Modelling compliance risk: a structured approach

被引:3
|
作者
Esayas, Samson [1 ]
Mahler, Tobias [1 ]
机构
[1] Norwegian Res Ctr Comp & Law, St Olavs Plass 5, N-0130 Oslo, Norway
关键词
Compliance; Risk identification; Legal risk; Graphical modelling; Compliance management; Natural language patterns;
D O I
10.1007/s10506-015-9174-x
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This article presents a structured and systematic approach for identifying and modelling compliance risks. The sophistication with which modern business is carried out and the unprecedented access to a global market means that businesses are exposed to increasing and diverse regulatory requirements in and across jurisdictions. Compliance with such requirements is practically challenging, partly due to the complexity of regulatory environments. One possibility in this regard is a risk-based approach to compliance, where resources are allocated to those compliance issues that are most risky. Despite the need for risk-based compliance, few specific methods and techniques for identifying and modelling compliance risks have been developed. Due to the lack of methodological and tool support, compliance risk identification often involves unstructured brainstorming, with uncertain outcomes. The proposed approach consists of a five-step process for the structured identification and assessment of compliance risks. This process aims at facilitating the identification of compliance risks and their documentation in a consistent and reusable fashion. As part of the process, the article provides a systematic approach for a graphical modelling of compliance risks, which aims at facilitating communication among experts from different backgrounds. The creation of graphical models can be partly automated based on natural language patterns for regulatory requirements. Furthermore, the structuring of the compliance requirement in a template aims at simplifying the modelling of compliance risks and facilitating a potential future automated model.
引用
收藏
页码:271 / 300
页数:30
相关论文
共 50 条
  • [1] A structured approach to compliance with "Category a elements of performance"
    Popovich, JM
    JOURNAL OF NURSING CARE QUALITY, 2004, 19 (03) : 180 - 187
  • [2] Financial modelling: Adopting a structured approach
    Carter, L.
    Elvidge, A.
    Evans, S.
    Goodier, A.
    Martucci, J.
    Journal of the Institution of British Telecommunications Engineers, 2001, 2 (01): : 37 - 41
  • [3] A structured approach to software process modelling
    Franch, X
    Ribo, JM
    24TH EUROMICRO CONFERENCE - PROCEEDING, VOLS 1 AND 2, 1998, : 753 - 762
  • [4] Financial modelling: Adopting a structured approach
    Carter, L
    Elvidge, A
    Evans, S
    Goodier, A
    Martucci, J
    JOURNAL OF THE INSTITUTION OF BRITISH TELECOMMUNICATIONS ENGINEERS, 2001, 2 : 37 - 41
  • [5] Operational risk modelling and organizational learning in structured finance operations: a Bayesian network approach
    Sanford, Andrew
    Moosa, Imad
    JOURNAL OF THE OPERATIONAL RESEARCH SOCIETY, 2015, 66 (01) : 86 - 115
  • [6] STRUCTURED APPROACH TO THE ADOPTION OF INFORMATION TECHNOLOGY GOVERNANCE, RISK AND COMPLIANCE IN HOSPITALS USING DESIGN SCIENCE PRINCIPLES
    Krey, Mike
    Furnell, Steven
    Harriehausen, Bettina
    Knoll, Matthias
    PROCEEDINGS OF THE IADIS INTERNATIONAL CONFERENCE E-HEALTH 2012, 2012, : 85 - 96
  • [7] Structured approach for traffic flow modelling and control
    Iordanova, V.
    Abouaissa, Hassane
    Jolly, D.
    Mediterranean Journal of Measurement and Control, 2007, 3 (04): : 173 - 182
  • [8] Regulatory Compliance Modelling Using Risk Management Techniques
    Taylor, Steve
    Surridge, Mike
    Pickering, Brian
    2021 IEEE WORLD AI IOT CONGRESS (AIIOT), 2021, : 474 - 481
  • [9] Predictive Risk Modelling for Integrated Care: a Structured Review
    Mesgarpour, Mohsen
    Chaussalet, Thierry
    Worrall, Philip
    Chahed, Salma
    2016 IEEE 29TH INTERNATIONAL SYMPOSIUM ON COMPUTER-BASED MEDICAL SYSTEMS (CBMS), 2016, : 42 - 47
  • [10] Structuring Compliance Risk Identification Using the CORAS Approach: Compliance as an Asset
    Esayas, Samson Yoseph
    2014 IEEE INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING WORKSHOPS (ISSREW), 2014, : 281 - 286