Solutions
Financial Crime Compliance

Ongoing Monitoring & Screening

Keep watching after onboarding — risk doesn't stand still

A customer's risk is not fixed at onboarding: sanctions lists change, people become politically exposed, adverse media surfaces and behaviour shifts. This programme composes continuous screening and ongoing monitoring so change is detected across the life of a relationship, surfaced as prioritised alerts, and routed to review — with tuning that keeps analysts focused on what matters.

At a glance

One programme, on one platform

Ongoing Monitoring & Screening on OnyxOneSchematic
Your teamsCompliance · risk · legalAnalysts & investigatorsScreen, review and decideOversight & approvalsSign-off and reportingOnyxOneCompliance & risk OSScreening · Due diligenceCases · Risk · MonitoringPolicy · Reporting · AuditSystems & sourcesConfigured per deploymentScreening data providersSanctions · PEP · mediaYour systems of recordOnboarding · core systemsOne platform for the whole programme — not a stack of disconnected tools and spreadsheets.

Your compliance, risk and legal teams run the programme in OnyxOne, which composes the relevant modules onto one record and connects to the systems and data sources your deployment requires.

The programme

What this programme is, and why it matters

A solution is a programme, not a single tool — the outcome a set of platform capabilities add up to when they run on one record.

The customer compliance lifecycleSchematic
1AlertRaised2TriagePrioritise3InvestigateEvidence4DecisionApprove5ReportAudit-loggedreopenClear ownership and recorded decisions at every stage — a defensible trail from alert to closure.

How onboarding, due diligence and review become a decided, evidenced outcome — with a defensible trail from first contact to closure.

Onboarding is a snapshot; monitoring is the film

Screening at onboarding tells you who a customer is on day one. Ongoing monitoring keeps that picture current — re-screening against updated lists and watching for behavioural change so new risk is caught when it emerges, not at the next periodic review.

Continuous screening

Customers and entities are re-screened against sanctions, PEP and adverse-media sources on an ongoing basis, so a newly listed party or a change in PEP status raises an alert rather than sitting undetected until someone looks.

Behavioural monitoring

The programme surfaces shifts in expected activity against the customer's profile, so patterns that warrant a closer look are flagged and routed to review with the context attached.

Signal over noise

Volume is the enemy of monitoring. Configurable match logic, thresholds and tuning keep false positives down, so analysts spend their time on genuinely suspicious activity rather than clearing the same benign matches repeatedly.

The challenge

What makes this hard today

The operational realities this programme is designed to resolve.

Point-in-time only

Firms that screen at onboarding but not continuously miss the moment a customer becomes sanctioned or politically exposed after the relationship begins.

Alert overload

Poorly tuned screening generates walls of false positives, burning analyst time and burying the alerts that actually matter.

Disconnected signals

When screening and transaction-behaviour signals live in separate tools, no one view shows the full change in a customer's risk.

Untraceable dispositions

Clearing an alert without capturing why leaves no defensible record of the decision when it is later questioned.

Reactive periodic reviews

Relying on scheduled reviews alone means risk that emerges between reviews goes unaddressed until the next cycle.

How it works

The operating model, at a glance

How the composed programme runs — from the data it takes in to the decisions and evidence it produces.

A representative flowSchematic
Item receivedOnboarding / eventRiskthreshold?Auto-clearLow risk · loggedEscalate to reviewAnalyst investigatesRecord &auditNoYes — parallel review paths

Work is triaged, escalated when it matters, and recorded either way — every path lands on the audit trail.

01

Configure monitoring

Set re-screening cadence, match logic, behavioural rules and thresholds against your risk methodology and expected-activity profiles.

02

Screen continuously

Customers and entities are re-screened against updated sanctions, PEP and adverse-media sources on an ongoing basis.

03

Detect change

New matches, status changes and behavioural shifts are detected and raised as alerts against the customer record.

04

Triage & tune

Alerts are prioritised, false positives are dispositioned with rationale, and tuning reduces recurring noise.

05

Escalate & record

Material alerts route into structured review or investigation, and every disposition is preserved in the audit trail.

Capabilities

What the programme gives you

The concrete capabilities the composed programme provides, end to end.

Continuous re-screening

Re-screen customers and entities against updated sanctions, PEP and adverse-media sources so new matches surface as they arise.

Behavioural monitoring

Surface shifts in activity against expected-behaviour profiles and flag patterns that warrant a closer look, with context attached.

