<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Conformance Checking with Regulations - A Research Agenda</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Luise Pufahl</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Jana-Rebecca Rehse</string-name>
        </contrib>
      </contrib-group>
      <pub-date>
        <year>2021</year>
      </pub-date>
      <fpage>4</fpage>
      <lpage>9</lpage>
      <abstract>
        <p>Business processes need to follow prescribed regulations. For audits and for following good practices, organizations need to know whether regulations are followed or where and why deviations exist, such that they can manage their processes accordingly. Conformance checking, a key function of process mining, allows to check the relation between a process model and process data collected by IT systems, and to identify as well as analyze deviations between them. At the same time eforts exists to formalize laws, guidelines, and manuals in the computer-interpretable form of so-called reference process models. Hence, conformance checking appears to be a well-suited approach to automatically check whether a business process fulfills certain regulations, but several challenges need to be overcome. In this paper, we review existing research in this area, describe open research challenges, and design a research agenda to combine techniques from reference modeling and conformance checking to compare real-life process behavior with prescribed regulations. 1 Technische Universität Berlin, Software and Business Engineering, Einsteinufer 17, 10587 Berlin, Deutschland luise.pufahl@tu-berlin.de 2 Universität Mannheim, Juniorprofessur für Management Analytics, L15 1-6, 68161 Mannheim, Deutschland rehse@uni-mannheim.de</p>
      </abstract>
      <kwd-group>
        <kwd>Regulations</kwd>
        <kwd>Reference models</kwd>
        <kwd>Conformance checking</kwd>
        <kwd>Event log</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>Business processes often have to follow specific prescribed regulations, such as clinical
practice guidelines in healthcare, laws and statutes in public administration, or the new
hygiene rules in many diferent domains. For both organizational success and oficial audits,
it is essential to know: Are we following the prescribed regulations? If we deviate, why?
Should we improve employees’ training or system implementation ? Could the rules be
adapted to be better applicable in the real world?
Process mining provides insights into the business process execution and techniques
for evidence-based process analysis. Process conformance, a key function of process
mining, analyzes the relation between the designed and the recorded behavior of a business
process [Ca18]. A process model capturing the intended behavior of a business process as a
result of process modeling or process discovery is compared to an event log recorded during
the execution of a business process. It reveals overlaps and deviations, such as missing
activities, and hence allows organizations to answer the above-raised questions.
At the same time, eforts exist to formalize (suficiently concrete) laws, guidelines, and
manuals, such as clinical guidelines [Bo11] or youth welfare rules [Be18], in form of
business process models to increase the transparency, decrease ambiguities, and facilitate
stakeholders’ understanding. We define such models as reference models, i.e., conceptual
models that serve to be reused for the design of other conceptual models [FL06]. They
are often assumed to be universally applicable to a class of organizations and to exhibit a
certain quality, containing either best or common practices for conducting business [FL06].
Laws, guidelines, and manuals can be considered informal reference models, because they
are domain-specific, prescriptive, and universally applicable, but they exist in natural text.
Thus, they need to be transformed into computer-interpretable reference models.
These two developments make process conformance checking a well-suited approach to
automatically check whether a business process fulfills a certain regulations. However,
to leverage these potentials, major challenges need to be addressed. In the following, we
discuss existing works in Sect. 2, list open research challenges in Sect. 3, and describe our
research agenda in Sect. 4.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Overview of Existing Research</title>
      <p>Compliance Checking. Traditional compliance checking approaches rely on designed
business process models (design-time compliance) [AW09]. However, because those models
are often outdated or even non-existent [Ly15], compliance checking needs to take process
execution data into account. This data enables organizations to check whether a business
process follows the regulations by inspecting it on a case-by-case basis, either retrospectively
(auditing) or in real time (run-time compliance checking). Although multiple approaches
for run-time compliance or auditing exist, the practical application of these techniques still
faces serious limitations [Ha18], such as the extraction of formal representations of the
norms in an understandable format, the judgement of the deviation’s relevance and their
handling, and the evolution of business processes. One approach to address those challenges
is rule-based compliance checking, which automatically verifies whether process models
adhere to a certain set of (regulatory) rules. Although promising, there are many open
challenges in the practical management of such rules (within or separate from the process
models) [CD20]. Another approach to compliance checking on system execution data is
the application of complex event processing techniques [Kr20], which has also already
been used for the monitoring of business process execution [Kr14] and could therefore
be interesting for business process compliance as well. Overall, compliance checking
and conformance checking are closely related. Compliance checking is one application
case of conformance checking. Conformance checking is one technique for compliance
checking, which has the potential to address the above-mentioned practical challenges of
other compliance checking techniques. However, this would need a reliable conformance
basis and expressive visualizations.
