AI-Driven Control Effectiveness Prediction Using Graph Neural Networks for Enterprise Governance, Risk and Compliance: A Temporal Heterogeneous Graph Framework
Main Article Content
Abstract
Enterprise governance, risk and compliance systems increasingly contain large volumes of interconnected information describing risks, controls, business processes, regulatory obligations, audit findings, technology assets, incidents, control owners, and supporting evidence. Conventional control-effectiveness assessment methods, however, remain predominantly retrospective and frequently treat controls as independent records rather than as components of a highly interconnected organizational system. This study proposes an artificial intelligence-driven framework for predicting control effectiveness using graph neural networks. The proposed Governance, Risk and Compliance Control Effectiveness Graph Neural Network, termed GRC-CEGNN, represents an enterprise GRC environment as a temporal heterogeneous graph in which controls, risks, processes, assets, regulatory requirements, evidence items, findings, incidents, and organizational actors are represented as distinct node types connected through semantically meaningful relationships. The framework combines relation-aware graph message passing, temporal representations, attention-based aggregation, probability calibration, and graph-level explainability to predict whether a control is likely to become ineffective during a future assessment period. A controlled synthetic enterprise benchmark comprising 16,170 nodes, 68,450 graph relationships, and 24 monthly snapshots is employed to demonstrate the proposed methodology without making unsupported claims regarding proprietary organizational data. Experimental results indicate that GRC-CEGNN achieves an AUROC of 0.916, an AUPRC of 0.706, and an F1-score of 0.674, outperforming logistic regression, random forest, XGBoost, graph convolutional networks, GraphSAGE, and relational graph convolutional networks in the simulated environment. Ablation analysis indicates that relational semantics, temporal information, evidence connectivity, and attention mechanisms all contribute to predictive performance. The findings demonstrate the potential of graph-based predictive analytics to transform GRC from periodic control testing toward continuous, risk-based control assurance while highlighting the importance of explainability, human oversight, model governance, and data quality.