Platform
Governance

Governance

Roles, approvals and accountability across the whole programme

The oversight layer of the platform — roles, committees, delegation, approvals and segregation of duties — so the right people make and sign off the right decisions, and accountability is clear and evidenced across every module. OnyxOne Governance replaces org charts in slide decks and approval trails in email with a live model of who is responsible for what, what they are allowed to approve, and a durable record of every decision they made.

At a glance

How it works, visually

The governance modelSchematic
Board & audit committeeSets risk appetite · holds the programme accountable1st lineOperational managementOwns and manages risk dayto day2nd lineRisk & complianceSets policy, oversees andmonitors3rd lineInternal auditIndependent, objectiveassuranceExternal audit & regulators

Oversight and the three lines of defence — how accountability is structured across the programme.

The challenge

The problems this module solves

The operational realities that make this hard for compliance and risk teams today.

Accountability is assumed, not defined

Everyone believes someone owns a control, a policy or a risk — until something fails and it turns out no one did. Responsibilities live in job descriptions and folklore rather than a system, so when a regulator asks 'who is accountable for this', the answer takes a week to assemble and still has gaps.

Approvals happen in email and meetings

Material decisions — signing off a policy, accepting a risk, approving an exception — are made over email or in a committee with minutes nobody can find. There is no durable, queryable record of who approved what, when, and on what basis, so sign-off cannot be produced on demand.

Segregation of duties exists on paper only

Policy says the person who prepares a decision should not be the one who approves it, but nothing enforces it. The same individual drafts and signs off, or a leaver keeps approval rights for months, and the breach only surfaces in an audit finding.

Delegations are invisible and never expire

When an approver goes on leave, authority is handed over informally. There is no record of who holds delegated authority, for what, or until when — so decisions get made by people who technically should not be making them, and reversing a delegation is a scramble.

Committees run on disconnected documents

Boards and committees govern the programme, but their packs, agendas, decisions and actions live in shared drives and inboxes disconnected from the risks, policies and controls they oversee. Oversight becomes a document exercise rather than a live line of sight into the programme.

The approach

How OnyxOne addresses it

A live model of roles and responsibilities

Define roles, committees and reporting lines once, and map every responsibility — for a risk, a control, a policy, an obligation — to a named role rather than a person who might move on. Accountability becomes a queryable fact: point at anything in the platform and see who is responsible, who is accountable and who must be consulted or informed.

Approvals captured as durable, structured decisions

Every approval across the platform — policy sign-off, risk acceptance, exception, treatment plan — is recorded as a structured decision with who approved it, when, against which version and on what basis. Sign-off stops being an email thread and becomes an auditable record you can produce instantly.

Segregation of duties enforced by the platform

Configure segregation-of-duties rules so the person who prepares a decision cannot also approve it, and conflicting roles cannot be held at once. The platform blocks the conflict at the point of action rather than surfacing it in a later audit, and flags toxic role combinations for review.

Delegated authority that is explicit and time-boxed

Delegations are granted formally, scoped to specific decisions or limits, and carry an expiry. Everyone can see who currently holds authority for what, delegated authority lapses automatically, and the full chain of who decided under whose authority is preserved.

Committee governance connected to the programme

Run committees on the platform — agendas assembled from live risk, policy and control data, decisions recorded against the items they concern, and actions tracked to closure. Oversight is anchored to the real programme rather than to a static pack prepared the week before.

Capabilities

What's in the module

Turn on what you need and add more as your programme scales.

Roles & responsibility model

Define roles, committees and reporting lines, and map responsibility, accountability and consultation for every governed object.

RACI mapping

Assign responsible, accountable, consulted and informed roles to risks, controls, policies and obligations for unambiguous ownership.

Approval authority matrix

Configure who can approve what, up to which limits, with authority derived from role rather than named individual.

Segregation-of-duties rules

Enforce incompatible-duty and conflicting-role rules at the point of action, blocking breaches before they happen.

Delegated authority

Grant scoped, time-boxed delegations that expire automatically and preserve the full chain of authority.

Committee & meeting management

Assemble agendas from live programme data, record decisions against the items they concern and track actions to closure.

Decision register

A central, structured record of every material decision — approvals, acceptances, exceptions — with basis and version.

