Business Process Regulatory Compliance is Hard

Loading...
Thumbnail Image
File version

Accepted Manuscript (AM)

Author(s)
Tosatto, Silvano Colombo
Governatori, Guido
Kelsen, Pierre
Griffith University Author(s)
Primary Supervisor
Other Supervisors
Editor(s)
Date
2015
Size
File type(s)
Location
License
Abstract

Verifying whether a business process is compliant with a regulatory framework is a difficult task. In the present paper we prove the hardness of the business process regulatory compliance problem by taking into account a sub-problem of the general problem. This limited problem allows to verify only the compliance of structured processes with respect to a regulatory framework composed of a set of conditional obligations including a deadline. Experimental evidence from existing studies shows that compliance is a difficult task. In this paper, despite considering a sub-problem of the general problem, we provide some theoretical evidence of the difficulty of the task. In particular we show that the source of the complexity lies in the core language of verifying conditional obligations with a deadline. We prove that for this simplified case verifying partial compliance belongs to the class of NP-complete problems, and verifying full compliance belongs to the class of coNP-complete problems. Thus by proving the difficulty of a simplified compliance problem we prove that the general problem of verifying business process regulatory compliance is hard.

Journal Title

IEEE Transactions on Services Computing

Conference Title
Book Title
Edition
Volume

8

Issue

6

Thesis Type
Degree Program
School
Publisher link
Patent number
Funder(s)
Grant identifier(s)
Rights Statement
Rights Statement

© 2015 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.

Item Access Status
Note
Access the data
Related item(s)
Subject

Distributed computing and systems software

Information systems

Science & Technology

Computer Science, Software Engineering

Persistent link to this record
Citation

Tosatto, SC; Governatori, G; Kelsen, P, Business Process Regulatory Compliance is Hard, IEEE Transactions on Services Computing 2015, 8 (6), pp. 958-970

Collections