessment, and reasonable weight setting can make the risk information of key dimensions have a larger proportion, ensuring that the contribution of different dimensions to the total risk is accurately reflected, and avoiding that the information of a certain dimension is too prominent or ignored. Technically, the weighting process realizes the comprehensive evaluation of multiple risk information, ensures that the contribution of the risk of each dimension to the final result meets the actual situation, and improves the accuracy and rationality of risk assessment.
[0146] According to the adjustment experience of the same type of risk in the historical early warning results, the details of the weighted risk information are optimized according to the specification to obtain dynamic corrected risk information. In the technical implementation, by analyzing the historical early warning results and combining the processing experience of historical risk events, the weighted risk information is dynamically corrected, including optimizing the details of the risk information to ensure that the evaluation result is more consistent with the actual risk performance. The financial market is continuously developing and the trading mode is continuously changing, and the traditional risk assessment standard may not be able to adapt to the new risk performance form, and needs to be adjusted according to historical data to ensure the dynamics and timeliness of the risk information. Technically, combining historical adjustment experience can optimize the weighted risk information to make it more accurate and reliable, and dynamically correct the risk assessment to adapt to the new market environment, improve the real-time performance and accuracy of the evaluation model.
[0147] The core risk indicator in the dynamically corrected risk information is compared with the risk level division range to determine the corresponding level interval, and the level interval attribution information is obtained. In the technical implementation, the core risk indicator of the dynamically corrected risk information is compared with the preset risk level division range, the risk level division range is set according to historical data and industry specifications, and the final level interval attribution is obtained through matching. The actual risk information is matched with the preset risk level system, ensuring that the risk of each transaction is divided into an accurate level, and ensuring that the risk assessment result reflects the true risk level of the transaction. In terms of technical effects, through the comparison process, it is ensured that the risk assessment result is consistent with the preset risk level system, providing a scientific and accurate basis for subsequent decision-making.
[0148] According to the correspondence between the level interval attribution information and the level name, the interval attribution is converted into a transaction risk level. In the technical implementation, according to the correspondence between the level interval attribution information and the level name, the determined level interval is converted into an actual transaction risk level, for example, a certain transaction evaluation result falls in the "high risk" interval and is marked as "high risk". All risk assessment information is finally converted into a clear risk level, facilitating financial institutions or regulatory authorities to take corresponding risk control measures. In terms of technical effects, this conversion ensures that the risk assessment result is operable, providing a direct basis for further risk warning and control.
[0149] In one embodiment, the step of obtaining a corresponding risk expression according to the mode compliance deviation degree and generating a preliminary risk description according to the risk expression includes:
[0150] S3041, obtaining deviation detail data according to the mode compliance deviation degree and the deviation feature disassembly standard;
[0151] S3042, obtaining basic risk expression data according to the deviation detail data and the risk expression correspondence table;
[0152] S3043, obtaining a preset expression association logic, and obtaining associated risk expression data according to the basic risk expression data and the preset expression association logic;
[0153] S3044, obtaining a preset deviation integrity check list, and obtaining completed risk expression data according to the associated risk expression data and the preset deviation integrity check list;
[0154] S3045, removing repeated expressions in the structured risk description data, adjusting the coherence and conciseness of the expressions according to the description simplification standard, and generating a preliminary risk description.
[0155] As described in steps S3041-S3045 above, the present application generates an accurate, concise and compliant preliminary risk description from the mode compliance deviation degree, providing basic data for risk management and decision-making, and ultimately providing an effective compliance risk warning tool for enterprises, financial institutions, regulatory agencies, etc. In practical applications, compliance checks and risk warnings are highly dependent on the identification and analysis of transaction mode deviations. The compliance level of different transaction behaviors and the identification of abnormal patterns directly affect the effectiveness of risk identification and management. Therefore, generating effective risk descriptions through in-depth analysis of mode compliance deviation degrees is crucial for subsequent compliance judgments, potential risk assessments and warnings. If accurate, comprehensive and easy-to-understand risk descriptions cannot be achieved, it will be difficult to support related decisions, which may lead to risk management failures or excessive intervention. However, existing risk assessment methods rely heavily on manual judgment, and there is a strong subjective and low accuracy problem in identifying and describing compliance deviations. It is urgent to convert compliance deviation degrees into standardized and precise risk descriptions through automated and standardized processes.
