SYSTEM AND METHOD FOR MANAGING DIGITAL GOVERNANCE IN A DIGITAL ECOSYSTEM

The system addresses the challenges of outdated and biased digital governance by providing a data-driven approach to measure and improve policy effectiveness, ensuring continuous compliance and trust through real-time governance scoring.

JP7761312B2Active Publication Date: 2025-10-28SYBAL ENTERPRISES INC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024508579
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-08-13
Filing Date
2022-08-10
Publication Date
2025-10-28
Estimated Expiration
2042-08-10

AI Technical Summary

Technical Problem

Current digital governance technologies fail to dynamically measure and evaluate policy effectiveness, leading to outdated policies, biased risk assessment, insufficient implementation, and lack of immutability and transparency, which can result in penalties and loss of customer trust.

Method used

A system and method for managing digital governance that includes a data repository and processors to receive policy documents and digital event data, generate violation summaries, determine effectiveness and compliance scores, and communicate governance scores to enterprises for proactive policy adjustments.

Benefits of technology

Enables continuous and impartial measurement of governance effectiveness, ensuring policy relevance and compliance, thereby enhancing trust and reducing risks through real-time policy updates and proactive regulation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007761312000001
    Figure 0007761312000001
  • Figure 0007761312000002
    Figure 0007761312000002
  • Figure 0007761312000003
    Figure 0007761312000003
Patent Text Reader

Abstract

The present invention relates to a system for managing digital governance in a digital ecosystem. The system of the present invention includes a data repository for maintaining a library of policies and procedures used by at least one enterprise, and at least one processor. The processor is capable of: receiving, from the library, documents of policies used by enterprises belonging to the digital ecosystem; receiving digital event data about the actions of participants in the digital ecosystem from a target server associated with the enterprise; creating a violation summary based on the policies and the digital event data, where a violation is recorded if the digital event data does not comply with the policy; determining a policy effectiveness score based on the violation summary; determining a compliance score based on the policy effectiveness score; determining a governance score in the digital ecosystem based on the compliance score; and communicating the governance score to the target server so that the enterprise can take actions to maintain or improve digital governance in the digital ecosystem.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to governance in digital ecosystems, and more particularly to systems, methods and computer program products for managing digital governance in digital ecosystems. [Background technology]

[0002] Governance is a set of rules and standards in the form of policies and procedures to manage and control a system (or a specific area within a system), including measurement and validation of effectiveness for the purpose of maintaining the system. The introduction of governance into digital ecosystems has led to rapid expansion of digital transformation, but there are concerns that users may take advantage of this rapid expansion to carry out malicious actions.

[0003] Existing technologies for policy management pose several challenges. For example, current technologies do not measure or improve the effectiveness of policies implemented by digital ecosystems or digital governance. Furthermore, existing governance policies related to employee management, security, privacy, and other aspects often become outdated within a short period of time (e.g., three to six months). Governance policies need to be updated based on various factors that determine operational effectiveness, incurred losses and realized profits, quality of results, and consumer retention and trust. Furthermore, without implementing effective governance policies, companies risk facing significant fines and warnings (e.g., penalties). Digital ecosystems must dynamically and continuously measure and evaluate the effectiveness of policies to optimize them, maintain their integrity, and gain trust. Current technologies rely on policies as evidence tools, while risk assessment relies on subjective and biased user input. This leads to policy prioritization, biased risk assessment, and insufficient implementation of effective governance through dynamic control. Furthermore, as more participants, such as profiles, organizations, nodes, and users, enter the digital ecosystem, there is a growing need to verify the effectiveness of digital governance to protect them. Current technology does not allow for independent and impartial measurement of governance in terms of analyzing the effectiveness of policies. Furthermore, digital governance cannot be made immutable and transparent, meaning that customers, authorities, and businesses cannot verify and review policies and their implementation. Furthermore, insights gained from governance verification cannot be used to establish proactive regulations.

[0004] There is a need for techniques for establishing governance in digital ecosystems that overcome the above problems and / or limitations. Summary of the Invention

[0005] It is an object of the present invention to provide a system, method and computer program product for managing digital governance in a digital ecosystem that has all the advantages of the prior art and overcomes the problems inherent in the prior art.

[0006] According to one embodiment of the present invention, there is provided a system for managing digital governance in a digital ecosystem. The system includes a data repository and at least one processor communicatively coupled to the data repository. The data repository includes a library storing policies and procedures used by enterprises. The at least one processor is capable of: receiving at least one policy document from the library, where the at least one policy document is used by enterprises belonging to the digital ecosystem; receiving digital event data indicative of the behavior of participants in the digital ecosystem from a target server of the enterprise, where the target server is associated with the enterprises belonging to the digital ecosystem; generating a violation summary based on the at least one policy document and the digital event data, where at least one violation is recorded if the digital event data does not comply with the at least one policy; determining an effectiveness score for the at least one policy based on the violation summary; determining at least one compliance score based on the effectiveness score for the at least one policy; determining a governance score for the digital ecosystem based on the at least one compliance score; and communicating the governance score to the target server so that the enterprise can take at least one action to maintain or improve digital governance in the digital ecosystem.

[0007] According to another embodiment of the present invention, there is provided a method for managing digital governance in a digital ecosystem, the method including receiving at least one policy document from a library stored in a data repository, the library including policies and procedures used by enterprises, the at least one policy document used by the enterprises in the digital ecosystem; receiving digital event data indicative of the behavior of participants in the digital ecosystem from a target server of the enterprises, the target server associated with the enterprises in the digital ecosystem; generating a violation summary based on the at least one policy document and the digital event data, wherein at least one violation is recorded if the digital event data does not comply with the at least one policy; determining an effectiveness score for the at least one policy based on the violation summary; determining at least one compliance score based on the effectiveness score for the at least one policy; determining a governance score for the digital ecosystem based on the at least one compliance score; and communicating the governance score to the target server so that the enterprises can take at least one action to maintain or improve digital governance in the digital ecosystem.

[0008] According to yet another embodiment of the present invention, there is provided a computer program product, the computer program product including a non-transitory computer-readable storage medium having program instructions stored thereon, the program instructions, when accessed by a processing device, performing the following operations: receiving at least one policy document from a library of a data repository, the library storing policies and procedures used by enterprises, the at least one policy document used by enterprises belonging to a digital ecosystem; receiving digital event data indicative of behavior of participants in the digital ecosystem from a target server of the enterprise, the target server associated with the enterprise belonging to the digital ecosystem; creating a violation summary based on the at least one policy document and the digital event data, where if the digital event data does not comply with the at least one policy, the at least one violation is recorded in the summary; determining an effectiveness score for the at least one policy based on the violation summary; determining at least one compliance score based on the effectiveness score for the at least one policy; and communicating the governance score to the target server so that the enterprise can take action to maintain or improve digital governance.

[0009] The subject matter of the present invention is particularly disclosed in the specification and claims appended hereto, and for a further understanding of the invention, reference should be made to the accompanying drawings and detailed description in which exemplary embodiments of the invention are shown. [Brief explanation of the drawings]

[0010] The advantages and features of the present invention may be better understood by reference to the following detailed description and claims taken in conjunction with the accompanying drawings.

[0011] [Figure 1]1 is a diagram of a system for managing digital governance in a digital ecosystem, which is one embodiment of the present invention.

[0012] [Figure 2A] and [Figure 2B] 1 is a block diagram of a system according to a different embodiment of the present invention.

[0013] [Figure 3] 1 shows the flow of a process for recording a procedure violation in an embodiment of the present invention.

[0014] [Figure 4] 1 shows a process flow for recording parameter violations in an embodiment of the present invention.

[0015] [Figure 5] 1 is a diagram showing a process flow for determining the effectiveness score of at least one policy in the event of at least one procedural violation in an embodiment of the present invention.

[0016] [Figure 6] 1 is a diagram showing a process flow for determining the effectiveness score of at least one policy in the event of at least one parameter violation in an embodiment of the present invention.

[0017] [Figure 7] FIG. 1 is a diagram showing the flow of a process for recording evidence of governance in an embodiment of the present invention.

[0018] [Figure 8] 1 shows a process flow for determining at least one action that is required to be performed to maintain or improve digital governance in a digital ecosystem, which is an embodiment of the present invention.

[0019] [Figure 9]1 is a diagram showing the general flow of processing executed by a system according to an embodiment of the present invention.

[0020] [Figure 10] 1 is a flowchart showing steps of a method for managing digital governance in a digital ecosystem, which is an embodiment of the present invention.

[0021] In this specification and drawings, like numbered components and elements refer to like components and elements throughout. DETAILED DESCRIPTION OF THE INVENTION

[0022] For a full understanding of the present invention, please refer to the accompanying claims, drawings, and the following detailed description. Although exemplary embodiments are described herein, the present invention is not intended to be limited to these exemplary embodiments, and equivalents to the contents disclosed herein are also included within the scope of the present invention. Furthermore, the words and terms used in this specification are used for illustrative purposes only and should not be interpreted as limiting. In this specification, the terms "comprise," "comprise," "have," and the like encompass the items listed thereafter and their equivalents.

