Solutions
Financial Crime Compliance

Case Management & Investigations

Turn alerts and incidents into closed, defensible cases

Alerts, referrals and incidents only reduce risk when they are worked to a decision and recorded defensibly. This programme composes case management and investigations into one workspace where alerts become structured cases, evidence and entity links are gathered, decisions are reviewed and signed off, and every case closes with an auditable trail from the first signal to closure.

At a glance

One programme, on one platform

Case Management & Investigations on OnyxOneSchematic
Your teamsCompliance · risk · legalAnalysts & investigatorsScreen, review and decideOversight & approvalsSign-off and reportingOnyxOneCompliance & risk OSScreening · Due diligenceCases · Risk · MonitoringPolicy · Reporting · AuditSystems & sourcesConfigured per deploymentScreening data providersSanctions · PEP · mediaYour systems of recordOnboarding · core systemsOne platform for the whole programme — not a stack of disconnected tools and spreadsheets.

Your compliance, risk and legal teams run the programme in OnyxOne, which composes the relevant modules onto one record and connects to the systems and data sources your deployment requires.

The programme

What this programme is, and why it matters

A solution is a programme, not a single tool — the outcome a set of platform capabilities add up to when they run on one record.

The customer compliance lifecycleSchematic
1AlertRaised2TriagePrioritise3InvestigateEvidence4DecisionApprove5ReportAudit-loggedreopenClear ownership and recorded decisions at every stage — a defensible trail from alert to closure.

How onboarding, due diligence and review become a decided, evidenced outcome — with a defensible trail from first contact to closure.

From signal to decision

A financial-crime programme generates alerts, referrals and incidents; this programme is where they are triaged, investigated and resolved. Routing them into structured cases with defined workflows turns scattered signals into a managed queue with ownership and SLAs.

The full picture in one workspace

Investigators see the customer, the linked people and entities, the evidence and the decision history in one place, instead of chasing context across systems — so conclusions are reached on complete information and documented as they go.

Four-eyes and segregation of duties

Consequential decisions route through review and sign-off, and segregation-of-duties controls can prevent the same person raising and approving an outcome where your policy forbids it — making the decision defensible, not just made.

A trail that stands up

Every case closes with a recorded outcome and rationale, and every action along the way is timestamped and attributed in an immutable audit trail — the evidence base for internal review, external audit and regulatory scrutiny.

The challenge

What makes this hard today

The operational realities this programme is designed to resolve.

Alerts worked in inboxes

When alerts and referrals are handled over email and spreadsheets, there is no queue, no ownership and no reliable record of what was decided or why.

Context scattered across systems

Investigators lose time reassembling a customer's history, links and evidence from separate tools before they can even begin to assess a case.

Inconsistent investigations

Without defined workflows, how a case is investigated depends on who picks it up, so quality and defensibility vary.

Decisions without a trail

Outcomes recorded loosely — or only in someone's memory — cannot answer the regulator's question of how a decision was reached.

No visibility of the queue

Managers cannot see case ageing, SLA breaches or bottlenecks when work is spread across personal inboxes.

How it works

The operating model, at a glance

How the composed programme runs — from the data it takes in to the decisions and evidence it produces.

A representative flowSchematic
Item receivedOnboarding / eventRiskthreshold?Auto-clearLow risk · loggedEscalate to reviewAnalyst investigatesRecord &auditNoYes — parallel review paths

Work is triaged, escalated when it matters, and recorded either way — every path lands on the audit trail.

01

Define case types & workflows

Configure case types, investigation workflows, SLAs, roles and approval steps to match how your team actually works.

02

Route alerts into cases

Alerts, referrals and incidents from across the programme are routed into structured cases with clear ownership.

03

Investigate together

Investigators gather evidence, link people and entities, collaborate and record their reasoning in one workspace.

04

Review & sign off

Consequential decisions route through four-eyes review and approval, with segregation of duties where policy requires.

05

Close & preserve

Cases close with a recorded outcome and rationale, and everything is preserved in an immutable audit trail.

Capabilities

What the programme gives you

The concrete capabilities the composed programme provides, end to end.

Structured case workflows

Route alerts, referrals and incidents into cases with defined workflows, ownership, SLAs and status, so nothing is worked in an inbox.

Investigation workspace

Gather evidence, link people and entities, and build the full picture of a case in one workspace instead of across systems.

Entity linking

Connect people, organisations and events so relationships and networks behind a case are visible to the investigator.