Conformance Checking with Regulations. In existing research, we can observe that
conformance checking with regulations is domain-specific, fragmented, and no general
approach exists. Table 1 contains an overview of existing works, along with their domains,
regulatory documents, goals, and technical approaches. It shows that conformance checking
with regulations is already applied in several domains and that existing work has already
identified and targeted diferent challenges. Those challenges include the consideration of
organizational [JAV14] or temporal aspects [STD17] as well as contradicting [PTD18] or
cross-referencing regulations [Hu20]. Also, the non-conformance of process executions
to a regulation might be necessary or justified, such that positive (i.e., desired) deviations
need to be considered [Bo11]. In addition, regulations, corresponding reference models,
and process events logs are available in very diferent granularities, such that currently, it is
a manual efort to align the events with the activities in a reference model [GT09].</p>
      <p>Domain
Auditing
Data
Privacy
Protection
Healthcare</p>
      <p>Regulation
Auditing
rules
General
Data
tection
Regulation
Clinical
guidelines</p>
      <p>ProITSM</p>
      <p>ITIL</p>
      <p>Source
[JAV14]
[ZH20]
[STD17]
[Bo11]
[PTD18]
[GT09]</p>
      <p>Goal of conformance checking
As a new auditing procedure to detect
whether certain rules are fulfilled
Ascertaining compliance to certain
GDPR provisions, mainly related to
the data subject rights
Checking conformance of temporal
rules
Involving basic medical knowledge
in addition to the clinical guideline
aiming at providing a justification for
non-conformances
Explaining non-conformance by
considering that multiple clinical
guidelines exist
Improving the quality of IT
processes by comparing their execution to a
reference model representing incident
management in ITIL</p>
      <p>Technique
Manual approach where specific variants
and the interaction between involved staf
is checked
Manual approach where a process model
in a company is extended by GDPR
activities and temporal constraints for using
it as input for conformance checking
Answer set programming
Formalize Clinical Guidelines and
Medical Know-ledge as Event Calculus
Use the approach in [STD17] and use
ontologies to identify inter-actions between
clinical guidelines
Application of the token-replay in the
academic tool ProM, manual bridging
of granularity levels in log and reference
model
Visualization of conformance checking results. State-of-the-art conformance checking
methods usually compute an overall fitness or conformance measure between log and
model [Ca18]. If more details are required, they compare trace and model, illustrating the
deviations per trace [Ca18]. Existing approaches for conformance checking visualization on
the trace level were developed to convey research results rather than being optimized for
understandability. This is why there is a number of problems with these visualizations that
make them dificult to adapt. [ Ga17] provide textual representation of behavior deviations
to the users, which was perceived as simpler. Still, the authors promote future research in
this direction to improve the interpretability of conformance checking results.
Regulations and Conformance Checking 27
3</p>
    </sec>
    <sec id="sec-3">
      <title>Open Challenges</title>
      <p>Based on the above review of the state-of-the-art, we can summarize the research gap related
to conformance checking with regulations by means of three challenges:
Visualization: Conformance checking results need to be visualizedsuch that they provide
actual value for business users and allow to initiate actions based on the results. The
requirements by non-process expert business users are currently unclear and empirical
research on user-friendly visualizations are rare.</p>
      <p>Computer-interpretable regulations:. Regulations are only available as extensive and
informal documents. However, computer-interpretable (semi-)formal reference process
models are needed as input for conformance checking. So far, no general approaches exist
for supporting the (deductive) construction of such models.</p>
      <p>Generalized Approach:. A generalized approach for conformance checking with regulations
is missing. Such an approach should consider, among other aspects, diferent process
dimensions (such as control-flow, timestamps, and organizational aspects), cross-references
and contradicting relations between regulations, the opportunity of positive deviations, and
the right degree of abstraction between logs and models.
4</p>
    </sec>
    <sec id="sec-4">
      <title>Research Agenda</title>
      <p>Useful representation and visualization of conformance checking results. Guidelines
and regulations are usually generated by expert committees to reach a certain process quality
or to streamline the process execution. Organizations want to know how they are applying
them, and where improvements in IT systems, or trainings for employees are necessary.
Furthermore, some aspects of guidelines/regulations might not be applicable in reality such
that a feedback loop into the expert committees is useful. Thus, the objective is to identify
business users’ needs for representation and visualization to allow actions for handling
violations. Furthermore, it should be a goal to develop techniques to ease the representation
of conformance checking results for business users and to handle their complexity.
(Semi)-automatic support for deductive reference modeling. Conformance checking with
regulations needs as input a (semi-)formalized reference model. Currently, creating such
models is still a manual efort. It is the objective to develop a (semi-)automatic technique to
formalize a reference model based on a given textual description.</p>
      <p>Holistic conformance checking approach with regulations It is the objective to develop a
conformance checking approach, which considers the special aspects of regulations, such
as diferent dimensions (including control-flow, temporal, and organizational aspects), or
the existence of multiple competing or related regulations. Such an approach should be
able to handle non-conformance that might be justified with business knowledge or with
specific circumstances in the environment. In addition, event logs need to be available
on the abstraction level of the reference model representing the regulation to perform the
conformance checking.
[Be18]
[Bo11]
[Ca18]
[FL06]
[Ga17]
[CD20] Corea, Carl; Delfmann, Patrick: A Taxonomy of Business Rule Organizing Approaches in
Regard to Business Process Compliance. Enterprise Modelling and Information Systems
Architectures (EMISAJ), 15(4), 2020.</p>
      <p>Fettke, Peter; Loos, Peter: Reference modeling for business systems analysis. IGI Global,
2006.</p>
      <p>García-Bañuelos, Luciano; Van Beest, Nick RTP; Dumas, Marlon; La Rosa, Marcello;
Mertens, Willem: Complete and interpretable conformance checking of business processes.</p>
      <p>IEEE Transactions on Software Engineering, 44(3):262–290, 2017.
[GT09]
[Ha18]
[Hu20]
[Kr14]
[Kr20]
[Ly15]
Gerke, Kerstin; Tamm, Gerrit: Continuous Quality Improvement of IT Processes based on
Reference Models and Process Mining. AMCIS 2009 Proceedings, January 2009.
Hashmi, Mustafa; Governatori, Guido; Lam, Ho-Pun; Wynn, Moe Thandar: Are we done
with business process compliance: state of the art and challenges ahead. Knowledge and
Information Systems, 57(1):79–133, 2018.</p>
      <p>Hussung, Cai; Rehse, Jana-Rebecca; Houy, Constantin; Fettke, Peter: Entwicklung eines
Referenzprozessmodells für Rettungseinsätze der Feuerwehr und Anwendung als Grundlage
eines Prozessassistenzsystems. In: Internationale Tagung Wirtschaftsinformatik. 2020.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [AW09] Awad, Ahmed; Weske,
          <article-title>Mathias: Visualization of compliance violation in business process models</article-title>
          .
          <source>In: BPM</source>
          . Springer, pp.
          <fpage>182</fpage>
          -
          <lpage>193</lpage>
          ,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <string-name>
            <surname>Tagungsband</surname>
            <given-names>MKWI</given-names>
          </string-name>
          , pp.
