Check table generation method and system for digital intelligence auditing
By employing a digital and intelligent auditing approach, utilizing large language models and distributed database technology, standard checklists are generated and task scheduling is optimized. This solves the problems of low efficiency, poor adaptability, and data leakage associated with traditional auditing methods, achieving an efficient and secure auditing process.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CCIC TECH SERVICE (SHENZHEN) CO LTD
- Filing Date
- 2025-12-30
- Publication Date
- 2026-04-24
Smart Images

Figure CN121920747A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and in particular to a method and system for generating checklists for digital auditing. Background Technology
[0002] In the auditing of enterprise management systems, traditional auditing methods rely on manually prepared checklists, which has the following problems: Using fixed checklist templates results in a large workload and low efficiency for on-site inspections and report compilation; audit standards are difficult to unify, and checklists prepared by different auditors vary greatly, making it easy to miss or misidentify audits; audit tasks are numerous and geographically dispersed, and scheduling requires comprehensive consideration of personnel and routes, which is time-consuming and makes it difficult to generate a reasonable audit task schedule; traditional checklists cannot quickly adapt to the audit requirements of different industries and different system standards; and data entered into checklists is not subject to secondary confidentiality processing, which also poses a risk of data leakage. Summary of the Invention
[0003] The main objective of this invention is to provide a method and system for generating checklists for digital auditing, aiming to overcome the shortcomings of current checklists that cannot quickly adapt to the auditing needs of different industries and different system standards, and that it is difficult to generate reasonable auditing task schedules.
[0004] To achieve the above objectives, this invention provides a method for generating a checklist for digital auditing, comprising the following steps: Based on at least one management system standard and industry characteristic tags, the audit data required by the digital audit tool is classified and uploaded, and the basic indicator knowledge base, original input documents, and generated document templates are divided. The basic indicator knowledge base is managed by a table import combined with a real-time data update mechanism. Based on the indicator data in the basic indicator knowledge base and semantic analysis of the large language model, the system automatically matches the corresponding management system standards and industry-standard modules for the keywords of the audit scenario input by the user, and generates a standard checklist; the standard checklist supports collaborative access and use on mobile and PC terminals. On-site auditors record inspection results and upload evidence documents in real time via mobile devices, which are then synchronized to the system database. The PC system intelligently optimizes the scheduling of subsequent audit tasks based on the completion progress in the standard checklist, the location information of the auditors, the matching degree of professional qualifications, and the task priority, generating multiple optimal audit route options for users to choose from.
[0005] Furthermore, the method also includes: The basic indicator knowledge base is stored redundantly and its consistency is verified across multiple nodes using distributed database technology.
[0006] Furthermore, the method also includes: When users manually adjust the standard checklist items, the system intelligently recommends supplementary items based on historical audit data and similar enterprise cases. It also performs compliance pre-verification on the user-added items and alerts users to potential risks. The system retains the version history of item adjustments for comparison and generates a user-adaptive custom checklist.
[0007] Furthermore, based on at least one management system standard and industry-specific tags, the audit data required by the digital audit tool is categorized and uploaded, dividing the data into a basic indicator knowledge base, original input documents, and generated document templates, including: For management system standards, the core clauses are automatically extracted and annotated. For industry-specific tags, a hierarchical structure of main tags and sub-tags is adopted. The main tag includes the industry type, and the sub-tags correspond to the specific scenarios of each industry. When uploading review data, the system automatically matches the corresponding standard core clauses and industry sub-tags based on the content of the review data. According to the data judgment criteria of the basic indicator knowledge base, the content that meets the criteria in the audited data is uploaded to the basic indicator knowledge base; according to the judgment criteria of the original input document, the content that meets the criteria is uploaded to the original input document; according to the judgment criteria of the generated document template, the content that meets the criteria is uploaded to the generated document template.
[0008] Furthermore, a mechanism combining table creation and import with real-time data updates is adopted to manage the basic indicator knowledge base, including: When adopting a table creation and import combined with a real-time data update mechanism, a standard update monitoring crawler tool is deployed to crawl and semantically parse data in real time, automatically identifying new / revised content that affects basic indicators, triggering version iteration and source tracing of the corresponding indicators; AI-driven cross-dimensional data adaptation and verification rules are embedded to verify data from different sources and generate a visual analysis report that includes conflict point location, adaptability score and optimization scheme.
[0009] Furthermore, based on indicator data in the basic indicator knowledge base and semantic analysis of the large language model, for the keywords of the audit scenario input by the user, the system automatically matches the corresponding management system standards and industry-standard modules, and generates a standard checklist, including: The semantic depth of the user-input review scenario keywords is analyzed using a large language model to extract the core requirements and implicit constraints of the scenario and generate scenario feature vectors. Based on scene feature vectors, multi-dimensional quantitative scoring is performed on the indicator data in the basic indicator knowledge base to select the core indicator set whose scores reach the preset threshold. The system calls upon a general industry module library, matches the industry-specific module with the highest semantic similarity to the scene feature vector, and combines the core indicator set with the industry-specific module. During the combination process, the system automatically adjusts the order of indicator items, merges duplicate verification items, supplements logical connection explanations, and generates a structured standard checklist. By using a large language model, the structured standard checklist is pre-validated for compliance, potential compliance vulnerabilities are identified, and optimization suggestions are provided.
[0010] Furthermore, the PC-based system intelligently optimizes the scheduling of subsequent review tasks based on the completion progress in the standard checklist, the location information of the reviewers, the matching degree of professional qualifications, and the task priority, generating multiple optimal review route options for users to choose from, including: The completion progress of the standard checklist is broken down into statuses, the urgency coefficient of the tasks to be started is calculated, the audit workload is quantified by level, and a task time matrix is generated. The professional qualifications of auditors are evaluated using a three-dimensional weighted score based on the system standard certification level, the number of industry-specific audit cases, and the historical audit pass rate to obtain a suitability score. Combined with the current workload of the auditors, the optimal pool of personnel with a suitability score greater than the first threshold and a workload less than the second threshold is selected. Collect the real-time location of the reviewers and the geographic coordinates of the review locations. Integrate real-time traffic data, traffic control information and morning and evening peak hour characteristics through the GIS system to calculate the shortest travel path and time fluctuation range between any two locations, as dynamic travel time data. Based on task urgency coefficient, task time matrix, optimal personnel pool, dynamic passage time data, and task priority, a multi-constraint optimization algorithm model is constructed. Combined with a dynamic adjustment mechanism, the review task is broken down into parallel sub-tasks according to process nodes, taking into account the connection time of personnel cross-regional collaboration. The improved particle swarm optimization algorithm is used to solve the problem, with multiple objectives of shortest total review cycle, optimal personnel capability matching, lowest traffic energy consumption, and minimum task splitting conflict, generating multiple sets of differentiated scheduling schemes.
[0011] Furthermore, each differentiated scheduling plan includes detailed personnel division of labor, time-based task sequences, dynamically optimized routes, and task priority adjustment interfaces. It also uses visual charts to display the time cost, manpower cost, transportation energy consumption cost, and risk coefficient of each plan.
[0012] Furthermore, based on indicator data in the basic indicator knowledge base and semantic analysis of the large language model, for the keywords of the audit scenario input by the user, the system automatically matches the corresponding management system standards and industry-standard modules, and generates a standard checklist, including: By using a large language model, semantic mining is performed on the keywords of the review scenario input by users in four layers: business scenario, industry attributes, compliance focus, and implicit needs, to generate a precise profile containing multiple scenario features. Based on the precise profile, the industry risk map library is called to match the high-frequency problem points and high-incidence links of compliance vulnerabilities corresponding to the business scenario, and generate a list of risk-related indicators. The risk-related indicator list is semantically fused with the core indicators in the basic indicator knowledge base. The weight of high-risk indicators is strengthened through the attention mechanism algorithm, while automatically removing scenario-irrelevant indicators and merging duplicate verification items. To address the complex audit requirements specific to certain scenarios, a large language model is triggered to generate customized inspection logic, which is then embedded into the inspection process. This ensures that the final standard checklist not only includes basic audit items but also adds value-added modules such as scenario risk warnings, abnormal situation handling guidelines, and extended interpretations of compliance basis. Furthermore, it supports automatically triggering secondary verification reminders for relevant related indicators based on real-time data collected during on-site audits.
[0013] This invention also provides a checklist generation system for digital auditing, comprising: The upload module is used to classify and upload the audit data required by the digital audit tool according to at least one management system standard and industry characteristic tags. It divides the basic indicator knowledge base, original input documents, and generated document templates, and adopts a table import combined with a real-time data update mechanism to manage the basic indicator knowledge base. The generation module is used to automatically match the corresponding management system standards and industry-wide modules based on the indicator data in the basic indicator knowledge base and the semantic analysis of the large language model, and generate a standard checklist for the user-input keywords of the audit scenario; the standard checklist supports collaborative access and use on mobile and PC terminals. The optimization module allows on-site auditors to record inspection results and upload evidence documents in real time via mobile devices, which are then synchronized to the system database. The PC system intelligently optimizes the scheduling of subsequent audit tasks based on the completion progress in the standard checklist, the location information of the auditors, the matching degree of professional qualifications, and the task priority, generating multiple optimal audit route plans for users to choose from.
