An enterprise operation risk assessment method based on artificial intelligence analysis
Patent Information
- Application Number
- CN202610841462.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-11
- Publication Date
- 2026-09-11
AI Technical Summary
[0005]因此,本发明提供了一种基于人工智能分析的企业经营风险评估方法解决多异常经营动作并发场景下核心风险诱因难以筛选和候选风险诱因难以验证为核心经营风险原因的问题
[0016]本发明有益效果为:通过异常节点遮断与连通判断,筛出切断风险路径的核心诱因候选,避免多异常叠加误判;通过反事实替换压测,验证候选诱因对风险传导的实际影响,锁定核心经营风险原因,提高评估可解释性与准确性。
Smart Images

Figure CN122736310A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of business risk control data processing technology, and in particular to a method for assessing business risks based on artificial intelligence analysis. Background Technology
[0002] With the digitalization of enterprise operations, the intelligentization of post-loan management, and the improvement of big data analysis capabilities, technologies for enterprise operational risk assessment have gradually evolved from financial statement verification, public information inquiry, and manual due diligence to a multi-source data processing path that integrates order fulfillment, bill circulation, payment status, business operations, and public risk events. Enterprise operational risk assessment methods based on artificial intelligence analysis have begun to be used for business event aggregation, risk transmission identification, anomaly screening, and risk level generation.
[0003] Existing business risk assessment technologies still have certain shortcomings. First, they mostly rely on indicator weighting or anomaly scoring, making it difficult to pinpoint which business action triggered the risk and along which transmission path it will spread. Second, when faced with multiple concurrent abnormal business actions, it is difficult to distinguish between ordinary abnormal nodes and core risk triggers, resulting in inaccurate risk cause identification and a lack of traceable evidence for the level of business risk. Summary of the Invention
[0004] In view of the aforementioned existing problems, the present invention is proposed.
[0005] Therefore, this invention provides a business risk assessment method based on artificial intelligence analysis to solve the problems of difficulty in screening core risk factors and difficulty in verifying candidate risk factors as the causes of core business risks in scenarios with multiple abnormal business actions occurring concurrently.
[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution: This invention provides a method for assessing business risks based on artificial intelligence analysis, comprising: The process involves collecting enterprise operation records, semantically normalizing the elements of operation items, and performing chaining and supplementary chaining for similar items to form a set of operation item chain records. Based on this set, closed-loop sample inheritance is extracted to generate operational action inheritance benchmarks. Deviation identification and anomaly point recording are then performed to form an event anomaly chain set. This anomaly chain set is then graphed to generate anomaly point graph records, and risk transmission is weighted to generate a weighted operational risk relationship diagram. Based on the weighted operational risk relationship diagram, anomaly node blocking is performed to generate a risk path blocking record set, and connectivity is determined to generate a core risk cause candidate set. Finally, based on the core risk cause candidate set, counterfactual substitution stress testing of operation items is performed to generate risk transmission records after substitution, identify the core operational risk causes, and generate the enterprise operational risk assessment result.
[0007] As a preferred embodiment of the enterprise operation risk assessment method based on artificial intelligence analysis described in this invention, the formation of the business event chain record set is specifically as follows: Extract business transaction elements from enterprise operation records, and use artificial intelligence semantic representation to perform semantic alignment, unified identification merging and related mark retention to form an element unified table; Based on the element unification table, the business operation records are arranged in order of business actions and the corresponding positions are written to form a colleague necklace record. Based on the colleague necklace records, similar associations are added to the business records of enterprises with related tags, and the records are categorized into colleague necklace records according to the position of the business actions, forming a set of business event chain records.
[0008] As a preferred embodiment of the enterprise operation risk assessment method based on artificial intelligence analysis described in this invention, the generation of the operational action acceptance benchmark is specifically as follows: When screening the closed state of the business event chain in the business event chain record set, the access position, output position and advancement direction of adjacent business actions in the business event chain are checked. Business event chains with continuous positions, consistent advancement direction and closed completion of the tail business action are written into the closed candidate range, and business event chains with risky result chains are removed to form a closed sample set. Based on the closed sample set of operations, steady-state analysis is performed, and the stable content is merged into benchmarks to generate operational action benchmarks.
[0009] As a preferred embodiment of the enterprise operation risk assessment method based on artificial intelligence analysis described in this invention, the formation of the event anomaly chain set is specifically as follows: Based on the operational action acceptance benchmark, the operational action verification is carried out on the operational item chain record set, and the deviation position of the operational item chain with acceptance deviation chain is recorded to form an acceptance deviation identification record; After the deviation position in the deviation identification record is matched with the preceding and following business actions, the positions of missing business actions, misaligned sequence, abnormal intervals, and closed interruption are locked as abnormal landing points. Then, breakpoints are written in the chain at the subsequent termination of the abnormal landing point, and an abnormal landing point chain is formed according to the order of business action progression. Based on the abnormal landing point chain, the corresponding business event chain in the business event chain record set is written back, and the deviation basis corresponding to the business action acceptance benchmark is retained to form a set of abnormal event chains.
[0010] As a preferred embodiment of the enterprise operation risk assessment method based on artificial intelligence analysis described in this invention, the generation of abnormal landing point map records is specifically as follows: Based on the abnormal chain set of events, the abnormal landing point location and corresponding business action are extracted, the corresponding business action is converted into a business node, and the connection position between business nodes is established according to the order of business action. The abnormal landing point is written into the corresponding connection position, indicating that the abnormality occurred between adjacent business actions, thus forming an abnormal landing point node table. According to the order of business operations, check the connecting edge where the abnormal landing point is located. When the connecting edge cannot continue to connect to the next business node, the direction of acceptance is interrupted, or the closing action is performed, the corresponding connecting edge is judged as an abnormal acceptance edge that has stopped accepting, and the break point position is retained to form an abnormal acceptance edge sequence. The abnormal receiving edge sequence is sequentially concatenated and the abnormal receiving edges are grouped in the same position to form an abnormal landing point map record.
[0011] As a preferred embodiment of the enterprise business risk assessment method based on artificial intelligence analysis described in this invention, the generation of the weighted business risk relationship diagram is specifically as follows: Based on the abnormal landing point map record, historical transmission samples are aligned, and risk transmission weights are written in through artificial intelligence weighting to form a risk transmission weighted segment. Based on the risk transmission weighted segment back-write of abnormal landing point map records, and weighted back-write and map completion, a weighted operational risk relationship diagram is generated.
