Internal control compliance review method and system based on process mining

By constructing process chains through process mining technology, identifying and quantifying interference events, calculating process interference information entropy, and combining process reconstruction and compliance risk index analysis of interference events, the problem of low efficiency and insufficient accuracy in existing compliance review methods is solved, and efficient and accurate review of complex processes is achieved.

CN121660633APending Publication Date: 2026-03-13SHANDONG SHANYI ACCOUNTING FIRM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-10
Publication Date
2026-03-13

AI Technical Summary

Technical Problem

Existing compliance review methods rely on static analysis and manual auditing, which are inefficient and cannot accurately identify disruptive events and their risks in complex processes, resulting in insufficient review accuracy and delayed response.

Method used

By constructing process chains through process mining technology, identifying and quantifying disruptive events, calculating the entropy of process disruption information, and combining process reconstruction and compliance risk index analysis of disruptive events, a dual review can be achieved.

Benefits of technology

It improves the efficiency and accuracy of compliance reviews, enabling the quantification of the impact of disruptive events and the optimization of process refactoring, thereby enhancing the accuracy and efficiency of reviews.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121660633A_ABST
    Figure CN121660633A_ABST
Patent Text Reader

Abstract

The invention discloses an internal control compliance review method and system based on process mining, and relates to the technical field of intelligent management.The method comprises the steps that a process chain constructed based on an event sequence is extracted from a process event table, and interference events are input; performing interference assignment on each flow node in the flow chain according to the interference event to obtain a flow interference information entropy, and outputting the flow interference information entropy as a first compliance review result; reconstructing the process chain according to the interference event to obtain a reconstructed process chain, and performing compliance risk index analysis to obtain a second compliance review result; and outputting a compliance review result according to the first compliance review result and the second compliance review result. The technical problems that an existing compliance review method depends on static analysis and manual auditing, the efficiency is low, and interference events and risks thereof in a complex process cannot be accurately recognized are solved, and the technical effects that the influence of the interference events is quantified based on process mining, process reconstruction optimization is conducted, and the review efficiency and accuracy are improved are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of intelligent management technology, specifically to an internal control compliance review method and system based on process mining. Background Technology

[0002] In an enterprise's information-based operational environment, the execution of business processes often relies on the collaboration of multiple systems, roles, and resources. The increasingly complex process structures make compliance reviews of internal controls increasingly difficult. Existing compliance review methods largely depend on manual checks or static rule comparisons, making it difficult to promptly identify interference factors during process execution, such as missing nodes, insufficient resources, system anomalies, and changes in the external environment. Furthermore, they cannot quantify the actual impact of these interferences on the process, resulting in insufficient review accuracy and delayed response. Summary of the Invention

[0003] This application provides an internal control compliance review method and system based on process mining, which addresses the technical problems of existing compliance review methods that rely on static analysis and manual auditing, resulting in low efficiency and an inability to accurately identify disruptive events and their risks in complex processes.

[0004] The first aspect of this application provides an internal control compliance review method based on process mining. The method includes: extracting a process chain constructed based on an event sequence from a process event table; recording interference events in the process chain, wherein the interference events are disturbance events affecting process compliance, and the types of interference events include node-level, resource-level, system-level, and external-level; assigning interference values ​​to each process node in the process chain according to the interference events to obtain process interference information entropy, and outputting the process interference information entropy as a first compliance review result; reconstructing the process chain according to the interference events to obtain a reconstructed process chain, performing compliance risk index analysis on the reconstructed process chain to obtain a second compliance review result; and outputting the compliance review result of the process chain based on the first compliance review result and the second compliance review result.

[0005] A second aspect of this application provides an internal control compliance review system based on process mining. The system includes: a process chain extraction module for extracting process chains constructed based on event sequences from a process event table; an interference event input module for inputting interference events in the process chain, wherein the interference events are disturbance events affecting process compliance, and the types of interference events include node-level, resource-level, system-level, and external-level; an interference assignment module for assigning interference values ​​to each process node in the process chain according to the interference events, obtaining process interference information entropy, and outputting the process interference information entropy as a first compliance review result; a compliance risk analysis module for reconstructing the process chain according to the interference events to obtain a reconstructed process chain, performing compliance risk index analysis on the reconstructed process chain to obtain a second compliance review result; and a review result output module for outputting the compliance review result of the process chain based on the first compliance review result and the second compliance review result.

[0006] One or more technical solutions provided in this application have at least the following technical effects or advantages: The internal control compliance review method and system based on process mining provided in this application belong to the field of intelligent management technology. By introducing process mining technology, it performs interference identification, interference assignment, and information entropy quantification analysis on the process chain constructed by the process event table. Combined with process reconstruction based on interference events and compliance risk index calculation, it realizes a dual review of process compliance from two dimensions: interference impact and process reconstruction risk. It solves the technical problems of existing compliance review methods that rely on static analysis and manual auditing, which are inefficient and unable to accurately identify interference events and their risks in complex processes. It achieves the technical effect of quantifying the impact of interference events based on process mining and optimizing process reconstruction, thereby improving the efficiency and accuracy of the review. Attached Figure Description

[0007] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0008] Figure 1 A flowchart illustrating the internal control compliance review method based on process mining provided in this application embodiment; Figure 2 A schematic diagram of the internal control compliance review system based on process mining provided in this application embodiment.

[0009] Figure labeling: Process chain extraction module 11, interference event entry module 12, interference assignment module 13, compliance risk analysis module 14, review result output module 15. Detailed Implementation

[0010] This application provides an internal control compliance review method and system based on process mining, which addresses the technical problems of existing compliance review methods that rely on static analysis and manual auditing, resulting in low efficiency and an inability to accurately identify disruptive events and their risks in complex processes.