[0014] The present invention provides a method and system for generating checklists for digital auditing, comprising: classifying and uploading audit data required by the digital auditing tool according to at least one management system standard and industry characteristic tags; dividing the data into a basic indicator knowledge base, original input documents, and generated document templates; and managing the basic indicator knowledge base using a table creation and import combined with a real-time data update mechanism. Based on the indicator data in the basic indicator knowledge base and semantic analysis using a large language model, the system automatically matches corresponding management system standards and industry-wide modules to generate a standard checklist based on user-input audit scenario keywords. The standard checklist supports collaborative retrieval and use on both mobile and PC terminals. On-site auditors record inspection results and upload evidence documents in real time via mobile terminals, which are synchronized to the system database in real time. The PC system intelligently optimizes the scheduling of subsequent audit tasks based on the completion progress, auditor location information, professional qualification matching degree, and task priority in the standard checklist, generating multiple optimal audit route schemes for users to choose from. In this invention, based on at least one management system standard and industry-specific tags, a basic indicator knowledge base, original input documents, and generated document templates are divided. For user-input audit scenario keywords, the corresponding management system standard and industry-standard modules are automatically matched to generate a standard checklist. Finally, combining on-site audit scenarios with the PC system's intelligent optimization of subsequent audit task scheduling based on the standard checklist, multiple optimal audit route plans are generated for the user to choose from. This overcomes the shortcomings of current checklists, which cannot quickly adapt to the audit needs of different industries and system standards, and are difficult to generate reasonable audit task schedules. Attached Figure Description
[0015] Figure 1 This is a schematic diagram of the steps in the digital audit checklist generation method in one embodiment of the present invention; Figure 2 This is a block diagram of the checklist generation system for digital auditing in one embodiment of the present invention; Figure 3 This is a schematic block diagram of the structure of a computer device according to an embodiment of the present invention.
[0016] The implementation, functional features, and advantages of this invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0018] It is particularly important to note that all technical steps, algorithm applications, and parameter settings in the technical solution of this application have clear technical objectives and application value. They do not utilize complex steps and algorithmic formulas to achieve simple functions. To provide detailed explanations of each step and avoid ambiguity, some conventional algorithms are used for illustration. However, this does not mean that the algorithms and technical features listed herein are the only way to implement the technical solution of this application, nor is it intended to limit the scope of protection of this application. This application is not a combination or stacking of the listed algorithms and technical features; its essence is to exemplify the implementation methods of this application to fully explain it. It does not pursue formal complexity by adding meaningless technical steps, nor does it involve the accumulation of technologies divorced from practical needs; it conforms to the conventional logic of technical improvement and design.
[0019] Reference Figure 1 One embodiment of the present invention provides a method for generating a checklist for digital auditing, comprising the following steps: Step S1: Based on at least one management system standard and industry characteristic tags, classify and upload the audit data required by the digital audit tool, divide the basic indicator knowledge base, original input documents, and generated document templates, and manage the basic indicator knowledge base by adopting a table import combined with a real-time data update mechanism. Step S2: Based on the indicator data in the basic indicator knowledge base and semantic analysis of the large language model, the corresponding management system standards and industry-wide modules are automatically matched and combined to generate a standard checklist for the user-input keywords of the audit scenario; the standard checklist supports collaborative retrieval and use on mobile and PC terminals. In step S3, on-site auditors record inspection results and upload evidence documents in real time via mobile devices, which are then synchronized to the system database. The PC system intelligently optimizes the scheduling of subsequent audit tasks based on the completion progress in the standard checklist, the location information of the auditors, the matching degree of professional qualifications, and the task priority, generating multiple optimal audit route plans for users to choose from.
[0020] In this embodiment, digital intelligent review is a new review model that integrates digital technology and intelligent capabilities. Its core is to replace or optimize the traditional manual review process through data-driven, intelligent algorithms and cross-terminal collaboration, so as to achieve standardization, efficiency, accuracy and dynamism in the review work.
[0021] Step S1 aims to establish a core data support system for intelligent digital auditing, providing accurate and up-to-date foundational data for subsequent checklist generation. Specifically, it first identifies at least one applicable management system standard (such as a quality management system or food safety management system) and, combined with the industry-specific characteristics of the target audit object (such as food processing, electronics manufacturing, medical devices, or chemical production), determines the core coverage and adaptation direction of the audit data. Subsequently, the multi-source audit data required by the intelligent digital auditing tool is categorized, collected, and uploaded. This audit data includes, but is not limited to, national and local laws and regulations, industry-standard system texts, and custom management requirements developed internally by the enterprise. Based on data attributes and functional positioning, it is divided into three core modules: a basic indicator knowledge base, raw input documents, and generated document templates. The basic indicator knowledge base stores structured, directly accessible audit indicator data; the raw input documents retain unstructured raw standard texts and policy documents; and the generated document templates provide a standardized format framework for the checklist. In the data management phase, a table-building and import method is adopted to achieve batch entry and structured storage of multi-source data. At the same time, combined with a real-time data update mechanism, through multiple channels such as connecting to the official standard release platform API interface, deploying industry dynamic monitoring crawlers, and receiving internal enterprise policy update pushes, dynamic changes such as legal and regulatory revisions, system standard iterations, and enterprise requirement adjustments are captured in real time. This automatically triggers the marking, updating, and version tracing of corresponding data in the basic indicator knowledge base, ensuring the timeliness, accuracy, and completeness of the basic indicator knowledge base, and laying a solid data foundation for the intelligent generation of subsequent checklists.
[0022] Step S2 focuses on achieving accurate and automated checklist generation while ensuring ease of use across multiple terminals. Specifically, using the basic indicator knowledge base built in Step S1 as the core data source, and leveraging the semantic analysis and understanding capabilities of a Large Language Model (LLM), the user-input keywords for the audit scenario are deeply analyzed to extract core elements, including audit object type, applicable system standards, core audit objectives, and key control directions, generating a scenario feature profile. Based on this profile, indicator data in the basic indicator knowledge base is automatically retrieved and matched with management system standard modules corresponding to the scenario (such as modules for "food safety planning," "implementation and operation," and "inspection and corrective measures"). Simultaneously, pre-defined industry-standard modules (including typical industry risk points, special audit points, and common inspection methods) are invoked. A logical association algorithm organically combines the matched indicator data with the module content. During this combination process, the data is structured and sorted according to the audit logic order, indicator risk level, and business process nodes. Redundant and repetitive content is removed, and logical connection explanations are added. Finally, a standardized checklist containing core elements such as audit project name, compliance clauses, inspection operation requirements, judgment criteria, and risk warnings is generated. To adapt to the diverse needs of on-site audits and remote collaboration, this standard checklist supports collaborative access and use on mobile and PC terminals. Through the system's multi-terminal data synchronization mechanism, it ensures that the checklist content obtained by users on different terminals is consistent and that operation records are synchronized in real time, meeting the needs of auditors to carry out their work anytime, anywhere.
[0023] Step S3 enables data integration during the audit execution process and efficient planning of subsequent tasks, improving the collaborative efficiency and execution effectiveness of the entire audit process. During the on-site audit phase, auditors log into the system via mobile terminals, retrieve the standard checklist generated in step S2, and conduct on-site inspections according to the audit items on the checklist, entering inspection results in real time (e.g., compliant, non-compliant, pending confirmation), and simultaneously uploading corresponding evidence documents (e.g., on-site photos, record forms, test reports, etc.). The mobile system encrypts the entered inspection results and uploaded evidence documents in real time before synchronizing them to the backend system database, ensuring the real-time nature and security of audit data and facilitating remote management personnel to monitor audit progress in real time. In the task scheduling optimization phase, the PC system, based on the progress data (including completed audit items, pending audit items, critical path items, etc.) synchronized in the backend database from the standard checklist, combines this with the auditors' real-time location information, professional qualification matching data (e.g., proficiency in system standards, industry audit experience, qualification certification level, etc.), and task priorities (set according to compliance urgency, customer demand level, and risk impact scope) to construct a multi-dimensional optimization model. This model re-plans incomplete review tasks, intelligently allocates review personnel, rationally arranges task execution order, and calculates the optimal travel routes between review locations using a Geographic Information System (GIS). It comprehensively balances core objectives such as review efficiency, personnel suitability, and execution costs, generating at least two differentiated optimal review route plans. Each plan clearly includes key information such as a personnel allocation list, daily task schedule, route navigation planning, and task adjustment flexibility, allowing users to choose and adopt based on actual execution scenarios, or triggering secondary optimization adjustments by the system. This achieves intelligent, efficient, and flexible scheduling of review tasks.
[0024] In one embodiment, the method further includes: The basic indicator knowledge base is stored redundantly and its consistency is verified across multiple nodes using distributed database technology.
[0025] In this embodiment, the aim is to ensure the high availability, data integrity, and access reliability of the basic indicator knowledge base from the data storage architecture level, providing solid underlying data support for the entire digital and intelligent audit process.