[0023] In this specification, the term "one" does not refer to "only one" but rather to "at least one."

[0024] The present invention provides a system for managing digital governance in a digital ecosystem. The system includes a data repository and at least one processor communicatively coupled to the data repository. The data repository manages a library storing policies and procedures used by enterprises. The at least one processor is capable of: receiving at least one policy document from the library, where the at least one policy document is used by enterprises belonging to the digital ecosystem; receiving digital event data indicating the behavior of participants in the digital ecosystem from a target server of the enterprise, where the target server is associated with the enterprise belonging to the digital ecosystem; generating a violation summary based on the at least one policy document and the digital event data, where at least one violation is recorded in the summary if the digital event data does not comply with the at least one policy; determining an effectiveness score for at least one policy based on the violation summary; determining at least one compliance score based on the effectiveness score for the at least one policy; determining a governance score for the digital ecosystem based on the at least one compliance score; and communicating the governance score to the target server so that the enterprise can take at least one action to maintain or improve the digital ecosystem.

[0025] Another embodiment of the present invention provides a method for managing digital governance in a digital ecosystem. The method includes receiving at least one policy document from a library stored in a data repository, the library including policies and procedures used by enterprises, the at least one policy document used by the enterprises in the digital ecosystem; receiving digital event data indicative of the behavior of participants in the digital ecosystem from a target server associated with the enterprises in the digital ecosystem; generating a violation summary based on the at least one policy document and the digital event data, wherein at least one violation is recorded if the digital event data does not comply with the at least one policy; determining an effectiveness score for the at least one policy based on the violation summary; determining at least one compliance score based on the effectiveness score for the at least one policy; determining a governance score for the digital ecosystem based on the at least one compliance score; and communicating the governance score to the target server so that the enterprise can take at least one action to manage or improve digital governance in the digital ecosystem.

[0026] The present invention further provides a computer program product, the computer program product including a non-transitory computer-readable storage medium having program instructions stored thereon, which, when accessed by a processing device, cause the program instructions to: receive at least one policy document from a library stored in a data repository, the library including policies and procedures used by enterprises, the at least one policy document used by the enterprises belonging to a digital ecosystem; receive digital event data indicative of behavior of participants in the digital ecosystem from a target server of the enterprises, the target server associated with the enterprises belonging to the digital ecosystem; create a violation summary based on the at least one policy document and the digital event data, and record at least one violation in the summary if the digital event data does not comply with at least one policy; determine an effectiveness score for at least one policy based on the violation summary; determine at least one compliance score based on the effectiveness score for the at least one policy; determine a governance score in the digital ecosystem based on the at least one compliance score; and communicate the governance score to the target server so that the enterprises can take action to manage or improve digital governance.

[0027] FIG. 1 illustrates a system 100 for managing digital governance in a digital ecosystem, according to one embodiment of the present invention. The system includes a target server 102 associated with an enterprise 104, which is communicatively connected to the system 100. At least one processor of the system 100 optionally hosts a platform for managing digital governance in the digital ecosystem. The system 100 is communicatively connected to one or more network entities, such as, for example, a mobile device 108 (e.g., a smartphone, a laptop, a tablet computer), other electronic devices 110 and 112 (e.g., a desktop computer, a server computer), a database 114, sensors 116, actuators, etc., via a communications network 106. The enterprise 104 is a customer of the system 100. Users of the system 100 can include one or more participants, such as a system administrator of the system 100, end users (i.e., customers of the enterprise), auditors, third parties, etc. The enterprise 104 and / or users of the system 100 can access the platform via a web-based software application or a browser. Web-based software applications include, but are not limited to, websites, web applications, desktop applications, and mobile applications compatible with system 100. Examples of communication networks 106 include, but are not limited to, the Internet, radio networks, local area networks (LANs), metropolitan area networks (MANs), wide area networks (WANs), wireless networks, and wired networks.

[0028] 2A and 2B show block diagrams of a system 100 according to another embodiment of the present invention. FIG. 2A shows a simplified block diagram of the system 100, and FIG. 2B shows a detailed block diagram of the system 100, both alone and in connection with other devices. As shown in FIGS. 2A and 2B, the system 100 includes a data repository 120 and at least one processor (processor 122) communicatively connected to the data repository 120. As shown in FIG. 2B, the system 100 may also include a communication device 124, through which the data repository 120 and the at least one processor 122 are communicatively connected and can communicate with all other devices. Here, the communication device 124 is communicatively connected to, for example, a corporate target server (represented by three target servers 126, 128, and 130) and, optionally, at least one regulatory server 132. The at least one processor 122 and the communication device 124 are communicatively coupled to a target server 126 of a business 104 belonging to the digital ecosystem. The target server 126 is a client device for the at least one processor 122, since the business 104 belonging to the digital ecosystem is a customer of the system 100. One or more businesses can utilize the system 100 to manage digital governance in the digital ecosystem, and the business's target server is communicatively coupled to the at least one processor 122 (and in particular, the at least one communication device 124). In some embodiments, the communication device 124 is integrated with the at least one processor 122, while in other embodiments, the communication device 124 is separate from the at least one processor 122.

[0029] The system 100 manages the governance lifecycle of a digital ecosystem. The governance lifecycle, in this context, is also known as the evidence governance lifecycle. The governance lifecycle manages digital governance in a digital ecosystem and can build trust between the enterprise 104's digital ecosystem and its participants. For the system 100 to manage digital governance in a digital ecosystem, it is essential that the enterprise 104 have at least one policy that applies to the digital ecosystem. The at least one policy must be in digital form, and metadata can be created from its records and digital properties. Digitizing the policies involves capturing the policies into a single database (e.g., a library), making them readable, and processing them so that they can be measured and analyzed. Characteristics that can be measured and analyzed include domains, verticals, digital ecosystems, and enterprises. Existing governance applied to a digital ecosystem sets basic parameters or baselines for acceptable behavior in the digital ecosystem. The baseline parameters then set binary flags for what is and is not acceptable, along with reason codes.

[0030] The term “governance” refers to a set of rules, guidelines, recommendations, standards, etc., formulated in the form of policies and procedures that manage and govern the domain of the enterprise 104 by measuring, acting on, and verifying effectiveness. The term “digital governance” simply means digitized governance. The terms “governance” and “digital governance” are used interchangeably herein. The term “managing digital governance in a digital ecosystem” includes at least one of determining the level of governance in a digital ecosystem, verifying governance in a digital ecosystem, recording governance decisions in a digital ecosystem, proposing actions to maintain or improve digital governance in a digital ecosystem, managing digital governance in a digital ecosystem, etc. The system 100 and method for managing digital governance in a digital ecosystem herein include periodic and continuous processes performed by an impartial and independent authority (the authority having the system 100) that exists outside the enterprise 104.

[0031] The data repository 120 comprises a library of policies and procedures used by the enterprise. The term "data repository" refers to hardware, software, firmware, or a combination thereof for storing predetermined information in an organized (i.e., structured) manner so that the information can be easily stored, accessed, searched, updated, and analyzed. The data repository 120 can be implemented as a device's memory (e.g., at least one processor 122), removable memory, cloud-based memory, etc. The data repository 120 can be implemented using one or more storage devices.

[0032] The data repository 120 can be communicatively connected to the target servers (126, 128, and 130) of the enterprise. Here, the data repository 120 is configured to receive policies and procedures used by the enterprise from the target servers (126, 128, and 130) and store them in a library. The enterprise 104 can periodically or intermittently modify, add, or delete policy documents. The data repository 120 can automatically receive information about policy changes from the target servers 126 of the enterprise 104, or the data repository 120 can periodically or intermittently prompt the target servers 126 of the enterprise 104 to make policy changes.

[0033] The library can store one or more policy documents used by one or more enterprises. Here, the library stores one or more policy documents used by enterprises 104, optionally belonging to the digital ecosystem. The library is a digital database managed by the data repository 120 for storing one or more policy documents used by one or more enterprises. Enterprises use one or more policies to ensure compliance. A policy is a one- or multi-page document that sets rules and guidelines for behavior in the digital ecosystem. The term "action" refers to an enterprise's actions in the digital ecosystem. A policy includes its own policies and guidelines, verification models, enforcement programs, etc. The policy governs interactions between participants and the target server 126. Participants can use the target server 126 for services, management, governance, etc. The at least one policy used by the enterprise 104 may be at least one policy and / or at least one regulation established by an industry for the enterprise. The industry may be in the same field as the enterprise 104 or in a different field from the enterprise 104.

[0034] The term "target server" refers to a server of a company that belongs to a digital ecosystem. A digital participant is involved in events in a digital ecosystem. The term "digital participant" or simply "participant" refers to any entity that creates event data in a digital ecosystem. Digital participants can communicate with each other within a digital ecosystem and / or within a digital ecosystem. Examples of digital participants include, but are not limited to, end users, end user profiles, digital entities (digital organizations), digital transactions, IoT devices, entities that use digital entities to create event data, and nodes. The behavior of a digital participant can be normal (i.e., compliant with digital governance) or anomalous (i.e., non-compliant with digital governance). The behavior of an anomalous digital participant is abnormal and optionally triggers governance verification in the digital ecosystem.