[0156] Converting compliance deviation degrees into specific deviation detail data, since the calculation results of mode compliance deviation degrees are mostly quantitative or qualitative indicators, they cannot directly provide sufficient details, so deviation degree data needs to be subdivided according to established deviation feature disassembly standards to obtain deviation values, deviation properties, and differences from standards in each risk dimension. Technically, it relies on structured processing of deviation degree data. By establishing deviation feature disassembly standards, setting deviation value ranges and types, and using calculation algorithms to map mode compliance deviation degrees to specific deviations, specific operations include data querying, comparing and automatic calculation based on database rules to obtain detailed deviation data related to each transaction or behavior. By disassembling the deviation degree.
[0157] Generating basic risk expressions based on deviation detail data through a risk expression correspondence table. Since deviation detail data only describes the deviation degree, it lacks explicit risk expressions, so different deviation details need to be mapped to corresponding basic risk expressions with the help of a pre-set risk expression correspondence table. In technical implementation, the risk expression correspondence table lists different deviation details and corresponding risk descriptions, such as "high risk" for high deviation degree and "financial anomaly" for financial inconsistency. Through algorithmic quick querying of the correspondence table, a basic risk expression is generated for each transaction. Mapping deviation details to specific risk expressions makes the risk situation of each transaction or behavior more specific and structured, improves the standardization of risk descriptions, reduces human subjective bias, and ensures the uniformity and consistency of risk assessment.
[0158] The correlation logic refines the basic risk representation to compensate for the possible simplification defects of the basic representation and generate a more comprehensive correlation risk representation. In terms of technical implementation, the preset representation correlation logic is a rule code for the relationship between risk representations, for example, "large transaction amount and unknown source" needs to be associated with the "suspicious fund source" representation. By coding these rules, the expansion and refinement of the basic representation are realized. Through the processing of the correlation logic, a more targeted, detailed and complete risk description is constructed on the basis of the basic representation, which more accurately reflects the risk characteristics behind the transaction.
[0159] The integrity of the associated risk representation is checked by means of a preset deviation integrity checklist to compensate for possible description omissions. The checklist contains the necessary elements of various risk descriptions. In terms of technical implementation, the associated risk representation data is automatically checked for completeness based on the checklist, and the missing content is supplemented by templates or rule engines. The integrity of the risk description is ensured and it conforms to the regulations, so that the final generated description is both comprehensive and accurate, providing a solid foundation for subsequent decision-making.
[0160] The risk description is optimized by eliminating redundant content to ensure that the description is concise and coherent, and to improve the readability and effectiveness of the report. In terms of technical implementation, redundant risk descriptions are removed by text processing algorithms, and the coherence and conciseness of the representation are optimized according to the optimization standards, such as using natural language processing techniques to remove redundant content and adjusting sentence structure. The readability of the description is improved on the premise of retaining key information, providing a more efficient risk assessment tool for decision-makers.
[0161] In one embodiment, according to the complexity of the fund flow level data and the frequency of regulatory parameter updates, the steps of generating risk weight factors by determining the proportion of each level according to the specification include:
[0162] S4051, according to the fund flow level data, obtain the account node sequence, extract the number of transfer accounts, account attributes and flow interval information in the account node sequence, and integrate to form level detail data.
[0163] S4052, obtain level complexity representation data according to level detail data;
[0164] S4053, obtain frequency interval data and statistical records of regulatory parameter update frequency, and divide them into corresponding intervals according to the time span in the frequency segmentation standard to form frequency interval data;
[0165] S4054, obtain update impact description data according to frequency interval data;
[0166] S4055, obtain initial proportion data according to level complexity representation data and update impact description data;
[0167] S4056, according to the initial proportion data and factor generation specification, obtain risk weight factor.
[0168] As described in steps S4051-S4056 above, the present application generates risk weight factors according to the complexity of the fund flow level data and the frequency of regulatory parameter updates, and determines the proportion distribution of each level according to the specification. Specifically, through multi-step detailed analysis, the fund flow level related features and the frequency of regulatory parameter updates are extracted, and finally the weight factors that can accurately reflect the risk are generated. These factors will be further used in risk assessment, decision-making and early warning to improve the risk identification ability of cross-border payment and other financial behaviors. In the financial industry, especially in the cross-border payment scenario, the complexity of fund flow and the frequent updates of regulatory requirements may affect the compliance and risk control of the payment process, so it is crucial to design a mechanism to dynamically calculate the risk weight factor: the fund flow level data contains information of multiple nodes, and the characteristics of each node (such as account attributes) and the flow interval have different degrees of influence on payment risk, so detailed analysis is needed for these level details; and the frequent update of regulatory parameters requires timely adjustment of the allocation of risk factors in a dynamically changing environment. Through the above process, the risk weight factor can be reasonably allocated based on the actual situation in the fund flow, thereby enhancing the accuracy and real-time performance of the risk assessment model.
