{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T16:55:56Z","timestamp":1784912156119,"version":"3.55.0"},"reference-count":199,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2018,1,22]],"date-time":"2018-01-22T00:00:00Z","timestamp":1516579200000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Knowl Inf Syst"],"published-print":{"date-parts":[[2018,10]]},"DOI":"10.1007\/s10115-017-1142-1","type":"journal-article","created":{"date-parts":[[2018,1,22]],"date-time":"2018-01-22T14:34:28Z","timestamp":1516631668000},"page":"79-133","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":124,"title":["Are we done with business process compliance: state of the art and challenges ahead"],"prefix":"10.1007","volume":"57","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6376-082X","authenticated-orcid":false,"given":"Mustafa","family":"Hashmi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Guido","family":"Governatori","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ho-Pun","family":"Lam","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Moe Thandar","family":"Wynn","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2018,1,22]]},"reference":[{"key":"1142_CR1","doi-asserted-by":"crossref","unstructured":"Abdullah NS, Sadiq S, Indulska M (2010) Emerging challenges in information systems research for regulatory compliance management. In: Proceedings of CAiSE\u201910. Springer, pp 251\u2013265","DOI":"10.1007\/978-3-642-13094-6_21"},{"issue":"6","key":"1142_CR2","doi-asserted-by":"crossref","first-page":"568","DOI":"10.1016\/j.infsof.2014.02.001","volume":"56","author":"P Achimugu","year":"2014","unstructured":"Achimugu P, Selamat A, Ibrahim R, Mahrin MN (2014) A systematic literature review of software requirements prioritization research. Inf Softw Technol 56(6):568\u2013585","journal-title":"Inf Softw Technol"},{"key":"1142_CR3","unstructured":"\u00c5gotnes T, van\u00a0der Hoek W, Rodr\u00edguez-Aguilar JA, Sierra C, Wooldridge M (2007) On the Logic of Normative Systems. In: Proceedings of the 20th international joint conference on artificial intelligence. AAAI Press, Menlo Park, pp 1175\u20131180"},{"issue":"1","key":"1142_CR4","first-page":"4","volume":"18","author":"T \u00c5gotnes","year":"2010","unstructured":"\u00c5gotnes T, Van der Hoek W, Wooldridge M (2010) Robust normative systems and a logic of norm compliance. J Log 18(1):4\u201330","journal-title":"J Log"},{"key":"1142_CR5","doi-asserted-by":"crossref","unstructured":"Agrawal R, Bayardo R, Faloutsos C, Kiernan J, Rantzau R, Srikant R (2004) Auditing compliance with a hippocratic database. In: Proceedings of the thirtieth international conference on very large data bases, vol 30, VLDB Endowment, VLDB \u201904, pp 516\u2013527","DOI":"10.1016\/B978-012088469-8.50047-4"},{"key":"1142_CR6","doi-asserted-by":"crossref","unstructured":"Agrawal R, Johnson C, Kiernan J, Leymann F (2006) Taming compliance with Sarbanes\u2013Oxley internal controls using database technology. In: Proceedings of the 22nd international IEEE conference on data engineering, p\u00a092","DOI":"10.1109\/ICDE.2006.155"},{"key":"1142_CR7","unstructured":"Ahmed A, Sakr S (2010) Querying graph-based repositories of business process models. In: DASFAA workshops, pp 33\u201344"},{"key":"1142_CR8","unstructured":"Alberti M, Chesani F, Gavanelli M, Lamma E, Mello P, Montali M, Torroni P (2007) Expressing and verifying business contracts with abductive. In: Boella G, van\u00a0der Torre L, Verhagen H (eds) Normative multi-agent systems, Internationales Begegnungs- und Forschungszentrum f\u00fcr Informatik (IBFI), Schloss Dagstuhl, Germany, Dagstuhl, Germany, No. 07122 in Dagstuhl seminar proceedings"},{"issue":"7","key":"1142_CR9","doi-asserted-by":"crossref","first-page":"109","DOI":"10.1145\/1272516.1272522","volume":"50","author":"AI Ant\u00f3n","year":"2007","unstructured":"Ant\u00f3n AI, Bertino E, Li N, Yu T (2007) A roadmap for comprehensive online privacy policy management. Commun ACM 50(7):109\u2013116","journal-title":"Commun ACM"},{"key":"1142_CR10","first-page":"108","volume-title":"ISoLA\u201908","author":"F Arbab","year":"2008","unstructured":"Arbab F, Kokash N, Meng S (2008) Towards using REO for compliance-aware business process modeling. In: Margaria T, Steffen B (eds) ISoLA\u201908, vol 17. Springer, Berlin, pp 108\u2013123"},{"key":"1142_CR11","unstructured":"Arya A, van Dongen B, van\u00a0der Aalst W (2010) Towards robust conformance checking. In: BPM workshops\u201910, pp 122\u2013133"},{"key":"1142_CR12","first-page":"406","volume":"1","author":"S Ashby","year":"2008","unstructured":"Ashby S (2008) Operational risk: lessons from non-financial organisations. J Risk Manag Financ Inst 1:406\u2013415","journal-title":"J Risk Manag Financ Inst"},{"key":"1142_CR13","unstructured":"Awad A (2010) A compliance management framework for business process models. Ph.D. thesis, Hasso Plattner Institut, Potsdam University, Germany"},{"key":"1142_CR14","unstructured":"Awad A, Weske M (2009) Visualisation of compliance violations in business process models. In: 5th Workshop on business process intelligence, vol\u00a09, pp 182\u2013193"},{"key":"1142_CR15","doi-asserted-by":"crossref","unstructured":"Awad A, Decker G, Weske M (2008) Efficient compliance checking using BPMN-Q and temporal logic. In: Proceedings of the 6th international conference on business process management (BPM 2008). Springer, Milano, pp 326\u2013341","DOI":"10.1007\/978-3-540-85758-7_24"},{"key":"1142_CR16","unstructured":"Awad A, Smirnov S, Weske M (2009) Towards resolving compliance violations in business process models. In: Sadiq S, Indulska M, zur Muehlen M, Dubois E, Johannesson P (eds) Proceedings of the 2nd international workshop on governance risk and compliance GRCIS, pp 18\u201333"},{"key":"1142_CR17","doi-asserted-by":"crossref","unstructured":"Awad A, Weidlich M, Weske M (2009) Specification, verification and explanation of violation for data aware compliance rules. In: Baresi L, Chi CH, Suzuki J (eds) Proceedings of the 7th international joint conference on service-oriented computing (ICSOC-Service Wave 2009). Springer, Stockholm, pp 500\u2013515","DOI":"10.1007\/978-3-642-10383-4_37"},{"key":"1142_CR18","doi-asserted-by":"crossref","unstructured":"Bai X, Liu Y, Wang L, Tsai WT, Zhong P (2009) Model-based monitoring and policy enforcement of services. In: Proceedings of the 2009 world conference on services, vol\u00a0I, pp 789 \u2013796","DOI":"10.1109\/SERVICES-I.2009.103"},{"issue":"2","key":"1142_CR19","first-page":"551","volume":"7","author":"A Barnawi","year":"2016","unstructured":"Barnawi A, Awad A, Elgammal A, Elshawi R, Almalaise A, Sakr S (2016) An anti-pattern-based runtime business process compliance monitoring framework. Int J Adv Comput Sci Appl (IJACSA) 7(2):551\u2013572","journal-title":"Int J Adv Comput Sci Appl (IJACSA)"},{"key":"1142_CR20","unstructured":"Bartolini R, Lenci A, Montemagni S, Pirrelli V, Soria C (2004) Semantic mark-up of Italian legal texts through NLP-based techniques. In: Proceedings of the fourth international conference on language resources and evaluation (LREC 2004), Lisbon, Portugal"},{"key":"1142_CR21","unstructured":"BCBS (2013) Basel III: The liquidity coverage ratio and liquidity risk monitoring tools. http:\/\/www.bis.org\/publ\/bcbs238.pdf"},{"issue":"12","key":"1142_CR22","doi-asserted-by":"crossref","first-page":"5219","DOI":"10.1016\/j.eswa.2015.02.029","volume":"42","author":"T Beach","year":"2015","unstructured":"Beach T, Rezgui Y, Li H, Kasim T (2015) A rule-based semantic approach for automated regulatory compliance in the construction sector. Expert Syst Appl 42(12):5219\u20135231","journal-title":"Expert Syst Appl"},{"issue":"2","key":"1142_CR23","doi-asserted-by":"crossref","first-page":"221","DOI":"10.1007\/BF03342739","volume":"5","author":"J Becker","year":"2012","unstructured":"Becker J, Delfmann P, Eggert M, Schwittay S (2012) Generalizability and