Customer Due Diligence
Structured CDD, KYC and KYB mapped to your risk policy
Collect, verify and risk-rate customers and businesses through structured customer-due-diligence, know-your-customer and know-your-business workflows configured to your policy, so every relationship is understood and documented before and throughout onboarding. CDD is the front door of the AML programme: what is captured, verified and rated here determines the quality of screening, monitoring and every decision that follows. OnyxOne Customer Due Diligence turns onboarding from a document-collection exercise into a policy-driven workflow where identity, ownership and risk are established on a consistent standard, evidenced as they are gathered, and carried forward as the customer's living record.
How it works, visually
From onboarding and due diligence through review, approval and remediation to an evidenced, audit-logged outcome.
The problems this module solves
The operational realities that make this hard for compliance and risk teams today.
Onboarding is a manual document chase
Analysts collect identity documents by email, chase missing items by hand, and re-key data into multiple systems. The process is slow, the customer experience is poor, and information gathered at onboarding is scattered the moment it arrives rather than forming a single record.
The standard varies by analyst and by day
Without a structured workflow, what counts as sufficient due diligence depends on who did it and how busy they were. One customer is diligenced thoroughly, the next thinly, and the firm cannot demonstrate a consistent CDD standard across its book.
Beneficial ownership is hard to establish and harder to evidence
For corporate customers, working out who ultimately owns and controls the business means untangling layered structures by hand, and the resulting picture lives in a spreadsheet with no trail of how it was reached. When ownership changes, nothing prompts a refresh.
Risk rating is disconnected from the diligence behind it
Customers are assigned a risk rating, but the factors that justify it are not captured alongside the rating. When an examiner asks why a customer was rated low or high risk, the rationale has to be reconstructed from memory rather than read off the record.
The CDD record is a snapshot that immediately ages
Due diligence is treated as a one-off completed at onboarding, then filed. There is no structured link between the CDD record and the events, screening results and reviews that should keep it current, so it describes the customer as they were, not as they are.
How OnyxOne addresses it
A policy-driven onboarding workflow
CDD, KYC and KYB run on a structured workflow configured to your policy — the data to collect, the verification required, the checks to run — with different paths for individuals, businesses and risk tiers. Requirements are enforced consistently rather than left to each analyst's judgement of what is enough.
Identity and business verification in the flow
Identity and business-registration verification are performed within onboarding through your existing verification services, with the result and its evidence captured against the record. Screening runs as part of the same flow, so a customer is verified, screened and rated in one connected process.
Beneficial-ownership mapping with a trail
For corporate customers, ownership and control structures are mapped, ultimate beneficial owners identified against your threshold, and the basis for each conclusion recorded. The structure is a living part of the record, and a change in ownership can trigger a refresh rather than going unnoticed.
Risk rating tied to its evidence
Customers are risk-rated against your own factors, weightings and thresholds, and the factors behind each rating are captured automatically. The rationale for why a customer sits at a given risk level is always on the record, ready for an examiner rather than reconstructed for one.
A living customer record, not a snapshot
The CDD record is the customer's living AML file. Screening results, ongoing-monitoring events, reviews and re-ratings write back to it, and periodic and trigger-based reviews keep it current — so diligence reflects the customer as they are, not only as they were at onboarding.
What's in the module
Turn on what you need and add more as your programme scales.
Configurable CDD workflow
Structured onboarding paths with the data, verification and checks required by your policy, differentiated by customer type and risk tier.
KYC identity verification
Verify individual identity through your existing verification services, with the result and evidence captured against the record.
KYB business verification
Verify business registration, status and structure for corporate customers as part of the same onboarding flow.
Beneficial-ownership mapping
Map ownership and control structures, identify ultimate beneficial owners against your threshold, and record the basis for each.
Integrated screening
Run sanctions, PEP and adverse-media screening within onboarding so verification and screening are one connected step.
Customer risk rating
Score risk against your own factors, weightings and thresholds, with the rationale captured alongside the rating.
Document collection & verification
Request, receive and validate supporting documents in the workflow rather than by email, with completeness enforced.
Periodic & trigger-based review
Schedule refreshes by risk tier and re-open diligence automatically on trigger events that change the customer's risk.
Living customer record
A single AML file per customer that screening, monitoring and reviews write back to, kept current over the relationship.
Immutable diligence trail
Every check, verification, ownership conclusion, rating and review is written to an append-only record.
The views your team works from
Purpose-built dashboards and views, each answering a question a specific role needs to act on.
A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.
Onboarding pipeline
Customers moving through CDD by stage, with outstanding requirements, ageing and bottlenecks surfaced for follow-up.
Risk-rating distribution
The book by customer risk tier, with the factors driving ratings and shifts in distribution over time.
Ownership explorer
Corporate ownership and control structures with ultimate beneficial owners highlighted and the basis for each recorded.
Review scheduler
Periodic reviews due and overdue by risk tier, so refreshes keep pace with the risk they are meant to manage.
Verification status
Identity and business verification outcomes and document completeness across onboarding, with exceptions flagged.
What the platform automates
Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.
Requirement enforcement
The workflow requests exactly the data, documents and checks your policy requires for the customer type and blocks completion until they are met.
In-flow verification & screening
Identity verification and sanctions, PEP and adverse-media screening run automatically at the right step, with results captured against the record.
Auto risk rating
Customer risk ratings are calculated from captured factors against your methodology, with the rationale recorded and higher risk escalated.
Review scheduling & reminders
Periodic reviews are scheduled by risk tier and chased before they fall due, and trigger events re-open diligence automatically.
Ownership-change re-diligence
A detected change in beneficial ownership automatically flags the record for refreshed diligence rather than going unnoticed.
Where AI helps the analyst
Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.
