Method and system for adaptive data analysis capabilities framework

The framework addresses inefficiencies in traditional audits by using a digitally secured adaptation module to automate data processing and integrate new capabilities, enhancing data analysis and adaptability to changing audit requirements, thus improving audit efficiency and accuracy.

WO2025251141A1PCT designated stage Publication Date: 2025-12-11VIGILANT AI INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CA2025/000012
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-06
Filing Date
2025-06-06
Publication Date
2025-12-11

AI Technical Summary

Technical Problem

Traditional business process audits rely heavily on the general ledger (GL) as the primary source of truth, which is limiting and often contains errors, leading to inefficient and costly audits due to incomplete data collection and manual processes, exacerbated by the exponential growth of data and evolving regulatory requirements.

Method used

A framework for data analysis that includes a digitally secured adaptation module (SAM) for installing within a data analysis system, utilizing natural language processing and asymmetric encryption to ensure data integrity and adaptability, enabling automated data processing and integration of new capabilities through a capability matrix.

Benefits of technology

This framework enhances data analysis by providing accurate insights into financial situations, adapting to changing audit requirements, and automating data processing, reducing manual effort and costs, while ensuring data security and integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CA2025000012_11122025_PF_FP_ABST
    Figure CA2025000012_11122025_PF_FP_ABST
Patent Text Reader

Abstract

A method is disclosed for analysing a data set to resolve a truth. The system utilized in this analysis is designed to grow and scale with the demands of their users. Similarly, the framework platform adapts and includes new capabilities as needs and requirements evolve. The system supports changes and evolution without requiring technologists to modify the platform for each change.
Need to check novelty before this filing date? Find Prior Art

Description

Method and System for Adaptive Data Analysis Capabilities FrameworkFIELD OF THE INVENTION

[0001] The invention relates to data analysis and more particularly to a framework for applied artificial intelligence and machine learning solutions in business process analysis and audits.BACKGROUND

[0002] Traditional business process audits are based on the premise that the general ledger (GL) is the primary source of truth. In a typical enterprise this is not problematic, though it is somewhat limiting. When it comes to a corporation, the general ledger and its supporting financial systems represent 20% of the overall data, relating to the processes. This leaves roughly 80% of the overall data untapped as a source of truth or insight. It should be noted that even the 20% within the general ledger is not always guaranteed to be error-free.

[0003] Consider the following situation, the GL is being updated at month-end. In the massive rush of month-end, a few errors occur, some of the input data is misinterpreted - input data gets corrupted in the GL and a line or two from the table representing a sub-ledger gets deleted with no one aware of the issues. Six months later, an audit is in process. The corrupted GL is deemed the primary source of truth and the audit proceeds. The auditors may or may not discover the errors introduced earlier on, or they may actually go in search of the corroborating documents supporting the errors and waste significant time and cost searching for evidence that does not exist. When the missing entries are not detected, it might be problematic or even catastrophic.

[0004] Occasionally, errors such as those described above are simple and are detected or resolved with minimal effort. However, in many cases with respect to ledger audits no leeway is allowed without incurring reportable issues. Worse yet is when there are multiple errors concerning a single transaction. These become extremely difficult to detect and resolve.|005] To further exacerbate these challenges, the rate at which these businesses are producing data, ledger transactions and supporting documentation alike Is growing at an almost exponential rate. At the same time as the amount of data to be analysed is growing, regulatory and governance requirements are rapidly changing and evolving in an effort to maintain high-quality analytics and audits. Therefore, the scale and breadth of data and the types of tests, analyses, and audits on that data are a moving target, demanding analyses of increasing complexity and efficiency.|006] It would be advantageous to provide an improved view of facts, events, an accurate ledger and subledgers, and supporting documentation, allowing stronger insights into the financial situation of the organization. Further, it would be advantageous to provide a means of gaining these stronger insights in a manner that evolves and adapts to the rapidly changing analytical landscape and audit requirements in a timely manner.SUMMARY OF EMBODIMENTS[007 J In accordance with embodiments of the invention there is provided a method comprising: defining an action; and generating a digitally secured adaptation module (SAM) based on the defined action, the digitally secured adaptation module (SAM) for installation within a framework for data analysis, the SAM secured against modification.

[0008] In an embodiment the action is defined using natural language processing.

[0009] In an embodiment the action is defined by performing the action digitally within a system and saving steps involved in performing the action.

[0010] In accordance with embodiments of the invention there is provided a method comprising: providing a digitally secured adaptation module (SAM); verifying the digitally SAM against tampering; installing the digitally SAM within a framework, the framework verifying a security of the digitally SAM to establish permission to install same; and executing data analysis functions within the framework, the data analysis functions having been installed from the digitally secured SAM.

[0011] In accordance with embodiments of the invention there is provided a method comprising: providing a first dataset for audit; modeling a process reflected by the supporting documents to produce a modeled process; building a digital workflow for an instance of the modeled process; and saving the digital workflow for future execution.

[0012] In some embodiments the method comprises: providing a digitally secured adaptation module (SAM); verifying the digitally SAM against tampering; verifying a security of the digitally SAM to establish permission to install same; when permission is established, installing the digitally SAM within the digital model,; and executing data analysis functions within the digital model, the data analysis functions having been installed from the digitally SAM.

[0013] in some embodiments the digitally SAM is secured with a public key of a framework in which it is to be executed.|0014| In some embodiments the digitally SAM is secured with a private key of a service provider by whom it is provided.|0015] In some embodiments the SAM modifies a function present within the model.

[0016] In some embodiments the SAM adds a new function other than present within the model.|0017] In accordance with embodiments of the invention there is provided a method comprising: providing a first framework comprising: data, models, and functionality; receiving a secured adaptation module (SAM); verifying the SAM to establish integrity thereof; when the integrity of the SAM is verified, decrypting the SAM, unbundling the SAM into capability matrix components: data, models, and functionality, and installing the data, models, and functionality within the first framework to produce a changed first framework.

