Platform
Compliance Management

Policy & Procedure Management

Author, approve, publish and attest — every policy, versioned and evidenced

The full lifecycle of policies and procedures on one platform — drafting, review, approval, publication, attestation and scheduled review — with every version, approval and acknowledgement preserved. OnyxOne replaces shared drives full of conflicting documents and email attestation chases with a single library where the current version is unambiguous, the right people have approved it, staff have acknowledged it, and mapped controls show the policy is actually enforced.

At a glance

How it works, visually

A representative compliance flowSchematic
Item receivedOnboarding / eventRiskthreshold?Auto-clearLow risk · loggedEscalate to reviewAnalyst investigatesRecord &auditNoYes — parallel review paths

How an obligation or event is triaged, escalated when it matters, and recorded either way.

The challenge

The problems this module solves

The operational realities that make this hard for compliance and risk teams today.

Nobody knows which version is current

Policies live on shared drives and in email attachments, in multiple near-identical versions. Staff follow whichever copy they happened to save, approvers can't tell what they signed off, and 'the current policy' becomes a matter of debate rather than fact.

Approvals are informal and untraceable

Policy sign-off happens over email or in a meeting with no durable record. When an auditor asks who approved a policy and when, the answer is buried in an inbox — if it exists at all.

Attestation is a manual chase

Confirming that staff have read and understood a policy means chasing acknowledgements by email and tracking them in a spreadsheet. Coverage is never complete, reminders are manual, and there is no clean evidence of who has attested to what.

Reviews lapse and policies go stale

Policies are supposed to be reviewed on a cycle, but without automated scheduling, reviews slip. Out-of-date policies stay in force, no longer matching regulation or actual practice, and the gap only surfaces when something goes wrong.

Policies aren't connected to the controls that enforce them

A policy states a requirement, but nothing links it to the controls that implement it. There's no line of sight from an obligation, to the policy that addresses it, to the control that enforces it — so 'we have a policy' is asserted rather than evidenced.

The approach

How OnyxOne addresses it

A single, versioned policy library

Every policy and procedure lives in one library with a clear current version, full version history and status. There is never ambiguity about what is in force — the platform is the single source of truth, and superseded versions are retained for the record.

Structured authoring, review and approval

Policies move through configurable draft, review and approval stages with defined owners and reviewers. Each approval is captured with who approved it, when and against which version — a durable, auditable sign-off rather than an email thread.

Targeted attestation with automated tracking

Publish a policy to the roles or groups it applies to and require acknowledgement. The platform tracks who has attested, sends reminders automatically, and shows coverage at a glance — no spreadsheet, no manual chasing.

Scheduled reviews that don't lapse

Each policy carries a review cadence, and the platform prompts owners before it falls due. Reviews are logged, so a policy is provably current rather than quietly stale.

Policies mapped to controls and obligations

Policies link to the controls that enforce them and the obligations they address, creating a traceable line from regulation to policy to control. 'We have a policy and here is the control that enforces it' becomes evidenced, not asserted.

Capabilities

What's in the module

Turn on what you need and add more as your programme scales.

Central policy library

One versioned library for every policy and procedure, with an unambiguous current version and full history.

Authoring & drafting

Draft and edit policies with structure and templates, keeping work-in-progress separate from the published version.

Review & approval workflow

Configurable draft → review → approve stages with defined owners, reviewers and durable sign-off.

Version control

Every change produces a new version; superseded versions are retained and comparable.

Publication & distribution

Publish the approved version to the roles and groups it applies to, so staff always see what's in force.

Attestation & acknowledgement

Require and track read-and-understood acknowledgements with automated reminders and coverage reporting.

Scheduled review cycles

Set a review cadence per policy and prompt owners before it falls due, logging each review.

Control & obligation mapping

Link policies to the controls that enforce them and the obligations they address for full traceability.

Exceptions & waivers

Record, approve and time-box policy exceptions with owners and expiry, rather than leaving them undocumented.

Immutable audit trail

Every draft, approval, publication, attestation and review is written to an append-only record.

The workflow

The enterprise workflow

A defined, end-to-end process with clear ownership at every stage.

The workflow, step by stepSchematic
01DraftAn owner drafts or revises a policy from a template, with work-in-progress keptseparate from the version currently in force.02ReviewReviewers provide input and changes on a defined stage, so the right stakeholdersshape the policy before approval.03ApproveDesignated approvers sign the policy off against a specific version, with theapproval captured durably for audit.04PublishThe approved version is published to the roles and groups it applies to and becomesthe unambiguous current version.05AttestStaff acknowledge the policy; the platform tracks coverage, sends reminders andrecords each attestation.06Review on cycleThe policy is scheduled for periodic review, prompting the owner before it falls dueso it never quietly goes stale.

