Risk vector generation system
Patent Information
- Application Number
- TW114115513
- Authority / Receiving Office
- TW · TW
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-02-06
- Filing Date
- 2025-04-24
- Publication Date
- 2026-08-16
- Estimated Expiration
- 2045-04-23
AI Technical Summary
Conventional quality management systems rely on reactive strategies, leading to high costs, regulatory penalties, and damage to brand reputation, while traditional risk classification methods are diverse and complex, requiring significant resources and often fail to integrate internal and external risk factors, affecting decision-making efficiency and product quality stability.
A risk vector generation system using a database, large language model module, risk assessment module, and risk vector generation module to quantify risks, generate multi-dimensional risk vectors, and identify potential interactions, adaptable to various industries.
The system reduces reliance on manpower and resources, accurately quantifies risks, enhances assessment efficiency, and identifies risk interactions, enabling timely responses and improved quality management.
Smart Images

Figure TWG2TA001072440_001 
Figure TWG2TA001072440_002 
Figure TWG2TA001072440_003
Abstract
Description
[Technical Field]
[0001] This invention relates to a risk assessment system, and more particularly to a risk vector generation system based on quality management. [Previous Technology]
[0002] Conventional quality management systems mostly adopt a reactive strategy, meaning that companies only invest significant resources in quality correction, product recall, and customer compensation after quality problems occur. However, this reactive approach not only incurs high costs but may also lead to regulatory penalties and damage to brand reputation, thereby weakening the company's competitiveness. Since the release of ISO 9001:2015, quality management systems have formally adopted a risk-oriented approach. ISO 9001:2015 primarily emphasizes that companies should proactively identify and mitigate risks when planning and implementing quality management systems to prevent quality problems from occurring. To effectively implement risk-oriented management, companies need to first clarify the types of risks they may face and establish an appropriate risk classification framework based on business characteristics and industry needs to ensure that risk assessment and management measures can be systematically implemented.
[0003] However, traditional risk classification methods are diverse, and different industries need to develop applicable risk classification frameworks based on their product characteristics, supply chain structure, compliance requirements, and manufacturing environment to ensure that quality management strategies can effectively control different risk categories. As industries continue to expand and business processes become increasingly complex, the types of risks faced by each industry are also continuously increasing. Furthermore, when risk management systems must cover multi-level and multi-category risk assessments while simultaneously considering risk coefficients, risk management becomes more complex and execution costs increase. Enterprises need to invest significant time, manpower, and resources in identifying and assessing risks, which not only affects decision-making efficiency but may also make it difficult for management mechanisms to accurately identify and control risks in a timely manner.
[0004] Furthermore, the interrelationships between risk categories are often overlooked due to fragmented information or limitations in risk assessment tools, making it difficult for companies to build a complete risk architecture. When risk management strategies fail to effectively integrate internal and external risk factors, decision-makers may misjudge the actual threats faced by the company, or even affect overall operational stability due to incorrect identification of key risks. At the same time, quality management is also deeply affected by risk management mechanisms. A lack of systematic risk assessment, monitoring, and auditing may lead to instability in product or service quality, thereby increasing defect rates and compliance risks, and making it difficult for companies to formulate effective risk improvement strategies in a timely manner. [Summary of the Invention]
[0005] In view of this, the present invention provides a risk vector generation system, comprising: a database pre-stored a first standard operating procedure (SOP) and a risk calculation table; a large language model module connected to the database, used to receive a first instruction to generate N attribute data and determine whether the N attribute data matches the first SOP; a risk assessment module connected to the database and the large language model module, used to receive the N attribute data and calculate a first risk priority number (RPN) based on the risk calculation table; and a risk vector generation module connected to the large language model module and the risk assessment module, used to receive the N attribute data matching the first SOP to generate M components, and generate a multi-dimensional risk vector with the first RPN; wherein N and M are both natural numbers greater than 1. The risk vector generation system of the present invention can not only quantify all possible risks, but also discover the cumulative effect of potential risk interactions. Furthermore, this invention is highly flexible and can be adapted to the risk management needs of various industries.
[0006] The risk vector generation module is used to generate the M components based on the N attribute data and the first SOP, and M is greater than N.
