Combining Cloud Computing with an Automated Process Engine to Build an Information-Based Internal Audit Decision-Making Support System
Main Article Content
Abstract
To address the core challenges of internal audit systems in cloud environments, including the trade-off between multisource sensitive data privacy and audit efficiency, rigid process execution, and insufficient mining of hidden associations in distributed enterprises, this study proposes an information-based internal audit decision-making support system integrating lightweight federated learning, adaptive differential privacy, and a BPMN-based automated process engine. Considering the increasing demand for secure intelligent information processing in cloud-edge infrastructures that also underpin large-scale electromagnetic information systems, the proposed framework enables privacy-preserving collaborative analysis while maintaining high computational efficiency. At the edge layer, a four-level privacy classification strategy is employed, where LSTM-based anomaly detection models are trained locally and only ϵ-differential privacy-protected encrypted gradients are uploaded for FedAvg aggregation in the cloud. Rényi differential privacy dynamically adjusts privacy budgets, while entropy weight-TOPSIS risk evaluation and a Neo4j knowledge graph drive adaptive task scheduling through the BPMN engine. NLP-based report generation, Elasticsearch logging, and blockchain anchoring further ensure traceability and reliability. Experimental results demonstrate an average end-to-end latency of 8.4±1.4 s, audit coverage of 93.9±2.2%, risk identification F1-score of 89.2±2.7%, data re-identification rate of 2.5±1.0%, and process automation exceeding 89%. The proposed framework effectively resolves the privacy–efficiency– process dilemma and provides a secure, intelligent, and scalable decision-support paradigm for cloud-enabled enterprise auditing, while offering methodological insights for trustworthy information processing in distributed electromagnetic and cyber-physical infrastructures.
Downloads
Article Details

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (See The Effect of Open Access).
References
F. A. Wassie and L. P. Lakatos, “Artificial intelligence and the future of the internal audit function,” Humanities and Social Sciences Communications, vol. 11, no. 1, pp. 1-13, 2024, doi: 10.1057/s41599-024-02905-w.
M. M. Thottoli, “Leveraging information communication technology (ICT) and artificial intelligence (AI) to enhance auditing practices,” Accounting Research Journal, vol. 37, no. 2, pp. 134-150, 2024, doi: 10.1108/arj-09-2023-0269.
C. Aldemir and T. Uçma Uysal, “AI competencies for internal auditors in the public sector,” EDPACS, vol. 69, no. 1, pp. 3-21, 2024, doi: 10.1080/07366981.2024.2312001.
D. T. Valivarthi, “Optimizing cloud computing environments for big data processing,” International Journal of Engineering & Science Research, vol. 14, no. 2, pp. 1756-1775, 2024, [Online]. Available: IJESR/Apr-June.2024/ Vol-14/Issue-2/1756-1775.
Q. Gao and Z. Kuang, “Can robotic process automation technology enable risk data analysis for customs’ postclearance audit: A China customs case study,” World Customs Journal, vol. 17, no. 2, pp. 93-104, 2023, doi: 10.55596/001c.88821.
M. Pa´nkowska, “Process modeling paradigm change,” Knowledge and Process Management, vol. 30, no. 2, pp. 163-175, 2023, doi: 10.1002/kpm.1749.
J. Abrera, “Data privacy and security in cloud computing: A comprehensive review,” Journal of Computer Science and Information Technology, vol. 1, no. 1, pp. 01-09, 2024, doi: 10.1051/e3sconf/202339904040.
A. Mishra, T. S. Jabar, Y. I. Alzoubi, and K. N. Mishra, “Enhancing privacy-preserving mechanisms in cloud storage: A novel conceptual framework,” Concurrency and Computation: Practice and Experience, vol. 35, no. 26, pp. e7831, 2023, doi: 10.1002/cpe.7831.
M. Almutairi and F. T. Sheldon, “IoT–cloud integration security: A survey of challenges, solutions, and directions,” Electronics, vol. 14, no. 7, pp. 1394, 2025, doi: 10.3390/electronics14071394.
F. Ullah, C. M. Pun, M. I. Mohmand, R. K. Mahendran, A. A. Khan, S. M. Alhammad, J. J. P. Rodrigues, and A. Farouk, “Privacy-aware secure data auditing for cloud-based intelligence of things environment,” IEEE Internet of Things Journal, vol. 12, no. 11, pp. 15288-15303, 2025, doi: 10.1109/JIOT.2025.3528117.
Y. Wang, W. Xue, and A. Zhang, “Application of big data technology in enterprise information security management and risk assessment,” Journal of Global Information Management (JGIM), vol. 31, no. 3, pp. 1-16, 2023, doi: 10.4018/JGIM.324465.
S. Hanumanthaiah, “SOX Considerations for Cloud Data Architecture: A Comprehensive Literature Review,” IJSAT-International Journal on Science and Technology, vol. 16, no. 2, pp. 1-11, 2025, doi: 10.71097/IJSAT.v16.i2.6482.
