Home › Information Management › Our approach
Five phases. One accountable team. NIS2, DORA and the audits that follow, designed in from week one.
Regulation now shapes how documents, data and processes have to be handled: who can access what, how long it is kept, and how fast an incident gets reported. Acxess designs and runs information management processes where that evidence exists by default: retention rules, access logs and audit trails built into the process itself, not reconstructed under deadline before an audit. This is the approach behind every engagement, from the first two weeks of discovery to the team still running it years later.
Digital customers expect an answer before the sentence is finished. Digital employees expect the official version of a document to be the one everyone actually uses. Digital compliance expects the evidence to already exist. The Canon Information Orchestration Framework is how Acxess addresses all three at once: by connecting four areas of expertise into one governed approach instead of four separate projects. The five phases below are how that approach gets delivered, engagement by engagement.
Turns documents, emails and forms into trusted digital assets from the moment they arrive, so nothing has to be re-keyed downstream.
Gives that information one governed home, with retention, access and audit trails built into the process rather than checked afterwards.
Routes the work itself (approvals, integrations between business applications, and increasingly the AI agents that act across them) instead of routing paper.
Delivers the resulting information back to customers and employees, consistently, on the channel they picked.
Five phases, run in order, with a decision point between each one. You can stop, change direction or hand a phase to your own team at any boundary, and at every step, the evidence a NIS2 or DORA audit will ask for is already being built.
Canon's country organisations, close to the customer: local knowledge, local language, and a single point of contact for all Canon services.
A central organisation available to every country, providing deeper knowledge and specialist expertise whenever it's needed.
We spend two weeks inside the process before proposing anything.
We start by watching. For roughly two weeks we sit with the process as it is actually performed, not as the procedure describes it. We measure how long a document sits still, who touches it, how often it goes back a step and where people have built their own workaround. That produces a short list of changes ranked by the time they give back, and a set of numbers we can be held to later.
A target process, the platform that fits it, and the rules built in.
From that list we design the target process and choose the platform that fits it. Retention periods, access rules and audit trails are decided here, together with your legal and compliance people, rather than bolted on at the end. We also decide what stays as it is: the point is rarely to redesign everything, it is to fix the handovers that leak.
Built in stages, each one live on its own.
Building happens in stages, and each stage goes live on its own. That way value arrives before the full programme is finished and you keep the option to change direction. We connect to your existing systems first; replacing one is a last resort rather than an opening bid. The people who will use the process are involved during the build, not trained on it afterwards.
The team that designed it keeps it running.
After go-live the same team keeps the process running. That covers the platform, the integrations and the questions from the floor. Having one accountable party matters most at the moment something breaks, because there is nobody to point at, including the moment a NIS2 incident clock starts running.
Measured against the discovery numbers and adjusted.
At agreed intervals we measure the process against the numbers from the discovery phase and report what has changed. Volumes shift, legislation changes and departments reorganise, so the design is revisited rather than frozen. A process nobody reviews is a process nobody is watching, and it is also the record a DORA resilience test or a NIS2 audit will ask to see.
Each phase above is also something you can engage on its own, whether or not you continue with us for what comes next.
A discovery assessment and a vendor-neutral platform recommendation, before anything gets implemented. Discover and Design, delivered as a standalone engagement.
Learn moreInstallation, configuration and integration once the platform is chosen, with a project team and training so the new setup gets used the way it was designed.
Learn moreKeeping the platforms you run healthy: monitoring, patching, upgrades and defined response times when something needs attention.
Learn moreFull day-to-day operation of your information management estate, with one accountable team instead of a mix of internal and external owners.
Learn moreNIS2 made cybersecurity risk management mandatory for essential and important entities across the EU from October 2024, with named accountability at management-body level and a duty to report significant incidents within 24 hours and in full within 72. DORA did the same for the financial sector from January 2025, adding a register of every ICT third-party arrangement and regular resilience testing. Both start from the same assumption: the evidence has to already exist. Acxess builds that evidence into the same five phases used for every engagement, not into a separate compliance track.
Management bodies of essential and important entities are personally accountable for risk-management measures, and significant incidents must be reported within 24 hours, with a full report inside 72. Design decides who has access to what before anything goes live, and Support and manage means there is one team to call, not a committee to assemble.
Financial entities must keep a register of every ICT third-party arrangement and prove operational resilience under testing. Every platform and integration we deliver is documented to register standard, and staged implementation means each stage can be tested on its own before the next one depends on it.
The rules that predate NIS2 and DORA, GDPR among them, still apply and rarely relax. Retention periods, access rules and audit trails are decided in Design, together with your legal and compliance people, so the record exists before anyone has to ask for it.
Read how compliance runs across all of our information management practices
Three things make this different from a typical systems integrator or software reseller, and all three matter more, not less, once compliance is on the table.
Process engineering, implementation and orchestration of information management solutions since the early nineties.
Three thousand organisations rely on Acxess solutions and services to keep their document flows running.
Twenty of them are Fortune 500 companies, with the volumes and the compliance requirements that come with it.
Process engineering, implementation and orchestration are done by the same team. There is no handover from a consultant who understood your situation to an engineer who does not, and no gap where a compliance requirement gets lost in translation between them.
We implement and run established software rather than something we wrote ourselves. Which platform we propose depends on your process, your systems and your volume, not on what we happen to sell, so your NIS2 risk assessment or DORA third-party register is never held hostage to one supplier's roadmap.
That portfolio spans intelligent document processing, content services, process automation and customer communications. See the full software portfolio
The engagement does not end at delivery. Support, management and periodic review are part of the same agreement, with one party answerable for the result, which matters most on the day a NIS2 incident clock starts running, or a DORA resilience test finds a gap.
The same process can be delivered three ways. Which one fits depends on your data, your existing infrastructure and the rules you work under: data residency and access requirements under NIS2 and DORA often decide this before cost does.
Run the solution in the cloud for maximum flexibility, quick deployment and automatic updates, with minimal involvement from your own IT team.
Deployed inside your own infrastructure, for organisations with strict requirements on data residency, integration with legacy systems or internal security policy.
A combination of both, where sensitive records stay on your infrastructure and the parts that benefit from scale run in the cloud.
A five-phase process (Discover, Design, Implement and transition, Support and manage, Review and change), run by the same team from the first two weeks of discovery through years of operation, with retention, access and audit-trail rules built in during Design rather than added later.
About two weeks, spent observing the process as it is actually performed rather than as the written procedure describes it, producing a ranked list of changes and the baseline numbers used to measure the result later.
Not by default. Existing systems are connected to first; replacing one is treated as a last resort rather than a starting proposal.
It depends on your data residency requirements, existing infrastructure and the sector rules you operate under, which is often decided by NIS2 or DORA obligations before cost is considered.
No. Acxess implements and runs established platforms from named suppliers rather than proprietary software, and which platform is proposed follows from the process design rather than from a sales target.
The same team that designed and built the process supports and manages it: the platform, the integrations and day-to-day questions, with one party accountable for the result. The process is re-measured against the original discovery numbers at agreed intervals.
Start with a two-week discovery, or ask us how this approach applies to your NIS2 or DORA obligations specifically.
Our approach applies to every layer of the Canon Information Orchestration Framework: Capture, Content, Communicate and Process.