Platform
Financial Crime Compliance

Ongoing Monitoring

Continuous re-screening and event monitoring after onboarding

Keep customer and third-party risk current with continuous re-screening and event monitoring, surfacing changes in circumstances, ownership, screening status or behaviour that warrant review — so risk is managed throughout the relationship, not just at the moment of onboarding. Onboarding captures a customer as they are on day one; a real AML programme has to notice when that picture changes. OnyxOne Ongoing Monitoring watches the existing population against updated lists and defined events, re-rates risk when it shifts, and drives the resulting reviews and alerts through a consistent workflow, so the diligence done at onboarding stays true for as long as the relationship lasts.

At a glance

How it works, visually

Onboarding-to-evidence lifecycleSchematic
1AlertRaised2TriagePrioritise3InvestigateEvidence4DecisionApprove5ReportAudit-loggedreopenClear ownership and recorded decisions at every stage — a defensible trail from alert to closure.

From onboarding and due diligence through review, approval and remediation to an evidenced, audit-logged outcome.

The challenge

The problems this module solves

The operational realities that make this hard for compliance and risk teams today.

Diligence is a snapshot that ages the moment it is filed

A customer verified, screened and rated at onboarding is treated as settled. But people become sanctioned, appear in adverse media, change ownership or start behaving differently — and if nothing watches for that, the firm's picture of its customer drifts steadily out of date.

Periodic review is too slow and too blunt

Relying on a calendar-driven review every one, two or three years means a customer can turn risky the week after their last review and stay unnoticed until the next one. Meanwhile low-risk customers who have not changed absorb review effort they do not need.

Events happen where monitoring cannot see them

A change of beneficial owner, a new adverse-media hit, a shift in transaction behaviour or a country moving onto a high-risk list all matter, but they occur in different systems and lists that are not joined to the customer record. The signal exists; nothing brings it to the analyst.

Re-rating is manual and easily skipped

Even when a change is noticed, updating the customer's risk rating is a manual step that competes with everything else. Ratings lag reality, and the firm cannot show that risk was re-assessed when circumstances changed.

The firm cannot evidence that monitoring actually happens

Ongoing monitoring is an obligation regulators test directly. Without a structured record of what was re-screened, what events were reviewed and what action followed, the firm can assert it monitors its customers but cannot prove it.

The approach

How OnyxOne addresses it

Continuous re-screening of the existing book

The existing customer and counterparty population is re-screened against sanctions, PEP and adverse-media sources whenever those lists update, so a relationship that becomes a screening concern after onboarding is surfaced promptly rather than waiting for a scheduled review.

Event-based monitoring, not just the calendar

Defined trigger events — ownership changes, new adverse media, transaction-behaviour shifts, a geography moving to high risk — are watched and raised as they occur. Monitoring responds to what actually changes about a customer instead of only to the passage of time.

Risk-based review cadence

Periodic reviews are scheduled by risk tier, so higher-risk customers are revisited more often and lower-risk ones less, and trigger events can pull a review forward. Review effort follows risk rather than a flat schedule applied to everyone.

Automatic re-rating when risk shifts

When a monitored event or new screening result changes a customer's risk, the rating is re-evaluated against your methodology and the change and its rationale are recorded. Ratings keep pace with reality, and the firm can show risk was re-assessed when circumstances changed.

One consistent workflow for alerts and reviews

Re-screening hits, monitored events and due reviews all flow into a consistent workflow with ownership, SLAs and dispositions, and can be escalated into due diligence or a financial-crime case. Every monitoring outcome is handled the same way and recorded on the customer's living file.

Capabilities

What's in the module

Turn on what you need and add more as your programme scales.

Continuous re-screening

Re-screen the existing population against sanctions, PEP and adverse-media sources whenever lists and data update.

Trigger-event monitoring

Watch defined events — ownership change, new adverse media, behaviour shift, geography change — and raise them as they occur.

Transaction-behaviour monitoring

Surface shifts in customer transaction patterns from your systems that warrant review against expected behaviour.

Risk-based review scheduling

Schedule periodic reviews by risk tier, with trigger events able to pull a review forward.

Automatic re-rating

Re-evaluate customer risk against your methodology when monitored events or new results change the picture, with rationale recorded.

Alert & event workflow

Route re-screening hits, events and due reviews into a consistent workflow with ownership, SLAs and dispositions.

Escalation to diligence & cases

Escalate material events into enhanced due diligence or a financial-crime case without losing context.