Every result, decision and override is captured against the record it belongs to.

01

Draft

An owner drafts or revises a policy from a template, with work-in-progress kept separate from the version currently in force.

02

Review

Reviewers provide input and changes on a defined stage, so the right stakeholders shape the policy before approval.

03

Approve

Designated approvers sign the policy off against a specific version, with the approval captured durably for audit.

04

Publish

The approved version is published to the roles and groups it applies to and becomes the unambiguous current version.

05

Attest

Staff acknowledge the policy; the platform tracks coverage, sends reminders and records each attestation.

06

Review on cycle

The policy is scheduled for periodic review, prompting the owner before it falls due so it never quietly goes stale.

The value

What your team gains

Single source of truth

No more version confusion

One library with an unambiguous current version means staff, approvers and auditors all reference the same policy.

Auditable

Durable approval evidence

Every approval is captured with who, when and which version, so policy sign-off can be produced instantly on request.

Tracked

Attestation without the chase

Automated acknowledgement tracking and reminders replace the spreadsheet and the email chase, with coverage visible at a glance.

Current

Policies that don't go stale

Scheduled reviews prompt owners before policies fall due, so what's in force is provably up to date.

Traceable from obligation to control

Mapping policies to obligations and enforcing controls turns 'we have a policy' into an evidenced line of assurance.

Cleaner audits and examinations

Because approvals, attestations and reviews are captured as they happen, evidence is retrieved rather than reconstructed.

Built for

Industries it serves

Financial ServicesBankingInsuranceFintechInvestment FirmsCorporate & Trust Service ProvidersLegal FirmsAccounting FirmsRegulated Enterprises
Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.

Controls & obligations
  • Links policies to your internal-controls and compliance-obligation modules for end-to-end traceability
Identity & HR directory
  • Targets attestation to the right roles and groups using your existing identity provider and HR directory
Document repositories
  • Connects to your existing document stores while keeping the authoritative, versioned copy in the policy library
Learning & training
  • Aligns policy attestation with your existing training and learning systems where acknowledgement and training go together
Collaboration & notification
  • Routes review requests, approvals and attestation reminders through your existing email and messaging channels
Assurance

Security, compliance & reporting

Security & data handling

  • Policy content, approvals and attestations are encrypted in transit and at rest.
  • Role-based access controls who can author, review, approve and publish, keeping drafts separate from the published version.
  • Segregation of duties can prevent the same person from both authoring and approving a policy where policy requires it.
  • Every draft, approval, publication, attestation and review is written to an append-only audit trail.
  • Superseded versions are retained, so the exact policy in force at any past date can be produced.
  • Retention of policy versions and attestation records is configurable to your regulatory obligations.

Compliance support

  • Supports policy-governance expectations across AML, data-protection and conduct regimes
  • Provides documented approval and attestation evidence for regulatory examination
  • Underpins the policy layer of a three-lines-of-defence model
  • Supports GDPR and information-governance policy requirements
  • Links policies to obligations and controls for demonstrable regulatory coverage

Reports & exports

  • Policy inventory with current version and status
  • Approval history and sign-off reports
  • Attestation coverage and outstanding-acknowledgement reports
  • Overdue and upcoming policy-review reports
  • Exception / waiver register with expiry tracking
  • Policy-to-control and policy-to-obligation coverage reports
Best practice

How to get the most from it

Make the library the only source

Retire shared-drive copies and point everyone to the library. The value collapses the moment a second 'current' version exists elsewhere.

Target attestation, don't broadcast it

Publish policies to the roles they actually apply to. Blanket attestation dilutes coverage evidence and irritates staff who don't need it.

Schedule reviews at creation

Set the review cadence when a policy is first approved, so it enters the review cycle immediately rather than being remembered later.

Map policies to controls

Link each policy to the controls that enforce it. Traceability from obligation to policy to control is what turns documentation into assurance.

FAQ

Questions, answered

How does version control work?

Every change creates a new version while the published version remains unambiguous. Superseded versions are retained and comparable, so the exact policy in force at any past date can always be produced.

Can we require staff to attest to policies?

Yes. Publish a policy to the roles or groups it applies to and require read-and-understood acknowledgement. The platform tracks coverage, sends reminders automatically and records each attestation as evidence.

How are policy approvals evidenced?

Approvals are captured durably with who approved, when and against which version, replacing email sign-off with an auditable record you can produce on request.

Does it stop policies going out of date?

Each policy carries a review cadence, and owners are prompted before a review falls due. Reviews are logged, so a policy is provably current rather than quietly stale.

Can we link policies to controls and obligations?

Yes. Policies map to the controls that enforce them and the obligations they address, creating a traceable line from regulation to policy to control for demonstrable coverage.

See Policy & Procedure Management in your programme

Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.