[0169] The related features of the account nodes are extracted from the fund flow data to help understand the relationship between the nodes. Each account node in the fund flow may represent different roles (such as intermediary accounts, final receiving accounts, etc.), and the number of nodes, attributes, and flow intervals are crucial to risk assessment. For example, frequent flow may imply high risk, and specific attributes such as foreign accounts and non-resident accounts may increase compliance risk. Traditional methods usually only focus on explicit factors such as transaction amount and payment time, ignoring the diversity of account levels and the complexity of flow path. This problem is solved by detailed analysis of each node: technically, by gradually tracking the fund flow path, identifying the account nodes in each transaction, extracting information such as account category (such as personal account, company account), flow interval (time required for fund transfer), and whether it involves a transit account, etc., after data integration and preprocessing, level detail data is formed, providing a basis for subsequent level complex representation.
[0170] The characteristics of each node in the fund flow path are integrated to form higher-level complex representation data, and the complexity of the flow is revealed. The transfer of each account node is not only related to a single transaction, but also may involve multi-level flow. The node characteristics need to be synthesized to understand the path complexity and provide a basis for generating risk factors. Traditional methods cannot integrate various types of information, process each level of account data in isolation, and lack in-depth analysis of the correlation between levels. The present application solves this problem by converting hierarchical detail data into hierarchical complex representation data: Technically, the attributes of each account node, the flow interval and other information are aggregated, the relationship and interaction between nodes are analyzed, and factors such as the number of nodes, path complexity, and the potential contribution of each node to the overall risk are considered. The fund flow path is quantified and modeled to obtain the overall complexity and form the hierarchical complex representation data.
[0171] According to the update frequency of the regulatory parameters, frequency interval data is established for the fund flow activities in each time period. The update frequency of the regulatory parameters reflects the speed of change in the financial environment. By dividing the frequency interval, the influence of different update frequencies on the complexity of the fund flow path can be determined, and the flexibility of risk assessment can be dynamically adjusted. Traditional methods ignore the influence of the update frequency of the regulatory parameters and use fixed parameter standards. This problem is solved by dividing the frequency interval: Technically, the update frequency of the regulatory parameters is calculated, the update frequency data of each time period is obtained, and the data is classified into corresponding frequency intervals according to the preset time span standard. The risk assessment model is dynamically adjusted through classification to provide a basis for subsequent risk factor calculation.
[0172] According to the frequency interval data, the influence of the update of the regulatory parameters is analyzed, and influence description data is generated. Frequent updates of the regulatory parameters may have different effects on financial behavior. Data that accurately describes the influence of the update is needed to reflect its potential impact on the risk of fund flow. Technically, the specific content of the update of the regulatory parameters in different frequency intervals is analyzed, and the data describing the influence of the update is generated based on the update frequency characteristics to provide necessary basis for the generation of subsequent hierarchical risk weight factors.
[0173] The hierarchical complexity and the update frequency of the regulatory parameters are considered to calculate preliminary proportion data, which lays the foundation for risk weight factor calculation. The initial proportion data generated by analyzing the complexity of each level and the update of the regulatory parameters can provide key support for the final risk assessment. Technically, the hierarchical complex representation data and the update influence description data are combined, and the initial proportion of each level is calculated by algorithm. This data reflects the importance of each level in the fund flow path and the influence of the update frequency on it.
[0174] Based on the initial proportion data, final risk weight factors are generated according to specifications. These risk weight factors are calculated based on the proportions of each level and reflect the contribution of different levels and update frequencies to the overall risk, serving as an important basis for risk assessment and decision-making. Technically, the initial proportion data is combined with the factor generation specifications to calculate the risk weight factors for each level. These factors will be used in subsequent risk assessments to ensure that the assessment results dynamically reflect the risk situation in cross-border payments.