Living customer file

Write every re-screen, event, review and re-rating back to the customer's AML record over the relationship.

Coverage assurance

Track which customers are under monitoring and current, so gaps in ongoing coverage are visible and closed.

Immutable monitoring trail

Every re-screen, event, review, disposition and re-rating is written to an append-only record.

Dashboards

The views your team works from

Purpose-built dashboards and views, each answering a question a specific role needs to act on.

An executive viewIllustrative
ILLUSTRATIVE EXAMPLEOPEN CASES128SLA ADHERENCE96%SCREENING ALERTS1.2kOVERDUE REVIEWS14Cases by categoryAMLKYCFraudSanctionsConductOtherRisk mixby tierHighMediumLow

A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.

Monitoring coverage

Which customers are under current monitoring and which are stale or unenrolled, so ongoing coverage gaps are visible and closable.

Event queue

Re-screening hits, trigger events and behaviour changes awaiting review, prioritised by risk with ownership and ageing.

Review calendar

Periodic reviews due and overdue by risk tier, with trigger-pulled reviews highlighted for priority.

Risk-migration view

How customers are moving between risk tiers over time, showing where the book's risk is rising or falling.

New-hit monitor

Fresh sanctions, PEP and adverse-media matches raised by continuous re-screening since the last review.

Automation

What the platform automates

Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.

List-update re-screening

When a configured list or source updates, the existing population is re-screened automatically and any new matches are routed for review.

Event detection & routing

Defined trigger events are detected from connected sources and raised against the relevant customer with a review task.

Risk-based review scheduling

Periodic reviews are scheduled and chased by risk tier, and trigger events pull a review forward automatically.

Auto re-rating

Material events and new results re-evaluate the customer's risk rating against your methodology, recording the change and rationale.

Escalation on material change

A material event or new true match automatically raises an enhanced-diligence review or a financial-crime case with context attached.

AI assistance

Where AI helps the analyst

Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.

Event-relevance triage

Ranks monitored events and re-screening hits by likely significance so analysts review the most material first — the disposition stays with the analyst.

Behaviour-change detection

Highlights shifts in a customer's transaction pattern that diverge from expected behaviour, prompting a person to review rather than concluding alone.

Review-summary drafting

Drafts a periodic-review summary from screening, events and prior diligence for the analyst to verify, edit and own.

The workflow

The enterprise workflow

A defined, end-to-end process with clear ownership at every stage.

The workflow, step by stepSchematic
01Enrol the populationOnboarded customers and counterparties are enrolled in ongoing monitoring with areview cadence set by their risk tier.02Re-screen continuouslyThe population is re-screened against sanctions, PEP and adverse-media sourceswhenever lists update, raising any new hits.03Watch for eventsDefined trigger events and behaviour shifts are monitored and surfaced against therelevant customer record as they occur.04Review & dispositionHits, events and due reviews enter a consistent workflow where analysts review,clear, escalate or re-rate, recording the rationale.05Re-rate & escalateWhere risk has changed, the customer is re-rated, and material concerns areescalated into enhanced diligence or a case.06Evidence coverageMonitoring coverage, events reviewed and actions taken are reported and preserved onan immutable trail for audit and examination.

Every result, decision and override is captured against the record it belongs to.

01

Enrol the population

Onboarded customers and counterparties are enrolled in ongoing monitoring with a review cadence set by their risk tier.

02

Re-screen continuously

The population is re-screened against sanctions, PEP and adverse-media sources whenever lists update, raising any new hits.

03

Watch for events

Defined trigger events and behaviour shifts are monitored and surfaced against the relevant customer record as they occur.

04

Review & disposition

Hits, events and due reviews enter a consistent workflow where analysts review, clear, escalate or re-rate, recording the rationale.

05

Re-rate & escalate

Where risk has changed, the customer is re-rated, and material concerns are escalated into enhanced diligence or a case.

06

Evidence coverage

Monitoring coverage, events reviewed and actions taken are reported and preserved on an immutable trail for audit and examination.

The value

What your team gains

Continuous

Diligence that stays true

Re-screening and event monitoring keep the onboarding picture current, so the firm's view of a customer reflects who they are now, not who they were.

Event-driven

Change caught when it happens

Monitoring responds to real events — ownership, screening, behaviour — rather than waiting years for the next scheduled review.

Risk-based

Effort where the risk is

A risk-tiered review cadence revisits higher-risk customers more often and spares effort on those that have not changed.

Current

Ratings that keep pace

Automatic re-rating when circumstances shift means risk ratings reflect reality and the firm can show risk was re-assessed.

Consistent handling of every signal

Re-screening hits, events and reviews all run through one workflow with SLAs and recorded dispositions, so nothing is handled ad hoc.

Monitoring the firm can prove

An immutable record of what was monitored, reviewed and actioned turns an obligation regulators test directly into evidence on demand.

Built for

Industries it serves

BankingFinancial ServicesFintechLendingInvestment FirmsInsuranceWealth ManagementCorporate & Trust Service ProvidersGaming
Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.

Screening & data sources
  • Re-screens the population against the sanctions, PEP and adverse-media providers configured for your deployment as lists update
Transaction & core systems
  • Ingests transaction and account signals from your existing core and monitoring systems to surface behavioural change
Ownership & corporate data
  • Watches corporate registry and ownership sources for changes in beneficial ownership that warrant review
Due diligence & cases
  • Escalates material events into the enhanced-due-diligence and case-management modules with full context preserved
Collaboration & notification
  • Routes review tasks, event alerts and escalations through your existing email and messaging tools
Assurance

Security, compliance & reporting

Security & data handling

  • Monitoring events, re-screening results and review records are encrypted in transit and at rest, with access governed by granular, role-based permissions.
  • Sensitive event and screening detail is restricted to authorised roles and handled under strict need-to-know.
  • Segregation of duties can prevent the same person from both raising and clearing a material event where policy requires it.
  • Every re-screen, event, review, disposition and re-rating is written to an append-only audit trail against the customer record.
  • Data residency and retention for monitoring records are configurable to the regulatory obligations of your jurisdiction.

Compliance support

  • Supports ongoing-monitoring obligations for the life of the customer relationship
  • Underpins continuous sanctions, PEP and adverse-media re-screening of the existing population
  • Supports risk-based periodic review and trigger-based re-rating requirements
  • Assists detection of changes that may warrant escalation, enhanced diligence or suspicious-activity reporting
  • Provides the coverage and audit-trail evidence expected by AML supervisors for ongoing monitoring
  • OnyxOne is a technology vendor, not an obliged entity — responsibility for monitoring obligations remains with your firm

Reports & exports

  • Monitoring-coverage reports showing which customers are current and where gaps exist
  • Re-screening and new-match reports over time
  • Trigger-event and behaviour-change reports
  • Periodic-review due, overdue and completion reports by risk tier
  • Re-rating and risk-migration reports
  • Ongoing-monitoring management information for the MLRO / compliance function
Best practice

How to get the most from it

Monitor on events, not only on the calendar

Define the trigger events that should prompt a review and watch for them continuously. A three-year review cycle cannot catch a customer who turns risky the month after onboarding.

Set the review cadence by risk

Revisit higher-risk customers more often and lower-risk ones less. A flat review schedule either over-works low risk or under-watches high risk — usually both.

Re-rate as circumstances change

Let material events re-evaluate the risk rating automatically and record why. A rating that never moves after onboarding is a rating that no longer describes the customer.

Prove coverage, not just activity

Track which customers are actually under current monitoring, not only how many alerts were cleared. Regulators test whether the whole book is covered, so make the gaps visible.

FAQ

Questions, answered

How is ongoing monitoring different from screening at onboarding?

Onboarding screening checks a customer at the point they join. Ongoing monitoring re-screens the existing population as lists change and watches for defined events over the whole relationship, so a customer who becomes a concern after onboarding is surfaced rather than remaining as they were assessed on day one.

What kinds of events does it monitor?

Continuous re-screening surfaces new sanctions, PEP and adverse-media matches, and event monitoring watches for changes such as beneficial-ownership changes, shifts in transaction behaviour, and a geography moving onto a high-risk list. You define which trigger events matter and how they are handled.

Does it replace periodic review?

It makes periodic review sharper rather than replacing it. Reviews are scheduled by risk tier, and trigger events can pull a review forward, so a customer is revisited when something changes instead of only when the calendar says so.

How does re-rating work?

When a monitored event or new screening result changes a customer's risk, their rating is re-evaluated against your methodology and the change and its rationale are recorded, so ratings stay current and the firm can evidence that risk was re-assessed when circumstances changed.

Can we prove monitoring is actually happening?

Yes. Coverage is tracked so you can see which customers are current, and every re-screen, event, review, disposition and re-rating is written to an immutable trail — turning an obligation regulators test directly into evidence that can be produced on demand.

See Ongoing Monitoring in your programme

Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.