[0035] The term "processor" refers to hardware, software, firmware, or a combination thereof configured to perform specialized processing tasks for managing digital governance in a digital ecosystem. At least one processor 122 is communicatively connected to the data repository 120 and at least a target server 126. The communicative connection is performed via a communication device 124 connected / not integrated with the at least one processor 122. The at least one processor 122 is configured to obtain at least one policy document from a library, where the at least one policy document is used by the enterprises 104 belonging to the digital ecosystem; receive digital event data from the target server 126, where the digital event data indicates actions of the enterprises belonging to the digital ecosystem, and the target server 126 is associated with the enterprises 104 belonging to the digital ecosystem; and generate a violation summary based on the at least one policy document and the digital event data. Here, if the digital event data does not comply with at least one policy, at least one violation is recorded in a summary; an effectiveness score for the at least one policy is determined based on the violation summary; at least one compliance score is determined based on the effectiveness score for the at least one policy; a governance score in the digital ecosystem is determined based on the at least one compliance score; and the governance score is communicated to the target server 126 so that the enterprise 104 can take at least one action to maintain or improve governance in the digital ecosystem. These processing steps are described below.

[0036] The at least one processor 122 can receive the at least one policy document from the library in real time or near real time, thereby ensuring that the at least one processor 122 keeps the policies of the enterprise 104 up to date. The at least one policy document can be at least one of a text document, a spreadsheet, a transcript of verbal communication, an image, a video, an audio-video, and an audio. The at least one policy document can be processed by the at least one processor 122. In one embodiment, the at least one policy document is created by the enterprise 104 in a physical format. Here, a device associated with the enterprise 104 is configured to digitize the at least one policy document in physical format and obtain the at least one policy document in digital format. The digitization can be performed by manually entering the at least one policy in physical format (e.g., document, poster), scanning the physical format, using character recognition from an image, etc. The at least one policy document in digital format is shared with the data repository 120. In another embodiment, the at least one policy document is created in digital format. Here, the at least one policy document is created by a device associated with the enterprise 104. The device associated with the enterprise 104 may be, for example, a computing device (desktop computer, laptop computer, server, etc.). The at least one policy document includes at least one policy used by the enterprise 104, which may be either a fixed policy or a dynamic policy. Fixed policies and dynamic policies are described in more detail below.

[0037] Optionally, at least one processor 122 receives digital event data from the target server 126 in real time or near real time. The term "digital event" refers to the results of transactions occurring in the digital ecosystem. The transactions may be monetary or non-monetary. Furthermore, the transactions may be quantifiable or non-quantifiable. Digital event data may also be understood as transaction data. Digital events occurring in the digital ecosystem must be digitally recorded and captured to analyze participants' real-time behavior and / or behavioral history and understand their relationship with at least one policy of the enterprise 104. Digital event data may be one or more of numeric data, text data, image data, transaction logs, cookie data, etc. When providing evidence of governance in any domain or business area, the digital ecosystem or enterprise 104 may not have captured the necessary digital events. In this case, due to the unavailability of digital event data, the system 100 can be used to identify gaps and areas where governance effectiveness improvement and evidence are needed. If some or all of the digital event data is unavailable, the at least one processor 122 may be configured to flag such discrepancies at the time of measurement and communicate the flag to the target server 126 of the enterprise 104.

[0038] The at least one processor 122 creates a violation summary based on the at least one policy document and the digital event data. To create the violation summary, the at least one processor 122 digitally analyzes the participant's behavior with respect to the at least one policy document. If the participant's behavior fully complies with the at least one policy, no violation summary is recorded. On the other hand, if the participant's behavior partially or fully does not comply with the at least one policy, at least one violation is recorded in the summary. The at least one violation may be either a partial violation or a full violation. Recording the at least one violation is described in more detail below.

[0039] 3 shows a process flow for recording a procedure violation in an embodiment of the present invention. In one embodiment, the at least one policy document includes at least one fixed policy, and the at least one fixed policy is associated with at least one procedure. Here, when creating a violation summary, the at least one processor 122 performs the following processing functions: extracting procedure data from the digital event data (302); comparing the procedure data with one or more reference data in the at least one fixed policy (304); and recording a specified violation in the violation summary if the procedure data partially or completely mismatches the reference data (306).

[0040] The term “fixed policy” refers to a policy that does not include quantifiable parameters. Typically, fixed policies are specific to a digital ecosystem / enterprise and include minimal editing, review, and / or measurement. Fixed policies are often created within the framework of a set of policies that the digital ecosystem / enterprise 104 must adhere to. At least one fixed policy is often used to monitor non-quantifiable events. The term “procedure” refers to a set of recordable procedures that the digital ecosystem / enterprise 104 follows to ensure policy compliance. Procedural data in digital event data is captured for the digital ecosystem and includes at least one of steps (including multiple sequential steps, a predetermined number of steps) performed by participants, procedure outcomes, inputs for the procedures, etc. Procedural reference data includes at least one of predetermined procedural steps (including a sequential predetermined procedural steps, a predetermined number of procedural steps), expected procedure outcomes, expected procedure inputs, etc. By matching the procedural data with the procedural reference data, the at least one processor 122 reviews / evaluates the fixed policy and its procedures from the procedural data to detect full / partial violations.

[0041] 4 shows a process flow for recording parameter violations in an embodiment of the present invention. In one embodiment, at least one policy document has at least one dynamic policy, and the at least one dynamic policy is associated with one or more parameters. Here, when creating a violation summary, the at least one processor 122 performs the following processing functions: extract parameter data from digital event data (402), compare the parameter data with reference values ​​or reference ranges of one or more parameters in the at least one dynamic policy (404), and record in the violation summary (406) when the parameter data partially or completely mismatches the reference value and / or when the parameter data is outside the reference range. Here, a violation refers to a parameter violation.

[0042] The term "dynamic policy" refers to a policy that includes measurable (i.e., quantifiable) parameters. A dynamic policy also has one or more of predetermined thresholds, measurements, key performance indicators (KPIs), etc. Dynamic policies may be frequently edited and reviewed to have measurable parameters, predetermined thresholds, and / or measurements. Dynamic policies are often created by digital ecosystems / enterprises themselves to assist in monitoring quantifiable events such as transactions or KPIs. A dynamic policy is associated with a set of one or more parameters. The term "parameter" refers to a measurable entity / element that indicates the operating conditions of a digital ecosystem. The set of one or more parameters in a dynamic policy varies from policy to policy, domain to domain, and digital ecosystem to digital ecosystem.

[0043] The parameter data in the digital event data is actual data captured for the digital ecosystem, and includes at least one of the following: actual parameter values ​​adopted by participants, actual parameter ranges adopted by participants, the actual number of parameters adopted in the digital ecosystem, etc. The parameter reference values ​​and reference ranges associated with one or more parameters in the at least one dynamic policy include, but are not limited to, at least one of expected parameter values ​​adopted by participants, expected parameter ranges adopted by participants, and expected parameter values ​​adopted in the digital ecosystem, etc. The at least one processor 122 evaluates the parameters by comparing the parameter data with the parameter reference values ​​and reference ranges to detect full / partial parameter violations. In the parameter evaluation, it is determined whether the digital event is within the parameter range set by the at least one dynamic policy. Only if the parameter data exactly matches the reference parameter value and / or is within the reference parameter range, is it determined that there is no parameter violation.

[0044] A digital event may be triggered by multiple policies (i.e., multiple fixed policies, multiple dynamic policies, or at least one fixed policy and at least one dynamic policy, etc.). If the digital event does not comply with at least one policy used by the enterprise 104, the digital event may be flagged multiple times and determined to potentially cause multiple violations. These multiple violations are recorded in a violation summary.

[0045] The at least one processor 122 determines an effectiveness score for at least one policy based on the violation summary. The term "policy effectiveness score" refers to a measurable score that indicates how well a policy is being implemented in the digital ecosystem. A high policy effectiveness score is obtained when the number and severity of policy violations recorded in the violation summary are low. Conversely, a high number and severity of violations result in a low policy effectiveness score. A low policy effectiveness score indicates a low (i.e., poor) level of digital governance in the corresponding digital ecosystem. A low policy effectiveness score indicates that the enterprise 104 has established policies for the digital ecosystem, but participants in the digital ecosystem are behaving in violation of the policies. The effectiveness score for at least one policy is determined using at least one of a mathematical formula and a computational algorithm. When participants' behavior triggers anomalies, the multi-model network of the system 100 calculates and learns from these anomalies to analyze their proximity to existing governance parameters. Based on this analysis, a multi-model network-ethical artificial intelligence (AI) optionally measures the effectiveness of the policies. The multi-model network of system 100 is executed by at least one processor 122. The multi-model network of system 100 includes a processing model that employs mathematical formulas and / or computational algorithms to analyze event data and calculate (i.e., measure) a value / score based on the analysis, and an AI model that learns from the at least one policy effectiveness score, at least one compliance score, and governance score and, optionally, makes suggestions and / or predictions, etc. The processing model may also perform other non-AI-based processing tasks. The determination of the at least one policy effectiveness score, at least one compliance score, and governance score is performed by the processing model executed by at least one processor 122. The determination of the at least one policy effectiveness score for different types of violations is described in more detail below.