Document data extraction
Reads submitted identity and registration documents and pre-fills the record, which the analyst reviews and confirms before it is accepted.
Ownership-structure suggestion
Proposes a beneficial-ownership structure from registry and document data for the analyst to verify, correct and approve.
Risk-factor prompting
Highlights attributes that may warrant a higher risk rating or enhanced due diligence, prompting the analyst rather than deciding for them.
The enterprise workflow
A defined, end-to-end process with clear ownership at every stage.
Every result, decision and override is captured against the record it belongs to.
Capture
Customer and business information is collected through a structured workflow configured to your policy, with the right requirements for the customer type.
Verify identity & ownership
Identity and business registration are verified through your existing services, and beneficial ownership is mapped with the basis recorded.
Screen
Sanctions, PEP and adverse-media screening runs within the same flow, with any matches captured against the record for review.
Risk-rate
The customer is scored against your risk-rating methodology, and the factors behind the rating are recorded so it is defensible.
Decide & onboard
Onboarding is approved, declined or escalated to enhanced due diligence, with the decision and its rationale documented.
Keep current
Periodic and trigger-based reviews refresh the record over the relationship, so diligence reflects the customer as they are.
What your team gains
One CDD standard across the book
A policy-driven workflow enforces the same requirements for every customer of a given type, so the firm can demonstrate a consistent diligence standard.
Verify, screen and rate in one flow
Identity verification, screening and risk rating run as one connected process, so a customer is fully understood before onboarding completes.
Ratings you can justify
Risk factors are captured with the rating, so the answer to why a customer sits at a given risk level is already on the record.
A record that stays current
Screening, monitoring and reviews write back to the customer's AML file, so diligence reflects reality rather than the day of onboarding.
Faster, cleaner onboarding
Structured collection and in-flow verification replace the email document chase, improving both throughput and the customer experience.
Ownership that is understood, not guessed
Beneficial-ownership mapping with a recorded basis means the firm knows who it is really dealing with and can evidence how it concluded that.
Industries it serves
Works with your existing systems
Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.
- Integrates with your existing identity-verification, document-checking and KYB data services to verify individuals and businesses in the flow
- Runs sanctions, PEP and adverse-media screening through the data providers configured for your deployment as part of onboarding
- Draws corporate registry and ownership data from your existing sources to support ownership mapping
- Reads and writes customer records to your existing core systems so the CDD file and the customer master stay aligned
- Routes information requests, approvals and review tasks through your existing email and messaging tools
Security, compliance & reporting
Security & data handling
- Customer identity data, documents and diligence records are encrypted in transit and at rest, with access governed by granular, role-based permissions.
- Personal and identity documents are restricted to authorised roles and handled under strict need-to-know and data-minimisation principles.
- Segregation of duties can prevent the same person from both performing and signing off diligence where policy requires it.
- Every check, verification, ownership conclusion, rating and review is written to an append-only audit trail.
- Data residency and retention for customer records and documents are configurable to your regulatory and privacy obligations.
Compliance support
- Supports customer-due-diligence (CDD), know-your-customer (KYC) and know-your-business (KYB) obligations
- Underpins beneficial-ownership identification and verification requirements
- Supports risk-based customer risk rating and periodic-review obligations
- Feeds sanctions, PEP and adverse-media screening requirements at onboarding
- Provides the record-keeping and audit-trail evidence expected by AML supervisors
- OnyxOne is a technology vendor, not an obliged entity — responsibility for CDD obligations remains with your firm
Reports & exports
- CDD completion and outstanding-requirement reports by customer and segment
- Customer risk-rating distribution and re-rating reports
- Beneficial-ownership and control-structure reports
- Verification-outcome and document-completeness reports
- Periodic-review due, overdue and coverage reports
- Onboarding decision and escalation reports for the compliance function
How to get the most from it
Differentiate diligence by risk
Configure lighter paths for low-risk customers and deeper ones for higher risk. A risk-based CDD workflow puts effort where it matters instead of applying the same heavy process to everyone.
Capture the rating's rationale as you rate
Record the factors behind a risk rating at the moment it is set. The cheapest time to justify a rating is when you assign it, not when an examiner questions it.
Map ownership, and record how you concluded
For corporate customers, keep the basis for each beneficial-ownership conclusion on the record. A structure with no trail of how it was derived is hard to defend and easy to get wrong.
Keep the record alive after onboarding
Link screening, monitoring and reviews back to the CDD file and refresh on trigger events. Diligence that is never revisited describes a customer who no longer exists.
Questions, answered
What is the difference between CDD, KYC and KYB?
KYC verifies the identity of individual customers and KYB verifies businesses and their structures. CDD is the wider discipline that includes both, plus risk rating, beneficial-ownership work and ongoing review. OnyxOne runs all of them in one configured workflow so onboarding is a single connected process.
Does OnyxOne verify identity itself?
It performs verification through your existing identity, document and KYB data services, orchestrating the checks within the onboarding flow and capturing the result and its evidence against the record. The underlying verification data comes from the services you contract; OnyxOne runs and evidences the process.
How does risk rating work?
Customers are scored against your own risk factors, weightings and thresholds, and the factors behind each rating are captured automatically. Ratings drive whether a customer proceeds on standard CDD or is escalated to enhanced due diligence, and re-rate on trigger events.
How does OnyxOne handle beneficial ownership?
For corporate customers it maps ownership and control structures, identifies ultimate beneficial owners against the threshold in your policy, and records the basis for each conclusion. A change in ownership can trigger a refresh so the picture stays current.
Is OnyxOne responsible for the CDD decision?
No. OnyxOne structures and evidences the diligence, but a person makes the onboarding decision and owns it. OnyxOne is a technology vendor and decision-support software; responsibility for CDD obligations remains with your firm.
Related modules
See Customer Due Diligence in your programme
Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.