[0026] The core characteristic of distributed database technology is that data is distributed and stored across multiple physical nodes (servers, cloud hosts, etc.), rather than centrally stored on a single node. In this method, the specific process of implementing redundant storage for the basic indicator knowledge base is as follows: First, the structured data in the basic indicator knowledge base (such as management system standard indicators, industry characteristic tags, enterprise-defined requirements, etc.) is logically sharded according to data attributes (such as standard type, industry classification, indicator risk level). Then, multiple copies (usually three or more) are created for each data shard, and these copies are distributed and deployed across different physical nodes of the distributed database. These nodes can be located in different regions or different server clusters. For example, after sharding the indicator data of the ISO 22000 food safety system, its copies are stored in cloud server nodes in East China, North China, and South China, respectively.
[0027] The system monitors the operational status of each storage node in real time (such as load rate, response speed, and failure risk). When a node experiences excessive load or a failure warning, it automatically triggers dynamic migration and addition of replicas to ensure that each data shard always maintains a preset number of available replicas. Simultaneously, redundant storage adheres to the "off-site disaster recovery" principle to prevent data inaccessibility due to hardware failures, network outages, or other unforeseen events in a single region.
[0028] The above storage method breaks through the single point of failure bottleneck of traditional centralized databases. Even if some storage nodes fail, the system can still retrieve data copies from other normal nodes, ensuring uninterrupted access to the basic indicator knowledge base and meeting the real-time data retrieval requirements of on-site auditing, checklist generation, and other processes.
[0029] In a distributed database with redundant storage architecture, the existence of multiple data replicas can lead to discrepancies in the basic indicator knowledge base data stored on each node due to factors such as network latency between nodes, asynchronous data updates, and hardware failures. Therefore, multi-node consistency verification is necessary to ensure the global uniformity of the data. The specific execution process is as follows: When the real-time data update mechanism triggers changes to the basic indicator knowledge base data (such as revisions to standard clauses, adjustments to enterprise requirements, or updates to indicator weights), the system automatically initiates multi-node consistency verification. Simultaneously, the system performs a full-scale data consistency check at a preset period (e.g., hourly), covering all data shards and replicas. Distributed consistency algorithms (such as Raft and Paxos) are used to verify the replica data on each node. Taking Raft as an example, the system elects a master node from the distributed nodes. The master node is responsible for synchronizing the update instructions for the basic indicator knowledge base to all slave nodes. After executing the update, the slave nodes send confirmation information back to the master node. The master node counts the confirmation results; if more than half of the slave nodes have completed synchronization, the update is considered successful, and data consistency is achieved. If some slave nodes fail to synchronize, the master node resends the update instructions until all node replicas are consistent. If a discrepancy is found between the replica data of a node and the primary node during the verification process, the system will automatically overwrite the abnormal node with the correct data from the primary node, completing the data repair. Simultaneously, the system will record the node information, timestamp, and discrepancies related to the inconsistent data, generating an anomaly tracing report to facilitate technical personnel in investigating network, hardware, or software-level faults. Multi-node consistency verification ensures that all data replicas of the basic indicator knowledge base remain consistent within the distributed storage architecture, preventing issues such as missing indicators, incorrect standard clauses, and deviations from industry requirements during checklist generation due to data inconsistencies. This fundamentally guarantees the accuracy and compliance of subsequent intelligent checklist generation and optimized audit task scheduling.
[0030] In one embodiment, the method further includes: When users manually adjust the standard checklist items, the system intelligently recommends supplementary items based on historical audit data and similar enterprise cases. It also performs compliance pre-verification on the user-added items and alerts users to potential risks. The system retains the version history of item adjustments for comparison and generates a user-adaptive custom checklist.
[0031] In this embodiment, when a user manually performs operations such as adding, deleting, rearranging, or modifying items on the generated standard checklist on a PC or mobile device, the system captures these adjustments in real time. Combining this with information such as the original standard checklist's corresponding audit scenario keywords, management system standard type, and industry characteristic tags, the system accurately re-identifies the current audit scenario, clarifying the business module and audit dimension corresponding to the adjustment operation. Based on the identified scenario information, two types of core data are retrieved from the backend database: first, historical audit data, including past checklist adjustment records under the same industry and system standards, high-frequency issues discovered during audits, and typical cases of rectification closure; second, similar enterprise cases, covering customized checklist templates from benchmark enterprises in the industry, compliance risk events caused by missing audit items in similar enterprises, and special audit guidelines issued by industry associations. Through big data analysis algorithms, the above data is clustered and correlation-mined to extract potential audit items that highly match the current adjustment scenario. These items are typically content not covered in the standard checklist but with significant compliance value in actual audits. The identified potential items are quantitatively scored using a three-dimensional approach: compliance necessity, risk weight, and industry suitability. A list of recommended items is then generated, sorted by score, and pushed to users. Each recommended item is accompanied by corresponding justification to help users decide whether to adopt it.
[0032] When users add new items to the checklist based on recommendations or their own needs, a compliance pre-verification process is immediately initiated to ensure the legality and suitability of the new items. Specifically, this involves using a built-in knowledge base of basic indicators as the core verification basis, integrating it with legal and regulatory clauses, original management system standards, and enterprise-defined compliance requirements. The new items are verified from three dimensions: first, clause compliance, checking whether the new item's requirements conflict with current management system standards and laws and regulations; second, scenario suitability, determining whether the new item conforms to the industry characteristics and actual business operations of the current audit scenario; and third, logical consistency, verifying whether the new item overlaps with existing items in the checklist, contains contradictions, or exhibits logical inconsistencies. If problems are found with the new item during the verification process, the system automatically identifies specific risk points and classifies them (e.g., major risk, general risk, minor risk), generating a detailed verification report.
[0033] Throughout the entire process of users adjusting checklist items, adopting recommended items, and addressing compliance risks, the system continuously records the operation trajectory, enabling traceability and comparison of version history. Each adjustment operation generates a unique version number and records key information such as adjustment time, operator, adjustment content (e.g., adding, deleting, or modifying items), whether recommended items were adopted, and compliance verification results, forming a structured version history log. Log data and audit data are synchronously stored in the system database to ensure immutability and retrieval at any time. A version comparison interface is provided, allowing users to visually compare any two or more checklist versions. Differences in item additions / deletions and content modifications are highlighted in different colors, along with the corresponding reasons and basis for the adjustments. If users find problems with the adjusted checklist, they can restore it to any historical version through the version rollback function, balancing the flexibility of adjustments with the correctability of operations.
[0034] After completing the aforementioned intelligent recommendation, compliance verification, and version retention stages, the system automatically integrates content and optimizes layout based on the user's final confirmed checklist items, following the structured framework of the standard checklist, to generate a user-adaptive custom checklist. This checklist retains the compliance and standardization foundation of the standard checklist while incorporating the user's personalized customization needs. Furthermore, intelligent recommendations and compliance verification compensate for potential issues such as missing items and compliance risks that may arise from manual adjustments. The generated custom checklist also supports collaborative access and use on mobile and PC platforms. Its item information, version history, and compliance verification reports are synchronized to the system database, providing accurate form data for on-site audit data recording and task scheduling optimization, achieving intelligent adaptation throughout the entire process from standard checklists to customized checklists.
[0035] In one embodiment, the audit data required by the digital audit tool is categorized and uploaded according to at least one management system standard and industry characteristic tags, including: a basic indicator knowledge base, original input documents, and generated document templates. For management system standards, the core clauses are automatically extracted and annotated. For industry-specific tags, a hierarchical structure of main tags and sub-tags is adopted. The main tag includes the industry type, and the sub-tags correspond to the specific scenarios of each industry. When uploading review data, the system automatically matches the corresponding standard core clauses and industry sub-tags based on the content of the review data. According to the data judgment criteria of the basic indicator knowledge base, the content that meets the criteria in the audited data is uploaded to the basic indicator knowledge base; according to the judgment criteria of the original input document, the content that meets the criteria is uploaded to the original input document; according to the judgment criteria of the generated document template, the content that meets the criteria is uploaded to the generated document template.
[0036] In this embodiment, the first step is to initiate the structured processing of the management system standard. The system first imports the electronic text of at least one selected management system standard, and uses Natural Language Processing (NLP) technology to remove irrelevant content such as formatting marks and redundant descriptions, retaining only the core chapters and detailed clauses. Then, relying on a pre-trained text mining model and combining the general structural features of the management system standard, the system automatically extracts core clauses such as food safety policy formulation and critical control point monitoring. Each clause is then labeled with a multi-dimensional identifier, including clause number, type (mandatory / recommended), compliance level, and applicable business process, forming a structured core clause library that can be recognized and called by the system. This is an important basis for subsequent audit data matching.
[0037] After completing the analysis of the management system standards, the process naturally transitions to the hierarchical structure construction of industry characteristic tags. First, main tags are defined based on industry type, covering major service areas such as food processing, electronics manufacturing, medical devices, and chemical production. Simultaneously, the core business characteristics and regulatory framework corresponding to each main tag are clarified. Then, for each industry main tag, sub-tags are decomposed based on its business processes, sub-scenarios, and regulatory priorities. For example, the food processing main tag extends to sub-tags such as "cold chain logistics," "dairy processing," and "pre-prepared food preparation," while the electronics manufacturing main tag is decomposed to sub-tags such as "semiconductor packaging" and "lithium battery production." Attributes such as core business processes and special regulatory requirements are labeled for each sub-tag. Finally, a tree-like hierarchical structure of "main tag - sub-tag" is established and stored in the system tag library, laying the foundation for scenario-based matching of audit data.
[0038] Once the core clause library and industry-specific tag library of the management system standards are established, the process enters the stage of uploading and intelligent matching of audit data. Users upload audit data such as laws and regulations, corporate management systems, and industry standards required by the digital audit tool to the system. The system first uses OCR recognition and NLP semantic analysis technology to extract key information such as the core content, scope of application, and business orientation of the audit data and generate feature vectors. Then, the feature vectors are compared with the core clause library for semantic similarity, and the system automatically matches the corresponding standard core clauses. For example, "Raw Material Acceptance Management System for Food Enterprises" will match the relevant clauses of "Procurement Control". At the same time, based on the business orientation of the data, the system first locates the corresponding industry main tag and then accurately matches the sub-tags. For example, "Cold Chain Transportation Control Standard for Dairy Products" will be associated with the main tag of "Food Processing" and the sub-tag of "Cold Chain Logistics". Finally, a relationship of "Audit Data - Standard Core Clauses - Industry Sub-Tags" is formed, which clarifies the direction for data classification and archiving.
[0039] After intelligent matching of the audit data is completed, the process enters the final classification and uploading stage. Clear judgment criteria are pre-defined for the three modules: the basic indicator knowledge base receives structured content that can be directly converted into audit indicators, such as compliance requirements of core clauses and quantifiable inspection standards; the original input documents retain unstructured original supporting texts, such as complete full texts of laws and regulations and original management system standards; the generated document templates collect content that can serve as a checklist framework, such as standardized audit form formats and the logical arrangement of inspection items. According to the above judgment criteria, the matched audit data is screened one by one: content that meets the basic indicator knowledge base standards is converted according to the audit indicator structure requirements and uploaded, and associated with corresponding clauses and tags; content that meets the original input document standards is uploaded while retaining its original format and adding associated identifiers; content that meets the generated document template standards is organized according to the template format specifications and uploaded, while also indicating the applicable scenarios and standards. Finally, a unified index is established for all data in the three modules, including information such as data source, matching clauses, and associated tags, to achieve data interconnection between modules, ultimately forming a structured and systematic audit data support system, providing accurate data assurance for the subsequent intelligent generation of checklists.
[0040] In one embodiment, a basic indicator knowledge base is managed using a table creation and import combined with a real-time data update mechanism, including: When adopting a table creation and import combined with a real-time data update mechanism, a standard update monitoring crawler tool is deployed to crawl and semantically parse data in real time, automatically identifying new / revised content that affects basic indicators, triggering version iteration and source tracing of the corresponding indicators; AI-driven cross-dimensional data adaptation and verification rules are embedded to verify data from different sources and generate a visual analysis report that includes conflict point location, adaptability score and optimization scheme.
[0041] In this embodiment, a core mechanism for real-time data updates is initiated by deploying a standard update monitoring crawler tool to achieve accurate dynamic capture of external standard data and synchronous iteration of internal indicators. The crawler tool's crawling rules and target data sources are pre-configured, covering authoritative platforms such as industry association websites and legal databases, as well as compliance management system release channels of benchmark enterprises. The crawler tool crawls these data sources in real time according to a preset crawling frequency (e.g., hourly). For the acquired text and announcement-type information, semantic analysis is immediately performed using Natural Language Processing (NLP) technology to extract core content related to management system standards and industry norms, focusing on identifying whether there are key changes such as the addition, revision, or repeal of standard clauses corresponding to indicators. When the analysis results show content affecting the basic indicator knowledge base, the internal indicator version iteration process is automatically triggered: for newly added clauses, new indicator entries are generated according to the structured rules of basic indicators and assigned a unique identifier; for revised clauses, a new version is created based on the original indicator version, retaining the content and applicable time range of the historical version; for repealed clauses, the corresponding indicator's invalidation status is marked and the repeal basis is associated. At the same time, a traceability mark will be added to each indicator version iteration to record information such as update time, data source, and content change comparison, forming a complete indicator version traceability chain to ensure that every adjustment to the basic indicators is traceable.
[0042] After completing the acquisition of external data and the iteration of internal metrics, the process naturally transitions to the data quality verification stage. This involves embedding AI-driven cross-dimensional data adaptation verification rules to comprehensively verify data from different sources and generate visual analysis reports. First, multi-source data is integrated, including external standard data crawled and iterated by web crawlers, management system data uploaded internally by the company, and indicator optimization data accumulated from historical audits. Then, a pre-trained AI verification model is activated to perform cross-dimensional adaptation verification: verifying whether the company's internal metrics conflict with the priority of national mandatory standards and industry recommended standards; verifying whether the regional differences in indicator requirements between regional industry norms and national standards are reasonable; verifying whether the indicator content matches the specific business processes of the corresponding industry sub-tags; and verifying whether there are logical contradictions in the inspection standards and judgment criteria of similar indicators from different sources. The AI verification model quantifies and scores each verification result, generating an adaptation score from 0 to 100, while accurately locating conflict points in the data, such as specific indicator items with conflicting clause validity or core content with incompatible scenario adaptation. Based on the verification results, a visual analysis report will be automatically generated. This report includes not only the location and labeling of conflict points and radar charts showing adaptability scores for each dimension, but also targeted optimization solutions based on industry compliance practices and standard requirements. Users can intuitively grasp the overall adaptability of the basic indicator knowledge base through the report, and manually adjust the indicators or trigger automatic corrections by the system according to the optimization solutions, ultimately achieving dynamic optimization and precise management of the basic indicator knowledge base.
[0043] In one embodiment, based on indicator data in the basic indicator knowledge base and semantic analysis of the large language model, the system automatically matches corresponding management system standards and industry-standard modules to generate a standard checklist for user-input keywords related to the audit scenario, including: The semantic depth of the user-input review scenario keywords is analyzed using a large language model to extract the core requirements and implicit constraints of the scenario and generate scenario feature vectors. Based on scene feature vectors, multi-dimensional quantitative scoring is performed on the indicator data in the basic indicator knowledge base to select the core indicator set whose scores reach the preset threshold. The system calls upon a general industry module library, matches the industry-specific module with the highest semantic similarity to the scene feature vector, and combines the core indicator set with the industry-specific module. During the combination process, the system automatically adjusts the order of indicator items, merges duplicate verification items, supplements logical connection explanations, and generates a structured standard checklist. By using a large language model, the structured standard checklist is pre-validated for compliance, potential compliance vulnerabilities are identified, and optimization suggestions are provided.
[0044] In this embodiment, when a user inputs scenario keywords such as "annual compliance audit of food processing enterprises" or "special verification of quality management system of electronic manufacturing plants," the text is input into a pre-trained large language model. The model, relying on its massive corpus and semantic understanding capabilities, performs multi-dimensional deep decomposition and mining of the keywords: on the one hand, it extracts the core requirements of the scenario, including explicit information such as the type of management system standard corresponding to the audit, the industry attributes of the audit object, the core objectives of the audit (such as annual compliance inspection, special risk investigation), and the business coverage of the audit (such as production, procurement, and warehousing); on the other hand, it identifies implicit constraints, such as time limits for the audit, sampling inspection ratio requirements, acceptance standards for audit results, and industry-specific regulatory requirements—all implicit information hidden in the scenario description. Subsequently, these extracted core requirements and implicit constraints are transformed into machine-recognizable numerical scenario feature vectors. These vectors contain all the key attributes of the scenario, providing accurate digital basis for subsequent indicator selection and module matching.
[0045] After generating the scenario feature vector, the system uses this vector as a matching benchmark to conduct multi-dimensional quantitative scoring on all structured indicator data stored in the basic indicator knowledge base. The scoring dimensions typically cover the compliance necessity with the scenario (whether the indicator is a mandatory requirement of the corresponding management system standard), scenario adaptability (whether the indicator aligns with the actual industry business of the audit target), and risk relevance (the probability and impact of compliance risks corresponding to the indicator). The system assigns scientific weight coefficients to each dimension, calculates a comprehensive score for each indicator through weighted summation, and then filters out indicators that meet the comprehensive score based on the user-preset scoring threshold (e.g., 80 points), forming a core indicator set highly matched to the current audit scenario. This process effectively eliminates indicators in the knowledge base that are irrelevant to the scenario or of low importance, ensuring that the subsequently generated checklist focuses on core audit points and avoids redundant content that could affect audit efficiency.
[0046] Once the core indicator set is determined, a pre-set industry-wide module library is retrieved. This library stores specialized audit modules for various industries, including key points for verifying typical industry risk points, detailed rules for checking specific business processes, and industry-wide audit methods and judgment standards. By calculating the semantic similarity between the scenario feature vector and the specialized modules of each industry, the module with the highest similarity is matched. For example, for the scenario of "cold chain logistics audit of food processing enterprises," the "food cold chain logistics specialized audit module" will be accurately matched. Subsequently, the selected core indicator set and the matched specialized modules are organically combined. During the combination process, a structured optimization mechanism is activated: the order of indicator items is automatically adjusted according to the process logic of the audit business (such as from procurement to production, from warehousing to sales), making the audit logic of the checklist more in line with the actual business of the enterprise; duplicate verification items are identified and merged through semantic comparison, such as integrating the inspection requirements of the same equipment involved in different indicators to avoid duplicate audits; and logical connection explanations are added for logical gaps between indicators. Through a series of optimizations, the system initially generates a structured standard checklist containing core elements such as "audit items, compliance basis, inspection methods, and judgment standards."
[0047] After the initial generation of the structured standard checklist, it is input back into the large language model. Leveraging its deep understanding of management system standards, laws and regulations, and industry norms, the model conducts a comprehensive compliance check on each indicator item in the checklist: verifying whether the compliance basis of the indicator is consistent with the current management system standard clauses and national legal and regulatory requirements; checking whether the judgment criteria for the indicator are operable and quantifiable; and verifying whether the logical relationships between indicators conform to industry business processes and compliance regulatory requirements. During the verification process, the model accurately identifies and marks potential compliance vulnerabilities, and, in conjunction with industry best practices and standard requirements, provides specific optimization suggestions for each vulnerability. Users can adjust and improve the checklist based on the model's verification results and optimization suggestions, ultimately forming a standard checklist that is compliant, adaptable, and logically sound, providing a standardized and scientific basis for on-site audits.
[0048] In one embodiment, the PC system intelligently optimizes the scheduling of subsequent review tasks based on the completion progress in the standard checklist, the location information of the reviewers, the matching degree of professional qualifications, and the task priority, generating multiple optimal review route plans for the user to choose from, including: The completion progress of the standard checklist is broken down into statuses, the urgency coefficient of the tasks to be started is calculated, the audit workload is quantified by level, and a task time matrix is generated. The professional qualifications of auditors are evaluated using a three-dimensional weighted score based on the system standard certification level, the number of industry-specific audit cases, and the historical audit pass rate to obtain a suitability score. Combined with the current workload of the auditors, the optimal pool of personnel with a suitability score greater than the first threshold and a workload less than the second threshold is selected. Collect the real-time location of the reviewers and the geographic coordinates of the review locations. Integrate real-time traffic data, traffic control information and morning and evening peak hour characteristics through the GIS system to calculate the shortest travel path and time fluctuation range between any two locations, as dynamic travel time data. Based on task urgency coefficient, task time matrix, optimal personnel pool, dynamic passage time data, and task priority, a multi-constraint optimization algorithm model is constructed. Combined with a dynamic adjustment mechanism, the review task is broken down into parallel sub-tasks according to process nodes, taking into account the connection time of personnel cross-regional collaboration. The improved particle swarm optimization algorithm is used to solve the problem, with multiple objectives of shortest total review cycle, optimal personnel capability matching, lowest traffic energy consumption, and minimum task splitting conflict, generating multiple sets of differentiated scheduling schemes.
[0049] In this embodiment, all audit items in the standard checklist are first broken down into "completed-in progress-not started" statuses. Focusing on the not started tasks, an urgency coefficient is calculated for each task based on its corresponding risk weight, compliance urgency, and business process dependencies using a preset algorithm. A higher coefficient indicates that the task should be executed first. Simultaneously, based on the operational complexity, volume of audit content, and required professional equipment / personnel coordination, the workload of the not started tasks is quantified and categorized into three levels: large, medium, and small. Combined with historical execution time data for similar tasks, corresponding base hours and flexible buffer periods are matched for different workload levels. Finally, the urgency coefficients, categorized workloads, and time data of all not started tasks are integrated to construct a structured task time matrix. This matrix clearly presents the execution difficulty, time requirements, and priority of each task, providing a quantitative basis for subsequent scheduling.
[0050] After quantifying the tasks, a three-dimensional weighted scoring system is established for the professional qualifications of auditors. The first dimension is the system standard certification level, assigning a base score based on the level of the system certification certificate held by the personnel. The second dimension is the number of industry-specific audit cases, which is calculated by counting the number of cases in the corresponding industry and audit scenarios that the personnel have participated in and converting them into scores. The third dimension is the historical audit pass rate, which is calculated based on the rectification and closure rate of problems found in the personnel's past audits and the accuracy of audit conclusions. Scientific weight coefficients are set for the three dimensions, and the professional qualification suitability score of each auditor is obtained through weighted calculation. On this basis, the current task load rate of each personnel (i.e., the proportion of remaining working hours of assigned tasks to their available working hours) is retrieved, and a first threshold (e.g., suitability score of 80 points) and a second threshold (e.g., task load rate of 60%) are set. Personnel with suitability scores higher than the first threshold and task load rates lower than the second threshold are selected to form an optimal personnel pool, ensuring that the selected personnel have both the professional ability to match the tasks and sufficient time and energy to take on new tasks.
[0051] Once the optimal personnel pool is determined, the real-time location coordinates of the reviewers are collected using positioning technology, while the geographic coordinates of all locations to be reviewed are retrieved. Both types of coordinate data are then imported into a Geographic Information System (GIS). The GIS system integrates real-time traffic data (such as road congestion index and traffic flow), traffic control information (such as road construction and traffic restrictions), and traffic characteristics during morning and evening peak hours. It uses a route planning algorithm to calculate the shortest travel path between any two review locations and, based on the volatility of traffic data, predicts the range of travel time fluctuations for this path at different times of day (e.g., 20 minutes during off-peak hours and 35-45 minutes during peak hours). This route information and time fluctuation range are integrated into dynamic travel time data. This data overcomes the limitations of static distance measurement and accurately reflects the impact of actual traffic conditions on the review process, providing a reliable basis for route planning in task scheduling.
[0052] After completing data preparation across the three dimensions of task, personnel, and route, the process enters the core stage of algorithm solving and scheduling plan generation. Using task urgency coefficients, task time matrices, optimal personnel pools, dynamic travel time data, and task priorities as input parameters, a multi-constraint optimization algorithm model is constructed, embedding a dynamic adjustment mechanism to handle unforeseen circumstances during execution. The model first breaks down the overall review task into parallelizable sub-tasks according to business process nodes, while simultaneously calculating the connection time when personnel collaborate across regions to execute sub-tasks (such as waiting time for personnel transfers and cross-team communication time), incorporating this into the model constraints. Subsequently, an improved particle swarm optimization algorithm is used to solve the model. This algorithm uses "shortest total review cycle, optimal personnel capability matching, lowest traffic energy consumption, and minimum task splitting conflicts" as multi-objective optimization constraints, and finds the optimal solution that satisfies all constraints through iterative search and position updates of the particle swarm. Ultimately, the algorithm will output at least three differentiated audit task scheduling schemes. Each scheme includes core information such as personnel allocation list, task execution sequence, optimal route, total cycle and cost calculation. Users can choose the appropriate scheme according to actual business needs (such as prioritizing shortening the audit cycle or prioritizing control of transportation costs), or trigger secondary optimization of the model based on the scheme to achieve intelligent and flexible audit task scheduling.
[0053] In one embodiment, each differentiated scheduling scheme includes a detailed division of labor, a time-based task sequence, a dynamically optimized route, and a task priority adjustment interface. The scheme's time cost, manpower cost, transportation energy cost, and risk factor are displayed through visual charts.
[0054] In one embodiment, based on indicator data in the basic indicator knowledge base and semantic analysis of the large language model, the system automatically matches corresponding management system standards and industry-standard modules to generate a standard checklist for user-input keywords related to the audit scenario, including: By using a large language model, semantic mining is performed on the keywords of the review scenario input by users in four layers: business scenario, industry attributes, compliance focus, and implicit needs, to generate a precise profile containing multiple scenario features. Based on the precise profile, the industry risk map library is called to match the high-frequency problem points and high-incidence links of compliance vulnerabilities corresponding to the business scenario, and generate a list of risk-related indicators. The risk-related indicator list is semantically fused with the core indicators in the basic indicator knowledge base. The weight of high-risk indicators is strengthened through the attention mechanism algorithm, while automatically removing scenario-irrelevant indicators and merging duplicate verification items. To address the complex audit requirements specific to certain scenarios, a large language model is triggered to generate customized inspection logic, which is then embedded into the inspection process. This ensures that the final standard checklist not only includes basic audit items but also adds value-added modules such as scenario risk warnings, abnormal situation handling guidelines, and extended interpretations of compliance basis. Furthermore, it supports automatically triggering secondary verification reminders for relevant related indicators based on real-time data collected during on-site audits.
[0055] In this embodiment, when a user inputs scenario keywords such as "special audit of cold chain logistics for dairy companies" or "compliance inspection of management system for semiconductor factories," the text is input into a pre-trained large language model. The model then initiates a four-layer semantic mining mechanism: at the business scenario layer, it accurately identifies the specific business links corresponding to the audit, such as the warehousing, transportation, and distribution links in cold chain logistics, and the production and waste disposal links in semiconductor factories; at the industry attribute layer, it clarifies the sub-industry to which the audit object belongs, distinguishing the industry differences between dairy processing and general food processing, and between semiconductor manufacturing and general electronics manufacturing; at the compliance focus layer, it locates the core compliance requirements corresponding to the scenario, such as temperature control standards for cold chain logistics; and at the implicit demand layer, it mines potential needs that are not explicitly mentioned by the user but are common in the industry, such as the verification of logistics supplier qualifications in dairy cold chain audits and the compliance requirements for hazardous chemical storage in semiconductor factory audits. Through this four-layer mining, fragmented keywords are transformed into a precise profile containing multiple scenario features, covering all dimensions of information such as business boundaries, industry characteristics, core compliance, and potential needs. Subsequently, based on this precise profile, a pre-set industry risk map library is retrieved. This library integrates historical audit data, regulatory penalty cases, and compliance risk research reports from various industries. It matches high-frequency problem points (such as missing temperature control records in the dairy cold chain and the risk of hazardous chemical leakage in semiconductor factories) and high-risk compliance loopholes (such as the transfer and handover process in cold chain transportation and the reporting process of environmental monitoring data in factories) corresponding to the current business scenario. Based on these risk points and loopholes, corresponding audit indicators are extracted from the industry risk map library, and a list of risk-related indicators is finally generated, which anchors the core of risk prevention and control for the construction of subsequent checklists.
[0056] After generating the list of risk-related indicators, these indicators are integrated with the core indicators in the basic indicator knowledge base. Algorithms are then used to strengthen the weights of these indicators and eliminate redundancies. First, the risk-related indicator list is semantically fused with the core indicators of the corresponding management system standards in the basic indicator knowledge base. This is achieved through text similarity comparison and clause-based association, integrating the inspection requirements, judgment criteria, and compliance basis of the two types of indicators. Building upon this foundation, an attention mechanism algorithm is introduced to adjust the weights of the fused indicators. For high-risk indicators in the risk-related indicator list (such as real-time temperature control monitoring indicators for cold chain logistics and explosion-proof facility inspection indicators for hazardous chemical storage), the algorithm automatically strengthens their weight proportion, placing these indicators in a core audit position in subsequent checklists and highlighting the priority of risk prevention and control. Simultaneously, the algorithm intelligently optimizes the fused indicator set, automatically eliminating indicators irrelevant to the current scenario based on precise scenario profiling. For example, hygiene inspection indicators for food processing production lines are eliminated in dairy cold chain audits, and product quality testing indicators for general electronic manufacturing are eliminated in ESG audits of semiconductor factories. Furthermore, duplicate verification items are identified and merged through semantic comparison to avoid redundancy in audit content, ultimately forming a fused indicator set that focuses on scenario risks, has clear logic, and hierarchical weighting.
[0057] After optimizing the fusion of indicators, personalized checklists are created to address the complex audit requirements of various scenarios, and these checklists are given dynamic verification capabilities. First, the complex audit requirements behind the fusion indicator set are identified, such as the temperature control data traceability requirements for cross-regional transportation in cold chain logistics audits, and the multi-dimensional verification requirements of ESG indicators in semiconductor factory audits. Then, a large language model is triggered to generate customized inspection logic: the model combines the business processes and compliance requirements of the scenario to design practical inspection steps, and these customized logics are embedded into the corresponding indicator items of the checklist, ensuring that the checklist's inspection process highly aligns with the company's actual business processes. Based on this, three value-added modules are added to the checklist: a scenario risk warning module, which marks the risk level and potential compliance consequences of high-risk indicators; an anomaly handling guidance module, which provides preliminary rectification directions and compliance basis for potential problems discovered during audits; and a compliance basis extended interpretation module, which provides industry-applicable explanations and case references for the compliance clauses of core indicators. Simultaneously, a dynamic verification mechanism was designed for the checklist, enabling it to automatically trigger secondary verification reminders for relevant indicators based on real-time data collected during on-site audits (such as actual temperature control values in cold chain transportation and real-time environmental monitoring data from the factory). For example, when the temperature control value exceeds the standard range, a secondary inspection reminder is triggered regarding the calibration status of temperature control equipment and the emergency response plan of the logistics supplier. Finally, the optimized set of fused indicators, customized inspection logic, and value-added modules are integrated to generate a complete and feature-rich standard checklist. This checklist retains the standardization of basic audit items while achieving precise adaptation to scenario requirements through risk control and customized design, providing a more guiding and practical basis for on-site audits.
[0058] In one embodiment, the method further includes: Using the character length and numerical range of the sensitive data fields in the check table as parameters, a Bézier baseline curve of random order is generated. The sensitive data is mapped to the coordinate point set of the Bézier baseline curve in binary stream form. Dynamic graphic offset processing based on sine function is performed on the coordinate point set. The offset is dynamically adjusted in real time according to the hash value of the unique identifier of the check table. After offset, the coordinate mapping relationship of the original data is removed, and only the curve features and offset algorithm parameters are retained. A multi-dimensional feature mutation mechanism for sensitive data is initiated. For structured sensitive values in the checklist, a mutation feature curve is generated through piecewise polynomial fitting. The original values are decomposed into the curvature, intercept, and inflection point of the curve and stored. For unstructured sensitive text, it is first converted into a high-dimensional feature matrix through word vectors. Then, fractal mutation is performed on the matrix in combination with the fractal dimension generation rules of fractal geometry. The mutated matrix features are bound and stored with the randomly generated fractal graphic features.
[0059] In this embodiment, sensitive data fields added to the checklist are first identified, including auditor identity information, confidential business data of the enterprise, and core risk values in the audit results. The character length (for text-based data) and numerical range (for numerical data) of each sensitive data field are precisely extracted as core parameters. Using these parameters as input, the order of a Bézier curve (e.g., quadratic, cubic, or quintic Bézier curve) is randomly generated, and the number of control points and coordinate range of the curve are determined based on the order, thus generating a unique Bézier baseline curve. The shape and parameters of this curve are entirely determined by the inherent properties of the sensitive data, becoming the geometric carrier for mapping the sensitive data.
[0060] Sensitive data is converted into a binary stream according to the computer's underlying storage rules. Then, following the coordinate point distribution pattern of the Bézier curve, each bit of the binary stream is mapped sequentially to the set of coordinate points on the curve (that is, the horizontal and vertical coordinate values of each coordinate point on the curve correspond to specific bits in the binary stream). This transforms the sensitive data, originally presented as characters / numerical values, into a set of coordinate points with geometric characteristics on the Bézier curve, completing the first transformation of data from digital form to geometric form.
[0061] Dynamic graphic offset processing is performed on the aforementioned coordinate point set. First, the hash value of the unique identifier in the checklist is calculated. This hash value is used as the phase parameter of the sine function. Combined with preset amplitude and frequency, an offset function that dynamically changes with the hash value is generated. Based on this function, the horizontal and vertical coordinates of each coordinate point on the Bézier baseline curve are offset, forming a new offset coordinate point set from the original set. The shape of the offset curve will vary depending on the unique identifier in the checklist. After the offset operation is completed, the direct mapping relationship between the original sensitive data and the coordinate point set is actively eliminated. Only the characteristic parameters of the Bézier baseline curve (order, control point coordinates) and the offset algorithm parameters (amplitude, frequency, and phase hash value of the sine function) are retained. At this point, the original sensitive data cannot be directly deduced from the stored curve and algorithm parameters, achieving the first-stage encryption protection of the data.
[0062] For structured sensitive values in the checklist (such as enterprise audit failure rate, risk indicator quantification score, sample size for sampling inspection, etc.), the numerical features corresponding to the coordinate point set after Bézier curve offset processing are first extracted. Then, a piecewise polynomial fitting algorithm is used to generate multiple continuous variation feature curves (such as combinations of linear segments, quadratic parabolic segments, and cubic curve segments) based on the changing trends of the values. After fitting, the original values are no longer stored, but are decomposed into geometric attribute parameters of the variation feature curves: curvature (degree of curve bending), intercept (value of the intersection of the curve and the coordinate axis), and inflection point (coordinates of the critical point of curve trend change). These geometric parameters are used as the storage form of structured sensitive values, so that the original values are completely transformed into the geometric features of the curve, realizing secondary encryption of numerical sensitive data.
[0063] For unstructured sensitive text in the checklist (such as detailed descriptions of corporate compliance deficiencies, on-site notes by auditors involving confidential matters, and technical parameters of the company's core business), the system first uses word vector models from natural language processing (such as Word2Vec and BERT) to transform each word in the text into a vector element in a high-dimensional feature matrix, thus converting the unstructured text content into structured high-dimensional matrix data. Then, fractal dimension generation rules from fractal geometry are introduced. The fractal dimension is determined based on parameters such as text length and semantic complexity. Based on this dimension, the high-dimensional feature matrix undergoes fractal mutation processing—iterative transformation rearranges the row and column elements of the matrix to generate a new matrix with fractal features. Simultaneously, the system randomly generates a fractal graph (such as the Mandelbrot set or the Julia set), binding the features of the mutated high-dimensional feature matrix with the geometric features of the fractal graph (such as the number of iterations of the fractal boundary and the topological parameters of the graph) for storage. This completely severs the direct association between the original text and the stored data, achieving secondary encryption of text-based sensitive data.
[0064] Through the above operations, the sensitive data in the checklist no longer exists in its original form, but is transformed into a series of geometric and algorithmic parameters without direct semantics, such as Bézier curve features, offset algorithm parameters, geometric properties of polynomial fitting curves, and binding features of fractal graphics and mutation matrices. This greatly improves the security of the storage and transmission of sensitive data and effectively prevents the risk of data leakage and tampering.
[0065] In one embodiment, the method further includes: Using the unique identifier of the checklist as the initial key, a chaotic attractor is generated by combining the type of sensitive data added to the checklist. The sensitive data is transformed into an initial data sequence and embedded in the trajectory point set of the chaotic attractor. By adjusting the parameters of the chaotic system, the trajectory point set forms an unpredictable dynamic chaotic curve. The sensitive data is only used as a hidden driving factor of the curve trajectory and no original data fragments are directly stored. The dynamic chaotic curve is mapped to a two-dimensional fractal graphic. The biometrics of the auditor are used as the offset key to dynamically modify the iterative generation formula of the two-dimensional fractal graphic. This allows the fractal details of the graphic to shift in real time with the biometric parameters, forming a personalized encrypted graphic. The direct mapping relationship between the graphic and the original data is eliminated, and only the fractal iteration parameters and biometric offset factors are retained. For structured sensitive values, they are decomposed into two features: the curvature abrupt change point of the dynamic chaotic curve and the iteration number of the two-dimensional fractal graph, and then bound and stored. For unstructured sensitive text, semantic segmentation is used to transform it into text fragments. Each text fragment is then mapped to an independent sub-graph of a two-dimensional fractal graph. The order of the sub-graphs is shuffled to generate a set of fractal graphs with no logical connection.
[0066] In this embodiment, the unique identifier of the checklist is first extracted as the initial key. Simultaneously, sensitive data types added to the checklist are identified. The initial key and data type parameters are then input into a preset chaotic system. By solving the dynamic equations of the chaotic system, a chaotic attractor matching the data characteristics is generated. As a core feature of chaotic systems, the chaotic attractor possesses extreme sensitivity to initial values and unpredictable trajectories, providing a dynamic carrier for embedding sensitive data.
[0067] Various types of sensitive data are transformed into standardized initial data sequences according to underlying encoding rules. Numerical data is converted to binary encoding, textual data is converted to ASCII or Unicode encoding, and semi-structured data is serialized. Subsequently, this initial data sequence is used as a perturbation parameter of a chaotic system and embedded into the trajectory point set of the chaotic attractor, so that the distribution pattern of the trajectory points is dynamically adjusted as the data sequence changes.
[0068] By adjusting the core parameters of the chaotic system (such as the Rayleigh number and Prandtl number for the Lorentz system, and the conductivity parameters for the Chua system), the trajectory point set embedded in the data sequence is made to form a dynamic chaotic curve with constantly changing shape and no fixed pattern. In this process, sensitive data is no longer stored in the form of any original fragment, but exists only as a latent factor driving the changes in the trajectory of the chaotic curve. The original data cannot be directly deduced from the curve shape from the outside, thus achieving complete decoupling between sensitive data and the storage medium.
[0069] Fractal geometry generation algorithms (such as the Mandelbrot set iteration algorithm and the Julia set iteration algorithm) are used to transform the trajectory point set of the dynamic chaotic curve generated in the previous step into a two-dimensional fractal graphic. During the transformation process, the curvature, trajectory density, inflection point distribution, and other features of the chaotic curve are directly mapped to the boundary shape, iterative texture, detail complexity, and other geometric properties of the fractal graphic. This transforms the dynamic features of the chaotic curve into the static geometric features of the fractal graphic, completing the upgrade of the data carrier from a one-dimensional curve to a two-dimensional graphic.
[0070] The unique biometric features of each reviewer (such as the fractal dimension of fingerprint texture, topological parameters of iris, and coordinate set of facial feature points) are collected as an offset key. These biometric parameters are input into the iterative generation formula of the fractal image, and the core iterative parameters of the formula (such as complex plane constant, scaling factor, and rotation angle) are dynamically modified. Because the biometric features of different reviewers are unique, the iterative formula of the fractal image will be adjusted differently according to changes in the biometric parameters, causing the detailed texture and local structure of the fractal image to shift in real time, ultimately forming a personalized encrypted image for each person.
[0071] After the personalized encrypted graphic is generated, the direct mapping relationship between the graphic and the original sensitive data and chaotic curve is actively removed. Only the iterative generation parameters of the fractal graphic (such as the number of iterations and the initial complex value) and the biometric offset factor (the correlation adjustment rules between biometric parameters and iterative formula) are retained. The path of inferring the original data from the graphic is cut off at the storage level, so as to realize the secondary encryption protection of the data.
[0072] For structured sensitive values in the checklist (such as enterprise audit failure rate, risk indicator quantification score, sampling inspection sample size, etc.), the key features of their corresponding dynamic chaotic curves are first extracted. The curvature abrupt change points (coordinate points where the curve's curvature changes drastically) are then extracted, followed by the core parameters of their mapped two-dimensional fractal graph and the number of iterations. These two features are then uniquely bound together as the storage format for the structured sensitive values. No original values are retained; external data cannot directly reconstruct the specific values using only the combination of curvature abrupt change points and iteration counts, thus achieving final encryption of the numerical data.
[0073] For unstructured sensitive text in checklists (such as detailed descriptions of corporate compliance deficiencies, on-site confidential notes by auditors, and core technical parameters of the enterprise), the text is first segmented into several independent text fragments (such as sentences, phrases, and keyword groups) according to semantic logic using natural language processing semantic segmentation algorithms. Then, each text fragment is mapped to an independent sub-graph of a two-dimensional fractal graph, with each sub-graph possessing a unique fractal texture and geometric boundary, forming a one-to-one correspondence with the corresponding text fragment. Finally, a random permutation algorithm shuffles the order of all independent sub-graphs, generating a set of fractal graphs with no semantic logical connection. This set is used as the storage format for the unstructured sensitive text. Even if an external entity obtains this graph set, it cannot reconstruct the semantic content of the original text from the disordered sub-graphs, thus achieving final encryption of the text-based data.
[0074] Through the above operations, the sensitive data in the checklist exists entirely in the form of the geometric features of chaotic curves, the iterative parameters of fractal graphics, and the set of sub-graphics. This not only utilizes the unpredictability of chaotic systems and the complexity of fractal geometry to enhance encryption strength, but also achieves personalized protection through the uniqueness of biometric features, fundamentally eliminating the risk of sensitive data leakage and tampering.
[0075] In the above embodiments, this application incorporates some existing algorithms and technical features for explanation and description to make the specification more detailed, clear, and complete, thus complying with the provisions of the Patent Law. However, this is not achieved by using a series of complex steps and algorithmic formulas, nor by complicating the technical solution, nor by combining or stacking conventional or simple features. The existing algorithms and technical features listed are for the purpose of disclosing the specific implementation methods of each step of this application (not to limit this application) and to avoid situations where this application cannot be implemented.
[0076] Reference Figure 2 In another embodiment of the present invention, a checklist generation system for digital auditing is also provided, comprising: The upload module is used to classify and upload the audit data required by the digital audit tool according to at least one management system standard and industry characteristic tags. It divides the basic indicator knowledge base, original input documents, and generated document templates, and adopts a table import combined with a real-time data update mechanism to manage the basic indicator knowledge base. The generation module is used to automatically match the corresponding management system standards and industry-wide modules based on the indicator data in the basic indicator knowledge base and the semantic analysis of the large language model, and generate a standard checklist for the user-input keywords of the audit scenario; the standard checklist supports collaborative access and use on mobile and PC terminals. The optimization module allows on-site auditors to record inspection results and upload evidence documents in real time via mobile devices, which are then synchronized to the system database. The PC system intelligently optimizes the scheduling of subsequent audit tasks based on the completion progress in the standard checklist, the location information of the auditors, the matching degree of professional qualifications, and the task priority, generating multiple optimal audit route plans for users to choose from.
[0077] In this embodiment, the specific implementation of each module in the above system embodiment is described in the above method embodiment, and will not be repeated here.
[0078] Reference Figure 3 This invention also provides a computer device, which can be a server, and its internal structure can be as follows: Figure 3As shown, the computer device includes a processor, memory, display screen, input device, network interface, and database connected via a system bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores the operating system, computer programs, and database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The database stores the data corresponding to this embodiment. The network interface is used to communicate with external terminals via a network connection. When the computer program is executed by the processor, it implements the above-described method.
[0079] Those skilled in the art will understand that Figure 3 The structures shown are merely block diagrams of some structures related to the present invention and do not constitute a limitation on the computer devices on which the present invention is applied.
[0080] An embodiment of the present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the above-described method. It is understood that the computer-readable storage medium in this embodiment can be a volatile readable storage medium or a non-volatile readable storage medium.
