Governance, risk & compliance · Enterprise-ready

Governance, risk
and compliance — unified.

OnyxOne is the enterprise GRC operating system — manage risk, controls, policies, obligations, audits, evidence and regulatory workflows from one platform. Built for regulated organisations. Defensible by design.

Programme
One platform
Every decision
Audit-logged
Configured to
Your policy
ONYXONE · Control record
Effective · Low residual
CONTROL · ONX-4821-K
Last tested
No exceptions
Status
Approved & evidenced
Control monitoring active

One platform, end-to-end coverage

GovernanceEnterprise riskOperational riskRisk registersInternal controlsControl testingPolicy managementCompliance obligations
Regulatory changeCompliance programmeKYC/KYB lifecycleThird-party riskAudit managementEvidence managementRegulatory reportingBoard reporting

The governance, risk and compliance domains the platform is built to cover — capabilities, not partnerships or endorsements.

What OnyxOne is

One platform for the whole GRC programme

Not another point tool bolted onto a stack of spreadsheets. A single operating system where risk, controls, policy, obligations, audit, evidence and reporting work together — with a defensible trail behind every decision.

One operating system for governance, risk & compliance

Risk registers, controls, policies, obligations, audits, evidence and reporting run on a single platform — not a patchwork of spreadsheets, shared drives and email chains. One taxonomy, one workflow, one source of truth across every framework and every business unit.

Risk and control, connected end to end

Every obligation maps to a control, every control to the risk it mitigates, and every test to the evidence that proves it worked. When a control fails, the issue, the owner, the remediation and the affected risk are already linked — so exposure is visible, not inferred.

Defensible by design

Every assessment, approval, override, policy version and control test is captured in an immutable audit trail. When a regulator, auditor or board committee asks how a decision was made and who owned it, the answer is already recorded — not reconstructed after the fact.

One platform, layered end to endSchematic
Data sources & inputsCustomers · vendors · transactions · documents · your systems of recordIngestion & screeningOnboarding · sanctions, PEP & adverse-media screening · capture & normalisationRisk, case & monitoring enginesRisk scoringCase & investigationOngoing monitoringControls, evidence & policyControls library · testing · evidence capture · policy mappingReporting & analyticsDashboards · regulatory returns · executive & board reportingIntegrations & audit trailAPIs & connectors · append-only, timestamped audit trailOne layered platform — every layer feeds the next, and every action lands in the audit trail.

Data sources feed ingestion and screening, the risk, case and monitoring engines, controls and evidence, reporting and analytics — with every action landing in the audit trail.

The platform

A complete module suite

Every capability a compliance and risk team needs, working together on one platform — turn on what you need, add more as you scale.

Explore the platform
GovernanceRiskControlsComplianceAuditReporting
Core

Compliance Hub

Operations

A single control room for your compliance programme — work, alerts and obligations in one place.

Availability
All plans
Domain
Operations
Core

Screening

Operations

Sanctions, PEP and adverse-media screening at onboarding and continuously, with configurable match rules.

Availability
All plans
Domain
Operations
Available

Customer Due Diligence

Due diligence

Structured CDD and KYC/KYB workflows that collect, verify and risk-rate each customer against your policy.

Availability
All plans
Domain
Due diligence
Available

Enhanced Due Diligence

Due diligence

Deeper EDD for higher-risk relationships — source-of-funds, ownership mapping and sign-off trails.

Availability
Professional & up
Domain
Due diligence
Available

Ongoing Monitoring

Risk

Continuous re-screening and event monitoring that surfaces changes in customer and third-party risk.

Availability
Professional & up
Domain
Risk
Core

Case Management & Investigations

Investigations

Route alerts into cases, gather evidence, record decisions and close with a defensible audit trail.

Availability
All plans
Domain
Investigations
Available

Risk Intelligence

Risk

Configurable risk scoring across customers, entities and jurisdictions, driven by your own risk model.

