Platform
Compliance Management

Compliance Management

Obligations, controls and attestation in one connected view

A single home for the compliance programme — a library of regulatory obligations mapped to the policies and controls that address them, with attestation, task tracking and coverage reporting — so the firm can show what it must do and prove it is doing it. OnyxOne Compliance Management replaces obligation spreadsheets, disconnected control lists and manual coverage reviews with one connected model where every requirement traces to the control that satisfies it and the evidence that it works.

At a glance

How it works, visually

A representative compliance flowSchematic
Item receivedOnboarding / eventRiskthreshold?Auto-clearLow risk · loggedEscalate to reviewAnalyst investigatesRecord &auditNoYes — parallel review paths

How an obligation or event is triaged, escalated when it matters, and recorded either way.

The challenge

The problems this module solves

The operational realities that make this hard for compliance and risk teams today.

Obligations live in a spreadsheet nobody maintains

The firm's regulatory obligations are captured once in a spreadsheet, then drift out of date as rules change and the business evolves. There is no clear owner, no link to the controls that satisfy each obligation, and no confidence the list is even complete.

No line of sight from requirement to control

A regulation imposes a requirement, a policy states an intention and a control is meant to enforce it — but these live in different tools maintained by different teams. Nobody can trace an obligation to the control that satisfies it, so 'we comply' is asserted rather than demonstrated.

Coverage gaps surface only in an exam

Because obligations and controls aren't connected, gaps — a requirement with no control, a control that isn't tested — stay hidden until a regulator or auditor finds them. The firm is perpetually reacting to findings instead of seeing its own coverage.

Compliance tasks are tracked in inboxes

Attestations, reviews, remediation and recurring obligations are chased over email and tracked in personal spreadsheets. Deadlines slip, completion is invisible to oversight, and there is no clean record that recurring compliance work was actually done.

Reporting compliance status is a manual grind

Producing a picture of programme health — coverage, overdue tasks, attestation rates, open gaps — means collating from multiple sources by hand. By the time the report is assembled it is already stale, and leadership sees a snapshot rather than the live position.

The approach

How OnyxOne addresses it

A single obligations library with owners

Capture every regulatory obligation in one structured library, each with an owner, source reference and applicability to the parts of the business it affects. Obligations become a maintained, owned asset rather than an orphaned spreadsheet, and completeness is something you can see and govern.

Obligations mapped to policies and controls

Each obligation links to the policies that express how the firm meets it and the controls that enforce it. The full line — regulation to obligation to policy to control to evidence — is traceable, so compliance is demonstrated through mapped, tested controls rather than asserted.

Coverage gaps made visible

Because obligations and controls are connected, the platform surfaces gaps directly: obligations with no mapped control, controls that aren't tested, requirements whose controls have failed. Weaknesses are visible to the firm before they are visible to an examiner.

Compliance tasks tracked in one place

Attestations, reviews, recurring obligations and remediation are managed as tracked tasks with owners, due dates and automated reminders. Recurring compliance work runs on schedule, completion is visible to oversight, and there is a clean record that it happened.

Live programme reporting

Coverage, attestation rates, overdue tasks and open gaps are reported from the live model rather than collated by hand. Leadership and the board see the current state of the compliance programme, with the detail to drill into any obligation or control.

Capabilities

What's in the module

Turn on what you need and add more as your programme scales.

Obligations library

A structured, owned register of regulatory obligations with source references and applicability to the business.

Obligation-to-control mapping

Link each obligation to the policies and controls that satisfy it for full regulation-to-control traceability.

Coverage & gap analysis

Surface obligations with no control, untested controls and failed controls so gaps are visible before an exam.

Attestation management

Request, track and evidence compliance attestations from the roles and groups they apply to.

Compliance task management

Manage recurring and ad-hoc compliance tasks with owners, due dates, reminders and completion evidence.

Requirement applicability

Scope obligations to the entities, products, jurisdictions and units they actually apply to.

Control reliance

Draw on the internal-controls module so obligation coverage reflects real control testing rather than assertion.

Remediation & action tracking

Turn gaps and findings into tracked remediation actions with owners and target dates.

