Ensuring the compliance of business processes with a set of requirements stemming from, for example, laws or regulations, is crucial for companies. When these requirements change, process compliance may be violated, resulting in either non-compliance, where updated requirements are no longer satisfied, or over-compliance, where processes adhere to stricter requirements than necessary. In both cases, this can result in financial or even reputational loss. This work provides an automated hybrid approach combining LLM-based and algorithmic steps for continuously analyzing the impact of regulatory requirement changes on business process compliance providing traceability through delta analysis and explanations on compliance deviations. To address this objective, we present the modular Requirements Change for Process Compliance (RC4PC) approach consisting of three steps. First, we provide a definition of regulatory requirements based on deontic logic allowing to formally represent requirements written in natural language. Second, we extract atomic change operations capturing the differences between an original and a modified requirement. Lastly, we assess the impact of changes on compliance of a process model and provide explanations for compliance deviations. RC4PC concepts are implemented using a combination of LLM-based and algorithmic steps. Change deltas plus explanations provided by the LLM can be taken as input for mitigation actions in case of compliance deviations and contribute to continuous compliance monitoring. RC4PC is evaluated on three datasets from different domains and in comparison with existing baselines and existing approaches. The results show promising results for each of the steps. Occasional drops in precision, due to inconsistent representations and redundancy, indicate the need for normalization and improved handling of related changes. RC4PC provides modular and transparent Gen-AI supported approach for analyzing how regulatory requirement changes affect business process compliance. It is domain-independent and can be equipped with existing techniques such as model-checking.
Barrientos et al. (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: