Platform
Cases & Investigations

Case Management & Investigations

Turn alerts into closed, defensible cases

A single workspace where alerts, referrals and incidents become structured cases — investigated with the full picture, decided on a defined workflow, and closed with an audit trail that stands up to scrutiny. Investigators stop chasing context across systems and shared inboxes; the evidence, entity links, decision history and sign-off all live on the case itself, so every conclusion is documented and every case is defensible.

At a glance

How it works, visually

The investigation lifecycleSchematic
1AlertRaised2TriagePrioritise3InvestigateEvidence4DecisionApprove5ReportAudit-loggedreopenClear ownership and recorded decisions at every stage — a defensible trail from alert to closure.

Alert, triage, investigate, decide, report — with clear ownership and a defensible trail at every stage.

The challenge

The problems this module solves

The operational realities that make this hard for compliance and risk teams today.

Investigations happen in inboxes and spreadsheets

Alerts land in a shared mailbox, evidence is gathered over email, and progress is tracked in a spreadsheet. Nothing is a system of record. Handovers lose context, cases stall silently, and there is no reliable way to show how — or how consistently — a decision was reached.

Context is scattered across systems

To understand a case, an investigator pulls the customer record from one place, screening results from another, prior alerts from a third, and related parties from memory. Building the full picture is slow manual work, and important links between people, entities and events get missed.

No consistent process or ownership

Without a defined workflow, similar cases are handled differently depending on who picks them up. Ownership is unclear, SLAs are informal, and reviews are ad hoc — the inconsistency that regulators and auditors single out.

Decisions aren't documented as they're made

The reasoning behind a disposition often lives only in the investigator's head or a stray email. When a decision is later questioned, the rationale has to be reconstructed, and the evidence base may no longer be intact.

Segregation of duties is hard to enforce

In manual processes the same person can raise, investigate and close a case. Enforcing that a decision is independently reviewed — and proving it was — is difficult without a system built around roles and sign-off.

The approach

How OnyxOne addresses it

Every alert becomes a structured case

Alerts, referrals and incidents are routed into cases with a consistent structure — subject, type, priority, owner, linked records and status. From the moment it opens, a case is a system of record, not a mailbox thread.

The full picture on one screen

The case pulls together the customer or entity record, screening results, prior alerts, related parties and evidence in one workspace. Investigators link people, entities and events to build the complete picture instead of assembling it by hand.

Defined workflows with ownership and SLAs

Cases move through configurable stages with clear ownership, due dates and SLAs. Work is assigned by role and workload, escalations follow defined paths, and nothing sits unowned or invisible.

Decisions captured with their reasoning

Every disposition, note and override is recorded on the case with its rationale as it happens. The case closes with a documented account of what was decided and why — the trail an auditor or regulator expects.

Four-eyes review and segregation of duties

Role-based assignment, review and approval enforce maker-checker separation where policy requires it, so the person who investigates a case is not the one who unilaterally signs it off. The controls are built in, and their operation is evidenced.

Capabilities

What's in the module

Turn on what you need and add more as your programme scales.

Case intake & routing

Turn alerts, referrals and incidents into cases and route them by type, priority and workload.

Investigation workspace

A single screen bringing together records, screening results, prior alerts, related parties and evidence.

Entity & relationship linking

Link people, organisations and events to reveal connections and build the full picture of a case.

Evidence attachment & chain

Attach documents, screenshots and system records to the case with a preserved history of what was added and when.

Configurable workflows & SLAs

Define case stages, ownership, due dates and escalation paths to match your operating model.

Timeline & activity view

A chronological view of everything that happened on a case, from intake to closure.

Notes & disposition capture

Record findings, reasoning and dispositions inline, so the rationale lives on the case.

Four-eyes review & sign-off

Enforce maker-checker review and role-based approval before a case can close.

Collaboration & assignment

Assign, reassign and collaborate across the team with clear ownership at every stage.

Immutable audit trail

Every action, decision, override and change is written to an append-only record.

The workflow

The enterprise workflow

A defined, end-to-end process with clear ownership at every stage.

The workflow, step by stepSchematic
01IntakeAlerts, referrals and incidents are captured as cases with type, priority andsubject, and routed to the right queue or owner.02Assign & ownEach case is assigned by role and workload, with a clear owner, due date and SLAfrom the outset.03InvestigateThe investigator works from a single workspace — records, screening results, prioralerts and related parties — linking entities and gathering evidence.04Document the decisionFindings, reasoning and the proposed disposition are recorded on the case as theinvestigation concludes.05Review & approveWhere policy requires, an independent reviewer applies four-eyes sign-off before thecase can be closed.06Close & preserveThe case closes with its outcome, rationale and full evidence base preserved in animmutable trail, ready for audit or regulatory review.

Every result, decision and override is captured against the record it belongs to.