Attestation of responsibilities

Ask role-holders to confirm they understand and accept their responsibilities, with tracked coverage.

Access & role certification

Periodically recertify who holds which roles and approval rights, removing access that is no longer justified.

Immutable governance trail

Every role change, delegation, approval and committee decision is written to an append-only audit record.

Dashboards

The views your team works from

Purpose-built dashboards and views, each answering a question a specific role needs to act on.

An executive viewIllustrative
ILLUSTRATIVE EXAMPLEOPEN CASES128SLA ADHERENCE96%SCREENING ALERTS1.2kOVERDUE REVIEWS14Cases by categoryAMLKYCFraudSanctionsConductOtherRisk mixby tierHighMediumLow

A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.

Accountability map

A live view of who is responsible and accountable for every risk, control, policy and obligation, navigable by role or by object.

Approvals & decisions

The decision register with pending approvals, recent sign-offs and the basis for each, filterable by type, approver and period.

Segregation-of-duties monitor

Current SoD conflicts, blocked actions and toxic role combinations flagged for review, with status and owner.

Delegations board

Every active delegation with its scope and expiry, plus authority due to lapse, so cover never outlives its purpose.

Committee cockpit

Agendas, decisions and open actions for each committee, anchored to the programme items under oversight.

Automation

What the platform automates

Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.

Role-driven approval routing

Decisions route automatically to the correct approver based on role and authority limits, with escalation when they stall.

Delegation expiry

Delegated authority lapses on its expiry date without manual intervention, and holders are reminded before it does.

SoD conflict blocking

Actions that would breach a segregation-of-duties rule are blocked at source and raised for review rather than silently allowed.

Recertification campaigns

Periodic role and access recertification is launched on schedule, chasing outstanding confirmations automatically.

Committee action follow-up

Actions arising from committee decisions are assigned, reminded and escalated until closed.

AI assistance

Where AI helps the analyst

Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.

Conflict-of-duty surfacing

Highlights potentially incompatible role and approval combinations across the model for a human to review and confirm, helping find conflicts that manual review misses.

Decision summarisation

Drafts concise summaries of committee decisions and their basis from the record, which the responsible role reviews and edits before it stands.

Accountability-gap detection

Flags governed objects with missing or ambiguous ownership so a person can assign the right accountable role, never assigning it automatically.

The workflow

The enterprise workflow

A defined, end-to-end process with clear ownership at every stage.

The workflow, step by stepSchematic
01Model roles & committeesDefine the roles, committees and reporting lines that govern the programme, and theresponsibilities each one carries.02Assign accountabilityMap responsible and accountable roles to risks, controls, policies and obligationsso ownership of everything governed is explicit.03Configure authority & SoDSet the approval-authority matrix and segregation-of-duties rules so the platformknows who may approve what and which duties must stay separate.04Operate approvals & delegationDecisions route to the right approvers by role; delegated authority is granted withscope and expiry when cover is needed.05Govern in committeeCommittees review live risk, policy and control data, record decisions against theitems concerned and assign actions with owners.06Certify & evidenceRoles and access are periodically recertified, and the full decision and delegationhistory stands as governance evidence for audit and the board.

Every result, decision and override is captured against the record it belongs to.

01

Model roles & committees

Define the roles, committees and reporting lines that govern the programme, and the responsibilities each one carries.

02

Assign accountability

Map responsible and accountable roles to risks, controls, policies and obligations so ownership of everything governed is explicit.

03

Configure authority & SoD

Set the approval-authority matrix and segregation-of-duties rules so the platform knows who may approve what and which duties must stay separate.

04

Operate approvals & delegation

Decisions route to the right approvers by role; delegated authority is granted with scope and expiry when cover is needed.

05

Govern in committee

Committees review live risk, policy and control data, record decisions against the items concerned and assign actions with owners.

06

Certify & evidence

Roles and access are periodically recertified, and the full decision and delegation history stands as governance evidence for audit and the board.

The value

What your team gains

Unambiguous

Accountability you can point at

Responsibility for every risk, control and policy maps to a named role, so 'who owns this' is answered instantly rather than assembled after the fact.

Auditable

Every decision on the record

Approvals, acceptances and exceptions are captured as structured decisions with basis and version, ready to produce on request.