[0011] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0012] It should be noted that the terms "first," "second," etc., in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or modules not explicitly listed or inherent to such processes, methods, products, or devices.

[0013] Example 1, as Figure 1 As shown, this application provides an internal control compliance review method based on process mining, which includes: P10: Extract the process chain built based on the event sequence from the process event table.

[0014] Specifically, the process event table is the key data source for this step. It's a data table that records all business process events, with each record containing information about the activity's execution, such as timestamps, activity names, and the personnel involved. For example, in an enterprise's procurement process, the event table records specific information about each stage, from initiating a purchase request, approval, order generation to goods acceptance. This information forms the foundational data for process analysis. By analyzing these events, the execution path of the entire business process can be reconstructed, allowing for process modeling and providing foundational data for subsequent compliance reviews and risk analyses.

[0015] A process event table typically includes fields such as event ID, event timestamp, activity name, executor, and resource information. The event ID is used to distinguish different event records, the timestamp indicates the specific time the event occurred, the activity name indicates the specific activity or process node corresponding to the event, the executor records the personnel or roles who perform the activity, and the resource information includes the personnel, equipment, etc. required to perform the activity.

[0016] In extracting the process chain, the first step is to sort each record in the process event table based on the event timestamps, generating an event sequence. The sorted events reflect the chronological order of process execution, ensuring the correct execution order of each activity. Next, process nodes are identified by activity names, grouping similar activities into the same category. Then, the sequential relationships between events are analyzed to determine which process nodes depend on others; these dependencies can be deduced from the event timestamps. For example, if event A's timestamp is earlier than event B's, then node A will be the predecessor node of node B in the process chain. Finally, through the sorting and dependency analysis described above, a complete process chain can be reconstructed, reflecting the execution order of the entire business process from start to finish.

[0017] This process can be achieved using process mining algorithms. By identifying the causal relationships and flow paths between events, a process model is generated, which in turn forms a process chain. For example, by analyzing the procurement process event table using process mining algorithms, it can be discovered that a procurement request initiation event is inevitably followed by an approval event, and then order generation, thus constructing a clear process chain. The process chain consists of a series of process nodes, which are connected by dependencies to form a complete business process path, providing data support for subsequent interference analysis and compliance review.

[0018] P20: Record the interference events of the process chain. The interference events are disturbance events that affect the compliance of the process. The types of interference events include node level, resource level, system level and external level.

[0019] Optionally, participants can record and categorize disruptive events that impact process compliance. Disruptive events are factors that may negatively affect the smooth operation and compliance of a process during its execution. Identifying and analyzing these disruptive events helps assess process stability and compliance, uncover potential compliance risks, and provide a basis for subsequent optimization.

[0020] First, the entry of interference events is based on the process chain extracted in the previous step. Building upon this process chain, each process node needs to be examined in detail to identify which nodes are affected by external or internal factors. Interference events can be categorized into four types based on their source and level of impact: node-level, resource-level, system-level, and external-level.

[0021] Node-level interference events refer to events that affect the normal execution or status of a specific process node. These interference events are directly related to a specific node in the process chain and typically manifest as abnormal behavior or status of that node. For example, in an approval process, an approval node might make an non-compliant approval decision due to the approver's failure to complete the approval operation within the stipulated time or a conflict of interest between the approver and the applicant. Similarly, in the data entry stage, operators might enter incorrect data due to negligence, leading to deviations in subsequent process handling. Node-level interference events usually reflect abnormalities in a specific part of the process. Although their impact is relatively limited, they can have a direct and significant impact on the compliance of the process. Therefore, when recording interference events, it is necessary to record in detail the specific manifestations of each node-level interference event, the time of occurrence, the personnel or system modules involved, and the possible consequences, in order to conduct targeted analysis and processing later.

[0022] Resource-level disruptions involve various resources required for process operation, including human, material, and financial resources. For example, in a procurement process, if the raw materials provided by a supplier do not meet quality requirements, or if the procurement personnel are on sick leave, causing delays in the procurement task, these situations fall under the category of resource-level disruptions. Resource-level disruptions may affect the normal execution efficiency and quality of the process, thereby indirectly affecting its compliance. In practice, the recording of resource-level disruptions requires attention to aspects such as resource supply, quality standards, personnel availability, and the rationality of resource allocation. For example, recording supplier information for raw materials, quality inspection results, procurement personnel attendance, and detailed resource allocation information is crucial for a comprehensive understanding of the background and impact of resource-level disruptions.

[0023] System-level disruption events refer to interference caused by problems with information systems or technology platforms. Modern enterprise processes often heavily rely on information technology systems for automation and efficient management. For example, a malfunction in a business process management system can prevent processes from functioning correctly, or unreasonable permission settings can allow certain users to perform unauthorized operations; these situations all fall under the category of system-level disruption events. System-level disruption events can affect the stability of the entire process, have a wide-ranging impact, and may lead to serious compliance risks. When recording system-level disruption events, it is necessary to record the specific manifestations of the system failure, the time of occurrence, the affected process steps, and the system configuration information. Simultaneously, it is also necessary to pay attention to the rationality of system permission settings, recording detailed permission allocation information and potential permission vulnerabilities to facilitate subsequent system-level optimization and improvement.