applicability of model-based business process compliance-checking approaches\u2013a state-of-the-art analysis and research roadmap. BuR Bus Res J 5(2):221\u2013247","journal-title":"BuR Bus Res J"},{"key":"1142_CR24","doi-asserted-by":"crossref","unstructured":"Bench-Capon T, Gordon TF (2009) Isomorphism and argumentation. In: Proceedings of the 12th international conference on artificial intelligence and law, ACM, NY, USA. ICAIL\u201909, pp 11\u201320","DOI":"10.1145\/1568234.1568237"},{"issue":"1","key":"1142_CR25","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1007\/BF00118479","volume":"1","author":"TJM Bench-Capon","year":"1992","unstructured":"Bench-Capon TJM, Coenen FP (1992) Isomorphism and legal knowledge based systems. Artif Intell Law 1(1):65\u201386","journal-title":"Artif Intell Law"},{"key":"1142_CR26","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-662-04558-9","volume-title":"System and software verification\u2013model checking techniques and tools","author":"B B\u00e9rard","year":"2001","unstructured":"B\u00e9rard B, Bidoit M, Finkel A, Laroussinie F, Petit A, Petrucci L, Schnoebelen P (2001) System and software verification\u2013model checking techniques and tools. Springer, Berlin"},{"key":"1142_CR27","volume-title":"Moving beyond the baseline Leveraging the compliance function to gain a competitive edge: state of compliance survey 2015","author":"S Bernstein","year":"2015","unstructured":"Bernstein S, Falcione A (2015) Moving beyond the baseline Leveraging the compliance function to gain a competitive edge: state of compliance survey 2015. Survey report, Pricewaterhousecoopers"},{"key":"1142_CR28","doi-asserted-by":"crossref","unstructured":"Bhattacharya K, Gerede C, Hull R, Liu R, Su J (2007) Towards formal analysis of artifact-centric business process models. In: Alonso G, Dadam P, Rosemann M (eds) Proceedings of the 5th international conference on business process management (BPM 2007). Springer, Berlin, pp 288\u2013304","DOI":"10.1007\/978-3-540-75183-0_21"},{"key":"1142_CR29","doi-asserted-by":"crossref","unstructured":"Biagioli C, Francesconi E, Passerini A, Montemagni S, Soria C (2005) Automatic semantics extraction in law documents. In: Proceedings of the 10th international conference on artificial intelligence and law, ACM, New York, NY, USA, ICAIL\u201905, pp 133\u2013140","DOI":"10.1145\/1165485.1165506"},{"key":"1142_CR30","doi-asserted-by":"crossref","unstructured":"Birukou A, D\u2019Andrea V, Leymann F, Serafinski J, Silveira P, Strauch S, Tluczek M (2010) An integrated solution for runtime compliance Governance in SOA. In: Proceeding of international conference on service-oriented computing (ICSOC), pp 122\u2013136","DOI":"10.1007\/978-3-642-17358-5_9"},{"key":"1142_CR31","unstructured":"Bonatti PA, Shahmehri N, Duma C, Olmedilla D, Nejdl W, Baldoni M, Baroglio C, Martelli A, Coraggio P, Antoniou G, Peer J, Fuchs NE (2004) Rule-based policy specification: state of the art and future work. Rewerse project report-i2-d1, Universit\u00e1 di Napoli Fedrecio II"},{"key":"1142_CR32","unstructured":"Bonazzi R, Pigneur Y (2009) Compliance management in multi-actor contexts. In: Proceedings of international workshop on governance, risk and compliance (GRCIS), An ancillary meeting of CAISE"},{"key":"1142_CR33","doi-asserted-by":"crossref","unstructured":"Brighi R, Palmirani M (2009) Legal text analysis of the modification provisions: a pattern oriented approach. In: Proceedings of the 12th international conference on artificial intelligence and law (ICAIL\u201909), ACM, New York, NY, USA, pp 238\u2013239","DOI":"10.1145\/1568234.1568272"},{"key":"1142_CR34","unstructured":"Cabanillas C, Resinas M, Ruiz-Cort\u00e9s A (2010) On the identification of data-related compliance problems in business processes. In: Jornadas Cient\u00edfico-T\u00e9cnicas En Servicios Web Y SOA (JSWEB\u201910), Valencia, Espa\u00f1a, vol\u00a01, pp 89\u2013102"},{"key":"1142_CR35","unstructured":"COBIT (2007) Control objectives for information related technology\u2014COBIT 4.1. http:\/\/www.isaca.org\/Knowledge-Center\/cobit\/Pages\/Downloads.aspx"},{"issue":"6","key":"1142_CR36","doi-asserted-by":"crossref","first-page":"958","DOI":"10.1109\/TSC.2014.2341236","volume":"8","author":"S Colombo Tosatto","year":"2015","unstructured":"Colombo Tosatto S, Governatori G, Kelsen P (2015) Business process regulatory compliance is hard. IEEE Trans Serv Comput 8(6):958\u2013970","journal-title":"IEEE Trans Serv Comput"},{"key":"1142_CR37","unstructured":"COMPAS-Project (2008) D2.1 state-of-the-art in the field of compliance languages\u2014compliance-driven models, languages, and architectures for services. Deliverable D2.1v1.0, Tilburg University, The Netherlands"},{"issue":"1","key":"1142_CR38","first-page":"104","volume":"1","author":"HM Cooper","year":"1988","unstructured":"Cooper HM (1988) Organizing knowledge syntheses: a taxonomy of literature reviews. Knowl Soc 1(1):104\u2013126","journal-title":"Knowl Soc"},{"key":"1142_CR39","unstructured":"COSO (1994) Internal control\u2013integrated framework. http:\/\/www.coso.org\/"},{"key":"1142_CR40","unstructured":"Cunningham H, Maynard D, Tablan V, Ursu C, Bontcheva K (2001) Developing language processing components with GATE: a user guide. https:\/\/gate.ac.uk\/sale\/tao\/tao.pdf"},{"key":"1142_CR41","unstructured":"d\u00a0Araujo DA, Rigo SJ, Muller C, Chishman R (2013) Automatic information extraction from texts with inference and linguistic knowledge acquisition rules. In: 2013 IEEE\/WIC\/ACM international joint conferences on web intelligence (WI) and intelligent agent technologies (IAT), vol\u00a03, pp 151\u2013154"},{"key":"1142_CR42","doi-asserted-by":"crossref","unstructured":"D\u2019Aprile D, Giordano L, Gliozzi V, Martelli A, Pozzato G, Theseider\u00a0Dupr\u00e9 D (2010) Verifying business process compliance by reasoning about actions. In: Dix J, Leite Ja, Governatori G, Jamroga W (eds) Proceeding of the 11th international workshop on computational logic in multi-agent systems (CLIMA XI). Springer, Berlin, pp 99\u2013116","DOI":"10.1007\/978-3-642-14977-1_10"},{"key":"1142_CR43","unstructured":"de\u00a0Maat E, Winkels R (2010) Suggesting model fragments for sentences in Dutch Laws. In: Proceedings of legal ontologies and artificial intelligence techniques, pp 19\u201328"},{"key":"1142_CR44","doi-asserted-by":"crossref","unstructured":"de\u00a0Moura\u00a0Araujo B, Schmitz EA, Correa AL, Alencar AJ (2010) A method for validating the compliance of business processes to business rules. In: Proceedings of SAC\u201910, ACM, pp 145\u2013149","DOI":"10.1145\/1774088.1774117"},{"key":"1142_CR45","doi-asserted-by":"crossref","unstructured":"Doganata Y, Curbera F (2009) Effect of using automated auditing tools on detecting compliance failures in unmanaged processes. In: Proceedings of the 7th international conference on business process management (BPM 2009), Ulm, Germany, pp 310\u2013326","DOI":"10.1007\/978-3-642-03848-8_21"},{"key":"1142_CR46","unstructured":"El Kharbili M (2012) Business process regulatory compliance management solution frameworks: a comparative evaluation. In: Ghose A, Ferrarotti F (eds) Proceedings of the 8th Asia-Pacific Conference on Conceptual Modelling (APCCM 2012). ACS, Inc., Melbourne, Australia, pp 23\u201332"},{"key":"1142_CR47","first-page":"178","volume":"420","author":"M Kharbili El","year":"2008","unstructured":"El Kharbili M, Stein S (2008) Policy-based semantic compliance checking for business process management. MobIS workshops, CEUR workshops 420:178\u2013192","journal-title":"MobIS workshops, CEUR workshops"},{"key":"1142_CR48","unstructured":"El Kharbili M, Stein S, Markovic I, Pulverm\u00fcller E (2008) Towards a framework for semantic business process compliance management. Banking 08(i):1\u201315"},{"key":"1142_CR49","unstructured":"Elgammal A (2012) Towards a comprehensive framewcompliacbusiness process compliance. Ph.D. thesis, Tiburg Universtity"},{"key":"1142_CR50","doi-asserted-by":"crossref","unstructured":"Elgammal A, T\u00fcretken O, van\u00a0den Heuvel WJ, Papazoglou MP (2010) Root-cause analysis of design-time compliance violations on the basis of property patterns. In: Proceedings of the 8th international conference on service-oriented computing (ICSOC 2010), San Francisco, CA, USA, pp 17\u201331","DOI":"10.1007\/978-3-642-17358-5_2"},{"key":"1142_CR51","doi-asserted-by":"crossref","unstructured":"Elgammal A, Turetken O, van\u00a0den Heuvel WJ, Papazoglou M (2011) On the formal specification of regulatory compliance: a comparative analysis. In: Proceedings of ICSOC\u201910, pp 27\u201338","DOI":"10.1007\/978-3-642-19394-1_4"},{"issue":"1","key":"1142_CR52","doi-asserted-by":"crossref","first-page":"119","DOI":"10.1007\/s10270-014-0395-3","volume":"15","author":"A Elgammal","year":"2016","unstructured":"Elgammal A, Turetken O, van den Heuvel WJ, Papazoglou M (2016) Formalizing and applying compliance patterns for business process compliance. Softw Syst Model 15(1):119\u2013146","journal-title":"Softw Syst Model"},{"issue":"1","key":"1142_CR53","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/1125808.1125809","volume":"15","author":"R Eshuis","year":"2006","unstructured":"Eshuis R (2006) Symbolic model checking of UML activity diagrams. ACM Trans Softw Eng Methodol 15(1):1\u201338","journal-title":"ACM Trans Softw Eng Methodol"},{"key":"1142_CR54","unstructured":"Evans GP (2014) Managing risk with an end-to-end process view: adopting a process-based approach to risk management. BPTrends article. https:\/\/www.bptrends.com\/managing-risks-with-an-end-to-end-processview\/"},{"key":"1142_CR55","unstructured":"Fellmann M, Zasada A (2014) state-of-the-art of business process compliance approaches. In: Proceedings of European conference on information system (ECIS\u201914), Tel Aviv, Israel"},{"key":"1142_CR56","unstructured":"Fongon P, Grillo K (2004) Corporate implications of Sarbanes\u2013Oxley Act: a public policy. http:\/\/www.global-trade.law.com\/ITRN711"},{"key":"1142_CR57","doi-asserted-by":"crossref","unstructured":"F\u00f6rster A, Engels G, Schattkowsky T (2005) Activity diagram patterns for modeling quality constraints in business processes. In: Proceedings of MoDELS\u201905, pp 2\u201316","DOI":"10.1007\/11557432_2"},{"key":"1142_CR58","first-page":"135","volume":"2006","author":"A F\u00f6rster","year":"2006","unstructured":"F\u00f6rster A, Engels G, Schattkowsky T, Straeten RVD (2006) A pattern-driven development process for quality standard-conforming business process models. Proceedings of VL\/HCC 2006:135\u2013142","journal-title":"Proceedings of VL\/HCC"},{"key":"1142_CR59","unstructured":"Francesconi E (2010) legal rules learning based on a semantic model for legislation. In: Proceedings of SPLeT workshop"},{"key":"1142_CR60","doi-asserted-by":"crossref","unstructured":"Ghanavati S, Amyot D, Peyton L (2007) Towards a framework for tracking legal compliance in healthcare. In: Proceedings of CAiSE\u201907, pp 218\u2013232","DOI":"10.1007\/978-3-540-72988-4_16"},{"key":"1142_CR61","first-page":"169","volume-title":"Collection of ICSOC 2007","author":"A Ghose","year":"2007","unstructured":"Ghose A, Koliadis G (2007) Auditing business process compliance. In: Kr\u00e4mer B, Lin KJ, Narasimhan P (eds) Collection of ICSOC 2007. Springer, Berlin, pp 169\u2013180"},{"key":"1142_CR62","unstructured":"Giblin C, Liu AY, M\u00fcller S, Pfitzmann B, Zhou X (2005) Regulations expressed as logical models (REALM). In: Proceeding of JURIX 2005, IOS Press, pp 37\u201348"},{"key":"1142_CR63","unstructured":"Gilliot M, Accorsi R (2009) Runtime predictions of policy violations in automated buisness processes. Extended abstract: presented at prime life\/IFIP Summer School Program, Sept 7\u201311, Nice\/France"},{"key":"1142_CR64","unstructured":"Goedertier S, Vanthienen J (2006) Business rules for compliant business process models. In: Proceeding of BIS 2006, Gesellschaft f\u00fcr Informatik, pp 558\u2013579"},{"key":"1142_CR65","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1007\/11837862_2","volume-title":"Business process management workshops 2006","author":"S Goedertier","year":"2006","unstructured":"Goedertier S, Vanthienen J (2006) Designing compliant business processes with obligations and permissions. In: Eder J, Dustdar S (eds) Business process management workshops 2006. Springer, Berlin, pp 5\u201314"},{"issue":"9","key":"1142_CR66","doi-asserted-by":"crossref","first-page":"161","DOI":"10.1080\/17517575.2013.830340","volume":"9","author":"S Goedertier","year":"2015","unstructured":"Goedertier S, Vanthienen J, Caron F (2015) Declarative business process modelling: principles and modelling languages. Enterp Inf Syst 9(9):161\u2013185","journal-title":"Enterp Inf Syst"},{"key":"1142_CR67","doi-asserted-by":"crossref","unstructured":"Gogolla M, Bttner F, Richters M (2007) USE: a UML-based specification environment for validating UML and OCL. Sci Comput Program 69(1\u20133):27\u201334 (special issue on experimental software and toolkits)","DOI":"10.1016\/j.scico.2007.01.013"},{"key":"1142_CR68","doi-asserted-by":"crossref","unstructured":"G\u00f3mez-L\u00f3pez M, Gasca R, Rinderle-Ma S (2013) Explaining the incorrect temporal events during business process monitoring by means of compliance rules and model-based diagnosis. In: Proceeding of EDOCW\u201913, pp 163\u2013172","DOI":"10.1109\/EDOCW.2013.25"},{"key":"1142_CR69","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1016\/j.is.2014.07.007","volume":"48","author":"MT G\u00f3mez-L\u00f3pez","year":"2015","unstructured":"G\u00f3mez-L\u00f3pez MT, Gasca RM, P\u00e9rez-\u00c1lvarez JM (2015) Compliance validation and diagnosis of business data constraints in business process at runtime. Inf Syst 48:26\u201343","journal-title":"Inf Syst"},{"issue":"2\u20133","key":"1142_CR70","doi-asserted-by":"crossref","first-page":"181","DOI":"10.1142\/S0218843005001092","volume":"14","author":"G Governatori","year":"2005","unstructured":"Governatori G (2005) Representing business contracts in RuleML. Int J Coop Inf Syst 14(2\u20133):181\u2013216","journal-title":"Int J Coop Inf Syst"},{"key":"1142_CR71","doi-asserted-by":"crossref","unstructured":"Governatori G, Hashmi M (2015) No time for compliance. In: Proceedings of EDOC15, Adelaide, Australia, pp 9\u201318","DOI":"10.1109\/EDOC.2015.12"},{"key":"1142_CR72","doi-asserted-by":"crossref","unstructured":"Governatori G, Milosevic Z (2005) Dealing with contract violations: formalism and domain specific language. In: Proceedings of EDOC 2005. IEEE Computer Society, pp 46\u201357","DOI":"10.1109\/EDOC.2005.13"},{"key":"1142_CR73","first-page":"193","volume":"4","author":"G Governatori","year":"2006","unstructured":"Governatori G, Rotolo A (2006) Logic of violations: a Gentzen system for reasoning with contrary-to-duty obligation. Aust J Log 4:193\u2013215","journal-title":"Aust J Log"},{"key":"1142_CR74","doi-asserted-by":"crossref","unstructured":"Governatori G, Rotolo A (2008) An algorithm for business process compliance. In: Proceedings Jurix 2008. IOS Press, pp 186\u2013191","DOI":"10.3233\/978-1-58603-952-3-186"},{"key":"1142_CR75","unstructured":"Governatori G, Rotolo A (2010) A conceptually rich model of business process compliance. In: Proceedings of APCCM\u201910, vol 110, pp 3\u201312"},{"key":"1142_CR76","doi-asserted-by":"crossref","unstructured":"Governatori G, Rotolo A (2010) Norm compliance in business process modeling. In: Proceedings of RuleML 2010. Springer, pp 194\u2013209","DOI":"10.1007\/978-3-642-16289-3_17"},{"key":"1142_CR77","doi-asserted-by":"crossref","unstructured":"Governatori G, Sadiq S (2009) The journey to business process compliance. In: Handbook of research on BPM, IGI Global, pp 426\u2013454","DOI":"10.4018\/978-1-60566-288-6.ch020"},{"key":"1142_CR78","doi-asserted-by":"crossref","unstructured":"Governatori G, Shek S (2013) Regorous: a business process compliance