A pharmaceutical enterprise quality risk assessment method, device, equipment and medium

CN122549907APending Publication Date: 2026-08-11CROSS STRAIT TSINGHUA RESEARCH INSTITUTE
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-09
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

其主要目的在于解决现有技术方案难以动态、精准地识别和应对药品生产及经营企业潜在的、动态变化的质量风险等问题

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122549907A_ABST
    Figure CN122549907A_ABST
Patent Text Reader

Abstract

This disclosure provides a method, apparatus, equipment, medium, and program product for quality risk assessment of pharmaceutical companies, relating to the field of computer technology. The method includes: acquiring multi-source real-world data of the target pharmaceutical company; quantitatively scoring the multi-source real-world data based on a preset risk assessment indicator system to obtain indicator scores for the target pharmaceutical company in inherent risk and compliance risk dimensions, wherein the preset risk assessment indicator system includes multiple levels of risk indicators with preset weights; determining the sub-item scores and comprehensive risk score for the target pharmaceutical company in inherent risk and compliance risk dimensions based on the indicator scores; and generating a risk profile of the target pharmaceutical company based on the comprehensive risk score and sub-item scores, the risk profile including risk level and risk label. By integrating multi-source data, constructing an indicator system, and generating a risk profile, quantitative assessment and precise supervision of pharmaceutical company quality risks can be achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of intelligent drug supervision and risk management technology, and in particular to a method, device, equipment and medium for quality risk assessment of pharmaceutical companies. Background Technology

[0002] Drug safety is directly related to public health, and implementing risk-based precision inspections is a core strategy for improving regulatory effectiveness. With the increasing complexity of drug production and distribution activities, the drug regulatory model is shifting from the traditional "passive response and post-event investigation" to a "proactive, risk-based" approach. Currently, although relevant regulations explicitly require risk-based inspection plans, in practice, they still mainly rely on the historical experience of regulatory personnel, limited information from complaints and reports, and relatively fixed inspection cycles. This approach struggles to dynamically and accurately identify and address the potential and dynamically changing quality risks of drug manufacturers and distributors, leading to a mismatch between regulatory resource allocation and actual risk conditions, thus affecting the overall effectiveness and efficiency of regulation. The root cause lies in the lack of a systematic technical solution that can effectively integrate multi-source, heterogeneous regulatory data and conduct scientific quantitative assessments.

[0003] Therefore, it is urgent to build a complete technical system for drug quality risk assessment and break through the technical bottlenecks in areas such as regulatory knowledge transformation, multi-source data fusion, interpretable rule engine, and dynamic iteration. Summary of the Invention

[0004] This disclosure provides a method, apparatus, equipment, and medium for quality risk assessment in pharmaceutical companies. Its main purpose is to address the limitations of existing technologies in dynamically and accurately identifying and responding to potential, dynamically changing quality risks in pharmaceutical manufacturing and distribution companies.

[0005] According to a first aspect of this disclosure, a method for quality risk assessment in pharmaceutical companies is provided, comprising:

[0006] Obtain multi-source real-world data of the target pharmaceutical company, including basic company information data, compliance history data, testing data, and monitoring data; Based on a preset risk assessment index system, the multi-source real-world data is quantitatively scored to obtain the target pharmaceutical company's index scores in the inherent risk dimension and compliance risk dimension. The preset risk assessment index system includes multiple levels of risk indicators with preset weights. Based on the scores of the aforementioned indicators, the sub-scores and comprehensive risk score of the target pharmaceutical company in the inherent risk dimension and compliance risk dimension are determined; Based on the comprehensive risk score and the sub-scores, a risk profile of the target pharmaceutical company is generated, which includes a risk level and a risk label.

[0007] Preferably, the quantitative scoring of the multi-source real-world data based on a preset risk assessment index system includes: Based on a preset rule engine, the multi-source real-world data is matched with multiple tertiary indicators in the risk assessment indicator system; Based on the matching results, determine the indicator score corresponding to each third-level indicator.

[0008] Preferably, it further includes: Obtain updated regulatory documents; The updated regulatory documents are compared and analyzed with the current mainline documents using a large language model to generate rule base update suggestions; In response to the received confirmation instruction, the rules in the rule engine are updated according to the rule base update suggestion.

[0009] Preferably, determining the target pharmaceutical company's sub-scores and comprehensive risk score in the inherent risk dimension and compliance risk dimension based on the index scores includes: The initial risk score is obtained by weighted summation of the scores of multiple indicators under the aforementioned compliance risk dimension. Based on the enterprise type or business scope in the enterprise basic information data, the inherent risk coefficient of the target pharmaceutical enterprise is determined. The inherent risk coefficient is used to characterize the basic risk level of the inherent risk dimension. The inherent risk coefficient is added to the initial risk score to obtain the comprehensive risk score.

[0010] Preferably, after generating the risk profile of the target pharmaceutical company based on the comprehensive risk score, the method further includes: A risk ranking list is generated based on the comprehensive risk scores of multiple target pharmaceutical companies. Based on the risk ranking list and preset inspection resource information, a differentiated annual inspection plan is generated.

[0011] Preferably, it further includes: In response to receiving a query request for a specific risk point in the risk profile, a semantic search is performed in a preset regulatory vector knowledge base to obtain relevant regulatory clauses; The relevant legal provisions are understood and organized using a large language model, and legal interpretation information is generated and output in response to the query request.

[0012] Preferably, it further includes: Obtain historical multi-source real-world data of the target pharmaceutical company; Based on the aforementioned historical multi-source real-world data and the aforementioned preset risk assessment indicator system, the historical comprehensive risk score of the target pharmaceutical company in multiple historical regulatory cycles is determined; Based on historical comprehensive risk scores over multiple historical regulatory cycles, risk trend information is generated for the target pharmaceutical company, which is used to indicate the trajectory of risk changes for the target pharmaceutical company.

[0013] According to a second aspect of this disclosure, a pharmaceutical enterprise quality risk assessment device is provided, comprising: The data acquisition unit is used to acquire multi-source real-world data of the target pharmaceutical company, including basic information data of the company, compliance history data, inspection data and monitoring data. The quantitative scoring unit is used to quantitatively score the multi-source real-world data based on a preset risk assessment indicator system, and obtain the indicator scores of the target pharmaceutical company in the inherent risk dimension and compliance risk dimension. The preset risk assessment indicator system includes multiple levels of risk indicators with preset weights. The comprehensive scoring unit is used to determine the target pharmaceutical company's sub-scores and comprehensive risk score in the inherent risk dimension and compliance risk dimension based on the index scores. The risk profile generation unit is used to generate a risk profile of the target pharmaceutical company based on the comprehensive risk score and the sub-item scores. The risk profile includes a risk level and a risk label.

