Enterprise penetration type supervision method and system based on decision chain, and computer readable medium

By constructing a multi-level event association model and decision chain, real-time monitoring of enterprise risks across the entire chain is achieved, which solves the shortcomings of traditional regulatory technologies in identifying cross-level risk associations and improves the accuracy and timeliness of supervision.

CN121836744APending Publication Date: 2026-04-10SUZHOU STATE-OWNED CAPITAL INVESTMENT GROUP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SUZHOU STATE-OWNED CAPITAL INVESTMENT GROUP CO LTD
Filing Date
2025-12-12
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Traditional enterprise monitoring technologies struggle to achieve precise, real-time, and comprehensive monitoring. They are unable to effectively identify risk relationships across levels and systems, and suffer from high false alarm and false alarm rates as well as untimely responses.

Method used

A multi-level event association model is constructed, which enables real-time monitoring of processes such as fund transfer, equity change, and business approval through dynamic risk tracking nodes and decision chains. Dynamic threshold adjustment, event chain modeling, and graph algorithms are used to track the risk diffusion path, thereby achieving real-time risk identification and accurate location.

Benefits of technology

It improves the accuracy and timeliness of risk identification, reduces the misjudgment rate, enables risk identification up to 24 hours in advance, shortens the response time, enhances the precision and timeliness of supervision, and prevents risks from escalating.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121836744A_ABST
    Figure CN121836744A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of enterprise operation supervision, and discloses an enterprise penetration-type supervision method and system based on a decision chain and a computer readable medium, and the method comprises the steps: building a multi-dimensional initial threshold model based on the inherent attributes of a national enterprise and a supervision architecture, dynamic threshold adjustment is carried out according to the real-time financial health condition and the risk level of the enterprise; the adjusted dynamic threshold model is deployed and embedded into key supervision nodes of national enterprise operation to form dynamic risk tracking points; defining a standardized event unit, and converting the business data of the state-owned enterprise into a structured event chain in a standardized event unit format; based on a structured event chain of a dynamic risk tracking point, a three-level early warning mechanism of single-point instant early warning, composite rule early warning and conduction chain early warning is constructed, and real-time identification, accurate positioning and diffusion pre-judgment of risks are realized. By means of the method, real-time penetrating type monitoring of the full-chain risk of the national assets from the top-level group to the basic-level enterprises can be achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of enterprise management and supervision technology, and more specifically to a method, system and computer-readable medium for enterprise penetration supervision based on the decision chain, particularly for multi-level supervision scenarios of state-owned enterprises and state-owned assets, applicable to full-chain risk monitoring of enterprises with multi-level structures including group headquarters, subsidiaries and sub-subsidiaries. Background Technology

[0002] With the group-oriented and diversified development of state-owned enterprises, the hierarchical structure has become increasingly complex, and cross-level and cross-system business collaboration and capital flow have become more frequent. Traditional regulatory technologies are no longer able to meet the needs of precise, real-time, and comprehensive supervision.

[0003] Currently, mainstream enterprise monitoring technology solutions are mainly built around decentralized node monitoring and post-event data verification, and are mainly divided into two categories: single-link static monitoring solutions and post-event batch traceability solutions.

[0004] In single-stage static monitoring solutions, separate systems are used to monitor different regulatory stages such as fund transfers, equity changes, and business approvals. For example, fund monitoring relies on bank transaction records, identifying large anomalies by setting fixed thresholds (such as daily transfers exceeding 500,000 yuan from a single account); equity change monitoring relies on self-reported business registration information, recording only changes in registered equity ratios; and business approval monitoring primarily involves manual spot checks of approval process forms, comparing them with standard procedures to determine compliance. Each system operates independently, and data is stored in different databases, lacking an automatic cross-system correlation mechanism, resulting in data silos.

[0005] In post-event batch traceability solutions, most adopt a model of periodic data aggregation and manual analysis, such as exporting data from various business systems weekly / monthly and performing batch verification using Excel or basic statistical tools to identify risk events. While some solutions introduce simple early warning functions, they only trigger alerts based on single indicators, such as a single transfer exceeding a threshold, lacking comprehensive rule-based judgment or risk transmission path analysis capabilities. Furthermore, such early warnings and responses are mostly post-event notifications, lacking proactive prediction mechanisms and failing to capture cross-stage risk correlations in real time. Most risk events are only discovered through batch data verification several days to weeks after they occur, missing the optimal time for handling. After a risk event occurs, manual cross-system data retrieval and correlation analysis are required, making it difficult to quickly trace the historical propagation path of the risk, such as the relationship between an abnormal fund situation of a company → related supply chain companies → downstream terminals. This makes it difficult to trace the full picture of the event and the execution trajectory of regulatory instructions, resulting in a lack of accurate data support for accountability for violations.

[0006] Meanwhile, existing early warning rules are based on static judgments using a single indicator, failing to consider the multi-dimensional correlations of risk events (such as the synergistic risks of changes in funds, equity, and personnel). They are unable to address hidden risks such as "split transfers" and "indirect shareholding changes," and are prone to false alarms due to a single indicator (such as marking large transfers of normal business transactions), increasing the workload of regulators. Traditional static judgments using a single indicator lack a dynamic adjustment mechanism, making them unsuitable for dynamic scenarios such as business growth and industry cycle changes. This can easily lead to "over-intervention" or "under-intervention," affecting regulatory effectiveness and normal business operations. Summary of the Invention

[0007] In view of the defects and shortcomings of existing technologies, the purpose of this invention is to provide a corporate penetration supervision method based on the decision chain. By constructing a multi-level event association model, dynamic risk tracking nodes are set in core supervision links such as fund flow, equity change, and business approval, so as to realize real-time penetration monitoring of the risks of state-owned assets from the top group to the grassroots enterprises.

