Intelligent compliance management method and device based on large model, equipment and medium
By using a large-scale model-based intelligent compliance management approach, compliance issues are analyzed and personalized suggestions are generated, which solves the problems of low efficiency and high error rate in existing compliance management, and achieves efficient and accurate compliance management that can adapt to specific enterprise needs and provide real-time feedback.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 深圳市和讯华谷信息技术有限公司
- Filing Date
- 2025-11-14
- Publication Date
- 2026-04-21
AI Technical Summary
Existing compliance management suffers from low efficiency, high error rates in manual review, and a lack of personalized advice. In particular, existing tools struggle to provide effective support when faced with complex laws and regulations and specific corporate needs.
We adopt a big model-based intelligent compliance management approach. By analyzing compliance issues and extracting key information through a pre-trained big model, we match compliance documents and question-and-answer combinations in a dynamic knowledge base to generate personalized compliance suggestions. We also continuously optimize the model through online learning and incremental update mechanisms.
It improves the efficiency and accuracy of compliance management, reduces the audit error rate, can provide personalized suggestions based on enterprise characteristics and user needs, enhances the adaptability and flexibility of compliance management, provides real-time feedback and alerts, and reduces legal risks.
Smart Images

Figure CN121902149A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security compliance, and in particular to an intelligent compliance management method, device, equipment and medium based on a large model. Background Technology
[0002] With the development of global information technology and the increasing awareness of data privacy protection, various policies and regulations (such as GDPR, CCPA, and ISO 27001) have been introduced, placing higher demands on enterprises' information security and compliance. However, many enterprises face numerous challenges in adhering to these compliance standards, including but not limited to the following: Managing the complexity of compliance requirements: The laws and regulations of different countries and regions are numerous and frequently updated, requiring companies to spend a lot of time and manpower to track changes in relevant policies; Traditional compliance management is inefficient: Currently, most companies rely on manual review and manual checks of compliance, which is not only time-consuming but also prone to human error, leading to increased compliance risks. Lack of real-time monitoring mechanism: The system cannot provide real-time feedback and alerts, and enterprises can usually only discover compliance issues after the fact, resulting in wasted resources and even legal liability; Insufficient compliance knowledge among employees: The understanding and mastery of compliance matters vary among employees, and the lack of effective training and guidance leads to errors and omissions in the compliance implementation process; Lack of personalized compliance advice: Existing compliance management tools often fail to provide personalized advice based on the specific needs and industry context of an enterprise, limiting the flexibility and adaptability of enterprises in practice. Summary of the Invention
[0003] This application mainly provides an intelligent compliance management method, device, equipment, and medium based on a large model to solve the problems of low management efficiency, high error rate of manual review, and inability to provide personalized suggestions in existing compliance management.
[0004] To address the aforementioned technical problems, this application adopts the following technical solution: providing an intelligent compliance management method based on a large model. This method includes: In response to the input compliance questions, the system analyzes the compliance questions based on a pre-trained large model and extracts key information. Based on the key information, a combination of compliance documents and questions / answers is matched in the dynamic knowledge base; Based on the compliance document, the question-and-answer combination, and the pre-built dialogue dataset, compliance recommendations are generated.
[0005] In one optional embodiment of this application, the pre-training method of the large model includes: Based on the large model, each compliance document in the dynamic knowledge base is segmented; Identify the compliance requirements for each compliance document segment and use the compliance requirements as the tags for the compliance document segments; For each of the aforementioned compliant documents, multiple question-and-answer combinations are generated in segments to obtain a training dataset; Set task objectives for the large model and train the large model based on the training dataset to obtain a large model that can meet the task objectives; the task objectives include at least responding to user requests, identifying compliance risks, and generating compliance recommendations.
[0006] In one optional embodiment of this application, the step of matching compliance documents and question-and-answer combinations in the dynamic knowledge base based on the key information includes: Based on the key information, the tags in the dynamic knowledge base are matched, and based on the tags, the corresponding compliance document segments and the associated multiple question-and-answer combinations are determined; Based on the key information, the question-and-answer combination with the strongest relevance is matched among multiple question-and-answer combinations.
[0007] In an optional embodiment of this application, after obtaining the large model capable of satisfying the task objective, the method further includes: Based on the large model and preset prompts, create a dialogue example for the user; The dialogue examples are created in multiple rounds to obtain the dialogue dataset, and the large model and the preset prompt words are fine-tuned.
[0008] In one optional embodiment of this application, the method further includes: The compliance documentation shall include at least historical compliance data and compliance policy documents; In response to the input compliance question being a compliance risk identification question, the system identifies the compliance risks based on the pre-trained large model using the historical compliance data and the compliance policy documents, and generates compliance recommendations for the compliance risks.
[0009] In one optional embodiment of this application, the method further includes: The compliance documents also include internal company documents; In response to the input compliance question being a compliance requirement identification question, the system extracts relevant compliance requirement information from the enterprise's internal documents based on the pre-trained large model and matches the corresponding compliance requirements in the compliance policy documents. The compliance recommendations are generated by comparing the relevant information of the compliance requirements with the corresponding compliance requirements.
[0010] In an optional embodiment of this application, after generating the compliance recommendation, the method further includes: The system receives feedback from the user and updates the large model in real time based on the feedback and the online learning mechanism.
[0011] In one optional embodiment of this application, the method further includes: In response to the update of compliance documents in the dynamic database, the large model is updated based on incremental learning techniques.
[0012] To address the aforementioned technical problems, another technical solution adopted in this application is to provide an intelligent compliance management device based on a large model. This device includes: The extraction module is used to respond to user-input compliance questions, analyze the compliance questions based on a pre-trained large model, and extract key information. The matching module is used to match compliance documents and question-and-answer combinations in the dynamic knowledge base based on the key information; The generation module is used to generate compliance suggestions and feed them back to the user based on the compliance document, the question-and-answer combination, and the pre-built dialogue dataset.
[0013] To solve the above-mentioned technical problems, another technical solution adopted in this application is: to provide a computer device, including a memory, a processor and a computer program stored in the memory, characterized in that the processor executes the computer program to implement the steps of the above-mentioned intelligent compliance management method based on a large model.
[0014] To solve the above-mentioned technical problems, another technical solution adopted in this application is: to provide a storage medium on which a computer program is stored, characterized in that the computer program, when executed by a processor, implements the steps of the above-mentioned intelligent compliance management method based on a large model.
[0015] The beneficial effects of this application are as follows: Unlike existing technologies, this application discloses an intelligent compliance management method, apparatus, device, and medium based on a large model. This method uses a pre-trained large model to analyze input compliance questions, extracts key information, and matches it with compliance documents and question-and-answer combinations in a dynamic knowledge base. Then, using a pre-built dialogue dataset as context, it generates personalized compliance suggestions for the enterprise. The entire automated process does not rely on manual intervention, effectively improving management efficiency and reducing the audit error rate. Furthermore, by constructing a dynamic knowledge base to store compliance documents for the enterprise and dialogue datasets corresponding to different user identities, it can provide personalized suggestions based on enterprise characteristics and user needs, improving the adaptability and flexibility of compliance management. Attached Figure Description
[0016] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort, wherein: Figure 1 This is a flowchart illustrating an embodiment of the intelligent compliance management method based on a large model provided in this application; Figure 2 This is a schematic diagram of the structure of an intelligent compliance management system according to an embodiment of the intelligent compliance management method based on a large model provided in this application; Figure 3 This is a schematic diagram of the user-big-model interaction question and answer process in an embodiment of the intelligent compliance management method based on a big model provided in this application; Figure 4 This is a schematic diagram of the structure of an embodiment of the intelligent compliance management device based on a large model provided in this application; Figure 5 This is a schematic diagram of the structure of an embodiment of the storage medium provided in this application; Figure 6 This is a schematic diagram of the structure of an embodiment of the computer device provided in this application. Detailed Implementation
[0017] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of the embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0018] The terms "first," "second," and "third" used in the embodiments of this application are for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined as "first," "second," or "third" may explicitly or implicitly include at least one of that feature. In the description of this application, "multiple" means at least two, such as two, three, etc., unless otherwise explicitly specified. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or devices.
[0019] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a mutually exclusive, independent, or alternative embodiment. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0020] This application provides an intelligent compliance management method based on a large model, see reference. Figure 1 , Figure 1 This is a flowchart illustrating an embodiment of the intelligent compliance management method based on a large model provided in this application. The intelligent compliance management method based on a large model includes: S10: In response to input compliance issues, analyze compliance issues based on a pre-trained large model and extract key information.
[0021] Compliance issues refer to various questions or needs related to corporate operations, laws and regulations, and industry practices within the field of compliance management. These issues may involve multiple specific aspects such as data protection compliance, financial reporting compliance, labor law compliance, and environmental compliance, aiming to ensure that corporate activities are conducted within the legal framework and to avoid legal risks and economic losses caused by violations.
[0022] Large Language Models (LLMs) are deep learning-based models with massive parameters and powerful language understanding and generation capabilities. By pre-training on large-scale text corpora, LLMs learn grammatical rules, semantic relationships, and world knowledge, enabling complex natural language processing tasks such as text generation, question-and-answer interaction, and logical reasoning. The large model pre-trained in this application can be any of the following: DeepSeek, GPT series, or BERT, without specific limitations.
[0023] This application utilizes an intuitive and user-friendly conversational interface, accessible via both web and mobile devices, allowing users to input compliance questions at any time. For example, a user can access the compliance query interface via smartphone, enter a compliance question (such as regulatory requirements or compliance measures) in the chat interface, and the pre-trained large model receives the input, processes the question, and provides relevant suggestions to the user in real time. This conversational question query makes it easy for employees without technical backgrounds to use, lowering the barrier to entry and increasing employee compliance awareness and participation.
[0024] In this application, the pre-training methods for the large model are as follows: S11: Based on the large model, each compliant document in the dynamic knowledge base is segmented.
[0025] In this application, the dynamic knowledge base is a collective term for a collection of multiple sub-knowledge bases storing compliance documents, which are categorized by compliance requirements. Compliance documents include internal company documents, compliance policy documents (national / industry policies and internal company policies), and historical compliance data.
[0026] The collection of compliance documents can be achieved using web crawling technology, which can automatically retrieve the latest regulatory documents, compliance manuals and industry reports and other compliance policy documents from government websites, industry associations and legal databases, retrieve internal documents and policies from internal enterprise databases, and retrieve historical compliance data from large model operation logs.
[0027] Specifically, web crawlers are scheduled to run regularly to ensure continuous acquisition of the latest information. The crawlers are configured to extract structured and unstructured data related to compliance, including regulatory clauses, policy updates, and other compliance guidelines as compliance documents. The extracted compliance documents undergo text parsing and data cleaning, including removing irrelevant noise, processing punctuation, and standardizing formats, to improve data quality. The cleaned compliance documents can then be manually reviewed, and the reviewed documents are uploaded to a dynamic knowledge base to ensure data integrity and validity. Furthermore, batch uploading of compliance documents is supported, and the documents support formats such as TXT, Markdown, PDF, DOCX, HTML, XLS, XLSX, CSV, and ZIP.
[0028] For all compliance documents uploaded to the dynamic knowledge base, after optical character recognition (OCR), a series of operations are performed, including paragraph segmentation and clause-level named entity recognition (NER) to automatically extract clauses and quantify them, using large-scale natural language processing technology. This collaboratively achieves the transformation from "unstructured documents" to "structured clauses," supporting the construction of the dynamic knowledge base and the efficient retrieval of compliance information.
