Prosecution Insights
Last updated: October 02, 2026
Application No. 18/920,708

SYSTEM AND METHOD FOR SAAS DATA CONTROL PLATFORM

Final Rejection §103
Filed
Oct 18, 2024
Priority
Oct 19, 2023 — provisional 63/591,690 +5 more
Examiner
RAHMAN, MAHFUZUR
Art Unit
2498
Tech Center
2400 — Computer Networks
Assignee
Royal Bank of Canada
OA Round
2 (Final)
91%
Grant Probability
Favorable
3-4
OA Rounds
6m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 91% — above average
91%
Career Allowance Rate
694 granted / 764 resolved
+32.8% vs TC avg
Moderate +8% lift
Without
With
+8.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
13 currently pending
Career history
780
Total Applications
across all art units

Statute-Specific Performance

§101
21.9%
-18.1% vs TC avg
§103
49.8%
+9.8% vs TC avg
§102
5.5%
-34.5% vs TC avg
§112
10.9%
-29.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 764 resolved cases

Office Action

§103
DETAILED ACTION This Office Action is in response to the amendment filed on 06/18/2026 in which claims 1-18 are presented for examination on the merits. Notice of Pre-AIA or AIA Status The present application is being examined under the first inventor to file provisions of the AIA . Response to Arguments 1. Applicant's arguments filed June 18, 2026 with respect to the rejection of claims 1-18 under 35 U.S.C. 103 as being unpatentable over Calado et al. (US 2023/0061234 A1, hereinafter Calado) in view of Kraus et al. (US 2020/0380160 A1, hereinafter Kraus) have been fully considered but are not persuasive, for the reasons set forth below. 2. Regarding independent claims 1, 7, and 13, rejected under 35 U.S.C. 103(a), applicant argues, for example: “The Applicant submits that Calado does not teach or suggest the claimed ‘receiving a plurality of documents containing rules’... However, there is no disclosure in Calado of ‘receiving a plurality of documents containing rules’, as recited by claim 1. Instead, the system of Calado appears to relate to a pre-existing graph database.” The argument is not persuasive. Calado expressly discloses that its graph database stores and manages a variety of data derived from documents that inherently contain rules, including at least one obligation represented by at least a portion of an entire law or regulation, at least one industry best practice represented by at least a portion of an entire industry best practice document, at least one policy represented by one or more documents within an organization that establishes one or more high-level operational requirements, and at least one standard represented by one or more documents subservient to a parent policy that contains more detailed requirements than its parent policy (Calado, Abstract; Paragraphs 0003-0004, 0008). Further, Calado discloses at least one mandate represented by one or more individual requirements identified from the obligation and the industry best practice (Calado, Paragraph 0008), confirming that the underlying documents (obligations, industry best practices, policies, standards) contain rules, i.e., mandates and requirements. Calado's Data Risk Management Engine 120 receives and organizes this data through an Enterprise Data Risk Ontology 122, Policy and Standards Hierarchy 124, and Standardized Risk and Control Catalog 126 (Calado, Fig. 1 and associated texts; Paragraph 0027), which necessarily involves receiving the underlying documents in order to populate the graph database with the rules and requirements contained therein. Applicant's assertion that Calado's system merely “relates to a pre-existing graph database” is not commensurate with the scope of claim 1, which recites no particular timing, order, or manner for the “receiving” step, and does not exclude a graph database that is itself populated by, or derived from, received documents. Although the claims are interpreted in light of the specification, limitations from the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). 3. Applicant further argues, for example: “Similarly, the Applicant submits that there is no teaching or suggestion of the claimed ‘converting each of said plurality of documents to a respective tree structure comprising a plurality of nodes’, as recited by claim 1... There is no disclosure in any of these passages relating to the conversion of a plurality of documents to a respective tree structure.” The argument is not persuasive. Calado discloses that its graph platform represents a hierarchy structure associated with a plurality of connected relationships, data types, and compliance obligations, policies, and standards, wherein various inputs are translated at various levels of the structure, including the relationships between nodes (Calado, Paragraphs 0006, 0009, 0012, 0032). Calado further discloses generating a tiered connected data structure between a first set and a second set of data associated with control objectives, policies, policy statements, standards, standard statements, and mandates (Calado, Paragraph 0009). A tiered, connected data structure organized through parent-child, nested relationships — for example, the “NESTED_UNDER,” “COMPRISED_OF,” and “CONTAINED_WITHIN” relationships illustrated in Fig. 3 among the Risk Taxonomy 310, Standardized Risk Library 320, External/Internal Obligations 330, and Governance Artifacts 340 nodes (Calado, Fig. 3) — reads on the claimed “tree structure comprising a plurality of nodes” under its broadest reasonable interpretation, since claim 1 recites no particular tree topology and does not exclude a hierarchically-organized graph. Because each document type in Calado (obligation, policy, standard, industry best practice) is translated into this hierarchically-organized set of nodes as part of building the tiered connected data structure, Calado teaches or suggests “converting each of said plurality of documents to a respective tree structure comprising a plurality of nodes,” as recited in claim 1. 