<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>BCIT: A Tool for Analyzing the Interactions between Business Process Compliance and Business Process Change</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Tobias Seyffarth</string-name>
          <email>tobias.seyffarth@wiwi.uni-halle.de</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Kai Raschke</string-name>
          <email>kai.raschke@wiwi.uni-halle.de</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Martin Luther University Halle-Wittenberg</institution>
          ,
          <addr-line>06108 Halle (Saale)</addr-line>
          ,
          <country country="DE">Germany</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>Business processes as well as their supporting information technology (IT) can be affected by compliance requirements. In the case of changing the business process, an IT component or a compliance requirement the interactions between business process compliance (BPC) and business process change must be determined to ensure BPC. However, there is a lack of tool-support that can analyze the interactions between BPC and business process change considering compliance requirements and supporting IT components. Therefore, we developed the prototype BCIT (Business Process Compliance and IT) which can analyze these interactions considering the change patterns “delete element” and “replace element”.</p>
      </abstract>
      <kwd-group>
        <kwd>business process compliance</kwd>
        <kwd>business process change</kwd>
        <kwd>compliance process</kwd>
        <kwd>information technology</kwd>
        <kwd>software prototype</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        Business process compliance (BPC) denotes the execution of business processes in
adherence to applicable compliance requirements [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. Not only business processes but
also information technology (IT) components that can support certain business
activities can be affected by so-called compliance requirements. In dynamic markets, the
rapid detection of compliance violations and the adherence to the demands of
compliance requirements to changed business processes and supporting IT components are
necessary [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Thus, in the case of a business process change, which includes the change
of a business activity, IT component, or compliance requirement, the effects on
business process compliance must be automatically determined [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. Although, there are
numerous process modeling tools, such as ARIS Architect, Bizagi Studio, Camunda
Modeler and Signavio Process Manager, to the best of our knowledge, there is a lack of a
tool that automatically determines the interaction between BPC and business process
change considering compliance requirements and supporting IT components.
Therefore, the goal of our paper is to present the software prototype BCIT (Business Process
F. Casati et al. (Eds.): Proceedings of the Dissertation Award and Demonstration,
Industrial Track at BPM 2018, CEUR-WS.org, 2018. Copyright © 2018 for the individual
papers by its authors. Copying permitted for private and academic purposes. This
volume is published and copyrighted by its editors.
Compliance and IT), which is able to determine those interaction between BPC and
business process change.
      </p>
      <p>The rest of the demo paper is structured as follows: Section 2 defines preliminaries
and provides a motivation example that can be solved by our prototype. Section 3 shows
the architecture and implementation of our prototype; and finally, Section 4 concludes
the paper.
2</p>
      <p>
        Business Process Compliance and Business Process Change
There are various approaches used to check for or ensure BPC. One possible solution
to ensure BPC during the design time of the business process is the separate modeling
of so-called compliance processes and their integration into the business process. In this
context, a compliance process is defined as an independent process (part) consisting of
at least one compliance-related activity that ensures BPC [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ].
      </p>
      <p>
        In the literature, many business process change patterns are discussed. In the
following, we focus on the change patterns “replace element” and “delete element” (e.g. [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ])
because they allow the determination of relationships between a changed element and
compliance requirement or a compliance process in a user-provided model. The replace
pattern replaces an existing element with a new one, while the delete pattern removes
an existing element. Business process change patterns can also be applied to views other
than a control flow perspective of a business process. In our case, they are applied to
the perspectives compliance and IT architecture. Further, we define an interaction
between BPC and business process change, if due to a change, an element is either
affected by a compliance requirement or compliance process and a change affects a
compliance requirement or compliance process.
      </p>
      <p>Physical
access</p>
      <p>Create purchase
request
ERP MM</p>
      <p>Send Receive
purchase goodsand
request invoice</p>
      <p>Hardware
§ 238
German
Com.</p>
      <p>Code</p>
      <p>Internal
policy</p>
      <p>Inform purchase
requester about
received goods</p>
      <p>Approve
invoice payment</p>
      <p>Pay invoice
ERP FI</p>
      <p>Replace ERP FI
Logical Logical access(CR)
access § 238 German</p>
      <p>CommercialCode (CR)</p>
      <p>Hardware (IT)
Physical access(CR)</p>
      <p>§ 238 German
CommercialCode (CR)
Pay invoice (activity)
Internal policy (CR)</p>
      <p>§ 238 German
CommercialCode (CR)
Approveinvoicepayment</p>
      <p>(CP)
IT is prerfeoqruisite CP cehleamngeendt redliarteicotn eilmempaecntt
egxatceluwsaivye cehleamngeendt trraenlastiitoivne eilmempaecntt</p>
      <p>Delete ERPFI</p>
      <p>Approveinvoice
payment(CP)
Internal policy (CR)</p>
      <p>§ 238 German
CommercialCode (CR)
Logical access(CR)</p>
      <p>Obsolete
element
BPC violated
because
CR is prerequisite CR
for
place
CR demands to IT</p>
      <p>IT is prerequisite activity IT is prerequisite IT
for for
place</p>
      <p>CR demands to activity
CP: compliance process | CR: compliance requirement | IT: IT component</p>
      <p>CP hsealtpissftyo CR start event,</p>
      <p>end event</p>
      <p>
        The left side of Figure 1 shows a simplified purchase-to-pay process including IT
components that support both business activities and the compliance process, which is
based on our previous work [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. Further, relevant compliance requirements (CR) of
business activities and IT components (IT) are modeled in the process model. The
compliance process (CP) “approve invoice payment” helps to satisfy the “internal policy”.
