Enterprise-level risk base line management and control system and method
The enterprise-level risk bottom-line control system addresses the shortcomings of existing risk control systems in terms of scanning efficiency, data integration, and rule configuration. It enables real-time/batch dual-mode scanning, automated hierarchical control of black and gray lists, and multi-dimensional visualization analysis of risk data, thereby improving the accuracy of risk identification and system availability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BANK OF SHANGHAI
- Filing Date
- 2026-02-09
- Publication Date
- 2026-05-19
AI Technical Summary
Existing risk control systems have shortcomings in scanning efficiency, data integration, rule configuration, workflow design, and list management. They cannot meet real-time and batch requirements, lack comprehensiveness and traceability in risk identification, resulting in low business efficiency and compliance risks.
The system adopts an enterprise-level risk bottom-line control system, including modules such as a multi-level approval workflow engine, multi-dimensional statistical analysis, a dynamically configurable rule engine, real-time and batch dual-mode scanning, automated hierarchical control of black and gray lists, and full-process digital approval, to achieve multi-source data fusion and intelligent risk identification.
It improves the efficiency and accuracy of risk scanning, reduces reliance on manual labor and operating costs, enhances system availability and compliance capabilities, and enables multi-dimensional visualization analysis and traceability of risk data.
Smart Images

Figure CN122066201A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of financial risk control technology, and in particular to an enterprise-level risk bottom-line control system and method. Background Technology
[0002] The existing risk control system mainly adopts the following technical solutions:
[0003] (1) The limitations of traditional risk scanning systems are that most of them are risk scanning based on local database queries. Advantages: data persistence and relatively simple query; Disadvantages: 1) low scanning efficiency, which cannot meet the needs of real-time risk control; 2) lack of external data integration, and incomplete risk identification; 3) complex rule configuration, which requires professional technical personnel to operate; 4) lack of risk snapshot records, which makes it impossible to trace risk changes.
[0004] (2) Shortcomings of traditional workflow systems and problems of existing workflow systems: 1) Complex workflow design requires professional developers; 2) Single approval node type, which cannot meet complex business needs; 3) Lack of workflow execution monitoring, which makes it impossible to detect anomalies in a timely manner; 4) Imperfect workflow version management, which makes it difficult to optimize the process.
[0005] (3) Deficiencies of risk scanning technology and problems of existing risk scanning technology: 1) The scanning mode is single and cannot meet the needs of real-time and batch processing at the same time; 2) There is a lack of automatic risk level classification mechanism; 3) The scanning results are not processed in a timely manner, which affects business efficiency.
[0006] (4) Inadequacies of list management technology and problems with existing list management technology: 1) The management of list validity period is not perfect and expired data is easy to be generated; 2) List changes lack approval process and rely on offline processing, which poses compliance risks.
[0007] Therefore, it is necessary to provide an enterprise-level risk bottom-line control system and method to achieve real-time / batch dual-mode scanning of customer risk profiles, automated hierarchical control of black and gray lists, full-process digital approval of special business and list transfers, and multi-dimensional visualization analysis of risk data. Summary of the Invention
[0008] The purpose of this invention is to provide an enterprise-level risk bottom-line control system and method to achieve real-time / batch dual-mode scanning of customer risk profiles, automated hierarchical control of black and gray lists, full-process digital approval of special business and list transfers, and multi-dimensional visualization analysis of risk data.
[0009] To address the problems existing in the prior art, this invention provides an enterprise-level risk bottom-line management system, comprising the following modules:
[0010] Control and execution information aggregation module: configured to implement a multi-level approval workflow engine;
[0011] Multi-dimensional statistical analysis module: configured to enable multi-dimensional visualization analysis of risk data;
[0012] Rule management module: Configured to build a dynamically configurable rule engine;
[0013] Risk bottom line scanning module: configured to enable real-time and batch dual-mode scanning of customer risk profiles;
[0014] List Management Module: Configured to achieve automated hierarchical control of blacklists and graylists;
[0015] Approval Process Module: Configured to enable fully digital approval for special cases and list transfers;
[0016] Multiple modules work together to manage enterprise-level risk bottom lines.