[0014] According to a third aspect of this disclosure, an electronic device is provided, comprising: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method described in the first aspect above.

[0015] According to a fourth aspect of this disclosure, a non-transitory computer-readable storage medium is provided storing computer instructions, wherein the computer instructions are configured to cause the computer to perform the method described in the first aspect above.

[0016] According to a fifth aspect of this disclosure, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the method described in the first aspect above.

[0017] In the embodiments provided in this disclosure, by integrating multi-source real-world data such as basic enterprise information, compliance history, inspection data, and monitoring data, and using the unified social credit code as the core index for integrated governance, the "data silos" in traditional supervision are broken down. Dispersed risk clues are transformed into quantifiable and traceable structured data assets, providing objective and comprehensive data support for regulatory decisions. A hierarchical system covering two dimensions—inherent risk and compliance risk—is constructed and subdivided into three levels of operable indicators. Through consistency verification, and by setting differentiated indicator frameworks for production enterprises and operating enterprises, the scientificity, reliability, and industry adaptability of the assessment are ensured. A rule engine is used as the core decision-making brain. When an enterprise is determined to be high-risk, regulatory personnel can directly trace back to the specific triggering rules, clearly understand the source of the risk, and greatly enhance the credibility and acceptability of regulatory decisions. Based on the comprehensive risk score, an enterprise risk ranking list is generated. Combined with the statutory inspection frequency requirements and the total annual inspection resources, differentiated inspection plans are intelligently generated, accurately allocating limited regulatory resources to high-risk enterprises, achieving optimal matching of resources and risks, and significantly improving regulatory efficiency. By using a large language model to intelligently compare and analyze old and new regulatory documents, it can automatically identify clause changes and generate update suggestions, and has a dynamic rule base maintenance mechanism.

[0018] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0019] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein: Figure 1 This is a flowchart illustrating a method for assessing quality risks in pharmaceutical companies, as provided in an embodiment of this disclosure. Figure 2 This is a flowchart illustrating another pharmaceutical enterprise quality risk assessment method provided in this embodiment of the disclosure; Figure 3 This is a logic diagram for determining risk levels. Figure 4 This is a schematic diagram of a pharmaceutical enterprise quality risk assessment device provided in an embodiment of this disclosure. Detailed Implementation

[0020] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0021] The following description, with reference to the accompanying drawings, outlines a method, apparatus, equipment medium, and program product for quality risk assessment in pharmaceutical companies, according to embodiments of this disclosure.

[0022] Figure 1 This is a flowchart illustrating a method for assessing quality risks in pharmaceutical companies, as provided in an embodiment of this disclosure. Figure 1 As shown, the method includes the following steps: Step S101: Obtain multi-source real-world data of the target pharmaceutical company. Multi-source real-world data includes basic company information data, compliance history data, testing data, and monitoring data. Step S102: Based on the preset risk assessment indicator system, quantitatively score the multi-source real-world data to obtain the indicator scores of the target pharmaceutical company in the inherent risk dimension and compliance risk dimension; the preset risk assessment indicator system includes multiple levels of risk indicators with preset weights. Step S103: Based on the indicator scores, determine the target pharmaceutical company's sub-scores and comprehensive risk score in the inherent risk dimension and compliance risk dimension; Step S104: Based on the comprehensive risk score and the sub-item scores, generate a risk profile of the target pharmaceutical company. The risk profile includes risk level and risk label.

[0023] Based on the above embodiments, this embodiment will provide a detailed description of step S101: In one embodiment, multi-source real-world data encompasses the sum of various data points that reflect the actual situation of an enterprise. Specifically, this data can originate from multiple aspects of routine regulatory work, such as the enterprise's static qualification information, historical inspection records, product testing results, and post-market safety monitoring information. These diverse data sources and varying structures collectively form the data foundation for a comprehensive risk assessment of the enterprise. Risk dimensions may include, for example, inherent risk dimensions and compliance risk dimensions.

[0024] Based on the above embodiments, this embodiment will provide a detailed description of step S102: In one embodiment, a pre-defined rule engine can be used to match multi-source real-world data with multiple tertiary indicators in a risk assessment indicator system. The rule engine is a software component that separates business decision-making logic from application code and uses predefined semantic modules for writing, management, and execution. It carries the entire chain of logic from data processing and tag generation to risk calculation, and is the core component for automating and standardizing risk assessment. Then, based on the matching results, the score corresponding to each tertiary indicator can be determined. For example, the pre-defined risk assessment indicator system can be a standardized yardstick for measuring enterprise risk, or a structured framework containing multiple levels. This pre-defined risk assessment indicator system can be constructed systematically to ensure the comprehensiveness and scientific rigor of the assessment dimensions. By cleaning and standardizing the acquired massive amounts of heterogeneous data and scoring them against the various dimensions of this system, the enterprise's raw data can be transformed into comparable and calculable quantitative scores.

[0025] Also includes: Obtain updated regulatory documents; The updated regulatory documents are compared and analyzed with the current main documents using a large language model to generate suggestions for updating the rule base. In response to the received confirmation instruction, the rules in the rule engine are updated according to the rule base update suggestions.

[0026] In one embodiment, when new regulations, guidelines, or inspection points are issued, updated regulatory documents can be obtained and imported into the system as "secondary guidelines." This ensures the rule base can promptly acquire the latest regulatory requirements, keeping the risk assessment system up-to-date with changes in the regulatory environment. This prevents assessment results from becoming invalid due to outdated regulations and provides a data input foundation for the rule base's self-evolution. Then, an integrated large language model can be invoked to automatically perform a deep intelligent comparative analysis between the newly imported "secondary guidelines" and the "main guidelines" currently upon which the rule base is based. Through comparison, the large language model can accurately identify changes such as additions, deletions, modifications, and adjustments between old and new regulatory provisions and automatically generate a structured "rule base update suggestion." This rule base update suggestion clearly indicates: the handling of old clauses that need to be repealed and their corresponding rules; the proposed revision schemes for risk indicators or scoring standards for new requirements; and the proposed adjustments to weights and thresholds for clauses whose wording or scale has changed. Subsequently, the generated rule base update suggestions can be pushed to regulatory personnel in the field for final review. Regulatory personnel review each suggestion on the system's interactive interface and make decisions to confirm, modify, or reject it, achieving human-in-the-loop key decision-making participation. After regulatory approval, the system administrator triggers the system to automatically complete operations such as adding, modifying, and disabling rules through the "one-click rule base update" function, and simultaneously completes version management and update records. This constitutes a human-machine collaborative dynamic maintenance and evolution mechanism for the rule base, overcoming the technical bottleneck of static rule bases being unable to adapt to frequent regulatory updates. It realizes the transformation from "manual maintenance and delayed updates" to "intelligent assistance and dynamic evolution," providing technical support for the continuous iterative upgrade of intelligent drug supervision, thereby ensuring that risk-based inspection models are always based on the latest regulations.