[0046] 5 shows a process flow for determining the effectiveness score of at least one policy for at least one procedural violation in an embodiment of the present invention. In one embodiment, at least one violation in the violation summary is at least one procedural violation of a fixed policy. When determining the effectiveness score of at least one policy, the processing capabilities of the at least one processor 122 are as follows: initialize the effectiveness score of the fixed policy to an initial value (502), where the initial value is the largest value overall; convert the initial value to a second value by subtracting the scores for at least one procedural violation from the largest value (504); and set the second value as the effectiveness score of the fixed policy (506).

[0047] In the present invention, the effectiveness score of a fixed policy can be initialized to any suitable scale, such as 0 to 1, 0 to 10, 0 to 100, 0 to 1000, or 0 to 100%, where the highest value is 1, 10, 100, 1000, or 100%, respectively. Optionally, in at least one fixed policy, each procedure has a predetermined score, which is equal to the total number of procedures in the at least one fixed policy divided by the highest value representing the whole. When converting the initial value to a second value, the score subtracted from the highest value corresponding to at least one procedural violation depends on the severity of the at least one procedural violation. Here, if a complete procedural violation occurs, all scores related to a given action are subtracted from the initial value. If a partial procedural violation occurs, half of the scores related to a given action are subtracted from the initial value. Such a system and gamification allows the system 100 (particularly the at least one processor 122) to accurately evaluate, measure, and aggregate the effectiveness of fixed policies within the domain of the enterprise 104.

[0048] For example, suppose the overall score is 100 points, and a given fixed policy has a total of 10 procedures. If two of the 10 procedures have complete procedure violations, the initial value (100 points) is deducted by 20 points (10 points for each of the two actions), and the second value is 80 points. In this case, the effectiveness score of the fixed policy is 80 points. In another example, if two of the 10 procedures have complete violations and one partial violation, the initial value (100 points) is deducted by 25 points (10 points for each of the two violations, and 5 points for the single violation), and the second value is 75 points. In this case, the effectiveness score of the fixed policy is 75 points.

[0049] 6 shows a process flow for determining the effectiveness score of at least one policy for at least one parameter violation in an embodiment of the present invention. In one embodiment, the at least one violation in the violation summary is at least one parameter violation in a dynamic policy, and when determining the effectiveness score of the at least one policy, the processing capabilities of the at least one processor 122 are as follows: determine a total number of digital events in the parameter data (602), determine the number of digital events among the total number of digital events that do not result in at least one parameter violation (604), and determine the effectiveness score of the dynamic policy by dividing the number of digital events among the total number of digital events that do not result in at least one parameter violation by the total number of digital events (606).

[0050] Here, the effectiveness score of a dynamic policy is determined by the percentage of digital events that comply with the dynamic policy and the total number of digital events. Only digital events that fully comply with the dynamic policy do not violate any parameters. A digital event fully complies with a dynamic policy (i.e., does not violate at least one parameter) when the digital event's parameter data exactly matches the reference parameter value and / or is within the reference parameter range of the dynamic policy. Because a digital event includes multiple parameters, the number of parameters does not necessarily equal the number of digital events. Analysis of this parameter data allows the system 100 (particularly, the at least one processor 122, and more particularly, the multi-model network processing model executed by the at least one processor 122) to measure and understand the associated data regarding changes between participant behavior and the dynamic policy designed to direct and control intended or pre-approved behavior within specific parameters.

[0051] For example, if a dynamic policy is associated with 15 parameters and the total number of digital events in the parameter data is 20, and 14 of the 20 digital events do not violate at least one parameter, the effectiveness score of the dynamic policy is 0.7 (i.e., 14 divided by 20).

[0052] The effectiveness scores of the dynamic policies may be modified according to the effectiveness scores of the fixed policies, whereby the appropriate measurement scale used to measure the effectiveness of the fixed policies is used as a common scale for measuring the effectiveness of policies in the system 100. This allows the at least one processor 122 to accurately determine the sum and / or average policy effectiveness scores, as needed, for different types of policies and / or enterprises 104. Here, the at least one processor 122 makes such determinations by executing a processing model employing mathematical formulas and / or computational algorithms.

[0053] As another example, assume that enterprise 104 has five fixed policies and two dynamic policies. The effectiveness scores of the five fixed policies are 80, 88, 70, 65, and 90. Furthermore, the effectiveness scores of the two dynamic policies are 0.82 and 0.7. Here, the effectiveness scores of the two dynamic policies can be changed to 82 and 70, respectively, according to the scale of the effectiveness scores of the five fixed policies. At least one processor 122 (particularly, a processing model using mathematical formulas and / or calculation algorithms) can measure the total policy effectiveness scores of the five fixed policies and the two dynamic policies as 393 and 152, respectively. At least one processor 122 can also determine the average policy effectiveness scores of the five fixed policies and the two dynamic policies as 78.6 and 76, respectively. At least one processor 122 can also determine the total and average policy effectiveness scores of enterprise 104 as 545 and 77.857, respectively.

[0054] At least one processor 122 (particularly, a processing model using mathematical formulas and / or computational algorithms) determines at least one compliance score for the digital ecosystem based on the effectiveness score of at least one policy. The enterprise 104 has one or more domains associated with it. Here, at least one compliance score is determined for each domain. That is, a compliance score is determined for each domain based on the effectiveness scores of policies associated with that domain. Domains are also known as business lines or business divisions, and can also be grouped together. The classification of policies into domains is purely a matter of domain rather than policy type. Examples of domains include, but are not limited to, finance, human resources, sales, etc. The compliance score for a given domain can be the sum of the effectiveness scores of policies associated with the given domain. Alternatively, the compliance score for a given domain can be the average of the effectiveness scores of policies associated with the given domain. Alternatively, the compliance score for a given domain can be a weighted average of the effectiveness scores of policies associated with the given domain. If there is only one domain associated with the enterprise 104, one compliance score is calculated as the sum / average / weighted average of the policy effectiveness scores associated with the one domain. The at least one compliance score is the total policy effectiveness score per domain, indicating that the participant's behavior complies with at least one policy. For example, the enterprise 104 has two domains, D1 and D2, and six policies, P1, P2, P3, P4, P5, and P6, where policies P1 and P2 are associated with domain D1 and policies P3, P4, P5, and P6 are associated with domain D2. The policy effectiveness scores of policies P1 and P2 are used to determine a compliance score C1, and the policy effectiveness scores of policies P3, P4, P5, and P6 are used to determine a compliance score C2. The compliance score C1 is associated with domain D1, and the compliance score C2 is associated with domain D2.

[0055] The at least one processor 122 may further have the following processing capabilities: assigning a weight to each policy in the at least one policy document, where the weighting is based on the importance of the policy; and determining at least one weighted policy effectiveness score for each policy in the at least one policy document, where the weighted policy effectiveness score is a product of the weight assigned to the policy and the policy effectiveness score, and where at least one compliance score of the digital ecosystem is determined based on the at least one weighted policy effectiveness score. Not all policies in the at least one policy document are equally important. Some policies may be more important to the operation of the digital ecosystem than other policies. The weighting may be in an appropriate range, for example, one of the following ranges: -1 to 1, 0 to 1, 0 to 10, 0 to 100, etc. As an example, a digital ecosystem may have four policies P1, P2, P3, and P4 with policy effectiveness scores of 75, 80, 65, and 90. The weights of these four policies P1, P2, P3, and P4 can be 0.8, 0.6, 0.8, and 1, respectively. The weighted policy effectiveness scores of the four policies P1, P2, P3, and P4 in this case are 60, 48, 52, and 90, respectively.

[0056] At least one processor 122 (particularly, a processing model using a mathematical formula and / or a computational algorithm) determines a governance score for the digital ecosystem based on the at least one compliance score. The term "governance score" is a measurable quantity indicating the level of effectiveness of an enterprise's governance (i.e., digital governance). Enterprises 104 in the digital ecosystem use at least one policy to implement digital governance, but in reality, digital governance effectiveness may be lost as the digital ecosystem is utilized. The at least one policy effectiveness score and the at least one compliance score are building blocks for understanding the governance effectiveness of the enterprise 104. Accurate, automated determination of the governance score by the at least one processor 122 (particularly, a processing model using a mathematical formula and / or a computational algorithm) means that the enterprise 104 does not need to rely on traditional monitoring schedules to understand risks, training opportunities, policy gaps, and the like. Furthermore, the governance score indicates both the governance health of an individual enterprise and the governance health of the industry. By aggregating and anonymizing these governance scores across multiple companies, it is possible to demonstrate the governance health of the industry to which the companies belong over a period of time, both historically and currently. This is useful for companies104, end clients (i.e., consumers), and regulators, ultimately supporting societal progress through predictive and dynamically controlled digital governance, collectively known as Proof of Governance. The governance score can be understood as evidence / proof of governance, as it indicates that digital governance is being implemented for the digital ecosystem and indicates how effective such digital governance is in practice.