[0081] In summary, the checklist generation method and system for digital auditing provided in this embodiment of the invention includes: classifying and uploading audit data required by the digital auditing tool according to at least one management system standard and industry characteristic tags; dividing the data into a basic indicator knowledge base, original input documents, and generated document templates; and managing the basic indicator knowledge base using a table import combined with a real-time data update mechanism. Based on the indicator data in the basic indicator knowledge base and semantic analysis using a large language model, the system automatically matches corresponding management system standards and industry-wide modules to generate a standard checklist for audit scenario keywords input by the user. The standard checklist supports collaborative retrieval and use on both mobile and PC terminals. On-site auditors record audit results and upload evidence documents in real time via mobile terminals, which are synchronized to the system database in real time. The PC system intelligently optimizes the scheduling of subsequent audit tasks based on the completion progress, auditor location information, professional qualification matching degree, and task priority in the standard checklist, generating multiple optimal audit route schemes for users to choose from. In this invention, based on at least one management system standard and industry-specific tags, a basic indicator knowledge base, original input documents, and generated document templates are divided. For user-input audit scenario keywords, the corresponding management system standard and industry-standard modules are automatically matched to generate a standard checklist. Finally, combining on-site audit scenarios with the PC system's intelligent optimization of subsequent audit task scheduling based on the standard checklist, multiple optimal audit route plans are generated for the user to choose from. This overcomes the shortcomings of current checklists, which cannot quickly adapt to the audit needs of different industries and system standards, and are difficult to generate reasonable audit task schedules.
[0082] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the present invention and embodiments can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual-rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM, etc.
[0083] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, apparatus, article, or method that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, apparatus, article, or method. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, apparatus, article, or method that includes that element.
[0084] The above description is only a preferred embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structural or procedural transformations made based on the content of the present invention specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of the present invention.
Claims
1. A method for generating a checklist for digital auditing, characterized in that, Includes the following steps: Based on at least one management system standard and industry characteristic tags, the audit data required by the digital audit tool is classified and uploaded, and the basic indicator knowledge base, original input documents, and generated document templates are divided. The basic indicator knowledge base is managed by a table import combined with a real-time data update mechanism. Based on the indicator data in the basic indicator knowledge base and semantic analysis of the large language model, the system automatically matches the corresponding management system standards and industry-standard modules for the user-input keywords of the audit scenario, and generates a standard checklist; the standard checklist supports collaborative access and use on mobile and PC terminals. On-site auditors record inspection results and upload evidence documents in real time via mobile devices, which are then synchronized to the system database. The PC system intelligently optimizes the scheduling of subsequent audit tasks based on the completion progress in the standard checklist, the location information of the auditors, the matching degree of professional qualifications, and the task priority, generating multiple optimal audit route options for users to choose from.
2. The method for generating a checklist for digital auditing according to claim 1, characterized in that, The method further includes: The basic indicator knowledge base is stored redundantly and its consistency is verified across multiple nodes using distributed database technology.
3. The method for generating a checklist for digital auditing according to claim 1, characterized in that, The method further includes: When users manually adjust the standard checklist items, the system intelligently recommends supplementary items based on historical audit data and similar enterprise cases. It also performs compliance pre-verification on the user-added items and alerts users to potential risks. The system retains the version history of item adjustments for comparison and generates a user-adaptive custom checklist.
4. The method for generating a checklist for digital auditing according to claim 1, characterized in that, Based on at least one management system standard and industry-specific tags, the audit data required by the digital audit tool is categorized and uploaded, and divided into a basic indicator knowledge base, original input documents, and generated document templates, including: For management system standards, the core clauses are automatically extracted and annotated. For industry-specific tags, a hierarchical structure of main tags and sub-tags is adopted. The main tag includes the industry type, and the sub-tags correspond to the specific scenarios of each industry. When uploading review data, the system automatically matches the corresponding standard core clauses and industry sub-tags based on the content of the review data. According to the data judgment criteria of the basic indicator knowledge base, the content that meets the criteria in the audited data is uploaded to the basic indicator knowledge base; according to the judgment criteria of the original input document, the content that meets the criteria is uploaded to the original input document; according to the judgment criteria of the generated document template, the content that meets the criteria is uploaded to the generated document template.
5. The method for generating a checklist for digital auditing according to claim 1, characterized in that, The basic indicator knowledge base is managed using a combination of table creation and import, along with a real-time data update mechanism, including: When adopting a table creation and import combined with a real-time data update mechanism, a standard update monitoring crawler tool is deployed to crawl and semantically parse data in real time, automatically identifying new / revised content that affects basic indicators, triggering version iteration and source tracing of the corresponding indicators; AI-driven cross-dimensional data adaptation and verification rules are embedded to verify data from different sources and generate a visual analysis report that includes conflict point location, adaptability score and optimization scheme.
6. The method for generating a checklist for digital auditing according to claim 1, characterized in that, Based on indicator data in the basic indicator knowledge base and semantic analysis of the large language model, the system automatically matches corresponding management system standards and industry-standard modules to generate a standard checklist for user-input keywords related to the audit scenario. This checklist includes: The semantic depth of the user-input review scenario keywords is analyzed using a large language model to extract the core requirements and implicit constraints of the scenario and generate scenario feature vectors. Based on scene feature vectors, multi-dimensional quantitative scoring is performed on the indicator data in the basic indicator knowledge base to select the core indicator set whose scores reach the preset threshold. The system calls upon a general industry module library, matches the industry-specific module with the highest semantic similarity to the scene feature vector, and combines the core indicator set with the industry-specific module. During the combination process, the system automatically adjusts the order of indicator items, merges duplicate verification items, supplements logical connection explanations, and generates a structured standard checklist. By using a large language model, the structured standard checklist is pre-validated for compliance, potential compliance vulnerabilities are identified, and optimization suggestions are provided.
7. The method for generating a checklist for digital auditing according to claim 1, characterized in that, The PC-based system intelligently optimizes the scheduling of subsequent review tasks based on the completion progress, location information of reviewers, professional qualification matching, and task priority in the standard checklist, generating multiple optimal review route options for users to choose from, including: The completion progress of the standard checklist is broken down into statuses, the urgency coefficient of the tasks to be started is calculated, the audit workload is quantified by level, and a task time matrix is generated. The professional qualifications of auditors are evaluated using a three-dimensional weighted score based on the system standard certification level, the number of industry-specific audit cases, and the historical audit pass rate to obtain a suitability score. Combined with the current workload of the auditors, the optimal pool of personnel with a suitability score greater than the first threshold and a workload less than the second threshold is selected. Collect the real-time location of the reviewers and the geographic coordinates of the review locations. Integrate real-time traffic data, traffic control information and characteristics of morning and evening peak hours through the GIS system to calculate the shortest travel path and time fluctuation range between any two locations, as dynamic travel time data. Based on task urgency coefficient, task time matrix, optimal personnel pool, dynamic passage time data, and task priority, a multi-constraint optimization algorithm model is constructed. Combined with a dynamic adjustment mechanism, the review task is broken down into parallel sub-tasks according to process nodes, taking into account the connection time of personnel cross-regional collaboration. The improved particle swarm optimization algorithm is used to solve the problem, with multiple objectives of shortest total review cycle, optimal personnel capability matching, lowest traffic energy consumption, and minimum task splitting conflict, generating multiple sets of differentiated scheduling schemes.
8. The method for generating a checklist for digital auditing according to claim 7, characterized in that, Each differentiated scheduling plan includes detailed personnel division of labor, time-based task sequences, dynamically optimized routes, and task priority adjustment interfaces. It also uses visual charts to display the time cost, manpower cost, transportation energy consumption cost, and risk factor of each plan.
9. The method for generating a checklist for digital auditing according to claim 1, characterized in that, Based on indicator data in the basic indicator knowledge base and semantic analysis of the large language model, the system automatically matches corresponding management system standards and industry-standard modules to generate a standard checklist for user-input keywords related to the audit scenario. This checklist includes: By using a large language model, semantic mining is performed on the keywords of the review scenario input by users in four layers: business scenario, industry attributes, compliance focus, and implicit needs, to generate a precise profile containing multiple scenario features. Based on the precise profile, the industry risk map library is called to match the high-frequency problem points and high-incidence links of compliance vulnerabilities corresponding to the business scenario, and generate a list of risk-related indicators. The risk-related indicator list is semantically fused with the core indicators in the basic indicator knowledge base. The weight of high-risk indicators is strengthened through the attention mechanism algorithm, while automatically removing scenario-irrelevant indicators and merging duplicate verification items. To address the complex audit requirements specific to certain scenarios, a large language model is triggered to generate customized inspection logic, which is then embedded into the inspection process. This ensures that the final standard checklist not only includes basic audit items but also adds value-added modules such as scenario risk warnings, abnormal situation handling guidelines, and extended interpretations of compliance basis. Furthermore, it supports automatically triggering secondary verification reminders for relevant related indicators based on real-time data collected during on-site audits.
10. A checklist generation system for digital auditing, characterized in that, include: The upload module is used to classify and upload the audit data required by the digital audit tool according to at least one management system standard and industry characteristic tags. It divides the basic indicator knowledge base, original input documents, and generated document templates, and adopts a table import combined with a real-time data update mechanism to manage the basic indicator knowledge base. The generation module is used to automatically match the corresponding management system standards and industry-wide modules based on the indicator data in the basic indicator knowledge base and the semantic analysis of the large language model, and generate a standard checklist for the user-input keywords of the audit scenario; the standard checklist supports collaborative access and use on mobile and PC terminals. The optimization module allows on-site auditors to record inspection results and upload evidence documents in real time via mobile devices, which are then synchronized to the system database. The PC system intelligently optimizes the scheduling of subsequent audit tasks based on the completion progress in the standard checklist, the location information of the auditors, the matching degree of professional qualifications, and the task priority, generating multiple optimal audit route plans for users to choose from.