Governance
Roles, approvals and accountability across the whole programme
The oversight layer of the platform — roles, committees, delegation, approvals and segregation of duties — so the right people make and sign off the right decisions, and accountability is clear and evidenced across every module. OnyxOne Governance replaces org charts in slide decks and approval trails in email with a live model of who is responsible for what, what they are allowed to approve, and a durable record of every decision they made.
How it works, visually
Oversight and the three lines of defence — how accountability is structured across the programme.
The problems this module solves
The operational realities that make this hard for compliance and risk teams today.
Accountability is assumed, not defined
Everyone believes someone owns a control, a policy or a risk — until something fails and it turns out no one did. Responsibilities live in job descriptions and folklore rather than a system, so when a regulator asks 'who is accountable for this', the answer takes a week to assemble and still has gaps.
Approvals happen in email and meetings
Material decisions — signing off a policy, accepting a risk, approving an exception — are made over email or in a committee with minutes nobody can find. There is no durable, queryable record of who approved what, when, and on what basis, so sign-off cannot be produced on demand.
Segregation of duties exists on paper only
Policy says the person who prepares a decision should not be the one who approves it, but nothing enforces it. The same individual drafts and signs off, or a leaver keeps approval rights for months, and the breach only surfaces in an audit finding.
Delegations are invisible and never expire
When an approver goes on leave, authority is handed over informally. There is no record of who holds delegated authority, for what, or until when — so decisions get made by people who technically should not be making them, and reversing a delegation is a scramble.
Committees run on disconnected documents
Boards and committees govern the programme, but their packs, agendas, decisions and actions live in shared drives and inboxes disconnected from the risks, policies and controls they oversee. Oversight becomes a document exercise rather than a live line of sight into the programme.
How OnyxOne addresses it
A live model of roles and responsibilities
Define roles, committees and reporting lines once, and map every responsibility — for a risk, a control, a policy, an obligation — to a named role rather than a person who might move on. Accountability becomes a queryable fact: point at anything in the platform and see who is responsible, who is accountable and who must be consulted or informed.
Approvals captured as durable, structured decisions
Every approval across the platform — policy sign-off, risk acceptance, exception, treatment plan — is recorded as a structured decision with who approved it, when, against which version and on what basis. Sign-off stops being an email thread and becomes an auditable record you can produce instantly.
Segregation of duties enforced by the platform
Configure segregation-of-duties rules so the person who prepares a decision cannot also approve it, and conflicting roles cannot be held at once. The platform blocks the conflict at the point of action rather than surfacing it in a later audit, and flags toxic role combinations for review.
Delegated authority that is explicit and time-boxed
Delegations are granted formally, scoped to specific decisions or limits, and carry an expiry. Everyone can see who currently holds authority for what, delegated authority lapses automatically, and the full chain of who decided under whose authority is preserved.
Committee governance connected to the programme
Run committees on the platform — agendas assembled from live risk, policy and control data, decisions recorded against the items they concern, and actions tracked to closure. Oversight is anchored to the real programme rather than to a static pack prepared the week before.
What's in the module
Turn on what you need and add more as your programme scales.
Roles & responsibility model
Define roles, committees and reporting lines, and map responsibility, accountability and consultation for every governed object.
RACI mapping
Assign responsible, accountable, consulted and informed roles to risks, controls, policies and obligations for unambiguous ownership.
Approval authority matrix
Configure who can approve what, up to which limits, with authority derived from role rather than named individual.
Segregation-of-duties rules
Enforce incompatible-duty and conflicting-role rules at the point of action, blocking breaches before they happen.
Delegated authority
Grant scoped, time-boxed delegations that expire automatically and preserve the full chain of authority.
Committee & meeting management
Assemble agendas from live programme data, record decisions against the items they concern and track actions to closure.
Decision register
A central, structured record of every material decision — approvals, acceptances, exceptions — with basis and version.
Attestation of responsibilities
Ask role-holders to confirm they understand and accept their responsibilities, with tracked coverage.
Access & role certification
Periodically recertify who holds which roles and approval rights, removing access that is no longer justified.
Immutable governance trail
Every role change, delegation, approval and committee decision is written to an append-only audit record.
The views your team works from
Purpose-built dashboards and views, each answering a question a specific role needs to act on.
A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.
Accountability map
A live view of who is responsible and accountable for every risk, control, policy and obligation, navigable by role or by object.
Approvals & decisions
The decision register with pending approvals, recent sign-offs and the basis for each, filterable by type, approver and period.
Segregation-of-duties monitor
Current SoD conflicts, blocked actions and toxic role combinations flagged for review, with status and owner.
Delegations board
Every active delegation with its scope and expiry, plus authority due to lapse, so cover never outlives its purpose.
Committee cockpit
Agendas, decisions and open actions for each committee, anchored to the programme items under oversight.
What the platform automates
Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.
Role-driven approval routing
Decisions route automatically to the correct approver based on role and authority limits, with escalation when they stall.
Delegation expiry
Delegated authority lapses on its expiry date without manual intervention, and holders are reminded before it does.
SoD conflict blocking
Actions that would breach a segregation-of-duties rule are blocked at source and raised for review rather than silently allowed.
Recertification campaigns
Periodic role and access recertification is launched on schedule, chasing outstanding confirmations automatically.
Committee action follow-up
Actions arising from committee decisions are assigned, reminded and escalated until closed.
Where AI helps the analyst
Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.