[0029] Optical character recognition (OCR) refers to the process of converting scanned documents and compliant documents in image format (such as PDF scans) into editable text, thus solving the machine readability problem of non-text documents.
[0030] Paragraph segmentation refers to dividing compliant documents into multiple independent segments based on semantic logic or format features (such as headings and chapters) using a large model, ensuring the integrity and independence of text units. Furthermore, each compliant document segment undergoes in-depth analysis, including word segmentation, part-of-speech tagging, and syntactic analysis, enabling the large model to understand its text structure and semantics.
[0031] Named entity recognition refers to the process of accurately extracting key terms, legal clauses, policy points, and compliance elements from compliance documents using a large model and quantifying them, such as extracting entities like "data protection" and "privacy rights," and then applying relationship extraction algorithms to identify the relationships between these entities.
[0032] S12: Identify the compliance requirements for each compliance document segment and use the compliance requirements as tags for the compliance document segments.
[0033] Based on the key terms, regulatory clauses, and compliance elements extracted from named entity recognition, the large model automatically matches and identifies the relevant compliance requirements corresponding to this information, and uses the identified compliance requirements as tags for the compliance document segments. Compliance documents are categorized and stored using these tags, with segments of compliance documents with the same tags stored in the same sub-knowledge base. The tags can also serve as the titles for sub-knowledge base management, enabling rapid identification and management of compliance information.
[0034] When identifying relevant compliance requirements, the system automatically matches and identifies relevant compliance requirements from compliance policy documents based on enterprise documents and historical compliance data; for compliance policy documents, it automatically identifies and extracts relevant compliance requirements from the compliance policy documents.
[0035] S13: Generate multiple question-and-answer combinations for each compliant document segment to obtain the training dataset.
[0036] For each compliant document in the dynamic knowledge base, questions are generated segment by segment. Specifically, relevant prompts are set for the large model to generate questions, such as "Please summarize the above content and generate 5 questions based on the content," and the answer requirements for the large model are set, such as "The output questions should be placed in..." <question>< / question> The system generates multiple question-and-answer mappings (referred to as question-and-answer combinations) for each compliance document segment, storing these segments and their associated question-and-answer combinations in the same sub-knowledge base. By generating questions for each compliance document segment, information extraction and understanding are facilitated, thereby supporting the generation of subsequent compliance recommendations.
[0037] For example, when segmenting a certain information security specification document, the large model will automatically generate the following questions: <question> What is the main objective of this specification?< / question> <question> Which industries does this standard apply to?< / question> <question> What are the main requirements for implementing this standard?< / question> <question> What are the possible consequences of violating this regulation?< / question> <question> How can we ensure the effectiveness of following this specification?< / question> Furthermore, the large model will also generate corresponding answers for each question based on the content of the information security specification document segments. These answers are optimized based on an understanding of the document content itself.
[0038] During the process of generating question-and-answer combinations, the generation results of the large model are observed and optimized to improve the quality and relevance of the generated questions.
[0039] S14: Set task objectives for the large model and train the large model based on the training dataset to obtain a large model that can meet the task objectives. The task objectives include at least responding to user requests, identifying compliance risks, and generating compliance recommendations.
[0040] In this application, at the very beginning of the pre-training stage of the large model, key terms, regulatory clauses, policy points, and compliance elements in compliance documents can be identified through manual annotation, and relevant compliance requirements can be identified to obtain a compliance text dataset, which is divided into training set, validation set, and test set. This helps the large model learn specific contexts, enabling it to accurately extract key terms, regulatory clauses, policy points, and compliance elements from compliance documents and identify relevant compliance requirements.
[0041] Then, this large model capable of identifying compliance requirements can be used to automatically annotate all compliance documents in the dynamic knowledge base. The annotation process includes segmenting the compliance documents, extracting key terms, regulatory clauses, policy points, and compliance elements, quantifying them, identifying and labeling relevant compliance requirements, and asking and answering questions for each segment. This creates sub-knowledge bases corresponding to the labels in the dynamic knowledge base. These sub-knowledge bases contain the compliance document segments and associated question-and-answer combinations, thus obtaining the training dataset.
[0042] Set task objectives for the large model, including at least responding to user requests (question answering), identifying compliance risks (classification), and generating compliance recommendations (generation task); configure the training environment for the large model and adjust hyperparameters (such as learning rate and batch size). Divide the obtained training dataset into training, validation, and test sets. Train the large model using the training set, updating the model weights through backpropagation to adapt it to the specific compliance task; evaluate the performance of the large model on the validation and test sets, monitoring accuracy and other metrics, and optimize the fine-tuning process based on the results.
[0043] The large model obtained through the above pre-training can meet the task objectives, enabling it to accurately understand the terminology and context of the compliance field, improve its ability to parse user input, and generate personalized compliance suggestions based on user background and needs, recommending best practices that comply with the latest regulatory requirements.
[0044] Unlike existing compliance management tools, which often fail to provide personalized recommendations based on specific enterprise needs and industry context, thus limiting the flexibility and adaptability of enterprises in practical operations, this application provides an intelligent compliance management method based on a large model. In the aforementioned pre-training process, the large model is fine-tuned for enterprise customization by combining internal enterprise documents and historical compliance data as training datasets, and further fine-tuned for industry-specific policies and regulations by combining compliance policy documents as training datasets. This enables the large model not only to understand general text but also to accurately parse information in specific domains, making it more targeted and practical. This significantly improves the accuracy of compliance identification, enhances the large model's understanding of industry-specific terminology and its context, effectively parses complex compliance information, greatly improves the quality of compliance recommendations generated, and enhances the flexibility and adaptability of enterprises in practical operations.