          <fpage>633</fpage>
          -
          <lpage>644</lpage>
          ,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <string-name>
            <surname>Bottrighi</surname>
          </string-name>
          , Alessio; Chesani, Federico; Mello, Paola; Montali, Marco; Montani, Stefania; Terenziani, Paolo:
          <article-title>Conformance checking of executed clinical guidelines in presence of basic medical knowledge</article-title>
          .
          <source>In: BPM</source>
          . Springer, pp.
          <fpage>200</fpage>
          -
          <lpage>211</lpage>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <string-name>
            <surname>Carmona</surname>
          </string-name>
          , Josep; van Dongen, Boudewĳn; Solti, Andreas; Weidlich, Matthias: Conformance checking. Springer,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [JAV14] Jans, Mieke; Alles,
          <string-name>
            <given-names>Michael G</given-names>
            ; Vasarhelyi,
            <surname>Miklos</surname>
          </string-name>
          <string-name>
            <surname>A</surname>
          </string-name>
          :
          <article-title>A field study on the use of process mining of event logs as an analytical procedure in auditing</article-title>
          .
          <source>The Accounting Review</source>
          ,
          <volume>89</volume>
          (
          <issue>5</issue>
          ):
          <fpage>1751</fpage>
          -
          <lpage>1773</lpage>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          <string-name>
            <surname>Krumeich</surname>
          </string-name>
          , Julian; Weis, Benjamin; Werth, Dirk; Loos, Peter:
          <article-title>Event-Driven Business Process Management: where are we now?: A comprehensive synthesis and analysis of literature</article-title>
          .
          <source>Business Process Management Journal</source>
          ,
          <volume>20</volume>
          (
          <issue>4</issue>
          ):
          <fpage>615</fpage>
          -
          <lpage>633</lpage>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          <string-name>
            <surname>Krieger</surname>
          </string-name>
          , Christoph; Breitenbücher, Uwe; Falkenthal, Michael; Leymann, Frank; Yussupov, Vladimir; Zdun,
          <article-title>Uwe: Monitoring Behavioral Compliance with Architectural Patterns Based on Complex Event Processing</article-title>
          .
          <source>In (Brogi</source>
          , Antonio; Zimmermann, Wolf; Kritikos, Kyriakos, eds):
          <source>Service-Oriented and Cloud Computing</source>
          . Springer, pp.
          <fpage>125</fpage>
          -
          <lpage>140</lpage>
          ,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          <string-name>
            <surname>Ly</surname>
          </string-name>
          , Linh Thao; Maggi, Fabrizio Maria; Montali, Marco; Rinderle-Ma, Stefanie; van der Aalst,
          <string-name>
            <surname>Wil</surname>
            <given-names>MP</given-names>
          </string-name>
          :
          <article-title>Compliance monitoring in business processes: Functionalities, application, and tool-support</article-title>
          .
          <source>Information systems</source>
          ,
          <volume>54</volume>
          :
          <fpage>209</fpage>
          -
          <lpage>234</lpage>
          ,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [PTD18] Piovesan, Luca; Terenziani, Paolo; Dupré, Daniele Theseider:
          <article-title>Temporal Conformance Analysis and Explanation on Comorbid Patients</article-title>
          . In: HEALTHINF. pp.
          <fpage>17</fpage>
          -
          <lpage>26</lpage>
          ,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [STD17] Spiotta, Matteo; Terenziani, Paolo; Dupré, Daniele Theseider:
          <article-title>Temporal conformance analysis and explanation of clinical guidelines execution</article-title>
          .
          <source>IEEE Transactions on Knowledge and Data Engineering</source>
          ,
          <volume>29</volume>
          (
          <issue>11</issue>
          ):
          <fpage>2567</fpage>
          -
          <lpage>2580</lpage>
          ,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          <string-name>
            <surname>Zaman</surname>
          </string-name>
          , Rashid; Hassani, Marwan:
          <article-title>On Enabling GDPR Compliance in Business Processes Through Data-Driven Solutions</article-title>
          .
          <source>SN Computer Science</source>
          ,
          <volume>1</volume>
          (
          <issue>4</issue>
          ):
          <fpage>210</fpage>
          ,
          <year>June 2020</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>