Availability
Professional & up
Domain
Risk
Available

Policy Management & Controls

Governance

Author, version and attest policies, and map them to the controls that enforce them across the platform.

Availability
Professional & up
Domain
Governance
Available

Regulatory Reporting

Reporting

Assemble, review and export the reports and returns your obligations require, from a single record.

Availability
Available
Domain
Reporting
Core

Audit Centre

Governance

An immutable record of every action, decision and change — ready for internal and external audit.

Availability
All plans
Domain
Governance
Add-on

Vendor & Third-Party Risk

Risk

Onboard, assess and monitor third parties with due-diligence questionnaires and continuous screening.

Availability
Add-on
Domain
Risk
Available

Compliance Analytics

Reporting

Dashboards and metrics across risks, controls, obligations, cases and SLAs — visibility for the whole programme.

Availability
Professional & up
Domain
Reporting
Core

Governance

Governance

Roles, approvals, segregation of duties and oversight so the right people sign off the right decisions.

Availability
All plans
Domain
Governance
How it works

From onboarding to audit-ready

Screen and diligence who you deal with, investigate what needs a closer look, and report — with every step captured against the record it belongs to.

Risk, controls & policy

Govern the programme, not just the paperwork

Maintain enterprise and operational risk registers on one taxonomy, map them to a single control library, and drive policy from authoring through approval, publication and attestation. Obligations and regulatory change flow into the same structure, so nothing lives in isolation.

  • One risk taxonomy across enterprise, operational and third-party risk
  • A single control library mapped to risks, obligations and frameworks
  • Policy authoring, versioning, approval and attestation with full history
Assurance & evidence

Prove the controls worked

Test control design and operating effectiveness on a schedule, capture the evidence once and reuse it across audits, frameworks and regulatory examinations. Findings become tracked issues with owners and due dates, driven to closure rather than logged and forgotten.

  • Scheduled control testing with sampling, workpapers and sign-off
  • Evidence collected once, reused across audits and frameworks
  • Issues and remediation tracked to closure with committee-level visibility
01

Govern

Establish the backbone: one risk taxonomy and register, a single control library, your policies and the obligations you are subject to — each mapped to the others so ownership and accountability are explicit from the start.

02

Control & monitor

Run the programme against that backbone. Risk assessments, control testing, compliance and due-diligence lifecycles, third-party reviews, cases and approvals execute on defined workflows, with regulatory change feeding straight back into the controls it affects.

03

Evidence & report

Evidence is captured as work happens, not assembled before an audit. Regulatory returns, committee packs and board reporting are generated from that same record, with every decision, override and version preserved in an immutable audit trail.

The screen-to-report workflowSchematic
1Ingest & screenOnboard and screen against sanctions, PEP & media2Assess & investigateRisk-score, then route reviews into cases3Report & auditProduce reports; every step is recordedEvery result, decision and override is captured against the record it belongs to.

Ingest and screen, assess risk and investigate, then report — with every result, decision and override captured against the record it belongs to.

Clear ownership at every lineSchematic
Board & audit committeeSets risk appetite · holds the programme accountable1st lineOperational managementOwns and manages risk dayto day2nd lineRisk & complianceSets policy, oversees andmonitors3rd lineInternal auditIndependent, objectiveassuranceExternal audit & regulators

Work carries defined ownership — from operational management through risk and compliance to independent internal audit, under board oversight.

Investigation Workspace

Every alert, a defensible case.

OnyxOne turns alerts into structured cases with evidence, entity links and recorded decisions. Investigators work in one place, decisions carry clear ownership and sign-off, and every case closes with an audit trail you can defend.