[0017] Optionally, in the enterprise-level risk bottom-line control system,
[0018] The control and execution information aggregation module is also used to aggregate control and execution information;
[0019] The multi-dimensional statistical analysis module analyzes dimensions including: institutional dimension, risk level dimension, reason for inclusion in the list dimension, and comprehensive statistical charts of control status.
[0020] The rule management module includes a rule base and a manual rule maintenance unit;
[0021] The risk bottom line scanning module includes: manual scanning, online scanning, batch scanning, and risk bottom line scanning results. The risk bottom line scanning results include risk snapshots, ledgers, and logs.
[0022] The list management module includes: list database, list system processing, and manual list maintenance;
[0023] The approval process module includes: regular application review process, differentiated access results, reconsideration application review process, and special case business supplementary review process. The regular application review process includes branch application, branch review, and head office review. Differentiated access results include: special case business records, list adjustment records, ledgers, and logs. The reconsideration application review process includes: branch application, branch review, head office review, and final review by the head office risk manager. The special case business supplementary review process includes: branch application and branch review.
[0024] This invention also provides an enterprise-level risk bottom-line control method, which is implemented based on the aforementioned enterprise-level risk bottom-line control system and includes the following steps:
[0025] Risk scan request processing;
[0026] Internal and external data integration;
[0027] Risk rule matching;
[0028] Risk classification and handling;
[0029] Results processing and feedback.
[0030] Optionally, in the enterprise-level risk bottom-line control method,
[0031] Risk scan request processing includes the following steps:
[0032] S1: Receive a risk scan request; the request includes basic customer information, scan type, and scan range;
[0033] S2: Verify the parameters of the request; the verification includes mandatory field checking, format validation, and business rule validation;
[0034] S3: Determine the scanning strategy; the scanning strategy acquires data based on customer type and scanning type.
[0035] Optionally, in the enterprise-level risk bottom-line control method,
[0036] Internal and external data integration includes the following steps:
[0037] S4: Invoke local data services; the services include enterprise customer information query and enterprise business status query;
[0038] S5: Call an external data platform; the data provided by the external data platform includes credit information and risk data;
[0039] S6: Integrate internal and external data; the integration methods include data cleaning, format conversion and data merging.
[0040] Optionally, in the enterprise-level risk bottom-line control method,
[0041] Risk rule matching includes the following steps:
[0042] S7: Determine the applicable risk rules; the rules are dynamically selected based on customer type and business scenario;
[0043] S8: Execute rule matching logic; the rule matching logic includes condition judgment and level classification;
[0044] S9: Determine the risk level; the level includes Black, Gray I, Gray II, Alert, and Normal.
[0045] Optionally, in the enterprise-level risk bottom-line control method,
[0046] Risk classification and processing includes the following steps:
[0047] S10: Determine the list type based on the risk level; the list type includes blacklists / greylists and whitelists;
[0048] S11: Generate risk scan results; the risk scan results include risk level and control recommendations;
[0049] S12: Record a risk snapshot; the risk snapshot includes the scan time, risk status, and historical records.
[0050] Optionally, in the enterprise-level risk bottom-line control method,
[0051] Results processing and feedback include the following steps:
[0052] S13: Generate a scan report; the scan report includes customer information, risk analysis, and control recommendations;
[0053] S14: Trigger control measures; the control measures are executed automatically according to the risk level.
[0054] S15: Notify the corresponding management system; the notification content includes scan results, risk changes, and business impact;
[0055] S16: Update business status; the update includes customer status, business status and system status.
[0056] Compared with the prior art, the present invention has the following advantages:
[0057] 1. Technical effects:
[0058] (1) Improve risk scanning efficiency:
[0059] The scan response time has been reduced from 2 seconds to 1 second, an improvement of more than 50%.
[0060] The accuracy of risk identification improved from 85% to 95%, an increase of 10%.
[0061] The system's processing capacity has increased from 40 transactions per second to 160 transactions per second, a fourfold increase.
[0062] (2) Reduce reliance on manual labor:
[0063] The rate of manual intervention decreased from 40-60% to 10-20%, a reduction of 70%.
[0064] The complexity of rule configuration has been reduced by 80%, transforming it from professional development to visual configuration.
[0065] (3) Enhance system availability:
[0066] System availability improved from 95% to over 99.5%;
[0067] Fault recovery time has been reduced from hours to minutes.
[0068] 2. Business Results:
[0069] (1) Reduce operating costs:
[0070] Labor costs reduced by 60%;
[0071] System maintenance costs have been reduced by 40%.
[0072] (2) Enhance compliance capabilities:
[0073] The completeness of the approval records reached 100%;
[0074] Improved traceability of risk management;
[0075] Compliance inspection efficiency improved by 80%.
[0076] 3. Innovation Effects:
[0077] (1) Technological innovation:
[0078] The first risk scanning mechanism to achieve multi-source data fusion;
[0079] Pioneering real-time / batch dual-mode scanning technology;
[0080] Record risk snapshots and traceability technologies.
[0081] (2) Architectural innovation:
[0082] Microservice architecture design, supporting horizontal scaling;
[0083] Distributed design enhances the system's high availability.
[0084] (3) Application Innovation:
[0085] Visual rule configuration lowers the technical barrier;
[0086] Intelligent risk identification improves identification accuracy;
[0087] Multi-dimensional data analysis supports decision optimization. Attached Figure Description
[0088] Figure 1 This is a module diagram of an enterprise-level risk bottom-line control system provided in an embodiment of the present invention. Detailed Implementation
[0089] The specific embodiments of the present invention will now be described in more detail with reference to the accompanying drawings. The advantages and features of the present invention will become clearer from the following description. It should be noted that the drawings are all in a very simplified form and use non-precise proportions, and are only used to facilitate and clarify the illustration of the embodiments of the present invention.
[0090] In the following, if the methods described herein include a series of steps, the order of these steps presented herein is not necessarily the only order in which these steps can be performed, and some of the steps described may be omitted and / or some other steps not described herein may be added to the method.
[0091] To address the problems existing in the prior art, this invention provides an enterprise-level risk bottom-line management system, such as... Figure 1 As shown, the system includes the following modules:
[0092] Control and execution information aggregation module: configured to implement a multi-level approval workflow engine;
[0093] Multi-dimensional statistical analysis module: configured to enable multi-dimensional visualization analysis of risk data;
[0094] Rule management module: Configured to build a dynamically configurable rule engine;
[0095] Risk bottom line scanning module: configured to enable real-time and batch dual-mode scanning of customer risk profiles;
[0096] List Management Module: Configured to achieve automated hierarchical control of blacklists and graylists;
[0097] Approval Process Module: Configured to enable fully digital approval for special cases and list transfers;
[0098] Multiple modules work together to manage enterprise-level risk bottom lines.
[0099] Optionally, in the enterprise-level risk bottom-line control system,
[0100] The control and execution information aggregation module is also used to aggregate control and execution information;
[0101] The multi-dimensional statistical analysis module analyzes dimensions including: institutional dimension, risk level dimension, reason for inclusion in the list dimension, and comprehensive statistical charts of control status.
[0102] The rule management module includes a rule base and a manual rule maintenance unit;
[0103] The risk bottom line scanning module includes: manual scanning, online scanning, batch scanning, and risk bottom line scanning results. The risk bottom line scanning results include risk snapshots, ledgers, and logs.
[0104] The list management module includes: list database, list system processing, and manual list maintenance;
[0105] The approval process module includes: regular application review process, differentiated access results, reconsideration application review process, and special case business supplementary review process. The regular application review process includes branch application, branch review, and head office review. Differentiated access results include: special case business records, list adjustment records, ledgers, and logs. The reconsideration application review process includes: branch application, branch review, head office review, and final review by the head office risk manager. The special case business supplementary review process includes: branch application and branch review.
[0106] This invention provides an enterprise-level risk bottom-line control system for realizing real-time / batch dual-mode scanning of customer risk profiles, automated hierarchical control of black and gray lists, full-process digital approval of special business and list transfers, and multi-dimensional visualization analysis of risk data.
[0107] Through the above-mentioned technological innovations, this invention realizes intelligent, automated and standardized risk management, effectively solves the problems existing in traditional risk control systems, provides a new technical solution for the financial risk control field, and has technological advancement and practical value.
[0108] Example 1: Enterprise Customer Risk Scan Example:
[0109] Scene description:
[0110] A bank needs to conduct risk scans on corporate clients applying for loans. Client information includes: company name, unified social credit code, etc.
[0111] Specific implementation process:
[0112] 1. Parameter verification stage:
[0113] Receive customer application information: company name, unified social credit code;
[0114] Validate required fields such as customer number and customer name;
[0115] Verification and control phases, business numbers, and other business parameters.
[0116] 2. Internal and external data retrieval phase:
[0117] Access external data from enterprise customer service to obtain information such as enterprise operating status, suspected relationships, and shell companies for judgment purposes;
[0118] Access internal data to obtain the company's business information within the industry;
[0119] Customer risk profile established: Registered capital of 10 million yuan, established in 2018, and operating normally. No overdue loans within the bank. However, there are issues with multiple business licenses at one address and the presence of third-class industry-specific markings.
[0120] 3. Risk rule matching stage:
[0121] Load applicable risk rules:
[0122] Rule A: Overdue loans exist within the bank → None, risk level "None";
[0123] Rule B: Multiple licenses at one address exist → Risk level "warning";
[0124] Rule C: The last three categories of competitors → meet the requirements, risk level "black";
[0125] The remaining rules apply.
[0126] 4. Risk Classification Stage:
[0127] Based on the risk assessment rules, the risk level is determined to be "black".
[0128] Risk classification result generated: Customer's risk level is black, business will be refused;
[0129] Update customer risk status: Risk level = Black.
[0130] 5. Results Processing Stage:
[0131] Generate a risk scan report, including basic customer information, risk level, scan time, etc.
[0132] Record risk snapshots: Save to the risk snapshot table;
[0133] Implementation results:
[0134] Scan response time: 1 second;
[0135] Risk identification accuracy: 95%;
[0136] Human intervention rate: 0% (fully automated processing).
[0137] This invention also provides an enterprise-level risk bottom-line control method, which is implemented based on the aforementioned enterprise-level risk bottom-line control system and includes the following steps:
[0138] Risk scan request processing;
[0139] Internal and external data integration;
[0140] Risk rule matching;
[0141] Risk classification and handling;
[0142] Results processing and feedback.
[0143] 1. Risk scan request processing includes the following steps:
[0144] S1: Receive a risk scan request; the request includes basic customer information, scan type, and scan range;
[0145] For example, a corporate client scanning request includes:
[0146] Customer basic information: Customer name (custNm), Customer number (custId);
[0147] Scan type: controlStag, including business application (1), contract signing (2), disbursement (3), customer rating (4), post-loan management (5), and others (6);
[0148] Scan scope: source system (srcSys), business number (bizId), contract number (contrId), disbursement number (disbId);
[0149] Operation information: Query employee ID (qryEmpId), query employee name (qryEmpNm), and organization information (usrBelgOrgId, usrBelgOrgNm);
[0150] Scanning requests for private clients include:
[0151] Customer basic information: Customer name (custNm), document type (certTyp), document number (certNum);
[0152] Scan scope: application number (applId), list of associated customer names (rltvCustNmList).
[0153] S2: Verify the parameters of the request; the verification includes mandatory field checking, format validation, and business rule validation;
[0154] For example:
[0155] Required fields check: Customer name must be filled in, and ID number must be filled in and cannot be empty;
[0156] Format validation: The control phase must be a valid value between 1 and 6;
[0157] Business rule validation: When the control phase is 1, 2, or 3, the business number (bizId) is a required field; when the control phase is 2 or 3, the contract number (contrId) is a required field.
[0158] S3: Determine the scanning strategy; the scanning strategy acquires data based on customer type and scanning type;
[0159] For example, the scanning strategy execution process includes:
[0160] Whitelist customer priority strategy - First check if the enterprise customer is in the whitelist (ADM_CORP_CST_INF_TY). If it exists, return no risk directly.
[0161] Blacklist / Graylist Query Strategy - Prioritize querying the blacklist / graylist table (ADM_BLACK_GRAY_LIST) by customer ID (custId). If not found, query by customer name (custNm). Filtering conditions include: MAKE_MODE!=2 (not deleted), IS_NT_VALID=1 (valid), IS_NT_OUT_BLK_LIST=0 (not retrieved).
[0162] Real-time rule enforcement strategy - Call external real-time APIs (such as GSZJ for business registration, empty shell EDM, suspected YSGXM, etc.) to obtain the latest risk information;
[0163] Differentiated access strategy - For specific control phases, check if the customer has any exception approvals; if so, the control method will be changed to prompt.
[0164] 2. Internal and external data integration, including the following steps:
[0165] S4: Invoke local data services; the services include enterprise customer information query and enterprise business status query;
[0166] S5: Call an external data platform; the data provided by the external data platform includes credit information and risk data;
[0167] S6: Integrate internal and external data; the integration methods include data cleaning, format conversion and data merging.
[0168] 3. Risk rule matching, including the following steps:
[0169] S7: Determine the applicable risk rules; the rules are dynamically selected based on customer type and business scenario;
[0170] For example, risk rule selection methods include:
[0171] Rule storage: Risk rules are stored in the rule table (rsd_zn_rule). Each rule contains a rule ID (ruleId), rule name (ruleName), risk description (ruleDesc), data source (dataSource), customer type (cstType, 1=public, 0=private), and rule status (0=disabled, 1=trial operation, 2=enabled, 3=deleted).
[0172] Rule execution mode: Classified by runMode, 0 = Batch (executed on a schedule, results stored in the ADM_BLACK_GRAY_LIST table), 1 = Real-time (called via external API during online scanning), 2 = Manual (initiated by the user);
[0173] Rule API Type: Real-time rules call different external interfaces according to API type (apiType), such as business information query interface, shell company detection interface, and suspected relationship detection interface;
[0174] Rule selection logic: Filter the corresponding rules according to customer type (corporate / private), load the applicable rules according to business scenario (control phase), and only execute the rules in the enabled (2) or trial operation (1) status.
[0175] S8: Execute rule matching logic; the rule matching logic includes condition judgment and level classification;
[0176] For example, rule execution methods include:
[0177] Batch rule execution: Scheduled tasks are executed automatically at a frequency (1=day, 2=month, 3=quarter, 4=year) and the matching results are written to the black and gray list table;
[0178] Real-time rule execution: External APIs are called concurrently through an asynchronous thread pool (ListeningExecutorService). Each API has a 15-second timeout. If the timeout occurs, data is cached using a 30-day window period.
[0179] Rule condition judgment: Each rule contains specific condition logic, such as "overdue loans exist in the bank", "multiple licenses exist at one address", "the last three categories of markings of peers", etc. The system returns a hit or no hit based on the condition matching;
[0180] Rule whitelist filtering: Perform rule whitelist filtering to exclude rules that have been added to the whitelist, ensuring that special customers are not misjudged;
[0181] Multiple rule priority: When a customer matches multiple rules, the final result is selected based on the principle of the strictest control mode (minimum controlMode value) and the highest risk level (minimum riskLevel value).
[0182] S9: Determine the risk level; the level includes Black, Gray I, Gray II, Warning, and Normal;
[0183] Example: Risk level classification standards and corresponding ranges:
[0184] Black (Level 1): Customers have serious violations or high-risk behaviors, such as serious overdue loans within the bank, involvement in major litigation, being listed as a dishonest person subject to enforcement, or having their business licenses revoked. The corresponding control method is to refuse new additions (1).
[0185] GRAY_1 (Level 2): The customer has high risk factors, such as minor overdue payments, risks associated with related companies, multiple licenses at one address, suspected shell companies, and the last three categories of industry-related markings. The corresponding control method is rigid control of exposure (2).
[0186] GRAY_2 (Level 3): The customer has certain risk warnings, such as abnormal business status, low registered capital, short establishment time, and general related risks. The corresponding control method is rigid control exposure (2) or warning (3).
[0187] Prompt (Level 4): The customer has information that needs attention, such as frequent business changes, minor credit record flaws, general business risk warnings, etc. The corresponding control method is Prompt (3);
[0188] Normal: The client did not match any risk rules, and the risk scan result is no risk.
[0189] Example of rule matching execution result:
[0190] Rule A "Overdue loans exist within the bank" → Not matched → Risk level is normal;
[0191] Rule B "One address, multiple licenses" → hit → risk level is gray two (3), control method is prompt (3);
[0192] Rule C "The last three categories of industry tags" → hit → risk level is black (1), control method is to refuse new additions (1);
[0193] Final result: Based on the strictest principle, the risk level is determined to be black (1), and the control method is to refuse new additions (1).
[0194] 4. Risk classification and handling, including the following steps:
[0195] S10: Determine the list type based on the risk level; the list type includes blacklists / greylists and whitelists;
[0196] S11: Generate risk scan results; the risk scan results include risk level and control recommendations;
[0197] For example, the data structure of risk scan results includes:
[0198] Risk level information: Risk level code (riskLvl, 1-6), risk level description (riskLvlDesc, such as "Black", "Gray I", "Gray II", "Warning");
[0199] Control method information: Control method code (ctrlMode, 1-4), control method description (ctrlModeDesc, such as "Reject new additions", "Just control open areas", "Prompt", "No control");
[0200] Related information: Related customer name (rltvCustNm, multiple customers separated by commas), reason code for inclusion in the list (incidListReason, comma-separated), description of reason for inclusion in the list (incidListReasonDesc);
[0201] Risk details: Risk information description (riskInfoDesc), control organization level (controlOrgTier), initial inclusion date (fstEnterDt, multiple dates separated by commas), control objective (ctrlTgt);
[0202] Query identifier: Query serial number (qryNm).
[0203] S12: Record a risk snapshot; the risk snapshot includes the scan time, risk status, and historical records.
[0204] 5. Results processing and feedback, including the following steps:
[0205] S13: Generate a scan report; the scan report includes customer information, risk analysis, and control recommendations;
[0206] S14: Trigger control measures; the control measures are executed automatically according to the risk level.
[0207] For example, automatic triggering mechanisms for control measures include:
[0208] Control Information Recording: When a risk scan hits a blacklist or graylist, the system automatically and asynchronously records control information to the control list table (ADM_CONTROL_LIST_OF_CUST_INFO). The recorded content includes customer type (custType), customer name (name), customer number (custNo), clout status (cloutStat), risk level (riskGrade), reason for inclusion (incldListReasn), associated customer name (rltvCustNm), control date (controlDate), control amount (controlAmount), credit balance (crdtBal), available credit (avalLmt), and outstanding balance (unpayoffBal).
[0209] Risk Snapshot Storage: Synchronously save scan snapshots to the Risk Snapshot Table (ADM_RISK_SNAPSHOT), recording scan time, customer information, risk level, scan result (0=miss, 1=hit), source system, control stage, business number, etc.; at the same time, save the specific blacklist records of hits to the Risk Snapshot Black and Gray List Details Table (ADM_RISK_SNAPSHOT_BLACK_GRAY_LIST);
[0210] External system synchronization: Automatically synchronize management and control information to external systems according to the configuration.
[0211] Control measures implemented:
[0212] Reject new addition (1): The system returns a rejection flag, and the front-end business system uses this flag to prevent the business from continuing to be processed;
[0213] Rigid control exposure (2): The system returns the rigid control identifier, and the business system restricts the growth of the credit limit accordingly, while existing business can continue;
[0214] Tip (3): The system returns a prompt icon, and the business system displays risk warning information. Business personnel can choose to continue or terminate.
[0215] No control (4): The system only records information and does not affect business processing;
[0216] Differentiated access coverage: If a customer has an exception approval, the system will automatically cover the control method as prompt (3), allowing the business to continue but retaining the risk prompt;
[0217] Scenario: Enterprise customer "ABC Technology Co., Ltd." was detected by scanning the blacklist, with a risk level of black (1) and a control method of rejecting new additions (1);
[0218] Triggering measures:
[0219] 1. Asynchronously record control information to the ADM_CONTROL_LIST_OF_CUST_INFO table;
[0220] 2. Synchronously save risk snapshots to the ADM_RISK_SNAPSHOT table, and mark the scan results as 1 (hit);
[0221] 3. Save the details of the blacklisted matches to the ADM_RISK_SNAPSHOT_BLACK_GRAY_LIST table;
[0222] 4. Synchronize control information to the RAD system, mobile devices, and data analysis platform;
[0223] 5. Return a rejection message to the business system, and the business system will block the customer from adding new services.
[0224] S15: Notify the corresponding management system; the notification content includes scan results, risk changes, and business impact;
[0225] S16: Update business status; the update includes customer status, business status and system status.
[0226] Compared with the prior art, the present invention has the following advantages:
[0227] 1. Technical effects:
[0228] (1) Improve risk scanning efficiency:
[0229] The scan response time has been reduced from 2 seconds to 1 second, an improvement of more than 50%.
[0230] The accuracy of risk identification improved from 85% to 95%, an increase of 10%.
[0231] The system's processing capacity has increased from 40 transactions per second to 160 transactions per second, a fourfold increase.
[0232] (2) Reduce reliance on manual labor:
[0233] The rate of manual intervention decreased from 40-60% to 10-20%, a reduction of 70%.
[0234] The complexity of rule configuration has been reduced by 80%, transforming it from professional development to visual configuration.
[0235] (3) Enhance system availability:
[0236] System availability improved from 95% to over 99.5%;
[0237] Fault recovery time has been reduced from hours to minutes.
[0238] 2. Business Results:
[0239] (1) Reduce operating costs:
[0240] Labor costs reduced by 60%;
[0241] System maintenance costs have been reduced by 40%.
[0242] (2) Enhance compliance capabilities:
[0243] The completeness of the approval records reached 100%;
[0244] Improved traceability of risk management;
[0245] Compliance inspection efficiency improved by 80%.
[0246] 3. Innovation Effects:
[0247] (1) Technological innovation:
[0248] The first risk scanning mechanism to achieve multi-source data fusion;
[0249] Pioneering real-time / batch dual-mode scanning technology;
[0250] Record risk snapshots and traceability technologies.
[0251] (2) Architectural innovation:
[0252] Microservice architecture design, supporting horizontal scaling;
[0253] Distributed design enhances the system's high availability.
[0254] (3) Application Innovation:
[0255] Visual rule configuration lowers the technical barrier;
[0256] Intelligent risk identification improves identification accuracy;
[0257] Multi-dimensional data analysis supports decision optimization.
[0258] The above are merely preferred embodiments of the present invention and do not constitute any limitation on the present invention. Any equivalent substitutions or modifications made by those skilled in the art to the technical solutions and content disclosed in the present invention without departing from the scope of the present invention shall be deemed to have remained within the protection scope of the present invention.
