Governed Onboarding

From scattered records to a governed privacy platform

Bring existing DPIAs, RoPA registers, supplier lists, system inventories, policies and documents into Acompli. Import, connect, enrich and start running assessments from a governed compliance foundation.

01Import02Connect03Enrich04Map05Cascade06Operate
Acompli Rapid Onboarding Brochure — page 1
View brochure
On this page
01
The onboarding workflow

Six stages from raw data to a governed compliance programme

Bring existing Word DPIAs, Excel registers, system exports, policies, and architecture diagrams into a scoped workflow. Acompli drafts downstream records, data flows, and classifications for named reviewers to confirm.

01Import

Bring your existing compliance estate

Upload up to 50 existing DPIAs and import your RoPA register with AI-powered column mapping. Bulk-load IT systems, vendors, and locations from any spreadsheet format.

AI extracts question-answer pairs from documents, detects frameworks (GDPR, EU AI Act, ISO 27701), and proposes matching templates or tailored drafts for review. Duplicate detection via file hashing prevents re-imports. Acompli hash- and time-stamps every imported file, so the trail back to source is preserved from the first upload.

Assessment import

50 files per batch. PDF, DOCX, DOC. AI Q&A extraction with OCR for scanned documents.

RoPA spreadsheet import

Excel or CSV. AI maps columns to regulatory compliance fields with confidence scores.

Knowledge base bulk load

IT systems, vendors, and locations imported from agreed spreadsheet sources.

Accepted →PDF, DOCX, DOC, XLSX, XLS, CSV — including OneTrust and TrustArc export formats
02Connect

Bring in data from agreed source systems

Confirm the business systems, document stores, access method, and import scope during deployment planning. Where a connector is included in the deployment agreement, records can be brought into the same reviewed migration workflow.

Each imported entity retains its source for provenance, so a reviewer can trace a register entry back to the connector or file it came from. Any recurring sync and update schedule is agreed as part of deployment scope.

CMDB and asset sources

Systems, vendors, locations, and ownership data

Work-management sources

Projects and agreed issue records

CRM sources

Relevant company and supplier records

Identity directories

Agreed tenant and organisational context

Document stores

Policies, contracts, and supporting evidence

Spreadsheet imports

RoPA, vendor, system, and location inventories

Scope →Connector availability, access, and any recurring sync are confirmed in the deployment agreement
03Enrich

Draft regulatory metadata for imported entities

Imported knowledge-base entities can be enriched with draft data categories, data subjects, risk levels, and processing purposes for review.

Enrichment runs in batches for cost efficiency. Confidence scores accompany every classification. User edits are never overwritten — AI only fills empty fields. Acompli's enrichment drafts the classification; your team reviews and confirms before it stands as part of the record.

AI Enrichment — Example System Record
Data categoriespersonal_details, financial, employment0.92
Data subjectscustomers, employees0.95
Risk levelHigh0.78
Processing purposeHR management, payroll0.88
Draft →Proposed values carry confidence scores; your team reviews and confirms each governed record.
04Map

Data flows are drafted from imported entities

After KB entities are imported, Acompli creates draft nodes for every system, vendor, and location, then proposes flows from supplier relationships, shared data categories, and assessment linkages.

Seven diagram types generated from reviewable inputs: full landscape, international transfers, third-party relationships, IT interconnections, data category flow, process map, and customer journey.

Drafted nodes

Every imported entity becomes a node in the data map — systems, vendors, locations, departments.

Inferred flows

Supplier relationships, shared data categories, and assessment linkages become directional data flows.

Vision extraction

Upload architecture diagrams or whiteboard photos — GPT Vision extracts systems and relationships.

Seven diagram types

Full landscape, international transfers, third-party, IT interconnections, and more — generated from imported records.

05Cascade

Every import starts a reviewed downstream workflow

Upload your DPIAs and Acompli drafts RoPA records, extracts candidate risks, and builds data flow maps for review. One import, multiple compliance artefacts.

Assessment imports produce RoPA records. KB imports generate data-flow maps and trigger AI enrichment. Templates unlock new assessments. Vendor names trigger AI contract research that locates their DPAs and privacy policies.

Assessment upload
→
Template match, RoPA generation, risk extraction, reports
KB spreadsheet or connector
→
AI enrichment, TPRM registers, data mapping, Mermaid diagrams
Architecture diagram
→
Vision extraction, KB entities, AI enrichment, data mapping
Assessment responses
→
Real-time entity detection, KB suggestions, data mapping updates
06Operate

Move from imported records to reviewed operations

Foundation, enhancement, and operation are illustrative phases, not fixed-day commitments. Timing depends on source-data volume and quality, the agreed integrations and security work, and the availability of named reviewers.

As your team answers new assessment questions, Acompli detects every system, vendor, and location mentioned and suggests KB entries for review. The knowledge base grows from ongoing work.

Phase 1

Foundation

Tenant setup, agreed source imports, RoPA mapping, assessment upload, and initial data-flow drafts.

Phase 2

Enhancement

Draft classification, template matching, risk review, and workflow configuration.

Phase 3

Operational

Named reviewers confirm imported records, team assignments begin, and the first governed workflows are launched.

Result →A current, searchable register backed by a full import audit trail

How onboarding works, in six steps

  1. Import — Upload existing DPIAs and import your RoPA register with AI-assisted column mapping.
  2. Connect — Bring in data from the source systems and document stores agreed for your deployment.
  3. Enrich — Draft data categories and regulatory metadata for named reviewers to confirm.
  4. Map — Draft data-flow nodes and flows are proposed from the imported systems and vendors.
  5. Cascade — Each import drafts downstream RoPA records, candidate risks and data-flow maps for review.
  6. Operate — Start governed work once the imported records and operating controls have been reviewed.
02

Onboarding answer

What determines the onboarding timeline?

Because Acompli imports your existing Article 30 RoPA export, your Word/PDF DPIAs, and your CMDB or vendor inventory and maps each field for review — rather than asking you to rebuild from a blank tenant — existing records can shorten the migration. The actual timeline depends on their volume and quality, the entities and jurisdictions in scope, agreed integrations and security work, and reviewer availability.

AI enrichment classifies and maps the imported entities; a person reviews and approves before anything becomes an official record, and every import is hash- and time-stamped for a defensible trail back to source.

Key takeaways

  • Scope before timing — source volume and quality, entities, integrations, security work, and reviewer availability define the migration plan.
  • No schema rewrite or rekeying — an Article 30 import preserves all seven controller fields the DPC and ICO look for under Article 30(1)(a)–(g), and Word/PDF DPIAs keep their Article 35(7) narrative verbatim with the original file hash- and time-stamped as evidence. See what a RoPA must contain.
  • Transfers and AI systems are surfaced for review — flows to non-EEA countries are flagged as Schrems II items (SCCs, an adequacy decision, or an Article 49 derogation), and imported AI systems are flagged against EU AI Act Annex III; the high-risk determination stays human-approved. Read the Schrems II / TIA guide · EU AI Act module (AI System Register available on opt-in (early access)).
  • Every import is auditable — each file is hash- and time-stamped with who imported what, so the trail back to source is defensible under the Data Protection Act 2018 (Ireland) and the UK GDPR (ICO).
03

Primary sources

What a migrated programme must preserve for the DPC and ICO

An Article 30 import preserves the seven controller fields under Article 30(1)(a)–(g); Word/PDF DPIAs keep their Article 35(7) narrative verbatim; transfers to non-EEA countries are surfaced as Schrems II items for review. The high-risk EU AI Act determination stays human-approved.

Last reviewed: 3 June 2026.

04
Migration comparison

How should you evaluate a privacy-platform migration?

Ask every provider how it preserves source records, handles gaps, scopes integrations, routes classifications to accountable reviewers, and records what changed during migration. A useful comparison starts with evidence and ownership rather than a headline duration.

Migration questionWhat to requireAcompli workflow
What defines the plan and timeline?Named source systems, data volumes, security dependencies, review owners, and acceptance criteriaScope and sequence are agreed before import; timing follows the confirmed data, integration, security, and review work
How is an existing RoPA migrated?Field-level mapping, visible gaps, and reviewer sign-off against Article 30XLSX/CSV or agreed source exports are mapped to Article 30 fields for review
What happens to existing DPIAs?Preserved narrative, linked original evidence, and clear treatment of missing fieldsSupported Word/PDF records are structured for review while the original remains linked as evidence
How are international transfers handled?Possible non-EEA flows surfaced with the destination, mechanism, and supporting evidence left for human confirmationImported location and supplier context can flag records for an SCC, adequacy, or Article 49 review
Can the migration itself be audited?Source provenance, import history, transformations, review decisions, and named ownershipImported files are hash- and time-stamped, with drafted outputs routed through named review

Legal and high-risk classifications remain the controller’s decision — AI drafts, maps, and flags; a human approves. For the underlying obligations see RoPA requirements guide (Ireland & UK), when a DPIA is required, and Transfer Impact Assessments.