[0007] The large language model module further includes a dynamic SOP generation unit, and the first instruction further includes a first regulatory data. If the N attribute data do not match the first SOP, the dynamic SOP generation unit extracts the first regulatory data from the first instruction to generate a second SOP.
[0008] The database further includes a regulatory database. If the N attribute data do not match the first SOP, the dynamic SOP generation unit retrieves one of the second regulatory data from the regulatory database to generate a third SOP.
[0009] The second SOP and the third SOP are stored in one of the databases, the quality database.
[0010] The large language model module further includes a comparison unit to determine whether the N attribute data match the first SOP.
[0011] The comparison unit includes an Artificial Intelligence Agent to compare the accuracy of the first SOP in order to automatically optimize and adjust the first SOP.
[0012] The M components further include a personnel component, a machinery component, a raw material component, a standard component, an environmental component, an event component, and a time component.
[0013] Among them, the N attribute data include a person attribute, an event attribute, a time attribute, a location attribute and an object attribute.
[0014] The risk assessment module further includes a negative RPN generation unit, which generates a second RPN based on the value of a severity indicator in the first RPN, as well as the value of a pre-stored detection indicator and an incidence indicator.
[0015] Where the second RPN is less than zero, the risk vector generation module receives the N attribute data to generate the M components, and combines them with the second RPN to generate a risk multidimensional negative vector.
[0016] In summary, this invention provides a risk vector generation system that not only significantly reduces the reliance on manpower and resources for risk assessment and improves assessment efficiency, but also specifically and accurately quantifies all possible risks. The large language model module of this invention converts the first instruction into N attribute data, and the risk vector generation module generates M components based on the N attribute data and the first standard operating procedure (SOP). The division of the M components corresponds to the N attribute data, where M is greater than N, indicating that more risk factors can be extracted from the N attribute data, and all risk factors are categorized into appropriate components, thereby constructing a unified risk vector model. This method ensures that all potential risk factors can be specifically presented and quantified, improving the accuracy and operability of risk assessment.
[0017] Furthermore, when all risk factors are integrated into a unified multidimensional risk vector, the correlation between various risks can be clearly and specifically identified. This invention can also uncover potential risk interaction mechanisms and cumulative effects through cross-analysis and statistical inference, enabling enterprises to grasp risk change trends in real time and optimize their response strategies.
[0018] Furthermore, this invention employs a risk assessment method that integrates M components into a single multi-dimensional risk vector, breaking through the assessment limitations caused by industry-specific risk categories in traditional risk management, and achieving a standardized and scalable risk assessment architecture. This invention possesses high adaptability and versatility, and can flexibly address the risk management needs of different industries. [Simplified Explanation of the Diagram]
[0050] Figure 1 is a functional block diagram illustrating a risk vector generation system according to a specific embodiment of the present invention.
[0051] Figure 2 is a functional block diagram illustrating a risk vector generation system according to another specific embodiment of the present invention.
[0052] Figure 3 is a schematic diagram illustrating the execution of a risk vector generation system according to a specific embodiment of the present invention.
Implementation Method
[0019] To make the advantages, spirit, and features of the present invention easier and clearer to understand, detailed descriptions and discussions will follow with reference to the accompanying drawings and specific embodiments. It should be noted that these specific embodiments are merely representative examples of the present invention, and the specific methods, apparatuses, conditions, etc., exemplified are not intended to limit the present invention or the corresponding specific embodiments. Furthermore, the elements in the figures are only used to express their relative positions and are not drawn to scale; the step numbers in the present invention are only for distinguishing different steps and do not represent the order of the steps, as will be stated previously.
[0020] Please refer to Figure 1. Figure 1 is a functional block diagram illustrating a risk vector generation system according to a specific embodiment of the present invention. As shown in Figure 1, the present invention provides a risk vector generation system 10 comprising a database 30, a large language model module 20, a risk assessment module 40, and a risk vector generation module 50. In this specific embodiment, the database 30 pre-stores a first standard operating procedure (SOP) (hereinafter referred to as the first SOP) and a risk calculation table. The large language model module 20 is connected to the database 30 and is used to receive a first instruction to generate N attribute data and determine whether the N attribute data matches the first SOP. The risk assessment module 40 is connected to the database 30 and the large language model module 20 and is used to receive the N attribute data and calculate and generate a first risk priority number (RPN) (hereinafter referred to as the first RPN) according to the risk calculation table. The risk vector generation module 50 is connected to the large language model module 20 and the risk assessment module 40. It receives N attribute data matching the first SOP to generate M components, and then uses these components with the first RPN to generate a multi-dimensional risk vector. This invention provides a risk vector generation system applicable to Contract Development and Manufacturing Organization (CDMO) factories, including product development and commercial production services for pharmaceuticals and biologics. However, in practice, it is not limited to this scope; this invention also provides a risk vector generation system that can be applied to other industries to meet quality management needs.