[0008] According to a first aspect of the present invention, a method for enterprise penetration supervision based on the decision chain is proposed, comprising the following steps:

[0009] Step 1: Construct a multi-dimensional initial threshold model based on the inherent attributes and regulatory framework of state-owned enterprises, and dynamically adjust the thresholds according to the real-time financial health status and risk level of the enterprises to obtain a modified dynamic threshold model.

[0010] Step 2: Deploy and embed the dynamic threshold model into key regulatory nodes of state-owned enterprise operations to form dynamic risk tracking points;

[0011] Step 3: Define standardized event units (T, G, A, M, L), and convert the business data of state-owned enterprise operations into a structured event chain in standardized event unit format through standardized modeling;

[0012] Step 4: Based on the structured event chain of dynamic risk tracking points, construct a three-tiered early warning mechanism: single-point real-time early warning, composite rule-based early warning, and transmission chain early warning. This enables real-time risk identification, accurate location, and prediction of risk spread.

[0013] The single-point real-time early warning includes immediately activating a single-point early warning and marking the risk event information when a dynamic risk tracking point detects that event data in a structured event chain triggers a dynamic threshold.

[0014] The composite rule-based early warning identifies composite risks by matching the set of event factors with the compliance rules defined by the business scenario.

[0015] The transmission chain early warning system uses state-owned asset hierarchical chain analysis and graph algorithms to track risk diffusion paths, calculate transmission intensity, identify high-risk levels, and issue early warnings.

[0016] According to a second aspect of the present invention, a computer system is provided, comprising:

[0017] One or more processors;

[0018] The memory stores operable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations, including the process of executing the aforementioned chain-of-decision-based enterprise oversight method.

[0019] In a third aspect of the present invention, a computer-readable medium for storing software is provided, the software including instructions executable by one or more computers, the instructions, when executed by the one or more computers, performing the process of the aforementioned chain-of-decision-based enterprise penetration monitoring method.

[0020] The event-based decision-making chain-based penetrating supervision method described in the above embodiments of the present invention constructs a multi-level event association model and sets dynamic risk tracking nodes in key links such as fund transfers, equity changes, and business approvals to achieve real-time penetrating monitoring of risks across the entire enterprise chain. Simultaneously, it uses an event graph engine to dynamically associate cross-system data. When any node triggers a risk threshold, it automatically generates a risk transmission path and initiates tiered early warnings, and supports reverse tracing of regulatory instructions.

[0021] Compared with existing technologies, the significant advantages of the enterprise penetration-based regulatory method based on the decision chain of this invention are:

[0022] (1) By modeling event chains and linking cross-system data, the limitations of traditional silo architecture can be broken, and the equity control relationship and capital flow of multi-level subsidiaries can be identified, thereby improving the coverage of state-owned asset penetration monitoring.

[0023] (2) By optimizing the dynamic threshold and iterating the composite rule, the false alarm rate and false negative rate of risk identification are reduced, and risks can be identified 24 hours in advance, shortening the response time and improving the accuracy and timeliness of early warning;

[0024] (3) For identified risk nodes, high-risk levels can be quickly locked by tracking the transmission path and quantifying the diffusion intensity, avoiding the risk from being amplified layer by layer, improving the accuracy of risk transmission and positioning, facilitating the rapid and effective tracing of risk points and transmission paths, and enabling targeted and efficient response and intervention, thereby improving the timeliness and accuracy of regulatory intervention.

[0025] It should be understood that all combinations of the foregoing concepts and the additional concepts described in more detail below may be considered part of the inventive subject matter of this disclosure, provided that such concepts do not contradict each other. Furthermore, all combinations of the claimed subject matter are considered part of the inventive subject matter of this disclosure.

[0026] The foregoing and other aspects, embodiments, and features of the teachings of the present invention will be more fully understood from the following description in conjunction with the accompanying drawings. Other additional aspects of the invention, such as features and / or beneficial effects of exemplary embodiments, will become apparent from the following description or may be learned through practice of specific embodiments according to the teachings of the present invention. Attached Figure Description

[0027] The accompanying drawings are not intended to be drawn to scale. In the drawings, each identical or nearly identical component shown in the various figures may be denoted by the same reference numerals. Embodiments of various aspects of the invention will now be described by way of example and with reference to the accompanying drawings.

[0028] Figure 1 This is a flowchart illustrating the enterprise penetration supervision method based on the decision chain according to an embodiment of the present invention.

[0029] Figure 2 This is the implementation process of an enterprise penetration supervision method according to a specific example of the present invention. Detailed Implementation

[0030] To better understand the technical content of the present invention, specific embodiments are described below in conjunction with the accompanying drawings.

[0031] Various aspects of the invention are described in this disclosure with reference to the accompanying drawings, which illustrate numerous illustrative embodiments. The embodiments of this disclosure are not necessarily intended to encompass all aspects of the invention. It should be understood that the various concepts and embodiments described above, as well as those described in more detail below, can be implemented in any of many ways, because the concepts and embodiments disclosed herein are not limited to any particular implementation. Furthermore, some aspects of the invention disclosed may be used alone or in any suitable combination with other aspects of the invention disclosed.