[0027] Based on the above embodiments, this embodiment will provide a detailed description of step S103: In one embodiment, the scores of multiple indicators under the compliance risk dimension can be weighted and summed to obtain an initial risk score. For example, the initial risk score is a quantitative assessment of the company's current compliance status, reflecting the risk level calculated based on dynamic data such as actual compliance history, inspection results, and quality and safety incidents within a specific regulatory cycle. The initial risk score can be composed of the sum of the products of each tertiary indicator score and its corresponding weight. A higher initial risk score indicates more and more serious compliance issues currently exposed by the company. The multiple indicator scores refer to the scores of each tertiary indicator under the compliance risk dimension. The initial risk score is obtained by weighting and summing the scores of all tertiary indicators within the compliance risk dimension, reflecting the company's dynamic compliance performance within a specific regulatory cycle. The inherent risk coefficient of the target pharmaceutical company can also be obtained. For example, the inherent risk coefficient is an important structural supplement to risk calculation, used to characterize the basic risk level determined by the company's inherent attributes. The inherent risk coefficient can be set according to the company's attributes and will remain relatively stable when the attributes do not fundamentally change. The inherent risk coefficient is unrelated to the company's dynamic compliance performance but is determined based on the company type or business scope in the company's basic information data. For example, companies that produce sterile preparations typically have a higher inherent risk coefficient than companies that produce ordinary oral preparations; companies whose business scope includes narcotic drugs and Class I psychotropic drugs also have a higher coefficient than companies that only deal in ordinary drugs. Introducing this inherent risk coefficient allows risk assessment models to distinguish between "inherently high-risk companies" and "poorly managed companies," avoiding the conflation of the two.

[0028] Then, the inherent risk coefficient can be added to the initial risk score to obtain the comprehensive risk score. For example, the comprehensive risk score R is the final quantification result of integrating the company's inherent risks and dynamic compliance performance. The calculation formula can be: R = Initial Risk Score + F, where F is the inherent risk coefficient. The comprehensive risk score can comprehensively reflect the overall risk level of a company, considering both the basic risks arising from the company's inherent attributes such as product characteristics and business scope, and the compliance issues exposed in actual operations. The comprehensive risk score will serve as the core basis for subsequent risk classification, risk profile generation, and inspection plan formulation. The higher the comprehensive risk score, the greater the overall risk of the company, and the more priority should be given to allocating regulatory resources. Specifically, after obtaining the scores for each risk dimension, a comprehensive calculation is needed to obtain a value that can represent the overall risk level of the company. For example, the scores of each dimension can be weighted and summed to obtain a comprehensive risk score; the higher the score, the greater the risk of the company. This comprehensive score will serve as the core basis for subsequent risk classification and regulatory decisions.

[0029] Understandably, the inherent risk coefficient is not included in the weighted summation calculation, but rather serves as an independent additive term to characterize the static basic risk level determined by the company's inherent attributes. The inherent risk coefficient is directly determined based on the company type or business scope.

[0030] Based on the above embodiments, this embodiment will provide a detailed description of step S104: In one embodiment, a risk profile can be a visualized and structured description of a company's risk status. It can include not only the risk level (e.g., high, medium, low) corresponding to a calculated comprehensive risk score, but also a series of labels describing the company's specific risk characteristics. Through risk profiles, regulators can quickly and comprehensively understand the overall risk profile of a company, including its overall risk level and the specific sources and characteristics of those risks.

[0031] Also includes: A risk ranking list is generated based on the comprehensive risk scores of multiple target pharmaceutical companies. Based on the risk ranking list and preset inspection resource information, generate differentiated annual inspection plans.

[0032] In one embodiment, after completing the batch risk assessment task, all target pharmaceutical companies can be automatically sorted (e.g., ascending or descending) according to their comprehensive risk score R, generating a risk ranking list. This list supports dynamic visualization by multiple dimensions such as region and company type, enabling regulatory agencies to intuitively and quickly grasp the risk clustering situation and accurately identify regions and company clusters requiring key attention. Then, a differentiated annual inspection plan can be generated by combining the risk ranking list, the preset total annual inspection resources, and statutory inspection frequency requirements. Statutory inspection frequency requirements may include: manufacturers of narcotic drugs, Class I psychotropic drugs, and pharmaceutical precursor chemicals must undergo at least one inspection per quarter; manufacturers of high-risk pharmaceuticals such as vaccines, blood products, radioactive drugs, medical toxic drugs, and sterile drugs should undergo at least one GMP compliance inspection per year; companies dealing in refrigerated and frozen pharmaceuticals, blood products, cell therapy biological products, Class II psychotropic drugs, and medical toxic drugs should undergo at least one inspection per year; other companies will be inspected on a random basis annually, ensuring full coverage within the administrative region within three years. The system can intelligently allocate inspection resources based on a company's risk level: prioritizing on-site inspections and appropriately increasing the frequency for high-risk companies, conducting inspections on medium-risk companies according to standard cycles, and using routine inspections or remote supervision for low-risk companies. This risk-based intelligent inspection plan generation mechanism can improve the overall effectiveness and efficiency of supervision.

[0033] Also includes: In response to receiving a query request for a specific risk point in the risk profile, semantic retrieval is performed in the preset regulatory vector knowledge base to obtain relevant regulatory clauses; The system utilizes a large language model to understand and organize relevant legal provisions, generating and outputting legal interpretation information for query requests.

[0034] In one embodiment, when regulatory personnel review a company's risk profile page, they can input a query request for specific risk points identified (such as "records of exceeding storage temperature limits," "frequent changes in key personnel," and "high rate of non-compliance in spot checks"). For example, they can directly input a natural language query request in the interactive chat box embedded in the page, such as "Can narcotic drugs be entrusted for storage and transportation?". Upon receiving a query request for a specific risk point in the risk profile, the system can trigger a background intelligent processing mechanism. For example, the query request text is first converted into a high-dimensional vector using embedding technology, and then efficiently retrieved and matched semantically in real-time using a pre-defined regulatory vector knowledge base to obtain the most relevant regulatory clauses. After retrieving relevant regulatory clauses from the regulatory vector knowledge base, a large language model can perform in-depth understanding, synthesis, and organization of the retrieved information. For example, the large language model can combine the specific context implied in the query request (such as company type, nature of the risk point, and product category) to perform applicability analysis on the retrieved regulatory clauses, generating and outputting structured regulatory interpretation information. As an example, the output of regulatory interpretation information may include: directly providing the original text of the relevant regulatory provisions and their precise source (regulation name, clause number, issuing authority, status of validity, etc.); briefly explaining the applicability of the clause in conjunction with the question context, explaining the specific meaning and applicable conditions of the clause in the current regulatory scenario; and, if necessary, providing principled references for the scope of penalty discretion to provide enforcement basis for regulatory decisions, etc.

[0035] Also includes: Obtain historical, multi-source, real-world data from the target pharmaceutical company; Based on historical multi-source real-world data and a pre-set risk assessment indicator system, the historical comprehensive risk score of the target pharmaceutical company in multiple historical regulatory cycles is determined. Based on historical comprehensive risk scores over multiple historical regulatory cycles, risk trend information for the target pharmaceutical company is generated. This risk trend information is used to indicate the trajectory of risk changes for the target pharmaceutical company.

[0036] In one embodiment, historical multi-source real-world data of the target pharmaceutical company can be periodically acquired over multiple historical regulatory cycles (such as the past three years). This data includes four interconnected key dimensions: basic enterprise information, compliance history data, testing data, and monitoring data. Basic enterprise information primarily includes registration information such as company name, address, scope of license, scale information, and qualifications of key personnel. Compliance history data systematically aggregates deficiencies discovered during various inspections, on-site inspection reports, rectification plans and reports, and administrative penalty information. Testing data includes sample names, batch numbers, testing items, testing conclusions, and detailed testing data for non-compliant items. Monitoring data mainly includes adverse drug reaction monitoring reports, complaint and reporting information, and public opinion information. This data can be integrated and managed using the company's unified social credit code as the core index to ensure the continuity, integrity, and traceability of historical data.

[0037] For each historical regulatory cycle, the risk assessment process can be repeated, including: based on a pre-set risk assessment indicator system (covering two dimensions—inherent risk and compliance risk—and multiple levels of risk indicators with pre-set weights), using a rule engine to quantify and score historical multi-source real-world data, obtaining indicator scores for multiple risk dimensions within each historical cycle; weighted summing of the indicator scores to obtain an initial risk score, and then adding an inherent risk coefficient to obtain a historical comprehensive risk score for each historical regulatory cycle. Subsequently, based on the historical comprehensive risk scores from multiple historical regulatory cycles, risk trend information for the target pharmaceutical company can be generated, for example, visually displaying the trajectory of risk score changes over time in a line graph. Risk trend information can indicate whether the company's risk is stabilizing, rising, or declining: a continuously rising score indicates a deterioration in the company's compliance status and risk accumulation, requiring stronger regulatory intervention; a continuously declining score indicates improved quality management and risk mitigation, allowing for appropriate adjustments to regulatory intensity; large score fluctuations indicate insufficient stability in the company's quality management system, requiring attention to changes in key elements and internal management issues; a consistently high score indicates systemic compliance deficiencies, requiring fundamental corrective measures.

[0038] This embodiment provides a method for assessing the quality risks of pharmaceutical companies. By integrating multi-source real-world data, including basic enterprise information, compliance history, testing data, and monitoring data, and using the unified social credit code as the core index for integrated governance, it breaks down the "data silos" in traditional supervision. It transforms scattered risk clues into quantifiable and traceable structured data assets, providing objective and comprehensive data support for regulatory decisions. A hierarchical system is constructed, encompassing both inherent and compliance risks, and further subdivided into three levels of operational indicators. Consistency testing is performed, and differentiated indicator frameworks are set for manufacturing and operating enterprises to ensure the scientific rigor, reliability, and industry suitability of the assessment. A rule engine serves as the core decision-making engine. When an enterprise is determined to be high-risk, regulators can directly trace back to the specific triggering rules, clearly understanding the source of the risk and greatly enhancing the credibility and acceptability of regulatory decisions. Based on a comprehensive risk score, a risk ranking list of enterprises is generated. Combined with statutory inspection frequency requirements and the total annual inspection resources, a differentiated inspection plan is intelligently generated, precisely allocating limited regulatory resources to high-risk enterprises, achieving optimal matching of resources and risks, and significantly improving regulatory efficiency. By using a large language model to intelligently compare and analyze old and new regulatory documents, it can automatically identify clause changes and generate update suggestions, and has a dynamic rule base maintenance mechanism.

[0039] Based on the above embodiments and combined with actual business scenarios in the field of drug regulation, this embodiment further describes a method for quality risk assessment of pharmaceutical companies, as follows: Step S201: Obtain multi-source real-world data of the target pharmaceutical company, and perform data fusion and governance using the company's unified social credit code as the core index; Specifically, real-world data refers to the sum of all types of data generated or collected continuously in the entire lifecycle of drug regulatory activities, based on routine workflows and under natural practical conditions, that can reflect the actual situation and behavioral trajectory of the regulated entities. Multi-source real-world data can be achieved by integrating data from multiple independent regulatory business systems, and this data covers four interrelated key dimensions: Basic enterprise information data: obtained from the drug administration licensing system, mainly including enterprise name, address, scope of license, scale information (such as registered capital and number of employees), and registration information such as the qualifications of key personnel. This data forms the basis for static qualification assessment and dynamic operational monitoring of the enterprise.

[0040] Compliance history data: Obtained from the drug administration enforcement system, this system systematically compiles deficiencies discovered during various inspections, on-site inspection reports, rectification plans and reports submitted by enterprises, and related administrative penalty information. Continuous tracking of these historical records allows for the assessment of the operational stability and ongoing compliance capabilities of the enterprise's quality management system.

[0041] Test data: Obtained from the drug testing system, this data includes basic fields such as sample name, batch number, test items, and test results, as well as detailed test data on non-compliant items and relevant expert opinions. This data provides objective technical evidence for regulatory oversight.

[0042] Monitoring data: Obtained from adverse drug reaction monitoring systems, complaint and reporting platforms, and public opinion monitoring systems. This primarily includes adverse drug reaction monitoring reports, complaint and reporting information from medical institutions, consumers, and other channels, as well as public opinion information related to the company or product in the public media. This type of data directly reflects the safety performance of drugs in real-world usage environments and is a key signal source for the early detection of potential safety risks.

[0043] The system uses the unified social credit code of enterprises as the core index to integrate and manage these data from different sources and with different standards. It strives to break down the "data silos" that exist in the traditional regulatory model, and integrates scattered risk clues into a continuous and three-dimensional enterprise data view, providing a high-quality data foundation for subsequent analysis.

[0044] Step S202: Based on the preset rule engine, match the multi-source real-world data with the three-level indicators in the risk assessment indicator system, and determine the indicator score corresponding to each three-level indicator based on the matching results. First, the pre-designed risk assessment indicator system is a multi-level indicator system constructed using a systematic approach. Specifically, the construction process of this system includes: Preliminary construction of the indicator system: For pharmaceutical manufacturers, in accordance with requirements, an indicator system encompassing both inherent and compliance risks can be preliminarily constructed by integrating attributes such as drug type, dosage form, and regulatory category, along with relevant drug safety information, risk warnings, major events, and multi-source data including past inspections, tests, adverse reactions, and complaints. This system can be built by combining these factors with multi-source data such as past inspections, tests, adverse reactions, and complaints. See Table 1 for details. Table 1: Quality Risk Indicator System for Pharmaceutical Manufacturers

[0045] For pharmaceutical companies, based on Articles 59 and 60 of the "Measures for the Supervision and Management of the Quality of Pharmaceutical Distribution and Use," and combined with pharmaceutical distribution supervision practices, an indicator system encompassing both inherent risks and compliance risks has been constructed. Details are shown in Table 2. Table 2: Quality Risk Indicator System for Pharmaceutical Distribution Enterprises

[0046] Determining the weights of the indicator system: The weights in this system are not subjectively set, but determined comprehensively through the Analytic Hierarchy Process (AHP) combined with multiple rounds of Delphi expert consultation. Experts compare and score the relative importance of indicators at the same level pairwise, and calculate the weight of each indicator accordingly. The consistency ratio (CR) of all judgment matrices is less than 0.1, passing the consistency test, indicating that the indicator system has good logical consistency and scientific validity. The Analytic Hierarchy Process (AHP) is a systematic analysis method that expresses and processes subjective judgments in quantitative form. By decomposing complex problems into several levels and factors, it compares and scores indicators at the same level pairwise, and calculates the weight of each indicator accordingly. It is suitable for multi-factor weight ranking and decision-making.

[0047] The Delphi method is a structured approach that collects and integrates expert opinions through a multi-round anonymous questionnaire survey system. Its core characteristic is that experts do not communicate with each other and independently offer their insights; the organizer summarizes and provides feedback in each round, prompting expert opinions to gradually converge through multiple iterations, ultimately forming a consensus. This study uses the Delphi method to validate a preliminary quality risk indicator system for pharmaceutical companies. The expert consultation for indicator validation focused on the rationality, necessity, and scientific validity of the indicator settings, inviting 20 experts from drug regulatory departments, inspection agencies, testing institutions, and production / distribution companies to participate. Among them, 85% of the experts had more than 10 years of experience in the pharmaceutical industry, and 75% were experts from the drug regulatory system (see Table 3 for details).

[0048] Table 3. Basic Information of Experts Consulting on Indicator Demonstration

[0049] The Consistency Ratio (CR) is an indicator used to measure the logical consistency of a judgment matrix. When CR < 0.1, it indicates that experts have good consistency in their judgments of the relative importance of the indicators, and the weight allocation results are reliable. If CR ≥ 0.1, it indicates that there is a logical contradiction in the judgments, and readjustment is required.

[0050] The final weights of the quality risk indicators for pharmaceutical manufacturers are shown in Table 4: Table 4: Weights of Quality Risk Indicators for Pharmaceutical Manufacturers

[0051] The final weights of the quality risk indicators for pharmaceutical companies are shown in Table 5: Table 5: Weights and Scores of Quality Risk Indicators for Pharmaceutical Companies

[0052] To ensure the transparency and traceability of weight determination, the following table shows the pairwise comparison judgment matrices of each level of indicators and their consistency test results for the judgment matrix data. 1. Pharmaceutical Manufacturer Judgment Matrix: Table 6. Matrix of Primary Indicators for Quality Risk Judgment of Pharmaceutical Manufacturers

[0053] Table 7 Inherent Risk Judgment Matrix

[0054] Table 8 Compliance Risk Assessment Matrix

[0055] Table 9 Variety Information Judgment Matrix

[0056] Note: For details of the specific items abcdefghi, please refer to Table 2. Table 10 Production Scale Judgment Matrix

[0057] Table 11 Judgment Matrix of Inspection Results

[0058] Table 12 Key Element Change Judgment Matrix

[0059] Table 13 GMP System Risk Assessment Matrix

[0060] Table 14 Quality and Safety Incident Judgment Matrix

[0061] 2. Judgment Matrix for Pharmaceutical Companies: Table 15 Matrix for Judging Primary Indicators of Quality Risk in Pharmaceutical Enterprises

[0062] Table 16 Inherent Risk Judgment Matrix

[0063] Table 17 Compliance Risk Assessment Matrix

[0064] Table 18 Business Performance Judgment Matrix

[0065] Table 19 Warehouse Status Judgment Matrix

[0066] Table 20: Judgment Matrix Based on the Time of the Last Supervision and Inspection

[0067] Table 21 Matrix for Judging Potential Violations

[0068] Table 22 Matrix for Judging Potential Illegal Activities

[0069] Note: For details of specific items, please refer to Table 2. Table 23 Key Element Change Judgment Matrix

[0070] Rule-based indicator matching and score calculation: The rule engine, as the core decision-making brain of the system, is pre-configured with structured business rules. Rules are expressed in a structured format: "IF <condition> THEN <conclusion / action>". The rule base is designed as an organic whole with a clear hierarchical structure and execution order, sequentially executing data preprocessing rules, indicator calculation rules, label generation rules, and comprehensive calculation and hierarchical rules.