  • Link people, entities and events to see the full picture
  • Role-based assignment, review and segregation of duties
  • Outcomes and rationale captured for audit and reporting

From alert to closure · one workspace

ONYXONECase
CASE · ONX-4821-K · OPEN
Assigned · under review · audit-logged
Oversight at a glanceIllustrative
ILLUSTRATIVE EXAMPLEOPEN CASES128SLA ADHERENCE96%SCREENING ALERTS1.2kOVERDUE REVIEWS14Cases by categoryAMLKYCFraudSanctionsConductOtherRisk mixby tierHighMediumLow

A representative view of the case metrics a team lead monitors — open cases, SLA adherence, alert volume and overdue reviews. Figures shown are illustrative examples, not real data.

Editions

Scaled to your programme

From growing teams to financial institutions. Each edition lists exactly what it includes; add-ons and roadmap items are labelled honestly. Pricing is scoped to your deployment.

Essentials

contact for pricing

Risk registers, controls and policy management for growing compliance teams.

  • Risk register & risk assessments
  • Control library & control testing
  • Policy management & attestation
  • Evidence store & audit trail
  • Standard support
Book a demo
Most popular

Professional

contact for pricing

The full GRC operating system for regulated firms scaling their programme.

  • Everything in Essentials
  • Compliance obligations & regulatory change management
  • Audit management, findings & remediation
  • Third-party & vendor risk
  • KYC/KYB compliance lifecycle & case management
  • Compliance analytics & priority support
Book a demo

Enterprise

contact for pricing

For financial institutions and large enterprises with complex governance and scale.

  • Everything in Professional
  • Enterprise & operational risk at group scale
  • Executive, committee & board reporting
  • Advanced governance & segregation of duties
  • SSO, granular roles & data residency options
  • Dedicated support
  • SOC 2 / ISO 27001 (on roadmap, not yet held)
Book a demo

Regulated add-ons

Add-on

Extend any edition with specialist governance and resilience modules.

  • Business continuity & disaster recovery
  • Whistleblowing & incident management
  • Regulatory reporting packs
  • Bespoke risk models & frameworks
  • Implementation & onboarding support
  • Screening, identity & data-provider integrations (configured per deployment)
Talk to us

Built for regulated organisations

Financial ServicesBankingFintechInsuranceLendingInvestment FirmsCorporate & Trust Service ProvidersLegal FirmsAccounting FirmsGamingE-commerceRegulated Enterprises
Security & trust

Built like critical infrastructure

Sensitive compliance data, handled the way it should be — encrypted, access-controlled, and audit-logged. Everything we claim, we document.

Encrypted in transit and at rest

Customer records, evidence and case data are encrypted in transit and at rest. Hardened HTTP security headers — HSTS, frame-ancestors none, nosniff and strict referrer and permissions policies — guard every request.

Server-only secret handling

Sensitive credentials and service keys live and stay on the server. The browser never receives a secret, so a compromised client cannot leak one.

Role-based access & segregation of duties

Granular roles govern who can screen, investigate, approve and report. Segregation-of-duties controls ensure the same person cannot both raise and sign off a decision where your policy forbids it.

Immutable audit trail

Every action, decision, override and policy change is written to an append-only audit record — the evidence base you need for internal review, external audit and regulatory scrutiny.

Data residency & retention

Data location and retention are configurable to your regulatory obligations, and records are kept only as long as the law and your policy require, then deleted or anonymised.

Monitored and logged

Access, activity and integrations are logged and monitored, with a documented incident-response process. Capabilities that are not configured refuse safely rather than fail open.

How OnyxOne sits in your operationSchematic
Your teamsCompliance · risk · legalAnalysts & investigatorsScreen, review and decideOversight & approvalsSign-off and reportingOnyxOneCompliance & risk OSScreening · Due diligenceCases · Risk · MonitoringPolicy · Reporting · AuditSystems & sourcesConfigured per deploymentScreening data providersSanctions · PEP · mediaYour systems of recordOnboarding · core systemsOne platform for the whole programme — not a stack of disconnected tools and spreadsheets.

Your teams work in one platform that centralises screening, cases and risk, and connects to the systems of record and data sources your deployment requires.

Enterprise-ready

SSO, granular roles, data residency options and audit-grade logging designed for financial institutions and regulated enterprises.