[0175] In one embodiment, the step of obtaining risk characteristic assessment information corresponding to transaction amount information, payment purpose information, and instruction initiation time information based on the feature correlation index includes:
[0176] S2051. Obtain multi-dimensional correlation data based on feature correlation index and information dimension classification criteria;
[0177] S2052. Obtain transaction amount-related related content based on the multi-dimensional related data, and obtain the correlation performance and correlation strength between the amount and other transaction elements based on the transaction amount-related related content, and generate amount-related feature data based on the correlation performance and correlation strength.
[0178] S2053. Based on the usage association fragments and usage feature extraction criteria in the multidimensional association data, obtain the usage association feature data;
[0179] S2054. Obtain time-related feature data based on the time-related segments and time feature extraction criteria in the multi-dimensional related data;
[0180] S2055. Obtain risk element data based on the amount-related characteristic data, purpose-related characteristic data, and time-related characteristic data;
[0181] S2056. Obtain risk characteristic assessment information based on the risk element data of the information segment.
[0182] As described in steps S2051-S2056 above, this invention uses a feature correlation index-based analysis method to assess the risk characteristics of cross-border payment transactions. Specifically, it obtains corresponding risk characteristic assessment information through correlation analysis of transaction amount information, payment purpose information, and instruction initiation time information, thereby generating compliance risk warning data and effectively identifying and warning of potential payment risks. This method addresses the complexity and high frequency of cross-border payments; a single data dimension (such as amount, purpose, or time) cannot capture the risk signals behind the transaction. Therefore, it is necessary to form a comprehensive risk assessment system through multi-type data correlation and feature extraction. This multi-type analysis not only improves the accuracy of risk detection but also enables risk warnings to reflect non-compliant or abnormal behaviors in transactions more promptly and accurately.
[0183] The relationship between different transaction characteristics is identified by the characteristic correlation index, which prepares for subsequent risk assessment. The characteristic correlation index quantifies the correlation between different characteristic dimensions, and the information dimension division standard ensures that each dimension characteristic accurately reflects the transaction. Traditional methods ignore the correlation between characteristics and only analyze single characteristics (such as only looking at transaction amounts). The information dimension (amount, purpose, time, etc.) division method is determined by pre-set characteristic correlation standards, the correlation between dimensions is analyzed based on the characteristic correlation index, and the correlation between dimensions is dynamically calculated and adjusted based on actual transaction data to obtain multi-dimensional correlation data containing all-dimensional correlation information, which lays the foundation for comprehensive assessment.
[0184] The correlation performance, strength, and other characteristics of transaction amounts and other factors (purpose, time) are analyzed to determine whether the transaction amount conforms to the normal mode or has potential risks. Traditional amount risk assessment ignores other risk factors behind the amount (such as unusual purpose and inconsistent time). The amount-related content is extracted from multi-dimensional correlation data, and statistical methods such as correlation coefficient and covariance are used to assess the correlation strength of the amount and other factors to generate amount correlation characteristic data.
[0185] Abnormal or abnormal purposes are identified through payment purpose correlation analysis. Payment purpose is an important component of transactions, and different purposes represent different risk levels. Existing methods treat purpose as a static factor and fail to capture its changes in different scenarios in real time. The purpose correlation segment in multi-dimensional correlation data is analyzed, and the purpose type, frequency, and trend are extracted based on the purpose feature extraction standard to identify transactions that do not conform to normal rules.
[0186] Potential abnormal behaviors are identified through transaction time information. Time characteristic analysis can reveal non-normal time period transactions (which may be caused by fraud, money laundering, etc.), which is a key to comprehensive risk assessment. Existing technologies simply extract time characteristics and only focus on specific time points, ignoring time intervals and periodic signals. The time correlation segment is extracted from multi-dimensional correlation data, and the time correlation characteristic data is obtained based on the time feature extraction standard. The time distribution rule is analyzed, and the accuracy of the assessment is enhanced by combining other dimension data.
[0187] The correlation characteristic data of the amount, purpose, and time dimensions is summarized to form a variety of risk factor data sets that comprehensively reflect the transaction risk level. Existing technologies independently process each dimension data and cannot form a comprehensive assessment system. The amount, purpose, and time correlation characteristic data are integrated to build a comprehensive risk factor set containing all transaction dimensions.