checker. In: Proceedings of ICAIL\u201913, ACM, Rome, pp 245\u2013246","DOI":"10.1145\/2514601.2514638"},{"key":"1142_CR79","doi-asserted-by":"crossref","unstructured":"Governatori G, Milosevic Z, Sadiq S (2006) Compliance checking between business processes and business contracts. In: Proceeding of EDOC\u201906, pp 221\u2013232","DOI":"10.1109\/EDOC.2006.22"},{"key":"1142_CR80","doi-asserted-by":"crossref","unstructured":"Han J, Jin Y, Li Z, Phan T, Yu J (2007) Guiding the service composition process with temporal business rules. In: Web Services 2007","DOI":"10.1109\/ICWS.2007.94"},{"key":"1142_CR81","doi-asserted-by":"crossref","unstructured":"Hashmi M (2015) A methodology for extracting legal norms from regulatory documents. In: Proceedings of EDOCW\u201915. IEEE Computer Society, pp 41\u201350","DOI":"10.1109\/EDOCW.2015.29"},{"key":"1142_CR82","doi-asserted-by":"publisher","unstructured":"Hashmi M, Governatori G (2017) Norms modeling constructs of business process compliance management frameworks: a conceptual evaluation. Artif Intell Law. https:\/\/doi.org\/10.1007\/s10506-017-9215-8","DOI":"10.1007\/s10506-017-9215-8"},{"key":"1142_CR83","doi-asserted-by":"publisher","unstructured":"Hashmi M, Governatori G, Wynn MT (2013) Normative requirements for business process compliance. In: Service research and innovation\u2013third Australian symposium, ASSRI 2013, Sydney, NSW, Australia, Nov 27\u201329, 2013. Revised selected papers, pp 100\u2013116. https:\/\/doi.org\/10.1007\/978-3-319-07950-9_8","DOI":"10.1007\/978-3-319-07950-9_8"},{"key":"1142_CR84","doi-asserted-by":"crossref","unstructured":"Hashmi M, Governatori G, Wynn MT (2014) Modeling obligations with event-calculus. In: Proceedings of RuleML\u201914, Czech Republic, pp 296\u2013310","DOI":"10.1007\/978-3-319-09870-8_22"},{"issue":"3","key":"1142_CR85","doi-asserted-by":"crossref","first-page":"429","DOI":"10.1007\/s10796-015-9558-1","volume":"18","author":"M Hashmi","year":"2015","unstructured":"Hashmi M, Governatori G, Wynn M (2015) Normative requirements for regulatory compliance: an abstract formal framework. Inf Syst Front 18(3):429\u2013455","journal-title":"Inf Syst Front"},{"key":"1142_CR86","doi-asserted-by":"crossref","unstructured":"Hassan W, Logrippo L (2008) Requirements and compliance in legal systems: a logic approach. In: Proceedings of RELAW\u201908, Barcelona, Spain, pp 40\u201344","DOI":"10.1109\/RELAW.2008.8"},{"key":"1142_CR87","doi-asserted-by":"crossref","unstructured":"Herrestad H (1991) Norms and formalization. In: ICAIL\u201991, ACM, pp 175\u2013184","DOI":"10.1145\/112646.112667"},{"issue":"3","key":"1142_CR88","doi-asserted-by":"crossref","first-page":"361","DOI":"10.1108\/02640470910966835","volume":"27","author":"NK Herther","year":"2009","unstructured":"Herther NK (2009) Research evaluation and citation analysis: key issues and implications. Electron Libr 27(3):361\u2013375","journal-title":"Electron Libr"},{"key":"1142_CR89","doi-asserted-by":"crossref","unstructured":"Hinge K, Ghose A, Koliadis G (2009) Process SEER: a tool for semantic effect annotation of business process models. In: Proceedings of EDOC \u201909, pp 54\u201363","DOI":"10.1109\/EDOC.2009.24"},{"key":"1142_CR90","unstructured":"HIPAA TUG (1996) The US Health Insurance Portability and Accountability Act of 1996"},{"issue":"2","key":"1142_CR91","doi-asserted-by":"crossref","first-page":"155","DOI":"10.1007\/s10796-009-9179-7","volume":"14","author":"J Hoffmann","year":"2009","unstructured":"Hoffmann J, Weber I, Governatori G (2009) On compliance checking for clausal constraints in annotated process models. Inf Syst Front 14(2):155\u2013177","journal-title":"Inf Syst Front"},{"key":"1142_CR92","unstructured":"IFRS (2014) IFRS 7 international financial reporting standards: financial instruments disclosures. http:\/\/www.ifrs.org\/IFRSs\/Pages\/IFRS.aspx"},{"key":"1142_CR93","series-title":"lecture notes in computer science","doi-asserted-by":"crossref","first-page":"275","DOI":"10.1007\/978-3-319-12206-9_22","volume-title":"Conceptual modeling","author":"S Ingolfo","year":"2014","unstructured":"Ingolfo S, Jureta I, Siena A, Perini A, Susi A (2014) N\u00f3mos 3: legal compliance of roles and requirements. In: Yu E, Dobbie G, Jarke M, Purao S (eds) Conceptual modeling, vol 8824. lecture notes in computer science. Springer, Berlin, pp 275\u2013288"},{"key":"1142_CR94","volume-title":"Software abstractions: logic, language, and analysis","author":"D Jackson","year":"2006","unstructured":"Jackson D (2006) Software abstractions: logic, language, and analysis. The MIT Press, Cambridge"},{"key":"1142_CR95","unstructured":"James E, Jonathan S (2011) The benefits of static compliance testing for SCA next. In: Proceedings of the SDR\u201911, The Wireless Innovation Forum, Inc"},{"key":"1142_CR96","unstructured":"Jiang J, Virginia D, Huib A, Frank D, Yao-Hua T (2013) Norm compliance checking. In: Proceedings of AAMAS\u201913, Saint Paul, USA, pp 1121\u20131122"},{"key":"1142_CR97","first-page":"1","volume-title":"Regulatory compliance of business processes","author":"J Jiang","year":"2014","unstructured":"Jiang J, Aldewereld H, Dignum V, Wang S, Baida Z (2014) Regulatory compliance of business processes. AI & Society, Heidelberg, pp 1\u201310"},{"issue":"2","key":"1142_CR98","doi-asserted-by":"crossref","first-page":"255","DOI":"10.1147\/sj.462.0255","volume":"46","author":"C Johnson","year":"2007","unstructured":"Johnson C, Grandison T (2007) Compliance with data protection laws using Hippocratic Database active enforcement and auditing. IBM Syst J 46(2):255\u2013264","journal-title":"IBM Syst J"},{"issue":"2","key":"1142_CR99","doi-asserted-by":"crossref","first-page":"255","DOI":"10.1147\/sj.462.0255","volume":"46","author":"CM Johnson","year":"2007","unstructured":"Johnson CM, Grandison TWA (2007) Compliance with data protection laws using Hippocratic Database active enforcement and auditing. IBM Syst J 46(2):255\u2013264","journal-title":"IBM Syst J"},{"key":"1142_CR100","first-page":"690","volume-title":"On The Move (OTM) workshops to meaningful internet systems","author":"V Kabilan","year":"2003","unstructured":"Kabilan V, Johannesson P, Rugaimukamu D (2003) Business contract obligation monitoring through use of multi-tier contract ontology. In: Meersman R, Tari Z (eds) On The Move (OTM) workshops to meaningful internet systems. Springer, Berlin, pp 690\u2013702"},{"key":"1142_CR101","unstructured":"Kabilan V, Johannesson P, Rugaimukamu DM (2003) An ontological approach to unified contract management. In: Proceedings of 13th European Japanese conference on information modelling and knowlege bases, pp 106\u2013110"},{"key":"1142_CR102","doi-asserted-by":"crossref","unstructured":"K\u00e4hmer M, Gilliot M, M\u00fcller G (2008) Automating privacy compliance with ExPDT. In: Proceedings of the 10th IEEE conference on e-commerce technology and 5th conference on enterprise computing, pp 87\u201394","DOI":"10.1109\/CECandEEE.2008.122"},{"key":"1142_CR103","doi-asserted-by":"crossref","unstructured":"Karagiannis D, Mylopoulos J, Schwab M (2007) Business process-based regulation compliance: the case of the Sarbanes\u2013Oxley Act. In: 15th IEEE international requirements engineering conference (RE 2007) pp 315\u2013321","DOI":"10.1109\/RE.2007.15"},{"key":"1142_CR104","first-page":"168","volume":"241","author":"P Kazmierczak","year":"2012","unstructured":"Kazmierczak P, Pedersen T, \u00c5gotnes T (2012) NORMC: a norm compliance temporal logic model checker. STAIRS, frontiers in artificial intelligence and applications 241:168\u2013179","journal-title":"STAIRS, frontiers in artificial intelligence and applications"},{"key":"1142_CR105","unstructured":"Keller A, Ludwig K (2002) Defining and monitoring service-level agreements for dynamic e-business. In: Proceedings of the 16th USENIX conference on system administration, USENIX Association, Berkeley, USA, pp 189\u2013204"},{"key":"1142_CR106","unstructured":"Kharbili