Platform
Financial Crime Compliance

Customer Due Diligence

Structured CDD, KYC and KYB mapped to your risk policy

Collect, verify and risk-rate customers and businesses through structured customer-due-diligence, know-your-customer and know-your-business workflows configured to your policy, so every relationship is understood and documented before and throughout onboarding. CDD is the front door of the AML programme: what is captured, verified and rated here determines the quality of screening, monitoring and every decision that follows. OnyxOne Customer Due Diligence turns onboarding from a document-collection exercise into a policy-driven workflow where identity, ownership and risk are established on a consistent standard, evidenced as they are gathered, and carried forward as the customer's living record.

At a glance

How it works, visually

Onboarding-to-evidence lifecycleSchematic
1AlertRaised2TriagePrioritise3InvestigateEvidence4DecisionApprove5ReportAudit-loggedreopenClear ownership and recorded decisions at every stage — a defensible trail from alert to closure.

From onboarding and due diligence through review, approval and remediation to an evidenced, audit-logged outcome.

The challenge

The problems this module solves

The operational realities that make this hard for compliance and risk teams today.

Onboarding is a manual document chase

Analysts collect identity documents by email, chase missing items by hand, and re-key data into multiple systems. The process is slow, the customer experience is poor, and information gathered at onboarding is scattered the moment it arrives rather than forming a single record.

The standard varies by analyst and by day

Without a structured workflow, what counts as sufficient due diligence depends on who did it and how busy they were. One customer is diligenced thoroughly, the next thinly, and the firm cannot demonstrate a consistent CDD standard across its book.

Beneficial ownership is hard to establish and harder to evidence

For corporate customers, working out who ultimately owns and controls the business means untangling layered structures by hand, and the resulting picture lives in a spreadsheet with no trail of how it was reached. When ownership changes, nothing prompts a refresh.

Risk rating is disconnected from the diligence behind it

Customers are assigned a risk rating, but the factors that justify it are not captured alongside the rating. When an examiner asks why a customer was rated low or high risk, the rationale has to be reconstructed from memory rather than read off the record.

The CDD record is a snapshot that immediately ages

Due diligence is treated as a one-off completed at onboarding, then filed. There is no structured link between the CDD record and the events, screening results and reviews that should keep it current, so it describes the customer as they were, not as they are.

The approach

How OnyxOne addresses it

A policy-driven onboarding workflow

CDD, KYC and KYB run on a structured workflow configured to your policy — the data to collect, the verification required, the checks to run — with different paths for individuals, businesses and risk tiers. Requirements are enforced consistently rather than left to each analyst's judgement of what is enough.

Identity and business verification in the flow

Identity and business-registration verification are performed within onboarding through your existing verification services, with the result and its evidence captured against the record. Screening runs as part of the same flow, so a customer is verified, screened and rated in one connected process.

Beneficial-ownership mapping with a trail

For corporate customers, ownership and control structures are mapped, ultimate beneficial owners identified against your threshold, and the basis for each conclusion recorded. The structure is a living part of the record, and a change in ownership can trigger a refresh rather than going unnoticed.

Risk rating tied to its evidence

Customers are risk-rated against your own factors, weightings and thresholds, and the factors behind each rating are captured automatically. The rationale for why a customer sits at a given risk level is always on the record, ready for an examiner rather than reconstructed for one.

A living customer record, not a snapshot

The CDD record is the customer's living AML file. Screening results, ongoing-monitoring events, reviews and re-ratings write back to it, and periodic and trigger-based reviews keep it current — so diligence reflects the customer as they are, not only as they were at onboarding.

Capabilities

What's in the module

Turn on what you need and add more as your programme scales.

Configurable CDD workflow

Structured onboarding paths with the data, verification and checks required by your policy, differentiated by customer type and risk tier.

KYC identity verification

Verify individual identity through your existing verification services, with the result and evidence captured against the record.

KYB business verification

Verify business registration, status and structure for corporate customers as part of the same onboarding flow.

Beneficial-ownership mapping

Map ownership and control structures, identify ultimate beneficial owners against your threshold, and record the basis for each.

Integrated screening

Run sanctions, PEP and adverse-media screening within onboarding so verification and screening are one connected step.

Customer risk rating

Score risk against your own factors, weightings and thresholds, with the rationale captured alongside the rating.

Document collection & verification

Request, receive and validate supporting documents in the workflow rather than by email, with completeness enforced.

Periodic & trigger-based review

Schedule refreshes by risk tier and re-open diligence automatically on trigger events that change the customer's risk.