[0024] External disruption events refer to factors originating from outside the enterprise that may affect process compliance. These factors are typically beyond the enterprise's internal control but have a significant impact on process operation and compliance. For example, changes in policies and regulations may render existing processes incompatible with new compliance requirements, or drastic fluctuations in the external market environment may lead to a sharp increase in raw material prices, thereby affecting the budgeting and execution of procurement processes. These are all considered external disruption events. External disruption events require enterprises to consider the uncertainty and dynamic changes of the external environment when designing and managing processes. When recording external disruption events, it is necessary to closely monitor external changes, market dynamics, and updates to industry standards. For example, record the content of relevant regulatory changes, their effective dates, and their specific impact on enterprise processes; at the same time, monitor the trend and magnitude of market raw material price fluctuations and their potential impact on the enterprise's procurement processes, so as to adjust processes in a timely manner to adapt to changes in the external environment.

[0025] When recording these interference events, it is necessary to analyze the execution process of each node in the workflow chain, combined with various problems that may arise in actual operation, and record in detail the occurrence, type, severity, and impact on the workflow of each interference event. Each interference event should clearly indicate its time of occurrence, the node where it occurred, and its specific impact on workflow compliance. For example, if a node cannot be completed due to a system failure, a system-level interference event will be recorded, along with an explanation of the risk level and compliance impact caused by the event. Establishing standardized data entry templates and processes can improve the efficiency and quality of data collection. Finally, in the classification and labeling stage of interference events, it is necessary to accurately classify them into the corresponding types based on their characteristics and scope of impact, and provide detailed labels and explanations. This helps to quickly identify and handle different types of interference events in subsequent analysis, improving the efficiency and accuracy of the analysis.

[0026] P30: Assign interference values ​​to each process node in the process chain according to the interference event to obtain the process interference information entropy, and output the process interference information entropy as the first compliance review result. The interference event includes an interference description field, which includes the interference type, the process nodes affected by the interference, and the type of offset caused by the interference.

[0027] Furthermore, in this embodiment, step P30 further includes assigning interference values ​​to each process node in the process chain according to the interference event: P31: Perform a traversal scan of each process node in the process chain according to the interference event to obtain the interference vector of each process node; P32: Calculate the node interference information entropy of each process node based on the interference vector of each process node, perform weighted entropy calculation on the node interference information entropy of each process node, and output the process interference information entropy.

[0028] It should be understood that, based on the recorded interference events, interference values ​​are assigned to each process node in the process chain, and the process interference information entropy is calculated. In other words, by identifying and quantifying interference events, the compliance risks faced by each process node during execution are assessed, and the compliance review results of the entire process are output by combining these risks.

[0029] In practical implementation, the first step is to traverse and scan each process node in the process chain. During the scan, the system quantifies the type, degree of impact, and specific effect of each interference event on the process node. Quantification can be done numerically, assigning a numerical value to each interference event and its corresponding degree of impact, such as the length of delay or the severity of the impact, thus forming an interference value. The larger the interference value, the higher the compliance risk faced by that node. By determining the type and degree of interference experienced by each process node, an interference vector can be generated for each node. The interference vector is a multi-dimensional numerical representation that reflects the node's interference status under different interference types. For example, a node may be simultaneously affected by node-level and resource-level interference; its interference vector will contain the quantified values ​​for both types of interference. The description fields of the interference event include the interference type, the process node affected by the interference, and the type of offset caused by the interference. This information provides crucial basis for assigning interference values.

[0030] After obtaining the disturbance vector for each process node, the next step is to calculate the node disturbance information entropy for each process node based on these disturbance vectors. Information entropy is an indicator that measures the degree of uncertainty or disorder of information, and in this application, it is used to quantify the disturbance complexity of each node. Specifically, the higher the node disturbance information entropy, the more disturbance factors the node experiences during execution, and the worse the stability and compliance of the process. The node disturbance information entropy can be calculated based on the values ​​of each dimension of the disturbance vector using the entropy calculation formula. This formula needs to consider the weights of different disturbance types to reflect the relative impact of different disturbance types on the node. For example, node-level disturbances may have a greater impact on the compliance of the node, so they are given a higher weight when calculating the node disturbance information entropy. Through this quantification method, the degree of uncertainty of each process node after being disturbed can be accurately assessed, thereby providing data support for subsequent overall evaluation.

[0031] Subsequently, weighted entropy calculations are performed on the node interference information entropy of each process node to obtain the overall process interference information entropy. Weighted entropy calculation is used to reflect the relative importance of each node in the process chain. The compliance of different nodes has varying degrees of impact on the entire process; critical nodes may be crucial to the completion of the process, therefore their interference entropy is assigned higher weights. Through weighted processing, the overall uncertainty of the entire process chain after being affected by interference events can be comprehensively reflected, resulting in the overall process interference information entropy of the entire process chain.

[0032] The calculated process disturbance information entropy serves as the output of the first compliance review, providing a quantitative basis for subsequent compliance analysis. A higher process disturbance information entropy indicates more complex disturbances to the process chain, greater uncertainty, and higher compliance risk; conversely, a lower entropy indicates that the process chain maintains high stability and compliance even after being disturbed. In practical applications, the first compliance review result can be used to preliminarily assess the compliance status of the process chain. For example, companies can determine whether the process disturbance information entropy is within an acceptable range based on a preset threshold. If it exceeds the threshold, it indicates potential compliance risks in the process, requiring further analysis and optimization; if it is within the threshold, it indicates that the process still maintains good compliance under the current disturbance conditions.

[0033] Furthermore, step P31 in the embodiments of this application also includes: P31-1: Collect historical interference event samples corresponding to each process node; P31-2: Identify the historical prior probability of each interference event type in the historical interference event samples corresponding to each process node; P31-3: Filter the interference event types with historical prior probabilities greater than the preset expected probability and identify each process node; P31-4: Match the interference events with the identified interference event types of each process node according to the interference events, and extract the interference vector of each process node based on the matched interference events.

