AI 中文总结
研究针对财务控制测试依赖ERP数据但直接复制有风险的问题,提出SEQ-FCT框架,结合多种技术,用合成数据集评估,与多种基线对比,在对账、欺诈触发召回率、控制失败等方面取得较好结果,表明综合评估更可靠。
AI 中文摘要
财务控制测试越来越依赖高质量环境中的代表性企业资源规划(ERP)数据,但直接复制生产数据会暴露个人、供应商、银行和商业敏感记录。本文提出了用于财务控制测试的安全ERP质量供应(SEQ-FCT),这是一个受治理的数据供应框架,结合了确定性掩码、合成场景扩展、引用令牌化、基于策略的发布批准以及用于对账、欺诈规则测试和审计分析的自动验证。使用单个合成数据集进行评估,该数据集包含2022 - 2025年来自六个子公司的186,000条财务流程记录。与生产克隆上限、静态掩码、仅规则合成、条件表格生成合成和混合基线相比,SEQ-FCT取得了0.932的对账F1、0.887的欺诈触发召回率、0.914的控制失败F1以及估计为0.018的泄漏风险分数。分析表明,当将掩码、合成数据和治理检查作为单个发布管道而不是独立实用程序进行评估时,可以更可靠地保留财务流程行为。
英文摘要
Financial control testing increasingly depends on representative enterprise resource planning (ERP) data in quality environments, yet direct production copies expose personal, supplier, banking, and commercially sensitive records. This work presents Secure ERP Quality Provisioning for Financial Control Testing (SEQ-FCT), a governed data-provisioning framework that combines deterministic masking, synthetic scenario expansion, referential tokenization, policy-based release approval, and automated validation for reconciliation, fraud-rule testing, and audit analytics. A single synthetic dataset is used for evaluation. It contains 186,000 finance-process records from six subsidiaries over 2022-2025, including accounts payable invoices, payments, general-ledger journals, accounts receivable receipts, and bank-statement lines. The dataset includes entity relationships, monetary values, approval paths, tax attributes, banking markers, exception labels, fraud-rule triggers, and control-failure outcomes. Because the dataset is synthetic, reported results demonstrate controlled internal consistency rather than production validation. Against a production-clone upper bound, static masking, rules-only synthesis, conditional tabular generative synthesis, and a hybrid baseline, SEQ-FCT achieved 0.932 reconciliation F1, 0.887 fraud-trigger recall, 0.914 control-failure F1, and an estimated leakage-risk score of 0.018. The analysis indicates that financial process behavior can be preserved more reliably when masking, synthetic data, and governance checks are evaluated as a single release pipeline instead of independent utilities.