Platform
Cases & Investigations

Incident Management

Capture, triage and resolve incidents with root cause and lessons learned

Record incidents as they happen, triage them by severity and impact, drive them through response and resolution, and capture root cause and lessons learned — with every incident linked to the risks and controls it exposes, so recurring weaknesses are addressed rather than repeated. An incident is a control speaking: a breach, an outage, a data loss, a process failure. OnyxOne treats each one as a structured record from first report to closure, so the firm responds consistently, meets its notification obligations, and turns the painful ones into the improvements that stop them happening again.

At a glance

How it works, visually

The investigation lifecycleSchematic
1AlertRaised2TriagePrioritise3InvestigateEvidence4DecisionApprove5ReportAudit-loggedreopenClear ownership and recorded decisions at every stage — a defensible trail from alert to closure.

Alert, triage, investigate, decide, report — with clear ownership and a defensible trail at every stage.

The challenge

The problems this module solves

The operational realities that make this hard for compliance and risk teams today.

Incidents are reported everywhere and nowhere

A breach surfaces in an email, an outage in a chat channel, a process failure in a hallway conversation. With no single intake, incidents are logged inconsistently or not at all, and the firm has no reliable view of what has actually gone wrong.

Severity is judged in the moment, inconsistently

Without defined triage criteria, one team treats an event as critical and another shrugs off something worse. Inconsistent severity assessment means the wrong incidents get the urgent response, and the firm cannot show it prioritises by real impact.

Notification deadlines are missed

Many incidents carry regulatory or contractual notification clocks that start the moment the incident is known. When response is ad hoc, those deadlines are tracked in someone's head, and a missed notification turns an operational problem into a compliance breach.

Root cause is never really established

Under pressure to restore service, teams fix the symptom and move on. The underlying cause is never documented, so nothing is learned, and the same failure recurs — each time treated as a surprise.

Incidents don't connect to risk and controls

An incident is evidence that a control failed or a risk crystallised, but if incidents live in their own silo, that evidence never reaches the risk register. The firm's view of its risk stays theoretical while reality keeps proving it wrong.

The approach

How OnyxOne addresses it

One intake for every incident

Incidents are captured through a single, consistent intake — reported by staff, raised from monitoring, or escalated from another module — so there is one reliable record of what has gone wrong across the organisation.

Consistent, criteria-based triage

Each incident is triaged against defined severity and impact criteria, so prioritisation reflects real consequence rather than the reporter's mood. The most serious incidents get the urgent response, consistently and demonstrably.

Notification clocks tracked from the start

When an incident type carries a regulatory or contractual notification obligation, the deadline is tracked on the record from the moment it opens, with reminders and escalation, so the firm meets its obligations rather than discovering them too late.

Structured response and root-cause analysis

Incidents move through defined response stages to resolution, and closure requires a documented root cause and lessons learned. The discipline of establishing why turns firefighting into improvement.

Linked to risks, controls and actions

Every incident links to the risks it crystallised and the controls it exposed, and can raise remediation actions against them. The incident record feeds the firm's real risk picture and drives the fixes that prevent recurrence.

Capabilities

What's in the module

Turn on what you need and add more as your programme scales.

Unified incident intake

Capture incidents from staff reports, monitoring signals and escalations through one consistent entry point.

Severity & impact triage

Assess each incident against defined criteria so prioritisation reflects real consequence.

Response workflow

Drive incidents through defined stages — contain, investigate, resolve — with clear ownership at each.

Notification tracking

Track regulatory and contractual notification deadlines on the record, with reminders and escalation.

Root-cause analysis

Capture the underlying cause of an incident, not just the symptom that was fixed.

Lessons learned

Record what the incident taught and what should change, so the firm improves rather than repeats.

Risk & control linkage

Link each incident to the risks it crystallised and the controls it exposed.

Remediation actions

Raise and track corrective actions against the risks and controls an incident revealed.

Incident register

Maintain a single, searchable register of all incidents, their severity, status and outcome.

Immutable incident trail

Every report, triage decision, action and closure is written to an append-only record.

Dashboards

The views your team works from

Purpose-built dashboards and views, each answering a question a specific role needs to act on.

An executive viewIllustrative
ILLUSTRATIVE EXAMPLEOPEN CASES128SLA ADHERENCE96%SCREENING ALERTS1.2kOVERDUE REVIEWS14Cases by categoryAMLKYCFraudSanctionsConductOtherRisk mixby tierHighMediumLow

A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.

Incident queue

Open incidents by severity and status, with owner, age and next action against each.

Severity heatmap

The distribution of incidents by severity and impact area, highlighting where things are going wrong most.

Notification tracker

Incidents with active notification deadlines, showing time remaining and escalation status.

Root-cause trends

Recurring root causes across incidents, surfacing the systemic weaknesses worth fixing once.

Remediation monitor

Corrective actions raised from incidents, tracked to completion against the risks and controls they address.

Automation

What the platform automates

Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.

Detection-driven intake

Alerts from monitoring and security systems raise incidents automatically, pre-populated with the signal that triggered them.

Severity-based routing

Triaged incidents are routed and escalated automatically according to their assessed severity and impact.

Notification deadline alerts

Approaching notification deadlines are escalated automatically so obligations are not missed.

Risk & control linkage

Incidents are linked to related risks and controls automatically where the mapping is known, and remediation actions raised against them.

Recurrence detection

Incidents matching prior root-cause patterns are flagged automatically so systemic issues are recognised early.

AI assistance

Where AI helps the analyst

Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.

Incident summarisation

Drafts a concise summary of an incident from its reports and response notes for responders and reviewers to verify.

Root-cause assistance

Suggests candidate root causes from the incident detail and similar prior incidents, which the team investigates and confirms.

