IP Library Granted Patent US 12,225,033
Granted Patent B1
US 12,225,033 · App. 18/155,837 · Granted Feb 11, 2025

Controlling or auditing compliance

Inventors: Chalam Peddada (Jersey City, NJ); Eric Schaust (Minneapolis, MN); Dhanesh Babu (Bangalore, IN)
Assignee: Wells Fargo Bank, N.A.
H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,225,033
App. No.
18/155,837
Granted
Feb 11, 2025
Kind
B1
Abstract

Artificial intelligence and machine learning systems provide collection and correlation between publicly available regulatory and technology industry framework authoritative sources for proactive operational risk management, guidance, and regulatory obligation adherence. These systems can employ artificial intelligence techniques such as Robotic Process Automation, Natural Language Processing, Explication, Statistical Data Aggregation, Heuristics, and Machine Learning algorithms to perform analysis using machine understanding to identify assets or policies that warrant closer human scrutiny for governance, risk and compliance.

Claims (37)

1. A compliance monitoring platform, comprising:

a plurality of internal assets of an enterprise, each of the plurality of internal assets being subject to at least one compliance standard;

a computing device including a processor and a memory, the memory storing instructions which, when executed, cause the computing device to:

collect a plurality of publicly available authoritative sources including:

a set of regulatory compliance rules; and

cyber threat intelligence information;

collect a plurality of internal policies corresponding to the plurality of internal assets, the internal policies including a risk landscape;

align and cross-map the plurality of publicly available authoritative sources, the plurality of internal policies, and the plurality of internal assets;

overlay the set of regulatory compliance rules with the plurality of internal policies;

overlay the cyber threat intelligence information with the risk landscape;

detect a change in at least one of the publicly available authoritative sources, the plurality of internal policies, and the plurality of internal assets;

determine an adequacy of the plurality of internal policies based on the detected change, the overlaying of the set of regulatory compliance rules with the plurality of internal policies, and the overlaying of the cyber threat intelligence information with the risk landscape;

provide guided assistance for the enterprise to maintain conformance with the at least one compliance standard of each of the plurality of internal assets;

generate a compliance check based on the determination of adequacy when any one of the plurality of publicly available authoritative sources is modified; and

generate an indication of a compliance status for the one of the plurality of internal assets when the one of the plurality of publicly available authoritative sources is modified.

2. The compliance monitoring platform of claim 1 , the memory further comprising instructions which, when executed by the processor, cause the compliance monitoring platform to monitor the publicly available authoritative sources, the plurality of internal policies, and the plurality of internal assets to detect the change.

3. The compliance monitoring platform of claim 1 , wherein the plurality of publicly available authoritative sources is periodically updated by a third party provider.

4. The compliance monitoring platform of claim 1 , the memory further comprising instructions which, when executed by the processor, cause the compliance monitoring platform to automatically determine adequacy of the plurality of internal policies when certain of the publicly available authoritative sources, the plurality of internal policies, or the plurality of internal assets of the enterprise is changed.

5. The compliance monitoring platform of claim 1 , comprising further instructions which, when executed by the processor, cause the compliance monitoring platform to provide artificial intelligence to overlay the set of regulatory compliance rules with the plurality of internal policies, overlay the cyber threat intelligence information with the risk landscape, detect the change, and determine the adequacy of the plurality of internal policies.

6. A method comprising:

collecting a plurality of publicly available authoritative sources including:

a set of regulatory compliance rules; and

cyber threat intelligence information;

collecting a plurality of internal policies corresponding to a plurality of internal assets of an enterprise, the internal policies including a risk landscape;

aligning and cross-map the plurality of publicly available authoritative sources, the plurality of internal policies, and the plurality of internal assets;

overlaying the set of regulatory compliance rules with the plurality of internal policies;

overlaying the cyber threat intelligence information with the risk landscape;

detecting a change in at least one of the plurality of publicly available authoritative sources, the plurality of internal policies, and the plurality of internal assets;

determining an adequacy of the plurality of internal policies based on the detected change, the overlaying of the set of regulatory compliance rules with the plurality of internal policies, and the overlaying of the cyber threat intelligence information with the risk landscape;

providing a guided assistance output for the enterprise to maintain conformance with at least one compliance standard that corresponds to each of the plurality of internal assets;

generating a compliance check based on the adequacy when any one of the plurality of publicly available authoritative sources is modified; and

generating an indication of a compliance status for the one of the plurality of internal assets when the one of the plurality of publicly available authoritative sources is modified.

7. The method of claim 6 , further comprising providing guided assistance on a display having a real-time dashboard of the risk landscape.

8. The method of claim 7 , wherein the real-time dashboard of the risk landscape includes a plurality of viewpoints ranging in specificity from a holistic enterprise-level view to an asset-level view that is specific to one of the assets of the plurality of internal assets.

9. The method of claim 6 , further comprising continuously monitoring the publicly available authoritative sources, the plurality of internal policies, and the plurality of internal assets to detect the change.

10. The method of claim 6 , wherein collecting the plurality of publicly available authoritative sources comprises periodically receiving an update from a third party provider.

11. The method of claim 6 , further comprising automatically determining the adequacy of the plurality of internal policies when certain of the publicly available authoritative sources, the plurality of internal policies, or the plurality of internal assets of the enterprise is changed.

Assignments (2)
STATEMENT OF CHANGE OF ADDRESS OF ASSIGNEE Recorded Jun 17, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 071679/0784 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 20, 2023
From: PEDDADA, CHALAM; SCHAUST, ERIC; BABU, DHANESH
To: WELLS FARGO BANK, N.A.
Reel/Frame 062436/0975 →
References Cited (27)
US 10171310B2 · Hernandez et al. · 2019 [cited by applicant]
US 10521747B2 · Warner et al. · 2019 [cited by applicant]
US 10872206B2 · Snyder et al. · 2020 [cited by applicant]
US 11297088B2 · Crabtree · 2022 [cited by examiner]
US 11509681B2 · Parekh · 2022 [cited by examiner]
US 11611591B2 · Parekh · 2023 [cited by examiner]
US 12015648B2 · McCaffery · 2024 [cited by examiner]
US 12058162B2 · Barzilay · 2024 [cited by examiner]
US 12093389B2 · Ermey · 2024 [cited by examiner]
US 20180018602A1 · DiMaggio et al. · 2018 [cited by applicant]
US 20190190953A1 · Feintuch · 2019 [cited by examiner]
US 20190378073A1 · Lopez et al. · 2019 [cited by applicant]
US 20200050620A1 · Clark et al. · 2020 [cited by applicant]
US 20200184556A1 · Cella · 2020 [cited by applicant]
US 20200410583A1 · Hart et al. · 2020 [cited by applicant]
US 20200410590A1 · Regmi et al. · 2020 [cited by applicant]
US 20210110047A1 · Fang · 2021 [cited by examiner]
US 20210133649A1 · Spoon et al. · 2021 [cited by applicant]
US 20210243223A1 · Arora · 2021 [cited by examiner]
US 20210250358A1 · Dumitru et al. · 2021 [cited by applicant]
US 20210334821A1 · Berrington et al. · 2021 [cited by applicant]
US 20220019624A1 · Gwozdz et al. · 2022 [cited by applicant]
US 20220067825A1 · Shapiro · 2022 [cited by applicant]
US 20220101221A1 · Hari · 2022 [cited by examiner]
US 20240022606A1 · Bin Dato' Ahmad Dhman Huri · 2024 [cited by examiner]
US 20240031411A1 · Levari · 2024 [cited by examiner]
WO 2020205669A1 · 2020 [cited by applicant]