Case Management & Investigations
Turn alerts and incidents into closed, defensible cases
Alerts, referrals and incidents only reduce risk when they are worked to a decision and recorded defensibly. This programme composes case management and investigations into one workspace where alerts become structured cases, evidence and entity links are gathered, decisions are reviewed and signed off, and every case closes with an auditable trail from the first signal to closure.
One programme, on one platform
Your compliance, risk and legal teams run the programme in OnyxOne, which composes the relevant modules onto one record and connects to the systems and data sources your deployment requires.
What this programme is, and why it matters
A solution is a programme, not a single tool — the outcome a set of platform capabilities add up to when they run on one record.
How onboarding, due diligence and review become a decided, evidenced outcome — with a defensible trail from first contact to closure.
From signal to decision
A financial-crime programme generates alerts, referrals and incidents; this programme is where they are triaged, investigated and resolved. Routing them into structured cases with defined workflows turns scattered signals into a managed queue with ownership and SLAs.
The full picture in one workspace
Investigators see the customer, the linked people and entities, the evidence and the decision history in one place, instead of chasing context across systems — so conclusions are reached on complete information and documented as they go.
Four-eyes and segregation of duties
Consequential decisions route through review and sign-off, and segregation-of-duties controls can prevent the same person raising and approving an outcome where your policy forbids it — making the decision defensible, not just made.
A trail that stands up
Every case closes with a recorded outcome and rationale, and every action along the way is timestamped and attributed in an immutable audit trail — the evidence base for internal review, external audit and regulatory scrutiny.
What makes this hard today
The operational realities this programme is designed to resolve.
Alerts worked in inboxes
When alerts and referrals are handled over email and spreadsheets, there is no queue, no ownership and no reliable record of what was decided or why.
Context scattered across systems
Investigators lose time reassembling a customer's history, links and evidence from separate tools before they can even begin to assess a case.
Inconsistent investigations
Without defined workflows, how a case is investigated depends on who picks it up, so quality and defensibility vary.
Decisions without a trail
Outcomes recorded loosely — or only in someone's memory — cannot answer the regulator's question of how a decision was reached.
No visibility of the queue
Managers cannot see case ageing, SLA breaches or bottlenecks when work is spread across personal inboxes.
The operating model, at a glance
How the composed programme runs — from the data it takes in to the decisions and evidence it produces.
Work is triaged, escalated when it matters, and recorded either way — every path lands on the audit trail.
Define case types & workflows
Configure case types, investigation workflows, SLAs, roles and approval steps to match how your team actually works.
Route alerts into cases
Alerts, referrals and incidents from across the programme are routed into structured cases with clear ownership.
Investigate together
Investigators gather evidence, link people and entities, collaborate and record their reasoning in one workspace.
Review & sign off
Consequential decisions route through four-eyes review and approval, with segregation of duties where policy requires.
Close & preserve
Cases close with a recorded outcome and rationale, and everything is preserved in an immutable audit trail.
The modules this solution composes
A solution is a curated set of platform modules working as one programme. Turn on what the programme needs and add more as it scales.
What the programme gives you
The concrete capabilities the composed programme provides, end to end.
Structured case workflows
Route alerts, referrals and incidents into cases with defined workflows, ownership, SLAs and status, so nothing is worked in an inbox.
Investigation workspace
Gather evidence, link people and entities, and build the full picture of a case in one workspace instead of across systems.
Entity linking
Connect people, organisations and events so relationships and networks behind a case are visible to the investigator.
Four-eyes review & sign-off
Route consequential decisions through review and approval, with segregation of duties where your policy requires it.
Incident & whistleblowing intake
Capture incidents and confidential reports into the same managed process, with sensitivity controls on who can see what.
Regulatory report hand-off
Assemble suspicious-activity content and referrals from the case record for the returns your obligations require.
The end-to-end workflow
A defined process with clear ownership at every stage, captured against the record it belongs to.
Every result, decision and override is captured against the record it belongs to.
Case raised
An alert, referral or incident is routed into a structured case with a type, owner and SLA.
Triage & prioritise
The case is assessed and prioritised so the highest-risk work is progressed first.
Investigate
Evidence is gathered, people and entities are linked, and reasoning is recorded in the workspace.
Review
The proposed outcome routes through four-eyes review under segregation-of-duties controls.
Decide & report
The decision is approved, and any required suspicious-activity content or referral is assembled.
Close & preserve
The case closes with a recorded outcome and rationale, preserved in the immutable audit trail.
Industries this programme serves
The sectors this programme is most often deployed in. The same programme, framed around each sector's obligations.
Works with your existing systems
Described as capabilities — OnyxOne connects to the systems the programme requires, configured per implementation.
- Receives alerts and referrals from screening, monitoring and other programme capabilities as structured cases
- Reads customer, account and transaction data so investigators have context without leaving the workspace
- Attaches documents and evidence to the case record via the document and evidence repository
- Exports suspicious-activity content and referrals in the formats your submission channels require
- Routes assignments, escalations and approvals through your existing email and messaging tools
Security & reporting
Security & data handling
- Case, evidence and investigation data are encrypted in transit and at rest.
- Sensitive and suspicion-related cases are restricted to authorised roles under need-to-know.
- Every case action, decision, override and closure is written to an append-only audit trail.
- Segregation of duties can prevent the same person raising and approving a case outcome.
- Confidential intake (for example whistleblowing) carries additional access controls and handling rules.
Reports & returns
- Case throughput, ageing and SLA-adherence reports
- Investigation outcome and disposition reporting
- Suspicious-activity / suspicious-transaction report content (SAR/STR)
- Incident and whistleblowing case reporting
- Investigator workload and queue-health reporting
What your team gains
A managed queue, not an inbox
Cases carry ownership, SLAs and status, so work is visible, prioritised and nothing falls through the cracks.
Faster, better-informed investigations
The full picture in one workspace removes the context-chasing that slows investigators down.
Decisions that stand up
Four-eyes review, segregation of duties and recorded rationale make every outcome defensible, not just made.
Evidence captured as you work
An immutable trail means the answer to "how was this decided?" already exists when it is asked.
Questions, answered
What kinds of work does a case cover?
Anything that needs to be investigated and decided — screening and monitoring alerts, referrals, incidents and confidential reports. They all run through structured case types with defined workflows, ownership and SLAs.
How does it make decisions defensible?
Consequential outcomes route through four-eyes review and approval, segregation-of-duties controls can prevent the same person raising and signing off, and every action and rationale is captured in an immutable audit trail.
Can investigators see everything in one place?
Yes. The workspace brings the customer, linked people and entities, evidence and decision history together, so investigators work from the full picture rather than reassembling it across systems.
Does it produce regulatory reports?
It assembles suspicious-activity content and referrals from the case record for the returns your obligations require, exported in the formats your submission channels use. Your firm remains responsible for filing.
Are SOC 2 or ISO 27001 held?
Not yet. Both are on our roadmap; we will publish attestations in the Trust Center once they are held rather than claim them beforehand.
Stand up your Case Management & Investigations programme
Book a walkthrough and we'll show how the composed programme fits your obligations, workflows and systems — then scope an implementation.