[0071] For example, for pharmaceutical manufacturers, the rules configured in the system include, but are not limited to: Rule 1 (Inherent Risk - Formulation Type): If the company's production scope includes "sterile formulations," then the "sterile formulations" score s_i = 37.00. Rule 2 (Compliance Risk - Inspection Results): If there is an administrative penalty record for "providing false materials or promises" within the past 12 months, then the indicator "providing false materials or promises" score s_i = 18.00, and the tag "deceptive behavior exists". Rule 3 (Compliance Risk - Sampling Inspection Situation): IF: Number of non-compliance inspections in the past 12 months >= 2 THEN: "Sampling Inspection Situation" score s_i = 7.00 AND Add the tag "High Non-Compliance Rate" Rule 4 (Compliance Risk - Complaints and Reports): If the number of valid complaints and reports received in the past 6 months is >= 3, then the "Complaints and Reports" score s_i = 10.00, and the tag "Abnormal Complaint Frequency" is added. For pharmaceutical companies, the rules configured in the system include, but are not limited to: Rule 5 (Inherent Risk - Warehouse Situation): IF The company has "cross-province warehousing" THEN The "cross-province warehousing" score s_i = 12.00 AND Add the tag "involves cross-province warehousing" Rule 6 (Compliance Risk - Key Element Changes): IF Number of changes in "Enterprise's Principal Responsible Person" >= 2 in the past 12 months THEN "Changes in Enterprise's Principal Responsible Person" score s_i = 4.00 AND Add the tag "Frequent Changes in Key Personnel" Rule 7 (Compliance Risk - Violations): If a deficiency is found in "Cold Chain Verification" during surveillance inspection, then the "Cold Chain and Verification" score s_i = 5.00, and the tag "Cold Chain Management in Question" is added. By executing the above rules, the system will accurately match the data obtained from the fused S201 step with the three-level indicators, completing the transformation from raw data to indicator scores.

[0072] Step S203: Calculate the weighted sum of the scores of multiple indicators to obtain the initial risk score; The system calculates based on the score of each tertiary indicator determined in step S202 and the corresponding weight in Table 3 or Table 4.

[0073] Step S204: Obtain the inherent risk coefficient of the target pharmaceutical company, and add the inherent risk coefficient to the initial risk score to obtain the comprehensive risk score; The inherent risk coefficient is an important structural supplement to risk calculation, used to characterize the basic risk level determined by the inherent attributes of a company. For example, a company that produces sterile preparations typically has a higher inherent risk coefficient than a company that produces ordinary oral preparations; a company whose business scope includes narcotic drugs also has a higher coefficient than a company that only deals in ordinary pharmaceuticals. Once this coefficient is set according to the company's attributes, it will remain relatively stable unless the attributes undergo fundamental changes.

[0074] The system adds the initial risk score calculated in step S203 to the inherent risk coefficient F to obtain the final comprehensive risk score R.

[0075] Step S205: Generate a risk profile of the target pharmaceutical company based on the comprehensive risk score; The risk profile includes a comprehensive risk level and multiple detailed business attribute tags.

[0076] Determining the overall risk level: The system determines the enterprise's risk level based on a pre-defined threshold range. For the R value calculated through S204, a three-part division method is used: enterprises ranking in the top 1 / 3 of the inherent risk indicator and compliance risk indicator scores are identified as high-risk enterprises; those ranking in the middle 1 / 3 are identified as medium-risk enterprises; and those ranking in the bottom 1 / 3 are identified as low-risk enterprises.

[0077] Based on this, the final overall risk level is determined according to a comprehensive assessment rule that prioritizes compliance risk. The specific assessment logic is as follows: Figure 3 As shown.

[0078] In the weighting study, most experts believed that compliance risk was more important than inherent risk. Therefore, this study primarily assessed enterprise risk levels based on compliance risk. When the compliance risk level was greater than or equal to the inherent risk level, the overall risk was calculated according to the compliance risk level; when the compliance risk level was less than the inherent risk level, the overall risk was calculated by increasing the compliance risk level by one level.

[0079] Generate risk labels: At the same time, based on the labels attached when executing the rules in step S202, the system will also dynamically generate refined risk characteristic labels such as "recent serious administrative penalty records", "frequent changes in key personnel", "involving high-risk links in cold chain storage and transportation", and "high rate of non-compliance in spot checks".

[0080] Step S206: Based on the comprehensive risk scores of multiple target pharmaceutical companies, generate a risk ranking list and intelligently generate differentiated annual inspection plans; After each batch scoring task is completed, the system automatically generates a "Corporate Risk Ranking" sorted in descending order of total risk score. This ranking supports dynamic visualization by multiple dimensions such as region and enterprise type, enabling provincial regulatory agencies to intuitively and quickly grasp the risk clustering situation and accurately identify regions and enterprise clusters that require key attention.

[0081] Simultaneously, the system automatically generates a structured "Enterprise Risk Profile Report" for each company. The report covers basic enterprise information, detailed scores for various risk indicators, assigned risk labels, total risk score and level determination, in-depth analysis of key risk points, and targeted regulatory recommendations.

[0082] Finally, the system intelligently generates a differentiated draft annual inspection plan by combining the preset total annual inspection resources and statutory inspection frequency requirements (for example, manufacturers of narcotic drugs and Class I psychotropic drugs must undergo inspection at least once per quarter; manufacturers of high-risk drugs such as vaccines and blood products must undergo GMP compliance inspection at least once per year). This plan explicitly recommends allocating more regulatory resources to high-risk enterprises, while low-risk enterprises can be subject to routine inspections or remote supervision, thus shifting from a "widespread" approach to regulation to a "precisely targeted" risk control model.

[0083] Step S207: In response to receiving a query request for a specific risk point in the risk profile, perform semantic retrieval in the preset regulatory vector knowledge base and generate regulatory interpretation information using a large language model; When regulators review a company's profile details page and have questions about a particular risk (such as "records of exceeding storage temperature limits"), they can directly enter a natural language question in the interactive chat box embedded on the page, such as: "Can narcotic drugs be entrusted to storage and transportation?".

[0084] The system then triggered a background intelligent processing mechanism. The core backend of the question-answering robot was connected to a finely tuned large language model, which was deeply coupled with a localized, structured legal knowledge base specifically built for this project.

[0085] The regulatory vector knowledge base is a semantic retrieval knowledge base built using text vectorization technology. The construction process of the regulatory vector knowledge base is as follows: Document preprocessing: First, the formats of laws and regulations such as the "Drug Administration Law", "Good Manufacturing Practice for Pharmaceuticals (2010 Revision)" and "Good Distribution Practice for Pharmaceuticals" are converted and cleaned. PDF, scanned images and other formats are uniformly converted into plain text with UTF-8 encoding, and page numbers, irrelevant line breaks and other noise information are removed.

