Case Management & Investigations
Turn alerts into closed, defensible cases
A single workspace where alerts, referrals and incidents become structured cases — investigated with the full picture, decided on a defined workflow, and closed with an audit trail that stands up to scrutiny. Investigators stop chasing context across systems and shared inboxes; the evidence, entity links, decision history and sign-off all live on the case itself, so every conclusion is documented and every case is defensible.
How it works, visually
Alert, triage, investigate, decide, report — with clear ownership and a defensible trail at every stage.
The problems this module solves
The operational realities that make this hard for compliance and risk teams today.
Investigations happen in inboxes and spreadsheets
Alerts land in a shared mailbox, evidence is gathered over email, and progress is tracked in a spreadsheet. Nothing is a system of record. Handovers lose context, cases stall silently, and there is no reliable way to show how — or how consistently — a decision was reached.
Context is scattered across systems
To understand a case, an investigator pulls the customer record from one place, screening results from another, prior alerts from a third, and related parties from memory. Building the full picture is slow manual work, and important links between people, entities and events get missed.
No consistent process or ownership
Without a defined workflow, similar cases are handled differently depending on who picks them up. Ownership is unclear, SLAs are informal, and reviews are ad hoc — the inconsistency that regulators and auditors single out.
Decisions aren't documented as they're made
The reasoning behind a disposition often lives only in the investigator's head or a stray email. When a decision is later questioned, the rationale has to be reconstructed, and the evidence base may no longer be intact.
Segregation of duties is hard to enforce
In manual processes the same person can raise, investigate and close a case. Enforcing that a decision is independently reviewed — and proving it was — is difficult without a system built around roles and sign-off.
How OnyxOne addresses it
Every alert becomes a structured case
Alerts, referrals and incidents are routed into cases with a consistent structure — subject, type, priority, owner, linked records and status. From the moment it opens, a case is a system of record, not a mailbox thread.
The full picture on one screen
The case pulls together the customer or entity record, screening results, prior alerts, related parties and evidence in one workspace. Investigators link people, entities and events to build the complete picture instead of assembling it by hand.
Defined workflows with ownership and SLAs
Cases move through configurable stages with clear ownership, due dates and SLAs. Work is assigned by role and workload, escalations follow defined paths, and nothing sits unowned or invisible.
Decisions captured with their reasoning
Every disposition, note and override is recorded on the case with its rationale as it happens. The case closes with a documented account of what was decided and why — the trail an auditor or regulator expects.
Four-eyes review and segregation of duties
Role-based assignment, review and approval enforce maker-checker separation where policy requires it, so the person who investigates a case is not the one who unilaterally signs it off. The controls are built in, and their operation is evidenced.
What's in the module
Turn on what you need and add more as your programme scales.
Case intake & routing
Turn alerts, referrals and incidents into cases and route them by type, priority and workload.
Investigation workspace
A single screen bringing together records, screening results, prior alerts, related parties and evidence.
Entity & relationship linking
Link people, organisations and events to reveal connections and build the full picture of a case.
Evidence attachment & chain
Attach documents, screenshots and system records to the case with a preserved history of what was added and when.
Configurable workflows & SLAs
Define case stages, ownership, due dates and escalation paths to match your operating model.
Timeline & activity view
A chronological view of everything that happened on a case, from intake to closure.
Notes & disposition capture
Record findings, reasoning and dispositions inline, so the rationale lives on the case.
Four-eyes review & sign-off
Enforce maker-checker review and role-based approval before a case can close.
Collaboration & assignment
Assign, reassign and collaborate across the team with clear ownership at every stage.
Immutable audit trail
Every action, decision, override and change is written to an append-only record.
The enterprise workflow
A defined, end-to-end process with clear ownership at every stage.
Every result, decision and override is captured against the record it belongs to.
Intake
Alerts, referrals and incidents are captured as cases with type, priority and subject, and routed to the right queue or owner.
Assign & own
Each case is assigned by role and workload, with a clear owner, due date and SLA from the outset.
Investigate
The investigator works from a single workspace — records, screening results, prior alerts and related parties — linking entities and gathering evidence.