Common questions

Onboarding questions answered

What does a typical Acompli onboarding sequence look like?

A typical onboarding moves through three illustrative phases: foundation, enhancement, and operation. Foundation covers tenant setup, agreed source imports, RoPA mapping, and assessment upload. Enhancement covers draft classification, template matching, risk review, and workflow configuration. Operation begins once named reviewers have checked the imported records and the team can start assigned work. The phases are a planning aid rather than a delivery guarantee: timing depends on source-data volume and quality, the integrations and security work included in the deployment agreement, and reviewer availability.

What must a RoPA import preserve to remain defensible under Article 30?

An Article 30 import must preserve all seven controller fields the DPC and ICO look for in an audit: (a) controller and DPO identity, (b) processing purposes, (c) categories of data subjects and personal data, (d) categories of recipients including processors and third countries, (e) third-country transfers and the transfer mechanism (SCCs, adequacy decision, or derogation under Article 49), (f) retention periods, and (g) a general description of the technical and organisational measures under Article 32. Processors must additionally preserve the categories of processing carried out on behalf of each controller per Article 30(2). Acompli's import maps each column from your source export into these fields and flags any missing element so the gap is visible before go-live, not in front of a regulator.

Can Acompli bulk-import Word and PDF DPIAs without rekeying?

Yes. Upload the folder of historical DPIAs as .docx or .pdf and the platform extracts each Article 35(7) section — systematic description, necessity and proportionality assessment, risks to data subjects, and safeguards — into a structured record while preserving the original document as evidence. The narrative answers are kept verbatim, then AI suggests matching template fields so the next iteration uses the same shape. EDPB Guidelines 04/2022 and the WP248 criteria are used as the classification spine for what counts as high-risk. The original file is hash-stamped and time-stamped against the imported record so the audit trail back to the source is intact.

What should a privacy platform onboarding prove?

It should preserve the records you already have, show what was imported, flag gaps before go-live, and leave an audit trail for the migration. In Acompli that means RoPA imports, historical DPIAs, vendor lists, transfer context and AI-system signals are mapped into governed records before the team starts new work.

How can onboarding surface international transfers from imported systems?

Spreadsheet imports and any source-system connectors included in the deployment agreement can populate the knowledge base of systems and vendors. Acompli then drafts hosting-region and processing-location fields for human review and surfaces possible non-EEA flows for a focused transfer assessment. The reviewer confirms the destination, transfer mechanism, and supporting evidence; the platform does not make the legal determination. Connector availability, access method, and any ongoing synchronisation are confirmed during deployment scoping.

How does onboarding classify high-risk AI systems from an imported inventory?

When the IT-asset inventory is imported, AI systems in the knowledge base are flagged for review against Annex III of the EU AI Act (the high-risk use cases including employment, education, essential services, law enforcement, migration, and justice). The AI Register module is available on opt-in (early access) and frames each entry across four classification fields — risk tier, Annex III applicability, Article 6(3) exception, and GPAI status. Self-attestation drives the classification; the platform structures the evidence but legal classification remains the controller's responsibility, working with counsel where needed. This is a roadmap area: today the value is rapid discovery and structured intake so an Annex III review is targeted rather than starting from a blank sheet.

What determines how long onboarding takes?

Timing depends on the volume and quality of the records you already hold, the number of entities and jurisdictions in scope, the source systems and security work included in the deployment agreement, and the availability of named reviewers. A clean RoPA export, a DPIA folder, and a current system or vendor inventory make mapping faster. Missing or inconsistent source records add discovery and review work. Acompli drafts mappings and classifications, but your team confirms them before they become governed records.

See governed onboarding in action

Bring the records you already have and see how Acompli maps them into reviewable, traceable workflows. Scope, integrations, security work, and timing are agreed for your deployment.

See how Acompli is packaged and priced on the pricing page.