[0012] As a preferred embodiment of the enterprise operation risk assessment method based on artificial intelligence analysis described in this invention, the generation of the risk path blocking record set is specifically as follows: The risk initiation point and the risk endpoint are locked in the weighted operating risk relationship diagram to generate a risk initiation and endpoint locking table. Based on the risk start and end point locking table, abnormal nodes are obtained item by item along the connecting edge between the risk start point and the risk end point, and arranged according to the blocking priority to form a sequence of abnormal nodes to be blocked. Based on the priority of blocking, the connecting edges before and after the abnormal node, and the connectivity status of the risk start and end point, the connection relationship of the abnormal node ranked first is cut off in sequence and the path status is recorded. If there is still an alternative connection path after a single point is blocked, the adjacent abnormal nodes that maintain connectivity in the same risk path are merged and blocked to generate a risk path blocking record set.
[0013] As a preferred embodiment of the enterprise operation risk assessment method based on artificial intelligence analysis described in this invention, the generation of the core risk factor candidate set is specifically as follows: Based on the risk path interruption record set, the remaining connecting edges after interruption, the original receiving direction and path status are used as the basis for connectivity judgment. The risk starting point is checked. If it can be reached, it is marked as still connected. If it cannot be reached and stops at the intermediate operating node, it is marked as interrupted in the middle. If it cannot continue to receive, it is marked as the path is broken. The number of combined interruption nodes and the break position are recorded at the same time to form a connectivity judgment content set. Based on the set of connectivity judgment content, verify the disconnection status of the risk origin and end points corresponding to the key blocking nodes, the number of blocking nodes, and the alternative connection paths. Key blocking nodes that can cut off the risk transmission path, require a small number of blocking nodes, and have no alternative connection paths are retained. The corresponding blocking basis is written in parallel to generate a core risk cause candidate set.
[0014] As a preferred embodiment of the enterprise operation risk assessment method based on artificial intelligence analysis described in this invention, the generation of the replaced risk transmission record is specifically as follows: Based on the core risk trigger candidate set, through artificial intelligence similarity matching, retrieve the historical closed business event chain in the business closed sample set that has not formed risk results, can complete the connection between the preceding and following business actions according to the business action acceptance benchmark, and form a counterfactual replacement fragment table of normal business action segments that are in the same business action position as the candidate abnormal business actions; Based on the counterfactual replacement fragment list, normal business operation fragments are replaced with candidate abnormal business operations. Without changing the original risk starting point, risk ending point, and connecting edge, the business operation process is replayed to verify whether the risk transmission continues to reach the risk ending point, thus forming a chain of business events after replacement. Based on the replaced business item chain, the original chain is replayed and the acceptance status is checked along the original connecting edge in the weighted business risk relationship diagram to form a risk transmission record after the replacement.
[0015] As a preferred embodiment of the enterprise business risk assessment method based on artificial intelligence analysis described in this invention, the generation of enterprise business risk assessment results is specifically as follows: Based on the risk transmission records after replacement, the risk transmission status before and after the replacement of candidate abnormal business actions is compared to identify the causes of core business risks. Based on the causes of core operational risks, the types of risk outcome nodes and the status of risk transmission changes corresponding to the causes of core operational risks are verified, and the enterprise's operational risk level is written according to the verified content, generating the enterprise's operational risk assessment results.
[0016] The beneficial effects of this invention are as follows: by judging the interruption and connectivity of abnormal nodes, the core inducement candidates for cutting off risk paths are screened out, avoiding misjudgment due to the superposition of multiple anomalies; by using counterfactual substitution stress testing, the actual impact of candidate inducements on risk transmission is verified, the core operational risk causes are identified, and the interpretability and accuracy of the assessment are improved. Attached Figure Description
[0017] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 This is a flowchart of a business risk assessment method based on artificial intelligence analysis.
[0019] Figure 2 A flowchart for forming a chain of records of business transactions.
[0020] Figure 3 A flowchart generated for a weighted operational risk relationship diagram.
[0021] Figure 4 A flowchart for identifying and assessing the causes of core operational risks. Detailed Implementation
[0022] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0023] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.
[0024] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it a single or selective embodiment that is mutually exclusive with other embodiments.
[0025] Reference Figures 1-4 This is one embodiment of the present invention, which provides a method for assessing business risks based on artificial intelligence analysis, including the following steps: S1: Collect enterprise operation records, semantically normalize the elements of operation items, and perform chaining of the same items and supplementary chaining of similar items on the enterprise operation records to form a chain record set of operation items; S1.1: Extract business transaction elements from enterprise business records, and use artificial intelligence semantic representation to perform semantic alignment, unification and merging of identifiers and retention of related tags to form an element unification table; The elements of an operational item are key contents extracted from the company's operational records one by one according to the item name, transaction object, operational action, and time of occurrence. They are used to identify the attribution of operational items and the succession relationship of operational actions.
[0026] Artificial intelligence semantic representation is generated by semantic encoding of business transaction elements. It is used to convert business transaction elements from different sources and with different writing styles into comparable semantic representation content, to determine whether business transaction elements point to the same business transaction, and to provide a basis for semantic alignment, unified identifier merging and related mark retention.
[0027] When performing semantic alignment based on semantic representation content, the semantic representation content is categorized according to the type of business action and the time of occurrence. Each item is compared with the business matter attribution, transaction object, and business action direction corresponding to the semantic representation content. Business matter elements with consistent attribution, consistent transaction object, and sequential business actions are merged under the same unified identifier. Business matter elements whose names correspond to the same business matter and consistent transaction object, but whose business actions lack adjacent successor actions and have not yet formed a closed loop, retain the association mark and form an element unified table.
[0028] S1.2: Based on the element unification table, the business operation records are arranged in order of business actions and the corresponding positions are written to form a colleague necklace record; Based on the element unification table, content with the same unification identifier in the enterprise's business records is grouped under the same business item. The business actions are arranged in order of occurrence time, type of business action, and relationship between preceding and subsequent business operations. For content with overlapping time or repeated actions under the same business item, it is rearranged according to the direction of business action succession, so that the business actions in the enterprise's business records form a continuous arrangement.
[0029] Based on the continuously arranged content, the connection position between adjacent business actions is verified one by one. Business actions that can be connected one after another are written into the continuous position in the chain. The connection position that lacks intermediate business actions is left as an empty position, and a gap mark and a connection position mark are written. Then, the continuous position, empty position and connection position mark are all placed under the same business item to form a colleague necklace record.
[0030] S1.3: Based on the colleague necklace record, perform similar association supplementation on the business records of enterprises with related tags, and classify them into the colleague necklace record according to the position of the business action to form a business event chain record set.
[0031] The association marker refers to the supplementary chain marker written to the business records of enterprises that cannot yet be merged into the same unified identifier but have business relationships between business elements during the semantic alignment process. It is used to indicate that the business record of the enterprise can be used as a candidate record for subsequent similar association supplementation.