[0018] In some embodiments access to the first framework is via a browser.|0019] In some embodiments a SAM is decrypted using one of a private key of the framework and a public key of a trusted service provider.J0020] In accordance with embodiments of the invention there is provided a method comprising: providing a first framework comprising: a capability matrix; receiving a secured adaptation module (SAM); verifying the SAM to establish integrity thereof; when the integrity of the SAM is verified, decrypting the SAM, unbundling the SAM into capability matrix components: the capability matrix, and installing the capability matrix within the first framework to produce a changed first framework.|0021 J In accordance with embodiments of the invention there is provided a method comprising: providing a data set comprising data from various sources and stored in various data stores; using the data set, performing an audit of a ground truth data file; based on a process for the audit and data accessed, building a first instance of a model for auditing the dataset; forming a first framework including the first instance of the model and comprising: data, at least a model, and functionality; and storing the first framework for subsequent execution.

[0022] in accordance with an embodiment, there is provided a method comprising; receiving a secured adaptation module (SAM); verifying the SAM to establish integrity thereof; when the integrity of the SAM is verified, decrypting the SAM, unbundling the SAM into capability matrix components: data, models, and functionality, and installing the data, models, and functionality within the first framework to produce a changed first framework.BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Exemplary embodiments of the invention will now be described in conjunction with the following drawings, wherein similar reference numerals denote similar elements throughout the several views, in which:

[0024] Figure 1 illustrates a simplified methodology of a traditional business process audit according to prior art.|0025] Figure 2 is an illustration of a system to provide a platform for enhanced analytics and audit.|0026] Figure 3 illustrates a simplified methodology for enhanced analytics and audit on the platform.[0027J Figure 4 illustrates a simplified methodology to provide for changing capabilities in the audit and analytics platform.

[0028] Figure 5 illustrates a simplified methodology for the automated generation and adoption of new capabilities for the analytics and audit platform without the requirement of skilled technologists.

[0029] Figure 6 illustrates a simplified methodology for the automated inclusion of externally driven capabilities, such as LLM (large language model) or Generative Al (artificial intelligence) linked from afar but provided by and available within as a capability of the audit and analytics platform.DETAILED DESCRIPTION OF EMBODIMENTS|0030] The following description is presented to enable a person skilled in the art to make and use the invention and is provided in the context of a particular application and its requirements. Various modifications to the disclosed embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments and applications without departing from the scope of the invention. Thus, the present invention is not intended to be limited to the embodiments disclosed but is to be accorded the widest scope consistent with the principles and features disclosed herein.Definitions:

[0031] Data Element: Data elements are meaningful segments of information logically identifiable but not necessarily constrained by a one-to-one relationship to a traditional file. It is possible for a data element to be an entire file, such as an invoice. However, at times data elements are notable sub-segments within a file. For example,an email archive file is a single file. It could be considered a data element. Similarly, that same email archive may contain many data elements in the form of emails some of which in turn each may contain external data elements. Where they are embedded within a file or container, a data element is optionally referred to as a data field. Similarly, some of the emails include attachments that could be considered data elements. The aforementioned attachments could for example be a spreadsheet. In such spreadsheets, the data constructs found within, tables, rows, columns, individual cells and the like are optionally considered data elements in their own right.

[0032] Data-driven Process Model (DDPM): a means of defining a series of steps forming tasks based on the changes in state or transformation that data goes through at each step. It is a process modelled around a known set of document classes where at each step one or more of these document classes is associated with the process. Specifically, the documents are created, modified, touched, read, altered, consumed, destroyed, or have some other direct or indirect interaction with a task in question.|0033] Modeled Business Process: is a means of representing activities which are undertaken by an enterprise in their normal course of business operations. It includes a representation of the flow of a process outlining steps taken in executing the process. A modeled business process includes a representation of the order of these steps, their dependencies, and their interrelationships. It also includes modeling and representation of data associated with these steps. This includes, the data and documents created, consumed, referenced, updated, or destroyed for each step in the process or involved in the process. A completely modeled business process identifies and includes representation of the informational segments and data fields within each of the documents associated with the business flow.

[0034] Data-driven Business Process Model (DDBPM): is a DDPM where the process being modeled is directly associated with a known business task or audit flow, e.g., a sales cycle.

[0035] Data, Structured: is the class of data that represents information in a known, pre-definable format, that optionally includes organized and repeating structuraldefinition. A classic example of structured data format is tabular in nature, with the data arranged in rows and columns such as in a spreadsheet.|0036] Data, Semi-structured; is actually a sub-class of unstructured data. It is data that is not necessarily pre-definablethat is optionally represented as a loosely defined set of tabular (rows and columns) data. Such data is optionally in the form of a sparsely populated table where some rows or columns only exist to satisfy a single or few instances of an otherwise more tightly defined table. An example of a semistructured file is a Microsoft Excel file that contains worksheets and tables but also contains data that is not tabular in nature.

[0037] Data, Unstructured: the class of data that does not readily map itself into known, i.e., structured configurations. It is typically non-tabular in nature and spans a wide breadth of data generated by an enterprise. Examples of unstructured data include: binary files, textual or scanned documents and images, multi-media files, including audio and / or video clips and files, drawings, photos, and many more.(0038] Data Lake: is a data storage mechanism that is able to include and house multiple forms of data including both structured and unstructured data.

[0039] Data Curation: is the activity of cleaning, organizing, and arranging stored data, often in a repository, in a manner that enables sought-after data to be found and retrieved.

[0040] Data Swamp: is a failed data lake that lacks data curation and thereby lacks the ability to find and retrieve sought-after data.

[0041] Supradata: supradata is a combination of at least some metadata regarding a data element. In addition to traditional metadata, it includes actions, transformations, and relationship elements that are stored in a time varying fashion such that metadata is often appended to previous metadata instead of overwriting same to form a present, historical, and continuously deepening metadata data set. In addition, supradata includes context regarding the data element. The context may give reference to the origins of the data, the purpose of the data, or the contents ofthe data. Some context also includes actions on, interactions with, associations, and relationships with other data elements within a data set. In an example, a PDF contract file includes a link to an email to which it was attached when it was delivered, which in turn contains a link to an email archive from which the email was extracted all within the current or some other external data set. The supradata relating to the PDF contract optionally also includes links to previous versions of the PDF contract or to changes to the PDF contract.

