<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Apromore Compliance Center: A No-Code Solution to Process Compliance Management</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Nigel Adams</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Adriano Augusto</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Michael Davern</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Marcello La Rosa</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Download/Demo URL Documentation URL</string-name>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Apromore</institution>
          ,
          <country country="AU">Australia</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>University of Melbourne</institution>
          ,
          <country country="AU">Australia</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>The aim of process compliance is to ensure that processes are executed according to a prescribed set of rules determined by an organization's policies and legal obligations. Evidence suggests that achieving this goal is complex and elusive. For instance, US banks alone have been fined more than US$243bn for non-compliance since 2008. Although business process compliance is a mature field of research, there has been limited success in translating the research outputs into industry-ready solutions. In this paper, we present our Compliance Center tool, a comprehensive, end-to-end, “no-code" solution that aims to streamline process compliance by simplifying and integrating: the storage and management of risks, obligations, and controls; the validation and real-time checking of controls; and the reporting of detected violations. Our solution was built and integrated within Apromore, a process intelligence platform, and it was validated with a set of Apromore's largest customers.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Process compliance</kwd>
        <kwd>Process mining</kwd>
        <kwd>Apromore</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>Source code repository
Screencast video
Value</p>
    </sec>
    <sec id="sec-2">
      <title>1. Significance to the business process compliance field</title>
      <p>
        The aim of business process compliance (BPC) is to ensure that business processes are executed
in accordance with a prescribed set of rules or norms [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. The evidence would suggest that this
is challenging in practice. For instance, since 2008, US banks have been fined US$243bn for
compliance-related events. While, in Australia, regulators recently issued penalties exceeding
A$2bn against the four major domestic banks [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Previous research endeavors have identified
23 factors that underpin the challenges faced by the banking industry practitioners [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. These
factors fall into three broad categories: i) the extent of complex, frequently changing, compliance
requirements; ii) impenetrable spaghetti processes; and iii) significant organizational barriers to
implementing a sustainable case for change. In addition, for the Australian case, the regulators’
ifndings included recommendations to address governance concerns, the lack of documentation,
a reactive approach to compliance checking, the level of staf expertise, the time taken to identify
compliance violations and the ability to diagnose root cause. The research community has also
recognized that there are many challenges associated with BPC [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. For example: i) identifying
and expressing natural language compliance requirements is complex [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]; ii) “compliance by
design” [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] is a goal, yet not all compliance requirements can be evaluated at design-time [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ];
iii) some of the proposed solutions demand a level of technical expertise unlikely to be found in
a commercial setting [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ], and v) fully automating BPC may be beyond reach [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
      </p>
    </sec>
    <sec id="sec-3">
      <title>2. Apromore’s Compliance Center</title>
      <p>
        Despite the extent of the academic research and a technology sector targeting regulatory
monitoring, reporting, and compliance problems, a comprehensive solution is yet to be developed [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
To manage their compliance, heavily regulated organizations (e.g., banks) usually rely on a
combination of three systems: a risk, obligation, and control management system; one or more
systems to instantiate and run operational controls; and a reporting system that is fed the
controls result (e.g., a dashboard). This common setup is complex in nature and, for its deployment
and maintenance, requires a range of stakeholders with a variety of technical knowledge 1.
      </p>
      <p>Our compliance center integrates all the systems in one while simplifying the interaction
between the stakeholders and the tool by leveraging a no-code solution. In the following, we
describe the main features of our tool and their innovation.</p>
      <sec id="sec-3-1">
        <title>2.1. Creating risks, obligations, and controls: a built-in compliance register</title>
        <p>Our compliance center allows users to either i) import an existing risks, obligations, and controls
register or ii) create from scratch any risk, obligation, or control.</p>
        <p>In the first scenario, it is suficient to prepare and upload a CSV-format register (usually
available for download from existing risk management systems) containing at least four columns:
ID, type, name, and description of the item (risk, obligation, control). In addition, any number
of fields can be processed and loaded automatically. For example, the register in Fig. 1 contains
two risks, one obligation, and three controls and each item has three additional fields: category,
sub-category, and linked control (determining what control is assigned to a risk or obligation).</p>
        <p>Alternatively, the user can create (or edit) one compliance item at a time by filling in all its
data, as shown in Fig. 2. Once a risk or obligation is created or imported into the tool, controls
can be assigned to it – to document the purpose of the control (i.e., prevent a risk or ensure an
1Source: Apromore’s customer base.
