US2022300619A1PendingUtilityA1

Data processing and scanning systems for assessing vendor risk

Assignee: ONETRUST LLCPriority: Jun 10, 2016Filed: Jun 9, 2022Published: Sep 22, 2022
Est. expiryJun 10, 2036(~9.9 yrs left)· nominal 20-yr term from priority
G06Q 10/0635G06F 11/3438Y02D10/00G06F 21/316G06Q 30/018G06F 21/50G06Q 50/26G06F 21/60G06F 2201/81G06F 2221/2119G06F 21/6245G06Q 30/0609G06F 2221/2111G06F 21/6263
78
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Data processing systems and methods, according to various embodiments, are adapted for efficiently processing data to allow for the streamlined assessment of risk ratings for one or more vendors. In various embodiments, the systems/methods may use one or more particular vendor attributes (e.g., as determined from scanning one or more webpages associated with the particular vendor) and the contents of one or more completed templates for the vendor to determine a vendor risk rating for the particular vendor. As a particular example, the system may scan a website associated with the vendor to automatically determine one or more security certifications associated with the vendor and use that information, along with information from a completed template for the vendor, to calculate a vendor risk rating that indicates the risk of doing business with the vendor.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 receiving, by computing hardware, a completed template from a vendor, the completed template including question/answer pairings regarding a particular product or service provided by the vendor;   scanning, by the computing hardware, webpages associated with the vendor to identify vendor attributes, wherein the vendor attributes include a notification regarding operations conducted by the vendor;   analyzing, by the computing hardware, the notification to identify key terms in the notification related to the particular product or service that is a subject of at least one question within the template;   analyzing, by the computing hardware, content of the at least one of the question/answer pairings in the completed template to identify verification data originating from a third-party entity and verifying that the vendor has implemented, with respect to one or more vendor systems, one or more procedures required by the third-party entity;   calculating, by the computing hardware, a vendor risk rating for the vendor based on:
 the verification data; 
 the key terms in the notification; and 
 the question/answer pairings from the template; and 
   taking, by the computing hardware, an automated action based on the calculated vendor risk rating.   
     
     
         2 . The method of  claim 1 , wherein the vendor attributes comprise at least one of a certification held by the vendor or an award earned by the vendor. 
     
     
         3 . The method of  claim 1 , wherein the automated action comprises providing the vendor risk rating to a current or potential customer of the vendor for use in assessing a risk of engaging the particular product or service provided by the vendor. 
     
     
         4 . The method of  claim 1 , wherein the method further comprises:
 requesting, by the computing hardware, an updated version of the completed template from the vendor in response to determining that the particular product or service has been revised;   receiving, by the computing hardware, the updated version of the completed template, the updated version comprising at least one revised question/answer paring; and   calculating, by the computing hardware, the vendor risk rating for the vendor based on the updated version of the completed template and the at least one revised question/answer paring.   
     
     
         5 . The method of  claim 1 , wherein:
 the method further comprises determining at least one of employee titles, employee roles, or available job posts for the vendor from one or more third party social networking sites; and   calculating the vendor risk rating based on the employee titles, employee roles, or available job posts for the vendor.   
     
     
         6 . The method of  claim 1 , wherein the particular product or service provided by the vendor includes at least one of a component or a raw material. 
     
     
         7 . The methhod of  claim 1 , further comprising:
 monitoring the webpages for changes to the vendor attributes;   in response to identifying changes to the vendor attributes, modifying, by the computing hardware, the vendor risk rating based on the changes.   
     