[0042] Asymmetric Encryption: is a form of encryption with two keys. The public key is used to encrypt the data element / file to be protected. The private key is used to decrypt the encrypted entity. It is also known as public key encryption.

[0043] Application Modules: are applications or services, either browser or webbased, that perform one or more tasks for a user utilizing capabilities, alone or in combination, provided by the solution framework.[0044| Futurization Modules: are packaged capabilities - adaptations - that are optionally added to the framework’s execution set and the framework elements - modules - that enable integration and execution of the new capabilities.[0045| Adaptation Definition Specification: is a human-readable description of a capability to be added to a framework's execution set. It describes the data, functional, and configuration model components of the capability, as well as its interfaces.

[0046] Adaptation Integration Module: is the framework component that ingests new capabilities, adding them to the existing base capability matrix, and making them available for application modules to execute.

[0047] Capability Matrix: is the collective set of operations available for execution from within the framework. It includes the base capability matrix and any additional capability packages that have been added to the framework. It can also include linkages to external tools and functions that are accessible directly through the capability matrix.|0048] Capabilities Service Module: is the framework component that executes capabilities drawn from the capability matrix.|0049] Capabilities Control Module: is the framework component that provides oversight on the Capabilities Service Module. It is responsible for operations monitoring, administration, management, instrumentation, and performance. Operations management includes but is not limited to starting and stopping tasks, suspending, and resuming execution, and overall module operations.(0050] External Capabilities Matrix: is a capabilities matrix where the actual functional capabilities are drawn from external sources, referenced from and utilized within the platform but utilized from functionality operating elsewhere. For example, an LLM (Large Language Model) solution for deconstructing an image into the data elements of its contents.

[0051] A financial audit is a mechanism where an organization validates or tries to validate that it is carrying out business with a financially valid methodology. The financial audit evaluates the business processes involved in the day-to-day operations of the organization to ensure they are structured, controlled, and executed correctly in support of the successful achievement of the business and financial goals of the organization. A financial audit ensures such operations are carried out within the boundaries established by internal risk management and governance and external law and regulation. It establishes the trustworthiness of the organization's financials, validating their business processes and verifying the organization's books.

[0052] In the world of enterprise finance and financial audit in particular, the general ledger (GL) is considered the primary source of truth for a corporation. This means that any financial audit of the corporation begins with and is based on the GLand its corresponding sub-ledgers. They are considered the fact-based, official financial corporate record. This is a proven and widely accepted contemporary business norm.

[0053] Audits, therefore, become predominantly verifications of the GL and its subledgers, in the context of business processes of the enterprise. Several other factors are also considered such as business goals and operations, risk profile, governance,and regulatory environment. Based on these criteria, supporting documentation and evidence is gathered to determine the veracity of or issues with ledgers under review.|0054| Several challenges influence the ability to execute an audit for an organization. The primary areas of these challenges are data management and the regulatory environment.|0055] In data management challenges stem from the enormous growth in data volume and in the breadth of sources contributing this data across the corporation, both inside and outside. Beyond the growth in data volume, the sources of supporting, evidentiary, or meaningfully associated documents continues to grow in most organizations. As more and more enterprises pass through their own digital transformations, more and more sources of electronic or manual documents, which may be relevant to a given process or set of transactions, grows. As a direct result, the varying degrees of association between supporting documentation and transactions tends to become more complex overtime. With a growth in volume and complexity, ensuring complete coverage of relevant materials becomes increasingly problematic.[0056| In the regulatory environment the issues focus around both internal and external issues. Internally, there is greater pressure to analyze and audit the larger portions of these larger data sets with greater efficiency, taking less time and effort to achieve broader coverage. This allows greater data collection without substantial increase in the cost of analysis. From an external perspective, the focus is on correctness and completeness. To that end, the regulatory environment is continuously growing, shifting, and changing adding new constraints and requirements, new tests, new laws, and new analytics in an effort to ensure accuracy, instill confidence, and maintain the legitimacy of their analysis.(0057| It would be advantageous to address one or more of the challenges outlined above. Various embodiments are detailed below with a focus on audit. However, one of skilled-in-the-art will see how to apply the methods to other areas of enterprise and organizational, analysis, operations and control.|0058] Referring to Figure 1, what is shown is a simplified methodology of a traditional business process audit This is the current state of the art, offered as a common frame of reference for the embodiments. The audit begins at 100. Historically, a large part of the effort in such audits, is focused on data collection, starting at 110. Often, data collection is a large amount of effort and still results in incomplete documentation and, as a step, is therefore returned to during the processing of the data numerous times to try to find missing documents. Another heavy lifting portion of the audit is during the individual audit tests, at 140. Finding the appropriate associated documents, as at 142, is predominantly a manual process performed by the audit team. As shown at 143, it may also entail going back to the client organization to request and garner additional information - external data collection. Such manual processes have limitations and are subject to human error, accidental omission, and other concerns. The volume of information continuously being generated by organizations is, in most cases, increasing, exacerbating the problem. This makes for an intractable manual data coverage challenge.|0059] To address this challenge the current state of the art takes two forms, enforcement, and discovery. In the enforcement model, the key supporting documents are expected to be loaded into a secure repository through the same tools which manage the financial books, statements, and the GL; effectively bundling together the document collection with the business processes. The second form, discovery, is essentially the manual process describe above.

[0060] It would be advantageous to have the means whereby the business processes being audited, and their supporting documentation are consolidated in a manner that provides information completeness and reflects reality but remains separate from the GL, thereby providing better evidence to compare with the GL from an audit perspective.

