Data governance system and methods

The method and system address the challenge of verifying data asset conformity to governance policies by using automated and user-certified processes, ensuring efficient compliance with dynamic data in large-scale data processing systems.

JP7856677B2Active Publication Date: 2026-05-11AB INITIO TECHNOLOGY LLC
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
AB INITIO TECHNOLOGY LLC
Filing Date
2022-06-07
Publication Date
2026-05-11

AI Technical Summary

Technical Problem

Modern data processing systems face challenges in efficiently verifying whether vast amounts of data assets conform to data governance policies, especially given the dynamic nature of data and the complexity of managing billions of data records across multiple locations.

Method used

A method and system for determining data compliance using a data governance policy, involving the use of computer hardware processors to receive user input, generate data asset sets, associate standards with these sets, and verify conformity through attribute-based rules, with optional user certification and communication network interactions.

Benefits of technology

Enables efficient verification of data asset conformity to governance policies, ensuring data integrity and security across large datasets, even with dynamic updates and multiple standards, by automating the process and incorporating user input for certification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007856677000001
    Figure 0007856677000001
  • Figure 0007856677000002
    Figure 0007856677000002
  • Figure 0007856677000003
    Figure 0007856677000003
Patent Text Reader

Abstract

Some embodiments relate to a method for use in connection with governance of a plurality of data assets managed by a data processing system, the method including: using at least one computer hardware processor to access a data governance policy including a first data standard (e.g., by obtaining information about the first standard stored in a database system); generating a first set of data assets, at least in part, by automatically selecting, from among the plurality of data assets managed by the data processing system and using the at least one data asset criterion, one or more data assets that comply with the at least one data asset criterion; associating the first set of data assets with the first data standard; and verifying whether at least one of the one or more data assets in the first set of data assets complies with the first data standard.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Related Applications This application claims the benefit of priority of U.S. Provisional Patent Application No. 63 / 210,951, entitled "DATA GOVERNANCE SYSTEMS AND METHODS," filed on June 15, 2021, and U.S. Provisional Patent Application No. 63 / 295,693, entitled "DATA GOVERNANCE SYSTEMS AND METHODS," filed on December 31, 2021, under 35 U.S.C. § 119(e), and each of these provisional applications is hereby incorporated by reference in its entirety.

[0002] Aspects of the present disclosure relate to data governance techniques for data managed by a data processing system. In particular, aspects of the present disclosure provide techniques for efficiently verifying that data assets managed by a data processing system comply with one or more data governance policies.

Background Art

[0003] Modern data processing systems manage vast amounts of data (e.g., millions, billions, or trillions of data records) and how this data can be accessed (e.g., created, updated, read, or deleted). The data managed by a data processing system can be of any appropriate type. For example, the data managed by a data processing system may include transactions, documents, tables, files, or any other appropriate type of data. Another example is that the data managed by a data processing system may include "metadata," which is data that contains information about other data (e.g., stored in the same data processing system and / or other data processing systems). For example, a data processing system may store metadata about credit card transaction data stored in a table in a credit card company's database. Non-limiting examples of such metadata include information indicating the size of the table in memory, when the table was created, when the table was last updated, the number of rows and / or columns in the table, where the table is stored, and who has permission to read, update, delete, or perform any other appropriate action on the data table. [Overview of the Initiative] [Means for solving the problem]

[0004] Several embodiments provide a method for determining whether data managed by a data processing system conforms to a data governance policy. The data processing system stores data in a plurality of data assets, each containing one or more attribute-value pairs. The data governance policy includes one or more data standards, each specifying one or more rules that a data asset must satisfy in order to conform to the data standard. The method includes using at least one computer hardware processor to receive user input indicating at least one criterion for including data assets in a first set of data assets; generating a first set of data assets by automatically identifying data assets from a plurality of data assets that conform to at least one criterion; selecting a first data standard from one or more data standards of the data governance policy; associating the first data standard with the first set of data assets; and determining whether data managed by the data processing system conforms to the data governance policy by at least partially verifying whether data assets in the first set of data assets satisfy one or more rules specified by the first data standard.

[0005] In some embodiments, at least one criterion indicates at least one value that at least one attribute in a data asset must take to conform to at least one criterion. In some embodiments, the method further includes selecting a second data standard from one or more data standards of the data, associating the second data standard with a first set of data assets, and determining whether the data managed by the data processing system conforms to a data governance policy by at least in part verifying whether the data assets in the first set of data assets satisfy one or more rules specified by the second data standard.

[0006] In some embodiments, the method further includes updating the first data asset set using at least one criterion before verifying whether the data assets in the first data asset set satisfy one or more rules specified by the first data standard. In some embodiments, updating the first data asset set using at least one criterion includes identifying at least one data asset in a plurality of data assets that are not in the first data asset set and conform to at least one criterion, and adding at least one data asset to the data asset set in response to identifying at least one data asset that conforms to at least one criterion. In some embodiments, updating the first dynamic data asset set using at least one data asset criterion includes identifying at least one data asset in the first data asset set that no longer conforms to at least one data asset criterion, and removing that at least one data asset from the first data asset set in response to identifying at least one data asset that no longer conforms to at least one data asset criterion.

[0007] In some embodiments, associating a first data standard with a first data asset set includes receiving user input through a graphical user interface (GUI) indicating a selection of a first data asset set from among multiple data asset sets, and associating the first data standard with the first data asset set in response to receiving this user input. In some embodiments, associating a first data standard with a first data asset set includes receiving user input through a graphical user interface (GUI) indicating a selection of a first data standard, and associating the first data standard with the first data asset set in response to receiving this user input. In some embodiments, the GUI displays GUI elements representing multiple data asset sets, and the user input indicates a selection of one of the GUI elements, thereby indicating a selection of the first data asset set. In some embodiments, after the selection of the first data asset set, the GUI displays information indicating one or more data assets that meet at least one criterion. In some embodiments, the GUI includes an interface that allows a user to search for data assets that meet at least one criterion.

[0008] In some embodiments, the method further includes generating a first GUI that displays a list of at least some data assets in a first data asset set, generating a first GUI that displays information about a first data standard, the information including an indication of the first data asset set, receiving user input through the first GUI indicating a selection of data assets in the list of at least some data assets, and generating a second GUI that displays information about the selected data assets in response to receiving this user input.

[0009] In some embodiments, verifying whether a data asset in a first data asset set satisfies one or more rules indicated by a first data standard includes identifying a user who, for at least one data asset in the first data asset set, determines whether the at least one data asset satisfies one or more rules indicated by a first data standard based on at least one attribute of the at least one data asset; transmitting information about the at least one data asset and the first data standard to a computing device associated with the user and through a communication network; and receiving information from the computing device associated with the user through the communication network indicating whether the at least one data asset satisfies one or more rules indicated by a first data standard.

[0010] In some embodiments, verifying whether a data asset in a first data asset set satisfies one or more rules indicated by a first data standard includes identifying a user who, for each of at least some specific data assets in the first data asset set, determines whether a particular data asset satisfies one or more rules indicated by a first data standard based on at least one attribute of the particular data asset; transmitting information about the particular data asset and the first data standard to a computing device associated with the user and through a communication network; and receiving information from the computing device associated with the user through the communication network indicating whether a particular data asset satisfies one or more rules indicated by a first data standard. In some embodiments, the information indicating whether a particular data asset satisfies one or more rules indicated by a first data standard includes a user's proof of whether a particular data asset satisfies one or more rules indicated by a first data standard.

[0011] In some embodiments, verifying whether a data asset in a first data asset set satisfies one or more rules specified by a first data standard includes automatically verifying whether a data asset satisfies one or more rules specified by a first data standard. In some embodiments, the method further includes receiving user input indicating at least one second criterion for including a data asset in a second data asset set, generating a second data asset set by automatically identifying from a plurality of data assets that conform to at least one second criterion for including a data asset in a second data asset set, selecting a second data standard from one or more data standards of a data governance policy, associating the second data standard with the second data asset set, and determining whether data managed by a data processing system conforms to a data governance policy by verifying, at least in part, whether a data asset in the second data asset set satisfies one or more rules specified by a second data standard.

[0012] In some embodiments, the method further includes selecting a second data standard from one or more data standards of the data governance policy, associating the second data standard with a first set of data assets, and determining whether the data managed by the data processing system conforms to the data governance policy by verifying, at least in part, whether the data assets in the first set of data assets satisfy one or more rules specified by the second data standard. In some embodiments, associating the first data standard with a first set of data assets includes storing instructions for the first set of data assets in the first data standard. In some embodiments, the data managed by the data processing system includes information associated with data in an enterprise system.

[0013] Some embodiments provide a non-temporary computer-readable storage medium for storing instructions. When executed by at least one computer hardware processor, these instructions cause at least one computer hardware processor to perform a method for determining whether data managed by a data processing system conforms to a data governance policy. The data processing system stores the data in a plurality of data assets, each containing one or more attribute-value pairs. The data governance policy includes one or more data standards, each specifying one or more rules that a data asset must satisfy in order to conform to the data standard. The method includes receiving user input indicating at least one criterion for including data assets in a first data asset set; generating a first data asset set by automatically identifying data assets from among multiple data assets that meet at least one criterion; selecting a first data standard from among one or more data standards of a data governance policy; associating the first data standard with the first data asset set; and determining whether data managed by a data processing system conforms to a data governance policy by verifying, at least in part, whether data assets in the first data asset set satisfy one or more rules specified by the first data standard.

[0014] Some embodiments provide a system for determining whether data managed by a data processing system conforms to a data governance policy. The data processing system stores data in multiple data assets, each containing one or more attribute-value pairs. The data governance policy includes one or more data standards, each specifying one or more rules that a data asset must satisfy in order to conform to the data standard. The system includes at least one computer hardware processor and at least one non-temporary computer-readable storage medium that stores instructions causing the at least one computer hardware processor to: receive user input indicating at least one criterion for including data assets in a first data asset set; generate a first data asset set by automatically identifying data assets from a plurality of data assets that meet at least one criterion; select a first data standard from one or more data standards of a data governance policy; associate the first data standard with the first data asset set; and determine whether data managed by the data processing system conforms to a data governance policy by verifying, at least in part, whether data assets in the first data asset set satisfy one or more rules specified by the first data standard.

[0015] Several embodiments provide a method for determining whether data managed by a data processing system conforms to a data governance policy. The data processing system stores data in a plurality of data assets, each containing one or more attribute-value pairs. The data governance policy includes one or more data standards, each specifying one or more rules that a data asset must satisfy in order to conform to the data standard. Each of the one or more data standards is associated with one or more sets of data assets. Each of the one or more data standards includes a first data standard associated with a first set of data assets of the one or more sets of data assets. The method includes using at least one computer hardware processor to access a first data asset from a first set of data assets associated with a first data standard; identifying a first user who certifies, based on the data in the first data asset, whether the first data asset satisfies one or more rules indicated by the first data standard; transmitting information about the first data asset and the first data standard to a first computing device associated with the first user and through a communication network; obtaining a first input from the first computing device and through a communication network that shows the first certification by the first user regarding whether the first data asset satisfies one or more rules indicated by the first data standard; and using the first input showing the first certification, determining whether the data managed by the data processing system conforms to a data governance policy.

[0016] In some embodiments, at least one criterion indicates at least one value that at least one attribute in a data asset must take to conform to at least one criterion. In some embodiments, the method further includes accessing a second data asset from a first set of data assets; identifying a second user who certifies, based on at least one attribute-value pair of the second data asset, whether the second data asset satisfies one or more rules indicated by a first data standard; transmitting information about the second data asset and the first data standard to a second computing device associated with the second user and through a communication network; obtaining a second input from the second computing device and through a communication network that indicates a second certification by the second user regarding whether the second data asset satisfies one or more rules indicated by the first data standard; and using the second input indicating the second certification, determining whether the data managed by the data processing system conforms to a data governance policy.

[0017] In some embodiments, identifying a first user who certifies whether a first data asset satisfies one or more rules indicated by a first data standard includes identifying one or more users, indicated by at least one attribute value pair of the first data asset, as responsible for managing the first data asset, and selecting a first user from one or more users. In some embodiments, obtaining first user input demonstrating the first certification includes obtaining first user input through a GUI. In some embodiments, the method further includes obtaining information from a first computing device and through a communication network that demonstrates evidence of a first certification by a first user regarding whether a first data asset satisfies one or more rules indicated by a first data standard.

[0018] In some embodiments, the method further includes tracking multiple proofs of whether a data asset in a first data asset set satisfies one or more rules indicated by a first data standard. In some embodiments, the method further includes generating GUI elements indicating the degree to which a proof is complete. In some embodiments, the method further includes generating a first proof object for the first data asset and storing information indicating the first proof in the first proof object. In some embodiments, the method further includes storing the association of the first data standard with the first data asset in the first proof object.

[0019] In some embodiments, the first proof indicates that the first data asset conforms to a first data standard, partially conforms to a first standard, is undefined, does not conform to a first standard, or the first data standard is not applicable to the first data asset. In some embodiments, the first data asset set is associated with a second data standard of one or more data standards, and the method further includes identifying a first user who proves, based on at least one attribute value pair of the first data asset, whether the first data asset satisfies one or more rules indicated by the second data standard; transmitting information about the first data asset and the second data standard to a first computing device associated with the first user and through a communication network; obtaining a second input from the first computing device and through a communication network that indicates the second proof by the first user regarding whether the first data asset satisfies one or more rules indicated by the second data standard; and using the second input indicating the second proof, determining whether the data managed by the data processing system conforms to a data governance policy.

[0020] Some embodiments provide a non-temporary computer-readable storage medium for storing instructions. When executed by at least one computer hardware processor, the instructions cause at least one computer hardware processor to perform a method for determining whether data managed by a data processing system conforms to a data governance policy. The data processing system stores the data in a plurality of data assets, each containing one or more attribute-value pairs. The data governance policy includes one or more data standards, each specifying one or more rules that a data asset must satisfy in order to conform to the data standard. Each of the one or more data standards is associated with one or more sets of data assets. Each of the one or more data standards includes a first data standard associated with a first set of data assets of the one or more sets of data assets. The method includes accessing a first data asset from a first set of data assets associated with a first data standard; identifying a first user who certifies, based on the data in the first data asset, whether the first data asset satisfies one or more rules indicated by the first data standard; transmitting information about the first data asset and the first data standard to a first computing device associated with the first user and through a communication network; obtaining a first input from the first computing device and through a communication network that represents the first certification by the first user regarding whether the first data asset satisfies one or more rules indicated by the first data standard; and using the first input representing the first certification, determining whether the data managed by the data processing system conforms to a data governance policy.

[0021] Some embodiments provide a system for determining whether data managed by a data processing system conforms to a data governance policy. The data processing system stores data in a plurality of data assets, each containing one or more attribute-value pairs. The data governance policy includes one or more data standards, each specifying one or more rules that a data asset must satisfy in order to conform to the data standard. Each of the one or more data standards is associated with one or more sets of data assets. Each of the one or more data standards includes a first data standard associated with a first set of data assets of the one or more sets of data assets. The system includes at least one computer hardware processor and at least one non-temporary computer-readable storage medium that stores instructions causing the at least one computer hardware processor to perform the following actions when executed by the at least one computer hardware processor: access a first data asset from a first set of data assets associated with a first data standard; identify a first user who, based on the data in the first data asset, proves whether the first data asset satisfies one or more rules indicated by the first data standard; transmit information about the first data asset and the first data standard to a first computing device associated with the first user and through a communication network; obtain a first input from the first computing device and through a communication network that shows the first proof by the first user regarding whether the first data asset satisfies one or more rules indicated by the first data standard; and use the first input showing the first proof to determine whether the data managed by the data processing system conforms to a data governance policy.

[0022] Several embodiments provide methods used in relation to the governance of multiple data assets managed by a data processing system. The methods include using at least one computer hardware processor to access a data governance policy including a first data standard; generating a first set of data assets by at least partially automatically selecting one or more data assets from among multiple data assets managed by the data processing system that conform to at least one data asset criterion using at least one data asset criterion; associating the first set of data assets with a first data standard; and verifying whether at least one of the one or more data assets in the first set of data assets conforms to the first data standard.

[0023] In some embodiments, at least one of one or more data assets in a first data asset set includes a first data asset, and verification includes identifying a first user who certifies whether the first data asset conforms to a first data standard based on at least one attribute of the first data asset. In some embodiments, the method further includes updating the first data asset set using at least one data asset criterion. In some embodiments, updating the first data asset set using at least one data asset criterion includes identifying one or more data assets in a plurality of data assets that are not in the first data asset set and conform to at least one data asset criterion, and adding one or more data assets to the first data asset set in response to identifying one or more assets that conform to at least one data asset criterion. In some embodiments, updating a first data asset set using at least one data asset criterion includes identifying one or more data assets in the first data asset set that no longer conform to at least one data asset criterion, and removing one or more data assets from the first data asset set in response to identifying one or more data assets that no longer conform to at least one data asset criterion.

[0024] In some embodiments, the method further includes, at least in part, generating a second set of data assets by automatically selecting one or more data assets from a plurality of data assets that conform to at least one other data asset criterion using at least one other data asset criterion; associating the second set of data assets with a first data standard; and verifying whether at least one of the one or more data assets in the second set of data assets conforms to the first data standard. In some embodiments, the data governance policy includes a second data standard, and the method further includes, at least in part, generating a second set of data assets by automatically selecting one or more data assets from a plurality of data assets that conform to at least one other data criterion using at least one other data asset criterion; associating the second set of data assets with a second data standard; and verifying whether at least one of the one or more data assets in the second set of data assets conforms to the second data standard.

