Governance, Policy & Controls
Make oversight, policy and control demonstrable — not assumed
A programme is only as strong as the governance behind it: clear roles, current policies, a control framework and evidence that it all operates. This programme composes governance, policy and procedure management, and internal controls into one framework, so who is accountable, what the policy says, and how it is controlled are explicit, connected and demonstrable — with a traceable line from policy to control to evidence.
One programme, on one platform
Your compliance, risk and legal teams run the programme in OnyxOne, which composes the relevant modules onto one record and connects to the systems and data sources your deployment requires.
What this programme is, and why it matters
A solution is a programme, not a single tool — the outcome a set of platform capabilities add up to when they run on one record.
How accountability is structured across the first line, risk and compliance, and independent assurance — the model the programme supports.
Policy to control to evidence, connected
The programme links each policy to the controls that operationalise it and the evidence that shows the control works. That traceable chain is what turns a stack of documents into a governance framework a firm can actually demonstrate.
Roles and accountability made explicit
Governance is about who decides and who is answerable. The programme makes roles, approvals, oversight and the three-lines model explicit, with escalation and sign-off recorded — so accountability can be shown rather than assumed.
Living policies, not stale documents
Policies are versioned, owned, reviewed on a cadence and attested by the people they apply to, so the firm can show not just that a policy exists but that it is current and that staff have acknowledged it.
Controls that are more than a list
The control library defines what each control is, who owns it and what risk and policy it serves — the foundation the assurance programme tests against and the reference the whole business works from.
What makes this hard today
The operational realities this programme is designed to resolve.
Policies in a document graveyard
Policies scattered across shared drives go stale, lose owners, and no one can show they are current or that staff have read them.
Controls with no home
When there is no single control library, the same control is described differently in different places and cannot be reliably tested or reported on.
Accountability by assumption
Without recorded roles, approvals and escalation, who is responsible for what is a matter of memory rather than record.
No line from policy to evidence
When policy, control and evidence live apart, the firm cannot show how a stated commitment is actually operated and proven.
Attestation as an email chase
Collecting policy acknowledgements over email leaves gaps and no reliable record of who attested to what, and when.
The operating model, at a glance
How the composed programme runs — from the data it takes in to the decisions and evidence it produces.
Work is triaged, escalated when it matters, and recorded either way — every path lands on the audit trail.
Define the framework
Establish roles, the three-lines model, the policy set and the control library, with owners for each.
Connect the chain
Map policies to the controls that operationalise them and the risks they address, so the framework is traceable.
Publish & attest
Version and publish policies, and capture attestations from the people each policy applies to.
Operate & evidence
Controls operate with owners, and the evidence they produce is captured against the control record.
Review & govern
Policies and controls are reviewed on cadence, and oversight, approvals and escalation are recorded for the board.
The modules this solution composes
A solution is a curated set of platform modules working as one programme. Turn on what the programme needs and add more as it scales.
What the programme gives you
The concrete capabilities the composed programme provides, end to end.
Governance & roles
Make roles, approvals, oversight and the three-lines model explicit, with escalation and sign-off recorded so accountability is demonstrable.
Policy lifecycle management
Author, version, publish, review and retire policies and procedures, each with an owner and a review cadence.
Attestation
Capture acknowledgements from the people a policy applies to, with a reliable record of who attested to what, and when.
Control library
A single definition of every control — its purpose, owner and the risk and policy it serves — that the whole business works from.
Policy-to-control mapping
Link policies to the controls that operationalise them, so a stated commitment traces to how it is actually operated.
Oversight & approvals
Route governance decisions through recorded approval and escalation, so who decided what is captured, not remembered.
The end-to-end workflow
A defined process with clear ownership at every stage, captured against the record it belongs to.
Every result, decision and override is captured against the record it belongs to.
Establish roles
Governance roles and the three-lines model are defined with clear ownership and accountability.
Author policy
Policies and procedures are authored, owned and versioned in one place.
Map to controls
Each policy is linked to the controls that operationalise it and the risks it addresses.
Publish & attest
Policies are published and attestations are captured from the staff they apply to.
Operate & evidence
Controls operate under their owners, and the evidence they produce is captured against the record.
Review & report
Policies and controls are reviewed on cadence, and oversight and approvals are reported to the board.
Industries this programme serves
The sectors this programme is most often deployed in. The same programme, framed around each sector's obligations.
Works with your existing systems
Described as capabilities — OnyxOne connects to the systems the programme requires, configured per implementation.
- Imports existing policy documents from your shared drives or document store into managed, versioned records
- Connects to your directory so attestations and roles map to the right people and teams
- Shares the control library with the risk and assurance programmes so everything maps to the same controls
- Feeds governance and attestation status into executive and board reporting
- Routes policy reviews, attestations and approvals through your existing email and messaging tools
Security & reporting
Security & data handling
- Policy, control and governance records are encrypted in transit and at rest.
- Access and editing rights are role-based, so only owners can change a policy or control definition.
- Every policy version, attestation, control change and approval is written to an append-only audit trail.
- Segregation of duties can separate policy authorship from approval where required.
- Data residency and retention are configurable to your obligations.
Reports & returns
- Policy currency, ownership and review-status reporting
- Attestation completion and coverage reports
- Control-library coverage and policy-to-control mapping reports
- Governance oversight, approval and escalation reporting
- Executive and board governance management information
What your team gains
A framework you can demonstrate
The traceable line from policy to control to evidence turns governance from a claim into something the firm can show.
Accountability on the record
Explicit roles, recorded approvals and escalation mean who is answerable for what is documented, not assumed.
Policies that stay current
Ownership, review cadence and attestation keep the policy set alive and acknowledged rather than stale.
One source of control truth
A single control library gives the whole business — and the assurance function — one consistent definition to work from.
Questions, answered
How does this connect policy to control?
Each policy is mapped to the controls that operationalise it and the risks it addresses, and controls carry the evidence that they work — giving a traceable line from a stated commitment to how it is actually operated and proven.
Can we prove staff have read a policy?
Yes. Attestation captures acknowledgements from the people a policy applies to, with a reliable record of who attested to what and when — rather than an email chase.
Is the control library shared with other programmes?
Yes. The same control library underpins the risk and assurance programmes, so risks, controls, policies and tests all reference one consistent set of control definitions.
Does OnyxOne write our policies?
No. The programme manages the lifecycle of the policies your firm authors — versioning, publishing, attestation and review. The content and responsibility for it remain with your firm.
Are SOC 2 or ISO 27001 held?
Not yet. Both are on our roadmap; we will publish attestations in the Trust Center once they are held rather than claim them beforehand.
Stand up your Governance, Policy & Controls programme
Book a walkthrough and we'll show how the composed programme fits your obligations, workflows and systems — then scope an implementation.