Score
Designs and operates processes and systems to obtain, verify, document, track, and renew individuals' work authorizations and related permits. Builds compliance controls, audit trails, reporting, and remediation procedures to ensure adherence to applicable laws, regulations, and organizational policies and to manage risks from unauthorized work.
This study addresses the lack of systematic comparative analysis in business process compliance monitoring, particularly for non-conformance checking techniques. Through a systematic literature review (SLR), process mining, compliance modeling, and qualitative comparative analysis, it maps real-world applications across domains, operational workflows, technical foundations, and result representations. The analysis identifies key implementation barriers—especially pervasive human dependence and the absence of standardized evaluation criteria. As the first structured survey framework dedicated to non-conformance checking, the study introduces a standardized, multi-dimensional evaluation framework that clarifies commonalities and distinctions across the technical landscape. It further proposes an extensible theoretical pathway and practical guidelines for automated compliance monitoring. This work provides a methodological foundation and strategic direction for both academic research and industrial deployment. (149 words)
本文提出PolicyGuide方法,通过将策略编译为工作流图并使用主动验证器来指导客服LLM代理遵循多步骤程序,从而提高策略合规性。
研究针对企业合规工作的效率和准确性需求,通过流程再造、系统建模和技术集成等方法,并结合RPA、规则引擎和语义识别技术优化辅助合规流程。
This study addresses widespread compliance issues in GitHub Actions workflows, such as excessive permissions and weak secret management. It proposes the first documentation-driven compliance checking framework, which derives a 30-item checklist from official documentation and implements a hybrid auditing pipeline combining large language models (LLMs) with expert oversight. The authors automatically evaluate 95 real-world Java workflows using four open-source LLMs, employ GPT-5 as a conflict arbitrator, and integrate manual review into a multi-tiered validation system. Experimental results reveal an overall compliance rate of only 28%, with permission control as low as 4%. The proposed approach reduces manual verification effort by 81% while achieving 87% agreement with expert judgments, significantly enhancing audit efficiency and reproducibility.
This study addresses a critical security vulnerability in AI coding agents wherein inconsistencies between user-approved and actually executed actions can be maliciously exploited. To systematically expose this threat, the work introduces a novel taxonomy termed "approval laundering," identifying six distinct failure modes that bypass user approval. Focusing on credential-binding integrity, the authors propose a defense mechanism based on key-capability tokens. The effectiveness of this approach is validated through PreToolUse hooks and statistical significance testing. Results demonstrate that the proposed token mechanism successfully mitigates delegation-based and temporal laundering attacks, establishing a new paradigm for AI agent security. Nevertheless, limitations persist regarding parameter-level and scope-level protections, indicating avenues for future research.
This study addresses the challenges posed by divergent and conflicting data protection regulations across jurisdictions, which hinder the early identification of compliance requirements in software development and often lead to costly rework and legal risks. Drawing on interviews with 70 legal experts from G20 and other countries, the research employs systematic content analysis and deductive qualitative methods to distill, for the first time from a legal expert perspective, both commonalities—such as consent—and key divergences—such as the right to be forgotten—across global data protection laws. These insights are innovatively operationalized into a comprehensive set of Data Protection Officer (DPO) user stories mapped to each phase of the software development lifecycle and enterprise architecture layers, significantly enhancing the actionable integration of compliance requirements into early-stage software engineering practices.
为解决多步骤工作流中的授权漂移问题,提出运行时授权一致性检查(RAC)方法,在控制器端边界处进行轻量级保护,有效减少了授权漂移遗漏。
This study addresses the challenges of dynamically managing compliance risks under Ukraine’s cybersecurity regulations and the complexity and error-proneness of manually constructing security profiles. To overcome these issues, the authors propose a novel approach that integrates Retrieval-Augmented Generation (RAG) with large language models (LLMs), harmonizing the ISO/IEC 27001 and NIST cybersecurity frameworks to automatically generate jurisdiction-specific target security profiles. By incorporating a vector database linked to a knowledge base of Ukrainian legal requirements and organizational policies, the method enables precise alignment between regulatory mandates and technical controls. This framework significantly reduces the need for manual intervention and associated error rates, offering a structured, AI-assisted workflow that effectively supports risk-driven cybersecurity compliance management.
本文针对工具使用型AI代理的授权架构问题,通过提出七个结构要求和四层参考架构来解决授权决策点、执行及问责机制不足的问题。
This study addresses the security blind spot in coding agents where approval logs fail to cover transitive side effects, proposing a closed-loop mechanism that binds approvals to workflow effect boundaries. Methodologically, it introduces the first formalized closed-loop approval security analysis framework, defining "approval laundering" as a quantifiable failure model and incorporating a source-supported effect prediction freezing strategy prior to authorization. The system implementation integrates information-theoretic limit derivations with pre-tool-call techniques. Experimental results demonstrate that the proposed approach significantly reduces residual unlogged events, achieving an effect prediction macro-recall of 0.926. By effectively curbing unrecorded persistent side effects, this work provides verifiable security guarantees for agent systems.