ME, Medeiros AKAD, Stein S, van\u00a0der Aalst W (2008) Business process compliance checking: current state and future challenges. In: Modellierung Betrieblicher Informationssyteme, MobIS, pp 107\u2013113"},{"key":"1142_CR107","unstructured":"Kitchenham B (2004) Procedure for performing systematic reviews. Technical Report TR\/SE-0401, Software Engineering Group, Department of Computer Science, Keele University, Keele, UK"},{"key":"1142_CR108","unstructured":"Kitchenham B, Charters S (2007) Guidelines for performing systematic literature reviews in software engineering. Technical Report EBSE 2007-001, Keele University and Durham University Joint Report"},{"key":"1142_CR109","doi-asserted-by":"crossref","unstructured":"Kiyavitskaya N, Zeni N, Breaux TD, Ant\u00f3n AI, Cordy JR, Mich L, Mylopoulos J (2008) Automating the extraction of rights and obligations for regulatory compliance. In: Li Q, Spaccapietra S, Yu E, Oliv\u00e9 A (eds) Proceedings of the 27th international conference on conceptual modeling (ER 2008). Springer, Berlin, pp 154\u2013168","DOI":"10.1007\/978-3-540-87877-3_13"},{"key":"1142_CR110","doi-asserted-by":"crossref","unstructured":"Knuplesch D, Ly L, Rinderle-Ma S, Pfeifer H, Dadam P (2010) On enabling data-aware compliance checking of business process models. In: Parsons J, Saeki M, Shoval P, Woo C, Wand Y (eds) Proceedings of the 29th international conference on conceptual modeling (ER 2010). Springer, Berlin, pp 332\u2013346","DOI":"10.1007\/978-3-642-16373-9_24"},{"key":"1142_CR111","doi-asserted-by":"crossref","unstructured":"Knuplesch D, Reichert M, Ly LT, Kumar A, Rinderle-Ma S (2013) Visual modeling of business process compliance rules with the support of multiple perspectives. In: Proceedings of the 32th international conference on conceptual modeling (ER 2013), Hong-Kong, pp 106\u2013120","DOI":"10.1007\/978-3-642-41924-9_10"},{"key":"1142_CR112","doi-asserted-by":"crossref","unstructured":"Knuplesch D, Reichert M, Kumar A (2015) Visually monitoring multiple perspectives of business process compliance. In: Proceedings of the 13th international conference on business process management (BPM 2015), Innsbruck, Austria, pp 263\u2013279","DOI":"10.1007\/978-3-319-23063-4_19"},{"key":"1142_CR113","first-page":"23","volume-title":"Foundations of knowledge base management, topics in information systems","author":"R Kowalski","year":"1989","unstructured":"Kowalski R, Sergot M (1989) A logic-based calculus of events. In: Schmidt J, Thanos C (eds) Foundations of knowledge base management, topics in information systems. Springer, Berlin, pp 23\u201355"},{"key":"1142_CR114","unstructured":"KPMG (2013) A survey of fraud, bribery, and corruption in Australia and New Zealand. Survey series: issues and insights, KPMG Forensic. https:\/\/www.kpmg.com\/AU\/IssuesAndInsights\/ArticlesPublications\/Fraud-Survey\/FDocuments\/fraud-bribery-corruption-survey-2012v2.pdf"},{"key":"1142_CR115","doi-asserted-by":"crossref","unstructured":"K\u00fcster JM, Ryndina K, Gall H (2007) Generation of business process models for object life cycle compliance. In: Proceedings of the 5th international conference on business process management (BPM 2007), Brisbane, Australia, pp 165\u2013181","DOI":"10.1007\/978-3-540-75183-0_13"},{"key":"1142_CR116","doi-asserted-by":"crossref","unstructured":"Lam HP, Governatori G (2009) The making of SPINdle. In: Governatori G, Hall J, Paschke A (eds) Proceedings of the 2009 international symposium on rule interchange and applications (RuleML 2009). Springer, Las Vegas, pp 315\u2013322","DOI":"10.1007\/978-3-642-04985-9_29"},{"key":"1142_CR117","doi-asserted-by":"crossref","unstructured":"Lam HP, Hashmi M, Scofield B (2016) Enabling reasoning with LegalRuleML. In: Alferes JJ, Bertossi L, Governatori G, Fodor P, Roman D (eds) Proceedings of the 10th international web rule symposium (RuleML 2016). Springer, Stony Brook, pp 241\u2013257","DOI":"10.1007\/978-3-319-42019-6_16"},{"key":"1142_CR118","doi-asserted-by":"crossref","unstructured":"LeFevre K, Agrawal R, Ercegovac V, Ramakrishnan R, Xu Y, DeWitt D (2004) Limiting disclosure in hippocratic databases. In: Proceedings of the thirtieth international conference on very large data bases, vol 30, VLDB endowment, VLDB \u201904, pp 108\u2013119","DOI":"10.1016\/B978-012088469-8.50013-9"},{"issue":"3","key":"1142_CR119","doi-asserted-by":"crossref","first-page":"273","DOI":"10.1016\/j.infsof.2013.12.004","volume":"56","author":"M Leitner","year":"2014","unstructured":"Leitner M, Rinderle-Ma S (2014) A systematic review on security in process-aware information systems? Constitution, challenges, and future directions. Inf Softw Technol 56(3):273\u2013293","journal-title":"Inf Softw Technol"},{"key":"1142_CR120","unstructured":"Leitner P, Wetzstein B, Rosenberg F, Michlmayr A, Dustdar S, Leymann F (2009) Runtime prediction of service level agreement violations for composite services. In: Proceedings of the 3rd workshop on non-functional properties and SLA management in service oriented computing. Springer, Heidelberg, pp 176\u2013186"},{"key":"1142_CR121","doi-asserted-by":"crossref","unstructured":"Leitner P, Michlmayr A, Rosenberg F, Dustdar S (2010) Monitoring, prediction and prevention of SLA violations in composite services. In: Proceedings of ICWS\u201910, pp 369\u2013376","DOI":"10.1109\/ICWS.2010.21"},{"key":"1142_CR122","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.datak.2013.03.002","volume":"87","author":"IA Letia","year":"2013","unstructured":"Letia IA, Groza A (2013) Compliance checking of integrated business processes. Data Knowl Eng 87:1\u201318","journal-title":"Data Knowl Eng"},{"issue":"2","key":"1142_CR123","doi-asserted-by":"crossref","first-page":"335","DOI":"10.1147\/sj.462.0335","volume":"46","author":"Y Liu","year":"2007","unstructured":"Liu Y, M\u00fcller S, Xu K (2007) A static compliance-checking framework for business process models. IBM Syst J 46(2):335\u2013361","journal-title":"IBM Syst J"},{"key":"1142_CR124","doi-asserted-by":"crossref","unstructured":"Lomuscio A, Qu H, Solanki M (2008) Towards verifying contract regulated service composition. In: Proceedings of ICWS\u201908, pp 254 \u2013261","DOI":"10.1109\/ICWS.2008.115"},{"key":"1142_CR125","unstructured":"Ly LT (2012) SeaFlows\u2014a compliance checking framework for supporting the process lifecycle. Ph.D. Thesis, University of Ulm, Osnabrck, Germany"},{"issue":"2","key":"1142_CR126","doi-asserted-by":"crossref","first-page":"195","DOI":"10.1007\/s10796-009-9185-9","volume":"14","author":"LT Ly","year":"2012","unstructured":"Ly LT, Rinderle-Ma S, G\u00f6ser K, Dadam P (2012) On enabling integrated process compliance with semantic constraints in process management systems. Inf Syst Front 14(2):195\u2013219","journal-title":"Inf Syst Front"},{"key":"1142_CR127","doi-asserted-by":"crossref","unstructured":"Ly LT, Maggi FM, Montali M, Rinderle S, van\u00a0der Aalst W (2013) A framework for the systematic comparison and evaluation of compliance monitoring approaches. In: Proceeding of EDOC\u201913. IEEE Computer Society","DOI":"10.1109\/EDOC.2013.11"},{"key":"1142_CR128","doi-asserted-by":"crossref","first-page":"209","DOI":"10.1016\/j.is.2015.02.007","volume":"54","author":"LT Ly","year":"2015","unstructured":"Ly LT, Maggi FM, Montali M, Rinderle-Ma S, van der Aalst WM (2015) Compliance monitoring in business processes: functionalities, application, and tool-support. Inf Syst 54:209\u2013234","journal-title":"Inf Syst"},{"key":"1142_CR129","doi-asserted-by":"crossref","unstructured":"Maggi F, Montali M, Westergaard M, van\u00a0der Aalst W (2011) Monitoring business constraints with linear temporal logic: an approach based on colored automata. In: Proceedings of the 9th international conference on business process management (BPM 2011). Springer, pp 132\u2013147","DOI":"10.1007\/978-3-642-23059-2_13"},{"key":"1142_CR130","doi-asserted-by":"crossref","first-page":"146","DOI":"10.1007\/978-3-642-28872-2_11","volume-title":"Fundamental