Strategy & Operations

Business Process Analysis and Engineering

We map, analyse and redesign business processes together with management: less waste and rework, controls in the right places, short procedures that staff apply in their daily work, and a solid basis for digitalisation and management systems.

What we do

Our areas of work

AS-IS process mapping

We reconstruct how the company works in practice, through interviews, observation in the field and analysis of management data. We set out the processes in BPMN 2.0 notation, with SIPOC sheets and RACI matrices for roles and responsibilities.

Analysis of weaknesses

We identify bottlenecks, rework, waiting times and excessive lead times using lean thinking; we highlight operational risks, missing control points and activities that create no value for the customer.

TO-BE process redesign

We design the future process: simplified steps, standardisation, segregation of duties, controls placed where they are needed. Every choice is discussed with the people who run the process every day.

Automation and digitalisation

We assess where workflow, robotic process automation (RPA) and system integration remove repetitive activities and the re-keying of data between applications. We define clear functional requirements for IT suppliers, independent of any specific technology.

KPIs, procedures and work instructions

We turn the process into measurable indicators and monitoring dashboards, short procedures and role-based work instructions, so that the new design remains stable even when people change.

Integration with compliance systems

We align the process map with the requirements of ISO 9001, the 231 Model, the GDPR (data protection by design, Article 25), NIS2 and ISO/IEC 27001, so that the resulting procedures and controls serve every management system.

The context

A company’s processes rarely come from a design. They grow with the business: a new customer adds a step, a mistake adds a check, a change of software adds a table to be filled in by hand. After a few years the result is a set of activities that works, but that nobody knows in full and that depends on the experience of a handful of people. It costs more than the accounts suggest: long lead times, rework, information copied from one system to another, complaints that arise from steps that were missed.

Some situations make the issue urgent: the introduction of an ERP or a CRM, which requires processes to be defined before the software is configured; generational handover, where implicit knowledge has to become an asset of the organisation; post-acquisition integration, when two ways of working have to become one; regulated sectors such as energy and telecommunications, where back office and customer care handle high volumes within the timescales and rules laid down by ARERA (the Italian energy regulator) and AGCOM (the Italian communications authority), and where failure to meet commercial quality standards generates complaints and, in the cases provided for, automatic compensation.

Finally, compliance. ISO 9001 is built on the process approach; the 231 Model, under Italian Legislative Decree 231/2001, calls for protocols covering activities at risk of offence; the GDPR requires data protection by design and by default (Article 25); the NIS2 regime (Italian Legislative Decree 138/2024), for the entities that fall within it, and ISO/IEC 27001, for those adopting an information security management system, require security measures embedded in the way the business operates. All of them start from the same need: knowing how the company works.

Our approach

We start from the facts, not from organisation charts. The AS-IS phase reconstructs the process as it is carried out in practice, through interviews with managers and operators, observation of activities and analysis of the data held in the systems (times, volumes, errors). We set out the result in BPMN 2.0 notation, accompanied by SIPOC sheets that clarify the suppliers, inputs, outputs and customers of each process, and by RACI matrices that make responsibilities explicit. The maps are validated with the people who do the work: a map that operators do not recognise is wrong.

The analysis applies lean thinking: we distinguish the activities that create value from those that do not, we measure waiting times, rework and bottlenecks, and we identify operational risks and the points where a control or a segregation of duties is missing. The result is a shared diagnosis, from which senior management chooses where to begin.

The TO-BE redesign takes place in workshops with the functions involved. We simplify the steps, remove unnecessary variants, place controls where they are needed and assess where workflow, RPA and system integration can replace manual work. Every redesigned process comes with KPIs, complete with definitions and data sources, together with short procedures and role-based work instructions.

We do not stop at the design. We build the implementation plan with management, look after internal communication and training, and come back to measure the results after some time, correcting whatever has not worked in practice.

What sets our service apart

  • Support, not just documents: we work alongside management and operators until the new process is adopted and measured.
  • Measured results: the objectives set with senior management at the outset are verified against the KPIs after implementation; the comparison with the starting position is part of the delivery.
  • Technology independence: we define functional requirements that are independent of any specific technology and support the business in selecting and rolling out the tools; the decision on the supplier remains with the business.
  • A single map for every management system: the BPMN 2.0 maps, the SIPOC sheets and the RACI matrices are the shared basis for the ISO 9001 quality system, 231 protocols, data protection and security measures, with no parallel documentation to maintain.