[0032] {Example 1}

[0033] Combination Figure 1 The enterprise penetration supervision method based on the decision chain according to embodiments of the present invention aims to propose a full-chain risk monitoring method for state-owned enterprises with multi-level supervision scenarios, including group headquarters, subsidiaries, and sub-subsidiaries. Its specific implementation includes the following steps:

[0034] Step 1: Construct a multi-dimensional initial threshold model based on the inherent attributes and regulatory framework of state-owned enterprises, and dynamically adjust the thresholds according to the real-time financial health status and risk level of the enterprises to obtain a modified dynamic threshold model.

[0035] Step 2: Deploy and embed the dynamic threshold model into key regulatory nodes of state-owned enterprise operations to form dynamic risk tracking points;

[0036] Step 3: Define standardized event units (T, G, A, M, L), and convert the business data of state-owned enterprise operations into a structured event chain in standardized event unit format through standardized modeling;

[0037] Step 4: Based on the structured event chain of dynamic risk tracking points, construct a three-tiered early warning mechanism: single-point real-time early warning, composite rule-based early warning, and transmission chain early warning. This enables real-time risk identification, accurate location, and prediction of risk spread.

[0038] The single-point real-time early warning includes immediately activating a single-point early warning and marking the risk event information when a dynamic risk tracking point detects that event data in a structured event chain triggers a dynamic threshold.

[0039] The composite rule-based early warning identifies composite risks by matching the set of event factors with the compliance rules defined by the business scenario.

[0040] The transmission chain early warning system uses state-owned asset hierarchical chain analysis and graph algorithms to track risk diffusion paths, calculate transmission intensity, identify high-risk levels, and issue early warnings.

[0041] In the following embodiments, we combine Figure 1 as well as Figure 2 As shown, the specific implementation process of the enterprise penetration supervision method based on the decision chain of the present invention will be further elaborated.

[0042] As an optional implementation, in step 1, the construction of a multi-dimensional initial threshold model based on the inherent attributes and regulatory framework of state-owned enterprises, and the dynamic adjustment of the thresholds according to the real-time financial health and risk level of the enterprise, to obtain a modified dynamic threshold model, includes:

[0043] Step 1.1: Based on the inherent attributes and regulatory framework of state-owned enterprises, construct a multi-dimensional initial threshold model, including the following process:

[0044] Collect data from six core dimensions of state-owned enterprises and quantify them into V. i , representing the quantized value of the i-th dimension;

[0045] Based on the industry calibration factor α and the standard reference value S std Calculate the initial threshold Th base :

[0046] ;

[0047] In the formula, W i The weight percentage of the i-th dimension is represented by i=1,2,3,4,5,6, which represent the six core dimensions, corresponding to the enterprise level Z(n), total net assets, main business risk level, industry average transaction size, regulatory red line requirements, and the number of risk events in the past three years, respectively.

[0048] The standard reference value S std The benchmark amount is set according to the different levels of the regulatory framework;

[0049] The industry calibration coefficient α is set according to industry characteristics, and its value ranges from 0.8 to 1.2.

[0050] Step 1.2: Obtain the company's debt-to-equity ratio (D), return on assets (R), and cash flow health coefficient (C) as dynamic parameters, and input them into the pre-trained gradient boosting tree model to dynamically adjust the weight coefficients W of each dimension. D W R W C W D +W R +W C =1;

[0051] Step 1.3: Based on the initial threshold Th base and the dynamically adjusted weighting coefficient W D W R W C Calculate the corrected dynamic threshold Th:

[0052]

[0053] In the formula, ΔD represents the debt-to-asset ratio adjustment coefficient, ΔD=min[(DD std ) / D std [0.5], D std Let D be the industry average debt-to-equity ratio, when D ≤ D std When ΔD=0;

[0054] ΔR represents the asset return adjustment factor, ΔR = min[(RR)] std ) / R std [0.3], R std Let R be the industry average return on assets, when R ≥ R std When ΔD=0;

[0055] ΔC represents the cash flow adjustment factor, ΔC=min[(0.3-C) / 0.3, 0.4], when C≥0.3 ΔC=0.

[0056] In an embodiment of the present invention, the overall constraint dynamic threshold is adjusted downward by no more than 50% of the initial threshold and upward by no more than 20% of the initial threshold.

[0057] In step 1, for the six core dimensions, a multi-dimensional initial threshold model is constructed based on the inherent attributes of the enterprise and regulatory requirements to ensure that the thresholds match the enterprise's risk tolerance and business scale.

[0058] As an example, the weight percentages and quantification values ​​for the six core dimensions are configured as follows:

[0059] Enterprise level Z(n): weight 30%, quantified value: Z(0)=1.0, Z(1)=0.8, Z(2)=0.6, Z(3)=0.4, Z(n≥4)=0.3;

[0060] Total net assets: weighted at 25%, the quantitative value is quantified according to the industry percentile, for example, the top 10% is 1.0, the top 20% is 0.9, and so on;

[0061] Main business risk level: weighted at 15%, quantitative value is divided by industry, high-risk industries (such as finance and energy) = 1.0, medium risk = 0.7, low risk = 0.4;

[0062] Industry average transaction size: weighted at 10%, the quantitative value is determined by the ratio of enterprise transaction size to industry average transaction size, and is quantified as 0.5-1.5;

[0063] Regulatory red line requirements: weight 15%, quantitative value = 1.0 for projects meeting special regulatory requirements (such as major investment projects), and quantitative value = 0.7 for projects meeting ordinary requirements;

[0064] Number of risk events in the past 3 years: weighted at 5%, the quantitative value is based on the number of risk events, with 1.0 for no risk, 0.8 for 1-2 events, and 0.5 for 3 or more events.