[0034] Optionally, the process of identifying interference events and extracting interference vectors can be further refined. Before assigning interference values ​​to process nodes, historical interference event samples for each process node must first be collected. This step requires the system to access and extract historical interference event data stored in the database, which records interference events that occurred at the same or similar process nodes in the past. The collected data should include detailed information such as the type of interference event, the time of occurrence, the scope of impact, and the processing results. By collecting these historical samples, a rich data foundation can be provided for subsequent probabilistic analysis.

[0035] Next, for each process node, the historical prior probability of each type of interference is calculated based on the historical interference event samples collected. This process is accomplished by statistically analyzing the types of interference encountered by each process node in the past and their frequency. For example, if a process node encountered resource-level interference 30 times in the past 100 operations, then the historical probability of that interference type is 30%. By statistically analyzing the frequency of different interference types, a prior probability basis can be provided for subsequent interference analysis. These prior probabilities reflect the prevalence of various interference event types on different process nodes in historical data, providing a quantitative basis for subsequent screening and matching.

[0036] Subsequently, based on the prior probabilities of historical disruptive events, event types with a frequency higher than a preset expected probability threshold are selected. The preset expected probability is a threshold used to determine which event types are sufficiently significant in the current analysis. For example, if the preset expected probability is 10%, only event types with a historical prior probability greater than 10% will be retained and used in subsequent analyses. This selection process helps focus on event types that have a significant impact on process nodes, avoiding the inclusion of overly rare or unimportant disruptive events.

[0037] Finally, based on the selected interference event types, historical interference events for each process node are matched, and interference vectors are extracted. For example, the currently entered interference event is compared with previously selected interference event types with a high probability of occurrence. If the current interference event matches the identified interference event type of a node, relevant interference features, such as interference intensity and impact range, are extracted from that event to form the interference vector for that process node. The interference vector is a multi-dimensional data structure that comprehensively reflects the state of the process node under the influence of the current interference event. For example, if a node is identified as potentially subject to node-level and resource-level interference, and the currently entered interference events include both types, then the node's interference vector will contain quantitative features of both interference types. These interference vectors provide a quantitative basis for subsequent interference information entropy calculations and help understand the potential risks of each node.

[0038] Furthermore, based on the interference vector of each process node, the node interference information entropy of each process node is calculated. In this embodiment, step P32 further includes: P32-1: Calculate the node interference probability distribution based on the interference vector of each process node, and output the node interference probability distribution set; P32-2: Calculate the node interference information entropy of each process node by using the Shannon entropy algorithm on the node interference probability distribution set.

[0039] In one possible embodiment of this application, the interference information entropy of each process node is further analyzed using the interference vector of each process node to quantify the compliance risks faced by each node. Before calculating the node interference information entropy of each process node, it is first necessary to calculate the node interference probability distribution based on the interference vector of each process node. The key to this process is to derive the probability distribution of interference events occurring at each node through various dimensions in the interference vector, such as interference type, degree of impact, and frequency of occurrence. Specifically, for each process node, the values ​​of each dimension in its interference vector can be analyzed. These values ​​reflect the frequency or intensity of different interference types occurring at that node. By statistically analyzing the distribution of these values, the interference probability distribution of that node can be obtained. For example, if the interference vector of a process node shows that the probability of it being affected by node-level interference is 0.4, the probability of resource-level interference is 0.3, the probability of system-level interference is 0.2, and the probability of external-level interference is 0.1, then these probability values ​​together constitute the interference probability distribution of that node. Repeating this process for all process nodes can output a set containing the interference probability distributions of all nodes. These distributions reflect the relative frequency of each type of interference, thus revealing the distribution of interference risks faced by each node.

[0040] Next, the Shannon entropy algorithm is used to calculate the node interference probability distribution set to obtain the node interference information entropy for each process node. Shannon entropy is a fundamental concept in information theory, used to quantify the degree of uncertainty or disorder in information. In this step, the Shannon entropy algorithm will be applied to the interference probability distribution of each process node. The specific calculation formula is as follows: ;in, Represents the node interference information entropy Let represent the probability of the i-th type of interference occurring at this node, and n be the total number of interference types. By applying this formula to the interference probability distribution of each process node, the node interference information entropy of each node can be obtained. The higher the value of the node interference information entropy, the more complex the interference and the greater the uncertainty of the node; conversely, the lower the value, the simpler the interference situation and the less uncertainty of the node.

[0041] In calculating the information entropy of node interference, the Shannon entropy algorithm can quantify the risk level of each node, providing data support for process compliance review. Through this process, nodes with potential risks in the process can be accurately identified, especially high-entropy nodes that are most susceptible to interference and compliance issues, providing quantitative basis for process optimization, risk avoidance, and compliance improvement.

[0042] Furthermore, weighted entropy calculation is performed on the node interference information entropy of each process node to output the process interference information entropy. Step P32 in this embodiment of the application also includes: P32-3: Obtain the importance coefficient of each process node based on compliance review, and assign a weight set according to the importance coefficient of each process node; P32-4: Calculate the weighted entropy of the node interference information entropy of each process node according to the weight set, and output the process interference information entropy.

[0043] Specifically, after calculating the node interference information entropy for each process node, the next step is to comprehensively process these node interference information entropies to obtain the overall process interference information entropy.