[0188] Through comprehensive analysis of the sub-information risk element data, risk characteristic evaluation information is generated, which provides a basis for transaction risk level division. The information is the core data of risk early warning and directly determines the subsequent early warning strategy and processing measures. The traditional method relies on static rules and cannot be dynamically adjusted. The risk assessment model is used to process the sub-information risk element data to generate evaluation results containing risk level, potential risk points, risk types and other information, which are important basis for subsequent risk early warning
[0189] In one embodiment, the step of obtaining sub-information risk element data according to the amount associated characteristic data, the use associated characteristic data and the time associated characteristic data comprises:
[0190] S20551, obtaining amount risk element data according to the amount associated characteristic data;
[0191] S20552, obtaining use risk element data according to the use associated characteristic data;
[0192] S20553, obtaining time risk element data according to the time associated characteristic data;
[0193] S20554, generating sub-information risk element data according to the amount risk element data, the use risk element data and the time risk element data.
[0194] As described in steps S20551-S20554, the present application extracts risk elements from the amount associated characteristic data, the use associated characteristic data and the time associated characteristic data through reasonable feature data association and extraction method, and finally integrates to generate sub-information risk element data.
[0195] Obtain amount risk element data according to the amount associated characteristic data. Extract the amount risk element. Amount is an important risk source in cross-border payment, especially high-value transactions mean higher complexity of fund flow. Accurate extraction of this element is crucial to assess whether the transaction meets regulatory requirements. In terms of technical solutions, first analyze the relationship between amount and other associated characteristics, obtain the amount data distribution, and determine its position in the overall transaction; focus on analyzing payment purpose and time node for large transactions, such as abnormal large transactions need to combine purpose and time to judge whether it involves cross-border money laundering or illegal fund flow. At the same time, according to the factors such as the association strength and the change trend of the amount, the risk coefficient is calculated, and the risk is evaluated by establishing the correlation degree model between the amount and other transaction elements, for example, when the transaction amount exceeds the threshold and the purpose is fund remittance, a higher amount risk element data is generated.
[0196] According to the use-related feature data, use risk factor data is acquired. This step aims to deduce potential risks by analyzing payment use features, and the risk level is directly related to the legality and compliance of the use, such as “personal remittance” has a lower risk, while “inter-enterprise fund circulation” and large amount have a higher risk. In technical implementation, first, the payment purpose, payee information, transaction description and other data are extracted according to the use type, and then combined with the amount, time and other information for joint analysis to identify high-risk uses that may involve illegal activities such as gambling and terrorist financing; by comparing the use data with industry standards and regulatory rules, compliance is determined and use risk factor data is generated, for example, if the large transaction of “import payment” use does not match the trade legality and use description, a higher use risk factor is generated.
[0197] According to the time-related feature data, time risk factor data is acquired. The goal of this step is to extract time dimension risk factors. High-risk transactions often occur in specific time windows such as holidays and night, and identifying these time characteristics can improve the accuracy of early warning. In the technical solution, first, the transaction time series data is analyzed to identify time node anomaly patterns, such as large amount transactions occurring at 1 am have a higher risk level; then the transaction time is compared with historical transaction time data to assess whether it matches the normal transaction pattern, for example, transactions occurring in low-frequency trading periods are determined as high-risk and time risk factor data is generated.
[0198] According to the amount risk factor data, use risk factor data and time risk factor data, sub-information risk factor data is generated. The goal of this step is to integrate the three types of risk factors to achieve comprehensive risk assessment. Single dimension risk factor cannot reflect the overall risk of the transaction, and after integration, a more complete risk profile can be formed. In technical implementation, first, the three types of risk factor data are weighted and fused, and the weights are adjusted according to the importance, relevance and transaction scenario of the factors (such as the amount and time correlation is more important than the use in some scenarios, and the use is more critical in legality review); then, through comprehensive analysis of the fused risk data, the overall risk level of the transaction is generated, and finally the sub-information risk factor data is formed.
[0199] In one embodiment, the step of generating sub-information risk factor data according to the amount risk factor data, use risk factor data and time risk factor data includes:
[0200] S205541, acquiring structured amount risk factor data according to the amount risk factor data;
[0201] S205542, acquiring structured use risk factor data according to the use risk factor data;
[0202] S205543, acquiring structured time risk factor data according to the time risk factor data;
[0203] S205544, correspond the structured amount risk factor data, the structured use risk factor data and the structured time risk factor data to the transaction amount, the payment use and the instruction initiation time respectively, and generate sub-information risk factor data according to the transaction amount, the payment use and the instruction initiation time.