[0086] Text standardization: Standardize terminology by unifying different expressions such as "GMP" and "Good Manufacturing Practice for Pharmaceuticals" into the standard term "Good Manufacturing Practice for Pharmaceuticals (GMP)"; at the same time, perform citation parsing to identify citations to other regulations in the text.

[0087] Semantic chunking: Using "articles" or "clauses" in legal text as the main chunking boundaries, further subdividing longer clauses, and setting overlapping areas of a specific length between adjacent text chunks to avoid information breaks.

[0088] Vectorization and Metadata Appending: The processed text blocks are transformed into high-dimensional vectors using embedding technology, and structured metadata is appended to each text block, including the source regulation name, issuing authority, issuance date, validity status, chapter title, and clause number, constructing a semantically searchable regulatory vector knowledge base. Embedding technology is a technique that maps discrete text data to a continuous vector space. Through a deep learning model, each text block is transformed into a fixed-length numerical vector, making semantically similar texts closer in the vector space, thereby enabling retrieval based on semantic similarity.

[0089] When a user asks a question, the system first performs efficient real-time retrieval and semantic matching in its local knowledge base. Then, a large language model deeply understands, synthesizes, and organizes the retrieved information. Finally, the system can return an accurate response to regulators within a short time, providing not only the original text and source of the relevant regulations, but also a brief explanation of the applicability of the provisions in the context of the question, and a principled reference for the range of penalties.

[0090] Vectorization (Embedding) refers to the technical process of converting textual data into high-dimensional numerical vectors that computers can understand. Through vectorization, each piece of regulatory text is mapped to a point in a vector space, and semantically similar texts are closer together in the vector space. After the regulatory vector knowledge base is built, when regulators input a query question, the system first vectorizes the question text, then performs a similarity search in the vector knowledge base to find the regulatory clauses most semantically relevant to the question, and finally, a large language model understands, synthesizes, and organizes the search results to generate accurate regulatory interpretation information.

[0091] Step S208: Obtain updated regulatory documents, perform comparative analysis using a large language model, generate rule base update suggestions, and update the rules in the rule engine after confirmation; To cope with the continuous updates of regulations and policies, this system is designed with a human-machine collaborative mechanism for the dynamic maintenance and evolution of the rule base. When national or provincial drug regulatory authorities issue new regulations, guidelines, or inspection points, the system administrator can import the new documents as "sub-files" into the system.

[0092] The system then invokes the integrated large language model to automatically perform a deep intelligent comparative analysis with the "main documents" upon which the rule base is currently based (such as the "Drug Administration Law" and the "Drug Inspection Management Measures (Trial)"). Through comparison, the large language model can accurately identify changes such as additions, deletions, modifications, and adjustments between old and new regulations, and automatically generate a structured "Rule Base Update Recommendation Report." This report clearly indicates the old clauses that need to be repealed and the corresponding rules for handling them, the proposed revisions to risk indicators or scoring standards for new requirements, and the proposed adjustments to weights and thresholds for clauses whose wording or scale has changed.

[0093] The main guidelines refer to the laws, regulations, and departmental rules that establish the fundamental principles, basic systems, core obligations, and general inspection procedures for the quality management of drugs throughout their entire life cycle, such as the "Drug Administration Law" and the "Drug Inspection Management Measures (Trial Implementation)." These constitute the underlying logic and basic framework of risk assessment. Secondary guidelines refer to various documents that provide specific explanations, refine standards, supplement operational requirements, or reflect local or phased regulatory priorities, such as national inspection guidelines, local implementation rules, and special governance notices.

[0094] The generated update recommendation report will be pushed to regulatory experts in the field for final review. Experts can review each recommendation on the system's interactive interface and make decisions to confirm, modify, or reject it. After the experts approve the recommendation, the system administrator can use the "One-Click Update Rule Base" function to trigger the system to automatically complete operations such as adding, modifying, and disabling rules, and simultaneously complete version management and update records.

[0095] Step S209: Obtain historical multi-source real-world data of the target pharmaceutical company and generate risk trend information; The system periodically acquires historical multi-source real-world data from target pharmaceutical companies over multiple historical regulatory cycles (such as the past three years). Then, steps S202 to S205 are repeated to determine the company's historical comprehensive risk score for each historical regulatory cycle.

[0096] Based on these historical comprehensive risk scores, the system generates risk trend information for the company, such as displaying the trajectory of risk score changes over time in the form of a line graph. This trend information can be used to indicate whether the risk of the target pharmaceutical company is stabilizing, rising, or declining, providing decision support for forward-looking regulation and early warning.

[0097] This embodiment provides a method for assessing the quality risks of pharmaceutical companies. By integrating multi-source real-world data, including basic enterprise information, compliance history, testing data, and monitoring data, and using the unified social credit code as the core index for integrated governance, it breaks down the "data silos" in traditional supervision. It transforms scattered risk clues into quantifiable and traceable structured data assets, providing objective and comprehensive data support for regulatory decisions. A hierarchical system is constructed, encompassing both inherent and compliance risks, and further subdivided into three levels of operational indicators. Consistency testing is performed, and differentiated indicator frameworks are set for manufacturing and operating enterprises to ensure the scientific rigor, reliability, and industry suitability of the assessment. A rule engine serves as the core decision-making engine. When an enterprise is determined to be high-risk, regulators can directly trace back to the specific triggering rules, clearly understanding the source of the risk and greatly enhancing the credibility and acceptability of regulatory decisions. Based on a comprehensive risk score, a risk ranking list of enterprises is generated. Combined with statutory inspection frequency requirements and the total annual inspection resources, a differentiated inspection plan is intelligently generated, precisely allocating limited regulatory resources to high-risk enterprises, achieving optimal matching of resources and risks, and significantly improving regulatory efficiency. By using a large language model to intelligently compare and analyze old and new regulatory documents, it can automatically identify clause changes and generate update suggestions, and has a dynamic rule base maintenance mechanism.

[0098] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method.

