AML & Financial Crime Programme
Run your whole anti-money-laundering programme on one record
An anti-money-laundering programme is not a single control — it is onboarding, screening, due diligence, monitoring, investigations, reporting and governance operating as one, with every decision defensible. OnyxOne composes those capabilities into a single operating layer so a customer's full financial-crime picture lives in one record, and audit readiness is a by-product of the work rather than a project in its own right.
One programme, on one platform
Your compliance, risk and legal teams run the programme in OnyxOne, which composes the relevant modules onto one record and connects to the systems and data sources your deployment requires.
What this programme is, and why it matters
A solution is a programme, not a single tool — the outcome a set of platform capabilities add up to when they run on one record.
How onboarding, due diligence and review become a decided, evidenced outcome — with a defensible trail from first contact to closure.
The financial-crime lifecycle, end to end
This programme covers the full lifecycle a firm is expected to operate — identify and verify customers, screen them, apply risk-based diligence, monitor for change, investigate what warrants it, and report and govern the whole thing. Composing it on one platform means each stage feeds the next instead of being reassembled across tools.
Risk-based by design
Regulators expect effort to be proportionate to risk. The programme is configured to your own risk methodology so low-risk relationships clear efficiently and higher-risk ones route into deeper diligence and review — with the rationale for the treatment recorded either way.
Defensible, not just done
The value of a financial-crime programme is proven when it is questioned. Every screening result, rating, disposition and override is written to an immutable audit trail, so the answer to "how was this decided?" already exists on the record.
One picture of a customer's risk
When screening, monitoring and cases share the same customer and entity records, the programme sees one risk picture rather than fragments held in separate teams — removing duplication and the blind spots that live between systems.
What makes this hard today
The operational realities this programme is designed to resolve.
Fragmented across point tools
Screening, monitoring, KYC and cases frequently sit in separate systems, so a single customer's risk is scattered and has to be reassembled by hand for every review.
Evidence assembled after the fact
When work lives in disconnected tools and inboxes, audit evidence is reconstructed from memory and screenshots when a regulator asks — rather than captured as the work happens.
Alert fatigue and hidden risk
High volumes without disciplined tuning and triage bury genuinely suspicious activity under false positives, and analyst time is spent clearing noise.
Inconsistent treatment
Thresholds, risk factors and diligence requirements drift between teams and business lines, so similar customers are treated differently and the programme is hard to defend.
No single owner of the picture
With the programme spread across functions, no one record shows the full history of a customer, the decisions taken and the evidence behind them.
The operating model, at a glance
How the composed programme runs — from the data it takes in to the decisions and evidence it produces.
Work is triaged, escalated when it matters, and recorded either way — every path lands on the audit trail.
Compose the programme
Turn on the modules the programme needs — screening, due diligence, monitoring, cases and reporting — configured to your risk methodology, thresholds and roles.
Onboard & screen
Customers and entities are verified, screened against sanctions, PEP and adverse-media sources, and risk-rated against your policy on entry.
Diligence by risk
Standard relationships follow CDD; higher-risk ones route into enhanced due diligence, with source-of-wealth, ownership and approval steps captured.
Monitor & investigate
Ongoing screening and monitoring surface change; anything material becomes a structured, four-eyes investigation with evidence attached.
Report & govern
Regulatory returns and suspicious-activity content are assembled from the same record, signed off, and preserved in the audit trail under three-lines oversight.
The modules this solution composes
A solution is a curated set of platform modules working as one programme. Turn on what the programme needs and add more as it scales.
What the programme gives you
The concrete capabilities the composed programme provides, end to end.
Sanctions, PEP & adverse-media screening
Screen customers and entities at onboarding and continuously thereafter, with configurable match logic and fuzzy-name handling to control false positives.
Risk-based CDD & EDD
Structured customer and enhanced due-diligence workflows mapped to your own risk policy, so diligence is proportionate and the treatment is recorded.
Configurable risk scoring
Rate customers and relationships against your methodology, with factors, weightings and thresholds you control and can change under version history.