Four-eyes review & sign-off

Route consequential decisions through review and approval, with segregation of duties where your policy requires it.

Incident & whistleblowing intake

Capture incidents and confidential reports into the same managed process, with sensitivity controls on who can see what.

Regulatory report hand-off

Assemble suspicious-activity content and referrals from the case record for the returns your obligations require.

The workflow

The end-to-end workflow

A defined process with clear ownership at every stage, captured against the record it belongs to.

The workflow, step by stepSchematic
01Case raisedAn alert, referral or incident is routed into a structured case with a type, ownerand SLA.02Triage & prioritiseThe case is assessed and prioritised so the highest-risk work is progressed first.03InvestigateEvidence is gathered, people and entities are linked, and reasoning is recorded inthe workspace.04ReviewThe proposed outcome routes through four-eyes review under segregation-of-dutiescontrols.05Decide & reportThe decision is approved, and any required suspicious-activity content or referralis assembled.06Close & preserveThe case closes with a recorded outcome and rationale, preserved in the immutableaudit trail.

Every result, decision and override is captured against the record it belongs to.

01

Case raised

An alert, referral or incident is routed into a structured case with a type, owner and SLA.

02

Triage & prioritise

The case is assessed and prioritised so the highest-risk work is progressed first.

03

Investigate

Evidence is gathered, people and entities are linked, and reasoning is recorded in the workspace.

04

Review

The proposed outcome routes through four-eyes review under segregation-of-duties controls.

05

Decide & report

The decision is approved, and any required suspicious-activity content or referral is assembled.

06

Close & preserve

The case closes with a recorded outcome and rationale, preserved in the immutable audit trail.

Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems the programme requires, configured per implementation.

Alert & signal sources
  • Receives alerts and referrals from screening, monitoring and other programme capabilities as structured cases
Systems of record
  • Reads customer, account and transaction data so investigators have context without leaving the workspace
Evidence & documents
  • Attaches documents and evidence to the case record via the document and evidence repository
Regulatory reporting channels
  • Exports suspicious-activity content and referrals in the formats your submission channels require
Collaboration & notification
  • Routes assignments, escalations and approvals through your existing email and messaging tools
Assurance

Security & reporting

Security & data handling

  • Case, evidence and investigation data are encrypted in transit and at rest.
  • Sensitive and suspicion-related cases are restricted to authorised roles under need-to-know.
  • Every case action, decision, override and closure is written to an append-only audit trail.
  • Segregation of duties can prevent the same person raising and approving a case outcome.
  • Confidential intake (for example whistleblowing) carries additional access controls and handling rules.

Reports & returns

  • Case throughput, ageing and SLA-adherence reports
  • Investigation outcome and disposition reporting
  • Suspicious-activity / suspicious-transaction report content (SAR/STR)
  • Incident and whistleblowing case reporting
  • Investigator workload and queue-health reporting
The value

What your team gains

A managed queue, not an inbox

Cases carry ownership, SLAs and status, so work is visible, prioritised and nothing falls through the cracks.

Faster, better-informed investigations

The full picture in one workspace removes the context-chasing that slows investigators down.

Decisions that stand up

Four-eyes review, segregation of duties and recorded rationale make every outcome defensible, not just made.

Evidence captured as you work

An immutable trail means the answer to "how was this decided?" already exists when it is asked.

FAQ

Questions, answered

What kinds of work does a case cover?

Anything that needs to be investigated and decided — screening and monitoring alerts, referrals, incidents and confidential reports. They all run through structured case types with defined workflows, ownership and SLAs.

How does it make decisions defensible?

Consequential outcomes route through four-eyes review and approval, segregation-of-duties controls can prevent the same person raising and signing off, and every action and rationale is captured in an immutable audit trail.

Can investigators see everything in one place?

Yes. The workspace brings the customer, linked people and entities, evidence and decision history together, so investigators work from the full picture rather than reassembling it across systems.

Does it produce regulatory reports?

It assembles suspicious-activity content and referrals from the case record for the returns your obligations require, exported in the formats your submission channels use. Your firm remains responsible for filing.

Are SOC 2 or ISO 27001 held?

Not yet. Both are on our roadmap; we will publish attestations in the Trust Center once they are held rather than claim them beforehand.

Stand up your Case Management & Investigations programme

Book a walkthrough and we'll show how the composed programme fits your obligations, workflows and systems — then scope an implementation.