IP Library › Granted Patent US 12,626,207
Granted Patent B2
US 12,626,207 · App. 17/897,814 · Granted May 12, 2026

System and method for integrating a data risk management engine and an intelligent graph platform

Inventors: Joao Pedro Seixas Calado (Birmingham, MI); Osman Santos Figueroa (Atlanta, GA); Michael James Henzey (Purcellville, VA); Ranjan Vivek Mannige (Berkeley Lake, GA)
Assignee: KPMG LLP
G06Q10/0635G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,626,207
App. No.
17/897,814
Granted
May 12, 2026
Kind
B2
Abstract

The invention relates to computer-implemented systems and methods for data risk management that provides traceability across governing artifacts which is key to driving effective data risk management and achieving compliance to policy, standards and controls. An embodiment of the present invention is directed to a standardized data risk taxonomy, harmonized classification schema, policy and standard hierarchy, control catalog and standard of care. These components facilitate an alignment to a full information lifecycle with a common definition of data risk, traceability across governing artifacts (e.g., obligations, policies, standards, risks, controls, etc.) and standardized catalogs with defined treatment across harmonized classification of assets.

Claims (88)

1 . A computer-implemented system for data risk management, the system comprising:

an interface coupled to a client environment;

a graph database that stores and manages a variety of data, wherein the variety of data comprises one or more of the following data types:

at least one obligation represented by at least a portion of an entire law or regulation;

at least one industry best practice represented by at least a portion of an entire industry best practice document;

at least one mandate represented by one or more individual requirements identified from the at least one obligation and the at least one industry best practice;

at least one policy represented by one or more documents within an organization that establishes one or more high-level operational requirements;

at least one policy statement represented by one or more individual requirements identified from one or more policies;

at least one standard represented by one or more documents subservient to a parent policy within an organization that contains more detailed requirements than its parent policy;

at least one standard statement represented by one or more individual requirements identified from the at least one standard;

at least one risk represented by one or more risk statements that identify and describe a particular potential manifestation of a threat and its impact upon an organization;

at least one control objective represented by one or more control statements describing activities that must be conducted in order to mitigate risk and/or to satisfy one or more mandates wherein one or more control objectives are derived from the one or more control statements;

at least one control represented by documentation of activities that are performed to mitigate risk and/or to satisfy one or more mandates;

at least one asset represented by things of value within an organization that require governance, protection and management;

at least one key control indicator represented by a numerical measure of performance of one or more controls;

a set of sensitivity classification tiers represented by a series of sensitivity labels that are associated with one or more control objectives indicating that at least one control objective applies to an identified sensitivity tier; and

a set of criticality classification tiers represented by a series of criticality labels that are associated with one or more control objectives indicating that at least one control objective applies to an identified criticality tier;

an intelligent graph platform coupled to the graph database, the intelligent graph platform representing how data is structured through a plurality of connected relationships; and

a data risk management engine comprising a computer processor and coupled to the interface and the intelligent graph platform, the data risk management engine configured to perform the steps of:

receiving a query that identifies a dataset based upon one or more pre-configured rules;

responsive to the query, identifying and displaying a curated dataset based upon an entered sensitivity classification tier wherein a first population of control objectives that have previously been associated with the entered sensitivity tier are collated;

identifying and displaying another curated dataset based upon an entered criticality classification tier wherein a second population of control objectives that have previously been associated with the entered criticality classification tier are collated;

responsive to the query for sensitivity and criticality tier, (1) identifying at least one gap in one or more sensitivity controls comprising encryption and access control and (2) producing a set of expected control objectives for data commensurate with the identified sensitivity tier and identified criticality tier, and in light of the identified at least one gap;

generating a graphical representation illustrating a first set of relationships between one or more of: the control objectives, the policies, the policy statements, the standards, the standard statements, the mandates, the obligations, and the industry best practices;

modeling a plurality of relationships between components comprising the control objectives and information from the client environment;

running one or more what-if analyses, based on the modeled plurality of relationships, with at least one change within a data risk ecosystem to determine hypothetical upstream and downstream impacts;

generating a graphical representation illustrating the modeled plurality of relationships and highlighting the identified at least one gap;

transmitting the graphical representations to an interactive user interface through a communication network; and

implementing at least one sensitivity control based on the set of expected control objectives, the at least one sensitivity control configured to secure data by implementation of one or more of in-transit edge encryption, encryption at rest, and crypto key access and management.

2 . The system of claim 1 , wherein the request is a query comprising one or more custom search parameters.

3 . The system of claim 1 , wherein the request relates to one or more of: control gap identification, a control assessment, policy and standard management, scenario analysis, risk metrics analysis, computational risk management, and client custom model.

4 . The system of claim 1 , wherein the entire law or regulation comprises the Gramm-Leach Bliley Act and wherein the entire industry best practice document comprises Control Objectives for Information Technologies published by ISACA (Information Systems Audit and Control Association).

5 . The system of claim 1 , wherein the things of value comprise: computer hardware, computer software, applications and data/information.

6 . The system of claim 1 , wherein the series of sensitivity labels comprise: restricted, confidential, nonpublic and public.

7 . The system of claim 1 , wherein the series of criticality labels comprise: enterprise critical data, line of business critical data and noncritical data.

8 . The system of claim 1 , wherein entering a high sensitivity tier returns a population of control objectives comprising encryption and access control to be satisfied by documenting and performing controls and wherein a low sensitivity classification tier returns a smaller population of control objectives.

9 . The system of claim 1 , wherein entering a high criticality classification tier returns a population of control objectives comprising data lineage and data quality to be satisfied by documenting and performing controls and wherein a low criticality classification tier returns a smaller population of control objectives to be satisfied.

10 . The system of claim 1 , wherein the client environment comprises: controls and metadata about controls, assets and metadata about assets.

11 . A computer-implemented method for data risk management, the method comprising the steps of:

storing and managing, in a graph database, a variety of data, wherein the graph database is coupled to an intelligent graph platform that represents how data is structured through a plurality of connected relationships, and wherein the variety of data comprises one or more of the following data types:

at least one obligation represented by at least a portion of an entire law or regulation;

at least one industry best practice represented by at least a portion of an entire industry best practice document;

at least one mandate represented by one or more individual requirements identified from the at least one obligation and the at least one industry best practice;

at least one policy represented by one or more documents within an organization that establishes one or more high-level operational requirements;

at least one policy statement represented by one or more individual requirements identified from one or more policies;

at least one standard represented by one or more documents subservient to a parent policy within an organization that contains more detailed requirements than its parent policy;

at least one standard statement represented by one or more individual requirements identified from the at least one standard;

at least one risk represented by one or more risk statements that identify and describe a particular potential manifestation of a threat and its impact upon an organization;

at least one control objective represented by one or more control statements describing activities that must be conducted in order to mitigate risk and/or to satisfy one or more mandates wherein one or more control objectives are derived from the one or more control statements;

at least one control represented by documentation of activities that are performed to mitigate risk and/or to satisfy one or more mandates;

at least one asset represented by things of value within an organization that require governance, protection and management;

at least one key control indicator represented by a numerical measure of performance of one or more controls;

a set of sensitivity classification tiers represented by a series of sensitivity labels that are associated with one or more control objectives indicating that at least one control objective applies to an identified sensitivity tier; and

a set of criticality classification tiers represented by a series of criticality labels that are associated with one or more control objectives indicating that at least one control objective applies to an identified criticality tier;

receiving, via an interface coupled to a client environment, a query that identifies a dataset based upon one or more pre-configured rules;

responsive to the query, identifying and displaying, via a data risk management engine, a curated dataset based upon an entered sensitivity classification tier wherein a first population of control objectives that have previously been associated with the entered sensitivity tier are collated;

identifying and displaying another curated dataset based upon an entered criticality classification tier wherein a second population of control objectives that have previously been associated with the entered criticality classification tier are collated;

responsive to the query for sensitivity and criticality tier, (1) identifying at least one gap in one or more sensitivity controls comprising encryption and access control and (2) producing a set of expected control objectives for data commensurate with the identified sensitivity tier and identified criticality tier, and in light of the identified at least one gap;

generating a graphical representation illustrating a first set of relationships between one or more of: the control objectives, the policies, the policy statements, the standards, the standard statements, the mandates, the obligations, and the industry best practices;

modeling a plurality of relationships between components comprising the control objectives and information from the client environment;

running one or more what-if analyses, based on the modeled plurality of relationships, with at least one change within a data risk ecosystem to determine hypothetical upstream and downstream impacts;

generating a graphical representation illustrating the modeled plurality of relationships and highlighting the identified at least one gap;

displaying, via an interactive user interface, the graphical representations through a communication network; and

implementing at least one sensitivity control based on the set of expected control objectives, the at least one sensitivity control configured to secure data by implementation of one or more of in-transit edge encryption, encryption at rest, and crypto key access and management.

12 . The method of claim 11 , wherein the request is a query comprising one or more custom search parameters.

13 . The method of claim 11 , wherein the request relates to one or more of: control gap identification, a control assessment, policy and standard management, scenario analysis, risk metrics analysis, computational risk management, and client custom model.

14 . The method of claim 11 , wherein the entire law or regulation comprises the Gramm-Leach Bliley Act and wherein the entire industry best practice document comprises Control Objectives for Information Technologies published by ISACA (Information Systems Audit and Control Association).

15 . The method of claim 11 , wherein the things of value comprise: computer hardware, computer software, applications and data/information.

16 . The method of claim 11 , wherein the series of sensitivity labels comprise: restricted, confidential, nonpublic and public.

17 . The method of claim 11 , wherein the series of criticality labels comprise: enterprise critical data, line of business critical data and noncritical data.

18 . The method of claim 11 , wherein entering a high sensitivity tier returns a population of control objectives comprising encryption and access control to be satisfied by documenting and performing controls and wherein a low sensitivity classification tier returns a smaller population of control objectives.