[0025] In some embodiments, the data governance policy includes a second data standard, and the method further includes associating a first data asset set with the second data standard and verifying whether at least one data asset in the first data asset set conforms to the second data standard. In some embodiments, associating a first data asset set with the first data standard includes storing the indication of the first data asset set in the first data standard. In some embodiments, generating a first data asset set using a first at least one data asset criterion includes identifying one or more data assets from among a plurality of data assets managed by a data processing system that conform to at least one data asset criterion, and including the identified one or more data assets in the first data asset set.

[0026] In some embodiments, associating a first data asset set with a first data standard includes receiving user input through a graphical user interface (GUI) indicating that the first data asset set is to be associated with the first data standard. In some embodiments, the GUI displays GUI elements representing multiple data asset sets, and the user input indicates the selection of the first data asset set by selecting one of the GUI elements. In some embodiments, after the selection of the first data asset set, the GUI displays information indicating one or more data assets that conform to at least one data asset criterion. In some embodiments, the GUI includes an interface that allows the user to search for data assets that conform to at least one data asset criterion.

[0027] In some embodiments, the first set of data assets includes a plurality of data assets, and the method further includes generating a first GUI that displays at least some list of the plurality of data assets in the first set of data assets, generating a first GUI that displays information about the first data standard, where the information includes an indication of the first set of data assets, receiving, through the first GUI, user input indicating a selection of a data asset in the list of at least some data assets, and in response to receiving this user input, generating a second GUI that displays information about the selected data asset. In some embodiments, the data governance policy includes a plurality of data standards, and the method further includes generating a first GUI that displays information about the data governance policy, where the information about the data governance policy includes a display of the first data standard, generating a first GUI that displays at least some list of the plurality of data standards, where at least some of the plurality of data standards include the first data standard, receiving, through the first GUI, user input indicating a selection of the first data standard from the list, and in response to receiving this user input, generating a second GUI that displays information about the first data standard.

[0028] Some embodiments provide a system for use in governing a plurality of data assets managed by a data processing system. The system includes at least one computer hardware processor and, when executed by the at least one computer hardware processor, causes the at least one hardware processor to access a data governance policy that includes a first data standard, and at least partially automatically select, from among the plurality of data assets managed by the data processing system, using at least one data asset criterion, one or more data assets that conform to the at least one data asset criterion to generate a first set of data assets, associate the first set of data assets with the first data standard, and verify whether at least one of the one or more data assets in the first set of data assets conforms to the first data standard, and at least one non-transitory computer-readable storage medium storing instructions for causing the operations to be performed.

[0029] Some embodiments provide a non-transitory computer-readable storage medium storing instructions that, when executed by at least one computer hardware processor, cause the at least one computer hardware processor to access a data governance policy that includes a first data standard, and at least partially automatically select, from among the plurality of data assets managed by the data processing system, using at least one data asset criterion, one or more data assets that conform to the at least one data asset criterion to generate a first set of data assets, associate the first set of data assets with the first data standard, and verify whether at least one of the one or more data assets in the first set of data assets conforms to the first data standard.

[0030] Several embodiments provide a method which includes using at least one computer hardware processor to verify whether a data asset managed by a data processing system conforms to a data governance policy which includes a first data standard associated with a first data asset, the verification including identifying a first user who certifies whether the first data asset conforms to the first data standard based on at least one attribute of the first data asset; transmitting information about the first data asset and the first data standard to a first computing device associated with the first user and using a communication network; obtaining a first input from the first computing device using the communication network which indicates a first certification by the first user regarding whether the first data asset conforms to the first data standard; and verifying whether the first data asset conforms to the first data standard based on the input indicating the first certification.

[0031] In some embodiments, identifying a first user who certifies whether a first data asset conforms to a first data standard includes identifying that the first user is responsible for managing the first data asset. In some embodiments, identifying that the first user is responsible for managing the first data asset includes accessing information associated with the data asset indicating that the first user is responsible for the first data asset.

[0032] In some embodiments, a first data standard is associated with a second data asset, and the method further includes identifying a second user who certifies whether the second data asset conforms to the second data standard based on at least one attribute of the second data asset; transmitting information about the second data asset and the first data standard to a second computing device associated with the second user and via a communication network; obtaining a second input from the second computing device via the communication network that displays a second certification by the second user regarding whether the second data asset conforms to the first data standard; and verifying whether the second data asset conforms to the second data standard based on the second certification.

[0033] In some embodiments, the data governance policy includes a second data standard associated with a second data asset, and the method further includes identifying a second user who certifies whether a first data asset conforms to the second data standard based on at least one attribute of the second data asset; transmitting information about the second data asset and the second data standard to a second computing device associated with the second user and via a communication network; obtaining a second input from the second computing device via the communication network that indicates a second certification by the second user regarding whether the second data asset conforms to the second data standard; and verifying whether the second data asset conforms to the second data standard based on the second certification.

[0034] In some embodiments, the data governance policy includes a second data standard associated with a second data asset, and the method further includes identifying a first user who certifies whether a first data asset conforms to a second data standard based on at least one attribute of the second data asset; transmitting information about the second data asset and the second data standard to a first computing device and through a communication network; obtaining a second input from the first computing device through the communication network that indicates a second certification by the first user regarding whether the second data asset conforms to a second data standard; and verifying whether the second data asset conforms to a second data standard based on the second certification.

[0035] In some embodiments, the method further includes generating a first proof object and storing a first input indicating the first proof in the first proof object. In some embodiments, the method further includes storing an association of a first data standard with a first data asset in the first proof object. In some embodiments, obtaining a first user input indicating the first proof includes obtaining the first user input through a GUI. In some embodiments, the GUI displays information indicating an association of a first standard with a first data asset. In some embodiments, the first proof indicates that the first data asset conforms to a first data standard, partially conforms to a first standard, is undefined, is not applicable, or does not conform to a first standard. In some embodiments, the method further includes obtaining information indicating evidence of the first proof from a first computing device through a communication network.

[0036] Several embodiments provide a system. The system includes at least one computer hardware processor and at least one non-temporary computer-readable storage medium that stores instructions, when executed by the at least one computer hardware processor, to cause the at least one hardware processor to perform, using the at least one computer hardware processor, verification whether a data asset managed by a data processing system conforms to a data governance policy, including a first data standard associated with a first data asset, wherein the verification includes identifying a first user who certifies whether the first data asset conforms to a first data standard based on at least one attribute of the first data asset; transmitting information about the first data asset and the first data standard to a first computing device associated with the first user and through a communication network; obtaining a first input from the first computing device through the communication network indicating a first certification by the first user regarding whether the first data asset conforms to a first data standard; and verifying whether the first data asset conforms to a first data standard based on the input indicating the first certification.

[0037] Some embodiments provide a non-temporary computer-readable storage medium for storing instructions. When executed by at least one computer hardware processor, the instructions include, using at least one computer hardware processor, verifying whether a data asset managed by a data processing system conforms to a data governance policy which includes a first data standard associated with a first data asset, and the verification includes, identifying a first user who certifies whether the first data asset conforms to the first data standard based on at least one attribute of the first data asset; transmitting information about the first data asset and the first data standard to a first computing device associated with the first user and through a communication network; obtaining a first input from the first computing device through the communication network which indicates a first certification by the first user regarding whether the first data asset conforms to the first data standard; and verifying whether the first data asset conforms to the first data standard based on the input indicating the first certification.

[0038] Several embodiments provide a method for processing data assets managed by a data processing system. The method involves using at least one computer hardware processor to access a plurality of data standards, each specifying one or more rules that a data asset must satisfy in order to conform to a data standard; and generating a plurality of data asset sets, each containing a set of data, wherein generating includes, for each data asset set, automatically selecting one or more data assets that conform to at least one data asset criterion from among a plurality of data assets managed by the data processing system, using at least one data asset criterion; associating each data asset set with one or more of the plurality of data standards; and associating at least one of the one or more data assets in each data asset set with one or more associated data rules. The process includes identifying a user who will certify whether a data asset conforms to a data standard, based on at least one attribute of the data asset for each of the one or more data assets in each set of data assets; identifying a computing device associated with the identified user; transmitting information about the data asset and data standard to the identified computing device associated with the identified user and via a communication network; obtaining input from the computing device via the communication network that indicates the user's certification of whether the data asset conforms to a data standard; and verifying that the data asset conforms to a data standard by verifying the input indicating the certification.

[0039] In some embodiments, at least some of the users identified with respect to different sets of data assets are different. In some embodiments, the data processing system further includes a queue for each user, and the method further includes storing a proof queue to be performed by each user, where the proof includes information about one or more data assets and one or more associated data standards.

[0040] The above is a non-definitive overview.

[0041] Various aspects and embodiments will be described with reference to the following figures. Please note that the figures are not necessarily drawn to a fixed scale. Features appearing in multiple figures are indicated by the same or similar reference numbers in all figures in which they appear. [Brief explanation of the drawing]

[0042] [Figure 1] Figure 10 shows a system that implements conventional data governance techniques for data assets. [Figure 2A] Figures of data processing systems 100 according to several embodiments of the technology described herein are shown. [Figure 2B] This specification illustrates an exemplary system for facilitating data governance in the data processing system 100 of Figure 2A, based on several embodiments of the technology described herein. [Figure 2C] Figure 2B shows the system after updating the data assets, according to several embodiments of the technology described herein. [Figure 2D] An example of how the system in Figure 2B obtains proof is shown, according to several embodiments of the technology described herein. [Figure 2E] This specification shows exemplary graphical user interfaces (GUIs) for compliance projects based on several embodiments of the technology described herein. [Figure 2F]The diagram illustrates the interactions between exemplary system components to facilitate governance in a data processing system 100, according to several embodiments of the technology described herein. [Figure 3] A diagram illustrating the generation of an exemplary compliance project according to several embodiments of the technology described herein is shown. [Figure 4A] Examples of data governance policies 232 and data standards 234 comprising them are shown below, according to several embodiments of the technology described herein. [Figure 4B] Examples of compliance projects 238 and compliance reviews 122 comprising them are shown, according to several embodiments of the technology described herein. [Figure 5A] This figure illustrates an example environment 200 in which the data processing system 100 may be used, according to several embodiments of the technology described herein. [Figure 5B] A block diagram illustrating an exemplary data processing system 100 according to several embodiments of the technology described herein is shown. [Figure 6] The flowcharts below illustrate other exemplary processes 600 used with respect to the governance of data assets managed by a data processing system, according to some embodiments of the technology described herein. [Figure 7] A flowchart of an exemplary process 700 for verifying whether a data asset managed by a system conforms to a data governance policy, including the data standards associated with the data asset, according to several embodiments of the technology described herein, is shown. [Figure 8] This figure shows an exemplary graphical user interface (GUI) 800 that displays information about a data governance policy, according to some embodiments of the technology described herein. [Figure 9] This figure shows an exemplary graphical user interface (GUI) 900 for displaying information about a data standard, according to some embodiments of the technology described herein. [Figure 10]This figure shows an exemplary graphical user interface (GUI) 1000, according to some embodiments of the technology described herein, which allows a user to select a set of data assets from a list of existing data asset sets for association with a data standard. [Figure 11] This figure shows an exemplary graphical user interface (GUI) 1100 that allows a user to create a new set of data assets for association with a data standard, according to some embodiments of the technology described herein. [Figure 12] This figure shows an exemplary graphical user interface (GUI) 1200 that allows a user to create a new set of data assets to associate with a data standard, according to some embodiments of the technology described herein. [Figure 13] This figure shows an exemplary graphical user interface (GUI) 1300 for displaying information about a data standard, according to some embodiments of the technology described herein. [Figure 14] This figure shows an exemplary graphical user interface (GUI) 1400 for displaying information about a compliance project, according to several embodiments of the technology described herein. [Figure 15] This figure shows an exemplary graphical user interface (GUI) 1500 for displaying information about compliance audits, according to several embodiments of the technology described herein. [Figure 16] This figure shows an exemplary graphical user interface (GUI) 1600 for displaying information about a proof, according to some embodiments of the technology described herein. [Figure 17] This figure shows an exemplary graphical user interface (GUI) 1700 that displays information about multiple compliance projects, according to several embodiments of the technology described herein. [Figure 18]This figure shows an exemplary graphical user interface (GUI) 1800 that displays information about the certification status of a compliance project, according to some embodiments of the technology described herein. [Figure 19] This figure shows an exemplary graphical user interface (GUI) 1900 that allows a user to edit one or more certificates, according to some embodiments of the technology described herein. [Figure 20] This figure shows an exemplary graphical user interface (GUI) 2000 that allows a user to sign one or more certificates, according to some embodiments of the technology described herein. [Figure 21] This figure shows an exemplary graphical user interface (GUI) 2100 that displays information about proof relating to data assets, according to some embodiments of the technology described herein. [Figure 22] This is a block diagram of an exemplary computing system 2200 that may be used when implementing some embodiments of the technology described herein. [Modes for carrying out the invention]

[0043] The inventors have developed a novel technology that enables efficient verification of whether data assets managed by a data processing system conform to a data governance policy.

[0044] A “data asset” can be any suitable set of data managed by a data processing system. For example, a data asset may include one or more data records, one or more datasets, one or more documents, one or more transactions, one or more files, one or more tables, and / or any set of the above. As another example, in some embodiments, a data asset may include one or more data entities. In some such embodiments, a data processing system may manage at least some data using data entities, which are used to organize the data using an object-oriented paradigm. Similar to how object-oriented programming includes classes and their instances, a data processing system may consist of definitions of data entities and manage data using instances of data entities and definitions of data entities.

[0045] In some embodiments, a data asset may include data and information about the data. In some embodiments, information about the data may be stored as attribute-value pairs. For example, a data asset may include one or more attributes having values, and information about the data within the data asset may include the values ​​of the attributes. A data asset may be stored by a data processing system in any suitable format and / or using any suitable data structure, because the embodiments of the technology described herein are not limited in this respect.

[0046] In some embodiments, a data processing system may manage data assets for an organization, such as a multinational corporation (e.g., a financial institution, utility company, automobile company, electronics company, etc.) or other company or organization. Large organizations may have enormous amounts of data assets, and therefore, in some embodiments, a data processing system may be used to manage large amounts of data assets (e.g., millions, billions, or trillions) for the organization.

[0047] For example, in some embodiments, a data processing system may be configured to manage millions or billions of data assets. In some such embodiments, the data processing system may be used for metadata management in an enterprise setting, thereby the data assets storing information about individual datasets (e.g., tables, transactions, documents, data records, etc.) stored across a globally distributed information technology (IT) infrastructure, including many databases, data warehouses, data lakes, etc. In this regard, the data assets may store information about corresponding datasets, such as when the dataset was created, where it is stored, its size, the identification of users authorized to edit the dataset, information identifying which application programs use the dataset, and identification of the data's confidentiality level. Large organizations (e.g., financial institutions such as banks or credit card companies, or public utilities such as telephone or electric companies) typically manage millions or billions of such datasets, so there may be millions or billions of data assets storing information about such datasets managed by the data processing system. In this application, the data processing system stores information about other data (sometimes called "metadata"), so this application can be called "metadata management." However, it should be understood that the techniques described herein are not limited to data processing systems used for metadata management, but can be applied to any data processing system that uses data assets to manage data, whether the data being managed is metadata or any other type of data.

[0048] Data governance refers to the processes, policies, procedures, and standards used to control and / or regulate various aspects of an organization's data, including but not limited to data quality and integrity, data security, data privacy, data versioning, data lineage, and traceability of data changes, data availability and accessibility, and / or any other appropriate aspects of an organization's data and / or its management.

[0049] Organizations can implement data governance by establishing data governance policies that regulate data managed by data processing systems. In some embodiments, the technology described herein provides a system that enables members of an organization to designate one or more data governance policies, each including one or more data standards. A data governance policy may include any appropriate number of data standards (e.g., at least one data standard, at least two data standards, at least five data standards, at least ten data standards, 1 to 50 data standards, 10 to 100 data standards, or any other appropriate range within these ranges). In some embodiments, a data standard may specify one or more rules that a data asset must satisfy in order to conform to the data standard. By conforming to a data standard, a data asset may at least partially conform to the data governance policy to which the data standard belongs (each data standard may be part of one or more data governance policies). Data governance policies and the data standards comprising them can be stored by a data processing system in any suitable way (for example, in any suitable format or using any suitable data structure), but the aspects of the technology described herein are not limited in this respect.

[0050] As an illustrative example, a data governance policy may specify that social security numbers in data managed by a data processing system should adhere to a consistent format. The data governance policy may include a data standard requiring that social security numbers be stored in the format "NNN-NN-NNNN," where N is an Arabic numeral from 0 to 9. As another example, a data governance policy may specify that applications should only use data from trusted sources. The data governance policy may include a data standard specifying a list of trusted sources from which applications can use data. As yet another example, a data governance policy may specify that sensitive data must comply with one or more security standards, and the data standards comprising it may require that data assets be stored on systems protected from external data access. Other examples of data governance policies and the data standards comprising them are provided herein.

[0051] In practice, as mentioned above, organizations can have numerous data governance policies and numerous data standards for each policy. Organizations can have millions or even billions of data assets to which data governance policies and data standards can apply. For example, an organization such as a bank may have millions or billions of data assets (e.g., customer records, transaction records, and / or account records) stored in multiple different locations around the world. Another example is an organization such as a telephone company, which may have millions or billions of data assets (e.g., call records, data usage records, customer information, and account information) stored in multiple different locations around the world. Verifying whether the large volume (e.g., millions or billions) of data assets managed by data processing systems conform to various data governance policies and the data standards that comprise them is a major technical challenge. This challenge is further complicated by the fact that data assets are dynamic in that at least some of the data within them can be updated. For example, if a data asset contains attribute-value pairs, one or more attribute values ​​may change. As a result, a data asset may conform to one or more data standards at one point in time, but not to one of these data standards at a later point in time. For example, the conformance of a data asset to a specific data standard may depend on the values ​​of the data asset's attributes, and if those attribute values ​​change, a data asset that previously conformed may no longer conform (and vice versa).

