Data management for top-down risk based audit approach

US9292808B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9292808-B2
Application numberUS-83253210-A
CountryUS
Kind codeB2
Filing dateJul 8, 2010
Priority dateApr 7, 2010
Publication dateMar 22, 2016
Grant dateMar 22, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Particular embodiments generally relate to providing risk management. In one embodiment, a first risk is linked to an account group assertion in a data structure. A second risk is linked to a control objective in the data structure. Access to the first risk is granted through the account group's assertion. Access to the second risk is granted through the control objective. Risk management is then performed using the accessed first risk and second risk.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: storing a first link that links a first risk to an account group in a first table in a data structure of a database; storing a second link that links a second risk to a control objective in a second table in the data structure, wherein the control objective is an objective of a control for managing risk; and performing, by a computing device, risk management by accessing both the first risk through the account group and the second risk through the control objective, wherein the risk management requires that the first risk is accessible due to the account group being accessed first from the data structure before accessing the first risk and the second risk is accessible due to the control objective being accessed first from the data structure before accessing the second risk, wherein performing risk management comprises: accessing the account group from the data structure; accessing the first link in the first table, the first link accessible via accessing the account group; accessing the first risk using the first link, wherein the first risk is accessible due to the account group being accessed first from the data structure and then the first link being accessed via the account group and used to access the first risk; accessing the control objective from the data structure; accessing the second link in the second table, the second link accessible via the control objective; and accessing the second risk using the second link, wherein the second risk is accessible due to the control objective being accessed first from the data structure and then the second link being accessed via the control objective and used to access the second risk. 2. The method of claim 1 , further comprising: storing a third link that links a third risk to a central sub-process in a third table in the data structure; and accessing the central sub-process from the data structure; accessing the third link in the third table, the third link accessible via accessing the central sub-process; accessing the third risk using the third link, wherein the third risk is accessible due to the central sub-process being accessed first from the data structure and then the third link being accessed via the central sub-process and used to access the third risk. 3. The method of claim 1 , further comprising: linking the account group to a central sub-process, wherein the first risk is inherited to the central sub-process. 4. The method of claim 3 , wherein accessing the first risk comprises: determining an account group assertion for the account group from the central sub-process; and accessing the first risk for the account group assertion using the determined account group. 5. The method of claim 2 , further comprising linking the control objective to the central sub-process, wherein the second risk is inherited to the central sub-process. 6. The method of claim 5 , wherein accessing the second risk comprises: accessing the control objective from the central sub-process; and accessing the second risk using the determined control objective. 7. The method of claim 2 , further comprising copying the central sub-process to an organization to create a local sub-process, wherein the local sub-process inherits the first risk and the second risk from the central sub-process. 8. The method of claim 7 , further comprising storing a fourth link in the data structure linking the central sub-process with the local sub-process. 9. The method of claim 7 , further comprising: determining a request to remove one of the first risk or the second risk in the local sub-process; and storing information indicating the one of the first risk or the second risk that has been removed. 10. The method of claim 9 , wherein the removed one of the first risk or the second risk is not evaluated in risk management for the local sub-process. 11. The method of claim 7 , further comprising: determining a request to remove one of the control objective or the account group in the local sub-process; and storing information indicating the one of the control objective or the account group that has been removed, wherein the removed one of the control objective or the account group is not evaluated in risk management for the local sub-process. 12. The method of claim 1 , wherein performing risk management comprises performing risk assessment using data for the first risk and the second risk stored in the data structure. 13. The method of claim 12 , further comprising: determining a first control for the first risk and a second control for the second risk; and performing risk evaluation using the first control and the second control. 14. A non-transitory computer-readable storage medium containing instructions for controlling a computer system to perform a method, the method comprising: storing a first link that links a first risk to an account group in a first table in a data structure of a database; storing a second link that links a second risk to a control objective in a second table in the data structure, wherein the control objective is an objective of a control for managing risk; and performing risk management by accessing both the first risk through the account group and the second risk through the control objective, wherein the risk management requires that the first risk is accessible due to the account group being accessed first from the data structure before accessing the first risk and the second risk is accessible due to the control objective being accessed first from the data structure before accessing the second risk, wherein performing risk management comprises: accessing the account group from the data structure; accessing the first link in the first table, the first link accessible via accessing the account group; accessing the first risk using the first link, wherein the first risk is accessible due to the account group being accessed first from the data structure and then the first link being accessed via the account group and used to access the first risk; accessing the control objective from the data structure; accessing the second link in the second table, the second link accessible via the control objective; and accessing the second risk using the second link, wherein the second risk is accessible due to the control objective being accessed first from the data structure and then the second link being accessed via the control objective and used to access the second risk. 15. The non-transitory computer-readable storage medium of claim 14 , further comprising: storing a third link that links a third risk to a central sub-process in a third table in the data structure; and accessing the central sub-process from the data structure; accessing the third link in the third table, the third link accessible via accessing the central sub-process; accessing the third risk using the third link, wherein the third risk is accessible due to the central sub-process being accessed first from the data structure and then the third link being accessed via the central sub-process and used to access the third risk. 16. The non-transitory computer-readable storage medium of claim 14 , further comprising: linking the account group to a central sub-process, wherein the first risk is inherited to the central sub-process. 17. The non-transitory computer-readable storage medium of claim 15 , wherein accessing the first risk comprises: determining an account group assertion for the account group from the central sub-process; and accessing the first risk for the acco

Assignees

Inventors

Classifications

  • G06Q10/06Primary

    Resources, workflows, human or project management; Enterprise or organisation planning; Enterprise or organisation modelling · CPC title

  • Accounting · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9292808B2 cover?
Particular embodiments generally relate to providing risk management. In one embodiment, a first risk is linked to an account group assertion in a data structure. A second risk is linked to a control objective in the data structure. Access to the first risk is granted through the account group's assertion. Access to the second risk is granted through the control objective. Risk management is th…
Who is the assignee on this patent?
Yu Haiyang, Zeng Ying, Chiu Chihhe, and 7 more
What technology area does this patent fall under?
Primary CPC classification G06Q10/06. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Mar 22 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).