[0061] In Figure 1 is shown the complexity of the audit process, specifically in the face of incomplete data gathering. Returning repeatedly to step 110 or even steps 102 and 103, results in a very inefficient and time-consuming audit process.|0062] Referring to Figure 2, what is shown is a system for resolving some data management issues of contemporary audits and analyses. Figure 2a illustrates the basic reference framework required for this novel solution. To facilitate the broadest possible data capture across the organization, rather than dedicated applications or custom clients installed in a variety of computational devices, a browser-based solution is presented for the user-facing elements of the solution both for auditors and analysts, as shown at 211, and for administrative access as shows at 212 and 213. As identified above, the high growth change, both in business processes and the means to capture, record, and document them may result in a wide variety of legacy or, as digital transformations occur, new applications which give the user access to the data management solution, as shown at 214.|0063] Each of these user or automated service facing modules, collectively called application modules, gains access to the data management system through a set of APIs, algorithmic programming interfaces, which are external to the application modules and present the external access to the data management system. These APIs may take the form of many well-known and established web or internet-based protocols for external interfaces and web services, including but not limited to: RPC (remote procedure calls), REST (Representational State Transfer), Web sockets, textbased serialization protocols such as xml (extensible markup language), html (hypertext mark-up language), YAML (yet another markup language), SGML (standard generalized, markup language), JSON (javascript object notation), and others. They all represent access to web services and data transfer across a computer network, collectively identified as the External API at 210. This API provides an abstraction and interface layer to decouple application modules from the data management services while providing direct access to their benefits.

[0064] The services exposed and offered by the External API at 210 and provided by the data management platform are offered at 200. This set of web services is actually a collection of loosely coupled closed services bundled into a unified closed services platform or framework. They are loosely coupled because they have no requirement to reside on the same physical platform or device, so long as they share networkconnectivity. They are a closed services bundle because they share a secure proprietary protocol which ties them functionally togetherthat is direct point-to-point and encrypted ensuring secured and private communications. Individually, the service modules offer, task execution services as at 202, data management services as at 203 and operations and management services as at 204. Together these services offer the capabilities to manage the data and perform various tasks and operations on the data accessed through the External API 210. Each of these services is optionally supported by a multiplicity of service modules working together to scale the service offering.

[0065] All of these services have controlled and protected access to the actual data storage repository, which runs underneath and behind this framework as illustrated at 201. This storage repository offers storage space and file management to store the data and any derivations thereof. It is any combination of cloud-based storage, onpremises storage, or direct attached storage.

[0066] This baseline framework as depicted in Figure 2a, reflects a minimalist view of what is needed to address the present-day data volume and variety of challenges for data solutions. Often, more resources are used. With a few additions, as depicted in Figure 2b, the solution of Figure 2a becomes a system capable of expanding beyond today's requirements for addressing data growth, data variety, and regulatory churn challenges of the future.

[0067] Referring to Figure 2b, what is shown is an architecture for a system enhanced to meet the growth and adaptation needs of contemporary and future audit and analysis solutions. As per prior art solutions, the end-user applications optionally take one or more of several forms, including browser-based tools such as the audit tool at 231 and the administration tool at 232. Alternatively, direct, command-line-based tools such as administration tool at 233 are used. Collectively, end user applications are referred to as application modules. Each of these is driven with a controlled external interface to the operational platform capabilities as shown at 230. This external interface supports a breadth of web-based remote execution and communication protocols.|0068] However, to grow and adapt to the contemporary and future requirements, the external interface must be designed to support next-generational tools and applications, including but not limited to Al (artificial intelligence), ML (machine learning), and / or LLM (large language model)-based tools and solutions, as shown at 235. Such tools are often data and situation driven and do not work effectively with traditionally, tightly specified, interfaces. To support this class of tools and solutions, the external interface at 230 includes an IBI (intention-based interface). Such interfaces for example are driven through direct interaction / remote invocation or by asynchronous messaging / message bus interfaces where messages are shared between components interested in same topics or capabilities. However, resolution of a request posted to one of these topics of interest / areas of concern, is left up to the servicing capabilities of the platform and the services it offers. The external service, tool, or solution puts its requested intent on the IBI and it gets serviced by the Services Platform component(s) which best meet the needs of the intent. The servicing component feeds its results back on the IBI enabling the requestor to learn the result of their test.|0069] To support these enhancements, a closed services platform or framework at 240 incorporates: a fully contextualized and indexed repository (250 / 251), a base capability matrix (260), and an intentions and topics bus (270). These new features add to the traditional approach and position the framework to meet the needs and requirements yet to be encountered. These are still collected together in a loosely coupled architecture that is closed to external parties except through the external interface at 230.(0070] The contextualized repository 250 is an aggregation of data storage technologies including relational databases, linear databases, associative or graph databases, vector databases, purpose-built databases, and ad hoc unstructured data storage. One or more of the storage technologies are used in a given embodiment. Together these databases 251 are integrated into a combined super-set of data storage and management technologies that presents as a unified system known as a supradata repository. The supradata repository supports raw data storage for all datatypes, structured, semi-structured, and unstructured. It has a unified query interface that supports high performant queries aligned with each of the enabling database technologies, e.g., a high-performance relationship query enabled through the graph database of associated objects that are stored and managed through the relational database. It also includes a higher-order contextual and informational component which is maintained for all data elements stored in the repository, known as supradata. Supradata includes, for each item held in the repository, associations, relationships, and interactions with other elements in the repository or beyond, its own origins, genealogies, and ancestry, and its further participation in more complex aggregated data structures. This supradata repository Is capable of auto-curation; indexing and maintaining context on-the-fly, establishing a full repository where data can be sought, found, and retrieved readily through a simple API, a web interface, or a command line.[00711 The capability matrix (260) is a construct of operations and functions for analytics on repository-resident and external data alike. It can include native transformations within the repository or external operations and calculations with the data. Each matrix entry has the opportunity for the inclusion of associated data, modeling, and its primary functionality, its capability. In the services framework platform 240, the base capability matrix or BCM 260 provides the key set of functionalities based on how the system is intended to be used. The BCM contains basic services such as messaging, logging, instrumentation, security, data management and organization.

[0072] The BCM also contains a use-case-targeted set of business logic capabilities. For example, default models for enterprise sales business processes and capabilities to provide audit testing, like the capability to extract data elements from supporting documents and to merge those into tests aligned with the business processes being audited. These also include utilities for merging of extracted information and storing it for further analytics.

[0073] Together the functionality offered by the services framework / platform 240 collectively offer the applications, users, and services the ability to build and maintaina useful, curated and managed data repository and analytics platform which both scales and adapts to the future evolution of its users.