[0052] Figure 1 shows Figure 10 of a system that implements conventional data governance techniques for data asset 16. As shown in Figure 1, the system includes multiple data governance rules, including data governance rules 12A, 12B, 12C, and 12D. The compliance manager 18 is responsible for manually associating each of the data governance rules 12A, 12B, 12C, and 12D with one or more of the millions of data assets 16 that can be managed by the system. The system shown in Figure 10 may require the compliance manager 18 to associate each data asset with an applicable data governance rule. In the example in Figure 1, the compliance manager 18 manually associates governance rule 12A with data asset 16A, governance rule 12B with data asset 16C, governance rule 12C with data asset 16D, and governance rule 12D with data asset 16F.

[0053] In a data processing system, there may be many (e.g., thousands, millions, or more) data assets to which data governance rules apply. Furthermore, data assets may be updated, and as a result, new data assets may need to be governed by different data governance rules, and / or data assets may no longer be governed by a certain data governance rule. For example, if governance rule 12A no longer applies to data asset 16A, its association would have to be manually removed. As another example, if data asset 16D is updated and governance rule 12B comes to apply to data asset 16D, data asset 16D would have to be manually associated with governance rule 12B. Therefore, the system cannot dynamically associate data assets with applicable data governance rules in response to changes in data assets. Furthermore, the compliance manager 18 may not be able to associate a governance rule with all data assets to which that governance rule applies. In the example in Figure 1, governance rule 12A may apply to data asset 16B. However, the compliance manager 18 has not associated governance rule 12A with data asset 16B. Governance rule 12C may apply to data asset 16E. However, compliance manager 18 has not associated governance rule 12C with data asset 16E.

[0054] In the system shown in Figure 1, the compliance manager 18, having associated governance rules 12A, 12B, 12C, and 12D with their respective data assets, is then responsible for determining whether the data assets conform to the governance rules to which they are associated. In a system with thousands or even millions of associations between governance rules and data assets, it may be impossible for the compliance manager 18 to determine whether the system's data assets conform to the applicable governance rules. As shown in Figure 1, the compliance manager 18 cannot provide any indication of whether the data assets conform to the applicable governance rules. Furthermore, the compliance manager 18 may not possess the knowledge to determine whether a particular data asset conforms to the applicable governance rules. Therefore, the system cannot effectively determine the conformity of data assets to governance rules.

[0055] To address the aforementioned challenges, the inventors have developed a system that can efficiently verify whether data assets managed by a data processing system conform to a data governance policy and the data standards that comprise it. The system achieves this, in part, by (1) a process in which the data processing system automatically associates data assets with applicable data governance policies and / or data standards (the association is, for example, based on the data within the data asset), and (2) a process in which the data processing system automatically identifies users ("certifiers") who will review the data assets for conformity to one or more data standards, and (b) guides the identified users through a workflow that enables them to certify whether the data assets conform to the data governance policy and the standards that comprise it.

[0056] In some embodiments, in order to associate data assets with applicable data governance policies and data standards, the system may be configured to generate a data asset set and associate this data asset set with one or more data standards. The data asset set can be generated in any suitable way. For example, in some embodiments, the system may be configured to generate a data asset set using one or more criteria that can define the data asset set, thereby including assets that conform to one or more criteria and excluding data assets that do not conform to one or more criteria. For example, in some embodiments, a data set may be automatically generated by using one or more criteria to select data assets that conform to one or more criteria from among a number of data assets managed by the data processing system.

[0057] In some embodiments, the criteria for including a data asset in a data asset set may include conditions relating to one or more attributes of the data asset. In some embodiments, the criteria may, for each attribute, specify one or more values ​​that the attribute within the data asset must take to conform to the criteria. For example, a system may group data assets of the same type (e.g., credit score data assets, customer ID data assets, and / or direct debit account data assets) indicated by their attribute values ​​into the same data asset set. As another example, data assets that store information associated with a particular region or location (e.g., the United States, Europe, Japan, etc.) indicated by their attribute values ​​may be grouped into the same data asset set. Yet another example is that a system may group data assets associated with the same system or the same application, indicated by their attribute values, into the same data asset set. Yet another example is that a system may group data associated with a common security level indicated by its attribute (e.g., all assets including personally identifiable information (PII)) into the same data asset set. More generally, data assets may have attribute values, and data assets may be grouped into data asset sets based on specified criteria with respect to attribute values ​​(for example, data assets having the same or similar values ​​for one or more attributes are grouped into the same data asset set, data assets having one or more attributes that have a specific value or fall within a specified range of values ​​are grouped into the same data asset set, etc.). In some embodiments, the system may be configured to group data assets into one or more data asset sets that do not group them, because the techniques described herein are not limited in this respect.

[0058] In some embodiments, after one or more data asset sets have been generated, the system may dynamically update the data asset sets based on updates to data assets managed by a data processing system. For example, the data processing system may remove a data asset from a data asset set if, after that data asset has been updated, the updated data asset no longer meets the criteria for inclusion in that data asset set. As another example, the data processing system may add a data asset to a data asset set if, after that data asset has been updated, the updated data asset meets one or more criteria for inclusion in the data asset set. Thus, associating data governance policies and data standards with data assets can be dynamic and can be constantly updated to reflect the most recent state of the data assets. In some embodiments, the system may be configured to periodically update data asset sets. For example, the system may update data asset sets according to a predetermined schedule. In some embodiments, the system may be configured to update data asset sets in response to certain events. For example, the system may update data asset sets in response to user and / or system access to the data asset set (for example, in relation to verifying that assets in the data asset set conform to one or more data standards). In some embodiments, the system may be configured to update the data asset set when a compliance project is created to identify compliance for the data asset set. The system may be further configured to freeze the data asset set after it has been created (for example, until the compliance project is completed).

[0059] In some embodiments, to efficiently verify whether a data asset conforms to a data standard associated with the set of data assets containing that data asset, the system automatically identifies a user who will certify whether the data asset conforms to an applicable data standard. The system may identify the user using information from the data asset. In some embodiments, a data asset may organize the data stored within it into one or more attributes, which can take various numerical values, such as numbers, strings, or references to other data assets. One or more attributes of a data asset may directly or indirectly indicate the user responsible for the data asset. The system may automatically identify the user who will certify whether the data asset conforms to a data standard using the attribute values ​​of the data asset (for example, data indicated by the "Business Data Steward" attribute of the data asset). The system may provide the identified user with information about the data asset and the applicable data standard (for example, through a graphical user interface (GUI)). An identified user may (1) view information about data standards (e.g., rules or requirements) and information about data assets (e.g., attribute values ​​of data assets), and (2) prove whether a data asset conforms to a data standard (e.g., whether it satisfies the rules and / or requirements of the data standard). For example, the system may provide one or more workflows through which a user can view information about data assets and data standards and submit a proof. The system may provide and / or request further evidence (e.g., files, descriptions, links, or other information) to support the proof submitted by the user. The evidence may be used to later verify whether the proof is accurate.

[0060] In some embodiments, the data processing system described herein enables the definition and monitoring of large-scale compliance projects. The data processing system may use compliance projects to manage verification of whether multiple data assets conform to one or more data standards. Compliance projects provide a mechanism for implementing workflows across multiple computing devices. The system may use this workflow to obtain user information regarding whether data assets conform to one or more data standards. In some embodiments, the information may include user certification of whether data assets conform to a data standard (e.g., by satisfying rules specified by the data standard). A compliance project may include multiple certifications regarding whether data assets conform to their respective data standards and data governance policies. In some embodiments, the system may be configured to distribute the workflow to multiple different users associated with different computing devices. The system can therefore distribute verification across multiple computing devices. The system may generate statistics on the progress of compliance projects (e.g., the percentage of certifications completed or incomplete). The compliance project therefore provides efficient tools and interfaces through which the verification of compliance with data standards and data governance policies can be managed by the data processing system.

[0061] This specification describes improved techniques for data governance in data processing systems. In particular, the system maintains dynamic associations between data standards and the data assets to which those standards apply, across a collection of data assets. The system updates data assets based on changes to them (e.g., changes in data asset attribute values). Thus, the system can maintain updated associations between data standards and applicable data assets. Additionally, the system uses information stored in data assets to automatically identify users who can verify whether a data asset conforms to an applicable data standard. The system can use these identified users to manage compliance projects, thereby enabling more efficient verification of data asset conformance to data standards than traditional data governance systems.

[0062] Some embodiments relate to methods used in connection with the governance of a plurality of data assets managed by a data processing system, the methods including: using at least one computer hardware processor to access a data governance policy including a first data standard (for example, by retrieving information about the first standard stored in a database system); generating a first set of data assets by at least in part automatically selecting one or more data assets that conform to at least one data asset criterion from a plurality of data assets managed by the data processing system using at least one data asset criterion; associating the first set of data assets with a first data standard; and verifying whether at least one of the one or more data assets in the first set of data assets conforms to the first data standard.

[0063] In some embodiments, at least one of the one or more data assets in a first data asset set includes a first data asset, and verification includes identifying a first user (a person responsible for the first data asset) who certifies, based on at least one attribute of the first data asset, whether the first data asset conforms to a first data standard.

[0064] In some embodiments, the method includes updating a first set of data assets (for example, to reflect the latest state of data assets managed by a data processing system) using at least one data asset criterion. In some embodiments, updating the first set of data assets using at least one data asset criterion includes identifying one or more data assets among a plurality of data assets that are not in the first set of data assets and conform to at least one data asset criterion, and adding that one or more data assets to the first set of data assets in response to identifying that one or more data assets conform to at least one data asset criterion. In some embodiments, updating the first set of data assets using at least one data asset criterion includes identifying one or more data assets in the first set of data assets that no longer conform to at least one data asset criterion, and removing that one or more data assets from the first set of data assets in response to identifying that one or more data assets that do not conform to at least one data asset criterion.

[0065] In some embodiments, the method includes, at least in part, generating a second set of data assets by automatically selecting one or more data assets from a plurality of data assets that conform to at least one other data asset criterion using at least one other data asset criterion; associating the second set of data assets with a first data criterion; and verifying whether at least one of the one or more data assets in the second set of data assets conforms to the first data standard.

[0066] In some embodiments, the data governance policy includes a second data standard, and the method further includes, at least in part, generating a second set of data assets by automatically selecting one or more data assets from a plurality of data assets that conform to at least one other data asset criterion using at least one other data asset criterion; associating the second set of data assets with a second data standard; and verifying whether at least one of the one or more data assets in the second set of data assets conforms to the second data standard.

[0067] In some embodiments, the data governance policy includes a second data standard, and the method further includes associating a first set of data assets with the second data standard and verifying whether at least one data asset in the first set of data assets conforms to the second data standard. In some embodiments, associating a first set of data assets with the first data standard includes storing a reference to the first set of data assets in the first data standard. For example, the first data standard may store a reference to the first set of data assets.

[0068] In some embodiments, generating a first data asset set using a first data asset criterion includes identifying one or more data assets that conform to the first data asset criterion from among a plurality of data assets managed by a data processing system, and including the identified one or more data assets in the first data asset set.

[0069] In some embodiments, associating a first data asset set with a first data standard includes receiving user input through a graphical user interface (GUI) indicating that the first data asset set is to be associated with the first data standard. In some embodiments, the GUI displays GUI elements representing multiple data asset sets, and the user input indicates the selection of a first data asset set by selecting one of the GUI elements. In some embodiments, after selecting a first data asset set, the GUI displays information indicating one or more data assets that conform to at least one data asset criterion. In some embodiments, the GUI includes an interface that allows the user to search for data assets that conform to at least one data asset criterion.

[0070] In some embodiments, the first data asset set comprises a plurality of data assets, and the method further comprises generating a first GUI that displays a list of at least a few of the plurality of data assets of the first data asset set, and generating a first GUI that displays information about a first data standard, the information including an indication of the first data asset set, receiving user input through the first GUI indicating a selection of data assets in the list of at least a few data assets, and generating a second GUI that displays information about the selected data assets in response to receiving this user input.

[0071] In some embodiments, the data governance policy includes a plurality of data standards, and the method further includes generating a first GUI that displays information about the data governance policy, the information about the data governance policy includes a display of the first data standards, and generating a first GUI that displays a list of at least a few of the plurality of data standards, the at least a few of which include the first data standards, and receiving user input through the first GUI indicating a selection of the first data standards from the list, and generating a second GUI that displays information about the first data standards in response to receiving this user input.

[0072] Several embodiments use at least one computer hardware processor to verify whether a data asset managed by a data processing system conforms to a data governance policy that includes a first data standard associated with a first data asset. Verification includes identifying a first user (e.g., a person responsible for the first data asset) who certifies whether the first data asset conforms to the first data standard based on at least one attribute of the first data asset; transmitting information about the first data asset and the first data standard to a first computing device associated with the first user and through a communication network; obtaining a first input from the first computing device through the communication network that indicates the first user's first certification regarding whether the first data asset conforms to the first data standard; and verifying whether the first data asset conforms to the first data standard based on the input indicating the first certification.

[0073] In some embodiments, identifying a first user who certifies whether a first data asset conforms to a first data standard includes identifying that the first user is responsible for managing the first data asset (e.g., based on the attribute values ​​of the first data asset). In some embodiments, identifying that the first user is responsible for managing the first data asset includes accessing information associated with the data asset that indicates the first user is responsible for the first data asset.

[0074] In some embodiments, a first data standard is associated with a second data asset, and the method further includes identifying a second user who certifies whether the second data asset conforms to the second data standard based on at least one attribute of the second data asset; transmitting information about the second data asset and the first data standard to a second computing device associated with the second user and using a communication network; obtaining a second input from the second computing device through the communication network that indicates a second certification by the second user regarding whether the second data asset conforms to the first data standard; and verifying whether the second data asset conforms to the second data standard based on the second certification.

[0075] In some embodiments, the data governance policy includes a second data standard associated with a second data asset, and the method includes identifying a second user who certifies whether a first data asset conforms to the second data standard based on at least one attribute of the second data asset; transmitting information about the second data asset and the second data standard to a second computing device associated with the second user and via a communication network; obtaining a second input from the second computing device via the communication network that indicates a second certification by the second user regarding whether the second data asset conforms to the second data standard; and verifying whether the second data asset conforms to the second data standard based on the second certification.

[0076] In some embodiments, the data governance policy includes a second data standard associated with a second data asset, and the method includes identifying a first user who certifies whether a first data asset conforms to a second data standard based on at least one attribute of the second data asset; transmitting information about the second data asset and the second data standard to a first computing device and using a communication network; obtaining a second input from the first computing device through the communication network that indicates a second certification by the first user regarding whether the second data asset conforms to a second data standard; and verifying whether the second data asset conforms to a second data standard based on the second certification.

[0077] In some embodiments, the method includes generating a first proof object and storing a first input representing the first proof in the first proof object. In some embodiments, the method includes storing an association between a first data standard and a first data asset in the first proof object.

[0078] In some embodiments, obtaining a first user input indicating a first proof includes obtaining the first user input through a GUI. In some embodiments, the GUI displays information indicating an association between a first standard and a first data asset. In some embodiments, the first proof indicates that the first data asset conforms to a first data standard, partially conforms to the first standard, or does not conform to the first standard. In some embodiments, the method includes obtaining information indicating evidence of the first proof from a first computing device through a communication network.

[0079] The techniques described herein can be carried out in any of many ways, and are not limited to any particular mode of implementation. Examples of implementation details are provided herein for illustrative purposes only. Furthermore, the techniques disclosed herein can be used individually or in any suitable combination, and the embodiments of the techniques described herein are not limited to the use of any particular technique or combination of techniques.

[0080] Figure 2A shows a diagram of a data processing system 100 according to several embodiments of the technology described herein. As shown in Figure 2A, the data processing system 100 includes a data governance policy 102, data assets 106, and compliance projects 120.

[0081] The data processing system 100 may be configured to govern data assets 106 managed by the data processing system 100 using data governance policies 102. More specifically, each of the data governance policies 102 includes one or more sets of constituent data standards. Conformance of a data asset to a data governance policy may be determined based on the data asset conforming to the data standards associated with it. The data processing system 100 may include any number of data governance policies. In some embodiments, the data governance policy 102 may provide standards for the data assets of the data processing system 100, and the data standards of the data governance policy 102 may be specific rules that, if met, indicate conformity to the guidelines of the data governance policy 102. An example of a data governance policy and the data standards comprising it is described herein with reference to Figure 4A.

[0082] As shown in Figure 2A, the data processing system 100 manages data assets 106. In some embodiments, the data processing system 100 may be configured to manage thousands, millions, or billions of data assets. In some embodiments, each data asset may store a set of attribute values. For example, each data asset may store a set of attribute values. The exemplary embodiment in Figure 2A shows data assets 106 in data storage within the data processing system 100, but in some embodiments, at least some of the data assets 106 may be stored in other systems. The data processing system 100 may be configured to access data assets stored in other systems.

[0083] In some embodiments, the data processing system 100 may be configured to use a compliance project 120 to identify compliance of data assets 106 with a data governance policy 102. The data processing system 100 may be configured to create a compliance project to identify whether one or more of the data assets 106 conform to one or more data standards. In some embodiments, the data processing system 100 may be configured to create a compliance project to identify compliance with a data governance policy. The compliance project may manage the review of data assets that a user (e.g., a compliance manager 118) must perform to identify their compliance with the data governance policy. As described in more detail herein, in some embodiments, the compliance project may include proof that a data asset conforms to an applicable data standard incorporated into one or more compliance reviews. The data processing system 100 may be configured to assign the proof to a user. Thus, the compliance project 120 distributes the task of identifying compliance of data assets 106 with the data governance policy 102 to various different users.