obligation is met). Controls can be assigned manually (via the risk/obligation edit window) or
automatically (if documented in the imported register – as in Fig. 1, Column G).</p>
        <p>As compliance registers are constantly changing, the tool allows the user not only to manually
edit items in the register, but also to perform a bulk update by re-importing the register (this
will automatically overwrite existing items and/or create new ones).</p>
      </sec>
      <sec id="sec-3-2">
        <title>2.2. Operationalizing controls</title>
        <p>Once the controls documentation is
in place, the next step is to
operationalize the controls (i.e., apply
controls to processes). There
exists a variety of commercial
solutions to do so from BPM systems
that can assess process execution
rules to sophisticated ad-hoc
software bots. Our solution is based on
the concept of control templates. A
control template is an abstract set of
compliance patterns that, after
being instantiated on a process, must
be checked through the process data
during (or post) process execution.</p>
        <p>This allows the user to instantiate a
control on many diferent processes
by filling the control templates on a
process-by-process basis –
maximizing reuse-ability and minimizing time to instantiate controls.</p>
        <p>
          A user can assign to a control a range of templates (derived from traditional compliance
patterns [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ]) and combine them via Boolean logic to construct complex and sophisticated
templates which can capture escalation routines and violation exceptions. Fig. 2 shows how we
would assign templates to the control CAD Validity for the Risk CAD Breach (see Fig. 1, Rows 3
and 6). While Fig. 3 shows how we would instantiate the control for a process using its event
log (i.e., the process data).
        </p>
      </sec>
      <sec id="sec-3-3">
        <title>2.3. Reporting compliance results</title>
        <p>When a control is operationalized, it is immediately and automatically checked on the available
process data. Subsequently, at every new ingestion of process data, all operational controls
assigned to the process are automatically checked.</p>
        <p>Any detected violation during control checks is permanently recorded in the database. All
the recorded violations are available for analysis via a configurable dashboard which allows the
user to report on: total non-compliant and compliant cases; total, median, average, max and
min violations per case by control. These statistics can be captured via a range of graphical and
numerical dashboard widgets: tiles; charts; and tables – all of them automatically updated at
every new data ingestion, providing a real-time compliance monitoring experience to the user.
Fig. 4 shows an example of compliance monitoring dashboard.</p>
        <p>Screencast. A demo video of the features mentioned in this section is available at the link
on Page 1, alongside the risks, obligations, and controls register shown in Fig. 1.</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>3. Maturity</title>
      <p>Our Compliance Center went through a range of assessment cycles. During the prototyping
phase, we have evaluated the tool through a combination of focus groups and executive
interviews. We ran two focus groups comprising senior managers from one of the four major
banks in Australia, each with at least ten years’ banking experience in risk management,
operations, process excellence or technology. The first group was part of a project team focused on
re-imagining and designing new processes. The second group was an operations team working
with existing, mature processes. We also conducted three 30-minute interviews with senior
banking executives including a Chief Operating Oficer, a Chief Compliance Oficer, and a
Divisional Chief Risk Oficer, as well as two interviews with consulting Principals (each with
more than ten years’ experience, one in process excellence, the other in technology).</p>
      <p>The feedback received validated the underlying challenges and the broad applicability of the
solution. Specifically, participants emphasized the importance of supporting non-technical users
with a no-code solution, the potentially lower cost of operating the solution (being end-to-end),
the benefit of compliance checking the full transaction population and not just a sample, and
the opportunity for control standardization.</p>
      <p>As a mature process intelligence platform, Apromore has already been commercialized and
is licensed by clients in the banking industry around the world. The Compliance Center is an
add-on module to the process intelligence platform and, at the time of writing, two Australian
banks are already using our tool on their process data.</p>
    </sec>
    <sec id="sec-5">
      <title>4. Outlook and conclusion</title>
      <p>Having our Compliance Center integrated into a mature process intelligence platform will allow
us to rapidly expand our tool and integrate further process compliance functionalities, which
will serve a vast range of organizational needs sourced from the customers and the regulatory
environment. These include root-cause analysis and prediction of compliance violations;
realtime violation notifications; and assessment of compliance at design time by assigning controls
to a process model, simulating it, and checking the controls on the simulated data.</p>
      <p>Given the role of process compliance in a range of industries and the consequences of violating
it, we are confident that our tool has the potential to become an extremely valuable solution for
a range of organizations.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>G.</given-names>
            <surname>Governatori</surname>
          </string-name>
          ,
          <string-name>
            <surname>S. Sadiq,</surname>
          </string-name>
          <article-title>The journey to business process compliance</article-title>
          ,
          <source>IGI global</source>
          ,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>N.</given-names>
            <surname>Adams</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Augusto</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Davern</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. L.</given-names>
            <surname>Rosa</surname>
          </string-name>
          ,
          <article-title>Why do banks find business process compliance so challenging? an australian perspective</article-title>
          , in: International Conference on Business Process Management, Springer,
          <year>2022</year>
          , pp.