[0057] The governance score for a digital ecosystem may be a sum of at least one compliance score. Alternatively, the governance score for a digital ecosystem may be an average of at least one compliance score. Furthermore, the governance score for a digital ecosystem may be a function of at least one compliance score. The function may be a weighted function, a linear function, a nonlinear function, or the like.

[0058] At least one processor 122 (particularly, a communication device 124 communicatively coupled to the at least one processor) communicates the governance score to the target server 126 to enable the enterprise 104 to take at least one action to maintain or improve governance in the digital ecosystem. The communication is communicated by the at least one processor 122 to the target server 126 via the communication device 124. The governance score can be communicated in real time or near real time. Upon receiving the governance score, the enterprise 104 (particularly, people associated with the enterprise 104) can determine, manually or with the assistance of the system 100, at least one action to take.

[0059] The at least one action may be at least one of a policy suggestion and a training suggestion. The purpose of the at least one action is to enhance, suggest, and / or dynamically control digital governance in the digital ecosystem through policies. The term “policy suggestion” includes any suggestion made regarding at least one policy used by the enterprise 104. The policy suggestion may be one or more of a suggestion to delete a policy, a suggestion to modify a policy, a suggestion on how to modify a policy, a suggestion to add a new policy, etc. The policy suggestion is executed based on the policies of other enterprises that have a digital ecosystem similar to that of the enterprise 104 and have a governance score higher than that of the enterprise 104. The other enterprises may be in the same domain / field as the enterprise 104 or in a different domain / field. The term “training suggestion” includes any suggestion made regarding training participants in the digital ecosystem so that their actions comply with at least one policy of the enterprise 104 belonging to the digital ecosystem. The training suggestion may be one or more of suggestions regarding the policy to the participant, suggestions to provide training to the participant as they are performing the procedure, suggestions to prompt when the participant deviates from the policy procedure, suggestions to prompt for correction when the participant enters an incorrect parameter, suggestions to prompt for correction when the participant enters a parameter value that falls outside the parameter range of reference, etc.

[0060] In one specific example, a policy suggestion may be a suggestion to modify a dynamic policy by triggering a parameter. The parameter triggering may be automated, allowing a program to change threshold parameters. This allows the dynamic policy to be controlled by pre-defined and approved governance without human intervention or manual analysis. The program understands both the policy and / or procedure parameters and the digital events. The digital events are analyzed for proximity to the parameters and thresholds. The program automatically makes the modifications based on the analysis.

[0061] FIG. 7 illustrates a process flow for recording evidence of governance according to an embodiment of the present invention. In one embodiment, at least one processor 122 has the following processing capabilities: timestamp the governance score (702); map the governance score to a unique digital identifier associated with the enterprise 104 (704); and record at least the time-stamped governance score, along with the unique digital identifier, in an immutable digital database as evidence of governance in the digital ecosystem (706). These processing steps can be performed by a processing model of the at least one processor 122. By time-stamping the governance score, the at least one processor 122 tags the governance score with the date and time when the governance score was calculated. Timestamping is very useful for analyzing trends in governance scores over a period of time. The unique digital identifier may be one or more of an alphabetic identifier, a numeric identifier, an alphanumeric identifier, a quick response code, a symbol, a barcode, etc. Mapping the governance score to a unique digital identifier associated with the enterprise 104 can be performed by an ID mapping module of the at least one processor 122. The ID mapping module anonymizes participants so that evidence of governance can be established without the need for personally identifiable information (PII). The at least one processor 122 is configured to create a unique digital identifier associated with the enterprise 104 upon connecting the target server 126 of the enterprise 104 to the system 100 and associate the unique digital identifier with the enterprise 104. Upon such connection, the system 100 (specifically, the ID mapping module of the at least one processor 122) may first create a unique digital identifier associated with the enterprise 104 and then map existing metadata of the target server 126 to the unique digital identifier in order to associate the unique digital identifier with the enterprise 104. At least one processor 122 (particularly, an ID mapping module) may be configured to store a mapping of the company's unique digital identifier in the data repository 120. The at least one processor 122 may further be configured to store the mapping of the company's unique digital identifier as an immutable record in an immutable digital database. The unique digital identifier is used to record at least a governance score in the immutable digital database to avoid using personally identifiable information (PII) of the company 104. Recording in the immutable digital database is performed without requiring PII, thereby protecting the privacy of the company 104. Evidence of governance in the company's 104 digital ecosystem is established as at least a recorded governance score that is time-stamped and associated with the unique digital identifier. The evidence of governance serves as immutable evidence that governance exists in the digital ecosystem and that actions are taken to protect participants and users of the digital ecosystem. The evidence of governance is accessible and / or searchable from the immutable digital database for viewing, auditing, etc. The governance record on the immutable digital database establishes Govbit(z), which is a governance decision on the immutable digital database. Govbit(z) is an immutable record of data / information stored on the immutable digital database. Govbit(z) can be retrieved from the immutable digital database for audit and governance evidence. Govbit(z) may be immutable digital governance evidence for digital participants, and at least one processor 122 may be configured to store Govbit(z) on the immutable digital database. Furthermore, Govbit(z) can be accessed and verified through the immutable digital database by digital participants, authorities (such as regulators), companies, etc. It is important to prove that governance decisions are based on impartial, independent measurement and analysis.Thus, evidence of governance can only be established if facilitated, supported, and enforced by an external entity, such as the system 100. Once evidence of governance is established, the enterprise 104 can use the evidence of its governance performance to build more trust in its business dealings with consumers (i.e., end users) and regulators.

[0062] The at least one processor 122 may be configured to time-stamp, map to a unique digital identifier associated with the enterprise 104, and record at least one of the at least one policy effectiveness score, the at least one compliance score, the violation summary, the event data, and the at least one policy in an immutable digital database, where the at least one policy effectiveness score, the at least one compliance score, the violation summary, the event data, and the at least one policy constitute evidence of governance in addition to the governance score. The at least one of the scores / data indicates governance health in the digital ecosystem and provides insights for constituting a measured evidence of governance score. The processing is performed by a processing model of the at least one processor 122.

[0063] The immutable digital database may be an immutable distributed ledger or blockchain. The immutable digital database may be implemented as an immutable digital capture. Anything recorded in the immutable digital database cannot be changed. This means that evidence of governance established on the immutable digital database is immutably recorded for current and future reference. The immutable distributed ledger may be hosted by a private centralized server, and the at least one processor 122 is communicatively connected to the private centralized server. The blockchain may be a private blockchain.

[0064] The at least one processor 122 may further have the following processing capabilities: receive at least one new policy document from the data repository 120 indicating at least one new policy to be used by the enterprise 104; create a smart contract to implement the at least one new policy, where the smart contract is bound to a unique digital identifier associated with the enterprise 104, and the smart contract determines a version of the at least one new policy and a governance for implementing the action, along with a unique policy identifier associated with the at least one new policy; timestamp the creation of the smart contract; and record the smart contract in an immutable digital database. In this manner, the immutable digital database records actions and enables the implementation of at least one new policy. The predetermined new policy may be an entirely new policy, a modified version of an existing policy, etc. A unique policy identifier (ID) may be represented as one or more of an alphabetic identifier, a numeric identifier, an alphanumeric identifier, a quick response code, a symbol, a barcode, etc. Here, Govbit(z) is created on the immutable digital database. The implementation of at least one new policy may be proposed by at least one processor 122. At least one new policy document indicating the at least one new policy to be implemented by the enterprise 104 may be communicated to the data repository 120 by the target server 126 of the enterprise 104. A smart contract is a secure digital contract that can execute itself. The smart contract of the present invention is applicable to the enterprise 104 and participants in the digital ecosystem. Smart contracts reduce administrative processing and cannot be tampered with because they are quickly created and recorded in an immutable digital database.

[0065] The data repository 120 can be communicatively connected to at least one regulatory authority server 132, where the data repository 120 is configured to retrieve policies and / or statutes created by industry for enterprises from the at least one regulatory authority server and store the policies and / or statutes in a regulatory authority library, where the regulatory authority library stores at least one regulatory authority document, where the at least one regulatory authority document is used by enterprises to determine policies and procedures.

[0066] The at least one regulatory authority may periodically or intermittently revise existing policies and / or laws, add new policies and / or laws, delete one or more of the existing policies and / or laws, etc. The data repository 120 may automatically receive information regarding changes to such policies and / or laws from the at least one regulatory authority's server 132, or the data repository 120 may periodically or intermittently prompt the at least one regulatory authority's server 132 for updates regarding changes to such policies and / or laws.

[0067] The regulatory library can store one or more policy documents created by at least one regulatory authority. Here, the regulatory library can store at least all regulatory authority documents used by enterprises 104 belonging to the digital ecosystem. The regulatory library is a digital database managed by the data repository 120 for storing one or more regulatory authority documents. Enterprises must comply with (i.e., conform to) one or more policies and / or regulations to be in compliance. A regulatory authority document is a single-page or multi-page document that sets policies and / or regulations for behavior in the digital ecosystem. At least one policy and / or at least one regulation created by industry for an enterprise serves as a document of reference for at least one policy used by the enterprise 104. Thus, at least one regulatory authority document is related to at least one policy, and at least one policy document is created based on at least one regulatory authority document. At least one regulatory authority document can be used as a reference document for creating policy proposals and / or policy and / or regulation proposals. At least one regulator may be an independent regulator, an industry regulator, or a government regulator.

