Platform
Knowledge & Records

Document Repository

One versioned store for compliance documents and records

A central, access-controlled repository for compliance documents and records, with versioning, retention and an audit trail, so supporting material is preserved, findable and produced on demand for audit or regulatory request. A compliance programme runs on documents — policies, evidence, correspondence, reports, records of decisions — and when they are scattered across shared drives, inboxes and personal folders, the firm cannot be sure what it holds, which version is current, or that a record still exists when it is needed. OnyxOne Document Repository gives the programme one governed store where every document is versioned, retained to policy, controlled by role and traceable end to end.

At a glance

How it works, visually

Where this sits in the platformSchematic
Data sources & inputsCustomers · vendors · transactions · documents · your systems of recordIngestion & screeningOnboarding · sanctions, PEP & adverse-media screening · capture & normalisationRisk, case & monitoring enginesRisk scoringCase & investigationOngoing monitoringControls, evidence & policyControls library · testing · evidence capture · policy mappingReporting & analyticsDashboards · regulatory returns · executive & board reportingIntegrations & audit trailAPIs & connectors · append-only, timestamped audit trailOne layered platform — every layer feeds the next, and every action lands in the audit trail.

The layered platform architecture — how sources, engines, controls, reporting and the audit trail connect.

The challenge

The problems this module solves

The operational realities that make this hard for compliance and risk teams today.

Documents are scattered and no one knows what's held

Records live on shared drives, in inboxes and on individual laptops, with no single index. When someone asks whether the firm holds a particular document, the honest answer is often that no one can be certain until they go looking.

No one is sure which version is current

Copies proliferate — draft, final, final-v2, the one someone edited locally — and without controlled versioning it is unclear which is authoritative. Decisions get made against a superseded document because it looked like the right one.

Records aren't retained or disposed to policy

Some records are deleted too early and are gone when a regulator asks; others are kept long past their retention period, becoming a liability. Without governed retention, the firm neither reliably keeps what it must nor disposes of what it should.

Producing evidence on demand is slow and stressful

When an auditor or regulator requests documents, assembling them means hunting across systems and people under time pressure. The material usually exists, but proving the firm holds it — and finding it fast — is a scramble.

No trail of who did what to a record

Who accessed, changed or downloaded a document, and when, is invisible on a shared drive. For sensitive compliance records that lack of traceability is itself a control weakness the firm cannot answer for.

The approach

How OnyxOne addresses it

One governed store the firm can trust

Compliance documents and records live in a single, indexed repository, so the firm knows what it holds rather than hoping someone can find it. There is one place to look, and one answer to whether a record exists.

Controlled versioning with a clear current version

Every document is versioned, with the current authoritative version unambiguous and prior versions preserved. Decisions rest on the right version, and the history of how a document changed is retained rather than scattered across copies.

Retention and disposition to policy

Records are held for their defined retention period and disposed of when it ends, driven by policy rather than by chance. The firm reliably keeps what it must and removes what it should, so retention is a control rather than an accident.

Fast, governed production on demand

Because documents are indexed, tagged and searchable in one place, assembling material for an audit or regulatory request is retrieval rather than a hunt. The firm can produce what it holds quickly and be confident it has found everything relevant.

Full traceability on every record

Access, changes and downloads are recorded on an append-only trail, so who did what to a document, and when, is always answerable. Sensitive compliance records carry the traceability their sensitivity demands.

Capabilities

What's in the module

Turn on what you need and add more as your programme scales.

Central document store

Hold compliance documents and records in one indexed repository, so the firm knows what it holds and where.

Version control

Version every document with an unambiguous current version and full prior history preserved.

Retention scheduling

Apply retention periods by document type and dispose of records to policy when the period ends.

Legal hold

Suspend disposition on records subject to a hold so nothing under investigation or dispute is removed.

Access control

Govern who can view, edit, download or manage each document by role and need-to-know.

Metadata & tagging

Classify documents by type, owner, jurisdiction and linkage so they can be organised and filtered.

Search & retrieval

Find documents fast by content, metadata and tags, so production on demand is retrieval, not a hunt.