[0032] Based on the colleague necklace record, the enterprise business records are checked back according to the marked position of the association mark in the element unification table. The enterprise business records that are not included in the colleague necklace record are located, and the business item elements, business action positions and source positions corresponding to the association mark are aligned with the colleague necklace record. Enterprise business records that can fill the gap in the colleague necklace record and whose business actions can be connected with the previous and subsequent business actions are regarded as similar association supplementary content.
[0033] Based on the location of the business action, similar related supplementary content is assigned to the gap position or adjacent continuation position of the corresponding colleague necklace record, while keeping the existing business action order in the colleague necklace record unchanged. The colleague necklace record after being assigned, together with the business records of enterprises that have not been supplemented but retain the association mark, form a business event chain record set.
[0034] S2: Based on the business event chain record set, extract the business closure sample acceptance, generate the business action acceptance benchmark, and perform acceptance deviation identification and abnormal landing point writing to form an event abnormal chain set; S2.1: When screening the closed state of the business event chain in the business event chain record set, check the access position, output position and advancement direction of adjacent business actions in the business event chain. Write the business event chain with continuous positions, consistent advancement direction and closed completion of the tail business action into the closed candidate range, and remove the business event chain with risky result chain to form a closed sample set. The business item chain record set is expanded one by one according to the business item chain identifier. The access position, output position and advancement direction of adjacent business actions in each business item chain are read. The continuity of the output position of the previous business action and the access position of the next business action are checked. At the same time, the advancement direction of adjacent business actions is checked to see if they are consistent. Business item chains that can be continuously accessed, have consistent advancement directions and have reached the closed completion state at the end of the chain are written into the closure candidate range. If any of the following situations occurs, such as the previous and next positions are disconnected, the advancement directions are inconsistent, or the business action at the end of the chain has not reached the closed completion state, the chain is excluded from the closure candidate range.
[0035] The risk outcome chain is formed by the performance status, payment status, invoicing status, and publicly disclosed risk event records in the enterprise's business records. It is used to identify the chain content that has been extended from the business event chain to the risk outcome. The business event chains in the closed candidate scope continue to be checked against the risk outcome chain. Business event chains that have been extended to risk outcomes such as performance suspension, payment interruption, invoicing refund, and public risk triggering are removed from the closed candidate scope. Business event chains that have not been extended to the risk outcome chain are retained and collected to form a closed sample set of business operations.
[0036] S2.2: Based on the closed sample set of operations, the steady-state extraction is carried out, and the stable content is merged into a benchmark to generate the operational action acceptance benchmark; Based on the set of closed-loop business samples, the closed-loop business samples are classified into similar sample ranges according to the type of business items and the business cycle. The order of acceptance, the interval of acceptance, and the completion status of adjacent business actions are read one by one. Acceptance contents with the same acceptance order, the interval of acceptance falling into the concentrated range of similar closed-loop business samples, and the completion status of closure are marked as stable acceptance contents.
[0037] Based on the stable content of the business operations, the business operations are grouped together according to the same combination of business operations. Content with inconsistent order of operations, intervals exceeding the concentration range of similar closed-loop business samples, or inconsistent completion status are removed. The order of operations, intervals, and completion status of the remaining content are then written into the same benchmark entry to generate the business operation operation benchmark.
[0038] S2.3: Based on the operational action acceptance benchmark, conduct operational action verification on the operational item chain record set, and record the deviation position of the operational item chain with acceptance deviation chain, forming an acceptance deviation identification record; A deviation chain refers to abnormal content in the chain of business operations where adjacent business operations do not proceed continuously according to the business operation acceptance benchmark. This includes missing business operations, misaligned business operation sequences, abnormally long intervals between business operations, or interrupted closing actions. It is used to mark the location of the deviation in the chain of business operations and to provide a basis for the subsequent formation of deviation identification records.
[0039] According to the operational action acceptance benchmark, read the adjacent operational actions in the operational action chain record set one by one, and match the adjacent operational actions to the benchmark entries in the operational action acceptance benchmark. If the subsequent operational action lacks the benchmark entry requirement after the previous operational action, the order of the preceding and following actions is inconsistent with the benchmark entries, the interval between adjacent operational actions exceeds the acceptance interval range in the benchmark entries, or the operational action at the end of the chain has not reached the closed completion state, it is determined to be a deviation from the operational action acceptance benchmark, and the corresponding position is written into the pending confirmation chain mark.
[0040] When verifying deviations from the acceptance chain of adjacent business actions in the confirmation chain, the preceding and following business actions are read in the order of business action progression, and compared with the acceptance order, acceptance interval range, and closure completion status in the business action acceptance benchmark. If a business action is missing, the order of business actions is misaligned, the interval of business actions exceeds the acceptance interval range, or the closure action is interrupted, the corresponding deviation position is locked, and the deviation type and deviation basis are written to form an acceptance deviation identification record.
[0041] It should be noted that the deviation criteria include inconsistencies between the order of business operations and the business operation acceptance benchmark, intervals between adjacent business operations exceeding the acceptance interval range, and the closed completion state not falling into the corresponding state of the business operation acceptance benchmark. These criteria are used to support the formation of acceptance deviation identification records, abnormal landing point chains, and event abnormal chain sets.
[0042] S2.4: After the deviation position in the deviation identification record is matched with the preceding and following business actions, the positions of missing business actions, misaligned sequence, abnormal intervals, and closed interruptions are locked as abnormal landing points. Then, breakpoints are written in the chain at the subsequent termination points of the abnormal landing points, and an abnormal landing point chain is formed according to the order of business action progression. The deviation positions in the acceptance deviation identification records are located one by one. The previous business action, the next business action and the acceptance relationship corresponding to the deviation position are aligned. The positions corresponding to missing business actions, misaligned business action sequence, abnormally widened business action interval or interrupted closing action are fixed as abnormal landing points.
[0043] Continue to examine the continuity and extension status within the business operation chain around the abnormal landing point, and write the positions that cannot continue to the next business operation or closing action into the chain breakpoint mark; read the corresponding connection position of the abnormal landing point and the connection termination position corresponding to the chain breakpoint mark according to the order of business operation. Pair the abnormal landing points that are adjacent to each other in the same business operation chain with the chain breakpoint mark, take the abnormal landing point as the starting position and the chain breakpoint mark as the termination position, and retain the order of business operations between the abnormal landing point and the chain breakpoint mark to form an abnormal landing point chain.