Regulatory change linkage

Connect obligations to the regulatory-change pipeline so new and amended rules update the library.

Immutable compliance trail

Every mapping, attestation, task and remediation is written to an append-only audit record.

Dashboards

The views your team works from

Purpose-built dashboards and views, each answering a question a specific role needs to act on.

An executive viewIllustrative
ILLUSTRATIVE EXAMPLEOPEN CASES128SLA ADHERENCE96%SCREENING ALERTS1.2kOVERDUE REVIEWS14Cases by categoryAMLKYCFraudSanctionsConductOtherRisk mixby tierHighMediumLow

A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.

Obligations register

The full obligations library with owner, source and applicability, filterable by jurisdiction, business unit and theme.

Coverage heat map

Obligations against their mapped controls, highlighting gaps, untested controls and failed controls at a glance.

Attestation tracker

Attestation campaigns with coverage, outstanding acknowledgements and reminders sent, by role and group.

Compliance task board

Recurring and ad-hoc compliance tasks by owner and due date, showing completion and what is overdue.

Programme health

A leadership view of coverage, attestation rates, overdue work and open gaps across the whole compliance programme.

Automation

What the platform automates

Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.

Recurring task scheduling

Recurring compliance obligations generate tasks on their cadence automatically, with owners assigned and reminders sent.

Attestation campaigns

Attestations are issued to the right roles and groups, tracked, and chased automatically until coverage is complete.

Gap detection alerts

New obligations without a mapped control, or controls that fail testing, raise a gap and notify the owner without manual review.

Change-driven library updates

Approved regulatory changes update or create obligations in the library and flag the mappings that need review.

Remediation follow-up

Gaps and findings become tracked actions that are reminded before they fall due and escalated when they slip.

AI assistance

Where AI helps the analyst

Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.

Obligation extraction assistance

Proposes discrete obligations from regulatory text for a compliance owner to review, refine and accept — the human decides what enters the library.

Control-mapping suggestions

Suggests existing controls that may satisfy an obligation based on similarity, which a person confirms rather than the system mapping automatically.

Coverage-narrative drafting

Drafts plain-language explanations of how the firm meets an obligation from its mapped controls and evidence, for the owner to review and own.

The workflow

The enterprise workflow

A defined, end-to-end process with clear ownership at every stage.

The workflow, step by stepSchematic
01Build the obligations libraryCapture regulatory obligations in one structured library, each with an owner, sourcereference and applicability to the business.02Map to policies & controlsLink each obligation to the policies that express it and the controls that enforceit, establishing end-to-end traceability.03Assess coverageIdentify obligations without controls, controls without testing and failed controls,exposing gaps before an examiner does.04Attest & operate tasksRun attestations and recurring compliance tasks with owners and due dates, withcompletion tracked and evidenced.05Remediate gapsTurn coverage gaps and findings into tracked remediation actions with owners,milestones and target dates.06Report programme healthReport coverage, attestation rates, overdue tasks and open gaps from the live modelto oversight and the board.

Every result, decision and override is captured against the record it belongs to.

01

Build the obligations library

Capture regulatory obligations in one structured library, each with an owner, source reference and applicability to the business.

02

Map to policies & controls

Link each obligation to the policies that express it and the controls that enforce it, establishing end-to-end traceability.

03

Assess coverage

Identify obligations without controls, controls without testing and failed controls, exposing gaps before an examiner does.

04

Attest & operate tasks

Run attestations and recurring compliance tasks with owners and due dates, with completion tracked and evidenced.

05

Remediate gaps

Turn coverage gaps and findings into tracked remediation actions with owners, milestones and target dates.

06

Report programme health

Report coverage, attestation rates, overdue tasks and open gaps from the live model to oversight and the board.

The value

What your team gains

Traceable

Regulation to control, evidenced

Every obligation traces to the policy and tested control that satisfies it, so compliance is demonstrated rather than asserted.

Single source of truth

One maintained obligations library

An owned, structured library replaces the orphaned spreadsheet, so what the firm must do is current, complete and governed.

