Matching logs to workflow steps: Align case IDs, activity names and workflow version before comparison.; Check for missing events or unexplained route deviations in recorded cases.; Classify differences as data issues, accepted variations or control concerns.
Image: Business Automation Desk

Process Discovery

Part of Process mining and operational evidence

Comparing process logs with the documented workflow

Map logged events to the applicable workflow, inspect differences by case and decide whether a gap concerns data, documentation or the route taken.

To compare a process log with a documented workflow, first align the case boundary, activity names and workflow version. Then inspect recorded cases that appear to follow or depart from the expected route. A mismatch is a question for review: it may reflect a valid exception, an outdated document, a missing event or a route that needs the process owner's attention.

Align the document and log

Obtain the workflow version that applied to the cases being examined, including its branches and completion states. State which case types it covers. A route written for complete requests should not automatically classify every incomplete submission as a departure.

Identify the log's case IDs, event names and timestamps. Map each event to a step or outcome in the document, leaving unmapped events visible. One documented step may produce several system events; a manual decision may produce none. Check these gaps before interpreting a conformance result.

ItemDocumented meaningLogged evidence to check
StartThe event admitting a case to this routeSource event and case identifier
DecisionThe rule and permitted branchDecision or status event and, where needed, the decision record
ReturnWhen and how a case goes backSequence leading to an earlier activity
FinishThe agreed business resultFinal event and, where needed, the destination record

If rules changed during the period, compare each case with the applicable version or state why it was excluded.

Review differences by case

Group cases by recorded route. Inspect examples from common paths and apparent departures. Look for a missing recorded approval, extra review, a return to an earlier step or a different final state. State the affected count and eligible population, and treat open and unmatched cases explicitly in any rate.

For each difference, ask whether the action happened without an event. Check whether the written route permits an exception or parallel step.

Confirm the case was assigned to the right process and rule version. Ask whether the route taken needs a decision from the process owner. Check the source record with the people responsible where the answer matters.

The log shows recorded behaviour; the document describes an expected route. Neither automatically determines whether an individual outcome was appropriate.

Record the resolution

Classify a reviewed difference as a data or mapping issue, an accepted variation to document, a possible control departure to investigate, or unresolved. Keep the case references and reason for the classification. If the workflow is outdated, take the correction to its owner. If relevant events are missing, repair the measurement before reporting a conformance rate as though it covered all cases.

After a correction, compare a defined later period using the same case boundary and applicable rule version, or explain what changed.

More from Process Discovery

Process Discovery

Checking whether available event data supports process mining

Check case IDs, activities, timestamps and event coverage before deciding whether process mining can answer your question.