Enabling Risk-Aware Enterprise Modeling using Semantic Annotations and Visual Rules

The engagement in professional risk management is today a fact for most large organizations. In order to satisfy regulation and auditing requirements, an important step thereby is the identification and documentation of risks in an organization and the definition of measures for their mitigation. Thereby, the use of enterprise models provides the foundation for a systematic and holistic analysis of processes, organizational structures and IT systems. In the approach at hand we build upon the SeMFIS approach for semantic annotations of enterprise models with concepts from an OWL2 ontology. By providing an ontology for representing risks and mitigation measures, this additional information can be represented through annotations in arbitrary types of enterprise models without having to adapt the originally used modeling language. In addition, the approach provides a visual modeling language for representing rules according to the SWRL specification. This permits to process the semantic information provided by the annotations. The usage of the approach is illustrated through an example from the domain of risk-aware business process management. Upon the representation of risks in business processes using the semantic annotation approach, it is shown how SWRL rules can be used to automatically generate configurable risk reports.

[1]  M. Rosemann,et al.  Integrating Risks in Business Process Models , 2005 .

[2]  Michael Rosemann,et al.  Potential pitfalls of process modeling: part A , 2006, Bus. Process. Manag. J..

[3]  Hans-Georg Fill,et al.  European Conference on Information Systems ( ECIS ) 5-15-2012 AN APPROACH FOR ANALYZING THE EFFECTS OF RISKS ON BUSINESS PROCESSES USING SEMANTIC ANNOTATIONS , 2017 .

[4]  M. Durigon,et al.  Business Process Modeling Approaches in the Context of Process Level Audit Risk-Assessment: An Analysis and Comparison , 2006, Int. J. Account. Inf. Syst..

[5]  Hans-Georg Fill,et al.  SeMFIS: A flexible engineering platform for semantic annotations of conceptual models , 2017, Semantic Web.

[6]  Robert Winter,et al.  Modellierung für Integrated Enterprise Balancing , 2007, Wirtschaftsinf..

[7]  Marta Indulska,et al.  Integrated modelling of business process models and business rules: a research agenda , 2014 .

[8]  Moe Thandar Wynn,et al.  Current Research in Risk-aware Business Process Management - Overview, Comparison, and Gap Analysis , 2014, Commun. Assoc. Inf. Syst..

[9]  Rajkumar Roy,et al.  Operational risk analysis in business processes , 2007 .

[10]  Stefanie Betz,et al.  Risk-Aware Business Process Modeling and Simulation Using XML Nets , 2011, 2011 IEEE 13th Conference on Commerce and Enterprise Computing.

[11]  Sim Segal,et al.  Corporate Value of Enterprise Risk Management: The Next Step in Business Management , 2011 .

[12]  Hans-Georg Fill,et al.  On the Conceptualization of a Modeling Language for Semantic Model Annotations , 2011, CAiSE Workshops.

[13]  Benjamin N. Grosof,et al.  Supporting Rule System Interoperability on the Semantic Web with SWRL , 2005, SEMWEB.

[14]  Mark A. Musen,et al.  The protégé project: a look back and a look forward , 2015, SIGAI.

[15]  Alan Meech,et al.  Business Rules Using OWL and SWRL , 2010 .

[16]  Elena-Teodora Miron,et al.  OMiLAB: An Open Collaborative Environment for Modeling Method Engineering , 2016, Domain-Specific Conceptual Modeling.

[17]  V. Tummala,et al.  Assessing and Managing Risks Using the Supply Chain Risk Management Process (SCRMP) , 2011 .

[18]  Marta Indulska,et al.  Modeling languages for business processes and business rules: A representational analysis , 2009, Inf. Syst..

[19]  Gerald Quirchmayr,et al.  Enhancing Business Impact Analysis and Risk Assessment Applying a Risk-Aware Business Process Modeling and Simulation Methodology , 2008, 2008 Third International Conference on Availability, Reliability and Security.

[20]  Robert Woitsch,et al.  Adaptive Processes in E-Government - A Field Report about Semantic-Based Approaches from the EU-Project "FIT" , 2007, ICEIS.

[21]  Dominik Bork,et al.  Formal Aspects of Enterprise Modeling Methods: A Comparison Framework , 2014, 2014 47th Hawaii International Conference on System Sciences.

[22]  Martin J. O'Connor,et al.  SQWRL: A Query Language for OWL , 2009, OWLED.

[23]  Michael Rosemann,et al.  Integrating risks in business process models with value focused process engineering , 2006, ECIS.

[24]  Dimitris Karagiannis,et al.  On the Conceptualisation of Modelling Methods Using the ADOxx Meta Modelling Platform , 2013, Enterp. Model. Inf. Syst. Archit. Int. J. Concept. Model..

[25]  Dimitris Karagiannis,et al.  Enriching Linked Data with Semantics from Domain-Specific Diagrammatic Models , 2016, Bus. Inf. Syst. Eng..

[26]  Stefan Strecker,et al.  RiskM: A multi-perspective modeling method for IT risk assessment , 2011, Inf. Syst. Frontiers.

[27]  Samer Al Hawari,et al.  Knowledge-Based Risk Management framework for Information Technology project , 2012, Int. J. Inf. Manag..

[28]  Pascal Hitzler,et al.  A Metamodel and UML Profile for Rule-Extended OWL DL Ontologies , 2006, ESWC.

[29]  Raffaele Conforti,et al.  PRISM - A Predictive Risk Monitoring Approach for Business Processes , 2016, BPM.

[30]  Axel Winkelmann,et al.  Developing a Process-Oriented Notation for Modeling Operational Risks - A Conceptual Metamodel Approach to Operational Risk Management in Knowledge Intensive Business Processes within the Financial Industry , 2011, 2011 44th Hawaii International Conference on System Sciences.

[31]  Shazia Wasim Sadiq,et al.  Modeling Control Objectives for Business Process Compliance , 2007, BPM.

[32]  Michael zur Muehlen,et al.  Risk Management in the BPM Lifecycle , 2005, Business Process Management Workshops.

[33]  H. Lan,et al.  SWRL : A semantic Web rule language combining OWL and ruleML , 2004 .

[34]  Gerald Quirchmayr,et al.  Rope: A Methodology for Enabling the Risk-Aware Modelling and Simulation of Business Processes , 2007, ECIS.