[0045] In this application, after obtaining a large model that can meet the task objectives, it also includes: Based on a large model and preset prompts, create examples of user dialogue; Multiple rounds of dialogue examples are created to obtain a dialogue dataset, and the large model and preset prompts are fine-tuned.
[0046] In this application, after obtaining a large model that can meet the task objectives, that is, when the large model can conduct compliance question dialogues after pre-training, the large model is further fine-tuned in order to enable the large model to parse users' compliance questions in real time and provide suggestions.
[0047] Specifically, first, a preset prompt word is set for the large-scale model to guide it in generating accurate answers to specific compliance questions. Then, dialogue examples containing compliance questions and their answers are collected and created to help the model learn how to effectively respond to user inquiries. These examples are created by posing compliance questions to the large-scale model, and the model is continuously debugged and the preset prompt word is modified based on the answers provided during the dialogue to ensure more accurate responses. These dialogue examples should cover various possible compliance scenarios and corresponding compliance questions to ensure broad representativeness and practicality.
[0048] Multiple rounds of dialogue examples are created to enhance the large model's ability to maintain information coherence in multi-turn dialogues, enabling it to provide more context-aware suggestions based on the user's questioning history. By continuously enriching and refining the dialogue examples through multiple rounds, a large-scale, high-quality dialogue dataset is formed.
[0049] During the multi-round dialogue example creation process, different user identities (such as corporate managers, finance personnel, or ordinary employees) and different industry backgrounds can be used to create dialogues, such as "As a finance personnel..." or "In the financial industry...". This allows the large model to accurately identify compliance issues under different identities and industry backgrounds and provide targeted suggestions. Simultaneously, diverse compliance issue types are introduced, such as legal and regulatory compliance, internal policy implementation, and business process compliance, to comprehensively enhance the large model's ability to handle complex compliance scenarios. Furthermore, the quality and coverage of the dialogue dataset can be regularly evaluated, and the dialogue example creation strategy can be adjusted based on the evaluation results to ensure the timeliness and comprehensiveness of the dataset, thereby continuously optimizing the performance of the large model.
[0050] By using this dialogue dataset, the large model and preset prompts are continuously fine-tuned, enabling the large model to more accurately understand the intent of compliance questions raised by users with different identities and industry backgrounds, and quickly generate compliance suggestions that meet the needs of users.
[0051] In this application, when a user enters a compliance question in the dialog interface, the pre-trained large model can understand its semantics and parse the input compliance question, accurately identify and extract key information in the compliance question, such as the specific compliance area involved (e.g., data protection, financial reporting, etc.), key terms (e.g., specific law names, industry terms), and the core demands of the question (e.g., seeking legal interpretation, compliance measure suggestions).
[0052] S20: Based on key information, match compliance documents and question-and-answer combinations in a dynamic knowledge base.
[0053] In this application, compliance documents and question-and-answer combinations in a dynamic knowledge base are matched based on key information, including: Based on key information, tags in a dynamic knowledge base are matched, and based on the tags, corresponding compliance document segments and multiple associated question-and-answer combinations are determined. Based on key information, the question-answer combination with the strongest relevance is matched among multiple question-answer combinations.
[0054] In this application, the large model extracts key information from compliance issues and performs precise matching based on this key information within a dynamic knowledge base. Since the dynamic knowledge base segments and categorizes compliance documents according to compliance requirements (tags), the large model quickly locates relevant sub-knowledge bases during the matching process by comparing the extracted key information with the tags in the dynamic knowledge base. This allows it to locate all compliance document segments and their associated question-and-answer combinations within that sub-knowledge base. Next, a deeper analysis is conducted combining the key information with each compliance document segment to select the compliance document segment with the strongest relevance to the key information. The relevance of the question-and-answer combinations is then ranked, and the most relevant question-and-answer combination is ultimately selected.
[0055] For example, when a user enters a question about cross-border data transfer in data protection compliance, the large model will locate the data protection-related sub-knowledge base and filter out the compliance document segments involving cross-border data transfer and the most relevant question-and-answer combinations.
[0056] By matching compliance documents and question-and-answer combinations from a dynamic knowledge base based on key information, the large-scale model ensures that it provides users with accurate and targeted compliance information. The dynamic knowledge base is continuously updated and improved to adapt to the ever-changing compliance environment, and the large-scale model continuously learns new compliance knowledge and cases, enhancing its matching capabilities and accuracy. Furthermore, to further improve matching efficiency, the large-scale model can employ optimization strategies, such as using caching technology to store frequently used compliance document segments and question-and-answer combinations, reducing the time spent on repetitive matching.
[0057] S30: Generate compliance recommendations based on compliance documents, question-and-answer combinations, and pre-built dialogue datasets.
[0058] In this application, after matching the compliance document and question-answer combination that is most relevant to the input compliance question, the large model further utilizes a pre-built dialogue dataset as context to comprehensively analyze the matched compliance document segments and related question-answer combinations in order to generate highly targeted personalized suggestions.
[0059] Specifically, based on key information such as user identity or industry background contained in the compliance questions input by the user, the model retrieves corresponding dialogue examples from a pre-built dialogue dataset as the context of the dialogue. By introducing these identity-specific dialogue examples, the large model can gain a deeper understanding of the user's specific situation and needs. This allows it to fully consider the impact of user identity or industry background on compliance requirements when analyzing compliance document segments and related question-and-answer combinations, thus optimizing the answers in the question-and-answer combinations. Finally, combined with the context, the large model generates compliance recommendations that conform to general compliance standards while also taking into account the user's personalized needs. Furthermore, the compliance recommendations fed back to the user also include the source data of the compliance document segments, providing supporting materials for the user to consult and reference.