J. H. F. Moreno, G. D. R. Quiñónez, F. G. E. Moreno, and L. A. C. Bone, “Robotic Process Automation (RPA) as a technological tool for automating the execution of audits,” Sapienza: International Journal of Interdisciplinary Studies, vol. 4, no. 4, Art. no. e23059-e23059, 2023, doi: 10.51798/sijis.v4i4.658.
Z. Gu, F. Corcoglioniti, D. Lanti, A. Mosca, G. Xiao, J. Xiong, et al., “A systematic overview of data federation systems,” Semantic Web, vol. 15, no. 1, pp. 107-165, 2024, doi: 10.3233/SW-223201.
S. Mishra and S. Konidala, “A polyglot data integration framework for seamless integration of heterogeneous data sources and formats,” International Journal of Emerging Trends in Computer Science and Information Technology, vol. 5, no. 4, pp. 70-81, 2024, doi: 10.63282/3050-9246.IJETCSIT-V5I4P108.
M. H. Safarzadeh and M. Derakhshan, “Risk Disclosure Quality Assessment Using Hidden Markov Chain Analysis of Firms’ Risk State,” Computational Economics, pp. 1-44, 2025, doi: 10.1007/s10614-025-10948-7.
J. Lillestøl, “Sampling risk evaluations in tax audits: Some modelling issues,” Law, Probability and Risk, vol. 21, no. 1, pp. 1-20, 2022, doi: 10.1093/lpr/mgac010.
L. Gao, “Enterprise internal audit data encryption based on blockchain technology,” PLoS one, vol. 20, no. 1, Art. no. e0315759, 2025, doi: 10.1371/journal.pone.0315759.
Y. Qu, H. Ji, and D. Cofell, “Financial Audit Method Innovation of Qinghai Energy Enterprises Based on Panel Data Regression Model,” Wireless Communications and Mobile Computing, vol. 2023, no. 1, Art. no. 6093443, 2023, doi: 10.1155/2023/6093443.
Z. Yang, “Privacy-Aware Financial Risk Control: A Federated Learning Approach with Differential Privacy Optimization,” Journal of Computer Technology and Software, pp. 4(4), 2025, doi: 10.5281/zenodo.15340786.
I. Namatevs, K. Sudars, A. Nikulins, and K. Ozols, “Privacy auditing in differential private machine learning: The current trends,” Applied Sciences, vol. 15, no. 2, pp. 647, 2025, doi: 10.3390/app15020647.
Y. Shin, H. Kim, J. Jeong, and D. Shin, “Federated learning for surveillance systems: A literature review and AHP expert-based evaluation,” Electronics, vol. 14, no. 17, pp. 3500, 2025, doi: 10.3390/electronics14173500.
S. A. Mahmud, N. Islam, Z. Islam, Z. Rahman, and S. T. Mehedi, “Privacy-preserving federated learning-based intrusion detection technique for cyber-physical systems,” Mathematics, vol. 12, no. 20, pp. 3194, 2024, doi: 10.3390/math12203194.
X. Gu, F. Sabrina, Z. Fan, and S. Sohail, “A review of privacy enhancement methods for federated learning in healthcare systems,” International Journal of Environmental Research and Public Health, vol. 20, no. 15, pp. 6539, 2023, doi: 10.3390/ijerph20156539.
V. Feldman and T. Zrnic, “Individual privacy accounting via a Renyi filter,” Advances in Neural Information Processing Systems, vol. 34, pp. 28080– 28091, 2021, doi: 10.48550/arXiv.2008.11193.
M. Ghazali, D. B. Nugroho, and Y. Latief, “Analyzing the Effect of the Construction Safety Audit Model Using the Business Process Model and Notation (BPMN) Method on Improving Communication and Collaboration Between Stakeholders,” CSID Journal of Infrastructure Development, vol. 7, no. 2, pp. 8, 2024, doi: 10.7454/jid.v7.i2.1144.
W. Li, “Audit automation process and realization path analysis based on financial technology,” European Journal of Business, Economics & Management, vol. 1, no. 2, pp. 69-75, 2025, [Online]. Available: https://ideas.repec.org/a/dba/ejbema/v1y2025i2p69-75.html.
S. Anvarkhatibi, H. R. Baradaran, A. Mottaghi, and H. Taghizadeh, “Recognition and ranking the effective factors on audit quality via the TOPSIS technique,” Advances in Mathematical Finance & Applications, vol. 9, no. 1, pp. 159-180, 2024, doi: 10.22034/AMFA.2022.1966676.1790.
K. F. Liew, W. S. Lam, and W. H. Lam, “Financial network analysis on the performance of companies using integrated entropy–DEMATEL–TOPSIS model,” Entropy, vol. 24, no. 8, pp. 1056, 2022, doi: 10.3390/e24081056.