Compliance Management
Obligations, controls and attestation in one connected view
A single home for the compliance programme — a library of regulatory obligations mapped to the policies and controls that address them, with attestation, task tracking and coverage reporting — so the firm can show what it must do and prove it is doing it. OnyxOne Compliance Management replaces obligation spreadsheets, disconnected control lists and manual coverage reviews with one connected model where every requirement traces to the control that satisfies it and the evidence that it works.
How it works, visually
How an obligation or event is triaged, escalated when it matters, and recorded either way.
The problems this module solves
The operational realities that make this hard for compliance and risk teams today.
Obligations live in a spreadsheet nobody maintains
The firm's regulatory obligations are captured once in a spreadsheet, then drift out of date as rules change and the business evolves. There is no clear owner, no link to the controls that satisfy each obligation, and no confidence the list is even complete.
No line of sight from requirement to control
A regulation imposes a requirement, a policy states an intention and a control is meant to enforce it — but these live in different tools maintained by different teams. Nobody can trace an obligation to the control that satisfies it, so 'we comply' is asserted rather than demonstrated.
Coverage gaps surface only in an exam
Because obligations and controls aren't connected, gaps — a requirement with no control, a control that isn't tested — stay hidden until a regulator or auditor finds them. The firm is perpetually reacting to findings instead of seeing its own coverage.
Compliance tasks are tracked in inboxes
Attestations, reviews, remediation and recurring obligations are chased over email and tracked in personal spreadsheets. Deadlines slip, completion is invisible to oversight, and there is no clean record that recurring compliance work was actually done.
Reporting compliance status is a manual grind
Producing a picture of programme health — coverage, overdue tasks, attestation rates, open gaps — means collating from multiple sources by hand. By the time the report is assembled it is already stale, and leadership sees a snapshot rather than the live position.
How OnyxOne addresses it
A single obligations library with owners
Capture every regulatory obligation in one structured library, each with an owner, source reference and applicability to the parts of the business it affects. Obligations become a maintained, owned asset rather than an orphaned spreadsheet, and completeness is something you can see and govern.
Obligations mapped to policies and controls
Each obligation links to the policies that express how the firm meets it and the controls that enforce it. The full line — regulation to obligation to policy to control to evidence — is traceable, so compliance is demonstrated through mapped, tested controls rather than asserted.
Coverage gaps made visible
Because obligations and controls are connected, the platform surfaces gaps directly: obligations with no mapped control, controls that aren't tested, requirements whose controls have failed. Weaknesses are visible to the firm before they are visible to an examiner.
Compliance tasks tracked in one place
Attestations, reviews, recurring obligations and remediation are managed as tracked tasks with owners, due dates and automated reminders. Recurring compliance work runs on schedule, completion is visible to oversight, and there is a clean record that it happened.
Live programme reporting
Coverage, attestation rates, overdue tasks and open gaps are reported from the live model rather than collated by hand. Leadership and the board see the current state of the compliance programme, with the detail to drill into any obligation or control.
What's in the module
Turn on what you need and add more as your programme scales.
Obligations library
A structured, owned register of regulatory obligations with source references and applicability to the business.
Obligation-to-control mapping
Link each obligation to the policies and controls that satisfy it for full regulation-to-control traceability.
Coverage & gap analysis
Surface obligations with no control, untested controls and failed controls so gaps are visible before an exam.
Attestation management
Request, track and evidence compliance attestations from the roles and groups they apply to.
Compliance task management
Manage recurring and ad-hoc compliance tasks with owners, due dates, reminders and completion evidence.
Requirement applicability
Scope obligations to the entities, products, jurisdictions and units they actually apply to.
Control reliance
Draw on the internal-controls module so obligation coverage reflects real control testing rather than assertion.
Remediation & action tracking
Turn gaps and findings into tracked remediation actions with owners and target dates.
Regulatory change linkage
Connect obligations to the regulatory-change pipeline so new and amended rules update the library.
Immutable compliance trail
Every mapping, attestation, task and remediation is written to an append-only audit record.
The views your team works from
Purpose-built dashboards and views, each answering a question a specific role needs to act on.
A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.
Obligations register
The full obligations library with owner, source and applicability, filterable by jurisdiction, business unit and theme.
Coverage heat map
Obligations against their mapped controls, highlighting gaps, untested controls and failed controls at a glance.
Attestation tracker
Attestation campaigns with coverage, outstanding acknowledgements and reminders sent, by role and group.
Compliance task board
Recurring and ad-hoc compliance tasks by owner and due date, showing completion and what is overdue.
Programme health
A leadership view of coverage, attestation rates, overdue work and open gaps across the whole compliance programme.
What the platform automates
Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.
Recurring task scheduling
Recurring compliance obligations generate tasks on their cadence automatically, with owners assigned and reminders sent.
Attestation campaigns
Attestations are issued to the right roles and groups, tracked, and chased automatically until coverage is complete.
Gap detection alerts
New obligations without a mapped control, or controls that fail testing, raise a gap and notify the owner without manual review.
Change-driven library updates
Approved regulatory changes update or create obligations in the library and flag the mappings that need review.
Remediation follow-up
Gaps and findings become tracked actions that are reminded before they fall due and escalated when they slip.
Where AI helps the analyst
Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.
