Platform
Financial Crime Compliance

Financial Crime Compliance Operations

Govern the whole financial-crime compliance programme on one operating system

The governance backbone of a financial-crime compliance programme — customer due diligence, risk rating, review scheduling, screening disposition, case handling, remediation and regulatory reporting working as one connected lifecycle instead of a patchwork of tools, spreadsheets and shared inboxes. OnyxOne governs and evidences the programme; where real-time detection is performed by a dedicated transaction-monitoring engine, OnyxOne integrates with it and takes ownership of the obligations, controls, cases and evidence that follow. Every check, decision, override and report is captured against the customer it belongs to, so the programme is defensible by design rather than reconstructed at examination time.

At a glance

How it works, visually

Onboarding-to-evidence lifecycleSchematic
1AlertRaised2TriagePrioritise3InvestigateEvidence4DecisionApprove5ReportAudit-loggedreopenClear ownership and recorded decisions at every stage — a defensible trail from alert to closure.

From onboarding and due diligence through review, approval and remediation to an evidenced, audit-logged outcome.

The challenge

The problems this module solves

The operational realities that make this hard for compliance and risk teams today.

The programme is stitched together from disconnected tools

Screening runs in one system, due diligence in another, monitoring in a third, and cases in a shared inbox. Analysts move data by hand between them, context is lost at every hop, and no single record shows the full AML history of a customer. The programme works despite its tooling, not because of it.

Alerts overwhelm the team

Poorly-tuned screening and monitoring generate a high volume of false positives. Analysts spend their time clearing noise, genuinely risky activity waits in the same queue as trivial name matches, and there is no reliable way to show a regulator that alerts are handled consistently.

Risk rating is inconsistent and undocumented

Customer risk is scored differently by different analysts, the rationale is not recorded, and re-rating on trigger events is manual and easily missed. When an examiner asks why a customer was rated low risk, the answer has to be reconstructed from memory and email.

Regulatory deadlines create pressure and risk

Suspicious-activity reporting and regulatory returns are assembled by hand under time pressure, pulling data from multiple systems. The process is slow, error-prone and hard to evidence — exactly where regulators focus their scrutiny.

Audit evidence is reconstructed, not captured

Because decisions are spread across tools and inboxes, preparing for an audit or examination means a scramble to rebuild the story after the fact. The evidence exists somewhere, but not as a single, timestamped, immutable trail.

The approach

How OnyxOne addresses it

One connected AML workflow

Onboarding, screening, due diligence, risk rating, monitoring, alert handling and reporting run on a single platform, all writing to the same customer record. An analyst sees the complete AML picture — every check, decision and alert — in one place instead of chasing it across systems.

Configurable screening tuned to your risk

Sanctions, PEP and adverse-media screening runs at onboarding and continuously, with match logic, fuzzy-name handling and thresholds you configure to control false positives. Screening data providers are contracted and configured per deployment rather than fixed to one named source.

A documented, policy-driven risk model

Customer risk is scored against your own risk-rating methodology — factors, weightings and thresholds you define. Ratings, the factors behind them and every re-rating on a trigger event are captured automatically, so the rationale is always on the record.

Structured alert and case handling

Screening and monitoring alerts are routed into a consistent workflow with ownership, SLAs, dispositions and four-eyes review. Analysts clear, escalate or convert alerts into investigations against a defined process, and every disposition is recorded with its reasoning.

Reporting assembled from the same record

Suspicious-activity reports and regulatory returns are built from the live customer and case record rather than reassembled by hand, with review and sign-off before submission and a full trail of who prepared and approved each one.

Capabilities

What's in the module

Turn on what you need and add more as your programme scales.

Customer onboarding & KYC/KYB

Collect, verify and record customer and business identity data as the front door to the AML programme.

Sanctions, PEP & adverse-media screening

Screen at onboarding and continuously, with configurable match logic and fuzzy-name handling.

Customer risk rating

Score risk against your own factors, weightings and thresholds, with re-rating on trigger events.

Ongoing transaction & event monitoring

Surface changes in customer and third-party risk between onboarding and review.

Alert management

Route, prioritise, disposition and audit screening and monitoring alerts on a defined workflow.

Four-eyes review & escalation

Enforce maker-checker review and structured escalation to investigations where policy requires.

Suspicious-activity reporting

Prepare, review and export SAR/STR content from the live case record with sign-off.

Case conversion

Convert alerts into full investigations in the case-management module without losing context.

Programme dashboards

Track alert volumes, ageing, SLA adherence and risk distribution across the programme.

Immutable audit trail

Every check, decision, override, rating and report is written to an append-only record.

The workflow

The enterprise workflow

A defined, end-to-end process with clear ownership at every stage.

The workflow, step by stepSchematic
01Onboard & screenNew customers and entities are onboarded with KYC/KYB data and screened againstsanctions, PEP and adverse-media sources, with matches captured against the record.02Risk-rateEach customer is scored against your risk-rating methodology, and the factors behindthe rating are recorded so the rationale is defensible.03Monitor continuouslyCustomers and entities are re-screened and monitored for events and behaviouralchange, surfacing shifts in risk after onboarding.04Triage alertsScreening and monitoring alerts enter a prioritised queue where analysts clear,escalate or convert them, each disposition recorded with reasoning.05Investigate & decideAlerts that warrant it become structured investigations with evidence, entity linksand four-eyes review before a documented decision is reached.06Report & preserveWhere required, suspicious-activity reports and regulatory returns are assembled,reviewed, signed off and preserved with a full audit trail.