[0084] As shown in Figure 2A, various types of users interact with the data processing system 100. These users include a compliance manager 118, a policy manager 114, and certifiers 116A and 116B.

[0085] In some embodiments, the policy manager 114 is responsible for creating the data governance policy for the data processing system 100. The policy manager 114 may create the data governance policy and the data standards that comprise it. For example, the policy manager 114 may create the data governance policy by (1) defining the data governance policy and (2) identifying one or more data standards to be included in the data governance policy (e.g., used to determine whether a data asset conforms to the data governance policy). The policy manager 114 may define the data governance policy by naming and describing it. The policy manager 114 may further name and define the data standards of the data governance policy. The policy manager 114 may further identify which data assets each data standard applies to and associate each data standard with its applicable data assets. As described herein with respect to Figure 2B, the policy manager 114 may associate data standards with data assets and with a set of data assets (also referred to here as a “data asset set”).

[0086] In some embodiments, the compliance manager 118 is responsible for verifying whether the data asset 106 conforms to the data governance policy 102. The compliance manager 118 may use a compliance project 120 to determine whether the data asset 106 conforms to the data governance policy 102. More specifically, the compliance manager 118 may use a compliance project to manage certification of whether the data asset conforms to the data standards of the data governance policy 102. As illustrated with reference to Figures 2D-2E herein, certification may be assigned to various different users (also referred to here as “certifiers”) (e.g., certifiers 116A, 116B).

[0087] In a compliance project, in some embodiments of the system, data assets may be paired with applicable data standards and provided to certifiers 116A and 116B to certify whether the data assets conform to the applicable data standards. Certifiers 116A and 116B are responsible for reviewing the data assets and the applicable data standards and determining whether the data assets conform to the applicable data standards. Certifiers 116A and 116B may provide inputs demonstrating their certification. In some embodiments, the system may further require certifier 116A to provide, in addition to the certification, evidence such as comments and / or supporting evidence.

[0088] Figure 2B shows an exemplary system for facilitating data governance in the data processing system 100 of Figure 2A, according to several embodiments of the technology described herein. As described with respect to Figure 2A, each of the data governance policies 102 includes its respective set of data standards. In the example of Figure 2B, data governance policy 102A includes data standards 104A and 104B, and data governance policy 102B includes data standards 104C and 104D. As indicated by the three dots in each of the data governance policies 102A and 102B, data governance policies 102A and 102B may include one or more other data standards not shown in Figure 2B. Each data governance policy may also have any suitable number of data standards (e.g., 1, 2, 3, at least 5, at least 10, at least 20, 1 to 10, 5 to 20, 1 to 30, or any other suitable range within these ranges). While the example in Figure 2B shows each data governance policy with a different set of data standards, in some embodiments, data governance policies may share data standards. For example, data standard 104A may be included in data governance policy 102B in addition to data governance policy 102A.

[0089] As an explanatory example, data governance policy 102A may specify that data input to an application must come from a trusted source. Data standard 104A of data governance policy 102A may indicate that data used by an application must come from a list of trusted sources, and data standard 104B may indicate that social security numbers used by an application must come from a specific database. Data governance policy 102B may specify that user identification numbers must conform to a standard format. Data standard 104C may indicate that social security numbers must have the format "NNN-NN-NNNN", where N is an Arabic numeral from 0 to 9. Data standard 104D may indicate that telephone numbers must have the format "(NNN)NNN-NNNN", where N is an Arabic numeral from 0 to 9. Data standards 102A, 102B, 104A, and 104B therefore provide specific compliance requirements that demonstrate the conformity of data assets to data governance policies 102 and 104.

[0090] As shown in Figure 2B, the system organizes data asset 106 into data asset sets 110A, 110B, and 110C. The system may be configured to generate each data asset set using one or more sets of data asset criteria. In the example in Figure 2B, data asset set 110A is generated using data asset criterion 112A, data asset set 110B is generated using data asset criterion 112B, and data asset set 110C is generated using data asset criterion 112C. The system may be configured to generate data asset sets using a set of criteria by (1) identifying millions of data assets 106 that conform to the criteria, and (2) including the identified data assets as members of the data asset set. For example, data asset criterion 112A may include the criterion that the data asset was obtained from the United States for use in the application. Data asset criterion 112B may include the criterion that the data asset contains a customer's social security number, and data asset criterion 112C may include the criterion that the data asset contains contact information of people in Brazil. The system may use the set of data asset criteria 112A, 112B, and 112C to generate (1) data asset set 110A which includes data assets containing information obtained from the United States, (2) data asset set 110B which includes data assets containing customer social security numbers, and (3) data asset set 110C which includes data assets containing contact information of people in Brazil. In the example in Figure 2B, data asset set 110A includes data assets 106A, 106B, and 106C, data asset set 110B includes data assets 106C and 106D, and data asset set 110C includes data asset 106E.

[0091] As indicated by the pattern portion of each data asset in data asset sets 110A, 110B, and 110C, the data assets in data asset sets 110A, 110B, and 110C satisfy the corresponding data asset criteria 112A, 112B, and 112C. For example, data assets 106A, 106B, and 106C satisfy data asset criterion 112A, which is indicated by a vertical line pattern. Data assets 106C and 106D satisfy data asset criterion 112B, which is indicated by a horizontal line pattern. Data asset 106C contains a vertical and horizontal line pattern because it satisfies data asset criteria 112A and 112B. Data asset 106E contains a diagonal line pattern because it satisfies data asset criterion 112C.

[0092] As shown in the example in Figure 2B, in some embodiments, a data asset may be a member of multiple data asset sets. In Figure 2B, data asset 106C is a member of both data asset set 110A and data asset set 110B. Continuing from the previous example, data asset 106C may include a Social Security number obtained in the United States and may be a member of both data asset set 110A and data asset set 110B. In some embodiments, the system may associate a data standard with multiple data asset sets. For example, the system may further associate data standard 104B with data asset set 110C.

[0093] The policy manager 114 can associate a data standard with a set of data assets to which that data standard applies. As shown in the example in Figure 2B, the policy manager 114 can associate a data standard with a set of data assets by associating the data standard with the data asset criteria used to generate the set of data assets. For example, the policy manager 114 can associate a data standard with a set of data assets by selecting the set from a list. In another example, the policy manager 114 can (1) create a set of data asset criteria that defines a new set of data assets, and (2) associate a data standard with that new set of data assets. Thus, the policy manager 114 does not need to manually associate each data standard with individual data assets 106. In the example in Figure 2B, the policy manager 114 associates data standard 104A with data asset set 110A via data asset criteria 112A, data standard 104B with data asset set 110B via data asset criteria 112B, data standard 104C with data asset set 110B via data asset criteria 112B, and data standard 104D with data asset set 110C via data asset criteria 112C.

[0094] As shown in Figure 2B, the system may be further configured to associate data standards directly with data assets, in addition to or instead of associating data standards with data asset sets. In the example in Figure 2B, policy manager 114 associates data standard 104C with data asset 106F. The system can use the association between data standard 104C and data asset 106F to determine whether data asset 106F conforms to data standard 104C. Data asset 106F does not belong to any of the data asset sets 110A, 110B, and 110C shown in Figure 2B, which is indicated by the fact that it does not contain a pattern.

[0095] As shown in Figure 2B, the system uses data asset criteria as an abstraction layer between data standards and the data assets to which those standards apply. By creating this abstraction layer, the system provides a dynamic association between data standards and data assets. If a data asset no longer satisfies the set of data asset criteria corresponding to a set of data assets, the system may remove the data asset from that set of data assets. This dissolves the association that the data set has with the data standards to which it is associated. Similarly, if a data asset is updated to conform to the set of data asset criteria corresponding to a set of data assets, the system may include this data asset in the set of data assets and thus automatically associate it with all applicable data standards.

[0096] In some embodiments, the data asset sets 110A, 110B, and 110C may be dynamic. The system may be configured to update the components of each data asset set in response to updates to data assets. For example, the system may add one or more data assets to a data asset set and / or remove one or more data assets from it based on whether the data assets meet one or more criteria that define the data asset set. Figure 2C shows the system of Figure 2B after updating several data assets, according to some embodiments of the technology described herein. In the example of Figure 2C, data asset 106E is updated so that it no longer meets data asset criterion 112C and meets data asset criterion 112B. As a result, the components of data asset set 110B are updated to include data asset 106E, and the components of data asset set 110C are updated so that they do not include data asset 106E. In some embodiments, the system may be configured to identify the components of a data asset set periodically (e.g., hourly, daily, weekly, monthly, or at other appropriate intervals). In some embodiments, the system may be configured to identify components of a data asset set in response to certain actions. For example, the system may identify components of a data asset set when a compliance project is created. In other examples, the system may identify components of a data asset set when a user requests to view information about the data asset set and / or associated data standards.

[0097] Figure 2D shows an example of how the system in Figure 2B obtains a proof of conformity between a data asset and a data standard, according to some embodiments of the technology described herein. As shown in Figure 2D, the system pairs a data standard with a corresponding data asset in its proof, which is then provided to the prover 116A through the prover queue 132. The prover queue 132 may be a set of proofs to be performed by the prover 116A. For example, the system may store a queue of proofs to be performed by a user. As shown in Figure 2D, the system may be configured to generate a proof by pairing a data standard with one or more data assets in the set of data assets to which the data standard is associated (e.g., via a corresponding data asset criterion). In the example in Figure 2D, the system pairs data standard 104A with data asset 106A, data standard 104A with data asset 106C, and data standard 104B with data asset 106C. The system may be configured to identify this pairing based on the association between data standard 104A and data asset set 110A, and between data standard 104B and data asset set 110B, as shown in Figure 2B.

[0098] The system may be configured to add a proof to the proof queue 132 by (1) determining whether the proofer 116A is responsible for making the proof, and (2) adding the proof to the proof queue 132 when it is determined that the proofer 116A is responsible for making the proof. In some embodiments, the system may be configured to determine that the proofer 116A is responsible for a proof based on information from a data asset related to that proof. For example, a data asset may store an attribute indicating the user responsible for managing the data asset (e.g., a data steward). In this example, the system may determine that the proofer 116A is responsible based on the identification that the user indicated by the attribute is the proofer 116A. In some embodiments, the system may be configured to determine that the proofer 116A is responsible for a proof based on input from another user. For example, a compliance manager 118 may provide input indicating that the proofer 116A is responsible for the proof. The system may be configured to transmit information to a computing device associated with the proofer 116A. For example, the system may transmit this information to the computing device over a communication network (e.g., the Internet). The information includes details about the data standards and data assets paired within the certification assigned to certifier 116A.

[0099] Figure 2D further illustrates an exemplary graphical user interface (GUI) through which a certifier 116A performs a certification. In the example in Figure 2D, the GUI demonstrates a certification 140A of whether data asset 106A conforms to data standard 104A. The GUI provides the certifier 116A with access to data standard 104A and data asset 106A, thereby enabling the certifier 116A to determine conformity. In some embodiments, the GUI may provide access to information about data standard 104A. For example, the GUI may display the name and / or description of data standard 104A. In other examples, the GUI may provide the certifier 116A with a link that, when selected, directs the user to a GUI that displays information about data standard 104A. In some embodiments, the GUI may provide access information about data asset 106A. For example, the GUI may display attribute values ​​of data asset 106A, the name of data asset 106A, a description of data asset 106A, and / or other information about data asset 106A. In another example, the GUI may provide the prover 116A with a link that, when selected, directs the prover 116A to a GUI that displays information about data asset 106A.

[0100] As shown in Figure 2D, the GUI includes a section where the user can enter proof information 142A for proof 140A. Proof information 142A includes an input 144A indicating whether data asset 106A conforms to data standard 104A. As shown in Figure 2D, the certifier 116A can select “conforms” or “does not conform” to demonstrate proof. In some embodiments, input 144A may allow the user to provide an input indicating whether data asset 106A conforms to data standard 104A, does not conform to data standard 104A, partially conforms to data standard 104A, or that data asset 106A is still under review. Proof information 142A further includes a comment 144B where the certifier 116A can enter other comments for proof. In the example in Figure 2D, the GUI provides a text field where the user can enter comments. In some embodiments, the user may also provide comments 144B through conversation, text input, or any other suitable input mechanism. The certification information 142A further includes evidence 144C. In some embodiments, the certifier 116A may be required to provide evidence 144C to support a certification of whether data asset 106A meets data standard 104A. In the example in Figure 2D, the certifier 116A may upload a file to support input 144A of whether data asset 106A meets data standard 104A. In some embodiments, evidence 144C may include documents, files, screenshots, images, text, audio data and / or other data as evidence of certification 140A. The GUI in Figure 2D further provides a “Submit Certification” button 144D which the certifier 116A may choose to submit certification 140A (for example, after entering certification information 142A). The system may update certification 140A in the system in response to the selection of button 144D. For example, the system may upload certification information 142A into a data object that stores information about certification 140A.

[0101] In some embodiments, the system may be configured to use proof 140A to verify whether data asset 106A conforms to data standard 104A. The system may be configured to identify data asset 106A conforms to data standard 104A when proof information 142A indicates that data asset 106A conforms to data standard 104A. The system may be configured to identify data asset 106A does not conform to data standard 104A when proof information 142A indicates that data asset 106A does not conform to data standard 104A. The system may be configured to identify data asset 106A partially conforms to data standard 104A when proof information 142A indicates that data asset 106A partially conforms to data standard 104A. In some embodiments, the system may be configured to obtain proof information 142A from the computing device of the certifier 116A. In some embodiments, the system may be configured to generate a proof object and store the proof information 142A in the proof object. The proof object may provide a record of verification for reference (for example, for review by compliance manager 118).

[0102] Figure 2E shows an exemplary graphical user interface for a compliance project 120A according to several embodiments of the technology described herein. In some embodiments, the system may provide the GUI shown in Figure 2E to a compliance manager 118 for the compliance manager 118 to determine the conformity of data assets with the data governance policy. For example, the system may create a compliance project 120A to determine whether a data asset conforms to the data governance policy 102A. In the example in Figure 2E, compliance project 120A includes compliance reviews 122A and 122B. Compliance review 122A is for determining the conformity of a data asset with the data standard 104A, and compliance review 122B is for determining the conformity of a data asset with the data standard 104B. Exemplary techniques for generating a compliance project are described herein with respect to Figures 3 and 7.

[0103] As shown in Figure 2E, compliance review 122A includes certification 140. Certification 140 may include certification for each data asset in the data asset set associated with data standard 104A. In the example in Figure 2E, certification 140 includes certifications 140A, 140B, and 140C. Certification 140A includes the pairing of data standard 104A and data asset 106A and certification information 142A. Certification 140B includes the pairing of data standard 104A and data asset 106B and certification information 142B. Certification 140C includes the pairing of data standard 104A and data asset 106C and certification information 142C. As shown in Figure 2E, each of certifications 140A, 140B, and 140C is assigned to the respective certifiers 116A, 116B, and 116A. Certification information may be provided by the certifier as described herein with respect to Figure 2D.

[0104] As shown in Figure 2E, compliance review 122B includes certification 150. Certification 150 may include certification for each data asset in the data asset set associated with data standard 104B. In the example in Figure 2E, certification 150 includes certifications 150A and 150B. Certification 150A includes the pairing of data standard 104B and data asset 106C and certification information 152A. Certification 150B includes the pairing of data standard 104B and data asset 106D. As shown in Figure 2E, each of certifications 150A and 150B is assigned to the respective certifiers 116A and 116C. Certification information may be provided by the certifier as described herein with respect to Figure 2D. Certification 150B does not include certification information because certifier 116C may not have submitted certification information. For example, certification 150B may be in the certification queue for certifier 116C but still not performed by certifier 116C. In other examples, certifier 116C may not have selected the "Submit Certificate" button in the GUI to send the certificate information.

[0105] The GUI in Figure 2E includes status displays for compliance project 120A and compliance audits 122A and 122B. Project status 121A indicates the completion percentage of the compliance audit for compliance project 120A. In the example in Figure 2E, 75% of the compliance audit for compliance project 120A is complete. Audit status 124A for compliance audit 122A indicates that it is 100% complete. This may indicate that all of the certifications 140 for compliance audit 122A have been completed. Audit status 124B for compliance audit 122B indicates that it is 50% complete. This may indicate that 50% of the certifications 150 for compliance audit 122B have been completed. In some embodiments, the system may use audit statuses 124A and 124B to identify project status 121A. In the example in Figure 2E, the system may average the 100% completion display for review status 124A and the 50% display for review status 124B to obtain a 75% project status 121A display.

[0106] Figure 2F shows a diagram illustrating the interactions between components of a data processing system 100 according to several embodiments of the technology described herein. As shown in Figure 2F, the data standards of data governance policies 102A and 102B are associated with each set of data assets 106 through each set of data asset criteria 112. For example, the policy manager 114 may associate data standards 104A, 104B, 104C, and 104D with data asset criteria, as described herein with respect to Figure 2B. The system may use the data asset sets to generate compliance projects 120. The compliance manager 118 may use the compliance projects 120 to identify that data assets conform to data governance policies 102A and 102B, as described herein with respect to Figure 2E. As shown in Figure 2E, each compliance project includes one or more compliance reviews, each of which includes one or more certifications. Certifiers may submit certification information, which the system stores in the certifications. The certifier 116A transmits the certificate information 142A for the certificate 140A, as described herein with respect to Figure 2C.

[0107] Figure 3 shows a diagram illustrating the generation of exemplary compliance projects 120A according to several embodiments of the technology described herein. The process shown in Figure 3 may be performed by the data governance system of the data processing system 100 described herein with respect to Figures 2A-2F. The system may generate compliance projects 120A to verify whether one or more data assets of a set of data assets conform to one or more data standards.