Obligation extraction assistance
Proposes discrete obligations from regulatory text for a compliance owner to review, refine and accept — the human decides what enters the library.
Control-mapping suggestions
Suggests existing controls that may satisfy an obligation based on similarity, which a person confirms rather than the system mapping automatically.
Coverage-narrative drafting
Drafts plain-language explanations of how the firm meets an obligation from its mapped controls and evidence, for the owner to review and own.
The enterprise workflow
A defined, end-to-end process with clear ownership at every stage.
Every result, decision and override is captured against the record it belongs to.
Build the obligations library
Capture regulatory obligations in one structured library, each with an owner, source reference and applicability to the business.
Map to policies & controls
Link each obligation to the policies that express it and the controls that enforce it, establishing end-to-end traceability.
Assess coverage
Identify obligations without controls, controls without testing and failed controls, exposing gaps before an examiner does.
Attest & operate tasks
Run attestations and recurring compliance tasks with owners and due dates, with completion tracked and evidenced.
Remediate gaps
Turn coverage gaps and findings into tracked remediation actions with owners, milestones and target dates.
Report programme health
Report coverage, attestation rates, overdue tasks and open gaps from the live model to oversight and the board.
What your team gains
Regulation to control, evidenced
Every obligation traces to the policy and tested control that satisfies it, so compliance is demonstrated rather than asserted.
One maintained obligations library
An owned, structured library replaces the orphaned spreadsheet, so what the firm must do is current, complete and governed.
Gaps you find before the regulator
Connected obligations and controls surface coverage gaps directly, so weaknesses are addressed rather than discovered in an exam.
Compliance work that runs on time
Attestations and recurring tasks run on schedule with visible completion, replacing inbox chasing with an auditable record.
Programme health at a glance
Coverage, attestation and overdue-task reporting comes from the live model, so leadership sees the current state, not a stale snapshot.
Exams and audits without the scramble
Because mappings, attestations and evidence accrue as work happens, examination evidence is retrieved rather than reconstructed.
Industries it serves
Works with your existing systems
Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.
- Maps obligations to the policies in policy management and the controls in internal controls for end-to-end traceability and tested coverage
- Connects to the regulatory-change pipeline so new and amended obligations flow into the library with impact assessed
- Draws on the regulatory knowledge base so obligations reference the underlying rules and interpretation
- Targets attestations and tasks to the right roles and groups using your existing identity provider and HR directory
- Routes attestations, task reminders and remediation actions through your existing email and messaging channels
Security, compliance & reporting
Security & data handling
- Obligations, mappings, attestations and tasks are encrypted in transit and at rest, with access governed by role-based permissions.
- Sensitive obligation or remediation detail can be restricted to named compliance and oversight roles.
- Segregation of duties can prevent the same person from both performing and signing off a compliance task where policy requires it.
- Every mapping, attestation, task and remediation action is written to an append-only audit trail.
- Retention of attestation and compliance-task records is configurable to your regulatory obligations.
Compliance support
- Provides the obligation-to-control mapping expected under conduct, prudential and financial-crime regimes
- Supports the compliance layer of a three-lines-of-defence model
- Supplies attestation and coverage evidence for regulatory examination
- Supports data-protection and information-governance obligation management including GDPR
- Links to regulatory change so the obligation library stays aligned to current rules
Reports & exports
- Obligations library with owner, source and applicability
- Obligation-to-control coverage and gap reports
- Attestation coverage and outstanding-attestation reports
- Compliance task completion and overdue-task reports
- Remediation-action status reports
- Programme-health and board compliance packs
How to get the most from it
Give every obligation an owner
An obligation without a named owner is nobody's job. Assign ownership at capture so the library is maintained and completeness is governed rather than assumed.
Map to tested controls, not intentions
Link obligations to controls whose effectiveness is actually tested. Coverage backed by a policy statement but no tested control will not survive an examination.
Treat gaps as a live queue
Work coverage gaps as they appear rather than at audit time. The point of connecting obligations to controls is to see and close weaknesses continuously.
Let regulatory change feed the library
Wire the regulatory-change pipeline into the obligations library so new and amended rules update it. A library that only updates manually will fall behind the rules it tracks.
Questions, answered
How does obligation-to-control mapping work?
Each obligation in the library links to the policies that express how the firm meets it and the controls that enforce it. This creates a traceable line from regulation to obligation to policy to control to evidence, so compliance is demonstrated through tested controls rather than asserted.
How are coverage gaps identified?
Because obligations and controls are connected, the platform surfaces obligations with no mapped control, controls that aren't tested and requirements whose controls have failed — so gaps are visible to the firm before they are visible to an examiner.
Can we run attestations through this module?
Yes. You request attestations from the roles and groups an obligation applies to, and the platform tracks who has attested, sends reminders automatically and records each attestation as evidence, with coverage visible at a glance.
Does coverage reflect real control testing?
Yes. The module draws on the internal-controls module, so obligation coverage reflects the actual design and tested operating effectiveness of the mapped controls rather than a manual assertion that a control exists.
How does the library stay current with regulation?
The obligations library connects to the regulatory-change pipeline, so new and amended rules flow in with their impact assessed and update the obligations, keeping the library aligned to the current regulatory landscape.
Related modules
See Compliance Management in your programme
Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.