Dynamic Risk Assessment Model for Audit Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large and complex organizations face challenges in assessing risks due to the difficulty in identifying key contributors and risk impacts across various products and systems, as well as static or outdated risk assessments that fail to account for changes such as cloud migrations or regulatory shifts, often relying on insufficiently systematic human evaluations prone to biases.

Innovation Solution

A method using system and role risk evaluation models to assess risks by assigning weights to data attributes, generating customized audits, and adjusting configurations based on identified risks, with the ability to update models based on audit results and changing conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional human evaluation methods are used for risk assessment, then the process is simple to implement, but the assessment accuracy is low and prone to biases

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidevaluation system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces manual human evaluation with automated computational models including machine learning algorithms and risk evaluation models. The system automatically processes organizational data, identifies key contributors, calculates risk impacts, and generates risk assessments without human intervention, thereby eliminating biases while maintaining high accuracy through systematic computational analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If static risk assessment methods are used, then the implementation is straightforward, but the assessments become outdated and fail to account for changes such as cloud migrations or regulatory shifts

Engineering Contradiction:
Improverisk assessment adaptabilityVSAvoidassessment update efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system implements continuous feedback loops where risk assessments are automatically updated based on changes in organizational data, regulatory updates, and identified risk factors. The models re-evaluate risks periodically or triggered by specific events, ensuring assessments remain current and adaptive to changing conditions without manual intervention.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The risk assessment system transitions from static to dynamic evaluation by continuously monitoring organizational changes, cloud migration status, and regulatory updates. The models adapt their parameters and weightings based on current organizational state, enabling real-time adjustment of risk assessments to reflect changing conditions.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If comprehensive risk assessment covering all systems and products is performed, then the assessment thoroughness is high, but the complexity of identifying key contributors and risk impacts increases significantly

Engineering Contradiction:
Improverisk identification thoroughnessVSAvoiddata analysis complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the organizational system into discrete units including individual products, systems, key contributors, and risk categories. Each segment is evaluated independently by specialized models that assess specific risk factors, allowing comprehensive coverage while managing complexity through modular analysis of divided components rather than monolithic evaluation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts evaluation parameters and weightings based on the specific organizational context, data availability, and risk priority. The models modify their analysis depth and focus areas according to changing conditions, enabling thorough assessment where needed while reducing complexity in lower-risk areas through adaptive parameter adjustment.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240220674A1Converged model based risk assessment and audit generation
Publication Date: 2024.07.04 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20240220674A1 patent drawing
  • US20240220674A1 patent drawing
  • US20240220674A1 patent drawing

AI summary

Using a system risk evaluation model, system data is evaluated, the evaluating identifying a system risk, the system risk comprising a risk associated with a system of an organization being audited, the system risk evaluation model computing a system risk score using a first plurality of weights assigned to data attributes of the system data. Using a role risk evaluation model, role data is evaluated, the evaluating identifying a role risk, the role risk comprising a risk associated with a role in the organization being audited, the role risk evaluation model comprising computing a role risk score using a second plurality of weights assigned to data attributes of the role data. Using an audit repository, an audit customized to the system risk and the role risk is generated. Using a result of the audit, a configuration of the system is caused to be adjusted.