[0068] The at least one processor 122 may receive the at least one regulatory document from the regulatory library in real time or near real time, thereby enabling the at least one processor 122 to stay current with policies and / or regulations used by the enterprise 104, particularly in the digital ecosystem. The at least one regulatory document may be in the form of a text document, a spreadsheet, or one or more other formats that can be processed by the at least one processor 122.

[0069] 8 shows a process flow for determining at least one action to maintain or improve digital governance in a digital ecosystem in an embodiment of the present invention. In one embodiment, the data repository 120 is configured to store records of risk cases of corporate antecedents. Here, the at least one processor 122 is configured to: receive the records of risk cases of corporate antecedents from the data repository (802); predict a risk level of digital governance in the digital ecosystem based on a violation summary and an effectiveness score of at least one policy (804); determine at least one action to maintain or improve digital governance in the digital ecosystem based on the risk level (806); and communicate the at least one action to the target server 126 (808). The at least one processor 122 has processing capability to update policy weights in at least one policy document (810).

[0070] Here, the at least one processor 122 (particularly, the AI ​​model executed by the at least one processor 122) suggests at least one action to the enterprise 104. This reduces the enterprise 104's efforts in analyzing indicators of digital governance in the digital ecosystem and suggesting actions to maintain or improve digital governance. Furthermore, because the at least one processor 122 accurately analyzes in detail the digital event data, the policies used by the enterprise 104, the enterprise's precedent risk cases, the violation summary, and the effectiveness score of the at least one policy, the at least one action suggested by the at least one processor 122 is highly useful for managing, controlling, or strengthening governance in the digital ecosystem.

[0071] At least one processor 122 can execute a model for predicting the digital governance risk level in the digital ecosystem. At least the company's precedent risk case records, violation summaries, and at least one policy effectiveness score serve as inputs for the predictive model. The predictive model functions as a tool for predicting the risk of the digital ecosystem / company 104 according to the summation of a series of scores (indicative of performance) created by the at least one processor 122 over time. Such scores include at least one policy effectiveness score, a governance score, and at least one compliance score. The predictive model is an AI model executed by the at least one processor 122. The violation summaries are first analyzed for precedent risk cases associated with similar violations in the digital ecosystem, and then performance data related to the precedent risk cases is compared with the company's performance data (e.g., at least one policy effectiveness score) to accurately determine the risk level. The predictive model may be a machine learning-based model. Here, the predictive model can be trained using at least one machine learning algorithm until a required accuracy of the predictive model is achieved. Such machine learning algorithms are well known in the art. The predictive model considers the company's precedent risk cases and the digital ecosystem's violation summary and policy effectiveness score to predict the risk that digital governance in the digital ecosystem does not comply with regulations and / or statutes of at least one regulatory body. The at least one processor 122 may have processing capabilities to predict a risk level of digital governance in the digital ecosystem based on the at least one compliance score. The risk level may be a penalty risk level (i.e., a level of risk of receiving a fine or penalty). Alternatively, the risk level may be a warning risk level (i.e., a level of risk of receiving a warning). Furthermore, the risk level may be a general risk level.

[0072] The data repository 120 is further configured to store past and current performance data of the enterprise 104. Here, the past and current performance data includes at least one of the following: a summary of past and current violations of the enterprise 104, past and current policy effectiveness scores, past and current compliance scores, and past and current governance scores. Here, when predicting a digital governance risk level in the digital ecosystem, the at least one processor 122 has processing capabilities to process the past and current performance data of the enterprise 104 using at least one predictive model. The performance data is output generated by the at least one processor 122 (particularly by the processing model of the at least one processor 122) related to digital governance in the digital ecosystem. The previous performance data and current performance data of the enterprise 104 represent both a previous and real-time assessment of digital governance in the digital ecosystem and are used to perform predictive analysis. The past data is historical internal data collected by the target server 126 from the system 100 and / or historical external data collected by the target server 126 from external sources. The at least one processor 122 compares the current performance data with antecedent performance data (which are precedents that provide evidence of the antecedent risk / violation-worthy event / case) to determine similarity. The greater the similarity between the current performance data and the antecedent performance data that led to the antecedent risk / violation-worthy event / case, the higher the risk level of digital governance in the digital ecosystem. Based on the predicted risk level, the at least one processor 122 takes action to prevent the score of governance in the digital ecosystem from dropping to the point where it becomes too risky or violates.At least one action is determined to enable the enterprise 104 to maintain digital governance in the digital ecosystem if the governance score is high and the risk level is low, and to enable the enterprise 104 to improve digital governance in the digital ecosystem if the governance score is low and the risk level is high.

[0073] This disclosure further describes pre-processing and post-processing of digital events. The enterprise 104 acts as the enforcer of governance policies. The system 100 can establish evidence of governance in two ways. First, the transaction receiver receives metadata from customers before settling the participant's digital transaction event, the transaction receiver enforces static policies, and then establishes evidence of governance as described above. Second, the transaction receiver receives metadata from customers after the digital transaction event is settled, and then establishes evidence of governance as described above.

[0074] Additionally, the present invention employs a transaction receiver. Furthermore, the system 100 can utilize a transaction receiver so that the system 100 operates behind the enterprise 104's applications without disrupting its participants' experience. The transaction receiver can obtain transaction metadata (i.e., digital event data) of the enterprise 104 via an API. The transaction receiver can be software and / or firmware. The system 100 can utilize the API as a governance agent in the enterprise 104's network. The system 100 can also utilize the API to obtain metadata for establishing governance evidence on behalf of the enterprise 104. The API interacts with at least one processor 122.

[0075] As an example, the immutable digital database may be the Hyperledger Fabric blockchain. In this example, Govbit(z) can be committed to the Hyperledger Fabric blockchain in three steps. First, the system 100 can communicate any additional information, such as a governance score, a unique identifier for the company 104, training suggestions, policy suggestions, a violation summary, or an action (synonymous with a governance decision), to the smart contract. Next, the smart contract immutably captures the governance decision, and the resulting Govbit(z) executed on the transaction is communicated to the system 100. Finally, Govbit(z) is packaged into a block and communicated to a private channel on the node for committing to the ledger. The blockchain is used by the system 100 to record and receive, in real time, near time, or at scheduled times, granting access to the blockchain. When a new policy is added to the repository or a policy is updated to a new version, the system 100 can prompt an action via the smart contract and immutably record the new policy's unique policy ID on the blockchain.

[0076] At least one processor 122 has processing capabilities to analyze digital event data to identify behaviors of participants in the digital ecosystem, generate at least one policy and / or procedure proposal based at least on the participant behaviors, and deliver the proposal to at least one regulatory server 132. The processing is performed by a model executed by the at least one processor 122, where the at least one processor 122 makes the proposal to proactively establish policies. The analysis of the digital event data provides insights into the (real-time) behaviors of participants in the digital ecosystem, where the insights are used to generate the proposal. Also, if the analysis reveals undesirable trends or patterns in participant behavior that violate policies, the at least one processor 122 makes the proposal to prevent such undesirable trends or patterns. The at least one processor 122 makes the at least one policy and / or regulatory proposal based on at least one regulatory document. Here, upon identifying policy-violating digital participant behavior, the at least one processor 122 identifies which behavior violates which policy, and therefore which procedure. This enables the at least one processor to generate accurate and useful suggestions for at least one regulation and / or statute. The at least one processor 122 communicates the suggestions to the server 132 for review as a way to enable proactive policy determination. The at least one regulator can implement or reject the suggestions.

[0077] The system 100 can anonymize the behavior of participants across industries. The various digital ecosystems may be associated with various companies. The anonymized participant behavior can be aggregated in a data repository 120 using various communication devices. At least one processor 122 accesses the aggregated, anonymized participant behavior and generates proposals based thereon. Here, different processors of the system 100 can perform processing tasks related to managing governance in different ecosystems. Individuals / entities cannot access the system 100 to make proposals. Only the at least one processor 122 can access the anonymized participant behavior across industries to make proposals.

[0078] The at least one processor 122 has processing capability to update (810) the weighting assigned to each policy in the at least one policy document. When a target server 126 connects to the system 100, the at least one processor 122 assigns an initial weighting value to each policy based on the policy and an assessment of the digital ecosystem and / or enterprise 104. The initial value is then updated by the at least one processor 122 based on at least one of governance of the digital ecosystem and / or enterprise 104, performance data, penalty data, and a risk level of digital governance in the digital ecosystem.