Severity suggestion

Proposes an initial severity from the reported impact against your criteria, which the responder reviews and sets.

The workflow

The enterprise workflow

A defined, end-to-end process with clear ownership at every stage.

The workflow, step by stepSchematic
01CaptureAn incident is logged through one intake — reported, detected or escalated — withits type, description and initial impact.02TriageThe incident is assessed against defined severity and impact criteria, prioritised,and assigned to an owner.03Contain & respondResponse moves through defined stages, with any notification deadlines tracked onthe record from the outset.04ResolveThe immediate issue is resolved and the resolution documented, closing theoperational impact.05Root cause & lessonsThe underlying cause is established and lessons learned recorded, with remediationactions raised against exposed risks and controls.06Close & feed backThe incident closes with its full record preserved, its risk and control linksupdated, and its remediation tracked to completion.

Every result, decision and override is captured against the record it belongs to.

01

Capture

An incident is logged through one intake — reported, detected or escalated — with its type, description and initial impact.

02

Triage

The incident is assessed against defined severity and impact criteria, prioritised, and assigned to an owner.

03

Contain & respond

Response moves through defined stages, with any notification deadlines tracked on the record from the outset.

04

Resolve

The immediate issue is resolved and the resolution documented, closing the operational impact.

05

Root cause & lessons

The underlying cause is established and lessons learned recorded, with remediation actions raised against exposed risks and controls.

06

Close & feed back

The incident closes with its full record preserved, its risk and control links updated, and its remediation tracked to completion.

The value

What your team gains

One record

A reliable view of what went wrong

A single intake and register replace scattered emails and chat threads, so the firm actually knows its incident history.

Consistent

Prioritised by real impact

Criteria-based triage means the most serious incidents get the urgent response, consistently and demonstrably.

On time

Notification deadlines met

Notification clocks tracked from the moment an incident opens keep an operational problem from becoming a compliance breach.

Preventive

Weaknesses fixed, not repeated

Documented root cause, lessons learned and remediation actions turn painful incidents into improvements that stop recurrence.

Reality feeds the risk register

Linking incidents to risks and controls updates the firm's risk picture with what actually happened, not just what was assumed.

Defensible incident response

Because triage, response, notification and root cause are all on the record, showing you handled an incident properly is retrieval.

Built for

Industries it serves

BankingFinancial ServicesFintechInsuranceInvestment FirmsTechnologyHealthcareGamingRegulated Enterprises
Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.

Monitoring & detection
  • Raises incidents automatically from your existing monitoring, security and operational alerting systems
Risk & controls
  • Links incidents to the risks and controls held in your enterprise-risk and internal-controls modules
Service & ticketing
  • Connects to your existing service-management and ticketing tools so operational response stays aligned
Identity & directory
  • Aligns incident ownership and response roles with your existing identity provider and directory
Collaboration & notification
  • Routes incident alerts, escalations and status updates through your existing email and messaging channels
Assurance

Security, compliance & reporting

Security & data handling

  • Incident records, evidence and response detail are encrypted in transit and at rest.
  • Role-based access controls who can view, respond to and close an incident, with need-to-know restrictions on sensitive incidents.
  • Incidents involving personal-data breaches can be handled under tighter access with the sensitivity flagged on the record.
  • Every report, triage decision, action and closure is written to an append-only audit trail.
  • Notification deadlines and the actions taken against them are preserved as evidence of timely response.
  • Data residency and retention for incident records are configurable to your regulatory obligations.

Compliance support

  • Supports operational-incident capture and response expectations under operational-resilience regimes
  • Underpins regulatory and contractual breach-notification obligations with deadline tracking
  • Supports data-breach incident handling and the associated notification duties
  • Feeds operational-risk loss-event and root-cause requirements
  • Provides documented, timestamped evidence of incident response for audit and examination

Reports & exports

  • Incident register with severity, status and outcome
  • Incident volume, severity and trend reports
  • Notification-deadline adherence reports
  • Root-cause and lessons-learned summaries
  • Remediation-action status against exposed risks and controls
  • Incident management information for risk committees and the board
Best practice

How to get the most from it

One front door for incidents

Insist that every incident, however minor, enters through the single intake. A reliable incident picture depends on nothing being logged off to the side.

Triage against criteria, not instinct

Assess severity against defined impact criteria so prioritisation is consistent and defensible, rather than a function of who happened to assess it.

Start the notification clock immediately

Record notification obligations the moment an incident is known. Deadlines tracked from the start are met; deadlines remembered later are missed.

Close on root cause, not symptom

Require a documented root cause and remediation before closure. An incident fixed but not understood is an incident you will see again.

FAQ

Questions, answered

What counts as an incident here?

Any event that disrupts operations, breaches a control or obligation, or exposes a risk — an outage, a data breach, a process failure, a security event. The intake and triage are designed to handle the full range consistently, with severity determining the response.

How are notification deadlines handled?

When an incident type carries a regulatory or contractual notification obligation, the deadline is tracked on the record from the moment the incident opens, with reminders and escalation, so the firm meets the deadline rather than discovering it after the fact. The firm remains responsible for the notification itself.

How do incidents connect to our risk register?

Each incident links to the risks it crystallised and the controls it exposed, and can raise remediation actions against them. That feeds the enterprise-risk and internal-controls modules, so your risk picture reflects what has actually happened.

Does closing an incident require root cause?

By configuration, yes — closure can require a documented root cause and lessons learned, so the discipline of understanding why is enforced rather than optional. That is what turns incident response into genuine improvement.

Is OnyxOne deciding how to respond to an incident?

No. The platform structures the response, tracks obligations and surfaces links to risks and controls, but the response team makes the decisions and owns them. OnyxOne is decision-support and record-keeping software, not an automated responder.

See Incident Management in your programme

Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.