[0108] As shown in Figure 3, the system first generates compliance project 120A. After generating compliance project 120, the system uses the data governance system shown in Figure 2B to identify associations between data asset sets 110A and data standards 104A. The system may be configured to use the associations between data asset sets 110A and data standards 104A to identify assets to be reviewed in compliance project 120A. In some embodiments, the system may be configured to identify data assets using data asset standards 112A corresponding to data asset sets 110A. The system may be configured to identify data assets 106A, 106B, and 106C as satisfying data asset standards 112A (e.g., data assets including data obtained from the United States). Identified data assets may be identified as becoming members of data asset sets 110A at some point. For example, the system may use the attributes of a data asset at the time compliance project 120A is generated to determine whether or not a data asset is a member of data asset sets 110A. In another example, the system may identify data assets using previously identified components of data asset set 110A.

[0109] As shown in Figure 3, each of the data assets 106A, 106B, and 106C is associated with one or more users. Data asset 106A is associated with user 202A, data asset 106B is associated with user 202B, and data asset 106C is associated with user 202C. In some embodiments, the system may identify the user responsible for a data asset using data within the data asset. For example, the data asset may include attributes that identify a user. In some embodiments, the user may be responsible for managing the data asset. For example, the user may be designated as the "business data steward" of the data asset. Identifiers (e.g., name, identification number, or other identifiers) may be stored as attribute values ​​within the data asset.

[0110] After identifying the association between data asset set 110A and data standard 104A, the system identifies users who certify whether data assets 106A, 106B, and 106C conform to data standard 104A. In some embodiments, the system may be configured to automatically identify users (e.g., business data stewards) indicated by the respective attributes of data assets 106A, 106B, and 106C as users who certify whether data assets 106A, 106B, and 106C conform to data standard 104A. As shown in Figure 3, the system identifies (1) certifier 116A who certifies whether data asset 106A conforms to data standard 104A, (2) certifier 116B who certifies whether data asset 106B conforms to data standard 104A, and (3) certifier 116A who certifies whether data asset 106C conforms to data standard 104A.

[0111] In some embodiments, the system may be configured to provide each user with information for performing a proof (for example, as described herein with respect to Figure 2D). In the example of Figure 3, the system may provide proofer 116A with information indicating data standard 104A and information about data assets 106A and 106C (e.g., attribute values). The system may provide proofer 116B with information indicating data standard 104A and information about data asset 106B (e.g., attribute values). For example, the system may provide proofs to proofers in each proofer's queue. Proofers may perform proofs using a GUI, as described herein with respect to Figure 2D.

[0112] Figure 4A shows examples of a data governance policy 232 and the data standards 234 comprising it, according to several embodiments of the technology described herein. The data governance policy 232 may include other data standards not shown in Figure 4B, as indicated by the dots within the data governance policy 232. The data governance policy 232 includes the name 232A: "Sensitive data shall be handled and stored in accordance with all governing standards." The data governance policy further includes the description 232B: "Sensitive data is data that conforms to one or six different criteria." In some embodiments, the data governance policy 232 may further include a list of data standards. In some embodiments, the data governance policy 232 may include references to data standards.

[0113] Data Standard 234 includes Name 234A: "Confidential information must be stored only in systems that are protected from external data access." Data Standard 234 includes Description 234B: "Datasets marked 'Confidential' must be stored only in systems that have been proven to be protected from external data access by IT security." Data Standard 234 includes Display of Proof of Certification to Verify Conformity with Data Standard 234C: "IT security certificates must be linked for the system storing the Confidential Datasets and for the direct source or substantially non-transformable target Datasets (indicated by lineage)." Data Standard 234 includes List 234D of data asset sets to which Data Standard 234 is associated (e.g., "Confidential Datasets"). As shown in the example in Figure 4A, Data Standard 234 is associated with the Confidential Dataset 237 of the data asset set through association with the data asset criterion 236 corresponding to Confidential Dataset 237. Data Standard 234 may be associated with data asset criterion 236 and / or Confidential Dataset 237 as described herein in relation to Figure 2B.

[0114] Figure 4B shows examples of compliance project 238 and the compliance review 240 comprising it according to several embodiments of the technology described herein. Compliance project 238 may also include other compliance reviews not shown in Figure 4B, as indicated by dots. Compliance project 238 includes name 238A: “Quarterly Data Handling Review”. Compliance project 238 includes description 238B: “Review the handling of sensitive datasets and certify that they conform to all applicable data standards”. In some embodiments, compliance project 238 may further include a list of compliance reviews that are part of compliance project 238.

[0115] Compliance Review 240 includes the name 240A: “Confidential Datasets”. Compliance Review 240 includes the description 240B: “Certifies the conformity of each dataset marked as confidential to each applicable data standard”. Compliance Review 240 further includes a list 240C of data asset sets to which Compliance Review 240 may be associated. In the example in Figure 2E, list 240C includes the data asset set, “Confidential Datasets”. The data asset set may be associated with the data standard associated with Compliance Review 240. Compliance Review 240 further includes a list 240D of certifications that are part of Compliance Review 240 (e.g., “Confidential Dataset 1” paired with “Data Standard A” and “Confidential Dataset 2” paired with “Data Standard A”). Certification 240D includes the respective certification information and certifier.

[0116] Figure 5A illustrates example environments 200 in which the data processing system 100 may be used, according to several embodiments of the techniques described herein. The example in Figure 5A is an implementation in which the data processing system 100 is used for metadata management. The techniques described herein should be understood to be applicable not only to specific types of data but can be used in any data processing system that uses data assets, regardless of whether the data being managed is metadata or any other type of data (e.g., transactions, files, data, records, tables, etc.).

[0117] Figure 5A shows an enterprise system including systems 209A, 209B, and 209C. Systems 209A, 209B, and 209C may be distributed across multiple geographical locations (e.g., different cities, countries, continents, etc.). Each of systems 209A, 209B, and 209C may store large amounts of data (e.g., in one or more database systems, data warehouses, data lakes, etc.). For example, systems 209A, 209B, and 209C may be part of the enterprise system of a global bank, with system 209A in the United States, system 209B in Brazil, and system 209C in Europe.

[0118] As shown in the exemplary embodiment of Figure 2A, each of systems 209A, 209B, and 209C includes a respective set of computing devices. For example, each system may include one or more servers, user devices, and / or databases. During the operation of the enterprise system, each of systems 209A, 209B, and 209C may generate and / or store large amounts of data (e.g., several terabytes of data). For example, the enterprise system may be a credit card company system, and each of systems 209A, 209B, and 209C generates and / or stores transaction data, credit scores, and / or any other suitable data. In another example, the enterprise system may be a bank system, and each of systems 209A, 209B, and 209C generates and / or stores bank records, loans, account holders, and / or any other suitable data. In another example, a corporate system could be a telephone company system, where each of systems 209A, 209B, and 209C generates and / or stores telephone calls, text messages, data usage, and / or any other suitable data.

[0119] In some embodiments, systems 209A, 209B, and 209C may be configured to store data (e.g., from enterprise systems). Each of systems 209A, 209B, and 209C may include a database, data warehouse, data lake, and / or any other database system. Systems 209A, 209B, and 209C may be any suitable type of database system, either of the same type or different types. For example, each of these systems may include one or more relational database systems (e.g., Oracle, SQL Server, etc.). As another example, in some embodiments, each of these systems may include one or more other types of database systems (e.g., non-relational (e.g., NoSQL) database systems, multi-filesystems, or any other suitable type of database system).

[0120] In the embodiment shown in Figure 2A, the data processing system 100 stores information 207 that describes the data stored in systems 209A, 209B, and 209C. In this sense, information 207 can be considered metadata. Metadata may include any of many types of information about the data stored in enterprise systems 209A, 209B, and 209C. For example, metadata may include information about the systems that process the data, the software applications running on the enterprise systems used for data processing, and / or the rules of the applications in data storage. In another example, metadata may include information about the data throughout the enterprise software system, such as how the data was generated, the size of the data, a description of the data, which users are authorized to read, update, create, delete or perform any other actions on the data, and / or any other relevant information about the data.

[0121] In some embodiments, the data processing system 100 may be configured to manage metadata using data assets. For example, the data processing system 100 may store data assets for each of several datasets (e.g., tables) stored by an enterprise system. Each such data asset may store information about the dataset (e.g., when the dataset was created or updated, where the dataset is stored, the size of the dataset, identification information of users authorized to read, edit, delete or perform any other appropriate actions on the dataset, information identifying which software applications use the dataset, information identifying the level of sensitivity of the data in the dataset, and / or any other appropriate metadata). As another example, the data processing system 100 may store data assets for each column of a table in an enterprise system. Each such data asset may store information about the column (e.g., the meaning of the column's values, who has the authority to read, write, update and / or delete the values ​​in the column, the range of allowed values ​​for entries in the column, and / or any other appropriate metadata). As yet another example, the data processing system 100 may store data assets for each of several software applications configured to run by some system or device part of the enterprise system. Such data assets may store information about a software application (for example, which datasets the software application processes, where the application places its output, a description of the application's functionality, the application's version, its dependencies on data and / or other applications, where the application's executable file can be found, and / or any other suitable metadata). As yet another example, the data processing system 100 may store data assets for each of several system parts that are part of an enterprise system.

[0122] As can already be seen from the above, in such metadata management scenarios, the data processing system 100 may manage millions or even billions of such data assets, and therefore it is important to efficiently verify whether the data assets conform to applicable data standards.

[0123] In some embodiments, the data processing system 100 may be configured to retrieve information about data from various systems 209A, 209B, and 209C. For example, the data processing system 100 may query the databases of systems 209A, 209B, and 209C for metadata of various systems 209A, 209B, and 209C. In some embodiments, the data processing system 100 may be configured to generate metadata using information retrieved from systems 209A, 209B, and 209C (for example, by querying the database system for metadata). In some embodiments, the data processing system 100 may be configured to store metadata about data stored within systems 209A, 209B, and 209C. For example, systems 209A, 209B, and 209C may be a data lake, a data warehouse, a database system, or other types of systems, respectively. The metadata may be stored using data assets, as described herein.

[0124] In some embodiments, the data processing system 100 may be configured to store data governance policies and / or data standards as data assets of the data processing system 100. For example, the data processing system 100 may store data governance policy 102A as a data asset. The data asset may contain information (for example, stored in one or more attribute fields). The data asset may store information indicating data standards 104A and 104B of data governance policy 102A. For example, the data asset may store references to data standards 104A and 104B, which may each be stored as separate data assets managed by the data processing system 100. A data asset that stores data governance policies ("data governance policy set") may store information including a textual description of the data governance policy. For example, the data governance policy set may contain a statement of the policy. A data asset that stores data standards ("data standards asset") may contain a textual description of the degree of conformity with the data governance policy. For example, a data standard asset for data standard 104A may include a textual description of the degree of conformity of the data asset (e.g., the data asset must be from a list of trusted sources).

[0125] The data processing system 100 may be configured to associate a data standard with one or more data asset sets, as described herein with respect to Figure 2B. In some embodiments, the data processing system 100 may be configured to associate a data standard with a data asset set by storing the association between the data standard and the data asset set. For example, the system may store the association between data standard 104A and data asset set 110A. The system may store a representation of data asset set 110A as part of the data standard asset of data standard 104A. For example, the data standard asset may include a field that lists the associated data asset sets. The data standard asset of data standard 104A may list data asset set 110A in its field. In some embodiments, the data standard asset may include references to one or more data asset sets to which the data standard is associated.

[0126] In some embodiments, the data processing system 100 may be configured to dynamically update the components of a data asset set. The data processing system 100 may be configured to identify the components of a data asset set at a given point in time by (1) selecting one or more assets using one or more criteria that define the data asset set, and (2) including the selected data assets in the data asset set. In some embodiments, the data processing system 100 may be configured to update the components of a data asset set when proof of the data assets in the data asset set is scheduled to be performed (e.g., to provide an updated list of data assets that are scheduled to be proven). In some embodiments, the data processing system 100 may be configured to update the components of a data asset set periodically (e.g., once a day, once a week, once a month, or at other appropriate time intervals). In some embodiments, the data processing system 100 may be configured to update the components of a data asset set in response to a command (e.g., a command input by a user).

[0127] In some embodiments, a user identified for pairing a data standard with a data asset may be responsible for verifying whether the data asset conforms to that data standard. The data processing system 100 may be configured to transmit information about the data asset and the data standard to a computing device associated with that user. The data processing system 100 may be configured to receive input from the computing device indicating the user's verification of whether the data asset conforms to that data standard. In some embodiments, the data processing system 100 may be configured to generate a workflow through which the user can view information about the data asset and the data standard and provide input. In some embodiments, the data processing system 100 may be configured to provide a graphical user interface (GUI) that guides the user through the verification process. The system may be configured to verify whether the data asset conforms to the data standard based on the input indicating the verification.

[0128] In some embodiments, the system may be configured to generate proof objects. A proof object may store an association between an identified user and a pairing of a data standard and a data asset. For example, the data processing system 100 may store the association between a user and a pairing of a data standard and a data asset within a proof object. In some embodiments, a proof object may be stored as a data asset of the data processing system 100 ("proof data asset"). In some embodiments, the data processing system 100 may be configured to use proof objects to track the status of compliance audits and / or compliance projects. The system may store the status and / or proof results in the proof object. The system may be configured to identify the status of compliance audits and / or compliance projects based on the status of proof within them (e.g., indicated by the proof object). In some embodiments, the system may be configured to identify proof statistics for compliance audits and / or compliance projects. The statistics may provide the data processing system 100 with a view of the verification of compliance with data policies and / or data standards. For example, users can view information such as the number of compliance projects, the number of compliance audits, the completion rate of compliance audits or projects, the incomplete percentage of compliance audits or projects, and other statistics.

[0129] Figure 5B shows a flock diagram illustrating an exemplary data processing system 100 according to several embodiments of the technology described herein. The data processing system 100 includes a graphical user interface (GUI) module 210, a data governance system 220, and a data persistence tier 230.

[0130] In some embodiments, the GUI module 210 may enable the user to interact with the data processing system 100 by generating various GUIs through which the user can interact with the data processing system 100. The GUI module 210 includes a defining user interface (UI) module 212, a compliance UI module 214, and a certification UI module 216.

[0131] In some embodiments, the definition UI module 212 may be configured to generate a GUI that can define data governance policies, data standards, and data asset sets in the data processing system 100. This GUI may allow a policy manager (e.g., policy manager 114) to define data governance policies. For example, this GUI may allow the policy manager to create a new data governance policy and define this data governance policy (e.g., guidelines or rules specified by the data governance policy). This GUI may allow the policy manager to generate one or more data standards as part of the data governance policy. This GUI may allow the policy manager to create new data standards. This GUI may allow the policy manager to input rules and / or requirements for the data standards (e.g., social security numbers conform to the standard format NNN-NN-NNNN, where N is an Arabic numeral from 0 to 9). This GUI may allow a compliance manager (e.g., compliance manager 118) to provide input indicating the association between data standards and one or more data asset sets. For example, this GUI may allow a compliance manager to select one or more data asset sets to which the data standard applies from a list of previously generated data asset sets.

[0132] In some embodiments, the definition UI module 212 may be configured to generate a GUI that allows the policy manager to create a new data asset set. This GUI may allow the policy manager to provide inputs through the GUI that indicate one or more criteria that the data processing system 100 can use to generate the data asset set. For example, this GUI may allow the user to specify criteria that the data processing system 100 can use to generate the data asset set, including location, data asset type, application, area, size, name, and / or other criteria.

[0133] In some embodiments, the definition UI module 212 may be configured to generate a GUI that displays information about a data governance policy. This GUI displays the name of the data governance policy, the rules specified by the policy, and / or one or more data standards of the data governance policy. In some embodiments, this GUI may guide the user to the data standards of the data governance policy (for example, by providing a link to a GUI that displays information about the data standards). In some embodiments, the definition UI module 212 may be configured to generate a GUI that displays information about a data standard. This GUI may display the name of the data standard, the degree of compliance of the data standard, the set of data assets associated with the data standard, and / or the data governance policy to which the data standard belongs. This GUI may allow the user to browse a list of data assets in a set of data assets. For example, this GUI may allow the user to select a set of data assets, and in response, may display a list of data assets in the selected set of data assets.

[0134] In some embodiments, the compliance UI module 214 may be configured to generate a GUI that allows a compliance manager (e.g., compliance manager 118) to generate compliance projects. This GUI may allow the user to provide inputs through the GUI indicating data governance policies and / or data standards to be validated within the compliance project. Furthermore, this GUI may allow the compliance manager to generate one or more compliance reviews for the compliance project. For example, this GUI may allow the compliance manager to select data standards for which a compliance project should be generated. In other examples, this GUI may allow the compliance manager to select data assets for which a compliance project should be generated. The compliance UI module 214 may also be configured to generate a GUI that allows the compliance manager to view information about the compliance reviews of the compliance project. This GUI may display the name of the compliance project, data standards (e.g., name, degree of compliance, etc.), data assets (e.g., name), and / or other information.

[0135] In some embodiments, the compliance UI module 214 may be configured to generate a GUI (e.g., shown in Figure 2E) that allows a compliance manager to view information about the compliance projects that have been generated. For example, the GUI may display the name of the compliance project, a list of compliance audits for the compliance project, a list of certifications for the compliance project, the status of the compliance project (e.g., identified based on the status of the compliance audits that comprise it), statistics about the compliance project (e.g., the number of data assets, data standards, percentage of completed certifications, percentage of incomplete certifications, etc.), and / or other information about the compliance project. The GUI may provide the compliance manager with a graphical view of the status of the compliance project. For example, the GUI may display the status of one or more compliance audits that are part of the compliance project and / or graphical elements that indicate the status of the compliance project as a whole. In some embodiments, the compliance UI module 214 may be configured to generate a GUI that allows a compliance manager to view information about compliance audits. For example, the GUI may display a list of certifications for a compliance audit, data standards associated with the audit, and / or data assets associated with the compliance audit.