Living customer record

A single AML file per customer that screening, monitoring and reviews write back to, kept current over the relationship.

Immutable diligence trail

Every check, verification, ownership conclusion, rating and review is written to an append-only record.

Dashboards

The views your team works from

Purpose-built dashboards and views, each answering a question a specific role needs to act on.

An executive viewIllustrative
ILLUSTRATIVE EXAMPLEOPEN CASES128SLA ADHERENCE96%SCREENING ALERTS1.2kOVERDUE REVIEWS14Cases by categoryAMLKYCFraudSanctionsConductOtherRisk mixby tierHighMediumLow

A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.

Onboarding pipeline

Customers moving through CDD by stage, with outstanding requirements, ageing and bottlenecks surfaced for follow-up.

Risk-rating distribution

The book by customer risk tier, with the factors driving ratings and shifts in distribution over time.

Ownership explorer

Corporate ownership and control structures with ultimate beneficial owners highlighted and the basis for each recorded.

Review scheduler

Periodic reviews due and overdue by risk tier, so refreshes keep pace with the risk they are meant to manage.

Verification status

Identity and business verification outcomes and document completeness across onboarding, with exceptions flagged.

Automation

What the platform automates

Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.

Requirement enforcement

The workflow requests exactly the data, documents and checks your policy requires for the customer type and blocks completion until they are met.

In-flow verification & screening

Identity verification and sanctions, PEP and adverse-media screening run automatically at the right step, with results captured against the record.

Auto risk rating

Customer risk ratings are calculated from captured factors against your methodology, with the rationale recorded and higher risk escalated.

Review scheduling & reminders

Periodic reviews are scheduled by risk tier and chased before they fall due, and trigger events re-open diligence automatically.

Ownership-change re-diligence

A detected change in beneficial ownership automatically flags the record for refreshed diligence rather than going unnoticed.

AI assistance

Where AI helps the analyst

Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.

Document data extraction

Reads submitted identity and registration documents and pre-fills the record, which the analyst reviews and confirms before it is accepted.

Ownership-structure suggestion

Proposes a beneficial-ownership structure from registry and document data for the analyst to verify, correct and approve.

Risk-factor prompting

Highlights attributes that may warrant a higher risk rating or enhanced due diligence, prompting the analyst rather than deciding for them.

The workflow

The enterprise workflow

A defined, end-to-end process with clear ownership at every stage.

The workflow, step by stepSchematic
01CaptureCustomer and business information is collected through a structured workflowconfigured to your policy, with the right requirements for the customer type.02Verify identity & ownershipIdentity and business registration are verified through your existing services, andbeneficial ownership is mapped with the basis recorded.03ScreenSanctions, PEP and adverse-media screening runs within the same flow, with anymatches captured against the record for review.04Risk-rateThe customer is scored against your risk-rating methodology, and the factors behindthe rating are recorded so it is defensible.05Decide & onboardOnboarding is approved, declined or escalated to enhanced due diligence, with thedecision and its rationale documented.06Keep currentPeriodic and trigger-based reviews refresh the record over the relationship, sodiligence reflects the customer as they are.

Every result, decision and override is captured against the record it belongs to.

01

Capture

Customer and business information is collected through a structured workflow configured to your policy, with the right requirements for the customer type.

02

Verify identity & ownership

Identity and business registration are verified through your existing services, and beneficial ownership is mapped with the basis recorded.

03

Screen

Sanctions, PEP and adverse-media screening runs within the same flow, with any matches captured against the record for review.

04

Risk-rate

The customer is scored against your risk-rating methodology, and the factors behind the rating are recorded so it is defensible.

05

Decide & onboard

Onboarding is approved, declined or escalated to enhanced due diligence, with the decision and its rationale documented.

06

Keep current

Periodic and trigger-based reviews refresh the record over the relationship, so diligence reflects the customer as they are.

The value

What your team gains

Consistent

One CDD standard across the book

A policy-driven workflow enforces the same requirements for every customer of a given type, so the firm can demonstrate a consistent diligence standard.

Connected

Verify, screen and rate in one flow

Identity verification, screening and risk rating run as one connected process, so a customer is fully understood before onboarding completes.

Evidenced

Ratings you can justify

Risk factors are captured with the rating, so the answer to why a customer sits at a given risk level is already on the record.

Living

A record that stays current

Screening, monitoring and reviews write back to the customer's AML file, so diligence reflects reality rather than the day of onboarding.

