IP Library Granted Patent US 11,550,897
Granted Patent B2
US 11,550,897 · App. 17/670,349 · Granted Jan 10, 2023

Data processing and scanning systems for assessing vendor risk

Inventor: Jonathan Blake Brannon (Smyrna, GA)
Assignee: OneTrust, LLC
G06F21/50G06F11/3438G06F21/316G06F21/60G06F21/6245G06F2201/81G06F2221/2111G06F2221/2119
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,550,897
App. No.
17/670,349
Granted
Jan 10, 2023
Kind
B2
Abstract

Data processing systems and methods, according to various embodiments, are adapted for efficiently processing data to allow for the streamlined assessment of risk ratings for one or more vendors. In various embodiments, the systems/methods may use one or more particular vendor attributes (e.g., as determined from scanning one or more webpages associated with the particular vendor) and the contents of one or more completed privacy templates for the vendor to determine a vendor risk rating for the particular vendor. As a particular example, the system may scan a website associated with the vendor to automatically determine one or more security certifications associated with the vendor and use that information, along with information from a completed privacy template for the vendor, to calculate a vendor risk rating that indicates the risk of doing business with the vendor.

Claims (61)

1. A method comprising:

scanning, by computing hardware, a webpage associated with a vendor;

identifying, by the computing hardware, vendor attributes associated with the vendor based on the scanned webpage, wherein the vendor attributes comprise verification data originating from a third-party entity and verifying that the vendor has implemented, with respect to a vendor system, a procedure required by the third-party entity;

accessing, by the computing hardware, a public database of third-party verifications to determine whether the vendor has obtained the verification data from the third-party entity;

calculating, by the computing hardware, a vendor risk rating based on the vendor attributes;

generating, by the computing hardware, a graphical user interface comprising a menu for managing a computerized workflow related to the vendor, the menu comprising a navigation element and a display element, wherein:

the navigation element is configured for initiating a responsive action based on the vendor risk rating, and

the display element is configured for presenting the vendor risk rating;

transmitting, by the computing hardware, an instruction to a user computing device to present the graphical user interface on the user computing device;

detecting, by the computing hardware, selection of the navigation element; and

responsive to detecting the selection of the navigation element, initiating, by the computing hardware, the responsive action, wherein the responsive action comprises at least one of:

(i) generating a second graphical user interface comprising an indication of the vendor risk rating and transmitting a second instruction to a third-party computing device to present the second graphical user interface on the third-party computing device,

(ii) generating an electronic communication comprising an indication of the vendor risk rating and transmitting the electronic communication to the third-party computing device, or

(iii) transferring the vendor risk rating to a current or potential customer of the vendor for use in assessing a risk of doing business with the vendor.

2. The method of claim 1 , wherein the vendor attributes comprise a certification that the vendor holds.

3. The method of claim 1 , wherein scanning the webpage comprises identifying an image that makes up part of the webpage and that is associated with the verification data.

4. The method of claim 1 further comprising:

monitoring, by the computing hardware, the webpage for an update;

responsive to identifying the update, identifying, by the computing hardware, updated vendor attributes for the vendor attributes; and

calculating, by the computing hardware, an updated vendor risk rating based on the updated vendor attributes.

5. A system comprising:

a non-transitory computer-readable medium storing instructions; and

a processing device communicatively coupled to the non-transitory computer-readable medium,

wherein, the processing device is configured to execute the instructions and thereby perform operations comprising:

scanning a webpage associated with a vendor;

identifying vendor attributes associated with the vendor based on the scanned webpage, wherein the vendor attributes comprise verification data originating from a third-party entity and verifying that the vendor has implemented, with respect to a vendor system, a procedure required by the third-party entity;

accessing a public database of third-party verifications to determine whether the vendor has obtained the verification data from the third-party entity;

calculating the vendor risk rating based on the vendor attributes; and

generating a graphical user interface comprising a menu for managing a computerized workflow related to the vendor, the menu comprising a navigation element and a display element, wherein:

the navigation element is configured for initiating a responsive action based on the vendor risk rating, and

the display element is configured for presenting the vendor risk rating;

transmitting an instruction to a user computing device to present the graphical user interface on the user computing device;

detecting selection of the navigation element; and

responsive to detecting the selection of the navigation element, initiating the responsive action, wherein the responsive action comprises at least one of:

(i) generating a second graphical user interface comprising an indication of the vendor risk rating and transmitting a second instruction to a third-party computing device to present the second graphical user interface on the third-party computing device,

(ii) generating an electronic communication comprising an indication of the vendor risk rating and transmitting the electronic communication to the third-party computing device, or

(iii) transferring the vendor risk rating to a current or potential customer of the vendor for use in assessing a risk of doing business with the vendor.

6. The system of claim 5 , wherein the vendor attributes comprise a certification that the vendor holds.

7. The system of claim 5 , wherein scanning the webpage comprises identifying an image that makes up part of the webpage and that is associated with the verification data.

8. The system of claim 5 , wherein the operations further comprise:

monitoring the webpage for an update;

responsive to identifying the update, identifying updated vendor attributes for the vendor attributes; and

calculating an updated vendor risk rating based on the updated vendor attributes.

9. A non-transitory computer-readable medium having program code that is stored thereon, the program code executable by one or more processing devices for performing operations comprising:

scanning a webpage associated with a vendor;

identifying vendor attributes associated with the vendor based on the scanned webpage, wherein the vendor attributes comprise verification data originating from a third-party entity and verifying that the vendor has implemented, with respect to a vendor system, a procedure required by the third-party entity;

accessing a public database of third-party verifications to determine whether the vendor has obtained the verification data from the third-party entity;

calculating the vendor risk rating based on the vendor attributes; and

generating a graphical user interface comprising a menu for managing a computerized workflow related to the vendor, the menu comprising a navigation element, wherein the navigation element is configured for initiating a responsive action based on the vendor risk rating, and

transmitting an instruction to a user computing device to present the graphical user interface on the user computing device;

detecting selection of the navigation element; and

responsive to detecting the selection of the navigation element, initiating the responsive action, wherein the responsive action comprises at least one of:

(i) generating a second graphical user interface comprising an indication of the vendor risk rating and transmitting a second instruction to a third-party computing device to present the second graphical user interface on the third-party computing device,

(ii) generating an electronic communication comprising an indication of the vendor risk rating and transmitting the electronic communication to the third-party computing device, or

(iii) transferring the vendor risk rating to a current or potential customer of the vendor for use in assessing a risk of doing business with the vendor.

10. The non-transitory computer-readable medium of claim 9 , wherein the vendor attributes comprise a certification that the vendor holds.

11. The non-transitory computer-readable medium of claim 9 , wherein scanning the webpage comprises identifying an image that makes up part of the webpage and that is associated with the verification data.

12. The non-transitory computer-readable medium of claim 9 , wherein the operations further comprise:

monitoring the webpage for an update;

responsive to identifying the update, identifying updated vendor attributes for the vendor attributes; and

calculating an updated vendor risk rating based on the updated vendor attributes.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2024
From: VISWANATHAN, SUBRAMANIAN; SHAH, MILAP
To: ONETRUST, LLC
Reel/Frame 067259/0313 →
SECURITY INTEREST Recorded Jul 5, 2022
From: ONETRUST LLC
To: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 060573/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2022
From: BRANNON, JONATHAN BLAKE
To: ONETRUST, LLC
Reel/Frame 058995/0024 →