[0074] Referring to Figure 3, what is shown is a methodology for utilizing a contextualized repository and capabilities-based framework to perform enhanced analytics, in this case for audits. The audit team prepares for the audit as they would in the traditional state-of-the-art, interviewing the client, examining the business process(es) to be audited and understanding the flow of business for the time-cycle in question. From this combined process and risk assessment, the audit team can develop the audit plan. This methodology is engaged when the audit team begins to execute their audit plan at 301. Using the system, the team captures and models the process(es) being audited. This modeling, expressed at 310, includes outlining what supporting documentation and what information or data elements from within those documents are needed. With the business process(es) modeled and the supporting documentation identified and modeled, the system is ready for data loading at 320.|0075] The data is loaded interactively or through an algorithmic program interface. Upon loading, data is selected for document classification and processing based on the auditor's input specifications. Either by manual invocation or automation (autocuration), data is processed by the system identifying key evidence and process data elements, extracting them based on the modeling, and loading both raw and processed data into the repository.

[0076] With the raw and pre-processed data loaded, an instance of the business model, based on the loaded supporting documents and possibly including (if needed) the source ledger or spreadsheet that contains the originally captured business process being audited is created at 330. In building this model, not necessarily all of the documentation loaded into the repository is needed. As outlined beginning at 340, for each document class in the business process model, the documents relevant to this particular instance are selected. The context of the data and its interrelationships with other data elements, available at loading and curated as subsequent data and relationship data is loaded and processed, enables search based on relevance at 341. The relevant data is used to generate an associated data classtable for the business model in question at 342 and 343. This methodology repeats until relevant documents have been selected for each relevant document class in the business process.|0077| The methodology continues at 350, where the business process model instance is compared to the source ledger, which reflects how the enterprise client had executed their business process. For example, the source ledger is the sales subledger of the general ledger (GL) where the selected sales transactions are under consideration for the audit. Using the business process model instance built and comparing it to the source ledger for the selected transactions under audit, the business process executed by the company is compared and contrasted to relevant supporting data, 351. in this example, captured sales transactions are compared to corresponding service orders, sales invoices, and payment receipts. With the modelbased approach, any test or series of tests which is / are required to verify the process or validate the transactions is designed and executed by the analyst / auditor directly from the repository-based model. This continues with further tests being defined and executed, at 351, until the analyst is satisfied that the transaction is confirmed or denied by the supporting documents, at 352. These results are then catalogued and annotated by the analyst, at 360, and summarized and rolled up at 370.

[0078] The audit team builds as many business process instances from the repository as needed. The novel auto-curation and the full context it develops result in more efficient document selection with each iteration. By growing in efficiency and by having flexibility to develop and reuse previously beneficial tests of the data, the system is enabled to handle the load and demand of today and account for growth and some changes in requirements of tomorrow.

[0079] It is further advantageous to use automation in both pre-processing and reprocessing the data and the tests. For example, a test suite is developed to be automated with each audit in turn on a quarterly basis, further accelerating the analysis or audit.|0080| As previously articulated, the audit and analysis environment is continuously changing with high growth and demand for change. Therefore, it is advantageous to have a system that grows, adapts, and evolves with these changes and demands. While the aforementioned solution facilitates both scale and moderate change, it does not, on its own, address major changes in the audit and analysis requirements. More significant changes including but not limited to, regulatory changes, governance changes or digital transformations of the participants, require greater flexibility from the audit / analysis framework and platform. It would be advantageous to have an audit platform capable of change and adaptation without overhaul or replacement.

[0081] Referring to Figure 4a, what is shown is a system that supports in-situ augmentation, updates, and evolution to meet demands for change and adaptation. Based on the system illustrated in Figure 2, the system in Figure 4a extends the platform, now including support for dynamic capabilities that self -integrate with the platform. With support for dynamic capabilities matrix updates and augmentation, the services offered by the framework, the platform, at 400 is modifiable and enhanced as requirements demand.

[0082] To support dynamic capabilities, the system provides a mechanism for secure loading, verification, and integration of new / updated capabilities matrices. As with the base capabilities matrix illustrated in Figure 2b, at 260, a capability matrix has three primary components: the Adaptation Definition Specification, the functions that implement the matrix, and the models that the matrix uses in its execution. In addition, a capabilities matrix that is outside the base matrix from the framework optionally carries with it a data component.|0083] Referring again to Figure 4a, at 430, based on a request outlined by a user, an analyst / auditor, a technician skilled-in-the-art, creates a new capabilities matrix that meets the auditor's needs and expectations. The resulting capability matrix, at 431, with its adaptation definition specification, that defines the capabilities, its functions, that implement the capabilities, the models that define the context and configuration of the capabilities, and the supporting data that enables the capabilities, are anintegrated bundle. This is the bundle, known in transit as a SAM (secured adaptation module), that is eventually integrated to platform / framework 400.|0084] For example, a technician relies on Al to assist in converting tasks as outlined into capabilities for implementing the audit process within the system. In an embodiment, the technician relies on an LLM. The LLM takes natural language and converts it to capabilities within a capability matrix. The technician then verifies the capabilities and tests the capabilities to verify their performance. Once verified, the capabilities are exported into a bundle, in the form of a SAM.|0085] Steps are taken to ensure only approved capabilities matrices are integrated into each system. The steps include extra security measures applied. In the example of Figure 4a, an asymmetric key system is employed to ensure only approved submitters send installable capability matrix bundles. This mechanism also offers tamper protection for legitimate bundles. While this public / private key solution is effective, it is obvious to those skilled-in-the-art that other similar mechanisms may be employed to ensure authorization and integrity of in-bound bundles. The resulting protected SAM 433 is delivered over a public network through an external API / IPI of the system at 410 to a receiving service forming part of the system.|0086] Alternatively, the SAM is secured locally and retrieved locally for installation when indicated. In this alternative, for example, a technician has designed a SAM for use with a particular client or with a particular group of clients and that SAM is not intended for broad distribution. An example of such a SAM is a capability matrix for extracting customers who might spend more in the future. Such a SAM is formable based on financial and other data within the system, but is separate from an audit process and is potentially a trade secret.