Faster, cleaner onboarding

Structured collection and in-flow verification replace the email document chase, improving both throughput and the customer experience.

Ownership that is understood, not guessed

Beneficial-ownership mapping with a recorded basis means the firm knows who it is really dealing with and can evidence how it concluded that.

Built for

Industries it serves

BankingFinancial ServicesFintechLendingInvestment FirmsInsuranceWealth ManagementCorporate & Trust Service ProvidersGaming
Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.

Identity & verification
  • Integrates with your existing identity-verification, document-checking and KYB data services to verify individuals and businesses in the flow
Screening & data sources
  • Runs sanctions, PEP and adverse-media screening through the data providers configured for your deployment as part of onboarding
Beneficial-ownership data
  • Draws corporate registry and ownership data from your existing sources to support ownership mapping
Core banking & customer systems
  • Reads and writes customer records to your existing core systems so the CDD file and the customer master stay aligned
Collaboration & notification
  • Routes information requests, approvals and review tasks through your existing email and messaging tools
Assurance

Security, compliance & reporting

Security & data handling

  • Customer identity data, documents and diligence records are encrypted in transit and at rest, with access governed by granular, role-based permissions.
  • Personal and identity documents are restricted to authorised roles and handled under strict need-to-know and data-minimisation principles.
  • Segregation of duties can prevent the same person from both performing and signing off diligence where policy requires it.
  • Every check, verification, ownership conclusion, rating and review is written to an append-only audit trail.
  • Data residency and retention for customer records and documents are configurable to your regulatory and privacy obligations.

Compliance support

  • Supports customer-due-diligence (CDD), know-your-customer (KYC) and know-your-business (KYB) obligations
  • Underpins beneficial-ownership identification and verification requirements
  • Supports risk-based customer risk rating and periodic-review obligations
  • Feeds sanctions, PEP and adverse-media screening requirements at onboarding
  • Provides the record-keeping and audit-trail evidence expected by AML supervisors
  • OnyxOne is a technology vendor, not an obliged entity — responsibility for CDD obligations remains with your firm

Reports & exports

  • CDD completion and outstanding-requirement reports by customer and segment
  • Customer risk-rating distribution and re-rating reports
  • Beneficial-ownership and control-structure reports
  • Verification-outcome and document-completeness reports
  • Periodic-review due, overdue and coverage reports
  • Onboarding decision and escalation reports for the compliance function
Best practice

How to get the most from it

Differentiate diligence by risk

Configure lighter paths for low-risk customers and deeper ones for higher risk. A risk-based CDD workflow puts effort where it matters instead of applying the same heavy process to everyone.

Capture the rating's rationale as you rate

Record the factors behind a risk rating at the moment it is set. The cheapest time to justify a rating is when you assign it, not when an examiner questions it.

Map ownership, and record how you concluded

For corporate customers, keep the basis for each beneficial-ownership conclusion on the record. A structure with no trail of how it was derived is hard to defend and easy to get wrong.

Keep the record alive after onboarding

Link screening, monitoring and reviews back to the CDD file and refresh on trigger events. Diligence that is never revisited describes a customer who no longer exists.

FAQ

Questions, answered

What is the difference between CDD, KYC and KYB?

KYC verifies the identity of individual customers and KYB verifies businesses and their structures. CDD is the wider discipline that includes both, plus risk rating, beneficial-ownership work and ongoing review. OnyxOne runs all of them in one configured workflow so onboarding is a single connected process.

Does OnyxOne verify identity itself?

It performs verification through your existing identity, document and KYB data services, orchestrating the checks within the onboarding flow and capturing the result and its evidence against the record. The underlying verification data comes from the services you contract; OnyxOne runs and evidences the process.

How does risk rating work?

Customers are scored against your own risk factors, weightings and thresholds, and the factors behind each rating are captured automatically. Ratings drive whether a customer proceeds on standard CDD or is escalated to enhanced due diligence, and re-rate on trigger events.

How does OnyxOne handle beneficial ownership?

For corporate customers it maps ownership and control structures, identifies ultimate beneficial owners against the threshold in your policy, and records the basis for each conclusion. A change in ownership can trigger a refresh so the picture stays current.

Is OnyxOne responsible for the CDD decision?

No. OnyxOne structures and evidences the diligence, but a person makes the onboarding decision and owns it. OnyxOne is a technology vendor and decision-support software; responsibility for CDD obligations remains with your firm.

See Customer Due Diligence in your programme

Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.