Solutions
Financial Crime Compliance

Customer & Enhanced Due Diligence

Proportionate diligence — standard where it fits, deeper where it matters

Due diligence is where a firm forms and evidences its understanding of a customer's risk. This programme composes customer due diligence (CDD) and enhanced due diligence (EDD) into one risk-based workflow, so standard relationships follow an efficient path and higher-risk ones route into deeper checks — source of wealth, ownership, purpose and approvals — all captured against the record.

At a glance

One programme, on one platform

Customer & Enhanced Due Diligence on OnyxOneSchematic
Your teamsCompliance · risk · legalAnalysts & investigatorsScreen, review and decideOversight & approvalsSign-off and reportingOnyxOneCompliance & risk OSScreening · Due diligenceCases · Risk · MonitoringPolicy · Reporting · AuditSystems & sourcesConfigured per deploymentScreening data providersSanctions · PEP · mediaYour systems of recordOnboarding · core systemsOne platform for the whole programme — not a stack of disconnected tools and spreadsheets.

Your compliance, risk and legal teams run the programme in OnyxOne, which composes the relevant modules onto one record and connects to the systems and data sources your deployment requires.

The programme

What this programme is, and why it matters

A solution is a programme, not a single tool — the outcome a set of platform capabilities add up to when they run on one record.

The customer compliance lifecycleSchematic
1AlertRaised2TriagePrioritise3InvestigateEvidence4DecisionApprove5ReportAudit-loggedreopenClear ownership and recorded decisions at every stage — a defensible trail from alert to closure.

How onboarding, due diligence and review become a decided, evidenced outcome — with a defensible trail from first contact to closure.

One programme, two depths

CDD establishes a baseline understanding for every customer; EDD adds depth for higher-risk relationships. Running both in one workflow means the step-up is a routing decision on the same record, not a hand-off to a different tool.

Triggered by risk, not by guesswork

The move from standard to enhanced diligence is driven by your risk methodology — PEP status, high-risk jurisdictions, complex ownership, adverse media or a rating threshold — so the trigger is defensible and consistent.

Source of wealth and funds, evidenced

For higher-risk relationships, the programme captures source-of-wealth and source-of-funds information with supporting evidence and documented rationale, so the firm's understanding is recorded rather than assumed.

Approvals where accountability sits

Higher-risk relationships route to the right level of sign-off — senior management or the MLRO where your policy requires — with the approval, its conditions and the evidence behind it captured on the record.

The challenge

What makes this hard today

The operational realities this programme is designed to resolve.

Inconsistent depth

Without a defined trigger, whether a relationship gets standard or enhanced diligence depends on who handled it — leaving uneven, hard-to-defend files.

Source-of-wealth as free text

Source-of-wealth understanding captured as unstructured notes is hard to review, evidence or stand behind when a relationship is examined.

Ownership that goes stale

Beneficial-ownership and control information gathered once at onboarding drifts out of date, so the firm's understanding no longer matches reality.

Approvals off the record

When higher-risk sign-off happens over email or in meetings, the who, when and on-what-evidence of the decision is lost.

Reviews that slip

Periodic re-diligence on higher-risk relationships is easy to miss when it is tracked in spreadsheets rather than driven by the system.

How it works

The operating model, at a glance

How the composed programme runs — from the data it takes in to the decisions and evidence it produces.

A representative flowSchematic
Item receivedOnboarding / eventRiskthreshold?Auto-clearLow risk · loggedEscalate to reviewAnalyst investigatesRecord &auditNoYes — parallel review paths

Work is triaged, escalated when it matters, and recorded either way — every path lands on the audit trail.

01

Set the diligence policy

Define CDD requirements, the risk triggers that step up to EDD, and the approval levels each risk tier requires.

02

Establish the baseline

Capture and verify the CDD information every customer needs — identity, purpose, expected activity and ownership.

03

Step up on risk

Where a trigger fires, the relationship routes into EDD with source-of-wealth, deeper ownership and purpose checks.

04

Review & approve

Higher-risk relationships route to the required approval level, with conditions and evidence captured on the record.

05

Schedule re-diligence

Periodic reviews are scheduled by risk tier so the firm's understanding is kept current, not left to drift.

Capabilities

What the programme gives you

The concrete capabilities the composed programme provides, end to end.

Structured CDD

A baseline due-diligence workflow — identity, purpose, expected activity and ownership — captured consistently against every customer record.

Risk-triggered EDD

Enhanced due-diligence workflows that fire on your configured triggers — PEP, high-risk jurisdiction, complex ownership or adverse media.

Source of wealth & funds

Capture source-of-wealth and source-of-funds information with supporting evidence and documented rationale for higher-risk relationships.