[0087] Once authenticated and decrypted, the SAM is ready as a new capability matrix, at 440, to be deployed into the system. Deployment entails inclusion in the operations management 405 and task execution services 404 subsystems of the closed framework when indicated. Optionally, the SAM is deployed only when applicable to a particular operation, customer, or type of audit. Alternatively, theseadaptions to the existing services are enabled by futurization modules: the Capability Control Module 406 and the Capability Services Module 407, which together act as the library and directory for the capabilities offered by the system. Once deployed the services framework / platform now includes the new capabilities as they were requested and provided.

[0088] Referring to Figure 4b, the methodology is outlined for using the adaptive framework to securely augment the capabilities of the existing platform. It relies upon someone(s) skilled-in-the-arts of analysis / audit and building capabilities matrices. These persons(s) not only design and build a new capabilities module 471; they also build an application to use these new capabilities 490.

[0089] Referring to the methodology of Figure 4b, building of the new capability matrix kicks off the methodology at 451. Once built, security and transport mechanisms are employed at 452 to package and send module 473 safely to framework 460 via the External API / IPI 466. The new module 4521 is received, its integrity verified and decrypted back to its constituent components at 4522 including a decrypted SAM. Then the decrypted SAM is integrated into the framework at 4523. The futurization modules ensure integration of the new capabilities through the framework. They appear alongside the original basic capabilities 464. New added capabilities 480 and the original capabilities 464 are executed by the same methodology and utilities built into the API, at 4532; the user of the API / IPI need only refer to the new features. For example, perhaps the new capability added was to sort by document type where previously only sort by name was known. In the IPI, the original intent to be invoked at 4532 might have been either "sort" or "sort by name". The same invocation is used but the reference is "sort by doc type" once the new capability is activated.

[0090] Activation of a new capability takes two possible forms, direct activation by the framework or remote activation. The direct activation is explicitly launched by an administrator of the system through the capability management and execution module 465. Remote activation is achieved by invoking an API / IPI call, at 466, to initialize the new capability. After either successful activation, at 4533, the newcapabilities implemented by the SAM are available at 455. Thereafter, any application using the new capabilities, such as an application written by the originators of the new capabilities at 490 invokes the new capabilities as any of the original capabilities were utilized.|0091| It is advantageous to have a system that adapts and evolves with changing needs of its application, users, and environment.[0092| There is a demand for rapid growth and change, as audit issues and known mechanisms for defeating audits change as newly discovered issues become known. It is advantageous to be able to build a system whereby someone skilled-! n-the-art of building adaptive capabilities matrices is not required to build and integrate new functionality. This often accelerates and lowers the cost of such adaptations in a more timely and impactful manner for the analysts requiring new capabilities. It also allows for expansion of an audit system to other purposes by people with relevant expertise - budgeting, marketing, and sales as examples.[0093J Referring to Figure 5a, what is shown is a system whereby a user skil led-in-the- art of their analyses, but not necessarily technical, is enabled to create adaptive capabilities to add to and integrate with their analytical framework. Al-assisted or auto-generated new capabilities as specified by the user are generated. In Figure 5a, a Generative Al tool takes the requirements from the analyst at 530 and creates the capabilities matrix module 531. Then, given the proper security key 572, the Generative Al tool bundles it for secure delivery in the form of a SAM. The security key is the public key. Alternatively, a private key is used to secure the SAM as an indication of an origin of the SAM. The SAM is delivered across the public network via the External API / IPI at 566. The rest of the progression of the system behaves as outlined for Figure 4.

[0094] Similarly, referring to Figure 5b, what is shown is the methodology whereby the system shown in Figure 5a operates. The methodology closely reflects the methodology of Figure 4b. The differences are in the creation and packaging of the Adaptation Definition Specification 571 and its components. The Generative Alsystem, trained on the External API / IPI and aware of the adaptive capabilities functionality offered by the framework, takes analyst's requests, for example through a selection methodology or alternatively using natural language, and builds out the pieces of functionality for the new capability.|0095] By way of example for Figure 5b, consider the situation where an auditor is faced with changes to both regulatory and internal governance requirements for audits they are expected to perform. The new regulations introduce a previously never-executed test requirement, documented as IFRS - x2345, which in turn references a new accounting principle defined in GAAP (generally accepted accounting principles) - y6789. In addition, because the audited company has annual revenues in excess of $100M US, the firm that the auditor works for requires them to over-sample the audited transactions by a factor 25%. In the example, the auditor interacts with the Generative Al system / interface and requests it to build the new capability. The interaction / conversation progresses along the lines of:"GenAI - "How Can I Help?"»» Please build a new capability, in the form of an adaptation module, for my audit tool that includes the latest editions of IFRS-x2345 and GAAP-y6789. In this new capability, include the model I have defined for the Sales Business Process for our client. Also please verify the annual revenue of our client. If this revenue exceeds $100M USD annually, please increase the audit sampling rate to 125% of the original number of sample transactions specified in my current audit.GenAI - "How Can I Help?" » I am working on your request ....» still working ...» still working ...» To complete your request I have a few questions. Would you like to continue? » yes» First question: Did you have any additional models that are relevant to these new capabilities?» no» Second question: Did you want to include any supporting data for these capabilities?» yes» What data would you like to add?» Please make the governance over-sampling settings variable. Set the initial defaults to be: Cutoff revenue = $100,000,000 USD; Oversampling rate -25%.» Any additional data?» no» Third question: Would you like to have this new capability bundled and delivered for Integration with your audit framework?» yes» Do you have an encryption key to secure it for delivery?» yes. Please use the file: c:\keys\my_framework_publickey.key.» Working ...» Working ...» Your new capability is ready. It is named: "newjrules". It is bundled for delivery as a Secure Adaptation Module, a SAM. Would you like to have It delivered now and integrated?» Yes» Please enter the target destination of the framework to be augmented with the new capability.» https: / / my framework external portal» Thank you. Working on the request...» working...» SAM delivered to https: / / mv framework external portal. Awaiting acknowledgement of acceptance....» ... still waiting» Your new capability has been accepted and installed. To activate "new rules," issue the following command at the portal: https: / / mv framework external portal?control=activate;capabilitv=new rules» CompleteGenAI - "How Can I Help?" »» Please build a web-based SPA (single page application) that takes input data from my document sets, in my curated data lake, and analyze it based on the new capabilities recently added for IFRS-x2345 and GAAP-y6789. Have the application raise a notification if the client's revenue exceeds the oversampling threshold of $100M. if so notified, an additional 25% more samples will be added to the working set at the repository here.