[0204] As described in steps S205541-S205544, the application extracts risk factor data from the amount, use and time dimensions and generates sub-information risk factor data through structured processing to support cross-border payment compliance risk early warning detection, thereby more effectively evaluating and predicting transaction risks and improving the accuracy of risk identification and early warning, and ultimately realizing automated risk detection and early warning.
[0205] In the bank-enterprise direct connection cross-border payment scenario, the amount, use, time and other key elements contained in the transaction information have inherent correlation and directly affect payment compliance and risk level. To effectively evaluate potential risks, not only the extraction of these element data needs to be accurate, but also the correlation between them needs to be mined to reveal potential risks under different transaction modes through classification, correlation and structured analysis.
[0206] The structured amount risk factor data is obtained according to the amount risk factor data. This step aims to convert the original amount risk factor data into a standardized structure. Amount is a core element of transaction, which is directly related to compliance and risk level, and needs to be accurately structured. In technical implementation, first, extract basic information from the amount field of the transaction log, including the size of each transaction amount and fluctuation, etc.; then classify the amount according to the preset rules, and generate structured data through specific algorithms. For example, when the amount exceeds the threshold, it is marked as high risk, and frequent fluctuations within a short period of time are determined as abnormal fund flow and trigger an early warning signal. This structured processing can accurately identify abnormal transactions in the amount dimension and provide key support for risk assessment.
[0207] The structured use risk factor data is obtained according to the use risk factor data. Payment use is related to fund flow, source and destination, and some uses (such as cross-border sensitive remittance and suspicious financing) imply high compliance risk and need detailed structured processing. In implementation, first, extract payment use information from the original use risk factor data (such as the transaction use field); then classify and analyze according to specific standards and algorithms, classify the use in detail, label the risk level according to the characteristics, and standardize the use type, purpose, beneficiary and other information into structured data. For example, “illegal financing” and “money laundering” are directly marked as high risk and trigger strict review and monitoring. The structured use data can help quickly lock high-risk transaction scenarios.
[0208] According to the time risk factor data acquisition structure time risk factor data. Time characteristics have implicit correlations with high-risk behaviors such as money laundering and terrorist financing. Patterns such as high-frequency trading and night trading often imply risks, which need to be mined through structured processing of time dimension risks. In the step, first, the transaction time information is extracted from the original time risk factor data; then, combined with the characteristics of transaction time, the time window analysis algorithm is used for processing to identify abnormal time patterns. For example, high-frequency short-time trading, large amount of transactions in non-active period such as early morning are marked as high risk. Structured time data can improve the risk assessment system and improve the prediction accuracy combined with other factors.
[0209] The three types of structured risk factor data are respectively matched with the transaction amount, payment purpose and instruction initiation time field to generate sub-information risk factor data. This step is the core of the fusion of multiple types of data, and needs to realize the accurate docking and integration of structured risk data and transaction original fields. First, the association mapping is established: the structured amount data is associated with the transaction amount field, the structured purpose data is associated with the payment purpose field, and the structured time data is associated with the instruction initiation time field, so as to ensure that the risk characteristics of each transaction are closely bound with the original information; then, the three types of data are integrated through the fusion algorithm to form sub-information risk factor data containing multiple types of risk information.
[0210] The above only describes the preferred embodiments of the present application, and does not limit the patent scope of the present application, and any equivalent results or equivalent process transformations obtained by using the content of the specification and drawings, or direct or indirect application in other related technical fields, are also included in the patent protection scope of the present application.
Claims
1. A compliance risk warning and detection method for direct bank-enterprise cross-border payments, characterized in that: include: Obtain the original transaction sequence of cross-border payments between banks and enterprises, and simultaneously collect transaction object information, fund flow data, and error-related regulatory parameter sequences; Obtain the transaction pattern component based on the original transaction sequence; Preliminary risk warning parameters are generated based on the transaction pattern components and error-related regulatory parameter sequence. Obtain the cumulative number of payment transactions, and generate an early warning threshold factor and a risk weight factor based on the cumulative number of transactions and fund flow data; The initial risk warning parameters, warning threshold factors, and risk weight factors are adaptively fused to generate a transaction risk level. Determine whether the transaction risk level is lower than the preset level; If the value is less than the threshold, the transaction is considered to be within a safe range, corresponding to the transaction risk level. If the risk level is greater than the risk level, the transaction is deemed to be at risk, and an early warning message is generated based on the risk level.