[0079] FIG. 9 illustrates a general process flow executed by the system 100 according to an embodiment of the present invention. An ID mapping module 902 of at least one processor 122 is connected to a client database 904. The client database 904 is a database managed by the target server 126 of the enterprise 104. At least one policy document in the client database 904 is used to create a library 906 in the data repository 120 of the system 100. The library 906 can store at least one fixed policy 908 and / or at least one dynamic policy 910. The at least one fixed policy 908 is associated with one or more procedures 912. The at least one dynamic policy 910 is associated with one or more parameters 914. A procedure evaluation 916 is performed to determine whether a procedure violation has occurred. A parameter evaluation 918 is performed to determine whether a parameter violation has occurred. A violation summary 920 is created based on the procedure evaluation 916 and the parameter evaluation 918. The violation summary 920 is used to determine an effectiveness score 922 for at least one policy. The at least one policy effectiveness score 922 is used to determine at least one compliance score 924 in the digital ecosystem, and the at least one compliance score is used to determine a governance score 926 in the digital ecosystem. The governance score enables the enterprise 104 to take at least one action to maintain or improve digital governance in the digital ecosystem. At 928, evidence of governance is recorded in an immutable digital database. This results in Govbit(z) being committed to the immutable ledger, finalizing the evidence of governance. Supporting features designed to further encourage good governance behavior by alerting the enterprise 104 to risks are described below. A regulator database 930 is maintained on at least one regulator server 132.The at least one regulatory agency document in the regulatory agency database 128 is used to create a regulatory agency library 932 in the data repository 120 of the system 100. A risk level prediction 934 can be performed to predict (using the AI ​​model) a digital governance risk level in the digital ecosystem, and based on the risk level 936, at least one action can be suggested to maintain or improve digital governance in the digital ecosystem. The at least one action is at least one of a policy suggestion 938, a training suggestion 940. The at least one regulatory agency document can be used to create the policy suggestion 938.

[0080] FIG. 10 is a flowchart illustrating steps of a method 1000 for managing digital governance in a digital ecosystem, an embodiment of the present invention. In step 1002, at least one policy document is received from a regulatory library managed in a data repository 120. The regulatory library stores policy and procedure documents used by enterprises, and the at least one policy document is used by an enterprise 104 belonging to the digital ecosystem. In step 1004, digital event data is received from a target server 126. The digital event data indicates the behavior of participants in the digital ecosystem, and the target server 126 is associated with the enterprise 104 belonging to the digital ecosystem. In step 1006, a violation summary is created based on the at least one policy document and the digital event data. If the digital event data does not comply with the at least one policy, at least one violation is recorded in the violation summary. In step 1008, an effectiveness score for at least one policy is determined based on the violation summary. In step 1010, at least one compliance score is determined based on the effectiveness score for the at least one policy. In step 1012, a governance score in the digital ecosystem is determined based on the at least one compliance score. In step 1014, the governance score is connected to a target server 126 for the enterprise 104 to perform at least one action to maintain or improve digital governance in the digital ecosystem. Method 1000 enables efficient and accurate management of digital governance in a digital ecosystem. Method 1000 is simple, fast, and reliable.

[0081] The method 1000 may further include: time-stamping the governance score; mapping the governance score to a unique digital identifier associated with the enterprise 104; and recording at least the time-stamped governance score along with the unique digital identifier in an immutable digital database as evidence of governance in the digital ecosystem. The process flow is described above in conjunction with FIG. 7.

[0082] The method 1000 may further include receiving, from the data repository 120, at least one new policy to be implemented by the enterprise 104; creating a smart contract to enforce the implementation of the at least one new policy, where the smart contract is bound to a unique digital identifier associated with the enterprise 104, where the smart contract determines a version of the at least one new policy and a governance implementing action, along with a unique policy identifier associated with the at least one new policy, and time-stamping the creation of the smart contract; and recording the smart contract in an immutable digital database, as described above.

[0083] The method 1000 may further include receiving a record of risk cases of the enterprise's antecedents; predicting a risk level of digital governance in the digital ecosystem based on at least one violation summary and at least one policy effectiveness score; determining at least one action to maintain or improve governance in the digital ecosystem based on the risk level; and communicating the at least one action to the target server 126. These process flows are as described above in conjunction with FIG. 8.

[0084] In method 1000, at least one violation in the violation summary is a violation related to at least one procedure of a fixed policy, and wherein determining the effectiveness score of the at least one policy includes: initializing the effectiveness score of the fixed policy to an initial value, where the initial value is the largest overall value; changing the initial value to a second value by subtracting points corresponding to the at least one procedure violation from the largest value; and determining the effectiveness score of the fixed policy as the second value. These process flows are as described above in conjunction with FIG. 5.

[0085] In method 1000, at least one violation in the violation summary is at least one parameter violation of a dynamic policy, and wherein determining an effectiveness score of the at least one policy includes: determining a total number of digital events in the parameter data; determining a number of digital events among the total number of digital events that do not result in at least one parameter violation; and dividing the number of digital events among the total number of digital events that do not result in at least one parameter violation by the total number of digital events to determine an effectiveness score of the dynamic policy. These process flows are as described above in conjunction with FIG. 6.

[0086] The present invention also provides a computer program product. The various embodiments and examples disclosed above with respect to the aforementioned system 100 and method 1000 also apply mutatis mutandis to the computer program product. In the computer program product, examples of non-transitory machine-readable storage media include, but are not limited to, electronic storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, portable computer diskettes, hard disks, random access memories, including, but not limited to, hard disks, random access memories (RAMs), read-only memories (ROMs), erasable programmable read-only memories (EPROMs or flash memory), static random access memories (SRAMs), portable compact disk read-only memories (CD-ROMs), digital versatile disks (DVDs), memory sticks, or any combination thereof.

[0087] The system 100, method 1000, and computer program product provide an innovative and efficient solution for managing digital governance in a digital ecosystem. The system 100, method 1000, and computer program product provide an efficient and effective solution for enforcing, suggesting, and dynamically controlling governance through policies. Such governance enforcement, suggestions, and dynamic controls are performed without PII. For the aforementioned purposes, the system 100, method 1000, and computer program product utilize ethical AI to calculate behavioral anomalies of participants in a digital ecosystem. Additionally, the system 100 can detect participants engaging in malicious events in the digital ecosystem. The system 100, method 1000, and computer program product can establish evidence of governance on an immutable digital database, for example, for monitoring purposes and to establish trust between the digital ecosystem and its end users. The system 100 also serves as an impartial third party regarding the digital ecosystem and its end users. As more users participate in the digital ecosystem, the need for digital governance to protect users and evidence of its effectiveness increases. The system 100, method 1000, and computer program product enable the recording of governance decisions in an immutable digital database and enable real-time insight into participant behavior to establish proactive policies. The system 100 can also dynamically reinforce, discover, and propose policies to protect participants. Many industries suggest reviewing policies annually, or preferably every six months. Because ecosystems are inherently dynamic, from policy drafting to approval, implementation, and evaluation, policies may lose their effectiveness and, over time, their desired capabilities. The method 1000 described herein can effectively manage governance in real time on top of existing governance and within a digital ecosystem to achieve the desired policy objectives.

[0088] The foregoing descriptions of specific embodiments of the present invention have been presented for purposes of illustration and description. They are not intended to be exhaustive or to limit the invention to the precise forms disclosed, and obviously, many modifications and variations are possible in light of the above teachings. The embodiments have been chosen and described to best explain the principles of the invention and its practical application, so as to enable those skilled in the art to best utilize the invention and its various embodiments, with various modifications as may be suited to the particular uses contemplated. Various omissions and substitutions of equivalents are contemplated as circumstances may suggest or are expedient, but these are intended to cover applications or practices without departing from the spirit or scope of the claims of the present invention.

Claims

1. A system for managing digital governance in a digital ecosystem, comprising: (1) a data repository that maintains at least one policy library containing policies and procedures used by the enterprise; (2) at least one processor communicatively connected to said data repository, wherein the at least one processor has the following processing capabilities: (i) obtaining at least one policy document from a policy library, where the at least one policy document is used by businesses in the digital ecosystem; (ii) obtaining digital event data from a target server, wherein the digital event data indicates participant behavior in a digital ecosystem, and the target server is associated with an enterprise belonging to the digital ecosystem; (iii) generating a violation summary based on the at least one policy document and the digital event data, wherein if the digital event data does not comply with the at least one policy document, the at least one violation is recorded in the violation summary; (iv) determining an effectiveness score for at least one policy based on the violation summary; wherein the at least one violation in the violation summary is at least one procedural violation in a fixed policy, and when determining the effectiveness score of the at least one policy, the at least one processor has the following processing capabilities: (a) Initialize the effectiveness score of the fixed policy, where the initial value is the largest value among all; (b) determining a second value by subtracting from said largest value (initial value) the score corresponding to at least one procedural violation; (c) determining the second value as the effectiveness score of the fixed policy; (v) determining at least one compliance score from the effectiveness score of the at least one policy; (vi) determining a governance score for the digital ecosystem from the at least one compliance score; (vii) time-stamping said governance score; (viii) mapping the governance score to a unique digital identifier associated with the company; (ix) recording at least one time-stamped governance score together with a unique digital identifier in an immutable digital database as evidence of governance in the digital ecosystem, and recording at least one time-stamped governance score together with the unique digital identifier; (x) communicating the governance score to a target server so that the enterprise can take at least one action to maintain or improve digital governance in the digital ecosystem;

2. 10. The system of claim 1, wherein the immutable digital database is an immutable distributed ledger or blockchain.