Ongoing monitoring
Detect sanctions hits, PEP status changes and behavioural shifts across the life of a relationship, not just at onboarding.
Investigations & case management
Route alerts into cases with evidence, entity links, ownership, SLAs and recorded decisions — a defensible trail from signal to closure.
Regulatory reporting
Assemble suspicious-activity content and the returns your obligations require from the same record the decisions were made on.
The end-to-end workflow
A defined process with clear ownership at every stage, captured against the record it belongs to.
Every result, decision and override is captured against the record it belongs to.
Onboard & verify
Customers and entities are onboarded with identity and beneficial-ownership data captured against a single record.
Screen & rate
Screening runs against sanctions, PEP and adverse-media sources, and a risk rating is applied using your methodology.
Apply diligence
Diligence is proportionate to risk — CDD as standard, EDD with source-of-wealth and approvals for higher-risk relationships.
Monitor for change
Ongoing screening and monitoring surface new matches, status changes and behavioural signals throughout the relationship.
Investigate & decide
Material alerts become structured investigations with evidence and four-eyes review, and decisions are recorded with rationale.
Report & preserve
Reports and returns are assembled, signed off and preserved in an immutable, timestamped audit trail.
Industries this programme serves
The sectors this programme is most often deployed in. The same programme, framed around each sector's obligations.
Works with your existing systems
Described as capabilities — OnyxOne connects to the systems the programme requires, configured per implementation.
- Ingests customer, account and transaction data from your existing core and CRM platforms to screen and monitor the right records
- Connects to the sanctions, PEP and adverse-media providers contracted for your deployment
- Integrates with your existing identity-verification and corporate-registry data services
- Exports returns and suspicious-activity content in the formats your submission channels require
- Routes alerts, escalations and approvals through your existing email and messaging tools
Security & reporting
Security & data handling
- Customer, entity and case data are encrypted in transit and at rest.
- Role-based access and segregation of duties align to your three-lines model.
- Every screening result, rating, disposition, override and report is written to an append-only audit trail.
- Suspicion-related and sensitive data are restricted to authorised roles under need-to-know.
- Data residency and retention are configurable to your jurisdiction and record-keeping obligations.
Reports & returns
- Suspicious-activity / suspicious-transaction report content (SAR/STR)
- Screening-coverage and disposition reports
- Customer risk-rating distribution and re-rating reports
- Case throughput, ageing and SLA-adherence reports
- Programme management information for the board and second line
What your team gains
A unified risk picture
Financial-crime operations that were siloed share one record, removing duplication and the blind spots between systems.
Continuous audit readiness
An immutable trail keeps the programme examination-ready all the time, not only in the run-up to a review.
Proportionate effort
Risk-based routing concentrates analyst time where risk is real, rather than on clearing noise.
Consistency you can defend
One configured methodology applied across teams means similar customers are treated the same way — and the treatment is evidenced.
Questions, answered
Is this a product or a set of modules?
It is a programme composed from OnyxOne modules — screening, due diligence, monitoring, cases, reporting and governance — configured to work as one. You turn on what the programme needs and add more as it scales.
Does OnyxOne decide what our AML obligations are?
No. OnyxOne is a technology vendor, not a regulated firm or an obliged entity. The programme enforces the policy, thresholds and risk methodology you design; responsibility for your obligations remains with your firm.
Can it run alongside our existing core systems?
Yes. The programme ingests customer, account and transaction data from your systems of record and sits as a financial-crime layer on top, rather than replacing your core.
How is it risk-based?
Risk scoring, screening thresholds and diligence requirements are configured to your methodology, so effort is proportionate — low-risk relationships clear efficiently and higher-risk ones route into deeper diligence, with the rationale recorded.
Are SOC 2 or ISO 27001 held?
Not yet. We build to recognised security standards and both are on our roadmap; we will publish attestations in the Trust Center once they are held rather than claim them beforehand.
Stand up your AML & Financial Crime Programme programme
Book a walkthrough and we'll show how the composed programme fits your obligations, workflows and systems — then scope an implementation.