2. The compliance risk early warning and detection method for direct bank-enterprise cross-border payments according to claim 1, characterized in that, The step of obtaining the transaction pattern component based on the original transaction sequence includes: A classification segmentation sequence is obtained based on the original transaction sequence, and transaction data groups are obtained based on the classification segmentation sequence; The transaction field set is obtained by grouping the transaction data, wherein the transaction field set includes transaction amount information, payment purpose information, and instruction initiation time information; Transaction feature fragments are obtained based on transaction amount information, payment purpose information, and instruction initiation time information, and transaction data is split into transaction time sequence feature information according to fixed time windows; The feature correlation index is obtained based on the transaction timing characteristics and the error-related regulatory parameter sequence. Based on the aforementioned feature correlation index, risk characteristic assessment information corresponding to transaction amount information, payment purpose information, and instruction initiation time information is obtained; The transaction pattern component is obtained based on the risk characteristic assessment information corresponding to the transaction amount information, payment purpose information, instruction initiation time information, and preset screening criteria.
3. The compliance risk early warning and detection method for direct bank-enterprise cross-border payments according to claim 1, characterized in that, The step of generating preliminary risk warning parameters based on the transaction pattern components and error-related regulatory parameter sequences includes: Obtain a preset regulatory parameter mapping table, break down the constituent elements of the transaction mode components, and extract matching regulatory parameters to form a subset by comparing the correspondence between elements and parameters in the preset regulatory parameter mapping table. Based on the subset of associated regulatory parameters, obtain the completeness and conformity of the required fields of each subset, and generate compliance feature requirements based on the completeness and conformity of the required fields. The actual characteristic description of the transaction pattern component is compared with the compliance characteristic requirements corresponding to the associated regulatory parameter subset to obtain the pattern compliance deviation degree; Obtain the corresponding risk statement based on the degree of deviation from the compliance of the pattern, and generate a preliminary risk description based on the risk statement; The preliminary risk description is matched with the risk scenarios in the risk level correspondence table, the risk quantification identifier corresponding to the matching scenario is extracted, and the preliminary risk coefficient is calculated based on the risk quantification identifier. Based on the preliminary risk coefficient and parameter dynamic adjustment instructions, and combined with the latest changes in regulatory parameters, a revised preliminary risk coefficient is generated, and then preliminary risk warning parameters are obtained based on the revised preliminary risk coefficient.
4. The compliance risk early warning and detection method for direct bank-enterprise cross-border payments according to claim 1, characterized in that, The steps of obtaining the cumulative number of payment transactions and generating early warning threshold factors and risk weight factors based on the cumulative number of transactions and fund flow data include: The cumulative number of payment transactions and transaction timestamps are obtained from the bank-enterprise direct connection transaction logs. Each transaction record in the transaction log is traversed, the total number of records is counted to obtain the cumulative number of transactions, and the time field of each record is extracted to obtain the transaction timestamp. The transaction timestamps are categorized into corresponding time windows according to preset time intervals, and the number of transaction records in each window is counted to obtain the transaction frequency per unit time. Based on the order of account receipt in the fund flow data, and combined with the account flow trajectory map, the fund flow hierarchy data is obtained by marking the levels of intermediary accounts and the number of nodes through which the funds pass. The cumulative number of transactions and the frequency of transactions per unit time are compared with similar data in the threshold benchmark dataset, and the threshold benchmark corresponding to the matching data is extracted as the early warning threshold factor. Based on the complexity of the fund transfer data at each level and the frequency of regulatory parameter updates, risk weight factors are generated by determining the proportion of each level in accordance with regulations.
5. The compliance risk early warning and detection method for direct bank-enterprise cross-border payments according to claim 1, characterized in that, The steps for generating a transaction risk level by adaptively fusing preliminary risk warning parameters with warning threshold factors and risk weight factors include: Standardized risk parameters are obtained based on the preliminary risk warning parameters and parameter normalization standards. By comparing the dimensional conversion requirements of each risk indicator in the parameter normalization standards, the different dimensions of the preliminary risk warning parameters are converted into values within a unified range. Extract the indicator values from the standardized risk parameters, find the corresponding threshold ranges of similar indicators in the early warning threshold factors, record the threshold intervals where the indicator values are located, and obtain the threshold comparison results. Based on the proportion of each dimension in the risk weighting factor, the risk information of different dimensions in the threshold comparison results is integrated to generate weighted risk information; Based on the adjustment experience of similar risks in historical early warning results, the detailed description of weighted risk information is optimized in accordance with the standard to obtain dynamically corrected risk information; By comparing the core risk indicators in the dynamically revised risk information with the risk level classification range, the corresponding level interval is determined, and the level interval attribution information is obtained. Based on the correspondence between the grade range attribution information and the grade name, the range attribution is converted into a transaction risk level.