[0044] It should be noted that the "continuation of continuity" status refers to the situation where the business operations following the abnormal landing point continue according to the business operation continuity benchmark. When checking the continuity of continuity status, the next business operation and the closing action are read one by one along the order of business operations following the abnormal landing point, and compared with the continuity order, continuity interval range and closing completion status in the business operation continuity benchmark. If the business operation cannot be continued, the continuity interval exceeds the continuity interval range, or the closing action is not formed, the corresponding continuity position is written into the chain breakpoint mark.
[0045] S2.5: Write back the corresponding business event chain in the business event chain record set based on the abnormal landing point chain, and retain the deviation basis corresponding to the business action acceptance benchmark to form a set of abnormal event chains.
[0046] Based on the abnormal landing point chain, the abnormal landing point, the chain breakpoint mark and the business item chain identifier are compared to locate the corresponding business item chain in the business item chain record set. The abnormal landing point is written into the continuation position between the preceding and following business actions according to the order of business action progress, and the chain breakpoint mark is written into the continuation and termination position, so that the corresponding business item chain forms a chain structure with abnormal landing points.
[0047] For each business item chain with an abnormal landing point, the preceding business action, the following business action, the order of acceptance, the interval of acceptance, and the closing completion status corresponding to the deviation position are compared with the benchmark items in the business action acceptance benchmark. The benchmark items corresponding to the deviation position are located, and the inconsistent acceptance order, the content that exceeds the acceptance interval range, or the content that does not meet the closing completion status in the benchmark items are extracted as deviation basis. The deviation basis, the abnormal landing point, the chain breakpoint mark, and the acceptance termination position are written into the corresponding business item chain. The corresponding business item chains with abnormal landing points are grouped according to the business item chain identifier to form a set of abnormal chain chains.
[0048] S3: Graph the abnormal event chain set into an anomaly landing point graph, generate an anomaly landing point graph record, and perform risk transmission weighting to generate a weighted operational risk relationship graph; S3.1: Extract the location of the anomaly and the corresponding business action based on the anomaly chain set, convert the corresponding business action into a business node, establish the connection position between business nodes according to the order of business action, write the anomaly location into the corresponding connection position, indicate that the anomaly occurred between adjacent business actions, and form an anomaly location node table. The abnormal chain set is expanded one by one according to the business item chain identifier to obtain the business item chain with abnormal landing points, locate the locked abnormal landing point position in the business item chain, and simultaneously obtain the corresponding business actions that have a succession relationship before and after the abnormal landing point; the abnormal landing point position is used to determine the place where the succession deviation occurs, and the corresponding business action is used to determine the range of actions within the chain to which the abnormal landing point belongs. After the two are matched, the corresponding business action is converted into a business node according to the business action progression sequence, and the succession relationship between the business nodes is preserved.
[0049] Adjacent business nodes establish connection positions based on the original business action connection relationships. These connection positions are used to handle abnormal landing points that occur between adjacent business actions. After the abnormal landing point position and the connection position are matched, the abnormal landing point is written to the corresponding connection position. When multiple abnormal landing points correspond to the same adjacent business action connection relationship, they are merged and written to the same connection position, while retaining the deviation type. This makes the abnormal landing point clearly indicate a connection deviation that occurs between adjacent business actions. The business nodes and connection positions are organized according to the business action progression order to form an abnormal landing point node table.
[0050] S3.2: Check the connecting edge where the abnormal landing point is located according to the order of business operation. When the connecting edge cannot continue to connect to the next business node, the direction of acceptance is interrupted, or the closing action is performed, the corresponding connecting edge is determined as an abnormal acceptance edge that has stopped accepting, and the break point position is retained to form an abnormal acceptance edge sequence. An abnormal connection edge that has been terminated refers to a connection edge that has been written into the abnormal landing point table and whose connection relationship between the corresponding business actions has stopped extending at the breakpoint mark position in the chain.
[0051] Connect the operational nodes in the abnormal landing point node table one by one according to the order of operational actions. Write the forward receiving position of the adjacent operational node as the receiving start point and the receiving position of the next operational node as the receiving end point. Write the receiving direction and the abnormal landing point position into the same receiving connection edge. When there is an abnormal landing point at the corresponding position of the receiving connection edge, mark the receiving connection edge as an abnormal receiving edge and retain the front and back relationship of the operational nodes at both ends of the abnormal receiving edge.
[0052] For abnormal acceptance edges marked with breakpoints within the chain, read the preceding business node and the acceptance termination position corresponding to the breakpoint mark, and write the preceding business node, the acceptance termination position, the acceptance termination status, and the abnormal landing position into the same abnormal acceptance edge. Arrange the abnormal acceptance edges according to the order of business action progression, and maintain the sequential relationship of consecutive abnormal acceptance edges in the same business item chain to form an abnormal acceptance edge sequence.
[0053] It should be noted that the sequential relationship refers to the relationship between adjacent abnormal acceptance edges in the same business transaction chain, which can be continuously connected according to the order of business action. The end point of the previous abnormal acceptance edge can correspond to the starting point of the next abnormal acceptance edge, and there are no unmarked gaps in business actions or reversed acceptance directions between the two abnormal acceptance edges.
[0054] S3.3: Perform sequential concatenation of abnormal receiving edges and grouping of abnormal receiving edges in the same position on the abnormal receiving edge sequence to form an abnormal landing point map record; Arrange abnormal acceptance edges according to the chain identifier of business items and the order of business action. Connect adjacent abnormal acceptance edges in the same business item chain that have the same acceptance direction and whose acceptance end point corresponds to the next acceptance start point continuously, and retain the order of abnormal landing point position, break point acceptance position and acceptance termination status in the chain.
[0055] By comparing the abnormal receiving edges in different business item chains according to the position of the business action, the receiving boundary, and the deviation basis, the abnormal receiving edges that correspond to the position of the business action, have the same receiving boundary, and have the same deviation basis are grouped into the same position in the graph, and the sequential connection relationship and the same position grouping relationship are written to form an abnormal landing point graph record.
[0056] It should be noted that sequential connection relationship is the relationship formed by connecting abnormal receiving edges within the same business item chain according to the order of business action. Same position grouping relationship is the relationship formed by abnormal receiving edges in different business item chains being grouped into the same position on the map because the position of business action, receiving boundary and deviation basis are consistent.
[0057] S3.4: Based on the abnormal landing point map record, historical transmission samples are aligned, and risk transmission weights are written through artificial intelligence weighting to form a risk transmission weighted segment; Artificial intelligence weighting is based on the risk transmission situation in historical risk enterprise samples. It marks the strength of the correlation between the abnormal receiving edge and the risk result in the abnormal landing point map record. It takes into account the frequency of occurrence, duration, result intensity and co-occurrence of historical transmission samples to determine the corresponding risk transmission weight. The risk transmission weight is written into the abnormal receiving edge, operation node and risk result node for subsequent generation of weighted operation risk relationship diagram.