[0060] For example, for users with a healthcare background, the large model can accurately filter out healthcare-related compliance dialogue examples from a pre-built dialogue dataset. When comprehensively analyzing compliance document segments and related question-and-answer combinations, it fully considers the specific compliance requirements of the healthcare industry in areas such as data privacy protection and medical operating procedures, thereby generating personalized compliance suggestions tailored to the actual needs of the healthcare industry. As another example, for users who are finance professionals, the large model will prioritize referencing compliance dialogue examples related to the finance field, gaining a deep understanding of the compliance issues and specific needs that finance professionals may encounter in their daily work. Then, when analyzing compliance document segments and related question-and-answer combinations, it accurately grasps the key compliance points of finance work, optimizes the answers in the question-and-answer combinations, and makes the generated compliance suggestions more relevant to the actual work scenarios of finance professionals.
[0061] After the large model outputs compliance recommendations to the user, the above dialogue will also be recorded in the log and added to the dialogue dataset. The continuously updated dialogue dataset covers historical dialogue records on various compliance issues from different identities (such as corporate managers, financial personnel, or ordinary employees) and different industry backgrounds, serving as the context to support the generation of compliance recommendations when the user has another dialogue with the large model.
[0062] By continuously enriching and updating the dialogue dataset, the large-scale model can learn the characteristics of compliance requirements under different identities and industry backgrounds, further improving the accuracy and practicality of generating personalized compliance suggestions. Each new dialogue record added allows the large-scale model to gain a more comprehensive understanding of various compliance scenarios. When faced with compliance questions from users with similar identities or industry backgrounds, it can more quickly and accurately call upon relevant dialogue examples as context for comprehensive analysis and to generate high-quality compliance suggestions.
[0063] In this application, the compliance documents include at least historical compliance data and compliance policy documents; in response to the input compliance question, which is a compliance risk identification question, compliance risks are identified based on the historical compliance data and compliance policy documents using a pre-trained large model, and compliance recommendations are generated for the compliance risks.
[0064] In this application, the compliance questions input by users include various types, such as compliance risk identification questions, compliance requirement identification questions, compliance process consultation questions, and compliance policy interpretation questions. For different types of compliance questions, the large model will call upon the corresponding processing logic and dynamic knowledge base for accurate analysis and answers.
[0065] When a user enters a compliance question about compliance procedures, the big model will provide detailed operational guidance based on established compliance process specifications. When a user enters a compliance question about interpreting compliance policies, the big model will provide easy-to-understand explanations of the policy provisions, taking into account the policy background and actual business scenarios.
[0066] When a user inputs a compliance question about identifying compliance risks, the large-scale model, while analyzing the question, extracts relevant keywords for compliance risk identification. It then uses the company's historical compliance data in a dynamic knowledge base to identify compliance risks, based on compliance policy documents found in the knowledge base. Specifically, the model deeply analyzes historical compliance data and policy documents, predicts potential compliance risks within the historical data, and automatically generates compliance recommendations based on legal provisions and best practices using pre-set prompts for compliance risk identification. It then sends reminders to relevant personnel to ensure timely implementation of these recommendations. Furthermore, these compliance recommendations are real-time; they are updated whenever compliance policy documents are changed or updated, providing users with real-time compliance advice to help them make informed compliance decisions.
[0067] In this application, in response to the input compliance question, which is a compliance requirement identification question, relevant compliance requirement information is extracted from internal enterprise documents based on a pre-trained large model, and the corresponding compliance requirements are matched in the compliance policy documents. Compare relevant information on compliance requirements with the corresponding compliance requirements, and generate compliance recommendations.
[0068] In this application, when the compliance question input by the user is a compliance requirement identification question, similar to the process of performing named entity recognition on compliance documents and extracting key terms, legal clauses, and compliance elements when building a dynamic knowledge base, the large model will perform named entity recognition on internal enterprise documents to extract compliance requirement-related information. This information will then be matched and compared with the corresponding compliance requirements in compliance policy documents to identify potential compliance gaps. After identifying potential compliance gaps, the large model will further analyze the specific content of these gaps, including the relevant legal clauses, potential risks, and impact on enterprise operations. Subsequently, the large model will combine the specific requirements in compliance policy documents with industry-recognized best practices to generate targeted and actionable compliance recommendations. These recommendations aim to help enterprises fill compliance gaps, adjust internal documents to comply with the latest policies and regulations, improve compliance management, and reduce compliance risks. Furthermore, similar to the compliance risk identification question, when compliance policy documents are changed or updated, the large model will also update the compliance recommendations in a timely manner to ensure that users always have access to the latest and most accurate compliance guidance.
[0069] Furthermore, regardless of the type of compliance issue mentioned above, if a user inputs a compliance question containing compliance information, the large-scale model will conduct a risk assessment and analysis based on this information during the compliance suggestion generation process, providing the user with practical compliance measures. This compliance information refers to various data, facts, policy provisions, and business operation details related to compliance that the user inputs. This compliance information may cover financial data, transaction records, or personnel management information from the company's operations, or it may include regulatory requirements or industry standards that must be followed in specific industries. It serves as a crucial basis for the large-scale model's risk assessment and analysis, helping it accurately identify potential compliance risks and provide effective response strategies.
[0070] Specifically, risk assessment and analysis, during the compliance recommendation generation process, involves comprehensively evaluating user-input compliance information, compliance policy documents, and historical compliance data to identify and manage potential compliance risks. This includes risk identification, risk assessment, and response strategies. Specifically, risk identification involves comparing user-input compliance information with compliance policy documents to identify compliance gaps and analyzing historical compliance data to identify compliance risks in similar scenarios. Risk assessment categorizes risks into high, medium, and low levels based on their severity and probability of occurrence, assessing the potential impact of different risk levels on the company, such as financial losses or reputational damage. Response strategies provide compliance action recommendations for addressing compliance gaps and risks, helping users mitigate risks and recommending preventative measures and optimizing internal documentation to reduce future risks.