4. Applicant further argues, for example: “Moreover, claim 1 recites a tree structure, which a person skilled in the art would understand is a hierarchical data structure having a single root node, parent-child relationships, and leaf nodes... Contrastingly, Calado uses a graph database and an ‘intelligent graph platform’, which a person skilled in the art would understand supports many-to-many relationships, non-hierarchical connections, and is fundamentally different from a tree structure.” After careful review, the Examiner respectfully disagrees and notes that a tree is itself a particular type of graph (i.e., a connected, acyclic graph), and the fact that Calado's overall data model is generally described using the term “graph” does not preclude that graph from containing, or being organized as, one or more hierarchical tree structures. Calado's Intelligent Graph Platform 130 is expressly described as “representing how data is structured through a plurality of connected relationships” (See, Calado, Paragraph 0008), which is broad enough to encompass hierarchical, tree-like relationships among nodes, and Calado's own data model depicts numerous parent-child, nested relationships as discussed above (Calado, Fig. 3 and associated texts, Paragraph 0009). Applicant's interpretation imposing a rigid definition on the claimed ‘tree structure’ — limited to a single root node with only parent-child relationships and excluding any many-to-many relationships — imports an unclaimed limitation from the specification (e.g., Figs. 6A-6B and associated texts) that does not appear in claim 1, and such limitations cannot be relied upon to distinguish over the prior art. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). Moreover, claim 1 itself contemplates that a node of the claimed “tree structure” also participates in relationships outside that tree structure, since claim 1 separately recites “generating a control mapping” relating the tree structure to a set of compliance controls; the claim thus does not require the tree structure to be an isolated, non-interconnected data structure, undermining Applicant's position that a tree structure cannot coexist within, or be derived from, a broader interconnected graph such as Calado's. 5. Applicant further argues, for example: “Claim 1 further recites ‘generating a tree mapping relating a first one of said respective tree structures to a second one of said respective tree structures’... Calado discloses generating a graphical representation illustrating relationships between control objectives, policies, and standards, but this is a visualization of relationships within a single graph, rather than a distinct mapping object between two independent tree data structures derived from two separate documents... Moreover, claim 1 recites ‘generating a control mapping’, which is also a separate mapping layer... The Applicant submits that Calado does not teach or suggest separate, independent mappings between controls and evidence, or between tree structures and compliance controls.” After careful review, the Examiner respectfully disagrees. Calado discloses generating a tiered connected data structure between a first and second set of data associated with control objectives, the policies, the policy statements, the standards, the standard statements, and the mandates (Calado, Paragraph 0009), which reads on the claimed “tree mapping.” Calado separately discloses generating a graphical representation illustrating a second set of relationships between data components comprising the control objectives and information, wherein a policy hierarchy generates evidence of compliance with each governance artifact pre-mapped to the control objective (See, Calado, Paragraphs 0009-0010), which reads on the claimed “control mapping.” Further, Calado discloses producing a set of control objectives for data commensurate with the identified sensitivity tier and criticality tier, wherein documenting and executing a control that is mapped to a control objective provides seamless evidence of compliance with each governance artifact pre-mapped to the control objective (Calado, Paragraphs 0009-0010), which reads on the claimed “evidence mapping.” Each of these mappings is separately generated and separately described in Calado. Nothing in claim 1 requires that the tree mapping, control mapping, and evidence mapping be embodied in physically distinct data objects, or precludes them from residing within a single interconnected graph database; claim 1 requires only that each mapping be generated, which Calado teaches. Applicant's characterization of Calado as a mere “visualization” that fails to constitute a “distinct mapping object” imports unclaimed structural requirements (e.g., a physically separate object, as in Fig. 7, object 620 of the specification) that are not recited in claim 1. See In re Van Geuns, supra. It is further noted that even if some structural distinction existed, the test for obviousness is not whether the features of a secondary reference may be bodily incorporated into the structure of the primary reference, but what the combined teachings would have suggested to one of ordinary skill in the art. In re Keller, 642 F.2d 413, 425, 208 USPQ 871, 881 (CCPA 1981); In re Sneed, 710 F.2d 1544, 1550, 218 USPQ 385, 389 (Fed. Cir. 1983). 