Record linkage

Link documents to the cases, policies, controls and obligations they support, so evidence sits with its context.

Evidence pack assembly

Assemble the documents relevant to an audit or request into a produced pack quickly and completely.

Immutable access & change trail

Record every access, edit, version and download in an append-only audit history.

Dashboards

The views your team works from

Purpose-built dashboards and views, each answering a question a specific role needs to act on.

An executive viewIllustrative
ILLUSTRATIVE EXAMPLEOPEN CASES128SLA ADHERENCE96%SCREENING ALERTS1.2kOVERDUE REVIEWS14Cases by categoryAMLKYCFraudSanctionsConductOtherRisk mixby tierHighMediumLow

A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.

Document inventory

Everything the repository holds by type, owner and jurisdiction, so the firm's holdings are visible at a glance.

Retention & disposition

Records against their retention schedules, showing what is due for disposition and what is on hold.

Legal hold

Records currently under hold, so nothing subject to investigation or dispute is at risk of removal.

Access & activity

Access, changes and downloads across sensitive records, surfacing unusual handling for review.

Production readiness

How quickly and completely documents can be assembled for a request, highlighting gaps before an auditor finds them.

Automation

What the platform automates

Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.

Retention scheduling

Retention periods run automatically by document type, driving disposition when a period ends unless a hold applies.

Legal-hold enforcement

A hold automatically suspends disposition on the affected records, so nothing under investigation is removed.

Version capture

Each change is captured as a new version automatically, preserving the prior version without manual effort.

Classification prompts

Documents added without required metadata are flagged automatically so they are classified rather than lost.

Evidence-pack assembly

Relevant documents for a request are gathered into a pack automatically from their links and tags for review before production.

AI assistance

Where AI helps the analyst

Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.

Content search assistance

Helps find relevant documents by meaning as well as keyword, for the user to confirm — it retrieves, it does not decide relevance.

Classification suggestion

Suggests document type and tags from content to speed capture, which a person confirms before the record is filed.

Production-set drafting

Proposes a candidate set of documents for an audit or request from links and tags, which a person reviews and approves before anything is produced.

The workflow

The enterprise workflow

A defined, end-to-end process with clear ownership at every stage.

The workflow, step by stepSchematic
01CaptureDocuments and records are added to the repository, classified by type, owner andjurisdiction, and indexed for search.02VersionEach change creates a new version with the current authoritative version clear andprior versions preserved.03Control accessRole and need-to-know permissions govern who can view, edit, download or manage eachdocument.04LinkDocuments are linked to the cases, policies, controls and obligations they support,so evidence sits with its context.05Retain & holdRetention periods run by policy, disposition happens when they end, and legal holdssuspend removal where required.06ProduceFor an audit or request, relevant documents are searched, assembled into a pack andproduced quickly and completely.

Every result, decision and override is captured against the record it belongs to.

01

Capture

Documents and records are added to the repository, classified by type, owner and jurisdiction, and indexed for search.

02

Version

Each change creates a new version with the current authoritative version clear and prior versions preserved.

03

Control access

Role and need-to-know permissions govern who can view, edit, download or manage each document.

04

Link

Documents are linked to the cases, policies, controls and obligations they support, so evidence sits with its context.

05

Retain & hold

Retention periods run by policy, disposition happens when they end, and legal holds suspend removal where required.

06

Produce

For an audit or request, relevant documents are searched, assembled into a pack and produced quickly and completely.

The value

What your team gains

Central

One place, one answer

A single governed store means the firm knows what it holds, instead of hoping someone can find a record scattered across drives and inboxes.

Versioned

Always the right version

Controlled versioning makes the current authoritative document unambiguous and preserves its history, so decisions never rest on a superseded copy.

Governed

Retention as a control

Policy-driven retention and disposition mean the firm reliably keeps what it must and removes what it should, rather than leaving it to chance.

On demand

Production, not a scramble

Indexed, searchable records turn an audit or regulatory request into fast retrieval, with confidence that everything relevant has been found.

Full traceability

An append-only trail of access, changes and downloads means who did what to a record, and when, is always answerable — the traceability sensitive records demand.