[0136] In some embodiments, the proof UI module 216 may be configured to generate a GUI (for example, as described herein with respect to Figure 2D) through which a proofer can perform a proof. This GUI allows the proofer to view information about data standards and data assets. For example, the GUI may lead the proofer to a GUI that displays information about data standards (e.g., degree of compliance) and a GUI that displays information about data assets (e.g., attribute values). This GUI may be configured to allow the user to input information as part of the proof. For example, the GUI may allow the proofer to provide text statements, attach files, display references to other data assets, and / or provide other information. In some embodiments, the GUI may provide the proofer with a list of options from which the proofer can provide inputs that demonstrate a proof. For example, the list of options may include inputs that the data asset conforms to the data standard, the data asset does not conform to the data standard, the data asset partially conforms to the data standard, no proof is defined, or the data standard does not apply. In some embodiments, this GUI may allow the prover to create a ticket to resolve non-conforming data assets (for example, if a data asset does not conform to a data standard).

[0137] As shown in Figure 5B, module 210 for the GUI may send a data request 216 to the data governance system 220. The data governance system may provide data 218. Module 210 may use data 218 to populate information in the GUI. For example, module 210 may use data 218 to display information about data governance policies, data standards, data asset sets, data assets, compliance projects, or compliance audits.

[0138] As shown in Figure 2F, the data governance system 220 of the data processing system 100 includes a definition module 222, a compliance module 224, and a certification module 226.

[0139] In some embodiments, the definition module 222 may be configured to generate a data governance policy, a constituent data standard, and / or a set of data assets. The definition module 222 may be configured to associate a set of data assets with a data standard (for example, as described herein with respect to Figure 2B). In some embodiments, the definition module 222 may be configured to store the data governance policy and / or data standard as a data asset in the data processing system 100. The definition module 222 may be configured to store information about the data governance policy (e.g., a statement of rules, a name, a constituent data standard) as an attribute value in the data asset. The definition module 222 may be configured to store information about the data standard (e.g., a name, a description of the degree of compliance, a list of associated data asset sets, and / or a reference to the data governance policy) as an attribute value in the data asset.

[0140] In some embodiments, the definition module 222 may be configured to generate a data asset set. The definition module 222 may be configured to generate a data asset set using one or more criteria (e.g., indicated by user input through a GUI). The definition module 222 may be configured to select one or more data assets managed by the data processing system 100 that conform to one or more criteria, using one or more criteria. The definition module 222 may be configured to include the selected data assets in the data asset set. In some embodiments, the definition module 222 may be configured to update the data asset set. After selecting data assets from the data asset set, the definition module 222 may be configured to update the data asset set by (1) identifying one or more data assets that conform to one or more criteria, and (2) including the identified data assets in the data asset set. The identified data assets may differ from data assets that previously existed in the data asset set (e.g., due to updates to one or more data assets).

[0141] In some embodiments, the definition module 222 may be configured to store associations between data standards and one or more data asset sets. For example, the definition module 222 may store a list of data asset sets in the fields of the data standard asset. In some embodiments, the definition module 222 may be configured to store references to data asset sets in the fields of the data standard asset.

[0142] In some embodiments, the compliance module 224 may be configured to manage verification of compliance with data governance policies and / or data standards. The compliance module 224 may be configured to generate compliance projects and the compliance audits that comprise them (e.g., compliance project 238 and compliance audits 122, 246). The compliance module 224 may be configured to pair data standards with the data assets to which they apply. The compliance module 224 may be configured to pair data standards and data assets by (1) identifying the set of data assets associated with the data standard (e.g., by the definition module 222), and (2) pairing the data standard with each of the data assets in the set of data assets. The compliance module 224 may be further configured to identify users for pairing data standards with data assets. The compliance module 224 may be configured to automatically identify users involved in pairing data standards with data assets (e.g., performing certification) using information from the data assets (e.g., attribute values ​​indicating the user responsible for the data asset).

[0143] In some embodiments, the compliance module 224 may be configured to generate compliance projects. In some embodiments, the compliance module 224 may be configured to generate compliance projects for managing compliance verification with the data governance policy. The compliance project may include compliance reviews for each data standard of the data governance policy. For example, the compliance project may include compliance reviews for each data standard of the data governance policy. In other examples, the compliance project may include compliance reviews for each set of data assets associated with the data standards of the data governance policy. The compliance module 224 may be further configured to generate proof objects for each pairing of data assets with applicable data standards. The compliance module 224 may identify users who provide proof that data assets conform to applicable data standards.

[0144] In some embodiments, the compliance module 222 may be configured to identify information about a compliance project. For example, the compliance module 222 may be configured to identify the status of a compliance project and / or the compliance review comprising it. The compliance module 222 may be configured to identify the status of a compliance review based on the status of one or more certifications within the compliance review. For example, the compliance module 222 may identify the number of completed or incomplete certifications within a compliance review and / or compliance project, and based on this, the compliance module 222 may identify the status of the compliance review and / or compliance project. In some embodiments, the compliance module 222 may identify a certification as complete when a certification of whether a data asset conforms to a data standard has been identified (e.g., indicated by input from a computing device). In some embodiments, for data assets that do not conform to a data standard and / or partially conform, the compliance module 222 may request that an action be taken to identify that the certification is complete. For example, the compliance module 222 may request that a ticket be created for the non-conforming and / or partially conforming data asset.

[0145] In some embodiments, the certification module 226 may be configured to obtain proof that a data asset conforms to a data standard. In some embodiments, the certification module 226 may be configured to obtain proof by taking input (e.g., received through a GUI generated by the certification UI module 216) indicating a user's proof that a data asset conforms to a data standard. The certification module 226 may be configured to generate a certification object that stores information indicating proof. In some embodiments, the certification object may further store the state of the proof identified by the certification module 226 (e.g., completed or incomplete). In some embodiments, the certification module 226 may be configured to guide the prover through a process flow that performs proof. For example, the process flow may provide the prover 202C with information about the data standard, the data asset, and the mechanism through which the prover can demonstrate proof. The certification module 226 may further store information related to proof. For example, the certification module 226 may store data as evidence of proof and / or statements from the prover regarding proof within the certification object.

[0146] In some embodiments, the data governance system 220 may be configured to access data stored by the data processing system 100 (for example, within the data persistence layer 230). As shown in Figure 5B, the data governance system 220 may be configured to send a data request 226 to the data persistence layer 230 and receive data in response to the data request 226. In some embodiments, the data governance system 220 may be configured to send queries requesting data. For example, the data governance system 220 may send an SQL query requesting data. In some embodiments, the data 228 may be data specified by the request. For example, the data 228 may be one or more values ​​requested in the query.

[0147] In some embodiments, queries can be customized to vendor-specific forms. For example, different vendors (e.g., Microsoft, Oracle, IBM, POSTGRESQL, etc.) may implement different dialects of SQL and / or provide extensions to the SQL standard. In such situations, an executable query can be generated for a target database system (e.g., Oracle) using the syntax and / or commands implemented by that target database system (e.g., any special syntax and / or commands implemented by Oracle). Additionally or alternatively, the query may include optimizations for queries that may be supported by the target database system. Thus, in some embodiments, a query for one type of database (e.g., an executable SQL query for a Microsoft SQL Server database) and a query for another type of database (e.g., an executable SQL query for IBM DB2) may differ, even if both queries are generated from the same basic intermediate representation.

[0148] As shown in Figure 5B, the data persistence layer 230 stores data assets 106, data governance policies 102, data standards 104, compliance projects 120, compliance reviews 122, and certifications 130. In some embodiments, the data persistence layer 230 may include a data store for storing data. In some embodiments, the data store may include a relational database system, thereby allowing data to be stored in tables of the relational database system. However, the data store is not limited to a relational database system, as it can also be configured to store data in any appropriate way. For example, the data store may include an object-oriented database, a distributed database, a NoSQL database, and / or any other appropriate database. In some embodiments, the data governance policies 102, data standards 104, compliance projects 120, compliance reviews 122, and / or certifications 130 may be stored as data assets.

[0149] In some embodiments, each of the data persistence layers 230 may include one or more storage devices that store data in one or more formats of any suitable type. For example, the storage portion of the datastore may store data using one or more database tables, spreadsheet files, plaintext files and / or files in any other suitable format (e.g., the mainframe's native format). The storage devices may be of any suitable type and may include one or more servers, one or more database systems, one or more portable storage devices, one or more non-volatile storage devices, one or more volatile storage devices and / or any other devices configured to electronically store data. In embodiments in which the datastore includes multiple storage devices, the storage devices may be located in one physical location (e.g., within one building) or distributed across multiple physical locations (e.g., multiple buildings, different cities, states, or countries). The storage devices may be configured to communicate with each other using one or more networks of any suitable type, and the embodiments of the technology described herein are not limited thereto.

[0150] In some embodiments, the data persistence tier 230 may be configured to store data assets as data entity instances. A data asset can therefore be a data entity instance defined by a data entity. For example, the data processing system 100 may include data entities that define data governance policies, data standards, compliance projects, compliance audits, and / or certifications. Information about the data governance policies, data standards, compliance projects, and compliance audits may be stored in instances of their respective data entities.

[0151] In some embodiments, data asset 106 may include data assets managed by data processing system 100. Data asset 106 may store metadata about a dataset of a system (e.g., an enterprise system). In some embodiments, data governance policy 102 may include a definition of a data governance policy. For example, data governance policy 102 may include a statement of rules for data assets. Data governance policy 102 may include data standards that constitute it. For example, data governance policy 102 may include data standards 104 that constitute data governance policy 102.

[0152] In some embodiments, the data standard 104 includes a definition of the data standard (e.g., a name and / or rules or standards). The data standard 104 may further include a list of associated data asset sets. The data standard 104 may further include references to data governance policies and compliance projects and / or audits in which the data standard 104 is validated. The data standard 104 may further include a description.

[0153] In some embodiments, compliance project 120 may include information about the data governance policy to which the compliance project relates. Compliance project 120 may include a list of compliance reviews for compliance project 120. Compliance project 120 may include data standards and / or certifications that are part of compliance project 120. Compliance project 120 may further include the status of compliance project 120. In some embodiments, compliance project 120 may include information about the users responsible for aspects of the compliance project (e.g., project owners and / or certifiers).

[0154] In some embodiments, the compliance review 122 may include information about the data standards associated with the compliance review. The compliance review 122 may further include information about the data assets of the compliance review 122. For example, the compliance review 122 may include information from and / or references to the data assets. The compliance review 122 may further include status. In some embodiments, the compliance review may include information about the user responsible for the compliance review (e.g., the project manager).

[0155] In some embodiments, the proof 130 may include information about the data asset and data standard that are the subject of the proof 130. For example, the proof may include information about the degree of compliance with the data standard and information about the data asset. The proof may include references to the data standard and / or data asset. In some embodiments, the proof includes the status of the proof (e.g., completed, incomplete, started, in progress). In some embodiments, the proof includes an indication of the proofer who is scheduled to perform the proof.

[0156] Figure 6 shows a flowchart of an exemplary process 600 used in relation to the governance of data assets managed by a data processing system (e.g., data processing system 100) according to several embodiments of the technology described herein. Process 600 can be performed by any suitable computing device. For example, process 600 can be performed by the data processing system 100 described herein with respect to Figures 2A-2F.

[0157] Process 600 begins at block 602, where the system accesses the data governance policy, which includes data standards. The system may be configured to access the data governance policy by accessing information that defines it. For example, the system may access the data governance policy by accessing information from a data asset that stores information about the governance policy (e.g., a description and list of the data standards it constitutes). As an illustrative example, the system may send a request (e.g., a query) to the data persistence layer to retrieve information about the data governance policy. This information may include information about data standards.

[0158] In some embodiments, the system may be configured to generate data standards for data governance policies. For example, the system may be configured to generate data standards by generating a new data asset associated with the data governance policy. The new data asset may store information about the data standards for the data governance policy. The system can then access the generated data standards.

[0159] Next, process 600 proceeds to block 604, where the system generates a set of data assets by selecting from data assets using one or more data asset criteria. In some embodiments, data assets may be data assets managed by a data processing system (e.g., data processing system 100). The system may be configured to select from data assets by (1) identifying one or more data assets that meet one or more criteria, and (2) selecting the identified data assets. For example, the system may perform a search using one or more criteria to identify data assets. As an illustrative example, in a banking system, one or more criteria may include (1) that the data asset is a “credit score” data asset, and (2) that the data asset stores information about a U.S. resident. In this example, the system may identify the “credit score” data asset for a U.S. resident. The system may include the identified data assets in the set of data assets.

[0160] In some embodiments, the data asset set may have been generated in the past, and in block 604, the system may be configured to update the data asset set. The system may be configured to update the data asset set by (1) identifying one or more data assets that meet one or more criteria, and (2) selecting the identified data assets. The identified data assets may differ from data assets that were previously included in the data asset set (for example, as a result of updating data assets). The system may be configured to update the data asset set to include the identified data assets. Thus, the data asset set may reflect the current state of the data assets.

[0161] In some embodiments, the system may be configured to acquire one or more criteria. The system may be configured to acquire one or more criteria by receiving user input (e.g., through a GUI) indicating one or more criteria. For example, the system may receive user input indicating a selection that indicates one or more criteria within a search and / or filter GUI.

[0162] Next, process 600 proceeds to block 606, where the system associates the data asset set with a data standard. In some embodiments, the system may be configured to associate a data asset set with a data standard by storing the association of the data asset set with the data standard. For example, the system may store a reference to the data asset set within the data standard (e.g., in the system's data standard asset). In some embodiments, associating a data asset set with a data standard may include associating the data standard with the data asset base set used to generate the data asset set. For example, the system may store a reference to the data asset base set within the data standard.

[0163] In some embodiments, the system may be configured to associate a set of data assets with a data standard in response to a command. The command may be user input indicating a command to associate a set of data assets with a data standard. For example, the system may receive user input indicating a command through a GUI. In response to receiving a command, the system may associate a set of data assets with a data standard. In some embodiments, the system may be configured to receive user input indicating a selection of a set of data assets from a list of one or more sets of data assets (e.g., previously generated by the system). For example, the system may receive a selection of GUI elements representing a set of data assets from a selection of GUI elements representing each set of data assets.

[0164] Next, process 600 proceeds to block 608, where the system verifies whether one or more data assets in the data asset set conform to the data standard. The system may be configured to verify whether the data assets in the data asset set conform to the data standard by performing process 700, which is described herein with respect to Figure 7.

[0165] Figure 7 shows a flowchart of an exemplary process 700, according to several embodiments of the technology described herein, for verifying whether a data asset managed by a system conforms to a data governance policy that includes the data standards associated with that data asset. Process 700 can be performed by any suitable computing device. For example, process 700 can be performed by the data processing system 100 described herein with respect to Figures 2A-2F.

[0166] Process 700 begins in block 702, where the system identifies a user who certifies whether a data asset conforms to a data standard. In some embodiments, the system may be configured to identify a user using information from the data asset. For example, the data asset may include attribute values ​​indicating the person responsible for the data asset. The system may identify a user as the person indicated by the attribute values. The system can therefore automatically identify the person who will certify the data asset.

[0167] In some embodiments, the system may be configured to generate compliance projects that include one or more compliance reviews (as described herein, for example, with respect to Figure 3). The system may identify users to match them with data standards for pairing data assets in compliance reviews. Users may be assigned pairings to perform certification.

[0168] Next, process 700 proceeds to block 704, where the system transmits information about data assets and data standards to a computing device. The computing device may be associated with a user. In some embodiments, the system may be configured to transmit information about data assets and data standards to the computing device via a communication network (e.g., the Internet).

[0169] In some embodiments, the system may be configured to retrieve information about data assets and data standards. The system may be configured to retrieve information by sending requests (e.g., queries) to a database system (e.g., data persistence tier 230) that stores the data assets and data standards. The system may be configured to receive information about data assets and data standards in response to sending requests.

[0170] Next, process 700 proceeds to block 706, where the system obtains an input from the computing device indicating a user's certification of whether or not the data asset conforms to a data standard. In some embodiments, the system may be configured to provide the user with one or more options (e.g., through a GUI and / or workflow). For example, the options may be that the data asset does not conform to a data standard, partially conforms to a data standard, does not conform to a data standard, or is not subject to a data standard. The system may be configured to receive an input indicating a selection of an option. In some embodiments, the system may be configured to obtain certification information, which includes an input indicating a user's certification of whether or not the data asset conforms to a data standard. In some embodiments, the certification information may also include other information, such as comments and evidence (e.g., files, documents, links, and / or other appropriate evidence).

[0171] In some embodiments, the system may be configured to store a record of proofs. In some embodiments, the system may be configured to store a record of proofs in a proof object. For example, a proof object may include one or more fields and / or attributes. The system may be configured to store a representation of a proof in a field or attribute.

[0172] Next, process 700 proceeds to block 708, where the system verifies, based on proof, whether the data asset conforms to the data standard. For example, the system may determine that a data asset conforms to the data standard if the user provides proof that the data asset fully or partially conforms to the data standard. Otherwise, the system may determine that the data asset does not conform. In another example, the system may determine that a data asset conforms to the data standard only if the user provides proof that the data asset fully conforms to the data standard. Otherwise, the system may determine that the data asset does not conform to the data standard.

[0173] In some embodiments, the system may be configured to store information indicating a certification in a certification object (e.g., part of a compliance review). In some embodiments, the system may be configured to update the status of certifications, compliance reviews, and / or compliance projects based on the certification. For example, the system may update the completion percentage of compliance reviews, compliance projects, and / or certifications to indicate that a certification has been completed.