Claims
1. An enterprise-level risk bottom-line control system, characterized in that, Includes the following modules: Control and execution information aggregation module: configured to implement a multi-level approval workflow engine; Multi-dimensional statistical analysis module: configured to enable multi-dimensional visualization analysis of risk data; Rule management module: Configured to build a dynamically configurable rule engine; Risk bottom line scanning module: configured to enable real-time and batch dual-mode scanning of customer risk profiles; List Management Module: Configured to achieve automated hierarchical control of blacklists and graylists; Approval Process Module: Configured to enable fully digital approval for special cases and list transfers; Multiple modules work together to manage enterprise-level risk bottom lines.
2. The enterprise-level risk bottom-line control system as described in claim 1, characterized in that, The control and execution information aggregation module is also used to aggregate control and execution information; The multi-dimensional statistical analysis module analyzes dimensions including: institutional dimension, risk level dimension, reason for inclusion in the list dimension, and comprehensive statistical charts of control status. The rule management module includes a rule base and a manual rule maintenance unit; The risk bottom line scanning module includes: manual scanning, online scanning, batch scanning, and risk bottom line scanning results. The risk bottom line scanning results include risk snapshots, ledgers, and logs. The list management module includes: list database, list system processing, and manual list maintenance; The approval process module includes: regular application review process, differentiated access results, reconsideration application review process, and special case business supplementary review process. The regular application review process includes branch application, branch review, and head office review. Differentiated access results include: special case business records, list adjustment records, ledgers, and logs. The reconsideration application review process includes: branch application, branch review, head office review, and final review by the head office risk manager. The special case business supplementary review process includes: branch application and branch review.
3. An enterprise-level risk bottom-line management method, characterized in that, The control method based on the enterprise-level risk bottom-line control system as described in any one of claims 1-2 includes the following steps: Risk scan request processing; Internal and external data integration; Risk rule matching; Risk classification and handling; Results processing and feedback.
4. The enterprise-level risk bottom-line management method as described in claim 3, characterized in that, Risk scan request processing includes the following steps: S1: Receive a risk scan request; the request includes basic customer information, scan type, and scan range; S2: Verify the parameters of the request; the verification includes mandatory field checking, format validation, and business rule validation; S3: Determine the scanning strategy; the scanning strategy acquires data based on customer type and scanning type.
5. The enterprise-level risk bottom-line control method as described in claim 4, characterized in that, Internal and external data integration includes the following steps: S4: Invoke local data services; the services include enterprise customer information query and enterprise business status query; S5: Call an external data platform; the data provided by the external data platform includes credit information and risk data; S6: Integrate internal and external data; the integration methods include data cleaning, format conversion and data merging.
6. The enterprise-level risk bottom-line management method as described in claim 5, characterized in that, Risk rule matching includes the following steps: S7: Determine the applicable risk rules; the rules are dynamically selected based on customer type and business scenario; S8: Execute rule matching logic; the rule matching logic includes condition judgment and level classification; S9: Determine the risk level; the level includes Black, Gray I, Gray II, Alert, and Normal.
7. The enterprise-level risk bottom-line management method as described in claim 6, characterized in that, Risk classification and processing includes the following steps: S10: Determine the list type based on the risk level; the list type includes blacklists / greylists and whitelists; S11: Generate risk scan results; the risk scan results include risk level and control recommendations; S12: Record a risk snapshot; the risk snapshot includes the scan time, risk status, and historical records.
8. The enterprise-level risk bottom-line control method as described in claim 7, characterized in that, Results processing and feedback include the following steps: S13: Generate a scan report; the scan report includes customer information, risk analysis, and control recommendations; S14: Trigger control measures; the control measures are executed automatically according to the risk level. S15: Notify the corresponding management system; the notification content includes scan results, risk changes, and business impact; S16: Update business status; the update includes customer status, business status and system status.