Third-Party Security System for Automated Vendor Risk Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional third-party security risk assessments are time-consuming, resource-intensive, lack standardization, and often fail to account for legal requirements, leading to inconsistent risk scores and inefficient vendor management, which complicates data security and compliance monitoring.

Innovation Solution

A third-party security system employing machine learning techniques to process vendor data, generate insights, and provide predictive risk scores, while connecting data silos across procurement, legal, and identity management to enhance data security and compliance monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional third-party security risk assessments are performed manually with detailed questionnaires and site visits, then comprehensive security evaluation is achieved, but the process becomes time-consuming and resource-intensive

Engineering Contradiction:
Improvesecurity assessment comprehensivenessVSAvoidvendor onboarding time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary security assessments automatically using machine learning algorithms before human analysts intervene. Vendor data is pre-processed, risk scores are generated, and initial evaluations are completed ahead of time, reducing the overall assessment duration while maintaining comprehensiveness through subsequent human review only when necessary.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Manual mechanical assessment processes are replaced with automated machine learning systems that analyze vendor data, generate risk scores, and provide security evaluations. The system substitutes human analysts' initial screening work with algorithms that can process multiple vendors simultaneously, dramatically reducing time loss while preserving assessment quality through targeted human review.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If manual security assessments are conducted by individual analysts, then flexible evaluation is possible, but inconsistencies and lack of standardization occur

Engineering Contradiction:
Improveassessment flexibilityVSAvoidrisk score consistency
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The system implements a universal machine learning model that serves multiple functions: data collection, initial risk assessment, consistency enforcement, and analyst support. This multi-functional system ensures all vendors are evaluated using the same standardized criteria while maintaining the flexibility for analysts to adjust assessments when warranted, resolving the contradiction between standardization and adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system incorporates feedback loops where machine learning models are continuously trained on analyst decisions and assessment outcomes. This feedback mechanism allows the system to learn from human expertise while maintaining standardization, enabling consistent risk scores across all vendors while preserving necessary flexibility through iterative improvement of the automated assessment criteria.

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive vendor monitoring and assessment are performed, then security risks are identified, but the complexity of managing multiple vendors increases

Engineering Contradiction:
Improvevendor security monitoringVSAvoidvendor management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts and automates specific monitoring functions from the overall vendor management process. Machine learning algorithms handle data collection, risk scoring, and compliance checking independently, separating these complex tasks from human analysts. This extraction reduces management complexity by automating routine monitoring while maintaining reliable security oversight through the specialized algorithms.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The vendor management system is segmented into distinct automated and human-managed components. The machine learning system handles data processing, initial risk assessment, and continuous monitoring, while human analysts focus on high-level decision-making and complex issue resolution. This segmentation reduces overall complexity by assigning appropriate tasks to the most suitable system component.

Inventive Principle:
Principle #1Segmentation

4Stability of the object's composition

If traditional security assessment methods are used, then established procedures are followed, but they fail to account for changing industry trends and legal requirements

Engineering Contradiction:
Improveassessment procedure stabilityVSAvoidresponse to changing requirements
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic assessment procedures where the machine learning model continuously adapts to changing industry trends, legal requirements, and emerging security threats. The system maintains stable core assessment frameworks while dynamically adjusting evaluation criteria, data sources, and risk factors based on current conditions, resolving the contradiction between procedural stability and adaptability to change.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20220405739A1System and method for enhancing third party security
Publication Date: 2022.12.22 KPMG LLP
  • US20220405739A1 patent drawing
  • US20220405739A1 patent drawing
  • US20220405739A1 patent drawing

AI summary

A third party security system having an intelligence unit for receiving and processing vendor related data to generate insights regarding vendor related tasks; a risk assessment unit for receiving and processing risk score data associated with the vendor and for generating a predicted risk score value of the vendor; a legal assessment unit for receiving legal data and for determining based on the legal data whether the vendor is in compliance with a contractual obligation; a vendor tiering unit for receiving the vendor related data and for classifying the vendor into one or more classes based on the vendor related data; a program quality and efficiency analysis unit for receiving the risk score data and for determining an accuracy of the risk score; and a service unit for generating a virtual agent for allowing communication with the system.