[0021] In this specific embodiment, N and M are both natural numbers greater than 1. The M components include personnel, machinery, raw materials, specifications, environment, events, and time. The N attribute data include personnel attributes, event attributes, time attributes, location attributes, and object attributes. However, in practice, the M components are not limited to the above categories and can be expanded according to actual needs to cover the composition and classification structure of all risk factors.
[0022] In this specific embodiment, the risk vector generation module 50 can also be used to generate M components based on N attribute data and the first SOP, where M is greater than N. M being greater than N indicates that more risk factors can be extracted from these attribute data and appropriately categorized into the various components. This invention can capture and integrate all subtle risk factors that are difficult for humans to directly perceive, ensuring the comprehensiveness and accuracy of risk assessment. However, in practical applications, it is not limited to this; M can also be equal to N.
[0023] In addition to the above embodiments, the present invention may also cover other application forms. Please refer to Figure 2. Figure 2 is a functional block diagram illustrating a risk vector generation system 10' according to another specific embodiment of the present invention. As shown in Figure 2, the difference between the risk vector generation system 10' in this specific embodiment and the above specific embodiment is that the database 30 in the risk vector generation system 10' in this specific embodiment may further include a regulatory database 301, a quality database 302, and a risk vector database 303; the large language model module 20 further includes a comparison unit 201 and a dynamic SOP generation unit 202; and the risk assessment module 40 further includes a negative RPN generation unit 401. In this specific embodiment, the comparison unit 201 is used to determine whether N attribute data match the first SOP, and the dynamic SOP generation unit 202 is used to extract the first regulatory data in the first instruction to generate the second SOP and to extract the second regulatory data in the regulatory database to generate the third SOP. However, in practice, this is not the only possibility. The dynamic SOP generation unit can also use manual identification to recognize the first regulatory information in the first directive to generate the second SOP, and to recognize the second regulatory information in the regulatory database to generate the third SOP. The regulatory database 301 can include national pharmaceutical regulations (such as FDA, EMA, TFDA), international standards (such as GMP, GLP, GCP, ISO 13485, ISO 9001), and cell therapy-related guidelines (such as ATMP, ICH, USP). <1046> This includes environmental and biosafety regulations (such as BSL biosafety level requirements and EU REACH), but is not limited to these in practice. The quality database 302 may contain internal standard operating procedures, internal quality management specifications, and internal audit and compliance documents, but is not limited to these in practice. The risk vector library 303 stores multi-dimensional risk vectors. The negative RPN generation unit 401 generates a second RPN based on the severity index value in the first RPN, and the pre-stored detectability index value and incidence index value. The second RPN is generated by multiplying the severity index value, detectability index value, and incidence index value, and then adding a negative sign to the result to generate a corresponding effective improvement measure.
[0024] In this specific embodiment, the risk calculation table further includes a severity index, a detectability index, and an incidence index, used to generate a first RPN for the first instruction. The first RPN is obtained by the risk assessment module multiplying the values of the severity index, the detectability index, and the incidence index according to the risk calculation table.
[0025] In this specific embodiment, the negative RPN generation unit 401 generates a second RPN based on the severity index value in the first RPN, and the pre-stored detectability index value and incidence index value. The second RPN is less than zero. The risk vector generation module 50 receives N attribute data to generate M components, and combines them with the second RPN to generate a multidimensional negative risk vector. Note that the risk vector generation system 10' in this specific embodiment has the same or corresponding components and modules as those in the aforementioned specific embodiments, which have been described in detail in the aforementioned specific embodiments, and therefore will not be repeated here.