Beneficial-ownership depth

Unwrap ownership and control structures for higher-risk counterparties and keep the understanding current through scheduled review.

Tiered approvals

Route higher-risk relationships to the right level of sign-off, with the approval, conditions and evidence recorded on the record.

Periodic re-diligence

Schedule reviews by risk tier so the firm's understanding of a customer stays current over the life of the relationship.

The workflow

The end-to-end workflow

A defined process with clear ownership at every stage, captured against the record it belongs to.

The workflow, step by stepSchematic
01Assess baseline riskA customer is risk-assessed against your methodology to determine the depth ofdiligence required.02Complete CDDBaseline due-diligence information is captured and verified against the customerrecord.03Evaluate triggersRisk triggers are evaluated; where one fires, the relationship steps up intoenhanced due diligence.04Perform EDDSource-of-wealth, deeper ownership and purpose checks are completed with supportingevidence attached.05Approve with conditionsThe relationship routes to the required approval level, and the decision, conditionsand evidence are recorded.06Review on schedulePeriodic re-diligence is scheduled by risk tier and captured on the same record whenit runs.

Every result, decision and override is captured against the record it belongs to.

01

Assess baseline risk

A customer is risk-assessed against your methodology to determine the depth of diligence required.

02

Complete CDD

Baseline due-diligence information is captured and verified against the customer record.

03

Evaluate triggers

Risk triggers are evaluated; where one fires, the relationship steps up into enhanced due diligence.

04

Perform EDD

Source-of-wealth, deeper ownership and purpose checks are completed with supporting evidence attached.

05

Approve with conditions

The relationship routes to the required approval level, and the decision, conditions and evidence are recorded.

06

Review on schedule

Periodic re-diligence is scheduled by risk tier and captured on the same record when it runs.

Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems the programme requires, configured per implementation.

Screening & data sources
  • Draws on the sanctions, PEP and adverse-media providers configured for your deployment to inform diligence triggers
Corporate registries & ownership
  • Connects to the corporate-registry and beneficial-ownership data services your deployment uses
Document evidence
  • Holds source-of-wealth and supporting documents against the record in the document repository
Systems of record
  • Reads customer and account data from your core systems to inform risk assessment and review scheduling
Collaboration & notification
  • Routes diligence referrals and approvals through your existing email and messaging tools
Assurance

Security & reporting

Security & data handling

  • Due-diligence records and supporting evidence are encrypted in transit and at rest.
  • Access to source-of-wealth and sensitive diligence data is role-based and restricted under need-to-know.
  • Every diligence step, trigger, approval and review is written to an append-only audit trail.
  • Segregation of duties can prevent the same person raising and approving a higher-risk relationship.
  • Data residency and retention are configurable to your jurisdiction and record-keeping obligations.

Reports & returns

  • CDD and EDD completion and coverage reports
  • Higher-risk relationship population and approval reports
  • Source-of-wealth evidence completeness reporting
  • Overdue and upcoming re-diligence reports
  • Diligence approval and exception reporting
The value

What your team gains

Proportionate, consistent diligence

A defined trigger means similar relationships get the same depth of diligence — and the step-up is defensible.

Evidenced understanding

Source-of-wealth, ownership and purpose are captured as structured, supported records rather than free-text notes.

Accountable approvals

Higher-risk sign-off happens on the record, so the who, when and on-what-evidence of the decision is never lost.

Understanding that stays current

Scheduled re-diligence keeps the firm's view of a customer aligned to reality over the life of the relationship.

FAQ

Questions, answered

What triggers enhanced due diligence?

The triggers are configured to your policy — for example PEP status, high-risk jurisdictions, complex ownership, adverse media or a risk-rating threshold. When a trigger fires, the relationship routes into EDD automatically, and the reason is recorded.

How is source of wealth handled?

Source-of-wealth and source-of-funds information is captured as structured records with supporting evidence and documented rationale held against the customer, rather than as free-text notes.

Does it keep diligence current?

Yes. Periodic re-diligence is scheduled by risk tier, so higher-risk relationships are reviewed on a defined cadence and the firm's understanding stays aligned to reality.

Can we require senior sign-off for higher-risk customers?

Yes. Approval levels are configured per risk tier, so higher-risk relationships route to the sign-off your policy requires, with the decision and its conditions recorded.

Are SOC 2 or ISO 27001 held?

Not yet. Both are on our roadmap; we will publish attestations in the Trust Center once they are held rather than claim them beforehand.

Stand up your Customer & Enhanced Due Diligence programme

Book a walkthrough and we'll show how the composed programme fits your obligations, workflows and systems — then scope an implementation.