Document the decision
Findings, reasoning and the proposed disposition are recorded on the case as the investigation concludes.
Review & approve
Where policy requires, an independent reviewer applies four-eyes sign-off before the case can be closed.
Close & preserve
The case closes with its outcome, rationale and full evidence base preserved in an immutable trail, ready for audit or regulatory review.
What your team gains
The full picture in one place
Records, evidence, entity links and decision history live on the case, so investigators stop reassembling context across systems.
Every case handled the same way
Defined workflows, ownership and SLAs replace ad-hoc handling with the consistency auditors and regulators expect.
Documented, auditable outcomes
Each case closes with its rationale and evidence intact, so a decision questioned months later is already fully accounted for.
Segregation of duties, evidenced
Four-eyes review and role-based sign-off are enforced and recorded, proving that decisions were independently reviewed.
Nothing falls through the cracks
Clear ownership, SLAs and escalation paths mean cases don't stall silently in a shared inbox.
Faster, calmer audits
Because evidence is captured as work happens, responding to an audit or examination is retrieval rather than a reconstruction scramble.
Industries it serves
Works with your existing systems
Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.
- Receives alerts from your screening, monitoring and AML modules and turns them into cases automatically
- Connects to your existing customer and entity systems so investigators work from the authoritative record
- Attaches evidence from your existing document repositories and preserves it on the case
- Aligns case ownership and review with your existing identity provider and role directory
- Routes assignments, escalations and approvals through your existing email and messaging channels
Security, compliance & reporting
Security & data handling
- Case data, evidence and decisions are encrypted in transit and at rest.
- Role-based access controls who can view, investigate, review and close a case, with need-to-know restrictions on sensitive cases.
- Segregation of duties prevents the same person from both raising and signing off a case where policy forbids it.
- Every action, note, disposition and override is written to an append-only audit trail.
- Evidence is preserved with a record of what was added and when, protecting the integrity of the case file.
- Data residency and retention for case records are configurable to your regulatory obligations.
Compliance support
- Supports investigation and record-keeping expectations under AML/CFT regimes
- Underpins suspicious-activity investigation and escalation workflows
- Provides segregation-of-duties and four-eyes evidence for governance and audit
- Supports incident, complaint and whistleblowing investigation obligations
- Supplies documented, timestamped evidence for internal audit and regulatory examination
Reports & exports
- Case status, ageing and SLA-adherence reports
- Case outcome and disposition reports
- Investigator and team workload reports
- Escalation and four-eyes review reports
- Full case files with timeline and evidence for audit or regulatory request
- Management information on case volumes and trends
How to get the most from it
Make every alert a case, not an email
Route alerts into structured cases from the start. The moment work happens in a shared inbox, it stops being defensible.
Capture reasoning inline
Record findings and rationale on the case as the investigation proceeds, not afterwards. Contemporaneous notes are the strongest evidence.
Enforce four-eyes on material decisions
Use role-based review so significant dispositions are independently signed off — and so you can prove they were.
Link entities early
Connect related people, organisations and events as they surface. Relationship links are what reveal patterns a single-record view would miss.
Questions, answered
How do alerts become cases?
Alerts, referrals and incidents from screening, monitoring and other modules are routed into structured cases automatically, with type, priority, subject and owner, so investigation starts from a system of record rather than a mailbox.
Can we configure our own case workflow?
Yes. Case stages, ownership rules, SLAs, escalation paths and the points at which four-eyes review is required are all configurable to your operating model and policy.
How is segregation of duties enforced?
Role-based assignment and approval separate investigation from sign-off where your policy requires it, so the person who investigates a case cannot unilaterally close it — and the review is recorded as evidence.
What happens to the evidence when a case closes?
The full case file — timeline, notes, dispositions, entity links and attached evidence — is preserved in an immutable trail, ready to be retrieved for audit or a regulatory request.
Does this connect to AML screening and monitoring?
Yes. Case Management is the destination for alerts raised by the screening, monitoring and AML modules, and it pulls the relevant customer and entity records so investigators work with the full context.
Related modules
See Case Management & Investigations in your programme
Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.