The context
A company’s processes rarely come from a design. They grow with the business: a new customer adds a step, a mistake adds a check, a change of software adds a table to be filled in by hand. After a few years the result is a set of activities that works, but that nobody knows in full and that depends on the experience of a handful of people. It costs more than the accounts suggest: long lead times, rework, information copied from one system to another, complaints that arise from steps that were missed.
Some situations make the issue urgent: the introduction of an ERP or a CRM, which requires processes to be defined before the software is configured; generational handover, where implicit knowledge has to become an asset of the organisation; post-acquisition integration, when two ways of working have to become one; regulated sectors such as energy and telecommunications, where back office and customer care handle high volumes within the timescales and rules laid down by ARERA (the Italian energy regulator) and AGCOM (the Italian communications authority), and where failure to meet commercial quality standards generates complaints and, in the cases provided for, automatic compensation.
Finally, compliance. ISO 9001 is built on the process approach; the 231 Model, under Italian Legislative Decree 231/2001, calls for protocols covering activities at risk of offence; the GDPR requires data protection by design and by default (Article 25); the NIS2 regime (Italian Legislative Decree 138/2024), for the entities that fall within it, and ISO/IEC 27001, for those adopting an information security management system, require security measures embedded in the way the business operates. All of them start from the same need: knowing how the company works.
Our approach
We start from the facts, not from organisation charts. The AS-IS phase reconstructs the process as it is carried out in practice, through interviews with managers and operators, observation of activities and analysis of the data held in the systems (times, volumes, errors). We set out the result in BPMN 2.0 notation, accompanied by SIPOC sheets that clarify the suppliers, inputs, outputs and customers of each process, and by RACI matrices that make responsibilities explicit. The maps are validated with the people who do the work: a map that operators do not recognise is wrong.
The analysis applies lean thinking: we distinguish the activities that create value from those that do not, we measure waiting times, rework and bottlenecks, and we identify operational risks and the points where a control or a segregation of duties is missing. The result is a shared diagnosis, from which senior management chooses where to begin.
The TO-BE redesign takes place in workshops with the functions involved. We simplify the steps, remove unnecessary variants, place controls where they are needed and assess where workflow, RPA and system integration can replace manual work. Every redesigned process comes with KPIs, complete with definitions and data sources, together with short procedures and role-based work instructions.
We do not stop at the design. We build the implementation plan with management, look after internal communication and training, and come back to measure the results after some time, correcting whatever has not worked in practice.
What sets our service apart
- Support, not just documents: we work alongside management and operators until the new process is adopted and measured.
- Measured results: the objectives set with senior management at the outset are verified against the KPIs after implementation; the comparison with the starting position is part of the delivery.
- Technology independence: we define functional requirements that are independent of any specific technology and support the business in selecting and rolling out the tools; the decision on the supplier remains with the business.
- A single map for every management system: the BPMN 2.0 maps, the SIPOC sheets and the RACI matrices are the shared basis for the ISO 9001 quality system, 231 protocols, data protection and security measures, with no parallel documentation to maintain.