Conflict-of-duty surfacing
Highlights potentially incompatible role and approval combinations across the model for a human to review and confirm, helping find conflicts that manual review misses.
Decision summarisation
Drafts concise summaries of committee decisions and their basis from the record, which the responsible role reviews and edits before it stands.
Accountability-gap detection
Flags governed objects with missing or ambiguous ownership so a person can assign the right accountable role, never assigning it automatically.
The enterprise workflow
A defined, end-to-end process with clear ownership at every stage.
Every result, decision and override is captured against the record it belongs to.
Model roles & committees
Define the roles, committees and reporting lines that govern the programme, and the responsibilities each one carries.
Assign accountability
Map responsible and accountable roles to risks, controls, policies and obligations so ownership of everything governed is explicit.
Configure authority & SoD
Set the approval-authority matrix and segregation-of-duties rules so the platform knows who may approve what and which duties must stay separate.
Operate approvals & delegation
Decisions route to the right approvers by role; delegated authority is granted with scope and expiry when cover is needed.
Govern in committee
Committees review live risk, policy and control data, record decisions against the items concerned and assign actions with owners.
Certify & evidence
Roles and access are periodically recertified, and the full decision and delegation history stands as governance evidence for audit and the board.
What your team gains
Accountability you can point at
Responsibility for every risk, control and policy maps to a named role, so 'who owns this' is answered instantly rather than assembled after the fact.
Every decision on the record
Approvals, acceptances and exceptions are captured as structured decisions with basis and version, ready to produce on request.
Segregation of duties that holds
Incompatible-duty rules are enforced at the point of action, so conflicts are prevented rather than discovered in an audit finding.
Delegated authority without drift
Delegations are scoped and time-boxed and lapse automatically, so authority never quietly outlives the reason it was granted.
Committees anchored to the real programme
Oversight works from live risk, policy and control data rather than a static pack, so governance reflects the current position.
A clean three-lines-of-defence picture
Clear role separation and mapped accountability make the operation of the three-lines model visible and defensible to audit and regulators.
Industries it serves
Works with your existing systems
Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.
- Aligns roles, reporting lines and approval rights with your existing identity provider and HR directory so leavers and movers update authority automatically
- Maps accountability onto the risks, controls, policies and obligations held in the other OnyxOne modules for end-to-end ownership
- Connects committee agendas, decisions and actions to your existing board-portal and document workflows
- Feeds role and approval-right certifications into your existing access-review and joiner-mover-leaver processes
- Routes approval requests, delegations and committee actions through your existing email and messaging channels
Security, compliance & reporting
Security & data handling
- Roles, delegations and decisions are encrypted in transit and at rest, with access governed by granular, role-based permissions.
- Segregation-of-duties enforcement prevents incompatible responsibilities from being held or exercised by the same person.
- Delegated authority is scoped and time-boxed, and lapses automatically without manual intervention.
- Every role change, delegation, approval and committee decision is written to an append-only audit trail.
- Board- and committee-sensitive material can be restricted to named roles and withheld from wider visibility.
- Retention of decision and delegation records is configurable to your regulatory and record-keeping obligations.
Compliance support
- Underpins three-lines-of-defence and governance expectations for regulated firms
- Supports individual-accountability and senior-management-responsibility regimes with mapped, evidenced ownership
- Provides the approval and decision evidence expected in regulatory examination
- Supports corporate-governance and board-oversight codes and expectations
- Evidences segregation of duties and delegated authority for internal and external audit
Reports & exports
- Roles and responsibility (RACI) matrix by object and by role-holder
- Approval-authority matrix and current delegations register
- Segregation-of-duties conflict and exception reports
- Decision register with basis, version and approver
- Committee decision and action-tracking reports
- Role and access recertification status reports
How to get the most from it
Map accountability to roles, not people
Assign responsibility to roles and let the identity directory drive who holds them. Mapping to individuals means every leaver or mover reopens the question of who is accountable.
Enforce SoD at the point of action
Configure segregation-of-duties rules so conflicts are blocked when a decision is made, not discovered months later. Prevention is worth far more than a retrospective finding.
Time-box every delegation
Never grant open-ended authority. Scope delegations to specific decisions and set an expiry, so authority contracts back automatically when cover is no longer needed.
Run committees on live data
Assemble packs from the current risk, policy and control record rather than a snapshot. Governance loses its value the moment it reviews yesterday's position.
Questions, answered
How is accountability tracked across the platform?
Responsibility, accountability, consultation and information are mapped as roles onto every governed object — risks, controls, policies, obligations. Because they map to roles rather than individuals, ownership stays accurate as people join, move and leave.
Can the platform enforce segregation of duties?
Yes. You configure incompatible-duty and conflicting-role rules, and the platform enforces them at the point of action — blocking, for example, the same person from both preparing and approving a decision — rather than surfacing the breach in a later audit.
How does delegated authority work?
Delegations are granted formally with a defined scope and an expiry date. The current holder of authority is always visible, delegated authority lapses automatically, and the full chain of who decided under whose authority is preserved for audit.
Where are approvals recorded?
Every material approval across the platform is captured in a central decision register as a structured record — who approved, when, against which version and on what basis — so sign-off can be produced instantly rather than reconstructed from email.
Does this support individual-accountability regimes?
Yes. By mapping responsibilities to named roles and preserving a durable record of decisions and delegations, the module provides the evidenced ownership and accountability that senior-management-responsibility regimes expect.
Related modules
See Governance in your programme
Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.