Dynamic Risk Meta-Model Extension for GRC Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing governance, risk management, and compliance (GRC) systems face challenges in providing a flexible and customizable framework for organizations to model specific risk structures, as fixed meta-models are rigid and difficult to modify, while custom solutions are expensive and prone to compatibility issues with software updates.
Innovation Solution
A GRC computer system that includes a stored fixed meta-model with dynamic risk modeling functionality, allowing organizations to extend the meta-model through user input, creating a conditional and user-configurable extended meta-model that supports dynamic risk models with process, risk, and control elements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Stability of the object's composition
If a fixed meta-model is used in GRC systems, then the system structure is stable and easy to maintain, but the system lacks flexibility and is difficult to modify for organization-specific requirements
Solution Approach 1:
The patent segments the meta-model into two distinct layers: a fixed base meta-model containing stable, standardized elements, and an extendable meta-model that allows organization-specific customizations. This segmentation enables the system to maintain stability in core functions while allowing flexibility in specialized applications without requiring programmers for modifications.
2Adaptability or versatility
If a custom meta-model is created to meet organization-specific requirements, then the system is highly adaptable, but the cost increases and compatibility issues arise with software updates
Solution Approach 1:
The patent implements a nested structure where the extendable meta-model is built upon and contains references to the fixed base meta-model. Organization-specific elements are nested within the standardized framework, allowing customizations to inherit from and integrate with the base model. This nesting reduces complexity by reusing established components rather than creating entirely custom solutions.
Solution Approach 2:
The system transitions from a static, fixed meta-model to a dynamic structure where the meta-model can be extended and configured based on organizational needs. The extendable meta-model allows dynamic addition of custom elements while maintaining connections to the stable base model, enabling adaptability without proportionally increasing overall system complexity.
3Adaptability or versatility
If programmers are involved to modify the meta-model, then the system can be customized, but the process becomes technically complex and time-consuming
Solution Approach 1:
The patent enables non-programmer users to perform meta-model extensions through a user-friendly interface that allows configuration of organization-specific elements without requiring programming knowledge. Users can independently customize the extendable meta-model by selecting and configuring elements from the base model and adding their own specifications, eliminating the need for programmer intervention and reducing customization time.
Data Source
AI summary
A governance, risk management, and compliance (GRC) computer system is provided that includes at least one processor, a user input device, and a storage system that stores meta-model. The meta-model includes at least one process element, a plurality of dynamic risk elements, and a plurality of dynamic control elements. The risk meta-model is loaded from the storage system. Input is accepted from the user input device for creating a new dynamic risk model based on the loaded extended risk meta-model. At least one process element is added to the new dynamic risk model based on user provided input and the extended risk meta-model. A first dynamic risk element is added from the plurality of dynamic risk elements based on user provided input. A risk type of the first dynamic risk element is determined based on user provided input.