[0044] First, obtain the importance coefficient of each process node based on the compliance review to quantify the importance of each node in the compliance review. The importance coefficient can be determined in various ways, such as based on the node's position in the process (e.g., whether it is a critical node), the node's impact on the final result (e.g., whether it involves a key decision point), and the node's error rate or risk level in historical data. These factors can be considered comprehensively to assign each process node an importance coefficient between 0 and 1, where 1 represents the highest importance. For example, if a node is a key decision point in the process and has historically experienced frequent errors or risks, then this node's importance coefficient might be assigned a higher value, such as 0.8 or 0.9. These importance coefficients will be used as weights in subsequent weighted calculations.

[0045] Subsequently, weight sets are assigned according to the importance coefficients of each process node. A weight set is an array or list containing the importance coefficients of all process nodes; the weight values ​​are implemented by mapping the importance coefficient of each node to an actual numerical value. For example, if a process contains three nodes with importance coefficients of 0.8, 0.5, and 0.2, the weight set would be {0.8, 0.5, 0.2}. These weight values ​​will be used to weight the interference information entropy of each node.

[0046] Next, weighted entropy calculation is performed on the node interference information entropy of each process node based on the weight set. The purpose of weighted entropy calculation is to comprehensively consider the interference information entropy of each node and its importance in the overall process, thereby obtaining a comprehensive index reflecting the interference situation of the entire process. Specifically, for each process node, its node interference information entropy is multiplied by its corresponding importance coefficient, i.e., its weight value, and then the results of all nodes are added together to obtain the weighted entropy value of the entire process. Through this weighted calculation, it is ensured that the interference situation of key nodes occupies a more significant position in the final result, thus more accurately reflecting the interference status of the entire process.

[0047] Finally, the process interference information entropy is output. As the final result, the process interference information entropy quantifies the compliance risk of the entire process. A high process interference information entropy indicates the presence of many high-risk nodes in the process chain, suggesting the process may face significant compliance issues. Conversely, a low process interference information entropy indicates a relatively stable overall process with lower compliance risk. This result can serve as the initial compliance review output, providing crucial quantitative evidence for subsequent compliance analysis and process optimization.

[0048] P40: The process chain is reconstructed according to the interference event to obtain a reconstructed process chain, and a compliance risk index analysis is performed on the reconstructed process chain to obtain a second compliance review result.

[0049] Furthermore, step P40 in this embodiment of the application also includes: P41: Reconstruct the process chain according to the interference event to obtain a reconstructed process chain; P42: Simultaneously record the reconstructed operation set, which includes the reconstructed operation of each process node based on the interference event; P43: wherein the reconstructed operation of each process node is obtained by judging the type of the interference event, including node-level reconstructed operation, resource-level reconstructed operation, system-level reconstructed operation and external-level reconstructed operation.

[0050] It should be understood that the process chain is restructured based on the identified disruptive events to generate a new restructured process chain, and the restructured process chain is subjected to compliance risk index analysis to obtain the second compliance review result.

[0051] Before refactoring the process chain, the original chain must first be analyzed based on the identified interference events. Specifically, each interference event affects certain nodes or steps in the chain, thus requiring targeted adjustments based on the nature of these events. The refactoring process may include adjusting the order of nodes, adding redundant paths, replacing certain nodes, or reconfiguring resources to accommodate the interference events. For example, if a node-level interference event causes a process node to fail, it may be necessary to add an extra verification step or adjust the node's execution logic; if it is a resource-level interference event, it may be necessary to reallocate resources or optimize resource usage.

[0052] Meanwhile, to ensure the traceability and transparency of the refactoring process, a set of refactoring operations needs to be recorded. This set details the refactoring operations performed at each process node under the influence of disruptive events. The recorded content includes, but is not limited to: adjustments to the node order, additions or removals of nodes, replacement of resource types, system improvement measures, and response strategies to changes in external factors. Systematically recording these refactoring operations provides a basis for subsequent audits, optimizations, and compliance checks.

[0053] Finally, for each process node's refactoring operation, the appropriate action needs to be determined and executed based on the type of interference event. Specifically, the type of interference event determines the nature and scope of the refactoring operation. For example, node-level refactoring operations mainly target individual nodes in the process and may include modifying the node's execution logic, adding fault tolerance mechanisms, or adjusting the node's input / output conditions; resource-level refactoring operations involve the reallocation of resources, optimizing resource utilization efficiency, or introducing new resource management strategies; system-level refactoring operations may include adjusting the entire system architecture, optimizing system performance, or introducing new technical modules; and external-level refactoring operations focus on responding to changes in the external environment, such as adjusting processes to adapt to new legal and regulatory requirements or changes in market conditions.

[0054] After the process chain is restructured, a compliance risk index analysis needs to be performed on the restructured process chain to assess its compliance performance under the influence of new disruptive events. The compliance risk index is a comprehensive indicator that reflects the process chain's resilience and compliance level in the face of various disruptive events. By analyzing the restructured process chain, potential compliance risks can be identified, and the impact of these risks on the overall process compliance can be assessed. For example, if a new external data source is introduced during the restructuring of a key node, the compliance risk index analysis might focus on the reliability and compliance of that data source, as well as its impact on the overall process compliance.

[0055] Furthermore, a compliance risk index analysis is performed on the restructured process chain to obtain a second compliance review result. Step P40 in this embodiment of the application also includes: P44: Calculate the reconstruction cost based on the set of reconstruction operations to obtain the reconstruction cost index; P45: Perform compliance review impact analysis based on the set of reconstruction operations to obtain the node offset impact and process offset impact, wherein the node offset impact includes structural offset impact, temporal offset impact, resource occupation offset impact, and control rule offset impact, and the process offset impact is used to quantify the degree of deviation of the reconstructed process chain from the original process specifications; P46: Obtain the second compliance review result according to the reconstruction cost index, node offset impact, and process offset impact.