[0026] Please refer to Figures 2 and 3 together. Figure 3 is a flowchart illustrating the execution of the risk vector generation system 10' according to a specific embodiment of the present invention. As shown in Figures 2 and 3, the operation of the risk vector generation system 10' in this specific embodiment includes the following steps: Step S1: Receive a first instruction to generate N attribute data; Step S2: Determine whether the N attribute data matches the first SOP; If the N attribute data matches the first SOP, then proceed to step S3: The risk assessment module 40 receives the N attribute data and calculates and generates a first RPN according to the risk calculation table; The risk vector generation module 50 receives the N attribute data to generate M components and generates a risk multidimensional vector with the first RPN; If the N attribute data does not match the first SOP, then proceed to step S4: Determine whether the first instruction further includes a first method. If the first instruction further includes first regulatory information, then proceed to step S5: the dynamic SOP generation unit 202 extracts the first regulatory information from the first instruction to generate a second SOP; if the first instruction does not include first regulatory information, then proceed to step S6: search the regulatory database 301; step S7: determine if there are relevant regulatory requirements; if there are relevant regulatory requirements, then proceed to step S8: the database 30 further includes the regulatory database 301, and the dynamic SOP generation unit 202 extracts the second regulatory information from the regulatory database 301 to generate a third SOP; if there are no relevant regulatory requirements, then proceed to step S9: set the specification component to N / A. In this specific embodiment, the quality database 302 in the database 30 pre-stores the first SOP. The second SOP and the third SOP generated by the dynamic SOP generation unit 202 are stored in the quality database 302 of the database 30.
[0027] In another specific embodiment, the comparison unit further includes an Artificial Intelligence Agent (AIA) for comparing the accuracy of the first SOP to automatically optimize and adjust the first SOP. Furthermore, the AIA can also determine whether N attributes matching the first SOP impair product quality and whether there are concerns about harming customers, generating judgment result information. The risk assessment module receives the aforementioned judgment result information to generate a severity index value.
[0028] Please refer to Figures 1 and 2. In a practical application scenario, the large language model module 20 receives a first instruction. The first instruction is "On January 1, 2025, a QC specialist operated a microscope in laboratory R01 and forgot to turn off the power after use, causing the lamp to burn out." The large language model module 20 receives the first instruction to generate N attribute data, which include personnel attributes, event attributes, time attributes, location attributes, and object attributes. The personnel attribute is "QC", the event attribute is "operating the microscope without turning off the power according to regulations, causing the lamp to burn out", the time attribute is "January 1, 2025", the location attribute is "laboratory R01", and the object attribute is "microscope". The comparison unit 201 in the large language model module 20 receives the first SOP from the quality database 302 in the database 30 to determine whether the N attribute data matches the first SOP. The first SOP is all SOP data pre-stored in the quality database 302. After comparison, the comparison unit 201 confirmed that the event attribute of the lamp burnout caused by the failure to turn off the power of the operating microscope in accordance with the specifications was consistent with the "QC-Laboratory Microscope Operation Manual" in the quality database 302.
[0029] The risk vector generation module 50 connects to the large language model module 20 to receive the above N attribute data to generate M components. The M components are sequence number component, personnel component, machine component, raw material component, standard component, environmental component, event component, and time component. The sequence number component is a serial number. The sequence number component for "QC specialist operated the microscope in laboratory R01 on January 1, 2025, and forgot to turn off the power after use, causing the lamp to burn out" is "00100". The personnel component is "QC", the machine component is "microscope", the raw material component is not classified, so it is "N / A", the standard component is "QC-Laboratory Microscope Operation Manual", the environmental component is "Laboratory R01", the event component is "operating the microscope without turning off the power according to the standard, causing the lamp to burn out", and the time component is "January 1, 2025".
