Automated Third-Party Data Risk Assessment System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for evaluating a third-party's data risk management capabilities are expensive, time-consuming, and prone to errors, relying on manual and labor-intensive questionnaires from the third-party, which are not objective or accurate.

Innovation Solution

Implementing a system that uses web crawlers to retrieve information from the third-party's websites, combined with natural language processing and machine learning or AI to assess data risk management capabilities automatically, without input from the third-party, including scanning for personally identifiable information (PII) and residual data after outsourcing engagements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If manual questionnaires are used to evaluate third-party data risk management capabilities, then the evaluation can be performed with simple tools, but the process becomes expensive, time-consuming, and error-prone

Engineering Contradiction:
Improveevaluation tool complexityVSAvoidevaluation efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent replaces manual questionnaire-based evaluation (mechanical human process) with an automated system using web crawlers, natural language processing, and machine learning algorithms. This substitution eliminates the need for manual data collection and analysis, directly resolving the contradiction by maintaining tool simplicity while dramatically improving evaluation efficiency and reducing errors

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The evaluation system performs self-service by automatically collecting data from third-party websites, processing the information through AI algorithms, and generating risk assessments without requiring third-party participation or manual intervention. This resolves the contradiction by eliminating the time-consuming manual questionnaire process while maintaining comprehensive evaluation capabilities

Inventive Principle:
Principle #25Self-service

2Ease of manufacture

If manual questionnaires are used to evaluate third-party data risk management capabilities, then the evaluation process is straightforward to implement, but the results are not objective or accurate

Engineering Contradiction:
Improveevaluation implementation easeVSAvoidrisk assessment accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent replaces subjective manual assessment with objective automated analysis using natural language processing and machine learning. The system objectively evaluates third-party data risk management capabilities by analyzing publicly available information, eliminating human bias and improving measurement precision while maintaining implementation ease through automated workflows

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system continuously monitors and analyzes third-party data security practices, providing ongoing feedback and updates to risk assessments. This feedback mechanism improves accuracy by incorporating the latest information from third-party websites and maintaining current evaluations without requiring manual re-assessment

Inventive Principle:
Principle #23Feedback

3Measurement precision

If automated web crawling and AI processing are implemented to assess third-party data risk, then evaluation accuracy and objectivity improve, but system complexity increases

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidevaluation system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the complex evaluation system into distinct functional modules: web crawling component, natural language processing component, machine learning assessment component, and reporting component. This segmentation manages system complexity by making each component independent and manageable while maintaining high overall accuracy through the coordinated operation of specialized modules

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The automated evaluation system is designed as a universal platform that can assess multiple third-parties across different industries and data types using the same core technology stack. This multi-functionality reduces overall system complexity by avoiding the need for separate specialized systems for each evaluation scenario

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If automated scanning for PII and residual data is performed, then data security and compliance are enhanced, but computing resources and time are consumed

Engineering Contradiction:
Improvedata securityVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary scanning and identification of PII and residual data before actual data processing or transfer occurs. By detecting potential security risks in advance, the system prevents compromised data from being processed, thereby enhancing data security while optimizing computing resource usage by avoiding unnecessary processing of identified risky data

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11714919B2Methods and systems for managing third-party data risk
Publication Date: 2023.08.01 PAYPAL INC
  • US11714919B2 patent drawing
  • US11714919B2 patent drawing
  • US11714919B2 patent drawing

AI summary

Some embodiments of the present disclosure disclose methods and systems for assessing the data risk management capabilities of data processors that receive second-party data as part of an engagement to provide support services. In some embodiments, the transfer of the second-party data to the data processors can be monitored to identify file transfers including unauthorized personally identifiable information (PII) attributes. In some embodiments, the database of the data processor may be scanned to locate any residual second-party data that should be removed after the data processor's engagement to provide the support services have expired.