Our method

How we work

  1. Scope and objectives

    Together with senior management we choose the processes to address on the basis of economic impact, risks and urgency; we set measurable objectives, points of contact and project timescales.

  2. AS-IS mapping

    We gather the knowledge of managers and operators and compare it with the data extracted from the systems. The maps are validated in a joint session with the people who do the work, before moving on to the analysis.

  3. Analysis and diagnosis

    We measure times, volumes, errors and rework and compare them with the objectives set. Senior management receives a picture of the weaknesses, with priorities and an estimate of the benefits achievable, in order to decide where to start.

  4. TO-BE redesign

    In workshops with the functions involved we compare alternatives, choose the simplifications and controls to introduce and agree who will do what. Senior management approves the final design and the priorities for roll-out.

  5. Implementation and measurement

    Implementation plan with owners and deadlines, change management, staff training and verification of results against the KPIs after a period of operation. We correct whatever is not working.

Benefits

What the business gains

  • Shorter lead times and lower operating costs, thanks to the removal of waiting times, rework and unnecessary steps
  • Operational risks kept under control: controls and segregation of duties placed at the critical points of the process
  • Decisions based on data: KPIs and dashboards that measure the process, not only the final result
  • Less dependence on individuals: knowledge documented in procedures and instructions, clear roles, repeatable activities
  • Procedures and controls written once and reused for certifications and compliance obligations, with no parallel documentation to maintain

Deliverables

What we deliver

  • AS-IS and TO-BE process maps in BPMN 2.0 notation, with SIPOC sheets and RACI matrices
  • Analysis report on weaknesses, with priorities for action and an estimate of the expected benefits
  • Role-based procedures and work instructions, in a short and usable format
  • KPI framework with definitions, data sources, frequencies and a monitoring dashboard
  • Functional requirements for workflow, RPA and system integration, supporting IT decisions
  • Implementation and change management plan with owners, deadlines and intermediate milestones
  • Staff training on the new process, with materials and certificates of attendance
  • Report measuring the results after roll-out, compared with the starting position

Frequently asked questions

Answers to the questions we hear most often

Our processes work: why call them into question?

Because they often work thanks to the experience of a few people and to stopgap fixes accumulated over time. Setting a process out explicitly makes it possible to see what it really costs, where errors arise and what happens if a key person is absent. This is not about changing everything: many measures are small and targeted, and the results are measured against data, not impressions.

How long does a process analysis project take?

It depends on the number and the complexity of the processes chosen. Mapping and analysing a single process, for example the order-to-cash cycle or complaint handling, generally takes a few weeks; work covering several areas or an entire back office is developed in phases. We agree the scope and the timescales before starting, so that senior management knows what to expect.

Does the project disrupt day-to-day operations?

We keep this to a minimum. Interviews and observation are organised around shifts and workload peaks, and the data is extracted from the systems already in use. The time required from company managers is concentrated in a few meetings and in the redesign workshops. Involving the people who run the process is in fact the condition for the new design to be adopted.

Is it better to digitalise first or to reorganise the processes first?

Reorganise first. Automating a confused process transfers the disorder into the software and makes corrections more expensive. The TO-BE design produces clear functional requirements to hand to the IT supplier: the business buys the functions it needs, reduces customisations and shortens go-live times. Where the adoption of a system is already under way, we align our work with the existing project plan.

How does this relate to ISO 9001 certification or to the 231 Model?

ISO 9001 requires a process approach; the 231 Model, under Italian Legislative Decree 231/2001, provides for protocols covering activities at risk of offence. Both start from the same question: how the company actually works. We use a single process map as the basis for the quality system, 231 protocols, data protection and security measures, without parallel procedures that nobody reads. Where the company is already certified, we update the existing documentation.

Let’s talk

Together, let’s build your tomorrow.

Tell us your business priorities: in a first meeting with no obligation we look at your context and propose a concrete way forward, with clear timescales and measurable results.