In the event of a compliance violation, the compliance process aborts the business
process instance. The right side of Figure 1 shows the interaction between BPC and
business process change. In the event of replacing the IT component “ERP FI”, both
compliance requirements “physical access” and “§ 238 German Commercial Code” must
be directly considered because “ERP FI” must consider all compliance requirements of
their prerequisite IT components. In addition, the “internal policy” must be considered
as well because there is a transitive relation between “ERP FI” and this compliance
requirement. “ERP FI” is necessary for the execution of the compliance process
“approve invoice payment”, which is in turn necessary to satisfy the “internal policy”.
      </p>
      <p>In the case of deleting the IT component “ERP FI” the compliance requirement
“internal policy” and its prerequisite “§ 238 German Commercial Code” are violated.
In this case, the compliance process “approve invoice payment” that helps to satisfy the
“internal policy” cannot be executed since “ERP FI” is a prerequisite to execute this
compliance process. Additionally, the “logical access” becomes obsolete.
3</p>
      <p>
        Tool Architecture and Implementation
We developed the software prototype BCIT1, which is available as a cross-platform
desktop application, based on the software frameworks Node.js and Electron. Figure 2
describes the basic interaction between the components of BCIT to perform each user
step. When starting BCIT, the component app each create an object of process-view,
IT-architecture-view and compliance-view. According to [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], the user has to follow
three steps to analyze the interaction between BPC and business process change. First,
the necessary models business process, IT architecture and compliance requirements
have to be imported. Second, the appropriate elements of the imported models have to
be linked together, and third, the element that shall be changed has to be defined.
process-importer
IT-architectureimporter
process
model
ITarchitecture
model
compliance
compliance-importer model
process-view
      </p>
      <p>&lt;&lt;UI&gt;&gt;
IT-architecture-view</p>
      <p>&lt;&lt;UI&gt;&gt;
comp&lt;l&lt;iaUnIc&gt;e&gt;-view
process
model
model/
link
model
elements/
change
element
process-editor</p>
      <p>interaction-analyzer
process
model</p>
      <p>app
&lt;&lt;UI&gt;&gt;
model link model</p>
      <p>elements
graph-creator
link model
elements
graph
change
element
graph</p>
      <p>change
graph element
interaction-view
&lt;&lt;UI&gt;&gt;
result
graph
component
provided interface</p>
      <p>
        requested interface
1 Our prototype, the sourcecode, a screencast and further information can be found at:
http://informationsmanagement.wiwi.uni-halle.de/projekte/bcit/
Import Models: Within the component process-importer, we use bpmn-js [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], a
JavaScript library for parsing, visualizing and modifying BPMN process models to
import process models. This library is also used for the visualization of process models in
the component process-view. In addition, within the component
IT-architectureimporter, we built a parser that can read The Open Group's ArchiMate XML exchange
format to import IT architectures. The IT-architecture-view uses the graph library
Cytoscape [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] to visualize the IT components and their interrelations. Finally, the
component compliance-importer can import compliance requirements that are provided either
as JSON files or as formal XML files by the German Federal Ministry of Justice.
      </p>
      <p>
        Link Models: Next, the user must link the corresponding elements of the imported
models together. Here, the following relationships are possible: process flow element
and IT component, process flow element and compliance requirement, IT component
and compliance requirement, and compliance requirement and compliance
requirement. Technically, within the component graph-creator the imported models are
transformed into a single graph  = ( ,  ,  ,  ,  ) with its elements   ∈  . The graph is
modelled using the graph library Cytoscape [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. In this graph,  is a nonempty finite
set of vertices,   ∈  is a directed edge between two vertices (  ,   ) and   ∈  is the
unique identification (id) of the vertex   . In addition, ℎ ∈  is the model type of the
vertex   with  = { ,  ,   }, which corresponds to the imported model types process
( ), IT architecture ( ) or compliance requirement ( ). Finally,   ∈  contains the
individual properties of vertex   . In case a process flow element is marked as a
compliance process, this information is available in   ∈  .
      </p>
      <p>When linking two elements together, the graph-creator generates the corresponding
edges between the vertices of the linked elements. In the case of linking an IT
component or compliance requirement to the process, the process-editor (1) extends the
respective extension element of the process flow element by the id of the added vertex
and (2) adds a data storage symbol or rather a data symbol to the process flow element.
