Ongoing Monitoring & Screening
Keep watching after onboarding — risk doesn't stand still
A customer's risk is not fixed at onboarding: sanctions lists change, people become politically exposed, adverse media surfaces and behaviour shifts. This programme composes continuous screening and ongoing monitoring so change is detected across the life of a relationship, surfaced as prioritised alerts, and routed to review — with tuning that keeps analysts focused on what matters.
One programme, on one platform
Your compliance, risk and legal teams run the programme in OnyxOne, which composes the relevant modules onto one record and connects to the systems and data sources your deployment requires.
What this programme is, and why it matters
A solution is a programme, not a single tool — the outcome a set of platform capabilities add up to when they run on one record.
How onboarding, due diligence and review become a decided, evidenced outcome — with a defensible trail from first contact to closure.
Onboarding is a snapshot; monitoring is the film
Screening at onboarding tells you who a customer is on day one. Ongoing monitoring keeps that picture current — re-screening against updated lists and watching for behavioural change so new risk is caught when it emerges, not at the next periodic review.
Continuous screening
Customers and entities are re-screened against sanctions, PEP and adverse-media sources on an ongoing basis, so a newly listed party or a change in PEP status raises an alert rather than sitting undetected until someone looks.
Behavioural monitoring
The programme surfaces shifts in expected activity against the customer's profile, so patterns that warrant a closer look are flagged and routed to review with the context attached.
Signal over noise
Volume is the enemy of monitoring. Configurable match logic, thresholds and tuning keep false positives down, so analysts spend their time on genuinely suspicious activity rather than clearing the same benign matches repeatedly.
What makes this hard today
The operational realities this programme is designed to resolve.
Point-in-time only
Firms that screen at onboarding but not continuously miss the moment a customer becomes sanctioned or politically exposed after the relationship begins.
Alert overload
Poorly tuned screening generates walls of false positives, burning analyst time and burying the alerts that actually matter.
Disconnected signals
When screening and transaction-behaviour signals live in separate tools, no one view shows the full change in a customer's risk.
Untraceable dispositions
Clearing an alert without capturing why leaves no defensible record of the decision when it is later questioned.
Reactive periodic reviews
Relying on scheduled reviews alone means risk that emerges between reviews goes unaddressed until the next cycle.
The operating model, at a glance
How the composed programme runs — from the data it takes in to the decisions and evidence it produces.
Work is triaged, escalated when it matters, and recorded either way — every path lands on the audit trail.
Configure monitoring
Set re-screening cadence, match logic, behavioural rules and thresholds against your risk methodology and expected-activity profiles.
Screen continuously
Customers and entities are re-screened against updated sanctions, PEP and adverse-media sources on an ongoing basis.
Detect change
New matches, status changes and behavioural shifts are detected and raised as alerts against the customer record.
Triage & tune
Alerts are prioritised, false positives are dispositioned with rationale, and tuning reduces recurring noise.
Escalate & record
Material alerts route into structured review or investigation, and every disposition is preserved in the audit trail.
The modules this solution composes
A solution is a curated set of platform modules working as one programme. Turn on what the programme needs and add more as it scales.
What the programme gives you
The concrete capabilities the composed programme provides, end to end.
Continuous re-screening
Re-screen customers and entities against updated sanctions, PEP and adverse-media sources so new matches surface as they arise.
Behavioural monitoring
Surface shifts in activity against expected-behaviour profiles and flag patterns that warrant a closer look, with context attached.
Configurable match logic
Tune fuzzy-name handling, thresholds and rules to control false positives without losing genuine hits.
Alert prioritisation
Rank alerts so analyst attention lands on the highest-risk signals first rather than in list order.
Disposition with rationale
Clear or escalate each alert with a recorded reason, so every decision is defensible when it is later reviewed.
Tuning analytics
Understand alert volumes, false-positive rates and disposition patterns so screening can be tuned on evidence, not guesswork.
The end-to-end workflow
A defined process with clear ownership at every stage, captured against the record it belongs to.
Every result, decision and override is captured against the record it belongs to.
Re-screen & monitor
Customers are re-screened and their activity monitored against profiles on an ongoing basis.
Raise alerts
New matches, status changes and behavioural shifts are raised as alerts against the customer record.
Prioritise
Alerts are ranked by risk so the highest-priority signals are worked first.
Disposition
Analysts clear false positives with rationale or escalate material alerts for review.
Investigate
Escalated alerts become structured investigations with evidence and four-eyes review where warranted.
Tune & preserve
Disposition patterns inform tuning, and every alert and outcome is preserved in the audit trail.
Industries this programme serves
The sectors this programme is most often deployed in. The same programme, framed around each sector's obligations.
Works with your existing systems
Described as capabilities — OnyxOne connects to the systems the programme requires, configured per implementation.
- Re-screens against the sanctions, PEP and adverse-media providers contracted for your deployment
- Ingests transaction and activity data from your core systems to support behavioural monitoring
- Reads customer and account records so alerts are raised against the right relationship
- Routes material alerts into case management and investigations for structured review
- Surfaces alerts and escalations through your existing email and messaging tools
Security & reporting
Security & data handling
- Screening results and monitoring data are encrypted in transit and at rest.
- Access to alerts and suspicion-related information is role-based and restricted under need-to-know.
- Every screening result, alert, disposition and override is written to an append-only audit trail.
- Tuning changes to match logic and thresholds are versioned and attributed.
- Data residency and retention are configurable to your jurisdiction and record-keeping obligations.
Reports & returns
- Screening-coverage and re-screening cadence reports
- Alert volume, ageing and disposition reports
- False-positive rate and tuning-effectiveness reporting
- Escalation and investigation-conversion reporting
- Sanctions and PEP exposure summaries for the second line
What your team gains
Risk caught as it emerges
Continuous screening and monitoring surface new risk when it appears, not at the next periodic review.
Analysts focused on real risk
Tuning and prioritisation cut recurring false positives, so effort concentrates on genuinely suspicious activity.
One view of change
Screening and behavioural signals land on the same record, so the full change in a customer's risk is visible in one place.
Defensible dispositions
Every alert clearance carries a recorded rationale, so decisions stand up when they are questioned.
Questions, answered
How is this different from onboarding screening?
Onboarding screening is a point-in-time check. This programme re-screens continuously and monitors behaviour over the life of a relationship, so risk that emerges after onboarding is caught when it appears.
How do you control false positives?
Match logic, fuzzy-name handling and thresholds are configurable, and tuning analytics show where recurring false positives come from — so screening can be tuned on evidence to keep genuine hits while cutting noise.
Does OnyxOne provide the sanctions and PEP data?
No. It re-screens against the sanctions, PEP and adverse-media providers configured for your deployment. OnyxOne orchestrates and records the screening; the data comes from the sources you contract.
What happens to a material alert?
Material alerts route into structured review or a full investigation with evidence and four-eyes sign-off, and the outcome and rationale are preserved on the record and in the audit trail.
Are SOC 2 or ISO 27001 held?
Not yet. Both are on our roadmap; we will publish attestations in the Trust Center once they are held rather than claim them beforehand.
Stand up your Ongoing Monitoring & Screening programme
Book a walkthrough and we'll show how the composed programme fits your obligations, workflows and systems — then scope an implementation.