Simplifying Compliance

Cybersecurity is a painful, costly, and complex operation for large institutional banks. Our team set out to address this problem with an end-to-end traceability and compliance auditing tool, Cymetric.

Understanding the Challenge

Cybersecurity compliance in a global financial organization is a veritable nightmare. (Not an exaggeration.)

Imagine you are Chief Compliance Officer at Chase bank.

You manage a global cybersecurity program for tens of thousands of employees. You must slay a three-headed compliance dragon:

1.    Identifying which regulations to comply with, including current federal and state regulations like HIPPA or NYCRR-500; adding new regulations like GDPR into your compliance roadmap.

2.    Managing security control implementation and ownership across dozens of information systems and thousands of people.

3.    Providing gapless records to prove to auditors that the organization is truly compliant with all relevant regulations at all levels.

If you do your job improperly, there are dire penalties; for instance, non-compliance with GDPR means your organization may be fined up to €10 million, or 2% annual global turnover — whichever is higher.

Surprisingly, most of this type of sensitive compliance work is still being done by siloed, ad hoc teams using outdated tools like paper journals and excel spreadsheets. Given my team's expertise in software and our partner firm's deep working relationships with the target customer segment, we decided that this is a billion-dollar problem for which we can design a 10x better solution than what exists in the market today.

chat icon Objective

To create an end-to-end cybersecurity compliance solution for large institutions to ensure compliance with the latest regulations across all levels of the organization.

chat icon My Role

15% UX Researcher | 75% Product designer | 10% Frontend engineer

Sketch, Marvel, Zeplin, Abstract, Optimal Workshop, Atom, Bitbucket

chat icon Success metrics

  • % Compliance
  • Time to close compliance evaluations for auditors
  • Cost savings in non-compliance fees

chat icon Technology

Angular, Node, GraphQL, Docker, Postgres, Python, Authy, Google Material Design

The Compliance Lifecycle

To understand the functionality of Cymetric, let's take a look at the conceptual architecture of the compliance lifecycle:

1.    There are Regulations at State, Federal, and International Levels. These regulations can be mapped onto a security framework which taxonomizes and details the type of security controls for compliance.

2.     Each canonical security control may be applied to information systems, which may be owned by sub-organizations. Each control-information system pairing is known as a "control instance"

3.     Auditors would evaluate the compliance at the organization, information system, and control instance levels as one of 5 ratings (ranging from Fully Compliant to Non-Compliant.)

Research

After 6 expert interviews with members of the partner team and 5 contextual inquiries with auditors, I focused on the experiences of two main personas:

Persona 1

Compliance Officer: the compliance owner inside the organization.

    Jobs:
  • Manage information systems
  • Manage ownership of regulatory controls
  • Accountable for completion of tasks related to controls
  • Need to see both the forest and the trees
    Pains:
  • Poor understanding of ownership across departments
  • Each department has its own system for managing compliance - hard to see the forest
  • Have to work with auditors to understand where the gaps are and how to address them, but no direct control of the timeline for the completion of the audit
  • No standard way to do assessments; may work with multiple independent assessors
  • Hard to get to 100% compliance

Persona 2

Auditor: The external auditor who performs assessments on the organization, information system, and control instance levels.

Strategy

Research insights led us to understand that the most addressable aspects of the problem are:

  • Traceability of each team's compliance activities back to a regulation
  • Clear assignment of ownership for each task
  • Single source of truth for the entire organization
  • Allowing auditors to have access to past data in a comprehensive and organized fashion, reduce communication overhead with hundreds of individuals

This led to a sequential system design that is end-to-end, mapping out the relationship between each actor and each step of the compliance process. I focused on two main design strategies:

1.    I designed a sequential, step-wise navigation menu that follows the lifecycle of compliance activities, starting with managing information and ending with the audit.

2.    To reduce cognitive load, I optimized for familiar design patterns over newfangled ones; simple list-detail views. Lastly, I broke out complex processes as workflow-modals and gave the ability to reuse past audits to help auditors manager optimize their workflow.

Design

Design Constraints

1.    Massive number of features and data to work with; complex flows

Work-around:

2.    Working with a law firm and banks, we were deeply embedded within the sales cycle and had a lot of restrictions on the way in which we conducted customer interviews. The feedback cycles were short, but most of the feedback came from non-end-users.

Work-around:

Designing better flows

My design process starts with mapping out the main workflows for each persona. Important flows include:

1.    Searching for a control instance

2.    Viewing and managing pending controls and groups of pending controls

3.    Mapping assessments onto control instances

Contact Management

Our top research insight from auditors yielded that it is painful to work with such an astronomical number of people. Hence, I designed an integrated contact managment tool with the following considerations:

1.    Roles, not people, are the owners of a compliance objective. Hence, this CRM is designed around "contacts", knowing that people will change roles in the organization

2.    The responsibilities and information of each contact is in this database for reference, even if they are not a Cymetric user.

Navigational Clarity

The first task I set out to do was to map out the different list-detail views that will house the essential data for the compliance management lifecycle. My design process:

1.    Brainstorm list of datasets & objects to be presented with stakeholders

2.    Card sorting exercise with stakeholders and engineering team

3.    Qualitative testing and iterate from feedback

This navigation hierarchy was designed to conform to the natural workflow of domain experts. The flat architecture also allows Cymetric users to navigate fluidly between different parts of the compliance management lifecycle and for easy cross-referencing.

The data was rigorously analyzed to produce the navigational architecture based on the responses from interviews.

See details on the Navigation Design Process here.

Automated control instance management

As our research surfaced that compliance officers have a lot of trouble mapping controls onto information systems, one of the key value propositions of the system is to provide automated control instance generation based on inputs. The workflow becomes a simple two-step process:

1.    Create information system, adding regulatory objectives

2.    Approve automatically generated pending control instances and publish to organization

Security Control Management

As each information system must have a security control instance to meet a regulatory line item, I designed a simple process for compliance officers to easily look up and modify security controls active for their org.

Reuse of Assessment Flow for Auditors

One of the most painful problems surfaced during our research is the lack of traceability for past assessment work that has been done by previous auditors. Additionally, banks and auditors often elect to use an assessment that has been done in a previous year to cover a current-year requirement. Currently, the assessments are duplicated manually. I designed this feature to allow auditors to instantly reuse a previous audit.

Closing thoughts

Cymetric is a full-featured application that has instances running in production for 2 clients. Here's what I learned:

On the product design roadmap: