Dynamic Identity Audit Frequency via Risk Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity management systems are inefficient in detecting compliance violations, as they treat all identity accounts equally and do not dynamically adjust the frequency of reconciliation based on compliance risk, leading to increased costs and resource usage without effectively improving compliance checking efficiency.

Innovation Solution

Implement a system that uses compliance violation risk data to dynamically adjust the frequency of reconciliation and compliance checks for individual identity accounts by calculating a risk score based on collected data, including compliance and historical violation information, and applying a risk heuristic to determine the audit frequency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the identity management system performs compliance checks on all identity accounts with equal frequency, then every account is audited uniformly, but computing resources are wasted on low-risk accounts and compliance violations in high-risk accounts may be detected too slowly

Engineering Contradiction:
Improvecompliance violation detection effectivenessVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by assigning different compliance check frequencies to different identity accounts based on their individual risk scores. High-risk accounts receive more frequent auditing while low-risk accounts are audited less frequently, optimizing resource allocation according to the specific needs of each account rather than applying a uniform approach across all accounts.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes the frequency parameter of compliance checks based on calculated risk scores. The risk score itself is a parameter that determines how often an account should be audited, allowing the system to adapt the auditing frequency parameter to match the actual risk level of each identity account, thereby improving detection effectiveness while reducing unnecessary resource consumption.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If the identity management system increases the frequency of compliance checks for all accounts, then more compliance violations are detected, but the cost and resource usage increase significantly

Engineering Contradiction:
Improvecompliance violation detection rateVSAvoidcomputing resource cost
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent implements local quality by tailoring the compliance check frequency to the specific risk profile of each identity account. Instead of uniformly increasing check frequency across all accounts, the system identifies high-risk accounts through risk scoring and concentrates auditing resources on those accounts, thereby achieving high detection rates without proportionally increasing overall resource consumption.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system applies partial action by performing compliance checks only on accounts where it is necessary based on risk assessment. Low-risk accounts undergo less frequent or reduced scrutiny, while high-risk accounts receive intensified monitoring. This selective approach achieves effective compliance detection without the excessive resource expenditure that would result from universal high-frequency auditing.

Inventive Principle:
Principle #16Partial or excessive action

3Loss of time

If the identity management system performs frequent reconciliation on all identity accounts, then compliance violations are detected more quickly, but the processing time and system load increase

Engineering Contradiction:
Improvetime to detect compliance violationsVSAvoidreconciliation processing efficiency
Core Design Contradiction:
Loss of timeVSProductivity

Solution Approach 1:

The patent changes the frequency parameter of reconciliation operations based on risk scores. Accounts with high risk scores trigger more frequent and timely reconciliation processes, reducing the time to detect violations for those accounts. Low-risk accounts undergo less frequent reconciliation, maintaining processing efficiency while still providing adequate oversight. This dynamic parameter adjustment optimizes both detection speed and system productivity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system applies local quality by differentiating reconciliation frequency according to the specific risk characteristics of each identity account. High-risk accounts receive prompt and frequent reconciliation to quickly detect and address potential violations, while low-risk accounts are reconciled at standard intervals. This targeted approach minimizes overall processing time and system load while ensuring rapid detection where most needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8812342B2Managing and monitoring continuous improvement in detection of compliance violations
Publication Date: 2014.08.19 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8812342B2 patent drawing
  • US8812342B2 patent drawing
  • US8812342B2 patent drawing

AI summary

A computer implemented method, data processing system, and computer program product is provided for using compliance violation risk data about an entity to enable an identity management system to dynamically adjust the frequency in which the identity management system performs a reconciliation and compliance check of an identity account associated with the entity. Data associated with an identity account is collected, wherein the data comprises at least one of compliance data, prior compliance violations, or personal data about an entity associated with the identity account. One or more risk factors for the identity account based on the collected data are determined. A risk score of the identity account is calculated based on the determined risk factors. The identity account is then audited with a frequency according to the risk score assigned to the identity account.