approaches to software engineering","author":"F Maggi","year":"2012","unstructured":"Maggi F, Montali M, van der Aalst W (2012) An operational decision support framework for monitoring business constraints. In: de Lara J, Zisman A (eds) Fundamental approaches to software engineering. Springer, Berlin, pp 146\u2013162"},{"key":"1142_CR131","doi-asserted-by":"crossref","unstructured":"Mateescu R, Sighireanu M (2003) Efficient on-the-fly model-checking ror regular alternation-free Mu-calculus. Sci Comput Program 46(3):255\u2013281 (special issue on formal methods for industrial critical systems)","DOI":"10.1016\/S0167-6423(02)00094-1"},{"key":"1142_CR132","volume-title":"Integrated governance, risk and compliance: improve performance and enhance productivity in federal agencies","author":"SR McIntyre","year":"2008","unstructured":"McIntyre SR (2008) Integrated governance, risk and compliance: improve performance and enhance productivity in federal agencies. Technical reports, PricewaterhouseCoopers"},{"issue":"6","key":"1142_CR133","doi-asserted-by":"crossref","first-page":"570","DOI":"10.1002\/asi.10244","volume":"54","author":"LI Meho","year":"2003","unstructured":"Meho LI, Tibbo HR (2003) Modeling the information-seeking behavior of social scientists: Ellis\u2019s study revisited. J Am Soc Inf Sci Technol 54(6):570\u2013587","journal-title":"J Am Soc Inf Sci Technol"},{"key":"1142_CR134","doi-asserted-by":"crossref","unstructured":"Milosevic Z, J\u00f6sang A, Dimitrakos T, Patton MA (2002) Discretionary enforcement of electronic contracts. In: Proceedings of EDOC\u201902. IEEE Computer Society, Washington, DC, USA, pp 39\u201350","DOI":"10.1109\/EDOC.2002.1137695"},{"key":"1142_CR135","doi-asserted-by":"crossref","unstructured":"Milosevic Z, Sadiq S, Orlowska M (2006) Towards a methodology for deriving contract-compliant business processes. In: Dustdar S, Fiadeiro J, Sheth A (eds) Proceedings of the 4th international conference on business process management (BPM 2006). Springer, Vienna, pp 395\u2013400","DOI":"10.1007\/11841760_29"},{"key":"1142_CR136","doi-asserted-by":"crossref","unstructured":"Milosevic Z, Sadiq S, Orlowska M (2006) Translating business contract into compliant business processes. In: Proceedings of EDOC\u201906. IEEE Computer Society, pp 211\u2013220","DOI":"10.1109\/EDOC.2006.64"},{"key":"1142_CR137","unstructured":"Monakova G, Kopp O, Leymann F, Moser S, Sch\u00e4fers K (2009) Verifying business rules using an SMT solver for BPEL processes. In: Business process, services computing and intelligent service management, Leipzig, Germany, pp 81\u201394. http:\/\/subs.emis.de\/LNI\/Proceedings\/Proceedings147\/article2475.html"},{"key":"1142_CR138","unstructured":"Montali M, Maggi FM, Chesani F, Mello P, Aalst WMPvd (2014) Monitoring business constraints with the event calculus. ACM Trans Intell Syst Technol 5(1):17:1\u201317:30"},{"key":"1142_CR139","doi-asserted-by":"crossref","unstructured":"Namiri K, Stojanovic N (2007) Pattern-based design and validation of business process compliance. In: Proceedings of CoopIS\u201907. Springer, Berlin, pp 59\u201376","DOI":"10.1007\/978-3-540-76848-7_6"},{"key":"1142_CR140","doi-asserted-by":"crossref","unstructured":"Namiri K, Stojanovic N (2007) Using control patterns in business processes compliance. In: Proceedings of WISE\u201907, Springer, pp 178\u2013190","DOI":"10.1007\/978-3-540-77010-7_18"},{"key":"1142_CR141","unstructured":"Namiri K, Stojanovic N (2008) Towards a formal framework for business process compliance. In: Proceedings of MKWI\u201908, M\u00fcnchen"},{"key":"1142_CR142","unstructured":"Namiri K, Stojanovic N (2008) Towards a formal framework for business process compliance. In: Multikonferenz Wirtschaftsinformatik (MKWI 2008), Germany, pp 1185\u20131196"},{"key":"1142_CR143","first-page":"70","volume-title":"Mobile communication and power engineering, communications in computer and information science","author":"S Nishizaki","year":"2013","unstructured":"Nishizaki S, Ohata T (2013) Real-time model checking for regulatory compliance. In: Das V, Chaba Y (eds) Mobile communication and power engineering, communications in computer and information science, vol 296. Springer, Berlin, pp 70\u201377"},{"key":"1142_CR144","volume-title":"Defeasible deontic logic, synthese library","year":"1997","unstructured":"Nute D (ed) (1997) Defeasible deontic logic, synthese library, vol 263. Academic Publishers, Dordrecht"},{"key":"1142_CR145","doi-asserted-by":"crossref","first-page":"151","DOI":"10.1007\/3-540-36524-9_13","volume-title":"Web knowledge management and decision support","author":"D Nute","year":"2003","unstructured":"Nute D (2003) Defeasible logic. In: Bartenstein O, Geske U, Hannebauer M, Yoshie O (eds) Web knowledge management and decision support. Springer, Berlin, pp 151\u2013169"},{"key":"1142_CR146","unstructured":"OASIS LegalRuleML Technical Committee (2015) LegalRuleML technical committee specifications. https:\/\/www.oasis-open.org\/committees\/legalruleml\/charter.php, Retrieved 12 March 2016"},{"key":"1142_CR147","unstructured":"OCEG (2012) Governance, Risk and Compliance Capability Model. https:\/\/www.oceg.org\/about\/what-is-grc\/"},{"issue":"4","key":"1142_CR148","doi-asserted-by":"crossref","first-page":"381","DOI":"10.1007\/s001650050023","volume":"10","author":"P Ochsenschl\u00e4ger","year":"1998","unstructured":"Ochsenschl\u00e4ger P, Repp J, Rieke R, Nitsche U (1998) The SH-verification tool\u2013abstraction-based verification of co-operating systems. J Form Asp Comput 10(4):381\u2013404","journal-title":"J Form Asp Comput"},{"key":"1142_CR149","unstructured":"Olivieri F (2014) Compliance by design. Synthesis of business processes by declarative specifications. Ph.D. Thesis, Dipartimento di Informatica, Universit\u00e0 digli Studi di Verona, Italy and Institute for Integrated and Intelligent Systems, Griffith University, Australia"},{"key":"1142_CR150","unstructured":"OMG (2010) Business Process Model Notation (BPMN). Standard. http:\/\/www.omg.org\/spec\/BPMN\/2.0\/"},{"key":"1142_CR151","unstructured":"OMG (2011) Unified Modeling Language (UML 2.0). http:\/\/www.omg.org\/spec\/UML\/2.0\/"},{"issue":"4","key":"1142_CR152","doi-asserted-by":"crossref","first-page":"342","DOI":"10.1108\/CGIJ-07-2014-0022","volume":"19","author":"A O\u2019Neill","year":"2014","unstructured":"O\u2019Neill A (2014) An Action framework for compliance and governance. Int J Clin Gov 19(4):342\u2013359","journal-title":"Int J Clin Gov"},{"key":"1142_CR153","doi-asserted-by":"crossref","unstructured":"Otto PN, Anton AI (2007) Addressing legal requirements in requirements engineering. In: Proceedings of the 15th IEEE international requirements engineering conference (RE 2007). IEEE Computer Society, pp 5\u201314","DOI":"10.1109\/RE.2007.65"},{"key":"1142_CR154","first-page":"40","volume":"70","author":"P Pattersson","year":"2000","unstructured":"Pattersson P, Larson K (2000) UPPAAL 2K. Bull Eur Assoc Theor Comput Sci 70:40\u201344","journal-title":"Bull Eur Assoc Theor Comput Sci"},{"issue":"4","key":"1142_CR155","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1108\/joic.2003.3.4.16","volume":"3","author":"BI Pershkow","year":"2002","unstructured":"Pershkow BI (2002) Sarbanes-Oxley: investment company compliance. J Invest Compliance 3(4):16\u201330","journal-title":"J Invest Compliance"},{"key":"1142_CR156","doi-asserted-by":"crossref","unstructured":"Pesic M, Schonenberg H, van\u00a0der Aalst W (2007) DECLARE: full support for loosely-structured processes. In: Proceedings of 11th IEEE international conference on enterprise distributed object computing (EDOC\u201907), pp 287\u2013287","DOI":"10.1109\/EDOC.2007.14"},{"key":"1142_CR157","unstructured":"Prakken H, Sergot M (1997) Dyadic denontic logic and contrary-to-duty obligations. In: [151], pp 223\u2013262"},{"key":"1142_CR158","doi-asserted-by":"crossref","unstructured":"Ramezani