          <fpage>3</fpage>
          -
          <lpage>20</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>M.</given-names>
            <surname>Hashmi</surname>
          </string-name>
          , G. Governatori,
          <string-name>
            <given-names>H.-P.</given-names>
            <surname>Lam</surname>
          </string-name>
          , M. T. Wynn,
          <article-title>Are we done with business process compliance: state of the art and challenges ahead</article-title>
          ,
          <source>Knowledge and Information Systems</source>
          <volume>57</volume>
          (
          <year>2018</year>
          )
          <fpage>79</fpage>
          -
          <lpage>133</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>F. M.</given-names>
            <surname>Maggi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Montali</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Westergaard</surname>
          </string-name>
          ,
          <string-name>
            <surname>W. M. Van Der Aalst</surname>
          </string-name>
          ,
          <article-title>Monitoring business constraints with linear temporal logic: An approach based on colored automata</article-title>
          ,
          <source>in: International Conference on Business Process Management</source>
          , Springer,
          <year>2011</year>
          , pp.
          <fpage>132</fpage>
          -
          <lpage>147</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>A.</given-names>
            <surname>Elgammal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Turetken</surname>
          </string-name>
          , W.-J. van den Heuvel, M. Papazoglou,
          <article-title>On the formal specification of regulatory compliance: a comparative analysis</article-title>
          ,
          <source>in: International Conference on ServiceOriented Computing</source>
          , Springer,
          <year>2010</year>
          , pp.
          <fpage>27</fpage>
          -
          <lpage>38</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>A.</given-names>
            <surname>Barnawi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Awad</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Elgammal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Elshawi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Almalaise</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Sakr</surname>
          </string-name>
          ,
          <article-title>An antipattern-based runtime business process compliance monitoring framework, framework 7 (</article-title>
          <year>2016</year>
          )
          <fpage>551</fpage>
          -
          <lpage>572</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>S.</given-names>
            <surname>Sackmann</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Kuehnel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Seyfarth</surname>
          </string-name>
          ,
          <article-title>Using business process compliance approaches for compliance management with regard to digitization: evidence from a systematic literature review</article-title>
          ,
          <source>in: ICBPM</source>
          , Springer,
          <year>2018</year>
          , pp.
          <fpage>409</fpage>
          -
          <lpage>425</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>A.</given-names>
            <surname>Elgammal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Turetken</surname>
          </string-name>
          , W.-J. Van Den Heuvel, M. Papazoglou,
          <article-title>Formalizing and appling compliance patterns for business process compliance</article-title>
          ,
          <source>Software &amp; Systems Modeling</source>
          <volume>15</volume>
          (
          <year>2016</year>
          )
          <fpage>119</fpage>
          -
          <lpage>146</lpage>
          . URL: https://dx.doi.org/10.1007/s10270-014-0395-3. doi:
          <volume>10</volume>
          .1007/ s10270-014-0395-3.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>