Configurable match logic

Tune fuzzy-name handling, thresholds and rules to control false positives without losing genuine hits.

Alert prioritisation

Rank alerts so analyst attention lands on the highest-risk signals first rather than in list order.

Disposition with rationale

Clear or escalate each alert with a recorded reason, so every decision is defensible when it is later reviewed.

Tuning analytics

Understand alert volumes, false-positive rates and disposition patterns so screening can be tuned on evidence, not guesswork.

The workflow

The end-to-end workflow

A defined process with clear ownership at every stage, captured against the record it belongs to.

The workflow, step by stepSchematic
01Re-screen & monitorCustomers are re-screened and their activity monitored against profiles on anongoing basis.02Raise alertsNew matches, status changes and behavioural shifts are raised as alerts against thecustomer record.03PrioritiseAlerts are ranked by risk so the highest-priority signals are worked first.04DispositionAnalysts clear false positives with rationale or escalate material alerts forreview.05InvestigateEscalated alerts become structured investigations with evidence and four-eyes reviewwhere warranted.06Tune & preserveDisposition patterns inform tuning, and every alert and outcome is preserved in theaudit trail.

Every result, decision and override is captured against the record it belongs to.

01

Re-screen & monitor

Customers are re-screened and their activity monitored against profiles on an ongoing basis.

02

Raise alerts

New matches, status changes and behavioural shifts are raised as alerts against the customer record.

03

Prioritise

Alerts are ranked by risk so the highest-priority signals are worked first.

04

Disposition

Analysts clear false positives with rationale or escalate material alerts for review.

05

Investigate

Escalated alerts become structured investigations with evidence and four-eyes review where warranted.

06

Tune & preserve

Disposition patterns inform tuning, and every alert and outcome is preserved in the audit trail.

Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems the programme requires, configured per implementation.

Screening & data sources
  • Re-screens against the sanctions, PEP and adverse-media providers contracted for your deployment
Transaction & activity data
  • Ingests transaction and activity data from your core systems to support behavioural monitoring
Systems of record
  • Reads customer and account records so alerts are raised against the right relationship
Case & investigation hand-off
  • Routes material alerts into case management and investigations for structured review
Collaboration & notification
  • Surfaces alerts and escalations through your existing email and messaging tools
Assurance

Security & reporting

Security & data handling

  • Screening results and monitoring data are encrypted in transit and at rest.
  • Access to alerts and suspicion-related information is role-based and restricted under need-to-know.
  • Every screening result, alert, disposition and override is written to an append-only audit trail.
  • Tuning changes to match logic and thresholds are versioned and attributed.
  • Data residency and retention are configurable to your jurisdiction and record-keeping obligations.

Reports & returns

  • Screening-coverage and re-screening cadence reports
  • Alert volume, ageing and disposition reports
  • False-positive rate and tuning-effectiveness reporting
  • Escalation and investigation-conversion reporting
  • Sanctions and PEP exposure summaries for the second line
The value

What your team gains

Risk caught as it emerges

Continuous screening and monitoring surface new risk when it appears, not at the next periodic review.

Analysts focused on real risk

Tuning and prioritisation cut recurring false positives, so effort concentrates on genuinely suspicious activity.

One view of change

Screening and behavioural signals land on the same record, so the full change in a customer's risk is visible in one place.

Defensible dispositions

Every alert clearance carries a recorded rationale, so decisions stand up when they are questioned.

FAQ

Questions, answered

How is this different from onboarding screening?

Onboarding screening is a point-in-time check. This programme re-screens continuously and monitors behaviour over the life of a relationship, so risk that emerges after onboarding is caught when it appears.

How do you control false positives?

Match logic, fuzzy-name handling and thresholds are configurable, and tuning analytics show where recurring false positives come from — so screening can be tuned on evidence to keep genuine hits while cutting noise.

Does OnyxOne provide the sanctions and PEP data?

No. It re-screens against the sanctions, PEP and adverse-media providers configured for your deployment. OnyxOne orchestrates and records the screening; the data comes from the sources you contract.

What happens to a material alert?

Material alerts route into structured review or a full investigation with evidence and four-eyes sign-off, and the outcome and rationale are preserved on the record and in the audit trail.

Are SOC 2 or ISO 27001 held?

Not yet. Both are on our roadmap; we will publish attestations in the Trust Center once they are held rather than claim them beforehand.

Stand up your Ongoing Monitoring & Screening programme

Book a walkthrough and we'll show how the composed programme fits your obligations, workflows and systems — then scope an implementation.