E, Fahland D, van\u00a0der Aalst W (2012) Where did i misbehave? Diagnostic information in compliance checking. In: Proceedings of the 10th international conference on Business Process Management (BPM 2012), Tallinn, Estonia, pp 262\u2013278","DOI":"10.1007\/978-3-642-32885-5_21"},{"key":"1142_CR159","unstructured":"Ramezani E, Fahland D, van Dongen BF, van\u00a0der Aalst W (2013) Diagnostic information for compliance checking of temporal compliance requirements. In: Proceedings of the 25th international conference on advanced information systems engineering (CAiSE 2013), Valencia, Spain, pp 304\u2013320"},{"issue":"3","key":"1142_CR160","doi-asserted-by":"crossref","first-page":"227","DOI":"10.1115\/1.2031270","volume":"5","author":"RM Rangan","year":"2005","unstructured":"Rangan RM, Rohde SM, Peak R, Chadha B, Bliznakov P (2005) Streamlining product lifecycle processes: a survey of product lifecycle management implementations, directions, and challenges. J Comput Inf Sci Eng 5(3):227\u2013237","journal-title":"J Comput Inf Sci Eng"},{"key":"1142_CR161","first-page":"552","volume-title":"2014 22nd Euromicro international conference on parallel, distributed, and network-based processing (PDP 2014)","author":"R Rieke","year":"2014","unstructured":"Rieke R, Repp J, Zhdanova M, Eichler J (2014) Monitoring security compliance of critical processes. 2014 22nd Euromicro international conference on parallel, distributed, and network-based processing (PDP 2014). Italy, Torino, pp 552\u2013560"},{"key":"1142_CR162","doi-asserted-by":"crossref","unstructured":"Rifaut A, Dubois E (2008) Using goal-oriented requirements engineering for improving the quality of ISO\/IEC 15504 based compliance assessment frameworks. In: Proceedings of the 16th IEEE international requirements engineering conference (RE 2008), pp 33\u201342","DOI":"10.1109\/RE.2008.44"},{"key":"1142_CR163","unstructured":"Rikhardsson P, Best PJ, Green P, Rosemann M (2006) Business process risk management and internal control: a proposed research agenda in the context of compliance and ERP systems. In: Second Asia\/Pacific research symposium on accounting information systems, Melbourne"},{"key":"1142_CR164","first-page":"51","volume-title":"International workshop on enterprise modelling and information systems architectures (EMISA 20110)","author":"S Rinderle-Ma","year":"2011","unstructured":"Rinderle-Ma S, Mangler J (2011) Integration of process constraints from heterogeneous sources in process-aware information systems. International workshop on enterprise modelling and information systems architectures (EMISA 20110). Hamburg, Germany, pp 51\u201364"},{"issue":"1","key":"1142_CR165","doi-asserted-by":"crossref","first-page":"21","DOI":"10.1145\/344788.344789","volume":"29","author":"JF Roddick","year":"2000","unstructured":"Roddick JF, Al-Jadir L, Bertossi L, Dumas M, Estrella F, Gregersen H, Hornsby K, Lufter J, Mandreoli F, M\u00e4nnist\u00f6 T, Mayol E, Wedemeijer L (2000) Evolution and change in data management\u2013issues and directions. SIGMOD Rec 29(1):21\u201325","journal-title":"SIGMOD Rec"},{"key":"1142_CR166","unstructured":"Rosemann M, zur Muehlen M (2005) Integrating risks in business process models. In: Proceedings of ACIS\u201905"},{"key":"1142_CR167","doi-asserted-by":"crossref","unstructured":"Sadiq S, Governatori G, Namiri K (2007) Modeling control objectives for business process compliance. In: Proceedings of BPM\u201907. Springer, pp 149\u2013164","DOI":"10.1007\/978-3-540-75183-0_12"},{"key":"1142_CR168","doi-asserted-by":"crossref","unstructured":"Salnitri M, Dalpiaz F, Giorgini P (2014) Modeling and verifying security policies in business processes. In: Bider I, Gaaloul K, Krogstie J, Nurcan S, Proper HA, Schmidt R, Soffer P (eds) Proceedings of the 15th international conference on business process modeling, development and support (BPMDS 2014). Springer, Berlin, pp 232\u2013249","DOI":"10.1007\/978-3-662-43745-2_14"},{"key":"1142_CR169","doi-asserted-by":"crossref","unstructured":"Sapkota K, Aldea A, Duce DA, Younas M, Ba\u00f1ares Alc\u00e1ntara R (2011) Towards semantic methodologies for automatic regulatory compliance support. In: Proceedings of PIKM\u201911, pp 83\u201386","DOI":"10.1145\/2065003.2065021"},{"key":"1142_CR170","doi-asserted-by":"crossref","unstructured":"Scannapieco S, Governatori G, Olivieri F, Cristani M (2011) Designing for compliance: norms and goal. In: The 5th international symposium on rules: research based and industry focused (RuleML 2011), Ft Lauderdale","DOI":"10.1007\/978-3-642-24908-2_29"},{"key":"1142_CR171","doi-asserted-by":"crossref","first-page":"60","DOI":"10.1007\/978-3-642-05148-7_7","volume-title":"On the move to meaningful internet systems: OTM 2009","author":"D Schleicher","year":"2009","unstructured":"Schleicher D, Anstett T, Leymann F, Mietzner R (2009) Maintaining compliance in customizable process models. In: Meersman R, Dillon T, Herrero P (eds) On the move to meaningful internet systems: OTM 2009. Springer, Heidelberg, pp 60\u201375"},{"key":"1142_CR172","unstructured":"Schmidt R, Bartsch C, Oberhauser R (2007) Ontology-based representation of compliance requirements for service processes. In: Proceedings of the workshop on semantic business process and product lifecycle management, pp 28\u201339"},{"issue":"1","key":"1142_CR173","doi-asserted-by":"crossref","first-page":"92","DOI":"10.1145\/504087.504091","volume":"11","author":"M Schrefl","year":"2002","unstructured":"Schrefl M, Stumptner M (2002) Behavior-consistent specialization of object life cycles. ACM Trans Softw Eng Methodol 11(1):92\u2013148","journal-title":"ACM Trans Softw Eng Methodol"},{"key":"1142_CR174","doi-asserted-by":"crossref","unstructured":"Schumm D, Turetken O, Kokash N, Elgammal A, Leymann F, Heuvel WJVD (2010) Business process compliance through reusable units of compliant processes. In: Proceedings of the 10th international conference on current trends in web engineering. Springer, Vienna, Austria, pp 325\u2013337","DOI":"10.1007\/978-3-642-16985-4_29"},{"key":"1142_CR175","first-page":"48","volume-title":"Proceeding of the 15th international conference on enterprise","author":"F Semmelrodt","year":"2014","unstructured":"Semmelrodt F, Knuplesch D, Reichert M (2014) Modeling the resource perspective of business process compliance rules with the extended compliance rule graph. Proceeding of the 15th international conference on enterprise. Business-process and information systems modeling, Thessaloniki, Greece, pp 48\u201363"},{"issue":"4","key":"1142_CR176","doi-asserted-by":"crossref","first-page":"640","DOI":"10.1108\/09513570310492335","volume":"16","author":"LF Spira","year":"2003","unstructured":"Spira LF, Page M (2003) Risk management: the reinvention of internal control and the changing role of internal audit. Account Audit Account J 16(4):640\u2013661","journal-title":"Account Audit Account J"},{"issue":"4","key":"1142_CR177","doi-asserted-by":"crossref","first-page":"595","DOI":"10.1007\/s10796-010-9235-3","volume":"13","author":"S Strecker","year":"2011","unstructured":"Strecker S, Heise D, Frank U (2011) RiskM: a multi-perspective modeling method for IT risk assessment. Inf Syst Front 13(4):595\u2013611","journal-title":"Inf Syst Front"},{"key":"1142_CR178","doi-asserted-by":"crossref","unstructured":"Stumptner M, Schrefl M (2000) Behavior consistent inheritance in UML. In: Laender AHF, Liddle SW, Storey VC (eds) Proceedings of the 19th international conference on conceptual modeling (ER 2000). Springer, Berlin, pp 527\u2013542","DOI":"10.1007\/3-540-45393-8_38"},{"issue":"1","key":"1142_CR179","first-page":"933","volume":"34","author":"S Suriadi","year":"2014","unstructured":"Suriadi S, Wei\u00df B, Winkelmann A, ter Hofstede AHM, Adams M, Conforti R, Fidge C, La Rosa M, Ouyang C, Pika A, Rosemann M, Wynn M (2014) Current research in risk-aware business process management\u2013overview, comparison, and gap