Every result, decision and override is captured against the record it belongs to.

01

Onboard & screen

New customers and entities are onboarded with KYC/KYB data and screened against sanctions, PEP and adverse-media sources, with matches captured against the record.

02

Risk-rate

Each customer is scored against your risk-rating methodology, and the factors behind the rating are recorded so the rationale is defensible.

03

Monitor continuously

Customers and entities are re-screened and monitored for events and behavioural change, surfacing shifts in risk after onboarding.

04

Triage alerts

Screening and monitoring alerts enter a prioritised queue where analysts clear, escalate or convert them, each disposition recorded with reasoning.

05

Investigate & decide

Alerts that warrant it become structured investigations with evidence, entity links and four-eyes review before a documented decision is reached.

06

Report & preserve

Where required, suspicious-activity reports and regulatory returns are assembled, reviewed, signed off and preserved with a full audit trail.

The value

What your team gains

Unified

The whole programme in one record

Screening, due diligence, monitoring, alerts and reporting write to the same customer record, so analysts and examiners see one complete AML history.

Configurable

Fewer false positives

Match logic, thresholds and monitoring rules are tuned to your risk, so analysts spend time on genuine risk rather than clearing noise.

Documented

Defensible risk decisions

Ratings, dispositions and overrides are captured with their rationale as they happen, so answers to examiner questions already exist.

Audit-grade

Evidence captured, not rebuilt

An immutable, timestamped trail of every check and decision means audit and examination preparation is retrieval, not reconstruction.

Consistent handling under scrutiny

Defined workflows, SLAs and four-eyes review mean alerts and cases are handled the same way every time — the consistency regulators look for.

Faster, cleaner regulatory reporting

Reports are assembled from the live record with review and sign-off, reducing manual effort and the risk of error under deadline pressure.

Built for

Industries it serves

BankingFinancial ServicesFintechLendingPayments-adjacent regulated firmsInvestment FirmsInsuranceCorporate & Trust Service ProvidersGaming
Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.

Screening & data sources
  • Connects to the sanctions, PEP and adverse-media data providers contracted for your deployment
Identity & verification
  • Integrates with your existing identity-verification and KYC/KYB data services
Core banking & customer systems
  • Ingests customer and account data from your existing core systems to screen and monitor the right records
Regulatory reporting channels
  • Exports suspicious-activity and regulatory-return content in the formats your submission channels require
Collaboration & notification
  • Routes alerts, escalations and approvals through your existing email and messaging tools
Assurance

Security, compliance & reporting

Security & data handling

  • Customer records, screening results and case data are encrypted in transit and at rest.
  • Access is role-based, and segregation of duties prevents the same person from both raising and signing off a decision where policy forbids it.
  • Every screening result, rating, disposition, override and report is written to an append-only audit trail.
  • Sensitive AML data — including suspicious-activity information — is restricted to authorised roles and handled under strict need-to-know.
  • Data residency and retention are configurable to the regulatory obligations of your jurisdiction.

Compliance support

  • Supports AML/CFT obligations including customer due diligence (CDD), KYC and KYB
  • Underpins sanctions, PEP and adverse-media screening requirements
  • Supports ongoing monitoring and periodic-review obligations
  • Assists suspicious-activity / suspicious-transaction reporting (SAR/STR) workflows
  • Provides record-keeping and audit-trail evidence expected by AML supervisors
  • OnyxOne is a technology vendor, not an obliged entity — responsibility for AML obligations remains with your firm

Reports & exports

  • Suspicious-activity / suspicious-transaction report content (SAR/STR)
  • Customer risk-rating and re-rating reports
  • Alert volume, ageing and SLA-adherence reports
  • Screening-coverage and match-disposition reports
  • Case outcome and escalation reports
  • Programme dashboards and management information for the MLRO / compliance function
Best practice

How to get the most from it

Tune screening to your risk appetite

Invest in match logic, fuzzy-name handling and thresholds. Well-tuned screening is the single biggest lever on false-positive volume and analyst focus.

Record the rationale, always

Capture the reasoning behind every rating and disposition as it is made. The cheapest time to document a decision is when you make it, not at examination.

Enforce four-eyes where it matters

Use maker-checker review and segregation of duties on high-impact decisions so no single analyst can both raise and clear a material alert.

Re-rate on trigger events, not just on schedule

Configure trigger-based re-rating so risk keeps pace with real change in a customer, rather than waiting for the next periodic review.

FAQ

Questions, answered

Is OnyxOne a regulated or licensed AML provider?

No. OnyxOne is a technology vendor. It provides software that helps your firm run its AML programme; it is not a regulated financial institution and is not an obliged entity under AML law. Responsibility for meeting AML obligations remains with your firm.

Which screening data sources do you use?

Screening and data providers are contracted and configured per deployment rather than fixed to a single named partner. The platform applies your chosen sources through configurable match logic and thresholds.

How does OnyxOne reduce false positives?

Match logic, fuzzy-name handling, thresholds and monitoring rules are configurable to your risk appetite, and dispositions feed back into how alerts are prioritised — so analysts focus on genuine risk rather than clearing noise.

Does it produce suspicious-activity reports?

It assembles SAR/STR content from the live customer and case record with review and sign-off, and exports it in the formats your submission channels require. Submission to the authority remains an action your firm performs.

How is the programme kept audit-ready?

Every check, rating, disposition, override and report is written to an immutable, timestamped audit trail against the relevant record, so audit and examination preparation is a matter of retrieval rather than reconstruction.

See Financial Crime Compliance Operations in your programme

Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.