[0058] When aligning historical transmission samples based on anomaly landing point map records, historical transmission content is merged according to the location of the anomaly receiving edge, the basis for deviation, and the type of risk result node to form transmission sample groups. Frequency of occurrence, duration, result intensity, and co-occurrence are extracted from the transmission sample groups and converted into normalized values for frequency of occurrence, duration, result intensity, and co-occurrence, respectively. The normalized values for frequency of occurrence, duration, and result intensity are used as common triggering content, and the normalized value for co-occurrence is used as aggregation correction content. Risk transmission weights are calculated, and these weights are then written into the operational nodes, anomaly receiving edges, and risk result nodes in the anomaly landing point map records to form weighted risk transmission segments.
[0059] The expression for calculating the risk transmission weight is: ; in, As a risk transmission weight; The frequency of occurrence of historical transmission content in the transmission sample group that is consistent with the current abnormal receiving edge position, deviation basis, and risk result node type is normalized. The continuous periodic normalization value is obtained by normalizing the number of operating cycles spanned by the current abnormal receiving edge in the transmission sample group from the abnormal landing point to the risk result node; The result strength normalization value is obtained by normalizing the strength of consequences corresponding to the risk result node types in the transmission sample group. The risk result node types include performance suspension, payment interruption, invoice refund and public risk trigger. The same position repetition normalization value is obtained by normalizing the number of abnormal acceptance edges that appear repeatedly under the same business action position, the same acceptance boundary, and the same deviation basis in the transmission sample group. The transmission amplification factor (example range: 0.80 to 2.50) is set based on the amplification sensitivity of the risk transmission weight when the frequency normalization value, duration normalization value, and result intensity normalization value work together. The higher the value is, the more concentrated the repeated occurrence of abnormal receiving edges in the historical transmission samples, the more stable the duration period, and the higher the risk result intensity. The correction coefficient for co-occurrence (example range: 0.10 to 0.35) is set based on the normalization value of co-occurrence to adjust the risk transmission weight. The higher the value, the more concentrated the abnormal bearing edge of the same business action position, the more obvious the co-occurrence abnormal clustering, and the more stable the bearing with the risk result node.
[0060] Risk transmission weights need to reflect the stability of transmission from abnormal receiving edges to risk outcome nodes, rather than the magnitude of a single historical event. A frequency normalization value only indicates that abnormal receiving edges occur frequently, not that the risk will continue to propagate; a duration normalization value only indicates a long transmission time, not that the risk outcome is strong; and an outcome intensity normalization value only indicates a severe risk consequence, not that occasional events can be ruled out.
[0061] Therefore, the frequency normalization value, duration normalization value, and result intensity normalization value are multiplied together in the calculation. This ensures that if any one of these values is low, the risk transmission weight is suppressed. Only when abnormal connecting edges repeatedly appear, continue to transmit, and correspond to strong risk results, is the risk transmission weight increased. The exponential convergence structure is used to suppress low-level, occasional transmission and to upper limit the convergence of continuous, high-intensity transmission, preventing the risk transmission weight from expanding indefinitely. The same-position repetition normalization value is calculated through logarithmic correction because the repeated occurrence of abnormal connecting edges at the same operational position can enhance the credibility of risk transmission. However, once the number of repetitions increases to a certain extent, the necessity for further amplification decreases. Logarithmic correction can retain the clustering effect while suppressing excessive amplification.
[0062] S3.5: Based on the risk transmission weighted segment, write back the abnormal landing point map record, and perform weighted write-back and map completion to generate a weighted operational risk relationship diagram.
[0063] Based on the risk transmission weighted fragment back-writing of the abnormal landing point map record, the risk transmission weight is written into the abnormal landing point map record according to the correspondence between the business node, the abnormal receiving edge and the risk result node. The correspondence between the risk transmission weight and the position of the abnormal receiving edge, the deviation basis and the risk result node type is verified to form an abnormal landing point map record with weight content.
[0064] Around the anomaly landing point graph records with weighted content, connect the business nodes and anomaly receiving edges according to the order of business action. Extend the anomaly receiving edges to the corresponding risk result nodes, and arrange the anomaly receiving edges under the same risk result node according to the risk transmission weight. This makes the business nodes, anomaly receiving edges, risk result nodes and risk transmission weight fall into the same graph structure, generating a weighted business risk relationship graph.
[0065] It should be noted that the weight content refers to the positional relationship between the risk transmission weight and the corresponding business node, abnormal receiving edge, and risk result node. This is used to enable the abnormal landing point map record to distinguish the strength of risk transmission and to provide a weighting basis for generating a weighted business risk relationship diagram.
[0066] The weighted operational risk relationship graph is a graph structure formed by writing risk transmission weights into the abnormal landing point graph record. It is used to represent the connection relationship and risk transmission strength between operational nodes, abnormal receiving edges and risk result nodes, and serves as the basis for subsequent abnormal node blocking, connectivity judgment and core risk cause screening.
[0067] S4: Based on the weighted operational risk relationship diagram, abnormal node blocking is performed to generate a risk path blocking record set, and connectivity judgment is performed to generate a core risk cause candidate set. S4.1: Perform risk start-point backtracking and risk end-point connection locking on the weighted operating risk relationship diagram, and generate a risk start-point and end-point locking table; For the risk outcome node in the weighted operational risk relationship graph, backtrack the operational nodes one by one along the abnormal receiving edge with risk transmission weight, find the operational node that was first written into the abnormal landing point chain and can reach the risk outcome node through the connecting edge, and write the corresponding operational node into the risk starting position.
[0068] Proceeding step by step from the risk starting point along the connecting edges to the risk result nodes, read the risk transmission weight, abnormal receiving edge, and risk result node on each connecting edge, find the risk result node at the end of the receiving chain, write the corresponding risk result node to the risk endpoint position, and link the risk starting point, risk endpoint, connecting path, and weight content together to generate a risk starting point and endpoint locking table.
[0069] S4.2: Based on the risk start and end point locking table, obtain abnormal nodes one by one along the connecting edge between the risk start point and the risk end point, and arrange them according to the blocking priority to form a sequence of abnormal nodes to be blocked. The priority of blocking refers to the order in which abnormal nodes between the risk initiation point and the risk endpoint are blocked. It is determined based on the abnormal node's position in the business chain, the risk transmission weight, the connection distance between the abnormal node and the risk endpoint, and the location of the breakpoint. It is used to deal with abnormal nodes that are more likely to affect the connection between the risk initiation point and the risk endpoint first.