[0096] As instructed, the Generative Al builds the new capabilities matrix at 571 and packages it as a SAM at 573. It then delivers the SAM to the External API / IPI 566 with the IPI request to augment the tool capabilities with the SAM. The Capability Management service within the framework 565 ingests the generated SAM, verifies it, and adopts its capabilities matrix.|0097] In parallel, the Generative Al builds and deploys the web-based SPA that gives the analyst access to these capabilities. Finally, the new capabilities initiation code is invoked through the API at 5532, for example by the SPA on startup or as an independent command to the interface. Thereafter, the SPA has access to data and capabilities as though they were within the original tool all along.(0098] As a result of this system and method, a non-technical analyst can keep their tool up to date with a high degree of change and demands on their analytics. It is noteworthy, that if the Al cannot understand the new rule, the analyst likely understands the rule well enough to explain its content and application.(0099] The interaction between the Generative Al and the auditor establishing the new capabilities optionally takes other forms and implementations yet achieves same end results.100100] As changes accelerate in the analyst's world, so too will there be changes and advancements in capabilities that are offered by third parties including but not limited to upgrades, SAMs, improved hardware, improved storage architectures, and improved integrations. Therefore, it would be advantageous to be able to reference and utilize such third-party capabilities as an augmentation of the framework.|00101] Referring now to Figure 6, what is shown is a system whereby the analysis framework incorporates functionality from third party tools and services, offering and presenting them as additional capabilities available from the framework. Such incorporation is initiated in the same manner as the Generative Al generation of new capabilities outlined in Figure 5. Alternatively, it is initiated differently. The auditor / analyst / user drives the addition of newly discovered services / capabilities. The driving individual need not be technical, they instruct the Generative Al to include the external tool / service's capabilities when they specify the adaptation for their framework. As in Figures 4 and 5, the augmentation or adaptation of the capabilities of the framework are user driven; alternatively, they are driven by the system administrators or framework developers.|00102] In this system, there is an expectation that the external tool or service is reached remotely, e.g., through a web-based API or invocation. Where credentials are required, the framework system queries for them when a connection is made. Alternatively, the credentials are pre-configured in the adaptation definition specification. The new capability is added to the existing base capabilities matrix just as user-driven new capabilities are added in Figures 4 and 5. The new capability is represented as another atomic function that is invoked by the task execution services as illustrated at 640. When a request comes in through the external interface, the task execution services interpret the request and its intention. When the framework interpretation works to verify the externally added capabilities, the external Interface references are seamlessly and asynchronously invoked by the task execution services. The results of the invoked external services are likewise channeled back through the framework and presented to the requestor as if they had come from within. Alternatively, external services are updated and executed without the requestor's knowledge, for example when the increased sampling for "best practices" is determined to be 30%, the increase merely occurs and the requestor trusts in the system to manage that knowledge or verifies it for themselves. The degree of this transparency and visibility to the new capability being external is configurable by the system administrators and the users integrating the new / enhanced capability. As a framework capability, the external service has access to a controlled subset of the framework utilities. The subset of internal services available is managed to keep security within the framework consistent.

[0103] It should be noted that the external connections are often bi-directional, linking external services as capabilities to be executed, getting results and linking data stored in the repository, making it accessible to the outside service with strict adherence to authentication and authorisation. Alternatively, external connections are more limited in their connections.

[0104] An example of how this system works from an end-user perspective is as follows. Consider the analyst using the IBI (intention-based interface) from the framework's external interface. The IBI requests might take the form of:"Take the results of my analysis and deliver them directly to my favorite third-party working paper tool."Or"Take my current working paper, built and maintained by my favorite third-party working paper vendor and use it as a new basis for data for a new set of analytics, e.g., test of details or a cut-off test "

[0105] Such internal tools relying on external services optionally include traditional tools or Generative Al and LLM tools, either of them bi-directional.

[0106] As yet another example, an analyst of a first organisation sets up a one directional authenticated link to a set of external connections for use by external third parties. Third parties are, using the external connection, able to verify, retrieve, and view their interactions with the first organisation. During an audit, an auditor verifies all payments to the first organisation against the GL, the documentation of the organisation being audited and the external connection to the first organisation. When all three align, the audit of those transactions is complete. When they do not, the auditor sorts out the issue between the three datasets.

[0107] In some embodiments, a SAM upgrades a capability matrix for a system for use in specific situations such that different SAMs are installed for different situations. In another embodiment, some SAM capabilities are incompatible with others, for example they implement a same capability differently with different results, and installation of those SAMs results in a query at execution to select the SAM installation for a session. Alternatively, when SAM capabilities are incompatible with others, SAM installation is based on a type of analysis, a type of client, or a specific client.

[0108] Numerous other embodiments may be envisaged without departing from the scope of the invention.

Claims

ClaimsWhat is claimed is:

1. A method comprising: providing a data analysis process including therein an artificial intelligence (Al) component trained on pre-existing data for analysing data provided thereto; defining an action for analysing data, the action other than an action automatically performed by the data analysis process prior to definition thereof, the defined action for being implemented within the data analysis process absent further training of the Al component thereof; and generating a digitally secured adaptation module (SAM) based on the defined action, the digitally secured adaptation module (SAM) for installation within a framework for data analysis, the SAM secured against modification.

2. A method according to claim 1 wherein the action is defined by defining at least a new capability for resulting in the action, the new capability for addition within a capability matrix of the data analysis process.

3. A method according to claim 1 wherein the SAM is digitally secured with a public key of a private-public key pair.

4. A method according to claim 1 wherein the action is defined by performing the action digitally within a system and saving steps involved in performing the action.

