Formalizing and appling compliance patterns for business process compliance

被引:61
|
作者
Elgammal, Amal [1 ]
Turetken, Oktay [2 ]
van den Heuvel, Willem-Jan [3 ]
Papazoglou, Mike [3 ]
机构
[1] Natl Univ Ireland Univ Coll Cork, Governance Risk Management & Compliance Technol C, Cork, Ireland
[2] Eindhoven Univ Technol, Sch Ind Engn, POB 513, NL-5600 MB Eindhoven, Netherlands
[3] Tilburg Univ, European Res Inst Serv Sci, NL-5000 LE Tilburg, Netherlands
来源
SOFTWARE AND SYSTEMS MODELING | 2016年 / 15卷 / 01期
关键词
Business process compliance; Compliance patterns; Formal specification; Regulatory compliance; Compliance management tool support; Design-time compliance management; COMPLIANCE-CHECKING; SPECIFICATION; VERIFICATION; FRAMEWORK; MODELS;
D O I
10.1007/s10270-014-0395-3
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Today's enterprises demand a high degree of compliance of business processes to meet diverse regulations and legislations. Several industrial studies have shown that compliance management is a daunting task, and organizations are still struggling and spending billions of dollars annually to ensure and prove their compliance. In this paper, we introduce a comprehensive compliance management framework with a main focus on design-time compliance management as a first step towards a preventive lifetime compliance support. The framework enables the automation of compliance-related activities that are amenable to automation, and therefore can significantly reduce the expenditures spent on compliance. It can help experts to carry out their work more efficiently, cut the time spent on tedious manual activities, and reduce potential human errors. An evident candidate compliance activity for automation is the compliance checking, which can be achieved by utilizing formal reasoning and verification techniques. However, formal languages are well known of their complexity as only versed users in mathematical theories and formal logics are able to use and understand them. However, this is generally not the case with business and compliance practitioners. Therefore, in the heart of the compliance management framework, we introduce the Compliance Request Language (CRL), which is formally grounded on temporal logic and enables the abstract pattern-based specification of compliance requirements. CRL constitutes a series of compliance patterns that spans three structural facets of business processes; control flow, employed resources and temporal perspectives. Furthermore, CRL supports the specification of compensations and non-monotonic requirements, which permit the relaxation of some compliance requirements to handle exceptional situations. An integrated tool suite has been developed as an instantiation artefact, and the validation of the approach is undertaken in several directions, which includes internal validity, controlled experiments, and functional testing.
引用
收藏
页码:119 / 146
页数:28
相关论文
共 50 条
  • [41] Automating Business Process Compliance for the EU AI Act
    Novelli, Claudio
    Governatori, Guido
    Rotolo, Antonino
    [J]. LEGAL KNOWLEDGE AND INFORMATION SYSTEMS, 2023, 379 : 125 - 130
  • [42] A Methodological Evaluation of Business Process Compliance Management Frameworks
    Hashmi, Mustafa
    Governatori, Guido
    [J]. ASIA PACIFIC BUSINESS PROCESS MANAGEMENT, 2013, 159 : 106 - 115
  • [43] Business process compliance checking based on provenance data
    Li, Bin
    Wang, Yifei
    Pei, Jisheng
    Ye, Xiaojun
    [J]. Qinghua Daxue Xuebao/Journal of Tsinghua University, 2013, 53 (12): : 1768 - 1776
  • [44] Visually Monitoring Multiple Perspectives of Business Process Compliance
    Knuplesch, David
    Reichert, Manfred
    Kumar, Akhil
    [J]. BUSINESS PROCESS MANAGEMENT, BPM 2015, 2015, 9253 : 263 - 279
  • [45] An Approach Toward the Economic Assessment of Business Process Compliance
    Kuehnel, Stephan
    Zasada, Andrea
    [J]. ADVANCES IN CONCEPTUAL MODELING, ER 2018, 2019, 11158 : 228 - 238
  • [46] Compliance requirements for business-process driven SOAs
    Papazoglou, Michael P.
    [J]. E-GOVERNMENT: ICT PROFESSIONALISM AND COMPETENCES - SERVICE SCIENCE, 2008, : 183 - 194
  • [47] Business Process Compliance via Security Validation as a Service
    Compagna, Luca
    Guilleminot, Pierre
    Brucker, Achim D.
    [J]. 2013 IEEE SIXTH INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION (ICST 2013), 2013, : 455 - 462
  • [48] Process Views to Support Compliance Management in Business Processes
    Schumm, David
    Leymann, Frank
    Streule, Alexander
    [J]. E-COMMERCE AND WEB TECHNOLOGIES, 2010, 61 : 131 - 142
  • [49] A Taxonomy of Business Rule Organizing Approaches in Regard to Business Process Compliance
    Corea, Carl
    Delfmann, Patrick
    [J]. ENTERPRISE MODELLING AND INFORMATION SYSTEMS ARCHITECTURES-AN INTERNATIONAL JOURNAL, 2020, 15
  • [50] An Experience Report of Improving Business Process Compliance Using Security Risk-Oriented Patterns
    Alakula, Mari-Liis
    Matulevicius, Raimundas
    [J]. PRACTICE OF ENTERPRISE MODELING, POEM 2015, 2015, 235 : 271 - 285