[0070] Based on the risk origin and end point locking table, the connection edges between the risk origin and the risk end point are expanded item by item according to the risk transmission direction. The operational nodes with abnormal landing point chains, abnormal receiving edges, or risk transmission weights are extracted, and the connection edge positions, breakpoint positions, and risk transmission weights corresponding to the operational nodes are written into the same node entry to obtain the abnormal node content to be sorted.
[0071] For the abnormal nodes to be sorted, first sort the abnormal nodes according to their progress position in the business event chain, then compare the risk transmission weights of abnormal nodes at the same progress position, and put the abnormal nodes with higher risk transmission weights first; if there are still ties, read the number of connecting edges between the abnormal node and the risk endpoint, and put the abnormal node with fewer connecting edges first; after sorting, retain the connection relationship between the abnormal node and the risk starting point and risk endpoint to form a sequence of abnormal nodes to be blocked.
[0072] S4.3: Based on the priority of blocking, the connection edges before and after the abnormal node and the connectivity status of the risk start and end point, cut off the connection relationship of the abnormal node ranked first in sequence and record the path status. If there is still an alternative connection path after a single point is blocked, merge and block the adjacent abnormal nodes that maintain connectivity in the same risk path to generate a risk path blocking record set. The sequence of abnormal nodes to be blocked is expanded according to the priority of blocking. The abnormal nodes at the beginning of the sequence are read, and the connectivity between the connecting edges before and after the abnormal node and the risk start point and risk end point is checked. The connection between the abnormal node and the connecting edges before and after it is cut off to form a single-point blocking result. Then the path status after single-point blocking is recorded. The path status includes whether the risk start point and risk end point are disconnected, still connected, or can only extend to the intermediate operating node.
[0073] When the risk origin and risk end are still connected after a single point block, find adjacent abnormal nodes that maintain the connection along the same risk path, merge the adjacent abnormal nodes into a combined block object, and simultaneously cut the corresponding front and rear connecting edges of the combined block object. Then check the disconnection position and connectivity status after the combined block. The single point block result, combined block object, disconnection position and path status are included in the same record to generate a risk path block record set.
[0074] S4.4: Based on the risk path interruption record set, the remaining connecting edges after interruption, the original receiving direction and the path status are used as the basis for connectivity judgment. The risk starting point is checked. If it can be reached, it is marked as still connected. If it cannot be reached and stops at the intermediate operating node, it is marked as interrupted in the middle. If it cannot continue to receive, it is marked as the path is broken. The number of combined interruption nodes and the break position are recorded simultaneously to form a connectivity judgment content set. The risk path interruption record set is expanded one by one according to the risk path. The remaining connection edges, original receiving direction and path status are read after the interruption. The remaining connection edges are used to determine whether there is still a path that can continue to extend the risk transmission. The original receiving direction is used to restrict the connection judgment to only advance along the original transmission direction from the risk starting point to the risk ending point. The path status is used to distinguish the different situations of path disconnection after single point interruption, path disconnection after combined interruption and still connected after interruption.
[0075] Connectivity determination starts from the risk starting point and proceeds segment by segment along the remaining connection edge after the blockage in the original acceptance direction. It checks whether each remaining connection edge can be connected to the next business node until the risk endpoint is reached or a connection termination position is reached. If the risk endpoint can be reached continuously, it is written as still connected. If the risk endpoint cannot be reached but it stays in the intermediate business node, it is written as intermediate termination. If the remaining connection edge cannot continue to be connected to the next business node, it is written as path disconnected.
[0076] The number of combined blocking nodes and the location of disconnection are checked simultaneously with the connectivity judgment results. The number of combined blocking nodes is used to indicate the number of abnormal nodes that the risk path depends on when it is cut off, and the location of disconnection is used to indicate the specific location where the risk transmission stops. The still connected state, the intermediate interrupted state, the path disconnected state, the number of combined blocking nodes and the location of disconnection are grouped into the same record to form a connectivity judgment content set.
[0077] S4.5: Based on the set of connectivity judgment content, check the disconnection status of the risk start and end points corresponding to the key blocking nodes, the number of blocking nodes and alternative connection paths. Key blocking nodes that can cut off the risk transmission path, require a small number of blocking nodes and have no alternative connection paths are retained. The corresponding blocking basis is written in parallel to generate a core risk cause candidate set.
[0078] The connectivity judgment set is expanded one by one according to the risk path. The disconnection status of the risk start and end points, the number of blocked nodes, and the status of alternative connection paths corresponding to the key blocking nodes are read. The key blocking nodes are abnormal nodes that prevent the risk transmission from reaching the risk end point after being blocked. They are used to indicate the actual interruption position in the risk path. During screening, the ability to cut off the risk transmission path is used as the admission condition, and the number of blocked nodes and the absence of alternative connection paths are used as the retention conditions. Nodes that can still reach the risk end point through the remaining connection edges after being blocked are not included in the retention range.
[0079] The key blocking nodes that are screened and retained are further reviewed against the risk path blocking record set and the connectivity judgment content set. The corresponding blocking establishment location, disconnection status and related business chain are verified. The disconnection status of the risk origin and end point, the number of blocking nodes and the verification results of alternative connection paths are written into the corresponding key blocking nodes as blocking basis. Then, they are grouped according to the risk transmission path. Candidate content that points to the same risk end point and has the same blocking basis is grouped into the same candidate range to generate a core risk cause candidate set.
[0080] S5: Based on the core risk trigger candidate set, perform counterfactual replacement stress test of business matters, generate risk transmission records after replacement, identify the core business risk causes, and generate enterprise business risk assessment results.
[0081] S5.1: Based on the core risk factor candidate set, through artificial intelligence similarity matching, retrieve the historical closed business event chain in the business closed sample set that has not formed risk results, can complete the continuity of the preceding and following business actions according to the business action acceptance benchmark, and form a counterfactual replacement fragment table of normal business action segments that are in the same business action position as the candidate abnormal business actions; Artificial intelligence similarity matching refers to comparing candidate abnormal business actions with business action segments in the historical closed business event chain based on the candidate factor elements in the core risk factor candidate set, and selecting business action segments with the same business event type, similar business action position and normal closed state as normal business action segments. This is used to ensure that the normal business action segments in the counterfactual replacement segment table have a replaceable relationship with the candidate abnormal business actions, and avoid arbitrary replacement that causes stress test distortion.
[0082] The core risk trigger candidate set is expanded item by item according to the candidate abnormal business actions. The identification of the business event chain where the candidate abnormal business action is located, the location of the business action and the basis for blocking are read. The location of the business action is used as the matching anchor point to review the historical closed business event chains in the business closure sample set, and the chain content that has not formed a risk result is screened out to avoid the participation of historical chains that have already transmitted risks in the replacement.
