Compliance Analysis System Using Tiered Question Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Determining applicable security compliance requirements from hundreds of international regulatory standards and guidelines for a specific business offering is challenging and time-consuming due to the complexity of harmonizing controls across various authority documents.

Innovation Solution

A system that analyzes client data by generating custom questions based on scope selections, submitting queries to a database integrated with the Unified Compliance Framework (UCF) data, and using a three-tiered architecture to extract relevant regulations and leading practices, with the ability to generate reports and interface with users through a user-friendly interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a comprehensive compliance database harmonizing controls from hundreds of international regulatory requirements is built, then the completeness and accuracy of compliance analysis is improved, but the complexity of the system and difficulty of determining applicable requirements increases

Engineering Contradiction:
Improvecompliance analysis accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the compliance analysis process into distinct functional modules: scope definition module, question generation module, query submission module, and report generation module. Each module handles a specific aspect of the compliance determination process, making the overall complex system more manageable and easier to operate while maintaining comprehensive coverage of regulatory requirements

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary layer in the form of a database that stores harmonized compliance data from multiple regulatory frameworks. This intermediary database acts as a mediator between the user's scope definitions and the complex regulatory requirements, enabling accurate compliance determination without requiring users to directly navigate through hundreds of regulatory documents

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If manual analysis of compliance requirements is performed, then flexibility and adaptability to specific business offerings is maintained, but the time required for compliance determination increases significantly

Engineering Contradiction:
Improvecustomization to business offeringVSAvoidcompliance analysis time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-defining compliance scopes and pre-generating customized questions based on selected business offerings before actual compliance analysis is needed. The database is pre-populated with harmonized compliance data, allowing rapid query execution and report generation without time-consuming manual analysis during the compliance determination process

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service compliance analysis by allowing users to select business offerings and receive automatically generated compliance requirements through customized questions. The system autonomously processes the compliance determination by submitting queries to the database and generating reports, eliminating the need for manual compliance analysis while maintaining adaptability to specific business contexts

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9123024B2System for analyzing security compliance requirements
Publication Date: 2015.09.01 ACCENTURE GLOBAL SERVICES LTD
  • US9123024B2 patent drawing
  • US9123024B2 patent drawing
  • US9123024B2 patent drawing

AI summary

A system for analyzing security compliance requirements analyzes a linked database that includes data from the Unified Compliance Framework™. The system generates a tiered question structure to obtain information about a particular business offering, wherein questions of a particular tier are based on answers to questions of a preceding tier. Based on the information, the system generates a query and submits the query to the linked database. The query results provide a list of security compliance requirements, leading practices, and/or regulations applicable to the business offering.