[0030] The risk assessment module 40 connects to the database 30 and the large language model module 20 to receive N attribute data and calculate the first RPN based on the risk calculation table, which is as follows:
[0031]
[0032]
[0033] The risk assessment module 40 connects to the regulatory database 301 to compare whether there is regulatory data matching N attributes, and receives the judgment result information from the artificial intelligence agent in the large language model module 20. The result generated by the risk assessment module 40 is that the failure to turn off the power of the microscope according to the specifications, resulting in the lamp burning out, does not violate any pharmaceutical regulations, but violates the usage specifications of the "QC-Laboratory Microscope Operation Manual". Although there is no direct concern about harming customer safety, it may affect product quality, so the severity index value is 3. The risk assessment module 40 connects to the quality database 302 to compare the monitoring data in the quality database 302. The result generated by the risk assessment module 40 is that there is no AI detection system or automated detection system at the microscope placement location in laboratory R01, only the relevant forms attached to the QC-Laboratory Microscope Operation Manual, and human signatures are used as the management basis, so the detection index value is 3. The risk assessment module 40 connects to the risk vector generation module 50 and the risk vector library 303 to receive the risk multidimensional vector generated by the risk vector generation module 50 in the first instruction and compare it with the risk vector library 303. The result generated by the risk assessment module 40 is that all non-time vectors in the historical risk multidimensional vector are the same as the non-time vectors of the risk multidimensional vector in the first instruction. Furthermore, its time vector is "May 1, 2024", therefore the incidence rate index value is 2. The risk assessment module 40 multiplies the severity index value, the detectability index value, and the incidence rate index value to generate the first RPN. The calculation formula for the first RPN is as follows:
[0034] First RPN = Severity index × Detectability index × Incidence index
[0035] The calculated value is:
[0036] First RPN = 3 × 3 × 2 = 18
[0037] The risk vector generation module 50 is connected to the large language model module 20 to receive the above N attribute data to generate M components, and generates a risk multidimensional vector with the first RPN. In this practical application scenario, the risk multidimensional vector is "(00100, QC, Microscope, N / A, QC-Laboratory Microscope Operation Manual, Laboratory R01, The power supply to the microscope was not turned off according to the specifications, causing the lamp to burn out, January 1, 2025, 18)".
[0038] The negative RPN generation unit 401 generates a second RPN based on the severity index value in the first RPN, and the pre-stored detection index value and incidence index value. The second RPN is generated by multiplying the severity index value, the detection index value, and the incidence index value, and adding a negative sign to the result, thereby generating a corresponding effective improvement measure. The calculation formula for the second RPN is as follows:
[0039] Second RPN = -(Severity index × Detectability index × Occurrence rate index)
[0040] In this practical application scenario, the severity index of the second RPN is 3, which is the same as the severity index of the first RPN. The detectability of the second RPN is 4, as it is preset to generate an automated detection system. The occurrence rate of the second RPN is 5, as it is preset to never occur again. The calculated values are:
[0041] Second RPN = -(3×4×5) = -60
[0042] The risk vector generation module 50 receives N attribute data to generate M components, and combines them with a second RPN to generate a multidimensional negative risk vector. In this practical application scenario, the multidimensional negative risk vector is: "(00100, QC, Microscope, N / A, QC-Laboratory Microscope Operation Manual, Laboratory R01, The power supply to the microscope was not turned off according to specifications, causing the lamp to burn out, January 1, 2025, -60)". This practical application scenario demonstrates how the present invention can automatically identify and assess risks in quality management through the large language model module 20, the risk assessment module 40, and the risk vector generation module 50. Through risk vector comparison and RPN calculation, the present invention can not only quantify the severity, detection capability, and occurrence rate of risks, but also further generate negative RPNs, providing effective risk improvement countermeasures.
[0043] This application case demonstrates that even if an event does not violate pharmaceutical regulations, it may still affect product quality due to non-compliance with internal SOPs. Therefore, by comparing risk vectors with historical data, the risk level can be accurately assessed, and feasible remedial measures can be generated. The dynamic analysis mechanism of this invention helps enterprises respond to potential risks in a timely manner and enhances the efficiency of quality control and management.
[0044] In summary, this invention provides a risk vector generation system that not only significantly reduces the reliance on manpower and resources for risk assessment and improves assessment efficiency, but also specifically and accurately quantifies all possible risks. The large language model module of this invention converts the first instruction into N attribute data, and the risk vector generation module generates M components based on the N attribute data and the first SOP. The division of the M components corresponds to the N attribute data, where M is greater than N, indicating that more risk factors can be extracted from the N attribute data, and all risk factors are categorized into appropriate components, thereby constructing a unified risk vector model. This method ensures that all potential risk factors can be specifically presented and quantified, improving the accuracy and operability of risk assessment.