[0174] Figure 8 shows an exemplary graphical user interface (GUI) 800 displaying information about a data governance policy according to several embodiments of the technology described herein. The GUI 800 displays information including the policy name 802, “Handling of Critical Data Elements (CDEs),” and a description of the policy 804. The GUI 800 also displays a list 806 of data standards that constitute the data governance policy. The list 806 includes a description 808 of the data standards.

[0175] Figure 9 shows an exemplary graphical user interface (GUI) 900 for displaying information about a data standard, according to several embodiments of the technology described herein. GUI 900 displays a display 902 of the data governance policy to which the data standard belongs (for example, information about which is displayed in GUI 800 in Figure 8). GUI 900 displays the name 904 and definition 906 of the standard. GUI 900 displays a list 908 of data asset sets associated with the data standard. Once a data asset set is selected from list 908, as shown in the example in Figure 9, GUI 900 displays a list 910 of the assets in the data asset set.

[0176] Figure 10 is a diagram of an exemplary graphical user interface (GUI) 1000 according to several embodiments of the technology described herein, which allows a user to select a data asset set from a list of existing data asset sets for association with a data standard. As indicated by the graphical element 1002 indicating the “Select an existing one” selection, the GUI 1000 displays a list 1004 of previously generated data asset sets from which one can be selected for association with a data standard. The GUI 1000 displays selection criteria 1005 associated with the listed data asset sets. As shown in the example of Figure 10, once a data asset set is selected from the list 1004, the GUI 1000 displays a list 1006 of data assets for the selected data asset set.

[0177] Figure 11 shows an exemplary graphical user interface (GUI) 1100 that allows a user to create a new set of data assets to associate with a data standard, according to several embodiments of the technology described herein. The GUI 1100 allows the user to create a new set of data assets, as indicated by GUI element 1102. The GUI 1100 allows the user to indicate the asset type 1104 and select a specific data asset 1106. The GUI 1100 displays a list of assets 1108 that will be included in the new set of data assets.

[0178] Figure 12 is a diagram of another example graphical user interface (GUI) 1200 that allows a user to create a new set of data assets to associate with a data standard, according to some embodiments of the technology described herein. As shown by GUI element 1202, the user has chosen to create a new set of data assets. GUI 1200 allows the user to specify one or more criteria to use to generate the set of data assets. GUI 1200 allows the user to specify a type of data asset 1204. In the example in Figure 12, the selected type of data asset is "Business Data Element". GUI 1200 allows the user to specify a regional criterion 1206 for the set of data assets. In the example in Figure 12, the region specified is "United States". GUI 1200 further displays a list 1208 of data assets that will be included in the set of data assets based on the criteria specified by the user.

[0179] Figure 13 shows an exemplary graphical user interface (GUI) 1300 that displays information about a data standard according to several embodiments of the technology described herein. GUI 1300 displays a display 1302 of the data governance policy to which the data standard belongs. GUI 1300 displays the name 1304 of the data standard, the definition 1306 of the data standard, and a description 1308 of the evidence required to indicate whether a data asset conforms to the data standard. GUI 1300 displays a list 1310 of the data asset sets associated with GUI 1300. As shown in Figure 13, GUI 1300 displays a list 1312 of data assets in the data asset sets selected from list 1310.

[0180] Figure 14 shows an exemplary graphical user interface (GUI) 1400 displaying information about a compliance project according to several embodiments of the technology described herein. The GUI 1400 displays the name of the compliance project 1402, a description of the compliance project 1404, and the duration of the compliance project (e.g., the period over which the compliance project will be completed) 1406. The GUI 1400 further displays the project owner 1407 of the compliance project. The GUI 1400 displays a list 1408 of compliance audits that are part of the compliance project. The list includes a description 1410 of each compliance audit, the name of the standard associated with the compliance audit 1412, and the status of the compliance audit 1414. As shown in Figure 14, the status 1414 may be a graphical element indicating the current status of the compliance project.

[0181] Figure 15 shows an exemplary graphical user interface (GUI) 1500 displaying information about a compliance review according to several embodiments of the technology described herein. GUI 1500 displays a display 1502 of the compliance project in which the compliance review is part. GUI 1500 displays the name 1504 of the compliance review, a description 1506 of the compliance review, and the duration 1508 of the compliance review (e.g., the period in which the compliance review will be completed). GUI 1500 further displays the project owner 1507 of the compliance review and / or the compliance project in which the compliance review is part. As shown in Figure 15, GUI 1500 displays a list 1510 of certifications to be performed as part of the compliance review. List 1510 includes a certification identifier 1512 and the name 1514 of the data asset in which the certification will be performed. GUI 1500 displays the status 1516 of whether the data asset conforms to the standard (e.g., as identified by the certification).

[0182] Figure 16 shows an exemplary graphical user interface (GUI) 1600 displaying information about certification according to several embodiments of the technology described herein. GUI 1600 displays information about the compliance project for which the certification will be created, including the name of the compliance project 1602, the duration of the compliance project 1604, and the name of the compliance review 1606 for which the certification is part. GUI 1600 further displays information about the personnel involved in the certification, including the compliance project owner 1608 and one or more subject experts 1610. GUI 1600 further displays information 1310 about the data standard for which certification will be made. As shown in Figure 16, the information 1610 about the data standard includes the name of the data standard, the name of the data governance policy to which the data standard belongs, a description of the data standard (e.g., the rule requirements of the data standard), and a description of the evidence required to prove that the data assets conform to the data standard. GUI 1600 further displays certification information 1612. The certification information 1612 includes a status (e.g., "Asset under evaluation") and a comment (e.g., "I have reviewed the data and this dataset is correctly listed as containing PII"). GUI 1600 provides GUI section 1614 through which users can submit certifications. For example, a user can provide a statement certifying whether the data asset associated with the certification conforms to the data standard associated with the certification.

[0183] Figure 17 shows an exemplary graphical user interface (GUI) 1700 displaying information about a compliance project in progress, according to several embodiments of the technology described herein. The GUI 1700 displays a list 1702 of compliance projects in progress. The list may be an expandable list in which the GUI 1700 displays compliance reviews for a compliance project when a compliance project is selected. For example, in the example in Figure 17, the GUI 1700 displays a list 1706 of compliance reviews for the selected compliance project in list 1702. The GUI 1700 further displays GUI elements 1704 indicating the status of the compliance project and GUI elements 1708 indicating the status of the compliance review. The GUI 1700 further displays a list 1710 of certifications for compliance projects in progress. The list 1710 may be divided by status (e.g., "Before Start", "Ticket Required", "Completed", etc.).

[0184] Figure 18 shows an exemplary graphical user interface (GUI) 1800 that displays information about the certification status of a compliance project according to several embodiments of the technology described herein. GUI 1800 provides an interface through which a user can view certifications (e.g., certifications for all certifications or certifications for one or more compliance audits). GUI 1800 provides a filter 1808 through which the user can filter certifications. For example, as shown in Figure 18, GUI 1800 may allow the user to filter the shown certifications (e.g., not conforming to data standards, not applicable, partially conforming to data standards, undefined, conforming to data standards, as shown in Figure 18) based on the compliance project. GUI 1800 may further allow the user to filter based on the certification status (e.g., attention required or sign off) and subject familiarity. GUI 1800 displays a list 1802 of certifications based on selected criteria. GUI 1800 displays a list 1804 of assets for which each certification should be made and a list 1810 of standards for which each certification should be made. GUI 1800 also displays List 1806 of the proof states listed.

[0185] Figure 19 shows an exemplary graphical user interface (GUI) 1900 that allows a user to edit one or more proofs selected from the GUI 1800 of Figure 18, according to several embodiments of the technology described herein. The GUI 1900 allows the user to edit the attributes of the selected proofs. Attributes include comments, proof ratings, project owner, review owner, subject expert, and textual evidence. In the example of Figure 19, the user has selected comments 1902 and proof ratings 1904. The GUI 1900 provides selectable options 1906 that the user can use to indicate proof ratings. The GUI 1900 provides a text input 1908 for the user to provide comments for the selected proofs.

[0186] Figure 20 shows an exemplary graphical user interface (GUI) 2000 that allows a user to sign off on one or more certificates according to several embodiments of the technology described herein. The GUI 2000 displays a list of selected certificates 2002. The GUI 2000 provides the user with the option 2008 to sign off on the selected certificates or to submit the certificates.

[0187] Figure 21 shows an exemplary graphical user interface (GUI) 2100 for displaying information about a data asset, according to several embodiments of the technology described herein. The GUI 2100 displays the name 2102 of the data asset. The GUI 2100 further displays a list 2104 of the certifications related to that data asset. The GUI 2100 displays a list 2106 of the data standards for the certifications. The GUI 2100 further displays a list 2108 of the status of the certifications in list 2104.

[0188] Exemplary computer system Figure 22 shows an example of a suitable computing system environment 2200 in which the technologies described herein may be implemented. The computing system environment 2200 is merely an example of a suitable computing environment and is not intended to imply any limitation on the scope of use or functionality of the technologies described herein. The computing environment 2200 should not be construed as having any dependencies or requirements relating to any one or combination of the components shown in the exemplary operating environment 2200.

[0189] The technologies described herein can operate using many other general-purpose or dedicated computing system environments or configurations. Examples of well-known computing systems, environments and / or configurations suitable for use with the technologies described herein include, but are not limited to, personal computers, server computers, handheld or laptop devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices.

[0190] A computing environment can execute computer executable instructions, such as program modules. Generally, a program module includes routines, programs, objects, components, data structures, etc., that perform a specific task or implement a specific abstract data type. The techniques described herein can also be implemented in a distributed computing environment where tasks are performed by remote processing devices linked through a communication network. In a distributed computing environment, program modules may reside on both local computer storage media, including memory storage devices, and remote computer storage media.

[0191] Referring to Figure 22, an exemplary system implementing the techniques described herein includes a general-purpose computing device in the form of a computer 2200. Components of computer 2210 may include, but are not limited to, a processing unit 2220, system memory 2230, and a system bus 2221 connecting various system components, including the system memory, to the processing unit 2220. The system bus 2221 may be any of several types of buses, including a memory bus or memory controller, peripheral buses, and local buses, using any of a variety of bus architectures. Examples of such architectures include, but are not limited to, industry standard architecture (ISA) buses, microchannel architecture (MCA) buses, extended ISA (ELISA) buses, video electronics standards society (VESA) local buses, and peripheral interconnect (PCI) buses, also known as mezzanine buses.

[0192] Computer 2210 typically includes a variety of computer-readable media. Computer-readable media can be any available media accessible by computer 2210, and include both volatile and non-volatile media, and both removable and non-removable media. For example, but not limited to, computer-readable media may include computer storage media and communication media. Computer storage media include volatile and non-volatile removable and non-removable media implemented in any method or technique for storing information such as computer-readable instructions, data structures, program modules, or other data. Computer storage media include, but not limited to, RAM, ROM, EEPROM, flash memory, or other memory technologies, CD-ROM, digital versatile disk (DVD), or other optical disk storage devices, magnetic cassettes, magnetic tapes, magnetic disk storage devices, or other magnetic storage devices, or any other media that can be used to store desired information and can be accessed by computer 2210. Communication media typically include any information transport media that embody computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transport mechanisms. The term "modulated data signal" means a signal that has one or more feature sets, or a signal that has been modified to encode information into the signal. Communication media include, but are not limited to, wired media such as wired networks or direct wiring connections, and wireless media such as acoustic, RF, infrared, and other wireless media. Any combination of the above should also be included within the scope of computer-readable media.

[0193] System memory 2230 includes computer storage media in the form of volatile and / or non-volatile memory, such as read-only memory (ROM) 2231 and random-access memory (RAM) 2232. The Basic Input / Output System 2233 (BIOS), which contains basic routines that help transfer information between elements within the computer 2210 during startup, is typically stored in ROM 2231. RAM 2232 typically contains data and / or program modules that are immediately accessible to and / or currently being manipulated by the processing unit 2220. As an example, but not limited to, Figure 22 shows an operating system 2234, an application program 2235, other program modules 2236, and program data 2237.

[0194] Computer 2210 may also include other removable / non-removable volatile / non-volatile computer storage media. As a mere example, Figure 22 shows a hard disk drive 2241 that reads or writes to a non-removable non-volatile magnetic medium, a flash drive 2251 that reads or writes to removable non-volatile memory 2252 such as flash memory, and an optical disk drive 2255 that reads or writes to removable non-volatile optical disks 2256 such as CD-ROMs or other optical media. Other removable / non-removable volatile / non-volatile computer storage media that may be used in the exemplary operating environment include, but are not limited to, magnetic tape cassettes, flash memory cards, digital multipurpose disks, digital videotapes, solid-state RAM, solid-state ROM, etc. The hard disk drive 2241 is typically connected to the system bus 2221 via a non-removable memory interface such as interface 2240, while the magnetic disk drive 2251 and optical disk drive 2255 are typically connected to the system bus 2221 via a removable memory interface such as interface 2250.

[0195] The drives and associated computer storage media described above and shown in Figure 22 provide storage for computer-readable instructions, data structures, program modules, and other data of the computer 2210. In Figure 22, for example, the hard disk drive 2241 is shown as storing the operating system 2244, application programs 2245, other program modules 2246, and program data 2247. These components may be the same as or different from the operating system 2234, application programs 2235, other program modules 2236, and program data 2237. The operating system 2244, application programs 2245, other program modules 2246, and program data 2247 are given different numbers here to indicate that they are at least different copies. An actor may input commands and information to the computer 2210 through input devices such as a keyboard 2262 and a pointing device 2261, commonly referred to as a mouse, trackball, or touchpad. Other input devices (not shown) may include microphones, joysticks, gamepads, parabolic antennas, scanners, etc. These and other input devices are often connected to the processing unit 2220 through a user input interface 2260 coupled to the system bus, but may also be connected by other interfaces and bus structures such as a parallel port, game port, or Universal Serial Bus (USB). A monitor 2291 or other type of display device is also connected to the system bus 2221 via an interface such as a video interface 2290. In addition to the monitor, the computer may also include other peripheral output devices such as speakers 2297 and a printer 2296, which may be connected through an output peripheral interface 2295.

[0196] Computer 2210 may operate in a networked environment using logical connections to one or more remote computers, such as remote computers 2280. The remote computers 2280 could be personal computers, servers, routers, network PCs, peer devices, or other common network nodes, typically including many or all of the elements described above with respect to computer 2210, except that only the memory storage device 2281 is shown in Figure 22. The logical connections shown in Figure 22 include a local area network (LAN) 2281 and a wide area network (WAN) 2283, but may include other networks. Such networking environments are common in offices, enterprise-scale computer networks, intranets, and the internet.

[0197] When used in a LAN networking environment, computer 2210 is connected to LAN 2281 via a network interface or adapter 2280. When used in a WAN networking environment, computer 2210 typically includes other means of establishing communication via modem 2282 or WAN 2283 such as the Internet. Modem 2282 may be internal or external and may be connected to system bus 2221 via actor input interface 2260 or other suitable mechanism. In a networked environment, program modules or parts thereof shown with respect to computer 2210 may be stored in remote memory storage. As an example, but not an limitation, Figure 22 shows a remote application program 2285 residing in memory device 2281. It will be understood that the networked connections shown are illustrative and other means of establishing communication links between computers may be used.

[0198] Although several aspects of at least one embodiment of the technology described herein have been explained, it should be understood that those skilled in the art will readily conceive of various modifications, alterations, and improvements.

[0199] Such modifications, alterations, and improvements are intended to be part of this disclosure and to be within the spirit and scope of this disclosure. Furthermore, while the advantages of the technology described herein have been shown, it should be understood that not all embodiments of the technology described herein include all of the advantages described herein. Some embodiments may not implement any of the features described herein as advantages, and in some cases one or more of the features described may be implemented to achieve further embodiments. Accordingly, the above description and drawings are for illustrative purposes only.

[0200] The embodiments of the technology described herein can be implemented in any of many ways. For example, the embodiments may be implemented using hardware, software, or a combination thereof. If implemented in software, the software code can run on any suitable processor or set of processors, whether provided on one computer or distributed across multiple computers. Such processors may be implemented as integrated circuits, and one or more processors may be located within an integrated circuit component, including commercially available integrated circuit components known in the art, such as CPU chips, GPU chips, microprocessors, microcontrollers, or coprocessors. Alternatively, the processor may be implemented in a semi-custom circuit resulting from the configuration of a custom circuit or programmable logic device, such as an ASIC. As a further alternative, the processor may be part of a larger circuit or semiconductor device, whether commercial, semi-custom, or custom. As a specific example, some commercial microprocessors have multiple cores, such that one or a subset of cores may constitute a processor. However, the processor may be implemented using a circuit in any suitable format.

[0201] Furthermore, it should be understood that computers can be implemented in any of many forms, such as rack-mount computers, desktop computers, laptop computers, or tablet computers. Additionally, computers can be implemented in devices that are not generally considered computers but possess suitable processing capabilities, including personal data assistants (PDAs), smartphones, or any other suitable portable or fixed electronic devices.

[0202] Furthermore, a computer may have one or more input and output devices. These devices can be used, in particular, to present a user interface. Examples of output devices that can be used to provide a user interface include printers or display screens for visually presenting output and speakers or other sound-generating devices for audibly presenting output. Examples of input devices that can be used for a user interface include keyboards and pointing devices such as mice, touchpads, and digitizing tablets. As another example, a computer may receive information input through speech recognition or in other audible formats.

[0203] Such computers may be interconnected by one or more networks in any suitable form, including local area networks or wide area networks such as enterprise networks or the Internet. Such networks may be based on any suitable technology, operate according to any suitable protocol, and may include wireless networks, wired networks or fiber optic networks.

[0204] Furthermore, the various methods or processes outlined herein can be coded as software executable on one or more processors utilizing a variety of operating systems or platforms. Moreover, such software can be written using several suitable programming languages ​​and / or programming or scripting tools, and can be compiled as executable machine language code or intermediate code run on a framework or virtual machine.