Then, the process-viewer visualize the updated process model again.</p>
      <p>Define the Element to be Changed: For analyzing the interactions between BPC
and business process change, the user has to define the element to be changed. This
element can be a compliance requirement, IT component, or a process flow element
that includes a compliance process. The interaction-analyzer always performs the
analysis when the interaction-view is opened. The analysis is based on the graph that was
generated and adjusted in the previous step. Figure 3 shows the algorithm used to
analyze the interactions between BPC and business process change by replacing an IT
component.</p>
      <p>Input: Graph g, element to be replaced v g where h=it architecture
1 // get all direct related compliance requirements and compliance processes to v
2 Foreach k in (get all predecessor of v where h=compliance requirement) do
3 mark k as direct AND add k including all vertices between k und v to result
4 // get all transitive related compliance processes and compliance requirements to v
5 Foreach it in (get all leafs of v where h=it architecture) do
8976 ForFoerkmaacerh=ackghaciettctr,iavliiatnclyt(pigivreniettdy(ega,celelcstrsdaoilarrnledocdfkticrpraerscetdterscauencsscsieotsrisvoorfANoDafcatitdidviwtthoyerwreheesh=ruelbtuhs=incoemspslpiarnocceesrse)qudoirement) do
10 Foreach complianceprocess in (get all direct successor of it where h=compliance process) do
111213 Formkaer=ackghietctr,alicnolm(ppglreieatdneaccleelpsrsodoicrreesoscf,tcsrcurcacensdskoraosftcroamnspliitainvceApNrDoacedsdstowhererseuhl=tcompliance requirement) do
14 generate result_graph based on g and result</p>
      <p>
        Output: Graph result_graph
Fig. 3. Algorithm to analyze interactions by replacing an IT component (based on [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ])
4
      </p>
      <p>Conclusion, Maturity and Future Work
In this paper we presented BCIT, a software prototype that is able to analyze the
interactions between BPC and business process change considering supporting IT
components and compliance requirements. The interaction between BPC and business process
change occurs in two cases. First, the changed element is affected by a compliance
requirement or a compliance process. Second, the changed element affects a
compliance requirement or a compliance process. More precisely, our software prototype
considers the business process change patterns “delete element” and “replace element”.</p>
      <p>Currently, BCIT considers the user-provided links between elements of the three
model types’ compliance requirements, processes and IT architectures. Furthermore,
only vertices of our single graph can be changed. As a consequent next step, we are
planning to add the data and resource perspectives on a business process to our
algorithm. Additionally, we are planning to extend BCIT by a function to add or remove
edges between individual IT components or compliance requirements. As a result, it is
possible to detect demands by compliance requirements and thus avoid compliance
violations due to changed relations between individual IT components or compliance
requirements.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Governatori</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sadiq</surname>
            ,
            <given-names>S.:</given-names>
          </string-name>
          <article-title>The Journey to Business Process Compliance</article-title>
          .
          <source>Handbook of research on business process modeling</source>
          ,
          <fpage>426</fpage>
          -
          <lpage>454</lpage>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Rinderle</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Reichert</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dadam</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Correctness criteria for dynamic changes in workflow systems--a survey</article-title>
          .
          <source>Data &amp; Knowledge Engineering</source>
          <volume>50</volume>
          ,
          <fpage>9</fpage>
          -
          <lpage>34</lpage>
          (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Seyffarth</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kühnel</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sackmann</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Business Process Compliance and Business Process Change. An Approach to Analyze the Interactions</article-title>
          .
          <source>Business Information Systems. BIS 2018. Lecture Notes in Business Information Processing</source>
          ,
          <fpage>176</fpage>
          -
          <lpage>189</lpage>
          (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Seyffarth</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kühnel</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sackmann</surname>
            ,
            <given-names>S.:</given-names>
          </string-name>
          <article-title>A Taxonomy of Compliance Processes for Business Process Compliance</article-title>
          .
          <source>15th International Conference on Business Process Management</source>
          ,
          <article-title>Business Process Management Forum</article-title>
          .
          <source>In: Lecture Notes in Business Information Processing (LNBIP)</source>
          (
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Rinderle-Ma</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Reichert</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Weber</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          :
          <article-title>On the Formal Semantics of Change Patterns in Process-aware Information Systems</article-title>
          .
          <source>Proc. 27th Int'l Conference on Conceptual Modeling (ER'08)</source>
          (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Camunda</surname>
          </string-name>
          <article-title>: bpmn-js</article-title>
          .
          <source>BPMN 2</source>
          .
          <article-title>0 for the web</article-title>
          , https://github.com/bpmn-io/bpmn-js
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Franz</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lopes</surname>
            ,
            <given-names>C.T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Huck</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dong</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sumer</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bader</surname>
          </string-name>
          , G.D.:
          <article-title>Cytoscape.js. A graph theory library for visualisation and analysis</article-title>
          .
          <source>Bioinformatics</source>
          (Oxford, England)
          <volume>32</volume>
          ,
          <fpage>309</fpage>
          -
          <lpage>311</lpage>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>