发表机构
Bristol Research and Innovation Laboratory (BRIL); Toshiba Europe Ltd.; Queen’s University Belfast(布里斯托尔研究与创新实验室(BRIL); 东芝欧洲有限公司; 贝尔法斯特女王大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出基于RAG的CTRAG框架,通过自适应分块、动态检索配置等策略实现自动化合规检查,在四大会计师事务所POC中F1达78%、召回85%,可减少手动工作量并提升监管信任。
AI 中文摘要
信任是现代监管生态系统的基础,合规检查在培育这种信任方面发挥着关键作用。对于在高度受控环境中运营的企业而言,监管合规验证至关重要,因为它确保企业符合财务报告、数据隐私、网络安全等领域的特定行业准则。然而,手动合规测试通常耗时且易出现不一致性,尤其是当合规性间接依赖第三方服务(如云提供商)时,供应商需依靠外部提供商来满足监管标准。在本文中,我们提出CTRAG,一种用于自动化合规检查的新型检索增强生成(RAG)流水线。CTRAG采用自适应分块、动态检索配置和上下文学习等先进策略,以提高合规评估的精度和相关性。通过从监管文本中提取控制问题,并将其与非结构化公司文档交叉核对,CTRAG实现了高度准确的、基于文档的合规验证,即使在通过第三方服务实现间接合规的情况下也能胜任。实证评估显示出显著改进:在最终部署配置中,CTRAG的F1分数达到78%,召回率达到85%,确保尽可能少漏报不合规案例,同时在实际部署中减少手动审核人员的工作量。为验证CTRAG的价值,我们在一家四大专业服务公司内开发并部署了一个POC,将其应用于实际案例,并将结果与手动合规报告进行交叉核对。这些发现凸显CTRAG有望简化合规工作流程、降低风险,并在复杂高风险环境中增强监管信任。
英文摘要
Trust is fundamental in modern regulatory ecosystems, and compliance checking plays a critical role in fostering that trust. Regulatory compliance verification is essential for businesses operating in highly controlled environments, as it ensures alignment with sector-specific guidelines across domains such as financial reporting, data privacy, and cybersecurity. Manual compliance testing, however, is often time-intensive and prone to inconsistencies, particularly when compliance depends indirectly on third-party services such as cloud providers, where vendors rely on external providers to meet regulatory standards. In this paper, we present CTRAG, a novel Retrieval-Augmented Generation (RAG) pipeline designed for automated compliance checking. CTRAG employs advanced strategies, including adaptive chunking, dynamic retrieval configurations, and in-context learning, to improve the precision and relevance of compliance assessments. By extracting control questions from regulatory texts and cross-referencing them with unstructured company documentation, CTRAG achieves highly accurate, document-informed compliance verification, even in cases of indirect compliance through third-party services. Empirical evaluations demonstrate significant improvements, with CTRAG achieving an F1-score of 78% and a recall of 85% in the final deployed configuration, ensuring minimal missed non-compliance cases while reducing manual reviewer effort in a real-world deployment. To validate CTRAG value, we developed and deployed a POC within a Big Four professional services firm, applying it to real-world cases and cross-checking results against manual compliance reports. These findings highlight CTRAG potential to streamline compliance workflows, mitigate risks, and enhance regulatory trust in complex, high-stakes environments.
Comments10 pages, 5 figures, 8 tables