Are we done with business process compliance: state of the art and challenges ahead

被引:75
|
作者
Hashmi, Mustafa [1 ]
Governatori, Guido [1 ]
Lam, Ho-Pun [1 ]
Wynn, Moe Thandar [2 ]
机构
[1] CSIRO, Data61, 41 Boggo Rd, Dutton Pk, Qld 4102, Australia
[2] Queensland Univ Technol, 2 George St, Brisbane, Qld 4000, Australia
关键词
Business processes; Business process compliance; Norms compliance; Normative requirements; Compliance management frameworks; COMPLIANCE-CHECKING; REGULATORY COMPLIANCE; MODEL-CHECKING; REQUIREMENTS; MANAGEMENT; LOGIC; SPECIFICATION; CONSTRAINTS; VALIDATION; FRAMEWORK;
D O I
10.1007/s10115-017-1142-1
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Literature on business process compliance (BPC) has predominantly focused on the alignment of the regulatory rules with the design, verification and validation of business processes. Previously, surveys on BPC have been conducted with specific context in mind; however, the literature on BPC management research is largely sparse and does not accumulate a detailed understanding on existing literature and related issues faced by the domain. This survey provides a holistic view of the literature on existing BPC management approaches and categorises them based on different compliance management strategies in the context of formulated research questions. A systematic literature approach is used where search terms pertaining keywords were used to identify literature related to the research questions from scholarly databases. From initially 183 papers, we selected 79 papers related to the themes of this survey published between 2000 and 2015. The survey results reveal that mostly compliance management approaches centre around three distinct categories, namely design-time (28%), run-time (32%) and auditing (10%). Also, organisational and internal control-based compliance management frameworks (21%) and hybrid approaches make (9%) of the surveyed approaches. Furthermore, open research challenges and gaps are identified and discussed with respect to the compliance problem.
引用
收藏
页码:79 / 133
页数:55
相关论文
共 50 条
  • [31] Formalizing and appling compliance patterns for business process compliance
    Elgammal, Amal
    Turetken, Oktay
    van den Heuvel, Willem-Jan
    Papazoglou, Mike
    SOFTWARE AND SYSTEMS MODELING, 2016, 15 (01): : 119 - 146
  • [32] Formalizing and appling compliance patterns for business process compliance
    Amal Elgammal
    Oktay Turetken
    Willem-Jan van den Heuvel
    Mike Papazoglou
    Software & Systems Modeling, 2016, 15 : 119 - 146
  • [33] Business Process Compliance and Business Process Change: An Approach to Analyze the Interactions
    Seyffarth, Tobias
    Kuehnel, Stephan
    Sackmann, Stefan
    BUSINESS INFORMATION SYSTEMS (BIS 2018), 2018, 320 : 176 - 189
  • [34] Workflow Signatures for Business Process Compliance
    Lim, Hoon Wei
    Kerschbaum, Florian
    Wang, Huaxiong
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2012, 9 (05) : 756 - 769
  • [35] Norm Compliance in Business Process Modeling
    Governatori, Guido
    Rotolo, Antonino
    SEMANTIC WEB RULES, 2010, 6403 : 194 - +
  • [36] Modeling and Analysis of Business Process Compliance
    Becker, Joerg
    Ahrendt, Christoph
    Coners, Andre
    Weiss, Burkhard
    Winkelmann, Axel
    GOVERNANCE AND SUSTAINABILITY IN INFORMATION SYSTEMS: MANAGING THE TRANSFER AND DIFFUSION OF IT, 2011, 366 : 259 - 269
  • [37] Business Process Regulatory Compliance is Hard
    Tosatto, Silvano Colombo
    Governatori, Guido
    Kelsen, Pierre
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2015, 8 (06) : 958 - 970
  • [38] Compliance aware business process design
    Lu, Ruopeng
    Sadiq, Shazia
    Governatori, Guido
    BUSINESS PROCESS MANAGEMENT WORKSHOPS, 2008, 4928 : 120 - 131
  • [39] A Roadmap for Research in Business Process Compliance
    Sadiq, Shazia
    BUSINESS INFORMATION SYSTEMS WORKSHOPS (BIS 2011), 2011, 97 : 1 - 4
  • [40] Towards a Framework for Business Process Compliance
    Ghanavati, Sepideh
    Amyot, Daniel
    Siena, Alberto
    Susi, Angelo
    Perini, Anna
    2010 14TH IEEE INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING CONFERENCE WORKSHOPS (EDOCW 2010), 2010, : 330 - 334