[0099] According to embodiments of this disclosure, this disclosure also provides a quality risk assessment device for pharmaceutical companies. For example, Figure 4 This is a schematic diagram of a pharmaceutical company quality risk assessment device provided in an embodiment of the present disclosure. The pharmaceutical company quality risk assessment device 400 includes: The data acquisition unit 410 is used to acquire multi-source real-world data of the target pharmaceutical company. The multi-source real-world data includes basic information data of the company, compliance history data, test data and monitoring data. The quantitative scoring unit 420 is used to quantitatively score multi-source real-world data based on a preset risk assessment indicator system, and obtain the indicator scores of the target pharmaceutical company in the inherent risk dimension and compliance risk dimension. The preset risk assessment indicator system includes multiple levels of risk indicators with preset weights. The comprehensive scoring unit 430 is used to determine the target pharmaceutical company's sub-scores and comprehensive risk score in the inherent risk dimension and compliance risk dimension based on the indicator scores. The risk profile generation unit 440 is used to generate a risk profile of the target pharmaceutical company based on the comprehensive risk score and the sub-item scores. The risk profile includes risk level and risk label.

[0100] This embodiment of a pharmaceutical enterprise quality risk assessment device is used to implement the aforementioned pharmaceutical enterprise quality risk assessment method. Therefore, the specific implementation of the pharmaceutical enterprise quality risk assessment device can be found in the embodiment section of the pharmaceutical enterprise quality risk assessment method above. For example, the data acquisition unit 410, the quantitative scoring unit 420, the comprehensive scoring determination unit 430, and the risk profile generation unit 440 are respectively used to implement steps S101, S102, S103, and S104 in the aforementioned pharmaceutical enterprise quality risk assessment method. Therefore, its specific implementation can be referred to the description of the corresponding embodiments, which will not be repeated here.

[0101] Embodiments of this disclosure also provide an electronic device including a memory and a processor, the memory storing a computer program and the processor being configured to run the computer program to perform the steps in any of the above method embodiments.

[0102] Embodiments of this disclosure also provide a computer-readable storage medium storing a computer program configured to perform the steps in any of the above method embodiments when executed.

[0103] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk.

[0104] Embodiments of this disclosure also provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps in any of the above method embodiments.

[0105] Embodiments of this disclosure also provide another computer program product, including a non-volatile computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps in any of the above method embodiments.

[0106] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.

[0107] The target detection method provided in this disclosure has been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this disclosure. The descriptions of the embodiments above are only for the purpose of helping to understand the method and its core ideas. It should be noted that those skilled in the art can make various improvements and modifications to this disclosure without departing from its principles, and these improvements and modifications also fall within the protection scope of the claims of this disclosure.

Claims

1. A method for quality risk assessment in pharmaceutical companies, characterized in that, include: Obtain multi-source real-world data of the target pharmaceutical company, including basic company information data, compliance history data, testing data, and monitoring data; Based on a preset risk assessment index system, the multi-source real-world data is quantitatively scored to obtain the target pharmaceutical company's index scores in the inherent risk dimension and compliance risk dimension. The preset risk assessment index system includes multiple levels of risk indicators with preset weights. Based on the scores of the aforementioned indicators, the sub-scores and comprehensive risk score of the target pharmaceutical company in the inherent risk dimension and compliance risk dimension are determined; Based on the comprehensive risk score and the sub-scores, a risk profile of the target pharmaceutical company is generated, which includes a risk level and a risk label.

2. The pharmaceutical enterprise quality risk assessment method according to claim 1, characterized in that, The quantitative scoring of the multi-source real-world data based on the preset risk assessment index system includes: Based on a preset rule engine, the multi-source real-world data is matched with multiple tertiary indicators in the risk assessment indicator system; Based on the matching results, determine the indicator score corresponding to each third-level indicator.

3. The pharmaceutical enterprise quality risk assessment method according to claim 2, characterized in that, Also includes: Obtain updated regulatory documents; The updated regulatory documents are compared and analyzed with the current mainline documents using a large language model to generate rule base update suggestions; In response to the received confirmation instruction, the rules in the rule engine are updated according to the rule base update suggestion.

4. The pharmaceutical enterprise quality risk assessment method according to claim 1, characterized in that, The process of determining the target pharmaceutical company's sub-scores and comprehensive risk score in the inherent risk dimension and compliance risk dimension based on the index scores includes: The initial risk score is obtained by weighted summation of the scores of multiple indicators under the aforementioned compliance risk dimension. Based on the enterprise type or business scope in the enterprise basic information data, the inherent risk coefficient of the target pharmaceutical enterprise is determined. The inherent risk coefficient is used to characterize the basic risk level of the inherent risk dimension. The inherent risk coefficient is added to the initial risk score to obtain the comprehensive risk score.

5. The pharmaceutical enterprise quality risk assessment method according to claim 1, characterized in that, After generating the risk profile of the target pharmaceutical company based on the comprehensive risk score, the process further includes: A risk ranking list is generated based on the comprehensive risk scores of multiple target pharmaceutical companies. Based on the risk ranking list and preset inspection resource information, a differentiated annual inspection plan is generated.

6. The pharmaceutical enterprise quality risk assessment method according to claim 1, characterized in that, Also includes: In response to receiving a query request for a specific risk point in the risk profile, a semantic search is performed in a preset regulatory vector knowledge base to obtain relevant regulatory clauses; The relevant legal provisions are understood and organized using a large language model, and legal interpretation information is generated and output in response to the query request.

7. The pharmaceutical enterprise quality risk assessment method according to claim 1, characterized in that, Also includes: Obtain historical multi-source real-world data of the target pharmaceutical company; Based on the aforementioned historical multi-source real-world data and the aforementioned preset risk assessment indicator system, the historical comprehensive risk score of the target pharmaceutical company in multiple historical regulatory cycles is determined; Based on historical comprehensive risk scores over multiple historical regulatory cycles, risk trend information is generated for the target pharmaceutical company, which is used to indicate the trajectory of risk changes for the target pharmaceutical company.

8. A quality risk assessment device for pharmaceutical companies, characterized in that, include: The data acquisition unit is used to acquire multi-source real-world data of the target pharmaceutical company, including basic information data of the company, compliance history data, inspection data and monitoring data. The quantitative scoring unit is used to quantitatively score the multi-source real-world data based on a preset risk assessment indicator system, and obtain the indicator scores of the target pharmaceutical company in the inherent risk dimension and compliance risk dimension. The preset risk assessment indicator system includes multiple levels of risk indicators with preset weights. The comprehensive scoring unit is used to determine the target pharmaceutical company's sub-scores and comprehensive risk score in the inherent risk dimension and compliance risk dimension based on the index scores. The risk profile generation unit is used to generate a risk profile of the target pharmaceutical company based on the comprehensive risk score and the sub-item scores. The risk profile includes a risk level and a risk label.

9. An electronic device, characterized in that, include: At least one processor; as well as, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1-7.

10. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to perform the method described in any one of claims 1-7.