6. The compliance risk early warning and detection method for direct bank-enterprise cross-border payments according to claim 3, characterized in that, The steps of obtaining the corresponding risk statement based on the degree of deviation from compliance with the pattern, and generating a preliminary risk description based on the risk statement, include: Based on the standards for decomposing the deviation degree and deviation characteristics of the pattern, detailed deviation data is obtained; Based on the deviation details data and the corresponding risk description table, obtain the basic risk description data; Obtain the preset statement association logic, and obtain the associated risk statement data based on the basic risk statement data and the preset statement association logic; Obtain the preset deviation integrity checklist, and obtain the supplementary risk statement data based on the associated risk statement data and the preset deviation integrity checklist; Remove duplicate statements from the structured risk description data, adjust the coherence and conciseness of the statements according to the description simplification standard, and generate a preliminary risk description.
7. The compliance risk early warning and detection method for direct bank-enterprise cross-border payments according to claim 4, characterized in that, Based on the complexity of the fund flow hierarchy data and the frequency of regulatory parameter updates, the steps for determining the proportion of each hierarchy and generating risk weight factors according to regulations include: Based on the hierarchical data of fund transfer, the account node sequence is obtained, and the number of transfer accounts, account attributes and transfer interval information in the account node sequence are extracted and integrated to form hierarchical detailed data. Obtain hierarchical complex representation data based on hierarchical detailed data; Obtain statistical records of frequency interval data and regulatory parameter update frequency, and classify the statistical records of frequency interval data and regulatory parameter update frequency into the corresponding intervals according to the time span division in the frequency segmentation standard to form frequency interval data; Obtain updated impact description data based on frequency range data; Initial percentage data are obtained based on hierarchical complex representation data and updated impact description data; Risk weight factors are obtained based on the initial percentage data and factor generation specifications.
8. The compliance risk early warning and detection method for direct bank-enterprise cross-border payments according to claim 2, characterized in that, The steps for obtaining risk characteristic assessment information corresponding to transaction amount information, payment purpose information, and instruction initiation time information based on the aforementioned feature correlation index include: Based on the feature correlation index and information dimension classification criteria, obtain multi-dimensional correlation data; Based on the multi-dimensional correlation data, obtain the relevant content related to the transaction amount, and based on the relevant content related to the transaction amount, obtain the correlation performance and correlation strength between the amount and other transaction elements, and generate the amount correlation feature data based on the correlation performance and correlation strength. Based on the usage-related fragments and usage feature extraction criteria in the multidimensional related data, usage-related feature data is obtained; Based on the time-related segments and time feature extraction criteria in the multidimensional related data, time-related feature data is obtained; Based on the data related to monetary amount, usage, and time, obtain risk factor data for sub-information. Risk characteristic assessment information is obtained based on risk element data.
9. The compliance risk early warning and detection method for direct bank-enterprise cross-border payments according to claim 8, characterized in that, The steps for obtaining risk factor data based on monetary value-related characteristics, usage-related characteristics, and time-related characteristics include: Obtain data on monetary risk elements based on monetary correlation characteristic data; Obtain application risk factor data based on application-related characteristic data; Obtain time risk element data based on time-related characteristic data; Based on the data on monetary risk factors, usage risk factors, and time risk factors, sub-information risk factor data is generated.
10. The compliance risk early warning and detection method for direct bank-enterprise cross-border payments according to claim 9, characterized in that, The steps for generating risk element data based on monetary risk element data, usage risk element data, and time risk element data include: Obtain structured monetary risk element data based on monetary risk element data; Obtain structured use risk factor data based on use risk factor data; Obtain structured time risk element data based on time risk element data; Structured amount risk factor data, structured purpose risk factor data, and structured time risk factor data are mapped to transaction amount, payment purpose, and instruction initiation time, respectively, and sub-information risk factor data are generated based on the transaction amount, payment purpose, and instruction initiation time.
Citation Information
Patent Citations
Transaction risk prediction method and device
CN116797365A
Abnormal transaction identification and early warning system based on financial time sequence characteristics
CN120031572A