[0071] Unlike existing technologies that rely on manual review and checks for compliance, which are time-consuming, prone to human error leading to increased compliance risks, and lack real-time feedback and alerts, this application presents a large-scale model-based intelligent compliance management method. This method automates the collection, analysis, and interpretation of compliance information, enabling rapid and accurate identification of potential compliance risks and providing real-time compliance recommendations. This reduces legal liability and economic losses due to violations of laws and regulations. Leveraging the powerful computing and deep learning capabilities of the large-scale model, it effectively avoids oversights and errors inherent in manual reviews. Furthermore, it provides real-time feedback and alert mechanisms, immediately notifying relevant personnel upon detection of compliance risks, allowing the company to take immediate action. This significantly reduces compliance risks, minimizes resource waste, and avoids potential legal liabilities.
[0072] This application, after generating compliance recommendations, also includes: Receive user feedback and update the large model in real time based on the feedback and online learning mechanism.
[0073] This application establishes a real-time feedback mechanism and user feedback channels. After receiving compliance recommendations from the large model, users can provide feedback (such as suggestions or ratings), which will be stored in the large model's runtime log. For example, users can provide feedback on the practicality, accuracy, and operability of the compliance recommendations, pointing out potential shortcomings or inconsistencies with actual business scenarios. Upon receiving this feedback, the large model will immediately process and analyze the data through an online learning mechanism, continuously optimizing its parameters and algorithms to achieve real-time updates and improve the quality and relevance of subsequent compliance recommendations.
[0074] In this application, in response to updates to compliance documents in the dynamic database, the large model is updated based on incremental learning technology.
[0075] This application also incorporates a dynamic update mechanism. By periodically scheduling and running web crawlers, it ensures the continuous acquisition of the latest regulatory and policy data, enabling real-time updates to the dynamic knowledge base. When updating the dynamic knowledge base, each sub-knowledge base can be updated individually. Once a segment of a compliance document in a sub-knowledge base is updated, the updated compliance document is re-segmented, and questions and answers related to the new compliance document segment are used to overwrite the previous sub-knowledge base. A new relevance index is generated for the question-answer combination to complete the update of that sub-knowledge base. Meanwhile, for sub-knowledge bases that have not been updated, their original content remains unchanged, with only the updated parts being addressed. This improves update efficiency while ensuring the integrity of the knowledge base.
[0076] Incremental learning techniques adjust and update the parameters of a large model only for newly collected data, rather than retraining the entire model. This improves efficiency and preserves existing knowledge.
[0077] Both of the above update methods occur in real time. As new regulations are introduced and user feedback accumulates, large models can be retrained periodically to ensure that the models adapt to the latest compliance environment and improve their performance.
[0078] After each update to the large model, rigorous verification and testing are performed to ensure that the model remains accurate and reliable. Version control is also implemented, recording the parameters of each major model update, allowing for a quick rollback to previous versions if necessary to prevent issues with the new version from affecting operation.
[0079] By automatically updating the dynamic knowledge base and optimizing the large model, the system achieves rapid response and precise adaptation to the compliance management environment. On one hand, automatically updating the dynamic knowledge base promptly captures subtle changes in regulations and policies, integrating the latest compliance requirements into the knowledge system and providing comprehensive and timely data support for the large model. On the other hand, optimizing the large model, through online learning mechanisms, incremental learning technology, and regular retraining, continuously improves the model's understanding and handling capabilities for complex compliance scenarios. This allows the model to dynamically adjust its decision-making logic based on new regulations and user feedback, ensuring that the generated compliance recommendations and management solutions always meet the latest requirements. This two-way optimization mechanism effectively enhances the adaptability and reliability of the intelligent compliance management system.
[0080] In this application, during the dialogue between the user and the large model, the user's query history and related behaviors can be recorded, the compliance status can be tracked in real time, and a compliance status report can be generated in real time. This provides management with a comprehensive analysis of the compliance situation, which helps to quickly identify potential risks and take necessary measures.
[0081] User-related behaviors include: query history, referring to users' search records for compliance issues or regulations, such as viewing specific legal clauses; decision-making records, referring to the choices users make in compliance management, such as approving or rejecting recommendations; usage frequency, referring to the number of times and duration users use the large model, reflecting their level of attention to compliance information; user feedback, referring to users' satisfaction ratings or suggestions for compliance recommendations, helping to identify effective recommendations; task completion status, referring to compliance-related tasks completed by users in the system, such as filling out checklists or submitting reports; and alert response, referring to users' viewing and handling of compliance alerts or notifications.
[0082] Compliance status tracking refers to the continuous monitoring and evaluation of an organization's compliance performance to ensure adherence to relevant laws, regulations, and internal policies. The process includes: real-time updates of compliance documents in a dynamic knowledge base; defining key compliance indicators (KPIs), such as compliance audit frequency and the number of violations, to quantify compliance status; deploying monitoring tools to automate the monitoring of compliance indicators and setting up alert systems to notify management when indicators exceed thresholds; using data analytics and visualization tools to generate dynamic dashboards providing an intuitive view of compliance performance; automatically generating compliance status reports based on real-time data and regularly sending them to management, summarizing the compliance status and providing improvement suggestions; and establishing feedback channels for management and employees to report compliance issues, driving continuous improvement.
[0083] A compliance status report typically includes: a compliance overview, an assessment of the overall compliance status, including compliant and non-compliant items; query and activity logs, referring to users' query history and related behaviors, showing compliance areas of concern; risk identification, referring to identified potential compliance risks and violation records; recommendations and actions, referring to compliance recommendations or necessary corrective actions in response to risk generation; regulatory compliance status, referring to an analysis of the degree of compliance with relevant laws and regulations; time trend, referring to the trend of compliance status changes over time; task completion status, referring to a list of completed compliance tasks and pending matters; and feedback and suggestions, referring to user and system feedback and optimization suggestions.