A technology vendor, honestly framed

OnyxOne provides software; it is not a regulated financial institution and is not itself an obliged entity. Your firm remains responsible for its regulatory obligations.

Documented & disclosed

Terms, security controls, data-processing terms and sub-processors are published and versioned in the Trust Center.

Transparency Center

Policies, audits, disclosures and system status — published and versioned. Empty sections are marked honestly until content is live.

FAQ

Straight answers

If we can't say something truthfully yet, we say that too.

OnyxOne is an enterprise governance, risk and compliance (GRC) operating system — a single platform for regulated organisations to manage risk registers, internal controls, policies, regulatory obligations, audits, evidence, compliance cases and regulatory reporting.

Compliance, risk, internal audit, legal and governance teams — and the boards and executives they report to. It is built for banks, EMIs, PSPs and payment institutions, fintechs, insurers, lenders, investment firms, corporate and trust service providers, and large regulated enterprises. It suits a 50-person regulated fintech and a multinational group alike.

No. OnyxOne is a technology vendor. We provide software that helps your organisation govern and evidence its own compliance obligations; we are not a bank, EMI, PSP, payment institution or other regulated financial services provider, and we are not an obliged entity under AML law. Responsibility for meeting regulatory obligations remains with your organisation.

No — and we would rather be explicit about that boundary than blur it. OnyxOne is the governance and compliance control plane: it manages risk, controls, policies, obligations, cases, evidence and reporting. Real-time transaction monitoring, payment-risk scoring and authorisation decisioning are a different operational layer, and OnyxOne integrates with the engines and providers that perform them rather than replacing them.

As governed lifecycle and orchestration, not as the underlying data or decisioning engine. OnyxOne runs KYC/KYB onboarding, verification, risk assessment, approval, periodic review, remediation and audit as structured workflows; it calls your chosen identity, registry and screening providers through integrations; and it stores the results as evidence against the right record, under approval controls and an immutable audit trail. The screening databases and matching engines are your providers' — the programme governing them is ours.

They are one connected structure rather than four separate registers. Obligations map to the controls that satisfy them, controls map to the risks they mitigate, and control tests produce the evidence that proves they operated. When a test fails, the resulting issue, its owner, the remediation plan and the affected risk are already linked — so residual exposure is visible rather than inferred.

Evidence is captured as work happens rather than assembled under deadline. Auditors and examiners can be given scoped access to the control, its test history, the evidence attached to it and the full decision trail — including overrides, approvals and policy versions. Audit management plans engagements, tracks findings and drives remediation to closure on the same record.

Yes. Risk taxonomies and scoring, control libraries and framework mappings, policy hierarchies, due-diligence requirements, workflows, roles and approval thresholds are configurable to your methodology and risk appetite. The platform enforces your model rather than imposing a fixed one.

Data is encrypted in transit and at rest, secrets stay server-side, access is role-based with segregation of duties, and all activity is logged. Data residency and retention are configurable to your regulatory obligations. See the Security page in the Trust Center for the full posture.

Not yet. We build to recognised security standards, and SOC 2 and ISO 27001 are on our roadmap. We will publish attestations in the Trust Center once they are held rather than claim them before they are complete.

OnyxOne is configured to your risk taxonomy, control framework, policies, roles and workflows, and integrated with the systems and data sources your deployment requires. Screening, identity and data providers are contracted and configured per deployment rather than fixed to a single named partner.

Integration options are scoped per deployment. We do not publish a public API surface or endpoints today, and we would rather say that plainly than document a contract that is not stable. Talk to us about the integrations your implementation needs.

Book a demo and we will walk through the platform against your programme, then scope an implementation. For diligence, a DPA or a security review, everything you need to begin is published in the Trust Center.

Run governance, risk & compliance on OnyxOne

See the platform against your programme. One place for risk, controls, policy, obligations, audit, evidence and reporting — defensible by design.