Evidence in its context

Linking documents to the cases, policies and controls they support keeps supporting material connected to what it evidences, not stranded in a folder.

Built for

Industries it serves

BankingFinancial ServicesFintechInsuranceInvestment FirmsAsset ManagementCorporate & Trust Service ProvidersLegal FirmsRegulated Enterprises
Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.

Platform modules
  • Stores and links the documents that support cases, policies, controls, due diligence and reporting across the platform
Evidence management
  • Holds the underlying documents behind assurance evidence so material is captured once and reused
Policy & procedure
  • Keeps versioned policy documents and their history in one governed store alongside the rest of the record
Regulatory knowledge
  • Supplies the source regulation, guidance and reference documents the knowledge base cites
Existing document stores
  • Connects to your existing content and file-storage systems so material can be brought under governed control
Assurance

Security, compliance & reporting

Security & data handling

  • Documents are encrypted in transit and at rest, with access governed by granular, role-based and need-to-know permissions.
  • Sensitive records can be restricted to named roles, so a document is never visible to someone without the right to see it.
  • Legal hold suspends disposition on records under investigation or dispute, so nothing that must be preserved is removed.
  • Every access, edit, version and download is written to an append-only audit trail, so handling of a record is always traceable.
  • Retention and disposition run to defined policy, so records are neither lost early nor kept beyond their period.
  • Data residency and retention are configurable to your regulatory and jurisdictional obligations.

Compliance support

  • Supports records-management and document-retention obligations across the programme
  • Provides the versioned, traceable document evidence expected in audit and regulatory examination
  • Underpins legal-hold and preservation requirements for records under investigation or dispute
  • Keeps supporting material linked to the cases, policies and controls it evidences
  • Supplies a dated, append-only trail of access and change for every record

Reports & exports

  • Document inventory and coverage reports by type, owner and jurisdiction
  • Version-history reports per document
  • Retention-schedule and upcoming-disposition reports
  • Legal-hold status reports
  • Access and download audit reports for sensitive records
  • Evidence-pack and production reports for audits and requests
Best practice

How to get the most from it

One store, not many copies

Bring records into a single governed repository rather than letting copies live on drives and in inboxes. The proliferation of copies is exactly what makes the current version and the true holding uncertain.

Classify on the way in

Tag type, owner, jurisdiction and linkage as documents are captured. Metadata added later, if ever, is what turns a request into a hunt; metadata added up front makes production fast.

Let retention run to policy

Drive retention and disposition from policy rather than individual judgement. Records kept too long are a liability and records deleted too early are a gap — both come from ad hoc decisions.

Apply holds before you dispose

Ensure legal hold reliably suspends disposition on anything under investigation or dispute. Automated retention without a working hold can destroy exactly the record that must be preserved.

FAQ

Questions, answered

What does the repository store?

The documents and records a compliance programme runs on — policies, evidence, correspondence, reports and records of decisions — in one governed, indexed store. The point is that the firm knows what it holds and where, rather than hoping a record can be found across scattered drives and inboxes.

How does versioning work?

Every document is versioned, with the current authoritative version unambiguous and all prior versions preserved. Decisions rest on the right version rather than a look-alike copy, and the history of how a document changed is retained in one place instead of scattered across renamed files.

How are retention and disposition handled?

Retention periods are applied by document type and run to policy, with records disposed of when their period ends — while legal hold suspends disposition on anything under investigation or dispute. The firm reliably keeps what it must and removes what it should, so retention is a control rather than an accident.

How quickly can we produce documents for an audit?

Because documents are indexed, tagged, searchable and linked to the cases, policies and controls they support, assembling material for an audit or regulatory request is retrieval rather than a hunt. Relevant documents can be searched and assembled into a produced pack quickly, with confidence that everything relevant has been found.

Can we see who accessed or changed a record?

Yes. Every access, edit, version and download is written to an append-only audit trail, so who did what to a document, and when, is always answerable. For sensitive compliance records that traceability is itself part of the control, not an afterthought.

See Document Repository in your programme

Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.