01

Intake

Alerts, referrals and incidents are captured as cases with type, priority and subject, and routed to the right queue or owner.

02

Assign & own

Each case is assigned by role and workload, with a clear owner, due date and SLA from the outset.

03

Investigate

The investigator works from a single workspace — records, screening results, prior alerts and related parties — linking entities and gathering evidence.

04

Document the decision

Findings, reasoning and the proposed disposition are recorded on the case as the investigation concludes.

05

Review & approve

Where policy requires, an independent reviewer applies four-eyes sign-off before the case can be closed.

06

Close & preserve

The case closes with its outcome, rationale and full evidence base preserved in an immutable trail, ready for audit or regulatory review.

The value

What your team gains

One workspace

The full picture in one place

Records, evidence, entity links and decision history live on the case, so investigators stop reassembling context across systems.

Consistent

Every case handled the same way

Defined workflows, ownership and SLAs replace ad-hoc handling with the consistency auditors and regulators expect.

Defensible

Documented, auditable outcomes

Each case closes with its rationale and evidence intact, so a decision questioned months later is already fully accounted for.

Controlled

Segregation of duties, evidenced

Four-eyes review and role-based sign-off are enforced and recorded, proving that decisions were independently reviewed.

Nothing falls through the cracks

Clear ownership, SLAs and escalation paths mean cases don't stall silently in a shared inbox.

Faster, calmer audits

Because evidence is captured as work happens, responding to an audit or examination is retrieval rather than a reconstruction scramble.

Built for

Industries it serves

BankingFinancial ServicesFintechInsuranceInvestment FirmsCorporate & Trust Service ProvidersLegal FirmsGamingRegulated Enterprises
Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.

Alerts & monitoring
  • Receives alerts from your screening, monitoring and AML modules and turns them into cases automatically
Customer & entity records
  • Connects to your existing customer and entity systems so investigators work from the authoritative record
Document & evidence stores
  • Attaches evidence from your existing document repositories and preserves it on the case
Identity & directory
  • Aligns case ownership and review with your existing identity provider and role directory
Collaboration & notification
  • Routes assignments, escalations and approvals through your existing email and messaging channels
Assurance

Security, compliance & reporting

Security & data handling

  • Case data, evidence and decisions are encrypted in transit and at rest.
  • Role-based access controls who can view, investigate, review and close a case, with need-to-know restrictions on sensitive cases.
  • Segregation of duties prevents the same person from both raising and signing off a case where policy forbids it.
  • Every action, note, disposition and override is written to an append-only audit trail.
  • Evidence is preserved with a record of what was added and when, protecting the integrity of the case file.
  • Data residency and retention for case records are configurable to your regulatory obligations.

Compliance support

  • Supports investigation and record-keeping expectations under AML/CFT regimes
  • Underpins suspicious-activity investigation and escalation workflows
  • Provides segregation-of-duties and four-eyes evidence for governance and audit
  • Supports incident, complaint and whistleblowing investigation obligations
  • Supplies documented, timestamped evidence for internal audit and regulatory examination

Reports & exports

  • Case status, ageing and SLA-adherence reports
  • Case outcome and disposition reports
  • Investigator and team workload reports
  • Escalation and four-eyes review reports
  • Full case files with timeline and evidence for audit or regulatory request
  • Management information on case volumes and trends
Best practice

How to get the most from it

Make every alert a case, not an email

Route alerts into structured cases from the start. The moment work happens in a shared inbox, it stops being defensible.

Capture reasoning inline

Record findings and rationale on the case as the investigation proceeds, not afterwards. Contemporaneous notes are the strongest evidence.

Enforce four-eyes on material decisions

Use role-based review so significant dispositions are independently signed off — and so you can prove they were.

Link entities early

Connect related people, organisations and events as they surface. Relationship links are what reveal patterns a single-record view would miss.

FAQ

Questions, answered

How do alerts become cases?

Alerts, referrals and incidents from screening, monitoring and other modules are routed into structured cases automatically, with type, priority, subject and owner, so investigation starts from a system of record rather than a mailbox.

Can we configure our own case workflow?

Yes. Case stages, ownership rules, SLAs, escalation paths and the points at which four-eyes review is required are all configurable to your operating model and policy.

How is segregation of duties enforced?

Role-based assignment and approval separate investigation from sign-off where your policy requires it, so the person who investigates a case cannot unilaterally close it — and the review is recorded as evidence.

What happens to the evidence when a case closes?

The full case file — timeline, notes, dispositions, entity links and attached evidence — is preserved in an immutable trail, ready to be retrieved for audit or a regulatory request.

Does this connect to AML screening and monitoring?

Yes. Case Management is the destination for alerts raised by the screening, monitoring and AML modules, and it pulls the relevant customer and entity records so investigators work with the full context.

See Case Management & Investigations in your programme

Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.