[0083] Artificial intelligence similarity matching compares candidate abnormal business actions with business action segments in the historical closed business event chain. It focuses on verifying whether the business action positions are the same and whether the preceding and following business actions can be completed in accordance with the business action succession benchmark. Business action segments that simultaneously meet the requirements of no risk result, valid succession, and the same business action position are identified as normal business action segments and are paired with the corresponding candidate abnormal business actions to form a counterfactual replacement segment table.
[0084] S5.2: Based on the counterfactual replacement fragment table, replace the normal business operation fragments with the candidate abnormal business operations. Without changing the original risk starting point, risk ending point and connecting edge, replay the business operation acceptance process to verify whether the risk transmission continues to reach the risk ending point, and form a chain of business items after replacement. The counterfactual replacement fragment table is expanded one by one according to the candidate abnormal business actions. The location of the candidate abnormal business action is obtained, and the normal business action fragment corresponding to the business action location is retrieved. The normal business action fragment is written into the location of the candidate abnormal business action. During the replacement process, the original risk starting point, risk ending point and connecting edge are preserved, so that the replacement content only changes the candidate abnormal business action itself and does not change the original structure of the risk path.
[0085] After the normal business operation segment is written, the business operation acceptance process is replayed according to the original connecting edge. It is checked whether the replaced business operation can continue to connect to the next business operation along the original acceptance direction, and whether the risk transmission can still extend to the risk endpoint. During the replay, the position that cannot continue to be accepted is retained as the acceptance termination position, and the position that can continue to be accepted retains the original path relationship. The replaced business operation, the original connecting edge and the acceptance verification results are sorted to form the replacement business item chain.
[0086] It should be noted that normal business operation segments refer to business operation content retrieved from historical closed business event chains that have not resulted in risk outcomes and can be completed in accordance with the business operation acceptance benchmark. These segments are used to replace candidate abnormal business operations and generate a replacement business event chain.
[0087] S5.3: Based on the replaced business item chain, perform original chain playback and acceptance status verification along the original connecting edge in the weighted business risk relationship diagram to form a risk transmission record after replacement; Based on the replaced business event chain, along the original connecting edges in the weighted business risk relationship diagram, the business nodes are replayed one by one from the risk starting point to the risk ending point. The replaced business actions are written into the original business node positions, while keeping the original connecting edge's receiving direction, receiving order, and risk result node positions unchanged. This is used to restore the transmission process of the replaced business event chain in the weighted business risk relationship diagram.
[0088] The status of the operational nodes after playback is checked. Each replacement operation is checked to see if it can continue along the original connection to the risk endpoint. The location of termination, the retention status of the risk result node, and the change status of risk transmission are recorded. The aforementioned check contents are merged into the same candidate abnormal operational operation to form a risk transmission record after replacement.
[0089] S5.4: Based on the risk transmission records after replacement, compare the risk transmission status before and after the replacement of the candidate abnormal business action to identify the core business risk causes; In the risk transmission record after replacement, select the connection status before and after the replacement corresponding to the candidate abnormal business action, and place the before and after status of the same candidate abnormal business action in the same comparison position. Verify the transmission changes that can continue to the risk endpoint before replacement, and stop extending or remain at the intermediate business node after replacement, and record the transmission comparison content.
[0090] Based on the candidate abnormal business actions corresponding to the transmission comparison content, the changes in risk outcome nodes and the status of risk transmission changes, the candidate abnormal business actions that cause the risk transmission to stop extending, the risk outcome nodes to no longer be retained, or the status of risk transmission changes to decline after replacement are identified as the core causes of business risks.
[0091] It should be noted that the core operational risk cause refers to the abnormal operational action that, after being replaced by a fragment of normal operational action, causes the original risk transmission path to stop extending, the risk outcome node to disappear, or the risk transmission status to decline, thereby confirming the abnormal operational action that plays a leading role in the formation of the enterprise's operational risk.
[0092] S5.5: Based on the core operational risk causes, verify the risk outcome node types and risk transmission change status corresponding to the core operational risk causes, and write down the enterprise's operational risk level according to the verified content to generate the enterprise's operational risk assessment results.
[0093] Based on the core operational risk causes, the risk outcome nodes connected to the core operational risk causes are reviewed, the risk outcome node types are verified, and the risk transmission change status in the replaced risk transmission record is read. The risk outcome node types are converted into risk categories, where performance suspension corresponds to performance risk, payment interruption corresponds to fund recovery risk, invoice return corresponds to bill circulation risk, and public risk trigger corresponds to public event risk. The risk categories are then linked with the core operational risk causes to form the level verification content.
[0094] According to the content of the risk assessment, the enterprise's business risk level is written down. If the risk result node is still retained after replacement and the risk transmission status does not decrease, it is written as high risk; if the risk transmission still reaches the risk endpoint after replacement but the transmission intensity decreases, it is written as medium risk; if the risk transmission stops extending after replacement and stays at the intermediate business node, it is written as low risk; if the risk result node is no longer retained after replacement, the candidate abnormal business action is confirmed as the core business risk cause, and the corresponding risk level is downgraded by one level to generate the enterprise business risk assessment result.
[0095] It should be noted that the enterprise operation risk level refers to the risk classification content determined based on the risk outcome node type and risk transmission change status corresponding to the core operation risk cause. It is used to indicate the severity of the enterprise operation risk and serves as the level conclusion in the enterprise operation risk assessment results.
[0096] In summary, this invention uses the following methods: judging abnormal node occlusion and connectivity to screen out core candidate causes for cutting off risk paths, avoiding misjudgments due to multiple superimposed anomalies; and through counterfactual substitution stress testing, it verifies the actual impact of candidate causes on risk transmission, identifies the core causes of operational risks, and improves the interpretability and accuracy of the assessment.
[0097] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. An enterprise management risk assessment method based on artificial intelligence analysis, characterized in that, include: Collect enterprise operation records, semantically normalize the elements of operation items, and perform chaining of the same items and supplementing of similar items in the enterprise operation records to form a chain record set of operation items; Based on the business event chain record set, the business closure sample is extracted to generate the business action acceptance benchmark, and the acceptance deviation identification and abnormal landing point writing are performed to form the event abnormal chain set; The abnormal chain set of events is graphed into an anomaly landing point map, generating an anomaly landing point map record, and risk transmission weighting is applied to generate a weighted operational risk relationship diagram; Based on the weighted operational risk relationship diagram, abnormal node blocking is performed to generate a risk path blocking record set, and connectivity judgment is performed to generate a core risk cause candidate set. Based on the candidate set of core risk causes, perform counterfactual substitution stress test on business matters, generate risk transmission records after substitution, identify the core business risk causes, and generate enterprise business risk assessment results.