6. Applicant further argues, for example: “The Kraus reference is cited only as purportedly disclosing determining a compliance score. The Applicant submits that Kraus does not remedy any of the above-identified deficiencies of Calado.” This argument is moot in view of the response set forth above, because Calado alone teaches or suggests each of the disputed limitations of claim 1, namely, receiving a plurality of documents containing rules, converting each of said documents to a respective tree structure, generating a tree mapping, and generating a control mapping. Kraus is cited, in combination with Calado, solely for its teaching of determining a compliance score for an entity based on compliance controls, compliance control evidence, and evidence mapping (Kraus, Paragraphs 0162, 0192-0193, 0203-0210), a limitation not separately argued by Applicant. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate Kraus's compliance-score determination into Calado's data risk management system for the advantage of enhancing cybersecurity and data categorization efficiency by providing reliable statistics that can be utilized for regulatory compliance, policy formulation or enforcement, data protection, forensic investigation, risk management, and evidence production (Kraus, Abstract). The Applicant has failed to clearly explain the pertinence of each cited passage, by failing to clearly articulate the difference between claim features and specification, with a convincing rationale and factual support. As is readily evident from the above, the claimed invention as a whole was at least prima facie obvious over the combined teachings of Calado and Kraus, especially in the absence of sufficient, clear, and convincing evidence to the contrary. Accordingly, the rejection of claims 1-18 under 35 U.S.C. 103 as being unpatentable over Calado in view of Kraus is maintained. Claim Rejections - 35 USC § 103 7. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 8. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 9. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. 10. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. 11. Claims 1-18 are rejected under 35 U.S.C. 103 as being unpatentable over Calado et al. (US 20230061234 A1, hereinafter, Calado) in view of Kraus et al. (US 20200380160 A1, hereinafter, Kraus). Regarding claim 1, Calado discloses a method for monitoring compliance of a computing system (Para 0032, 0005, 0002,0025: controls and metrics to monitor compliance with policies and standards, standard hierarchy), the method comprising: receiving a plurality of documents containing rules (Para 0008: the standards, the standard statements, the mandates, the obligations, and the industry best practices correspond to documents and requirements within an organization include one or more pre-configured rules. Para 0009: at least one policy represented by one or more documents within an organization that establishes one or more high-level operational requirements.); converting each of said plurality of documents to a respective tree structure comprising a plurality of nodes (0006, 0009, 0012, 0032: graph platform represent hierarchy structure associated with a plurality of connected relationships, data types, and compliance with law or regulation including obligations, policies and standards wherein various inputs are translated at various levels in the metrics including the relationships between the nodes); generating a tree mapping relating a first one of said respective tree structures to a second one of said respective tree structures (Para 0009: generating a tiered connected data structure between a first and second set of data associated with control objectives, the policies, the policy statements, the standards, the standard statements, and the mandates); generating a control mapping relating said first one of said respective tree structures to a set of one or more compliance controls (Para 0009-0010: generating a graphical representation illustrating a second set of relationships between data components comprising the control objectives and information wherein policy hierarchy generates evidence of compliance with each governance artifact pre-mapped to the control objective); generating an evidence mapping relating said set of one or more compliance controls to a set of compliance control evidence (Para 0009: producing a set of control objectives for data commensurate with the identified sensitivity tier and identified criticality tier associated with control objectives, the policies, the standards, the mandates, the obligations, and the industry best practices wherein documenting and executing a control that is mapped to a control objective provides seamless evidence of compliance with each governance artifact pre-mapped to the control objective); and [determining a compliance score for an entity based on said compliance controls, said compliance control evidence], and said evidence mapping (Para 0010: documenting and executing a control that is mapped to a control objective provides seamless evidence of compliance with each governance artifact mapped to the control objective ). Calado does not explicitly state but Kraus from the same or similar fields of endeavor teaches determining a compliance score for an entity based on said compliance controls, said compliance control evidence (Kraus, Para 0162, 0192-0193, 0203-0210: regulatory compliance tracks and produces evidence of compliance with regulations….calculate a weighted combination and statistics score and compute recommendations based on the results, regulatory compliance, policy formulation, policy enforcement, alert prioritization and data protection). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to determine a compliance score for an entity based on said compliance controls, said compliance control evidence as taught by Kraus in the teachings of Calado for the advantage of enhancing cybersecurity and data categorization efficiency by providing reliable statistics wherein the resulting statistics can be utilized for regulatory compliance, policy formulation or enforcement, data protection, forensic investigation, risk management, evidence production (Kraus, Abstract). Regarding claim 2, the combination of Calado and Kraus discloses the method of claim 1, wherein each of said mappings includes a set of weights (Calado, Para 0012, 0009: Risk and Compliance (GRC) system translates the various inputs into normalized scores and weighs the input scores based on the number of relationships associated with the node in the tiered data structure mapping). Regarding claim 3, the combination of Calado and Kraus discloses the method of claim 1, wherein said set of controls is decoupled from said set of compliance control evidence by said evidence mapping (Kraus, Para 0291, 0162: policy is included in the model that defines a many-to-one mapping in the hierarchy wherein set of controls are disjoint wherein regulatory compliance tracks or produces evidence of compliance with regulations). Regarding claim 4, the combination of Calado and Kraus discloses the method of claim 1, wherein each of said plurality of nodes has a unique identifying string assigned thereto (Kraus, Para 0125, 0078: : a string or enumeration value associated with computing nodes, for example). Regarding claim 5, the combination of Calado and Kraus discloses the method of claim 4, wherein said unique identifying string includes at least one of a name, a description, a data type, a version number, and/or a weight (Kraus, Para 0125, 0192-0193: a string or enumeration value identifies a sensitivity type wherein a weighted value is combined with data sensitivity statistic). Regarding claim 6, the combination of Calado and Kraus discloses method of claim 1, wherein each of said mappings is a tree structure comprising a set of weights (Kraus, Para 0162, 0192-0193, 0203-0210, 0291: regulatory compliance tracks and produces evidence of compliance with regulations. calculate a weighted combination and statistics score and compute recommendations based on the results, regulatory compliance, policy formulation, policy enforcement, alert prioritization and data protection wherein a policy is included in the model that defines a many-to-one mapping in the hierarchy). Regarding claim 7; Claim 7 is similar in scope to claim 1, and is therefore rejected under similar rationale (Further, Para 0123 of Calado teaches: computer-readable medium including a machine-readable storage device, a machine-readable storage substrate, a memory device, processors wherein computer program instructions are encoded). Regarding claim 8; Claim 8 is similar in scope to claim 2, and is therefore rejected under similar rationale. Regarding claim 9; Claim 9 is similar in scope to claim 3, and is therefore rejected under similar rationale. Regarding claim 10; Claim 10 is similar in scope to claim 4, and is therefore rejected under similar rationale. Regarding claim 11; Claim 11 is similar in scope to claim 5, and is therefore rejected under similar rationale. Regarding claim 12; Claim 12 is similar in scope to claim 6, and is therefore rejected under similar rationale. Regarding claim 13; Claim 13 is similar in scope to claim 1, and is therefore rejected under similar rationale (Further, Para 0123 of Calado teaches: computer-readable medium including a machine-readable storage device, a machine-readable storage substrate, a memory device wherein computer program instructions are encoded). Regarding claim 14; Claim 14 is similar in scope to claim 2, and is therefore rejected under similar rationale. Regarding claim 15; Claim 15 is similar in scope to claim 3, and is therefore rejected under similar rationale. Regarding claim 16; Claim 16 is similar in scope to claim 4, and is therefore rejected under similar rationale. Regarding claim 17; Claim 17 is similar in scope to claim 5, and is therefore rejected under similar rationale. Regarding claim 18; Claim 18 is similar in scope to claim 6, and is therefore rejected under similar rationale. Conclusion 12. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Witteman (US 20240242211 A1) discloses a method for automating financial regulatory compliance wherein a jurisdictional definition file based on a plurality of financial regulatory requirement is generated. 13. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MAHFUZUR RAHMAN whose telephone number is (571)270-7638. The examiner can normally be reached on Monday thru Friday. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yin-Chen Shaw can be reached on 571-272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MAHFUZUR RAHMAN/Primary Examiner, Art Unit 2498
Read full office action

Prosecution Timeline

Oct 18, 2024
Application Filed
Jan 24, 2026
Non-Final Rejection (signed) — §103
Mar 18, 2026
Non-Final Rejection mailed — §103
Jun 18, 2026
Response Filed
Aug 11, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743382
Key Management in Computer Processors
2y 10m to grant Granted Sep 22, 2026
Patent 12730865
AUTHENTICATION SYSTEM, AUTHENTICATION METHOD, AND COMPUTER READABLE MEDIUM
1y 11m to grant Granted Sep 08, 2026
Patent 12724859
WATERMARK PROCESSING
1y 9m to grant Granted Sep 01, 2026
Patent 12712716
QUANTUM-BASED DISTRIBUTED LEDGER
2y 1m to grant Granted Aug 18, 2026
Patent 12712885
SYSTEM FOR SIMPLIFYING EXECUTABLE INSTRUCTIONS FOR OPTIMISED VERIFIABLE COMPUTATION
1y 12m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
91%
Grant Probability
99%
With Interview (+8.4%)
2y 6m (~6m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 764 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month