[0065] As an optional implementation, in step 1, the pre-trained gradient boosting tree model takes the debt-to-equity ratio D, return on assets R, and cash flow health coefficient C as inputs, and automatically learns to dynamically adjust the weight coefficients of the dimensions and outputs the dynamically adjusted weight coefficients W for each dimension. D W R W C Its training process includes:

[0066] The input features include debt-to-asset ratio (D), return on assets (R), cash flow health coefficient (C), enterprise level, asset size, industry type, and risk event data from the past year. The actual occurrence of risk events is used as the label variable, with label 1 = risk occurred and label 0 = risk did not occur.

[0067] A sample set was constructed using data from state-owned enterprises in the industry over the past five years, and then divided into training, testing, and validation sets according to proportions.

[0068] The gradient boosting tree (GBDT) model is initialized and training parameters are set for iterative training. The training process uses gradient descent to minimize the loss function. The model accuracy is verified through a test machine every 10 iterations. Training is stopped when the accuracy improvement is ≤0.1%. Specific training parameter settings for this example include: number of decision trees = 100, depth of each tree = 5, learning rate = 0.05, and log loss function.

[0069] Use the validation set to verify the accuracy of the model and obtain the trained gradient boosting tree model.

[0070] As an optional implementation, in step 1, incremental data is used to incrementally train the gradient boosting tree model based on the quarterly financial data of state-owned enterprises, and the model is updated in real time.

[0071] As an optional implementation, in step 1, the definition and acquisition of the dynamic parameters include:

[0072] The debt-to-equity ratio D = total liabilities / total assets × 100%, obtained from the most recent financial statements;

[0073] Return on assets R = Net profit / Average total assets × 100%; calculated using a rolling 12-month period.

[0074] The cash flow health coefficient C = (net cash flow from operating activities + net cash flow from investing activities + net cash flow from financing activities) / current liabilities. The coefficient ranges from 0 to 1. ≥0.3 indicates healthy cash flow, 0.1-0.3 indicates average cash flow, and <0.1 indicates tight cash flow.

[0075] As an optional implementation, in step 2, the key regulatory nodes of the state-owned enterprise operation include the supervision of fund transfers, equity changes, business approvals, and related-party transactions. The deployment method uses the Flink streaming computing framework to construct a real-time processing pipeline, with each regulatory link corresponding to an independent processing operator, wherein:

[0076] The fund transfer process combines event-driven and window-based calculations: it monitors individual transactions in real time based on event-driven methods, while calculating the cumulative transaction amount over 1 hour, 24 hours, and 72 hours based on a sliding window.

[0077] Status monitoring is used for equity changes and related-party transactions: the status of corporate equity and the filing status of related-party relationships are recorded, and the monitoring logic is triggered when the status changes.

[0078] The business approval process uses process node hooks: hook functions are set at each node of the approval system to obtain the node execution status in real time and compare it with the standard approval process to trigger anomaly detection.

[0079] As an optional implementation, in step 3, the standardized event unit (T, G, A, M, L) is defined as follows:

[0080] T represents the specific timestamp of the event, in YYYY-MM-DDHH:MM:SS format;

[0081] G indicates the subject of the event execution, which is clearly defined as an enterprise or an internal department of an enterprise and the subject level attribute is marked. The name of the enterprise subject is identified by both the unified social credit code and the standardized name.

[0082] A represents the core action of the event, which adopts a standardized multi-level tag system, where the first-level tags cover fund operations, equity changes, business approvals, and related transactions;

[0083] M represents the object affected by the event, using a structured format of core data + supplementary information.

[0084] L represents a state-owned assets exclusive label, containing two layers of core information, using a label type-value encoding format: where:

[0085] The main asset ownership level label Z(n): n is the level, Z(0) represents the group, Z(1) represents the first-level subsidiary, Z(2) represents the second-level subsidiary, and so on. The level is automatically matched through the enterprise organizational structure tree.

[0086] Subject-object relationship label K(x): K(c) represents equity participation, K(d) represents controlling stake, K(g) represents related party, and K(f) represents unrelated party. It is automatically determined through equity structure diagram and actual controller penetration analysis.

[0087] The event units (T, G, A, M, L) as specific instances are defined in the following table:

[0088] For example, for an event whose original description is "a second-tier subsidiary transfers 20 million yuan to an investee company", the standardized event unit is constructed as follows:

[0089] Structured event generation: L(2)M(K(c)2000):

[0090] T: [The specific time the event occurred]

[0091] G: A second-tier subsidiary

[0092] A: Transfer money

[0093] M: "20 million yuan" (funds)

[0094] L: This field is the key to the parsing.

[0095] L(2): The asset ownership level of the entity G (a second-level subsidiary) is the second-level subsidiary Z(2).

[0096] M(K(c)): Here, M refers to the "shareholding enterprise" of the recipient of the transfer; the K(c) label indicates that the relationship between the entity G (a second-level subsidiary) and the recipient enterprise is that the entity holds shares in K(c).

[0097] Therefore, a more complete structured event unit is expressed as: (T="2023-10-26 09:00:00",G="a second-tier subsidiary",A="transfer",M="20 million yuan",L="Z(2),K(c)").

[0098] The structured event units clearly express that at a certain point in time, a state-owned enterprise at the second-tier level transferred 20 million yuan to one of its investee companies.

[0099] This allows for standardized and structured modeling of various business activities of state-owned enterprises, forming a traceable and analyzable event chain. By defining a unified event unit format and combining it with exclusive labels for the state-owned assets sector, previously fragmented and unstructured data (such as financial vouchers, equity change announcements, and approval process records) can be transformed into machine-understandable and computable structured information. This provides traceable and visualized standard data for subsequent supervision, risk identification, and risk warning.

[0100] As an optional implementation, in step 4, the single-point real-time early warning includes:

[0101] In the fund transfer process: the amount of a single transaction is greater than or equal to the dynamic threshold, or the cumulative transaction amount within the sliding window is greater than or equal to the dynamic threshold × 1.5;

[0102] Equity change process: Equity change ratio ≥ 5% and not filed, or change of actual controller not disclosed as required;

[0103] Business approval process: approvals exceeding authority, missing key steps in the process, or approval time exceeding twice the standard time.

[0104] Related party transactions: Transaction amount ≥ dynamic threshold, or transaction price deviates from fair market price ±10%.

[0105] If any dynamic risk tracking point detects that event data in the structured event chain triggers the above warning conditions, the core information of the event is extracted and the event chain database is called to obtain related event information, and warning information including warning ID, warning time, involved subject, regulatory link, event factor, trigger threshold, and related event ID is generated.

[0106] As an optional implementation, the aforementioned processing flow for composite rule-based early warning includes:

[0107] Extract key information such as event factors, involved entities, and business scenarios from single-point early warning information;

[0108] Based on the composite rule of "event factor set (E) ∧ business scenario limitation (S)", the warning level will be upgraded for cases that meet the composite rule.

[0109] Event factors constitute the basic risk events of a risk portfolio; E represents the set of basic risk events of each type, E=(E1,E2,E3,…,E…). n (For example, changes in equity ownership, missing procedures, and abnormal fund movements, these have independent risk attributes.)

[0110] The logical operator ∧ represents an AND relationship, meaning that all events must be satisfied simultaneously; while the logical operator ∨ ​​represents an OR operation, meaning that only one event needs to be satisfied. In the context of state-owned assets, the ∧ operation is mainly used to highlight the combinatorial relationship.

[0111] Business scenario limitation (S) indicates the specific subject attributes and business scope limitations of state-owned asset operation, such as "wholly state-owned enterprise" and "major investment project", which accurately anchors the state-owned asset scenario.

[0112] Taking a risk profile as an example, this combination, during a sensitive period of change in key personnel of an enterprise, superimposes two high-risk factors: "irregular operations" and "abnormal fund movements," aiming to prevent irregular operations such as "rushing to spend money" during the period of change of personnel.

[0113] For example, the compound rule as an example: (Unregistered change of state-owned equity) ∧E3 (Transfer of more than 5 million yuan to non-state-owned related parties): The core risk event combination points to "the disguised loss of state-owned assets through equity change + fund transfer". By matching the compound rules, it has a stronger risk identification capability, can penetrate the appearance and find the systemic or premeditated risks "disguised" under normal business, and is the core means to achieve precise risk supervision.

[0114] As an optional implementation method, the aforementioned transmission chain early warning aims to track and block the risk diffusion path of the state-owned assets system. It not only identifies the risk event itself, but also tracks the possible diffusion path of the risk in the complex state-owned assets system network, assesses its potential systemic impact, and intervenes before the risk escalates.

[0115] An example of a transmission chain early warning process includes:

[0116] Based on the management and control system of state-owned enterprises, with Group S0 as the top starting point, and extending downwards according to the management and control relationship, a hierarchical chain of state-owned assets is formed. Group S0 → First-tier subsidiary S 11 ,S 12 ,...,S 1m →Second-tier subsidiary S 21 ,S 22 ,...,S 2n →...→N-level subsidiary S n1 ,S n2 ,...,S nk The symbol → indicates the direction of risk transmission from the upper level to the lower level, reflecting the hierarchical diffusion logic from top to bottom. It can also use a graph database (such as Neo4j) to store the hierarchical chain data, supporting efficient path querying and association analysis.

[0117] A management and control relationship graph is constructed based on the state-owned asset hierarchy, where each node represents an enterprise and the edges represent control or related relationships. Control relationships are marked with the shareholding ratio, and related relationships are marked with the type of relationship. It should be understood that when enterprise equity or control relationship data changes, the graph structure is updated dynamically.

[0118] Starting from the enterprise node where the risk event occurs, the system automatically traverses the direct subordinate nodes in the control relationship graph downwards. By traversing all possible risk transmission paths, it identifies potentially affected enterprise nodes and obtains a list of risk transmission paths. Each path includes a node sequence, relationship type, and transmission direction.

[0119] Finally, based on the list of risk transmission paths, the risk transmission intensity R is quantitatively calculated. i :

[0120] .

[0121] Among them, R i R represents the risk transmission strength of the i-th level node, with a value ranging from 0 to 1. i A larger value indicates a stronger risk transmission impact.

[0122] This represents the vulnerability index of the i-th level node, with a value ranging from 0 to 1. .

[0123] This indicates the initial risk intensity, assigned a value based on the severity of the risk event. It represents the initial risk source intensity originating from the group level, such as the risk intensity of strategic decision-making errors or tight cash flow.

[0124] The product of the vulnerabilities of nodes at each level is represented by Π, which is the chain multiplication operator; group First-tier subsidiaries Second-tier subsidiaries The higher the vulnerability of a node, the larger the product, and the stronger the risk transmission.

[0125] This represents the reverse expression of the state-owned asset hierarchical chain-specific intervention coefficient. The coefficient of intervention measures targeting hierarchical transmission, such as subsidiary risk reporting systems and group fund control, is determined by the strength of the intervention. The smaller the value, the more significantly the risk transmission intensity is weakened.

[0126] Therefore, by tracing the transmission path based on the hierarchical chain of state-owned assets, it is possible to expand from risk events at specific points to a risk situation on a broader scale. This is a key link in preventing systemic risks and safeguarding the security of the state-owned economy, enabling early risk identification and warning.

[0127] Furthermore, we compared R at different levels i Numerical values ​​quickly pinpoint risk levels with high transmission intensity. For example, if a third-tier subsidiary R... i If the value is significantly higher than other levels, it indicates that the risk at this level is very likely to spread upwards to the group. The regulator can prioritize focusing on this level to carry out special inspections to avoid the risk from being amplified at each level.

[0128] As an optional implementation, the transmission path tracing is implemented using a depth-first search (DFS) algorithm. Starting with the enterprise node where the risk event occurred, the traversal search is performed according to a configured (configurable) depth, specifically including the following steps:

[0129] 1. Initialization: Add the starting node to the stack, mark it as "visited", and initialize the path list to be empty;

[0130] 2. Stack not empty check: If the stack is not empty, pop the top node of the stack and use it as the current node;

[0131] 3. Path recording: Add the current node to the current path;

[0132] 4. Termination condition judgment: If the current path length reaches the traversal depth, add the current path to the path list and backtrack to the previous node;

[0133] 5. Adjacent Node Traversal: Query all adjacent nodes of the current node (based on the specified transmission relationship type, including control relationship, equity participation relationship, guarantee relationship, and related transaction relationship), and filter out unvisited nodes;

[0134] 6. Recursive traversal: Mark unvisited adjacent nodes as "visited", add them to the stack, and repeat steps 2-5 above;

[0135] 7. Algorithm Termination: When the stack is empty, output all propagation paths. Each path contains the node sequence, relation type, and propagation direction, for example: S0 (Group) → S 11 (First-tier subsidiary, controlling relationship, 100% shareholding) → S 21 (Second-tier subsidiary, controlling relationship, 80% shareholding) → S 35 (Third-tier subsidiary, guarantee relationship, guarantee amount of 20 million yuan).

[0136] Furthermore, nodes with no potential for risk transmission (such as closed businesses or businesses with no actual business dealings) can be pruned to reduce the number of traversals.

[0137] In an optional embodiment, the transmission event can be further quantified to determine the time it takes for the source node to transmit to the i-th level of influencing node, reflecting the speed of risk spread.

[0138] In a further embodiment, the risk transmission strength R can be used as a basis. i Define warning levels and take corresponding interventions and measures. For example, different intervention and measures should be adopted for different warning levels.

[0139] As an optional implementation, a risk profile can be implemented using Vue.js + Echarts, displaying, for example, the number of risk events across the entire group, the distribution of warning levels, the distribution of high-risk levels, and the transmission path topology. Detailed information can also be provided for individual risk events, including: basic event information, triggering factors, transmission path (visualized hierarchical chain), risk intensity at each level (displayed on a heatmap), dynamic intervention coefficient, and rectification progress.

[0140] It should be understood that, in the embodiments of the present invention, each event has its unique DNA code. When each standardized event unit is generated, the system automatically generates a unique event DNA code according to preset rules and writes it into the event chain database. During tracing, queries based on multiple conditions such as event DNA code, event time, subject name, and event type are supported.

[0141] In some embodiments, based on the event chain database, the target event can be located in the event chain database according to the query conditions, the complete event unit information can be displayed, the event node can be located, or the upstream and downstream related events can be traced by associating the event ID field to form an event tracing chain.

[0142] {Example 2}

[0143] In conjunction with the enterprise penetration supervision method based on the decision chain of the above embodiments, the present invention also proposes a computer system, comprising:

[0144] One or more processors;

[0145] Memory stores instructions that can be operated.

[0146] When the instructions are executed by the one or more processors, the one or more processors perform an operation, the operation including the process of executing the enterprise penetration supervision method based on the decision chain of any of the foregoing embodiments.

[0147] {Example 3}

[0148] In conjunction with the decision chain-based enterprise penetration supervision method of the above embodiments, the present invention also proposes a computer-readable medium for storing software, the software including instructions executable by one or more computers, the instructions executing the process of the decision chain-based enterprise penetration supervision method of any of the foregoing embodiments when executed by the one or more computers.

[0149] While the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the invention. Those skilled in the art can make various modifications and refinements without departing from the spirit and scope of the invention. Therefore, the scope of protection of the present invention shall be determined by the claims.