[0084] The aforementioned compliance tracking and compliance status reporting allow management to gain real-time insights into the organization's compliance status, supporting data-driven decision-making, providing management with visualized compliance analysis, helping to identify potential compliance risks in a timely manner, and improving overall compliance governance. Furthermore, by tracking users' query history, the relevance and priority of future compliance recommendations can be adjusted.
[0085] In this application, the system comprised of a large model and a dynamic knowledge base can be deployed on a secure and scalable cloud platform, requiring no complex IT infrastructure, thus ensuring data security and high system availability. Specifically, data security can be ensured through the following methods: Data encryption: Encrypt sensitive data during storage and transmission, protecting information using industry-standard encryption protocols such as AES and TLS.
[0086] Access control: Implement strict access control policies, including multi-factor authentication (MFA) and role-based access control (RBAC), to ensure that only authorized users can access the system.
[0087] Security monitoring: Enable security logging, continuously monitor system activity, promptly detect and respond to potential threats, and conduct regular security audits.
[0088] Network security: Protect network boundaries and prevent unauthorized access through Virtual Private Cloud (VPC), firewalls, and Intrusion Detection Systems (IDS).
[0089] Data backup and recovery: Back up data regularly and establish a disaster recovery plan to ensure that data can be quickly recovered in case of emergencies.
[0090] Compliance: Adhere to relevant laws, regulations and industry standards (such as General Data Protection Regulation, GDPR, etc.) to enhance the compliance of data processing.
[0091] By comprehensively applying the aforementioned security measures, the system can construct a multi-layered security protection system. This system not only effectively resists external attacks but also prevents internal data leaks, ensuring the confidentiality, integrity, and availability of data throughout its entire lifecycle. Simultaneously, the cloud platform's elastic scalability allows the system to flexibly adjust resources according to business needs, further enhancing system reliability and responsiveness. Regarding compliance, the system continuously monitors and updates compliance policies through automated tools, ensuring that all data processing activities comply with the latest regulatory requirements, providing robust legal protection for the enterprise.
[0092] Unlike existing technologies that rely on manual checks and audits for compliance management, which are prone to human error and inefficient, unable to meet the demands of a rapidly changing compliance environment, and lack effective tools to track and analyze compliance requirements in real time, this application provides an intelligent compliance management method based on a large model. The entire compliance management process is automated based on this model, requiring no manual intervention. This not only effectively improves compliance management efficiency and reduces the time cost and human error associated with manual audits, but also provides highly personalized suggestions based on enterprise characteristics, industry background, and user identity needs. This greatly enhances the adaptability and flexibility of compliance management. Furthermore, by continuously updating the dynamic knowledge base and large model, it ensures that enterprises can promptly and accurately comply with the latest regulatory requirements, reducing legal risks and economic losses.
[0093] In one embodiment, see Figure 2 , Figure 2This is a schematic diagram of the structure of an intelligent compliance management system, an embodiment of the intelligent compliance management method based on a large model provided in this application. This application can construct an intelligent compliance management system based on a pre-trained large model, a dynamic knowledge base, and corresponding functions provided by the user interface. The system includes a data source module, an AI analysis module, a user interface module, and a feedback and learning module. The data source module consists of a dynamic knowledge base, which includes internal enterprise documents, compliance policy documents (national / industry policies and internal enterprise policies), and historical compliance data, providing rich data support. The AI analysis module, as the core processing unit of the pre-trained large model, analyzes the input compliance questions, extracts key information, and automatically generates personalized compliance suggestions. The user interface module provides an intuitive, conversational interface, allowing users to easily input compliance questions and receive immediate feedback and suggestions. The feedback and learning module updates the large model based on user feedback and changes in new regulations, maintaining the accuracy and timeliness of compliance suggestions and promoting the self-optimization of the large model. Through this architecture, the intelligent compliance management system can achieve efficient data processing and personalized services, providing comprehensive support for enterprise compliance management.
[0094] In one embodiment, see Figure 3 , Figure 3 This is a flowchart illustrating the user-big-model interactive question-and-answer process of an embodiment of the intelligent compliance management method based on a big-model provided in this application. First, the user accesses the system via the web or mobile device and enters a conversational interface, where they can input compliance questions, such as regulatory requirements or compliance measures. Then, the pre-trained big-model uses natural language processing technology to parse the user's input compliance questions, understands the context through the dialogue dataset, generates corresponding compliance suggestions, and retrieves relevant documents from a dynamic knowledge base to support the answer. Next, the big-model provides the compliance suggestions and relevant documents back to the user, helping them understand compliance requirements and best practices. Finally, after reviewing the compliance suggestions, the user can provide feedback or ask further questions. Throughout this interaction, the user's queries and behaviors are recorded to generate compliance status reports and improvement suggestions.
[0095] This application provides an intelligent compliance management device based on a large model, see reference. Figure 4 , Figure 4 This is a schematic diagram of an embodiment of the intelligent compliance management device based on a large model provided in this application. The intelligent compliance management device based on a large model includes: Extraction module 10 is used to respond to compliance questions input by the user, analyze the compliance questions based on a pre-trained large model, and extract key information; Matching module 20 is used to match compliance documents and question-and-answer combinations in a dynamic knowledge base based on key information; The generation module 30 is used to generate compliance suggestions and provide feedback to the user based on compliance documents, question-and-answer combinations, and pre-built dialogue datasets.
[0096] The process of intelligent compliance management based on a large model is achieved through the interaction of the extraction module 10, the matching module 20 and the generation module 30. Please refer to the specific description of steps S10 to S30 above. Repeated parts will not be repeated here.