[0045] Furthermore, when all risk factors are integrated into a unified multidimensional risk vector, the correlation between various risks can be clearly and specifically identified. This invention can also uncover potential risk interaction mechanisms and cumulative effects through cross-analysis and statistical inference, enabling enterprises to grasp risk change trends in real time and optimize their response strategies.
[0046] Furthermore, this invention employs a risk assessment method that integrates M components into a single multi-dimensional risk vector, breaking through the assessment limitations caused by industry-specific risk categories in traditional risk management, and achieving a standardized and scalable risk assessment architecture. This invention possesses high adaptability and versatility, and can flexibly address the risk management needs of different industries.
[0047] It should be noted that relational terms in this specification, such as “first” and “second”, are used only to distinguish an entity or operation from another entity or operation, and do not require or imply any actual relationship or order between these entities or operations. Furthermore, the words “comprising,” “having,” and “including,” as well as other similar forms, are intended to be equivalent in meaning and are open-ended; one or more items following any of these words do not imply an exhaustive list of such one or more items, or that the list is limited to one or more items.
[0048] The detailed description of the preferred embodiments above is intended to more clearly describe the features and spirit of the present invention, and is not intended to limit the scope of the present invention by the preferred embodiments disclosed above. Rather, the aim is to cover various changes and equivalent arrangements within the scope of the patent claims of the present invention. Therefore, the scope of the patent claims of the present invention should be interpreted in the broadest possible sense based on the foregoing description, so as to cover all possible changes and equivalent arrangements.
Claims
1. A risk vector generation system, comprising: a database pre-stored a first standard operating procedure (SOP) and a risk calculation table; a large language model module connected to the database, configured to receive a first instruction to generate N attribute data and determine whether the N attribute data matches the first SOP, wherein the large language model module further includes a dynamic SOP generation unit, the first instruction further includes first regulatory data, and if the N attribute data does not match the first SOP, the dynamic SOP generation unit extracts the first regulatory data from the first instruction to generate a second SOP; a risk assessment module connected to the database and the large language model module, configured to receive the N attribute data, read the risk calculation table to calculate a severity index, a detectability index, and an incidence index, and perform calculations to further multiply the severity index, the detectability index, and the incidence index to generate a first risk priority coefficient. The module includes a Number (RPN); and a risk vector generation module connected to the large language model module and the risk assessment module. This module receives N attribute data matching the first SOP to generate M components, and then uses these components to generate a multi-dimensional risk vector with the first RPN. Both N and M are natural numbers greater than 1.
2. The risk vector generation system as described in claim 1, wherein the risk vector generation module is used to generate the M components based on the N attribute data and the first SOP, and M is greater than N.
3. The risk vector generation system as described in claim 1, wherein the database further includes a regulatory database, and if the N attribute data do not match the first SOP, the dynamic SOP generation unit retrieves one of the second regulatory data from the regulatory database to generate a third SOP.
4. The risk vector generation system as described in claim 3, wherein the second SOP and the third SOP are stored in one of the databases, a quality database.
5. The risk vector generation system as described in claim 1, wherein the large language model module further includes a comparison unit for determining whether the N attribute data match the first SOP.
6. The risk vector generation system as described in claim 5, wherein the comparison unit includes an Artificial Intelligence Agent for identifying a mismatch between the N attribute data and the first SOP, and for correcting the first SOP based on the mismatch to generate an updated first SOP.
7. The risk vector generation system as described in claim 1, wherein the M components further include a personnel component, a machinery component, a raw material component, a standard component, an environmental component, an event component, and a time component.
8. The risk vector generation system as described in claim 1, wherein the N attribute data includes a person attribute, an event attribute, a time attribute, a location attribute, and an object attribute.
9. The risk vector generation system as described in claim 1, wherein the risk assessment module further includes a negative RPN generation unit, which multiplies the severity index value in the first RPN, the value of a pre-stored detection index, and the value of an incidence index and adds a negative sign to generate a second RPN.
10. The risk vector generation system as described in claim 9, wherein the second RPN is less than zero, the risk vector generation module receives the N attribute data to generate the M components, and combines them with the second RPN to generate a risk multidimensional negative vector.