Claims

1. A method for enterprise penetration supervision based on the decision-making chain, characterized in that, Includes the following steps: Step 1: Construct a multi-dimensional initial threshold model based on the inherent attributes and regulatory framework of state-owned enterprises, and dynamically adjust the thresholds according to the real-time financial health status and risk level of the enterprises to obtain a modified dynamic threshold model. Step 2: Deploy and embed the dynamic threshold model into key regulatory nodes of state-owned enterprise operations to form dynamic risk tracking points; Step 3: Define standardized event units (T, G, A, M, L), and convert the business data of state-owned enterprise operations into a structured event chain in standardized event unit format through standardized modeling; Step 4: Based on the structured event chain of dynamic risk tracking points, construct a three-tiered early warning mechanism: single-point real-time early warning, composite rule-based early warning, and transmission chain early warning. This enables real-time risk identification, accurate location, and prediction of risk spread. The single-point real-time early warning includes immediately activating a single-point early warning and marking the risk event information when a dynamic risk tracking point detects that event data in a structured event chain triggers a dynamic threshold. The composite rule-based early warning identifies composite risks by matching the set of event factors with the compliance rules defined by the business scenario. The transmission chain early warning system uses state-owned asset hierarchical chain analysis and graph algorithms to track risk diffusion paths, calculate transmission intensity, identify high-risk levels, and issue early warnings.

2. The enterprise penetration supervision method based on decision chain according to claim 1, characterized in that, In step 1, the construction of a multi-dimensional initial threshold model based on the inherent attributes and regulatory framework of state-owned enterprises, and the dynamic adjustment of the thresholds according to the real-time financial health and risk level of the enterprises, to obtain a modified dynamic threshold model, includes: Step 1.1: Based on the inherent attributes and regulatory framework of state-owned enterprises, construct a multi-dimensional initial threshold model, including the following process: Collect data from six core dimensions of state-owned enterprises and quantify them into V. i , representing the quantized value of the i-th dimension; Based on the industry calibration factor α and the standard reference value S std Calculate the initial threshold Th base : ; In the formula, W i The weight percentage of the i-th dimension is represented by i=1,2,3,4,5,6, which represent the six core dimensions, corresponding to the enterprise level Z(n), total net assets, main business risk level, industry average transaction size, regulatory red line requirements, and the number of risk events in the past three years, respectively. The standard reference value S std The benchmark amount is set according to the different levels of the regulatory framework; The industry calibration coefficient α is set according to industry characteristics, and its value ranges from 0.8 to 1.

2. Step 1.2: Obtain the company's debt-to-equity ratio (D), return on assets (R), and cash flow health coefficient (C) as dynamic parameters, and input them into the pre-trained gradient boosting tree model to dynamically adjust the weight coefficients W of each dimension. D W R W C W D +W R +W C =1; Step 1.3: Based on the initial threshold Th base and the dynamically adjusted weighting coefficient W D W R W C Calculate the corrected dynamic threshold Th: ; In the formula, ΔD represents the debt-to-asset ratio adjustment coefficient, ΔD=min[(DD std ) / D std [0.5], D std Let D be the industry average debt-to-equity ratio, when D ≤ D std When ΔD=0; ΔR represents the asset return adjustment factor, ΔR = min[(RR)] std ) / R std [0.3], R std Let R be the industry average return on assets, when R ≥ R std When ΔD=0; ΔC represents the cash flow adjustment factor, ΔC=min[(0.3-C) / 0.3, 0.4], when C≥0.3 ΔC=0; Furthermore, the overall constraint dynamic threshold can be adjusted by no more than 50% of the initial threshold and by no more than 20% of the initial threshold.

3. The enterprise penetration supervision method based on decision chain according to claim 2, characterized in that, In step 1, the pre-trained gradient boosting tree model takes the debt-to-equity ratio D, return on assets R, and cash flow health coefficient C as inputs, and automatically learns to dynamically adjust the weight coefficients of each dimension, outputting the dynamically adjusted weight coefficients W for each dimension. D W R W C Its training process includes: The input features include debt-to-asset ratio (D), return on assets (R), cash flow health coefficient (C), enterprise level, asset size, industry type, and risk event data from the past year. The actual occurrence of risk events is used as the label variable, with label 1 = risk occurred and label 0 = risk did not occur. A sample set was constructed using data from state-owned enterprises in the industry over the past five years, and then divided into training, testing, and validation sets according to proportions. The gradient boosting tree (GBDT) model is initialized and training parameters are set for iterative training. The training process uses gradient descent to minimize the loss function. The model accuracy is verified by testing the test machine every 10 iterations. Training is stopped when the accuracy improvement is ≤0.1%. The training parameters include: number of decision trees = 100, depth of each tree = 5, learning rate = 0.05, and log loss function. Use the validation set to verify the accuracy of the model and obtain the trained gradient boosting tree model.

4. The enterprise penetration supervision method based on decision chain according to claim 2, characterized in that, In step 1, incremental data is used to train the gradient boosting tree model incrementally based on the quarterly financial data of state-owned enterprises, and the model is updated in real time.

5. The enterprise penetration supervision method based on decision chain according to claim 2, characterized in that, In step 1, the definition and acquisition of the dynamic parameters include: The debt-to-equity ratio D = total liabilities / total assets × 100%, obtained from the most recent financial statements; Return on assets R = Net profit / Average total assets × 100%; calculated using a rolling 12-month period. The cash flow health coefficient C = (net cash flow from operating activities + net cash flow from investing activities + net cash flow from financing activities) / current liabilities. The coefficient ranges from 0 to 1. ≥0.3 indicates healthy cash flow, 0.1-0.3 indicates average cash flow, and <0.1 indicates tight cash flow.

6. The enterprise penetration supervision method based on decision chain according to claim 1, characterized in that, In step 2, the key regulatory nodes for the operation of state-owned enterprises include the supervision of fund transfers, equity changes, business approvals, and related-party transactions. The deployment method uses the Flink streaming computing framework to build a real-time processing pipeline, with each regulatory link corresponding to an independent processing operator. The fund transfer process combines event-driven and window-based calculations: it monitors individual transactions in real time based on event-driven methods, while calculating the cumulative transaction amount over 1 hour, 24 hours, and 72 hours based on a sliding window. Status monitoring is used for equity changes and related-party transactions: the status of corporate equity and the filing status of related-party relationships are recorded, and the monitoring logic is triggered when the status changes. The business approval process uses process node hooks: hook functions are set at each node of the approval system to obtain the node execution status in real time and compare it with the standard approval process to trigger anomaly detection.

7. The enterprise penetration supervision method based on decision chain according to claim 1, characterized in that, In step 3, the standardized event unit (T, G, A, M, L) is defined as follows: T represents the specific timestamp of the event, in YYYY-MM-DDHH:MM:SS format; G indicates the subject of the event execution, which is clearly defined as an enterprise or an internal department of an enterprise and the subject level attribute is marked. The name of the enterprise subject is identified by both the unified social credit code and the standardized name. A represents the core action of the event, which adopts a standardized multi-level tag system, where the first-level tags cover fund operations, equity changes, business approvals, and related transactions; M represents the object affected by the event, using a structured format of core data + supplementary information. L represents a state-owned assets exclusive label, containing two layers of core information, using a label type-value encoding format: where: The main asset ownership level label Z(n): n is the level, Z(0) represents the group, Z(1) represents the first-level subsidiary, Z(2) represents the second-level subsidiary, and so on. The level is automatically matched through the enterprise organizational structure tree. Subject-object relationship label K(x): K(c) represents equity participation, K(d) represents controlling stake, K(g) represents related party, and K(f) represents unrelated party. It is automatically determined through equity structure diagram and actual controller penetration analysis.

8. The enterprise penetration supervision method based on decision chain according to claim 1, characterized in that, In step 4, the single-point real-time early warning includes: In the fund transfer process: the amount of a single transaction is greater than or equal to the dynamic threshold, or the cumulative transaction amount within the sliding window is greater than or equal to the dynamic threshold × 1.5; Equity change process: Equity change ratio ≥ 5% and not filed, or change of actual controller not disclosed as required; Business approval process: approvals exceeding authority, missing key steps in the process, or approval time exceeding twice the standard time. Related party transactions: Transaction amount ≥ dynamic threshold, or transaction price deviates from fair market price ±10%; If any dynamic risk tracking point detects that event data in the structured event chain triggers the above warning conditions, the core information of the event is extracted and the event chain database is called to obtain related event information, and warning information including warning ID, warning time, involved subject, regulatory link, event factor, trigger threshold, and related event ID is generated.

9. The enterprise penetration supervision method based on decision chain according to claim 8, characterized in that, The processing flow for the composite rule-based early warning includes: Extract key information such as event factors, involved entities, and business scenarios from single-point early warning information; Based on the composite rule of "event factor set (E) ∧ business scenario limitation (S)", the warning level will be upgraded for those that meet the composite rule. Among them, event factors constitute the basic risk events of the risk portfolio and have independent risk attributes; E represents the set of basic risk events of each type, E=(E1,E2,E3,…,E…). n ); The logical operator ∧ represents an AND relationship, indicating that all events must be satisfied simultaneously; Business scenario limitations refer to the specific subject attributes and business scope limitations of state-owned asset operations.

10. The enterprise penetration supervision method based on decision chain according to claim 9, characterized in that, The transmission chain early warning process includes: Based on the management and control system of state-owned enterprises, with Group S0 as the top starting point, and extending downwards according to the management and control relationship, a hierarchical chain of state-owned assets is formed. Group S0 → First-tier subsidiary S 11 ,S 12 ,...,S 1m →Second-tier subsidiary S 21 ,S 22 ,...,S 2n →...→N-level subsidiary S n1 ,S n2 ,...,S nk In this context, → indicates the direction of risk transmission from the upper level to the lower level, reflecting a top-down hierarchical diffusion logic. A management and control relationship graph is constructed based on the state-owned asset hierarchy chain, where each node represents an enterprise and the edges represent control or related relationships. Control relationships are marked with the shareholding ratio, and related relationships are marked with the type of association. Starting from the enterprise node where the risk event occurs, the system automatically traverses the direct subordinate nodes in the control relationship graph downwards. By traversing all possible risk transmission paths, it identifies potentially affected enterprise nodes and obtains a list of risk transmission paths. Each path includes a node sequence, relationship type, and transmission direction. Based on the list of risk transmission paths, the risk transmission intensity R is quantitatively calculated. i : ; Among them, R i R represents the risk transmission strength of the i-th level node, with a value ranging from 0 to 1. i A higher value indicates a stronger risk transmission impact; This represents the vulnerability index of the i-th level node, with a value ranging from 0 to 1. ; This indicates the initial risk intensity, and is assigned a value based on the severity of the risk event. This represents the product of the vulnerabilities of nodes at each level, with Π being the chain multiplication operator. This represents the reverse expression of the state-owned asset hierarchical chain-specific intervention coefficient. For the intervention coefficients targeting the transmission at level i.

11. A computer system, characterized in that, include: One or more processors; A memory that stores operable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations, including the process of performing the method of any one of claims 1-10.

12. A computer-readable medium for storing software, characterized in that, The software includes instructions executable by one or more computers, which, when executed by the one or more computers, perform the process of the method as described in any one of claims 1-10.