     
         8 . A system comprising:
 a non-transitory computer-readable medium storing instructions; and   a processing device communicatively coupled to the non-transitory computer-readable medium, wherein the processing device is configured to execute the instructions and thereby perform operations comprising:   receiving, by computing hardware, a completed template from a vendor, the completed template including question/answer pairings regarding a particular product or service provided by the vendor;   scanning, by the computing hardware, webpages associated with the vendor to identify vendor attributes, wherein the vendor attributes include an indication regarding operations conducted by the vendor;   analyzing, by the computing hardware, the indication to identify an attestation related to the particular product or service that is a subject of at least one question within the template;   analyzing content of the at least one of the question/answer pairings in the completed template to identify verification data originating from a third-party entity and verifying that the vendor has implemented, with respect to one or more vendor systems, one or more procedures required by the third-party entity;   calculating a vendor risk rating for the vendor based on:
 the verification data; 
 the attestation related to the product or service; and 
   the question/answer pairings from the template; and   facilitating an action based on the calculated vendor risk rating.   
     
     
         9 . The system of  claim 8 , wherein the operations further comprise:
 accessing, via a public data network, one or more databases to confirm a validity of the attestation; and   calculating the vendor risk rating based on the validity of the attestation.   
     
     
         10 . The system of  claim 8 , wherein the vendor attributes comprise one or more policies implemented by the vendor. 
     
     
         11 . The system of  claim 8 , the operations further comprising:
 monitoring the webpages for updates;   in response to identifying the updates, determining whether the updates affect the vendor attributes; and   in response to determining that the updates affect the vendor attributes, calculating an updated vendor risk rating based on the affected vendor attributes.   
     
     
         12 . The system of  claim 8 , wherein the vendor attributes comprise at least one of a key partner of the vendor or a sub processor for the particular product or service provided by the vendor. 
     
     
         13 . The system of  claim 8 , the operations further comprising:
 accessing employment data for the vendor, the employment data comprising at least one of an employee title or an open job listing for the vendor; and   calculating the vendor risk rating based on the employee title or the open job listing for the vendor.   
     
     
         14 . The system of  claim 8 , wherein the vendor attributes comprise at least one of a certification held by the vendor or an award earned by the vendor. 
     
     
         15 . A method comprising:
 receiving, by computing hardware, a completed template from a vendor, the completed template including question/answer pairings regarding a particular product or service provided by the vendor;   scanning, by the computing hardware, webpages associated with the vendor to identify vendor attributes, wherein the vendor attributes include a policy regarding operations conducted by the vendor;   analyzing, by the computing hardware, the notification to identify key terms in the policy related to the particular product or service that is a subject of at least one question within the template;   analyzing, by the computing hardware, content of the at least one of the question/answer pairings in the completed template to identify verification data originating from a third-party entity and verifying that the vendor has implemented, with respect to one or more vendor systems, one or more procedures required by the third-party entity;   calculating, by the computing hardware, a vendor risk rating for the vendor based on:
 the verification data; 
 the key terms in the policy; and 
 the question/answer pairings from the template; and 
   facilitating, by the computing hardware, performance of an action based on the calculated vendor risk rating.   
     
     
         16 . The method of  claim 15 , wherein the action comprises providing the vendor risk rating to a current or potential customer of the vendor for use in assessing a risk of engaging the particular product or service provided by the vendor. 
     
     
         17 . The method of  claim 15 , wherein the particular product or service provided by the vendor includes at least one of a component or a raw material. 
     
     
         18 . The method of  claim 15 , further comprising:
 monitoring, by the computing hardware, the policy for changes;   in response to identifying the changes, identifying, by the computing hardware, updated key terms; and   calculating, by the computing hardware, an updated vendor risk rating based on the updated key terms.   
     
     
         19 . The method of  claim 15 , wherein the vendor attributes comprise at least one of a key partner of the vendor or a sub processor for the particular product or service provided by the vendor. 
     
     
         20 . The method of  claim 15 , wherein:
 the method further comprises determining at least one of employee titles, employee roles, or available job posts for the vendor from one or more third party social networking sites; and   calculating the vendor risk rating is based on the employee titles, employee roles, or available job posts for the vendor.

Join the waitlist — get patent alerts

Track US2022300619A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.