analysis. Commun Assoc Inf Syst 34(1):933\u2013984","journal-title":"Commun Assoc Inf Syst"},{"key":"1142_CR180","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1016\/j.is.2014.07.007","volume":"48","author":"M Teresa","year":"2015","unstructured":"Teresa M, G\u00f3mez-L\u00f3pez Gasca RM, P\u00e9rez-\u00c1lvarez JM (2015) Compliance validation and diagnosis of business data constraints in business processes at runtime. Inf Syst 48:26\u201343","journal-title":"Inf Syst"},{"key":"1142_CR181","unstructured":"The Basel Committee on Banking Supervision (2004) BASEL II accord - the international convergence of capital measurement and capital standards: a revised framework. https:\/\/www.bis.org\/publ\/bcbsca.htm"},{"key":"1142_CR182","doi-asserted-by":"crossref","unstructured":"Tr\u010dka N, van\u00a0der Aalst WMP, Sidorova N (2009) Data-flow anti-patterns: discovering data-flow errors in workflows. In: van Eck P, Gordijn J, Wieringa R (eds) Proceedings of the 21st international conference on advanced information systems engineering (CAiSE 2009). Springer, Berlin, pp 425\u2013439","DOI":"10.1007\/978-3-642-02144-2_34"},{"key":"1142_CR183","first-page":"270","volume-title":"Springer","author":"Turki S, Marija BO (2010) Compliance in e-government service engineering: state-of-the-art. 1st International conference on exploring services science (IESS","year":"2010","unstructured":"Turki S, Marija BO (2010) Compliance in e-government service engineering: state-of-the-art. 1st International conference on exploring services science (IESS (2010) Springer. Switzerland, Geneva, pp 270\u2013275"},{"key":"1142_CR184","unstructured":"US-Government (2002) Public Company Accounting Reforms and Investor Protection Act (Sarbanes-Oxley Act), Public Law 107\u2013204, 116 Stat. 745"},{"key":"1142_CR185","doi-asserted-by":"crossref","unstructured":"van\u00a0der Aalst WM, Basten T (2001) Identifying commonalities and differences in object life cycles using behavioral inheritance. In: Colom JM, Koutny M (eds) Proceedings of the 22nd international conference on application and theory of Petri nets (ICATPN 2001). Springer, Berlin, pp 32\u201352","DOI":"10.1007\/3-540-45740-2_4"},{"key":"1142_CR186","doi-asserted-by":"publisher","unstructured":"van der Aalst WMP, de Medeiros AKA (2005) Process mining and security: detecting anomalous process executions and checking process conformance. Electron Notes Theor Comput Sci 121(Suppl C):3\u201321. https:\/\/doi.org\/10.1016\/j.entcs.2004.10.013","DOI":"10.1016\/j.entcs.2004.10.013"},{"key":"1142_CR187","first-page":"130","volume-title":"CoopIS\u201905","author":"W Aalst van der","year":"2005","unstructured":"van der Aalst W, de Beer HT, van Dongen BT (2005) Process mining and verification of properties: an approach based on temporal logic. In: Robert Meersman ZT (ed) CoopIS\u201905. Springer, Berlin, pp 130\u2013147"},{"key":"1142_CR188","doi-asserted-by":"crossref","unstructured":"van der Aalst W, van Hee KM, van Werf JM, Verdonk M, (2010) Auditing 2.0: using process mining to support tomorrow\u2019s auditor. Computer 43(3):90\u201393","DOI":"10.1109\/MC.2010.61"},{"issue":"3","key":"1142_CR189","doi-asserted-by":"crossref","first-page":"636","DOI":"10.1016\/j.dss.2010.08.014","volume":"50","author":"W Aalst van der","year":"2011","unstructured":"van der Aalst W, van Hee K, van der Werf JM, Kumar A, Verdonk M (2011) Conceptual model for online auditing. Decis Support Syst 50(3):636\u2013647","journal-title":"Decis Support Syst"},{"issue":"2","key":"1142_CR190","doi-asserted-by":"crossref","first-page":"182","DOI":"10.1002\/widm.1045","volume":"2","author":"W Aalst van der","year":"2012","unstructured":"van der Aalst W, Adriansyah A, van Dongen B (2012) Replaying history on process models for conformance checking and performance analysis. Wiley Interdiscip Rev Data Min Knowl Discov 2(2):182\u2013192","journal-title":"Wiley Interdiscip Rev Data Min Knowl Discov"},{"issue":"1","key":"1142_CR191","doi-asserted-by":"crossref","first-page":"73","DOI":"10.1007\/s10506-007-9057-x","volume":"16","author":"J V\u00e1zquez-Salceda","year":"2008","unstructured":"V\u00e1zquez-Salceda J, Aldewereld H, Grossi D, Dignum F (2008) From human regulations to regulated software agents\u2019 behavior. Artif Intell Law 16(1):73\u201387","journal-title":"Artif Intell Law"},{"key":"1142_CR192","doi-asserted-by":"crossref","first-page":"199","DOI":"10.1007\/978-3-642-21640-4_16","volume-title":"Advanced information systems engineering","author":"P Vicente","year":"2011","unstructured":"Vicente P, Mira da Silva M (2011) A conceptual model for integrated governance, risk and compliance. In: Mouratidis H, Rolland C (eds) Advanced information systems engineering. Springer, Berlin, pp 199\u2013213"},{"key":"1142_CR193","doi-asserted-by":"crossref","first-page":"195","DOI":"10.1016\/j.is.2014.01.006","volume":"42","author":"Z Wang","year":"2014","unstructured":"Wang Z, ter Hofstede AH, Ouyang C, Wynn M, Wang J, Zhu X (2014) How to guarantee compliance between workflows and product lifecycles? Inf Syst 42:195\u2013215","journal-title":"Inf Syst"},{"key":"1142_CR194","first-page":"293","volume-title":"Physical electrochemistry: principles, methods and applications","author":"M Ward","year":"1995","unstructured":"Ward M (1995) Principles and applications of electrochemical quartz crystal microbalance. Physical electrochemistry: principles, methods and applications. Marcel Dekker Inc, New York, pp 293\u2013338"},{"key":"1142_CR195","volume-title":"Users, narcissism and control ? tracking the impact of scholarly publications in the 21st century","author":"P Wouters","year":"2012","unstructured":"Wouters P, Costas R (2012) Users, narcissism and control ? tracking the impact of scholarly publications in the 21st century. Technical reports, SURFfoundation, Utrecht, The Netherland"},{"key":"1142_CR196","doi-asserted-by":"crossref","unstructured":"Yip F, Parameswaran N, Ray P (2007) Rules and ontology in compliance management. In: Proceedings of EDOC\u201907, Washington, DC, USA, p 435","DOI":"10.1109\/EDOC.2007.50"},{"key":"1142_CR197","doi-asserted-by":"crossref","unstructured":"Yu J, Manh T, Han J, Jin Y, Han Y, Wang J (2006) Pattern based property specification and verification for service composition. In: Proceedings of WISE 2006. Springer, pp 156\u2013168","DOI":"10.1007\/11912873_18"},{"key":"1142_CR198","doi-asserted-by":"crossref","first-page":"885","DOI":"10.1007\/s11390-008-9196-x","volume":"23","author":"J Yu","year":"2008","unstructured":"Yu J, Han YB, Han J, Jin Y, Falcarin P, Morisio M (2008) Synthesizing service composition models on the basis of temporal business rules. J Comput Sci Technol 23:885\u2013894","journal-title":"J Comput Sci Technol"},{"issue":"1","key":"1142_CR199","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s00766-013-0181-8","volume":"20","author":"N Zeni","year":"2013","unstructured":"Zeni N, Kiyavitskaya N, Mich L, Cordy JR, Mylopoulos J (2013) GaiusT: supporting the extraction of rights and obligations for regulatory compliance. Requir Eng 20(1):1\u201322","journal-title":"Requir Eng"}],"container-title":["Knowledge and Information Systems"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10115-017-1142-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10115-017-1142-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10115-017-1142-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,29]],"date-time":"2025-06-29T23:31:20Z","timestamp":1751239880000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10115-017-1142-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,1,22]]},"references-count":199,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2018,10]]}},"alternative-id":["1142"],"URL":"https:\/\/doi.org\/10.1007\/s10115-017-1142-1","relation":{},"ISSN":["0219-1377","0219-3116"],"issn-type":[{"value":"0219-1377","type":"print"},{"value":"0219-3116","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,1,22]]}}}