[0056] Specifically, after restructuring the process chain, the next key step is to conduct a compliance risk index analysis on the restructured process chain in order to obtain the second compliance review result.

[0057] First, the system calculates refactoring costs based on the set of refactoring operations, quantifying the resource consumption and costs involved. Refactoring costs include not only direct financial costs, such as new equipment, software licenses, or personnel training expenses, but also indirect costs, such as production downtime and efficiency losses caused by the refactoring. Therefore, the system assesses the cost impact of each operation recorded in the refactoring operation set. For example, if a refactoring operation involves introducing a new system module, the system calculates the procurement, installation, and maintenance costs of that module; if a refactoring operation involves adjusting the execution order of process nodes, the system assesses the resulting efficiency changes and potential production delay costs. By integrating these factors, a refactoring cost metric is generated. This metric helps assess the actual cost of the refactored process chain, thus providing decision-makers with a financial basis for process optimization.

[0058] Next, a compliance review impact analysis is performed based on the set of refactoring operations. This involves assessing the degree to which the refactoring operations affect process compliance and obtaining the node offset impact and process offset impact. The node offset impact includes structural offset impact, temporal offset impact, resource allocation offset impact, and control rule offset impact. Specifically, the structural offset impact measures the degree to which the refactoring operations change the process node structure, such as whether certain nodes have been added or deleted; the temporal offset impact assesses the impact of changes in the execution order of nodes on the process; the resource allocation offset impact analyzes the impact of adjustments to resource allocation on process efficiency and compliance; and the control rule offset impact focuses on the impact of changes in process control rules caused by the refactoring on compliance.

[0059] The process deviation impact level quantifies the degree to which the restructured process chain deviates from the original process specifications. It comprehensively considers the deviations of the entire process chain in terms of structure, timing, resources, and control rules, providing a comprehensive quantitative indicator for assessing the compliance of the restructured process. A high process deviation impact level usually means reduced process compliance, and the restructured process may face more compliance risks.

[0060] Finally, based on the refactoring cost indicators, the impact of node offsets, and the impact of process offsets, a second compliance review result is obtained through comprehensive evaluation. Specifically, the system considers whether the refactoring cost is within an acceptable range and whether the impact of the refactoring operation on process compliance is within a controllable range. For example, if the refactoring cost is too high, but compliance improvement is significant, the refactoring may still be considered reasonable; conversely, if the refactoring cost is low, but the compliance impact is significant, the necessity of the refactoring may need to be reassessed. By comprehensively considering these factors, a second compliance review result is generated, providing decision-makers with a basis for whether to accept the refactored process chain. This result not only reflects the compliance performance of the refactored process chain but also considers the cost-effectiveness of implementing the refactoring, providing a comprehensive reference for enterprise process optimization and compliance management.

[0061] Furthermore, step P46 in this embodiment of the application also includes: P46-1: By integrating the aforementioned reconstruction cost indicators, node offset impact, and process offset impact, a compliance risk index is output; P46-2: The compliance risk index is output as the second compliance review result.

[0062] Optionally, the refactoring cost indicators, node offset impact, and process offset impact can be further integrated to ultimately output a compliance risk index, which is then provided to decision-makers as a second compliance review result.

[0063] First, a compliance risk index is output by integrating the reconstructed cost indicators, the impact of node offsets, and the impact of process offsets (P46-1). To obtain the compliance risk index, these three key indicators need to be weighted and synthesized. Each indicator may have a different degree of impact on compliance risk, therefore their weights in the final compliance risk index need to be adjusted according to the actual situation. Specifically, during the integration process, the system assigns corresponding weights based on the importance of each factor. For example, if the company's primary goal is to ensure compliance, then the impact of node offsets and the impact of process offsets may be given higher weights; if the company focuses more on cost control, then the weight of the reconstructed cost indicator may be relatively high. Then, through weighted integration, a comprehensive compliance risk index is generated, which can comprehensively reflect the overall performance of the reconstructed process chain in terms of compliance and cost-effectiveness.

[0064] Finally, the generated compliance risk index is output as the second compliance review result. This result provides decision-makers with a clear quantitative indicator to assess the feasibility and necessity of restructuring the process chain. The lower the compliance risk index value, the better the restructured process chain performs in terms of compliance and cost-effectiveness; conversely, a higher value indicates potentially higher compliance risks or cost burdens. By outputting this comprehensive indicator, enterprises can more intuitively understand the overall impact of restructuring operations, thereby making more informed decisions.

[0065] P50: Based on the first compliance review result and the second compliance review result, output the compliance review result of the process chain.

[0066] Furthermore, step P50 in this embodiment of the application also includes: P51: When the process interference information entropy of the first compliance review result is greater than the preset interference information entropy threshold, or the compliance risk index of the second compliance review result is greater than the preset compliance risk threshold, the process chain output is a non-compliant process chain; P52: Otherwise, the process chain is output as a compliant process chain.

[0067] It should be understood that the final compliance review result of the process chain is output by combining the results of the first compliance review (process interference information entropy) and the second compliance review (compliance risk index).

[0068] Specifically, these two indicators are judged based on preset thresholds. When either indicator fails to meet the corresponding threshold, the entire process chain is considered non-compliant. For example, when the process interference information entropy of the first compliance review result is greater than the preset interference information entropy threshold, it indicates that the process chain has a high degree of uncertainty after being affected by interference events, posing a significant compliance risk. This means that the process chain may not be able to effectively maintain its compliance under the current interference environment, so the system marks the process chain as non-compliant. Similarly, when the compliance risk index of the second compliance review result is greater than the preset compliance risk threshold, it also indicates that the process chain has a high compliance risk after reconstruction and cannot meet the company's compliance requirements. In this case, the system also marks the process chain as non-compliant. These two thresholds are preset based on the company's specific needs and compliance standards, and are used to quantitatively assess the compliance risk of the process chain.

[0069] Conversely, if the process interference information entropy of the first compliance review result is less than or equal to the preset interference information entropy threshold, and the compliance risk index of the second compliance review result is less than or equal to the preset compliance risk threshold, it indicates that the process chain can maintain low uncertainty after being affected by interference events, and the compliance risk after reconstruction is within a controllable range. In this case, the process chain is marked as a compliant process chain. This shows that the process chain can effectively maintain its compliance under the current interference environment, and can still meet the enterprise's compliance requirements after optimization and adjustment, providing a basis for enterprise compliance management decisions.

[0070] In summary, the embodiments of this application have at least the following technical effects: This application achieves automatic construction of process chains through process mining and classifies, identifies, and quantifies interference events at the node, resource, system, and external levels, thereby comprehensively improving the automation and accuracy of process compliance review. By assigning interference values ​​to process nodes and calculating the process interference information entropy, the stability risk of the process can be quantified. Based on the interference events, the process chain is reconstructed, and a compliance risk index is calculated by combining the reconstruction cost, node offset impact, and process offset impact, so that the process's anti-interference capability can be scientifically assessed. Through a two-dimensional review mechanism, more accurate and interpretable compliance review results are output, providing reliable data for process optimization and internal control improvement.

[0071] This technology achieves the goal of quantifying the impact of disruptive events based on process mining and optimizing the process to improve review efficiency and accuracy.

[0072] Example 2, based on the same inventive concept as the process mining-based internal control compliance review method in the previous examples, such as... Figure 2As shown, this application provides an internal control compliance review system based on process mining. The system and method embodiments in this application are based on the same inventive concept. The system includes: The process chain extraction module 11 is used to extract the process chain constructed based on the event sequence from the process event table.

[0073] The interference event entry module 12 is used to enter interference events of the process chain. The interference events are disturbance events that affect the compliance of the process. The types of interference events include node level, resource level, system level and external level.

[0074] The interference assignment module 13 is used to assign interference values ​​to each process node in the process chain according to the interference event, obtain the process interference information entropy, and output the process interference information entropy as the first compliance review result.

[0075] The compliance risk analysis module 14 is used to reconstruct the process chain according to the interference event to obtain a reconstructed process chain, and to perform compliance risk index analysis on the reconstructed process chain to obtain a second compliance review result.

[0076] The review result output module 15 is used to output the compliance review result of the process chain based on the first compliance review result and the second compliance review result.

[0077] Furthermore, the interference assignment module 13 is also used to perform the following steps: The interference event includes an interference description field, which includes the interference type, the process node affected by the interference, and the type of offset caused by the interference. The process chain is traversed and scanned according to the interference event to obtain the interference vector of each process node. The node interference information entropy of each process node is calculated based on the interference vector of each process node. The node interference information entropy of each process node is weighted and calculated to output the process interference information entropy.

[0078] Furthermore, the interference assignment module 13 is also used to perform the following steps: Collect historical interference event samples corresponding to each process node; identify the historical prior probability of each interference event type in the historical interference event samples corresponding to each process node; filter the interference event types with historical prior probabilities greater than the preset expected probability to identify each process node; match the interference events with the identified interference event types of each process node, and extract the interference vector of each process node based on the matched interference events.

[0079] Furthermore, the interference assignment module 13 is also used to perform the following steps: The node interference probability distribution is calculated based on the interference vector of each process node, and the set of node interference probability distributions is output. The node interference information entropy of each process node is obtained by calculating the set of node interference probability distributions using the Shannon entropy algorithm.

[0080] Furthermore, the interference assignment module 13 is also used to perform the following steps: Obtain the importance coefficient of each process node based on compliance review, and assign a weight set according to the importance coefficient of each process node; calculate the weighted entropy of the node interference information entropy of each process node according to the weight set, and output the process interference information entropy.

[0081] Furthermore, the compliance risk analysis module 14 is also used to perform the following steps: The process chain is reconstructed according to the interference event to obtain a reconstructed process chain; at the same time, a set of reconstructed operations is recorded, which includes the reconstructed operations of each process node based on the interference event; wherein, the reconstructed operation of each process node is obtained by determining the type of interference event, including node-level reconstructed operations, resource-level reconstructed operations, system-level reconstructed operations and external-level reconstructed operations.

[0082] Furthermore, the compliance risk analysis module 14 is also used to perform the following steps: The reconstruction cost is calculated based on the set of reconstruction operations to obtain the reconstruction cost index; the impact of compliance review is analyzed based on the set of reconstruction operations to obtain the node offset impact and process offset impact, wherein the node offset impact includes structural offset impact, temporal offset impact, resource usage offset impact, and control rule offset impact, and the process offset impact is used to quantify the degree of deviation of the reconstructed process chain from the original process specifications; the second compliance review result is obtained according to the reconstruction cost index, node offset impact, and process offset impact.

[0083] Furthermore, the compliance risk analysis module 14 is also used to perform the following steps: Based on the aforementioned reconstruction cost indicators, node offset impact, and process offset impact, a second compliance review result is obtained; by integrating the aforementioned reconstruction cost indicators, node offset impact, and process offset impact, a compliance risk index is output; the compliance risk index is then output as the second compliance review result.