Enforced

Segregation of duties that holds

Incompatible-duty rules are enforced at the point of action, so conflicts are prevented rather than discovered in an audit finding.

Controlled

Delegated authority without drift

Delegations are scoped and time-boxed and lapse automatically, so authority never quietly outlives the reason it was granted.

Committees anchored to the real programme

Oversight works from live risk, policy and control data rather than a static pack, so governance reflects the current position.

A clean three-lines-of-defence picture

Clear role separation and mapped accountability make the operation of the three-lines model visible and defensible to audit and regulators.

Built for

Industries it serves

Financial ServicesBankingInsuranceInvestment FirmsFintechCorporate & Trust Service ProvidersRegulated EnterprisesPublic SectorGaming
Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.

Identity & directory
  • Aligns roles, reporting lines and approval rights with your existing identity provider and HR directory so leavers and movers update authority automatically
Risk, controls & policy
  • Maps accountability onto the risks, controls, policies and obligations held in the other OnyxOne modules for end-to-end ownership
Board & committee tooling
  • Connects committee agendas, decisions and actions to your existing board-portal and document workflows
Access governance
  • Feeds role and approval-right certifications into your existing access-review and joiner-mover-leaver processes
Collaboration & notification
  • Routes approval requests, delegations and committee actions through your existing email and messaging channels
Assurance

Security, compliance & reporting

Security & data handling

  • Roles, delegations and decisions are encrypted in transit and at rest, with access governed by granular, role-based permissions.
  • Segregation-of-duties enforcement prevents incompatible responsibilities from being held or exercised by the same person.
  • Delegated authority is scoped and time-boxed, and lapses automatically without manual intervention.
  • Every role change, delegation, approval and committee decision is written to an append-only audit trail.
  • Board- and committee-sensitive material can be restricted to named roles and withheld from wider visibility.
  • Retention of decision and delegation records is configurable to your regulatory and record-keeping obligations.

Compliance support

  • Underpins three-lines-of-defence and governance expectations for regulated firms
  • Supports individual-accountability and senior-management-responsibility regimes with mapped, evidenced ownership
  • Provides the approval and decision evidence expected in regulatory examination
  • Supports corporate-governance and board-oversight codes and expectations
  • Evidences segregation of duties and delegated authority for internal and external audit

Reports & exports

  • Roles and responsibility (RACI) matrix by object and by role-holder
  • Approval-authority matrix and current delegations register
  • Segregation-of-duties conflict and exception reports
  • Decision register with basis, version and approver
  • Committee decision and action-tracking reports
  • Role and access recertification status reports
Best practice

How to get the most from it

Map accountability to roles, not people

Assign responsibility to roles and let the identity directory drive who holds them. Mapping to individuals means every leaver or mover reopens the question of who is accountable.

Enforce SoD at the point of action

Configure segregation-of-duties rules so conflicts are blocked when a decision is made, not discovered months later. Prevention is worth far more than a retrospective finding.

Time-box every delegation

Never grant open-ended authority. Scope delegations to specific decisions and set an expiry, so authority contracts back automatically when cover is no longer needed.

Run committees on live data

Assemble packs from the current risk, policy and control record rather than a snapshot. Governance loses its value the moment it reviews yesterday's position.

FAQ

Questions, answered

How is accountability tracked across the platform?

Responsibility, accountability, consultation and information are mapped as roles onto every governed object — risks, controls, policies, obligations. Because they map to roles rather than individuals, ownership stays accurate as people join, move and leave.

Can the platform enforce segregation of duties?

Yes. You configure incompatible-duty and conflicting-role rules, and the platform enforces them at the point of action — blocking, for example, the same person from both preparing and approving a decision — rather than surfacing the breach in a later audit.

How does delegated authority work?

Delegations are granted formally with a defined scope and an expiry date. The current holder of authority is always visible, delegated authority lapses automatically, and the full chain of who decided under whose authority is preserved for audit.

Where are approvals recorded?

Every material approval across the platform is captured in a central decision register as a structured record — who approved, when, against which version and on what basis — so sign-off can be produced instantly rather than reconstructed from email.

Does this support individual-accountability regimes?

Yes. By mapping responsibilities to named roles and preserving a durable record of decisions and delegations, the module provides the evidenced ownership and accountability that senior-management-responsibility regimes expect.

See Governance in your programme

Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.