[0097] See Figure 5 , Figure 5 This is a schematic diagram of an embodiment of the storage medium provided in this application.
[0098] The storage medium 500 stores program data 510, which, when executed by the processor, implements, as follows: Figure 1 The steps of the intelligent compliance management method based on a large model are described.
[0099] The program data 510 is stored in a storage medium 500 and includes several instructions for causing a network device (which may be a router, personal computer, server, or other network device) or a processor to execute all or part of the steps of the methods described in the various embodiments of this application.
[0100] Optionally, the storage medium 500 can be any medium that can store program data, such as a USB flash drive, external hard drive, read-only memory (ROM), random access memory (RAM), disk, or optical disc.
[0101] See Figure 6 , Figure 6 This is a schematic diagram of the structure of an embodiment of the computer device provided in this application.
[0102] The device 600 includes a processor 620 and a memory 610 connected to each other. The memory 610 stores a computer program. When the processor 620 executes the computer program, it implements the steps of the intelligent compliance management method based on the large model described above.
[0103] Unlike existing technologies, this application discloses a method, apparatus, device, and medium for intelligent compliance management based on a large model. This method uses a pre-trained large model to analyze input compliance questions, extracts key information, and matches it with compliance documents and question-and-answer combinations in a dynamic knowledge base. Then, using a pre-built dialogue dataset as context, it generates personalized compliance suggestions for the enterprise. The entire automated process does not rely on manual intervention, effectively improving management efficiency and reducing the audit error rate. Furthermore, by constructing a dynamic knowledge base to store compliance documents for the enterprise and dialogue datasets corresponding to different user identities, it can provide personalized suggestions based on enterprise characteristics and user needs, improving the adaptability and flexibility of compliance management.
[0104] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on its differences from other embodiments. In particular, the storage medium embodiments and computer device embodiments are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0105] This application can be used in a wide range of general-purpose or special-purpose computing system environments or configurations. For example: personal computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, network PCs, minicomputers, distributed computing environments including any of the above systems or devices, etc.
[0106] In the several embodiments provided in this application, it should be understood that the disclosed methods and devices can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, multiple units or components may be combined or integrated into another system, or some features may be omitted or not performed.
[0107] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0108] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0109] The above description is merely an embodiment of this application and does not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.
Claims
1. A smart compliance management method based on a large model, characterized in that, include: In response to the input compliance questions, the system analyzes the compliance questions based on a pre-trained large model and extracts key information. Based on the key information, a combination of compliance documents and questions / answers is matched in the dynamic knowledge base; Based on the compliance document, the question-and-answer combination, and the pre-built dialogue dataset, compliance recommendations are generated.
2. The intelligent compliance management method based on a large model according to claim 1, characterized in that, The pre-training methods for the large model are as follows: Based on the large model, each compliance document in the dynamic knowledge base is segmented; Identify the compliance requirements for each compliance document segment and use the compliance requirements as the tags for the compliance document segments; For each of the aforementioned compliant documents, multiple question-and-answer combinations are generated in segments to obtain a training dataset; Set task objectives for the large model and train the large model based on the training dataset to obtain a large model that can meet the task objectives; the task objectives include at least responding to user requests, identifying compliance risks, and generating compliance recommendations.
3. The intelligent compliance management method based on a large model according to claim 2, characterized in that, The matching of compliance documents and question-and-answer combinations in the dynamic knowledge base based on the key information includes: Based on the key information, the tags in the dynamic knowledge base are matched, and based on the tags, the corresponding compliance document segments and the associated multiple question-and-answer combinations are determined; Based on the key information, the question-and-answer combination with the strongest relevance is matched among multiple question-and-answer combinations.
4. The intelligent compliance management method based on a large model according to claim 2, characterized in that, After obtaining the large model that can satisfy the task objective, the process also includes: Based on the large model and preset prompts, create a dialogue example for the user; The dialogue examples are created in multiple rounds to obtain the dialogue dataset, and the large model and the preset prompt words are fine-tuned.
5. The intelligent compliance management method based on a large model according to claim 2, characterized in that, Also includes: The compliance documentation shall include at least historical compliance data and compliance policy documents; In response to the input compliance question being a compliance risk identification question, the system identifies the compliance risks based on the pre-trained large model using the historical compliance data and the compliance policy documents, and generates compliance recommendations for the compliance risks.
6. The intelligent compliance management method based on a large model according to claim 2, characterized in that, Also includes: The compliance documents also include internal company documents; In response to the input compliance question being a compliance requirement identification question, the system extracts relevant compliance requirement information from the enterprise's internal documents based on the pre-trained large model and matches the corresponding compliance requirements in the compliance policy documents. The compliance recommendations are generated by comparing the relevant information of the compliance requirements with the corresponding compliance requirements.
7. The intelligent compliance management method based on a large model according to claim 1, characterized in that, After generating the compliance recommendations, the following is also included: The system receives feedback from the user and updates the large model in real time based on the feedback and the online learning mechanism.
8. The intelligent compliance management method based on a large model according to claim 1, characterized in that, Also includes: In response to the update of compliance documents in the dynamic database, the large model is updated based on incremental learning techniques.
9. An intelligent compliance management device based on a large model, characterized in that, include: The extraction module is used to respond to user-input compliance questions, analyze the compliance questions based on a pre-trained large model, and extract key information. The matching module is used to match compliance documents and question-and-answer combinations in the dynamic knowledge base based on the key information; The generation module is used to generate compliance suggestions and feed them back to the user based on the compliance document, the question-and-answer combination, and the pre-built dialogue dataset.
10. A computer device, comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the steps of the intelligent compliance management method based on a large model as described in any one of claims 1-8.
11. A storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the steps of the intelligent compliance management method based on a large model as described in any one of claims 1-8.