[0084] Furthermore, the review result output module 15 is also used to perform the following steps: If the process interference information entropy of the first compliance review result is greater than the preset interference information entropy threshold, or the compliance risk index of the second compliance review result is greater than the preset compliance risk threshold, the process chain output is a non-compliant process chain; otherwise, the process chain output is a compliant process chain.

[0085] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, the above description focuses on specific embodiments of this specification. Additionally, the processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing are possible or may be advantageous.

[0086] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

[0087] This specification and accompanying drawings are merely illustrative examples of this application and are intended to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from its scope. Therefore, if such modifications and variations fall within the scope of this application and its equivalents, this application intends to include such modifications and variations.

Claims

1. An internal control compliance review method based on process mining, characterized in that, The method includes: Extract the process chain constructed based on the event sequence from the process event table; The interference events of the process chain are recorded. The interference events are disturbance events that affect the compliance of the process. The types of interference events include node level, resource level, system level and external level. According to the interference event, each process node in the process chain is assigned an interference value to obtain the process interference information entropy, and the process interference information entropy is output as the first compliance review result. The process chain is reconstructed according to the interference event to obtain a reconstructed process chain, and a compliance risk index analysis is performed on the reconstructed process chain to obtain a second compliance review result. Based on the first compliance review result and the second compliance review result, output the compliance review result of the process chain.

2. The method as described in claim 1, characterized in that, The method involves assigning interference values ​​to each process node in the process chain according to the aforementioned interference events. include: The interference event includes an interference description field, which includes the interference type, the process node affected by the interference, and the type of offset caused by the interference. The process nodes in the process chain are traversed and scanned according to the interference events to obtain the interference vector of each process node. Calculate the node interference information entropy of each process node based on the interference vector of each process node, perform weighted entropy calculation on the node interference information entropy of each process node, and output the process interference information entropy.

3. The method as described in claim 2, characterized in that, The method for traversing and scanning each process node in the process chain according to the interference event to obtain the interference vector of each process node includes: Collect historical interference event samples corresponding to each process node; Identify the prior probability of each type of interference event in the historical interference event samples corresponding to each process node; Each process node is identified by filtering out interference event types whose prior probability of occurrence in the past is greater than the preset expected probability. The interference events are matched with the identification interference event type of each process node, and the interference vector of each process node based on the matched interference events is extracted.

4. The method as described in claim 2, characterized in that, The node interference information entropy of each process node is calculated based on the interference vector of each process node. The method includes: Calculate the node interference probability distribution based on the interference vector of each process node, and output the set of node interference probability distributions; The node interference information entropy of each process node is obtained by calculating the node interference probability distribution set using the Shannon entropy algorithm.

5. The method as described in claim 2, characterized in that, The process interference information entropy is calculated by weighting the node interference information entropy of each process node and outputting the process interference information entropy. The method includes: Obtain the importance coefficient of each process node based on compliance review, and assign a weight set according to the importance coefficient of each process node; The node interference information entropy of each process node is weighted and calculated based on the weight set, and the process interference information entropy is output.

6. The method as described in claim 1, characterized in that, The process chain is reconstructed according to the interference events to obtain the reconstructed process chain; Simultaneously, a set of reconstruction operations is recorded, which includes reconstruction operations based on each process node under the interference event; The reconstruction operation of each process node is obtained by judging the type of interference event, including node-level reconstruction operation, resource-level reconstruction operation, system-level reconstruction operation and external-level reconstruction operation.

7. The method as described in claim 6, characterized in that, The second compliance review result is obtained by performing compliance risk index analysis on the restructured process chain. The method includes: The reconstruction cost is calculated based on the set of reconstruction operations to obtain the reconstruction cost index. Based on the set of refactoring operations, a compliance review impact analysis is performed to obtain the node offset impact and process offset impact. The node offset impact includes structural offset impact, temporal offset impact, resource consumption offset impact, and control rule offset impact. The process offset impact is used to quantify the degree of deviation of the refactored process chain from the original process specifications. Based on the aforementioned reconstruction cost indicators, node offset impact, and process offset impact, the second compliance review result is obtained.

8. The method as described in claim 7, characterized in that, Based on the aforementioned reconstruction cost indicators, node offset impact, and process offset impact, the second compliance review result is obtained; By integrating the aforementioned reconstruction cost indicators, node offset impact, and process offset impact, a compliance risk index is output. The compliance risk index will be output as the second compliance review result.

9. The method as described in claim 1, characterized in that, Based on the first compliance review result and the second compliance review result, the compliance review result of the process chain is output, and the method includes: When the process interference information entropy of the first compliance review result is greater than the preset interference information entropy threshold, or the compliance risk index of the second compliance review result is greater than the preset compliance risk threshold, the process chain output is a non-compliant process chain. Otherwise, the process chain will be output as a compliant process chain.

10. An internal control compliance review system based on process mining, characterized in that, The system includes: The process chain extraction module is used to extract process chains based on event sequences from the process event table; The interference event entry module is used to enter interference events of the process chain. The interference events are disturbance events that affect the compliance of the process. The types of interference events include node level, resource level, system level and external level. The interference assignment module is used to assign interference values ​​to each process node in the process chain according to the interference event, obtain the process interference information entropy, and output the process interference information entropy as the first compliance review result. The compliance risk analysis module is used to reconstruct the process chain according to the interference event to obtain a reconstructed process chain, and to perform compliance risk index analysis on the reconstructed process chain to obtain a second compliance review result. The review result output module is used to output the compliance review result of the process chain based on the first compliance review result and the second compliance review result.