5. A method according to claim 4 comprising: identifying first steps that are one of not performed within the digital analysis process or that are to be performed differently; and determining future steps for forming an action to one of perform the first steps and perform the first steps differently, wherein the SAM is for modifying data analysis processes including the data analysis process to perform the future steps automatically.

6. A method according to claim 5 wherein the future steps are determined based on a failure of the data analysis process to accurately resolve issues.

7. A method according to claim 6 wherein the future steps are determined by an operator of the data analysis process issuing commands to achieve something the data analysis process failed to achieve absent the issued commands, and where the data analysis process achieves what it failed to achieve with the issued commands, the SAM for repeatably programming the data analysis process to perform at least some of the issued commands.

8. A method according to claim 6 wherein the future steps are determined by an operator of the data analysis process issuing commands to achieve something the data analysis process failed to achieve absent the issued commands, and where the data analysis process achieves what it failed to achieve with the issued commands, the SAM for repeatably programming the data analysis process to perform the issued commands.

9. A method according to claim 1 wherein the action is defined using natural language processing and artificial intelligence to convert natural language commands into future steps for performing the action.

10. A method according to claim 9 wherein future steps are determined by an operator of the data analysis process issuing natural language commands to customise the data analysis process, and where similar data analysis processes are customisable relying on a SAM determined based on the natural language commands used to customise die data analysis process.

11. A method according to claim 3 wherein the SAM is decrypted prior to installation thereof.

12. A method according to claim 1 wherein the SAM is digitally secured with a private key of a private-public key pair.

13. A method according to claim 12 wherein the SAM is decrypted prior to installation thereof, the decryption verifying a source of the SAM.

14. A method according to claim 1 comprising determining conflicts between capabilities matrices resulting from installation of two different SAMs and preventing installation of one of the two different SAMs.

15. A method according to claim 14 comprising prompting a user to select which of the two different SAMs to install.

16. A method according to claim 14 wherein one of a task to be performed and a client automatically determines which of the two different SAMs to install.

17. A method comprising: providing a data analysis process including therein an artificial intelligence (Al) component trained on pre-existing data for analysing data provided thereto; installing into the data analysis process a SAM for defining an action for analysing data, the action other than an action automatically performed by the data analysis process prior to installation of the SAM, the defined action for being implemented within the data analysis process absent further training of the Al component thereof.

18. A method according to claim 17 comprising: automatically detecting a conflict between capabilities existing within the data analysis system and to be installed with the SAM to determine conflicting capabilities; and selecting between the conflicting capabilities.

19. A method comprising: defining an action; and generating a digitally secured adaptation module (SAM) based on the defined action, the digitally secured adaptation module (SAM) for installation within a framework for data analysis, the SAM secured against modification.

20. A method according to claim 19 wherein the action is defined using natural language processing.

21. A method according to claim 19 wherein the action is defined by performing the action digitally within a system and saving steps involved in performing the action.

22. A method wherein defining an action comprises: providing a first dataset for audit; modeling interactions with the supporting data and documents to produce a first modeled process; building a digital workflow for an instance of the first modeled process; and saving the digital workflow for future execution.

23. A method according to claim 22 wherein saving the digital workflow comprises storing the digital workflow in a SAM, the SAM secured for verifying the SAM.

24. A method according to claim 23 comprising: providing a digitally secured adaptation module (SAM); verifying the digitally SAM against tampering; verifying a security of the digitally SAM to establish permission to install same; when permission is established, installing the digitally SAM within the digital model; and executing data analysis functions within the digital model, the data analysis functions having been installed from the digitally SAM.

25. A method according to claim 24 wherein the digitally SAM is secured with a public key of a framework in which it is to be executed.

26. A method according to claim 24 wherein the digitally SAM is secured with a private key of a service provider by whom it is provided.

27. A method according to claim 24 wherein the SAM modifies one of a function present within the model and a capability matrix of the model.

28. A method according to claim 24 wherein the SAM adds a new function other than present within the model before installation of the SAM.

29. A method comprising:providing a digitally secured adaptation module (SAM); verifying the digitally SAM against tampering; installing the digitally SAM within a framework, the framework verifying a security of the digitally SAM to establish permission to install same; and executing data analysis functions within the framework, the data analysis functions having been installed from the digitally secured SAM.

30. A method according to claim 29 comprising prior to installing the digitally SAM: providing the framework; verifying the SAM to establish integrity thereof; when the integrity of the SAM is verified, decrypting the SAM, unbundling the SAM into capability matrix components: data, models, and functionality.

31. A method according to claim 30 wherein access to the framework is via a browser.

32. A method according to claim 31 wherein a SAM is decrypted using a private key of the framework.

33. A method according to claim 31 wherein a SAM is decrypted using a public key of a trusted service provider.

34. A method comprising: providing a first framework comprising: a capability matrix; receiving a secured adaptation module (SAM); verifying the SAM to establish integrity thereof; when the integrity of the SAM is verified, decrypting the SAM, unbundling the SAM into capability matrix components: the capability matrix, and installing the capability matrix within the first framework to produce a changed first framework.

35. A method according to claim 34 wherein the SAM includes an indication of data, models and functionality and comprising: installing the data, models, and functionality within the first framework to produce a changed first framework.

36. A method comprising: providing an data analysis platform including Al; providing a data set comprising data from various sources and stored in various data stores; using the data set, performing an audit of a ground truth data file; based on a process for the audit and data accessed, building a first instance of a model for auditing the dataset; forming a first framework including the first instance of the model and comprising: data, at least a model, and functionality; and storing the first framework for subsequent execution.

37. A method comprising: providing a framework for one of implementing and verifying a process model, the framework comprising an intention-based interface for sharing a plurality of messages between components; and servicing an intention-based message of the plurality of messages by at least a services platform component for meeting an intention of the intention-based interface message.

Citation Information

Patent Citations

  • Event auditing framework

    US20120296876A1

  • System and method for integrating a transactional middleware platform with a centralized audit framework

    US20170286188A1

  • Ai-augmented auditing platform including techniques for automated assessment of vouching evidence

    US20230005075A1