19 . The method of claim 11 , wherein entering a high criticality classification tier returns a population of control objectives comprising data lineage and data quality to be satisfied by documenting and performing controls and wherein a low criticality classification tier returns a smaller population of control objectives to be satisfied.

20 . The method of claim 11 , wherein the client environment comprises: controls and metadata about controls, assets and metadata about assets.

21 . A computer-implemented system for data risk management, the system comprising:

an interface coupled to a client environment;

a graph database that stores and manages a variety of data, wherein the variety of data comprises at least one of an internal obligation, an external obligation, a governance artifact, and a key control indicator, as well as a set of sensitivity classification tiers and a set of criticality classification tiers;

an intelligent graph platform coupled to the graph database, the intelligent graph platform representing how data is structured through a plurality of connected relationships; and

a data risk management engine comprising a computer processor and coupled to the interface and the intelligent graph platform, the data risk management engine configured to perform the steps of:

receiving a query that identifies a dataset based upon one or more pre-configured rules;

responsive to the query, identifying and displaying a curated dataset based upon an entered sensitivity classification tier wherein a first population of control objectives that have previously been associated with the entered sensitivity tier are collated;

identifying and displaying another curated dataset based upon an entered criticality classification tier wherein a second population of control objectives that have previously been associated with the entered criticality classification tier are collated;

responsive to the query for sensitivity and criticality tier, (1) identifying at least one gap in one or more sensitivity controls comprising encryption and access control and (2) producing a set of expected control objectives for data commensurate with the identified sensitivity tier and identified criticality tier, and in light of the identified at least one gap;

generating a graphical representation illustrating a first set of relationships between one or more of: the control objectives, the policies, the policy statements, the standards, the standard statements, the mandates, the obligations, and the industry best practices;

modeling a plurality of relationships between components comprising the control objectives and information from the client environment;

running one or more analyses, based on the modeled plurality of relationships, with at least one change within a data risk ecosystem to determine potential upstream and downstream impacts;

generating a graphical representation illustrating the modeled plurality of relationships and highlighting the identified at least one gap;

transmitting the graphical representations to a user interface through a communication network; and

implementing at least one sensitivity control based on the set of expected control objectives, the at least one sensitivity control configured to secure data by implementation of one or more of in-transit edge encryption, encryption at rest, and crypto key access and management.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2022
From: FIGUEROA, OSMAN SANTOS; CALADO, JOAO PEDRO SEIXAS; HENZEY, MICHAEL JAMES; MANNIGE, RANJAN VIVEK
To: KPMG LLP
Reel/Frame 060929/0685 →
Continuity (2)
Provisional Application 63237610 · Aug 27, 2021
Related Publication 20230061234A1 · Mar 2, 2023
References Cited (20)
US 8256004B1 · Hill · 2012 [cited by examiner]
US 10019677B2 · Gill · 2018 [cited by examiner]
US 20020129221A1 · Borgia · 2002 [cited by examiner]
US 20080282320A1 · DeNovo · 2008 [cited by examiner]
US 20100095235A1 · Bennett · 2010 [cited by examiner]
US 20150356477A1 · Milkman · 2015 [cited by examiner]
US 20160232358A1 · Grieco · 2016 [cited by examiner]
US 20170235569A1 · Sturtevant · 2017 [cited by examiner]
US 20180069899A1 · Lang · 2018 [cited by examiner]
US 20180146004A1 · Belfiore, Jr. · 2018 [cited by examiner]
US 20210133331A1 · Lipkis · 2021 [cited by examiner]
US 20210367963A1 · Murray · 2021 [cited by examiner]
US 20220103586A1 · Shao · 2022 [cited by examiner]
US 20230031994A1 · Jarvis · 2023 [cited by examiner]
Perera, Jeevan, and Jerry Holsomback. “An integrated risk management tool and process.” 2005 IEEE Aerospace Conference. IEEE, 2005 (Year: 2005). [cited by examiner]
Flowerday, Stephen, and Rossouw Von Solms. “Real-time information integrity= system integrity+ data integrity+ continuous assurances.” Computers & Security 24.8 (2005): 604-613 (Year: 2005). [cited by examiner]
Bassetto, Samuel, Ali Siadat, and Michel Tollenaere. “The management of process control deployment using interactions in risks analyses.” Journal of Loss Prevention in the Process Industries 24.4 (2011): 458-465 (Year: … [cited by examiner]
Thekdi, Shital, and Terje Aven. “An enhanced data-analytic framework for integrating risk management and performance management.” Reliability Engineering & System Safety 156 (2016): 277-287 (Year: 2016). [cited by examiner]
Labodová, Alena. “Implementing integrated management systems using a risk analysis based approach.” Journal of cleaner production 12.6 (2004): 571-580 (Year: 2004). [cited by examiner]
International Searching Authority, PCT Notification of International Search Report and Written Opinion, International Application No. PCT/US22/41878, Dec. 29, 2022, pp. 1-12. [cited by applicant]