[0205] In this regard, embodiments of the technology described herein may be implemented as a computer-readable storage medium (or more computer-readable media) (e.g., computer memory, one or more floppy disks, compact discs (CDs), optical discs, digital video discs (DVDs), magnetic tape, flash memory, field-programmable gate arrays or other semiconductor device circuit configurations or other tangible computer storage media) on which one or more programs that, when executed on one or more computers or other processors, perform methods for implementing the various embodiments described above are encoded. As will be apparent from the above examples, the computer-readable storage medium may retain information for a time sufficient to provide computer-executable instructions in a non-temporary form. One or more such computer-readable storage media may be transportable so that the stored one or more programs can be loaded onto one or more different computers or other processors to implement the various embodiments of the technology described above. As used herein, the term “computer-readable storage medium” includes only non-temporary computer-readable media that can be considered as a manufacture (i.e., product) or machine. Alternatively or in addition, the technologies described herein may be implemented using computer-readable media other than computer-readable storage media, such as propagated signals.

[0206] The terms “program” or “software” are used herein in a general sense to refer to any type of computer code or set of computer executable instructions that can be used to program a computer or other processor to implement various aspects of the techniques described herein. Furthermore, it should be understood that, according to one aspect of this embodiment, one or more computer programs that, when executed, perform the methods of the techniques described herein do not need to reside on a single computer or processor, but can be modularly distributed across several different computers or processors to implement various aspects of the techniques described herein.

[0207] Computer executable instructions can take many forms, such as program modules, which are executed by one or more computers or other devices. Generally, a program module includes routines, programs, objects, components, data structures, etc., that perform a specific task or implement a specific abstract data type. Typically, the functions of a program module can be combined or distributed as desired in various embodiments.

[0208] Furthermore, data structures can be stored in a computer-readable medium in any suitable form. For the sake of brevity of the example, a data structure may be represented by having related fields through locations in the data structure. Such relationships can also be achieved by assigning the storage of fields to locations in a computer-readable medium that convey the relationships between fields. However, any suitable mechanism can be used to establish relationships between information in the fields of a data structure, including the use of pointers, tags, or other mechanisms for establishing relationships between data elements.

[0209] Various aspects of the technology described herein may be used individually, in combination, or in a variety of configurations not specifically considered in the embodiments described above, and therefore their application is not limited to the details and arrangement of components described in the above description or shown in the drawings. For example, an aspect described in one embodiment may be combined in any way with an aspect described in another embodiment.

[0210] Furthermore, the techniques described herein may be implemented as methods, and examples of methods are provided herein, including by reference to Figures 3 and 7. The operations performed as part of any of the methods may be in any suitable order. Thus, embodiments can be constructed in which the operations are performed in a different order than those shown, which may include performing several operations simultaneously, even though they are shown as sequential operations in exemplary embodiments.

[0211] Furthermore, some actions are described as being performed by an "actor" or "user." It should be understood that the "actor" or "user" does not necessarily have to be a single individual; in some embodiments, actions attributed to an "actor" or "user" may be performed by a team of individuals and / or a combination of computer-aided tools or other mechanisms.

[0212] The use of ordinal numbers such as "first," "second," and "third" modifying claim elements in the claims does not, in itself, imply any priority, precedence, or sequence, or temporal order in which the actions of one claim element and another act on another claim element are performed, but is simply used as a label to distinguish a claim element having a particular name from another element having the same name (other than the use of ordinal numbers).

[0213] Furthermore, the expressions and terms used herein are for illustrative purposes only and should not be considered limiting. The use herein of “includes,” “contains,” “has,” “contains,” “accompanys,” and variations thereof means the inclusion of the items listed thereafter and their equivalents, as well as any additional items.

Claims

1. A method for determining whether data managed by a data processing system conforms to a data governance policy, wherein the data processing system stores the data in a plurality of data assets, each containing one or more attribute-value pairs, and the data governance policy includes one or more data standards, each specifying one or more rules that a data asset must satisfy in order to conform to the data standards, and the method is Using at least one computer hardware processor, Receiving user input indicating at least one criterion for including a data asset in a first data asset set, The first set of data assets is generated by automatically identifying data assets that meet at least one of the aforementioned criteria from among the plurality of data assets. The data governance policy receives user input indicating the selection of a first data standard from among the one or more data standards. Associating the first data standard with the first data asset set, At least in part, by verifying whether the data assets in the first data asset set satisfy one or more rules specified by the first data standard, it is possible to determine whether the data managed by the data processing system conforms to the data governance policy. A method that includes carrying out [something].

2. The method according to claim 1, wherein the at least one criterion indicates at least one value that at least one attribute in the data asset must take in order to conform to the at least one criterion.

3. Receiving user input indicating the selection of a second data standard from among the one or more data standards of the aforementioned data, Associating the second data standard with the first data asset set, At least in part, by verifying whether the data assets in the first data asset set satisfy one or more rules specified by the second data standard, it is possible to determine whether the data managed by the data processing system conforms to the data governance policy. The method according to claim 1, further comprising:

4. The method according to claim 1, further comprising updating the first data asset set using the at least one criterion before verifying whether the data assets in the first data asset set satisfy the one or more rules specified by the first data standard.

5. Updating the first data asset set using at least one of the aforementioned criteria is: Identifying at least one data asset among the plurality of data assets that is not in the first data asset set and that meets the at least one criterion, In response to identifying the at least one data asset that meets the at least one criterion, add the at least one data asset to the data asset set. The method according to claim 4, including the method described in claim 4.

6. Updating the first data asset set using at least one of the aforementioned criteria is: Identifying at least one data asset in the first set of data assets that no longer meets the aforementioned criterion, In response to identifying the at least one data asset that does not meet the at least one criterion, remove the at least one data asset from the first set of data assets. The method according to claim 4, including the method described in claim 4.

7. Associating the first data standard with the first data asset set means The system receives user input through a graphical user interface (GUI) indicating the selection of the first data asset set from among multiple data asset sets, In response to receiving the user input, the first data standard is associated with the first data asset set. The method according to claim 1, including the method described in claim 1.

8. Receiving user input indicating the selection of the first data standard includes receiving user input indicating the selection of the first data standard through a graphical user interface (GUI), The method according to claim 1, wherein associating the first data standard with the first data asset set includes associating the first data standard with the first data asset set in response to receiving the user input.

9. The method according to claim 8, wherein the GUI displays GUI elements representing a plurality of data asset sets, and the user input indicates the selection of the first data asset set by indicating the selection of one of the GUI elements.

10. The method according to claim 8, wherein the GUI displays information indicating one or more data assets that meet the at least one criterion after the selection of the first set of data assets.

11. The method according to claim 8, wherein the GUI includes an interface that enables a user to search for data assets that meet the at least one criterion.

12. To generate a first GUI that displays a list of at least some of the data assets in the first data asset set, Through the first GUI, the system receives user input indicating the selection of a data asset in the list of at least some data assets, In response to receiving the user input, a second GUI is generated that displays information about the selected data asset. The method according to claim 1, further comprising:

13. Verification of whether the data assets in the first data asset set satisfy the one or more rules indicated by the first data standard means that for at least one of the data assets in the first data asset set, Identifying a user who determines whether the at least one data asset satisfies the one or more rules indicated by the first data standard, based on at least one attribute value pair of the at least one data asset, wherein the at least one attribute value pair of the at least one data asset represents the user. Transmitting information about the at least one data asset and the first data standard to a computing device associated with the user and via a communication network, The computing device associated with the user receives information via the communication network indicating whether the at least one data asset satisfies the one or more rules indicated by the first data standard. The method according to claim 1, including the method described in claim 1.

14. Verification of whether the data assets in the first data asset set satisfy the one or more rules indicated by the first data standard means that for at least some of each specific data asset in the first data asset set, Identifying a user who determines, based on at least one attribute value of the specific data asset, whether the specific data asset satisfies the one or more rules indicated by the first data standard, wherein at least one attribute value of the specific data asset indicates the user. Transmitting information about the specific data asset and the first data standard to a computing device associated with the user and via a communication network, Receiving information from the computing device associated with the user via the communication network indicating whether the specific data asset satisfies one or more rules indicated by the first data standard. The method according to claim 1, including the method described in claim 1.

15. The method of claim 14, wherein the information indicating whether the particular data asset satisfies the one or more rules shown by the first data standard includes a user's proof of whether the particular data asset satisfies the one or more rules shown by the first data standard.

16. The method according to claim 1, wherein verifying whether a data asset in the first data asset set satisfies one or more rules indicated by the first data standard includes automatically verifying whether a data asset satisfies one or more rules indicated by the first data standard.

17. Receiving user input indicating at least one second criterion for including a data asset in a second data asset set, The second data asset set is generated by automatically identifying, from among the plurality of data assets, data assets that meet the at least one second criterion for including the data asset in the second data asset set. Receiving user input indicating the selection of a second data standard from among the one or more data standards of the aforementioned data governance policy, Associating the second data standard with the second data asset set, At least in part, by verifying whether the data assets in the second data asset set satisfy one or more rules specified by the second data standard, it is possible to determine whether the data managed by the data processing system conforms to the data governance policy. The method according to claim 1, further comprising:

18. Receiving user input indicating the selection of a second data standard from among the one or more data standards of the aforementioned data governance policy, Associating the second data standard with the first data asset set, At least in part, by verifying whether the data assets in the first data asset set satisfy one or more rules specified by the second data standard, it is possible to determine whether the data managed by the data processing system conforms to the data governance policy. The method according to claim 1, further comprising:

19. The method according to claim 1, wherein associating the first data standard with the first data asset set includes storing data representing the first data asset set in the first data standard.

20. The method according to claim 1, wherein the data managed by the data processing system includes information associated with data within an enterprise system.

21. At least one non-temporary computer-readable storage medium storing processor-executable instructions that, when executed by at least one computer hardware processor, cause the at least one computer hardware processor to perform a method for determining whether data managed by a data processing system conforms to a data governance policy, wherein the data processing system stores the data in a plurality of data assets, each comprising one or more attribute value pairs, and the data governance policy comprises one or more data standards, each indicating one or more rules that a data asset must satisfy in order to conform to the data standard, and the method is Receiving user input indicating at least one criterion for including a data asset in a first data asset set, The first set of data assets is generated by automatically identifying data assets that meet at least one of the aforementioned criteria from among the plurality of data assets. Receiving user input indicating the selection of a first data standard from among the one or more data standards of the aforementioned data governance policy, Associating the first data standard with the first data asset set, At least in part, by verifying whether the data assets in the first data asset set satisfy one or more rules specified by the first data standard, it is possible to determine whether the data managed by the data processing system conforms to the data governance policy. A non-temporary computer-readable storage medium including at least one such medium.

22. A system for determining whether data managed by a data processing system conforms to a data governance policy, wherein the data processing system stores the data in a plurality of data assets, each containing one or more attribute value pairs, and the data governance policy includes one or more data standards, each specifying one or more rules that a data asset must satisfy in order to conform to the data standards, and the system At least one computer hardware processor, When executed by the at least one computer hardware processor, the at least one computer hardware processor, Receiving user input indicating at least one criterion for including a data asset in a first data asset set, The first set of data assets is generated by automatically identifying data assets that meet at least one of the aforementioned criteria from among the plurality of data assets. Receiving user input indicating the selection of a first data standard from among the one or more data standards of the aforementioned data governance policy, Associating the first data standard with the first data asset set, At least in part, by verifying whether the data assets in the first data asset set satisfy one or more rules specified by the first data standard, it is possible to determine whether the data managed by the data processing system conforms to the data governance policy. A non-temporary computer-readable storage medium that stores instructions for carrying out the action A system that includes this.

23. A method for determining whether data managed by a data processing system conforms to a data governance policy, wherein the data processing system stores the data in a plurality of data assets, each containing one or more attribute-value pairs, the data governance policy includes one or more data standards, each indicating one or more rules that a data asset must satisfy in order to conform to the data standards, each of the one or more data standards associated with one or more sets of data assets, each of the one or more data standards including a first data standard associated with a first set of data assets of the one or more sets of data assets, and the method is Using at least one computer hardware processor, Accessing a first data asset from the first data asset set associated with the first data standard, Identifying a first user who proves whether the first data asset satisfies one or more rules indicated by the first data standard, based on at least one attribute value pair of the first data asset, wherein at least one attribute value pair of the first data asset indicates the first user, Transmitting information about the first data asset and the first data standard to a first computing device associated with the first user and via a communication network, Obtaining a first input from the first computing device and through the communication network that represents a first proof by the first user regarding whether the first data asset satisfies one or more rules indicated by the first data standard, Using the first input that provides the first proof, determine whether the data managed by the data processing system conforms to the data governance policy. A method that includes carrying out [the following].

24. The method according to claim 23, wherein all data assets in the first data asset set satisfy at least one criterion.

25. Accessing a second data asset in the first data asset set, which is different from the first data asset, Identifying a second user who proves, based on at least one attribute value pair of the second data asset, whether the second data asset satisfies the one or more rules indicated by the first data standard, wherein at least one attribute value pair of the second data asset indicates the second user, Transmitting information about the second data asset and the first data standard to a second computing device associated with the second user and through the communication network, Obtaining a second input from the second computing device and through the communication network that indicates a second proof by the second user regarding whether the second data asset satisfies the one or more rules indicated by the first data standard, Using the second input that provides the second proof, determine whether the data managed by the data processing system conforms to the data governance policy. The method according to claim 23, further comprising:

26. Identifying the first user who proves whether the first data asset satisfies the one or more rules indicated by the first data standard is: Identifying one or more users, represented by one or more attribute value pairs of the first data asset, as responsible for managing the first data asset, Selecting the first user from the aforementioned one or more users The method according to claim 23, including the method described in claim 23.

27. The method according to claim 23, wherein obtaining the first input that demonstrates the first proof includes obtaining the first input through a GUI.

28. The method according to claim 23, further comprising obtaining information from the first computing device and through the communication network that provides evidence of the first proof by the first user regarding whether the first data asset satisfies the one or more rules indicated by the first data standard.

29. The method according to claim 23, further comprising tracking a plurality of proofs relating to whether a data asset in the first data asset set satisfies the one or more rules indicated by the first data standard.

30. The method according to claim 29, further comprising generating a GUI element indicating the extent to which the proof has been completed.

31. To generate a first proof object for the first data asset, The information indicating the first proof is stored in the first proof object. The method according to claim 23, further comprising:

32. The method according to claim 31, further comprising storing the association of the first data standard with the first data asset in the first proof object.

33. The method according to claim 23, wherein the first proof indicates that the first data asset conforms to the first data standard, the first data asset partially conforms to the first data standard, the first data asset is undefined, the first data asset does not conform to the first data standard, or the first data standard is not applicable to the first data asset.

34. The first data asset set is associated with a second data standard of the one or more data standards, and the method is Identifying a first user who can prove, based on one or more attribute value pairs of the first data asset, whether the first data asset satisfies one or more rules indicated by the second data standard, wherein one or more attribute value pairs of the first data asset indicate the first user. Transmitting information about the first data asset and the second data standard to the first computing device associated with the first user and through the communication network, Obtaining a second input from the first computing device and through the communication network that indicates a second proof by the first user regarding whether the first data asset satisfies the one or more rules indicated by the second data standard, Using the second input that provides the second proof, determine whether the data managed by the data processing system conforms to the data governance policy. The method according to claim 23, further comprising:

35. At least one non-temporary computer-readable storage medium storing processor-executable instructions that, when executed by at least one computer hardware processor, cause the at least one computer hardware processor to perform a method for determining whether data managed by a data processing system conforms to a data governance policy, wherein the data processing system stores the data in a plurality of data assets, each containing one or more attribute value pairs, the data governance policy includes one or more data standards, each indicating one or more rules that a data asset must satisfy in order to conform to the data standards, each of the one or more data standards associated with one or more sets of data assets, each of the one or more data standards including a first data standard associated with a first set of the one or more sets of data assets, and the method is Accessing a first data asset from the first data asset set associated with the first data standard, Identifying a first user who, based on one or more attribute value pairs of the first data asset, proves whether the first data asset satisfies one or more rules indicated by the first data standard, wherein one or more attribute value pairs of the first data asset indicate the first user. Transmitting information about the first data asset and the first data standard to a first computing device associated with the first user and via a communication network, Obtaining a first input from the first computing device and through the communication network that represents a first proof by the first user regarding whether the first data asset satisfies one or more rules indicated by the first data standard, Using the first input that provides the first proof, determine whether the data managed by the data processing system conforms to the data governance policy. A non-temporary computer-readable storage medium including at least one such medium.

36. A system for determining whether data managed by a data processing system conforms to a data governance policy, wherein the data processing system stores the data in a plurality of data assets, each containing one or more attribute value pairs, the data governance policy includes one or more data standards, each indicating one or more rules that a data asset must satisfy in order to conform to the data standards, each of the one or more data standards is associated with one or more sets of data assets, each of the one or more data standards includes a first data standard associated with a first set of data assets of the one or more sets of data assets, and the system, At least one computer hardware processor, When executed by the at least one computer hardware processor, the at least one computer hardware processor, Accessing a first data asset from the first data asset set associated with the first data standard, Identifying a first user who, based on one or more attribute value pairs of the first data asset, proves whether the first data asset satisfies one or more rules indicated by the first data standard, wherein one or more attribute value pairs of the first data asset indicate the first user. Transmitting information about the first data asset and the first data standard to a first computing device associated with the first user and via a communication network, Obtaining a first input from the first computing device and through the communication network that represents a first proof by the first user regarding whether the first data asset satisfies one or more rules indicated by the first data standard, Using the first input that provides the first proof, determine whether the data managed by the data processing system conforms to the data governance policy. A non-temporary computer-readable storage medium that stores instructions for carrying out the action A system that includes this.