2. The enterprise operational risk assessment method based on artificial intelligence analysis as described in claim 1, characterized in that, The formation of the chain of records for business transactions is as follows: Extract business transaction elements from enterprise operation records, and use artificial intelligence semantic representation to perform semantic alignment, unified identification merging and related mark retention to form an element unified table; Based on the element unification table, the business operation records are arranged in order of business actions and the corresponding positions are written to form a colleague necklace record. Based on the colleague necklace records, similar associations are added to the business records of enterprises with related tags, and the records are categorized into colleague necklace records according to the position of the business actions, forming a set of business event chain records.
3. The enterprise operational risk assessment method based on artificial intelligence analysis as described in claim 2, characterized in that, The specific criteria for generating operational actions are as follows: When screening the closed state of the business event chain in the business event chain record set, the access position, output position and advancement direction of adjacent business actions in the business event chain are checked. Business event chains with continuous positions, consistent advancement direction and closed completion of the tail business action are written into the closed candidate range, and business event chains with risky result chains are removed to form a closed sample set. Based on the closed sample set of operations, steady-state analysis is performed, and the stable content is merged into benchmarks to generate operational action benchmarks.
4. The enterprise operational risk assessment method based on artificial intelligence analysis as described in claim 1, characterized in that, The specific details of the formation of the anomaly chain set are as follows: Based on the operational action acceptance benchmark, the operational action verification is carried out on the operational item chain record set, and the deviation position of the operational item chain with acceptance deviation chain is recorded to form an acceptance deviation identification record; After the deviation position in the deviation identification record is matched with the preceding and following business actions, the positions of missing business actions, misaligned sequence, abnormal intervals, and closed interruption are locked as abnormal landing points. Then, breakpoints are written in the chain at the subsequent termination of the abnormal landing point, and an abnormal landing point chain is formed according to the order of business action progression. Based on the abnormal landing point chain, the corresponding business event chain in the business event chain record set is written back, and the deviation basis corresponding to the business action acceptance benchmark is retained to form a set of abnormal event chains.
5. The enterprise operational risk assessment method based on artificial intelligence analysis as described in claim 4, characterized in that, The generation of abnormal landing point map records is as follows: Based on the abnormal chain set of events, the abnormal landing point location and corresponding business action are extracted, the corresponding business action is converted into a business node, and the connection position between business nodes is established according to the order of business action. The abnormal landing point is written into the corresponding connection position, indicating that the abnormality occurred between adjacent business actions, thus forming an abnormal landing point node table. According to the order of business operations, check the connecting edge where the abnormal landing point is located. When the connecting edge cannot continue to connect to the next business node, the direction of acceptance is interrupted, or the closing action is performed, the corresponding connecting edge is judged as an abnormal acceptance edge that has stopped accepting, and the break point position is retained to form an abnormal acceptance edge sequence. The abnormal receiving edge sequence is sequentially concatenated and the abnormal receiving edges are grouped in the same position to form an abnormal landing point map record.
6. The enterprise operational risk assessment method based on artificial intelligence analysis as described in claim 1, characterized in that, The generation of the weighted operating risk relationship diagram is as follows: Based on the abnormal landing point map record, historical transmission samples are aligned, and risk transmission weights are written in through artificial intelligence weighting to form a risk transmission weighted segment. Based on the risk transmission weighted segment back-write of abnormal landing point map records, and weighted back-write and map completion, a weighted operational risk relationship diagram is generated.
7. The enterprise operational risk assessment method based on artificial intelligence analysis as described in claim 1, characterized in that, The generation of the risk path blocking record set is as follows: The risk initiation point and the risk endpoint are locked in the weighted operating risk relationship diagram to generate a risk initiation and endpoint locking table. Based on the risk start and end point locking table, abnormal nodes are obtained item by item along the connecting edge between the risk start point and the risk end point, and arranged according to the blocking priority to form a sequence of abnormal nodes to be blocked. Based on the priority of blocking, the connecting edges before and after the abnormal node, and the connectivity status of the risk start and end point, the connection relationship of the abnormal node ranked first is cut off in sequence and the path status is recorded. If there is still an alternative connection path after a single point is blocked, the adjacent abnormal nodes that maintain connectivity in the same risk path are merged and blocked to generate a risk path blocking record set.
8. The enterprise operation risk assessment method based on artificial intelligence analysis as described in claim 1 or 7, characterized in that, The generation of the core risk factor candidate set is as follows: Based on the risk path interruption record set, the remaining connecting edges after interruption, the original receiving direction and path status are used as the basis for connectivity judgment. The risk starting point is checked. If it can be reached, it is marked as still connected. If it cannot be reached and stops at the intermediate operating node, it is marked as interrupted in the middle. If it cannot continue to receive, it is marked as the path is broken. The number of combined interruption nodes and the break position are recorded at the same time to form a connectivity judgment content set. Based on the set of connectivity judgment content, verify the disconnection status of the risk origin and end points corresponding to the key blocking nodes, the number of blocking nodes, and the alternative connection paths. Key blocking nodes that can cut off the risk transmission path, require a small number of blocking nodes, and have no alternative connection paths are retained. The corresponding blocking basis is written in parallel to generate a core risk cause candidate set.
9. The enterprise operational risk assessment method based on artificial intelligence analysis as described in claim 8, characterized in that, The generation of the replacement risk transmission record is as follows: Based on the core risk trigger candidate set, through artificial intelligence similarity matching, retrieve the historical closed business event chain in the business closed sample set that has not formed risk results, can complete the connection between the preceding and following business actions according to the business action acceptance benchmark, and form a counterfactual replacement fragment table of normal business action segments that are in the same business action position as the candidate abnormal business actions; Based on the counterfactual replacement fragment list, normal business operation fragments are replaced with candidate abnormal business operations. Without changing the original risk starting point, risk ending point, and connecting edge, the business operation process is replayed to verify whether the risk transmission continues to reach the risk ending point, thus forming a chain of business events after replacement. Based on the replaced business item chain, the original chain is replayed and the acceptance status is checked along the original connecting edge in the weighted business risk relationship diagram to form a risk transmission record after the replacement.
10. The enterprise operation risk assessment method based on artificial intelligence analysis as described in claim 9, characterized in that, The generated enterprise operational risk assessment results are as follows: Based on the risk transmission records after replacement, the risk transmission status before and after the replacement of candidate abnormal business actions is compared to identify the causes of core business risks. Based on the causes of core operational risks, the types of risk outcome nodes and the status of risk transmission changes corresponding to the causes of core operational risks are verified, and the enterprise's operational risk level is written according to the verified content, generating the enterprise's operational risk assessment results.