Visible

Gaps you find before the regulator

Connected obligations and controls surface coverage gaps directly, so weaknesses are addressed rather than discovered in an exam.

Tracked

Compliance work that runs on time

Attestations and recurring tasks run on schedule with visible completion, replacing inbox chasing with an auditable record.

Programme health at a glance

Coverage, attestation and overdue-task reporting comes from the live model, so leadership sees the current state, not a stale snapshot.

Exams and audits without the scramble

Because mappings, attestations and evidence accrue as work happens, examination evidence is retrieved rather than reconstructed.

Built for

Industries it serves

Financial ServicesBankingInsuranceInvestment FirmsFintechAsset ManagementCorporate & Trust Service ProvidersLegal FirmsRegulated Enterprises
Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.

Policies & controls
  • Maps obligations to the policies in policy management and the controls in internal controls for end-to-end traceability and tested coverage
Regulatory change
  • Connects to the regulatory-change pipeline so new and amended obligations flow into the library with impact assessed
Regulatory knowledge
  • Draws on the regulatory knowledge base so obligations reference the underlying rules and interpretation
Identity & HR directory
  • Targets attestations and tasks to the right roles and groups using your existing identity provider and HR directory
Collaboration & notification
  • Routes attestations, task reminders and remediation actions through your existing email and messaging channels
Assurance

Security, compliance & reporting

Security & data handling

  • Obligations, mappings, attestations and tasks are encrypted in transit and at rest, with access governed by role-based permissions.
  • Sensitive obligation or remediation detail can be restricted to named compliance and oversight roles.
  • Segregation of duties can prevent the same person from both performing and signing off a compliance task where policy requires it.
  • Every mapping, attestation, task and remediation action is written to an append-only audit trail.
  • Retention of attestation and compliance-task records is configurable to your regulatory obligations.

Compliance support

  • Provides the obligation-to-control mapping expected under conduct, prudential and financial-crime regimes
  • Supports the compliance layer of a three-lines-of-defence model
  • Supplies attestation and coverage evidence for regulatory examination
  • Supports data-protection and information-governance obligation management including GDPR
  • Links to regulatory change so the obligation library stays aligned to current rules

Reports & exports

  • Obligations library with owner, source and applicability
  • Obligation-to-control coverage and gap reports
  • Attestation coverage and outstanding-attestation reports
  • Compliance task completion and overdue-task reports
  • Remediation-action status reports
  • Programme-health and board compliance packs
Best practice

How to get the most from it

Give every obligation an owner

An obligation without a named owner is nobody's job. Assign ownership at capture so the library is maintained and completeness is governed rather than assumed.

Map to tested controls, not intentions

Link obligations to controls whose effectiveness is actually tested. Coverage backed by a policy statement but no tested control will not survive an examination.

Treat gaps as a live queue

Work coverage gaps as they appear rather than at audit time. The point of connecting obligations to controls is to see and close weaknesses continuously.

Let regulatory change feed the library

Wire the regulatory-change pipeline into the obligations library so new and amended rules update it. A library that only updates manually will fall behind the rules it tracks.

FAQ

Questions, answered

How does obligation-to-control mapping work?

Each obligation in the library links to the policies that express how the firm meets it and the controls that enforce it. This creates a traceable line from regulation to obligation to policy to control to evidence, so compliance is demonstrated through tested controls rather than asserted.

How are coverage gaps identified?

Because obligations and controls are connected, the platform surfaces obligations with no mapped control, controls that aren't tested and requirements whose controls have failed — so gaps are visible to the firm before they are visible to an examiner.

Can we run attestations through this module?

Yes. You request attestations from the roles and groups an obligation applies to, and the platform tracks who has attested, sends reminders automatically and records each attestation as evidence, with coverage visible at a glance.

Does coverage reflect real control testing?

Yes. The module draws on the internal-controls module, so obligation coverage reflects the actual design and tested operating effectiveness of the mapped controls rather than a manual assertion that a control exists.

How does the library stay current with regulation?

The obligations library connects to the regulatory-change pipeline, so new and amended rules flow in with their impact assessed and update the obligations, keeping the library aligned to the current regulatory landscape.

See Compliance Management in your programme

Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.