3. 2. The system of claim 1, wherein said at least one processor has the following processing capabilities: (1) receiving from a data repository a document of at least one new policy that the enterprise will implement; (2) creating a smart contract that enforces an action that implements the at least one new policy, where the smart contract is bound to a unique digital identifier associated with the enterprise, and where the smart contract includes a version of the at least one new policy, a unique policy identifier associated with the at least one new policy, a governance decision to implement the action, and a timestamp creating the smart contract, and recording the smart contract in an immutable digital database;

4. The system of claim 1 , wherein the at least one action is at least one of a policy suggestion, a training suggestion.

5. 10. The system of claim 1, wherein the data repository is further configured to store a record of the company's prior risk cases, and wherein the at least one processor has the processing capabilities of: (1) Obtaining records of the company's precedent risk cases from the data repository; (2) predicting the risk level of digital governance in the digital ecosystem based on at least a violation summary and at least one policy effectiveness score; (3) based on the risk level, determine at least one action to be taken to maintain or improve digital governance in the digital ecosystem; (4) Propagate at least one action to a target server.

6. 6. The system of claim 5, wherein the data repository is further configured to store past and current performance data of the enterprise, the past and current performance data including at least one of a summary of past and current violations of the enterprise, past and current policy effectiveness scores, past and current compliance scores, and past and current governance scores, and wherein when predicting a digital governance risk level in the digital ecosystem, at least one processor processes the past and current performance data of the enterprise using at least one predictive modeling technique.

7. 6. The system of claim 5, wherein the data repository is communicatively connected to at least one regulatory authority server, and wherein the data repository is configured to receive from the at least one regulatory authority server regulations and / or laws set by industry for companies and store the regulations and / or laws in the form of a regulatory authority library, the regulatory authority library including at least one regulatory authority document, and the at least one regulatory authority document is used by companies to create policies and procedures.

8. 8. The system of claim 7, wherein the at least one processor further comprises the following processing capabilities: (1) Analyzing digital event data to identify the behavior of participants in the digital ecosystem; (2) develop at least one proposed code and / or statute based at least on the actions of participants; (3) transmitting said proposal to at least one regulatory authority server;

9. 2. The system of claim 1, wherein the at least one policy document includes at least one fixed policy, the at least one fixed policy being associated with one or more procedures, and wherein when creating the violation summary, the at least one processor has the following processing capabilities: (1) Extracting procedure data from digital event data; (2) matching the procedure data with procedure reference data associated with one or more procedures of at least one fixed policy; (3) if the procedural data is partially or completely inconsistent with the procedural reference data, record a predetermined violation in the violation summary, where the predetermined violation is a procedural violation;

10. 2. The system of claim 1, wherein the at least one policy document includes at least one dynamic policy, the at least one dynamic policy being associated with one or more parameters, and wherein when generating the violation summary, the at least one processor has the following processing capabilities: (1) Extracting parameter data from digital event data; (2) comparing the parameter data to parameter reference values ​​and parameter reference ranges associated with one or more parameters of the at least one dynamic policy; (3) When the parameter data is partially or completely inconsistent with the reference parameter value and / or when the parameter data is outside the parameter range of the reference, recording a predetermined violation in the violation summary, where the predetermined violation is a parameter violation.

11. 2. The system of claim 1, wherein at least one violation in the violation summary is a violation of at least one parameter of a dynamic policy, and wherein when determining an effectiveness score for the at least one policy, the at least one processor has the following processing capabilities: (1) determining the total number of digital events in the data; (2) determining the number of digital events out of the total number of digital events that do not result in at least one parameter violation; (3) determining an effectiveness score for the dynamic policy as the number of digital events that do not cause at least one parameter violation divided by the total number of digital events;

12. 2. The system of claim 1, wherein the data repository is communicatively connected to a target server associated with the enterprise, and the data repository is configured to receive from the target server policies and procedures used by the enterprise and store the policies and procedures in the form of the library.

13. 10. The system of claim 1, wherein the at least one processor further comprises the following processing capabilities: (1) weighting each policy in the at least one policy document, wherein the weight is determined based on the importance of the policy; (2) determining at least one weighted policy effectiveness score for each policy of the at least one policy document, wherein a predetermined weighted policy effectiveness score is a product of a weight assigned to the policy and the policy effectiveness score, and determining at least one compliance score for the digital ecosystem based on the at least one weighted policy effectiveness score.

14. 1. A computer processor-executed method for managing digital governance in a digital ecosystem, the method comprising: (1) obtaining at least one policy document from a library of policies maintained in a data repository, where the library of policies includes policies and procedures used by the enterprise, and where the at least one policy document is used by the enterprise to which the digital ecosystem belongs; (2) obtaining digital event data from a target server, where the digital event data indicates the behavior of participants in the digital ecosystem, and the target server is associated with an enterprise belonging to the digital ecosystem; (3) creating a violation summary based on the at least one policy document and the digital event data, wherein if the digital event data does not comply with the at least one policy document, at least one violation is recorded in the violation summary; (4) determining an effectiveness score for at least one policy based on a violation summary, where the at least one violation of the violation summary is at least one procedural violation of a fixed policy, and determining the effectiveness score for the at least one policy includes: (i) initializing the effectiveness score of the fixed policy to an initial value, where the initial value is the largest value overall; (ii) reducing the initial value to a second value by subtracting points corresponding to at least one procedural violation from the highest value, and determining the effectiveness score of the fixed policy as the second value; (5) determining at least one compliance score based on the effectiveness score of the at least one policy, determining a governance score for the digital ecosystem based on the at least one compliance score, time-stamping the governance score, and mapping the governance score to a unique digital identifier associated with the enterprise; (6) recording at least one governance score, time-stamped with a unique digital identifier, in an immutable digital database as evidence of governance in the digital ecosystem; and (7) Communicating the governance score to a target server to enable the enterprise to take at least one action to maintain or improve digital governance in the digital ecosystem.

15. 15. The method of claim 14, further comprising: (1) receiving from the data repository at least one document of a new policy to be implemented by the enterprise; (2) creating a smart contract to facilitate an action to implement the at least one new policy, wherein the smart contract is associated with a unique digital identifier associated with the enterprise, and the smart contract includes a unique policy identifier associated with the at least one new policy, a version of the at least one new policy, a governance decision to implement the action, and a timestamp for creating the smart contract; (3) Record the smart contract in an immutable digital database.

16. 15. The method of claim 14, further comprising: (1) receive records of the company's precedent risk cases; (2) predicting a digital governance risk level in the digital ecosystem based on at least one violation summary and at least one policy effectiveness score; (3) Based on the risk level, determine at least one action required to be taken to maintain or improve governance in the digital ecosystem, and communicate the at least one action to the target server.

17. 15. The method of claim 14, wherein at least one violation in the violation summary is at least one parameter violation in a dynamic policy, and an effectiveness score of the at least one policy is determined by: (1) determining the total number of digital events in the parameter data; (2) determining the number of digital events out of the total number of digital events that do not result in at least one parameter violation; (3) determining an effectiveness score for the dynamic policy as the number of digital events that do not cause at least one parameter violation divided by the total number of digital events;

18. A computer program which, when executed by a processor, causes the processor to: (1) receiving at least one policy document from a library of policies stored in a data repository, where the library of policies includes policies and procedures used by enterprises, and where the at least one policy document is used by enterprises belonging to the digital ecosystem; (2) receiving digital event data from a target server, where the digital event data is indicative of the behavior of participants in the digital ecosystem, and the target server is associated with an enterprise belonging to the digital ecosystem; (3) creating a violation summary based on the at least one policy document and the digital event data, and if the digital event data does not comply with the at least one policy document, recording at least one violation in the violation summary; (4) determining an effectiveness score for the at least one policy based on the violation summary, where the at least one violation in the violation summary is at least one procedural violation of the fixed policy, and when determining the effectiveness score for the at least one policy, the at least one processor has the following processing capabilities: (i) initializing the effectiveness score of the fixed policy to a first value, where the first value is the largest value overall; (ii) reducing the initial value to a second value by subtracting points corresponding to at least one procedural violation from the largest value, and determining the effectiveness score of the fixed policy as the second value; (5) determining at least one compliance score based on the effectiveness score of the at least one policy; (6) determining a governance score for the digital ecosystem based on the at least one compliance score; (7) time-stamping the governance score; (8) mapping the governance score to a unique digital identifier associated with the company; recording at least one time-stamped governance score together with the unique digital identifier in an immutable digital database as evidence of governance in the digital ecosystem; and (9) Communicating the governance score to a target server to enable the enterprise to take at least one action to maintain or improve digital governance.

Citation Information

Patent Citations

  • System and method for creating and executing data-driven legal contracts

    US20170287090A1

  • Threat response using event vectors

    US20190319980A1

  • System and method to monitor, alert and predict precursory behavior

    US20200005213A1

  • Financial transaction analytics and data management

    WO2020264224A1