The management report (add-on)
One report across every risk area, measured against your global risk appetite: entities assessed, risks above appetite, exposure and plan cost. Part of the Enterprise Risk Management add-on.
One management report across every risk area: how many entities have been assessed, how many risks sit above appetite, what the exposure is now and once the open plans are done, and what those plans cost. Export it with your own comment on it, so the figures reach the board with your reading of them attached.
Unlimited users • Free onboarding and support • No commitment
Lars Bang is COO at Meridian Nordic and the executive sponsor for compliance. Maria Holm runs the risk areas across the group, GDPR, NIS2 and information security, each with its own scale and its own appetite. The numbers used to be collected out of three separate workbooks the week before a board meeting, and the person presenting them was rarely the person who made them. Now one management report brings the areas together against a single global risk appetite, Maria exports it with her own comment on it, and Lars takes one artefact into the meeting.
Exposure, in money
Financial exposure as it stands, exposure once the open mitigation plans are done, and what those plans are expected to cost.
Your comment travels with it
The report exports, and you insert a comment as part of the export, so nobody has to explain the numbers in a separate email.
Appetite against actual
How many entities have been assessed, and how many risks sit above appetite, measured against one global risk appetite.
A direction, not a snapshot
A trend over time shows whether the picture is improving, and a breakdown by area shows where the pressure comes from.
Risk assessment produces a lot of working material: entities, scenarios, consequence and probability, a justification on each. Almost none of it belongs in a board meeting.
Where several risk areas are in play, the management report brings the numbers together and measures them against one global risk appetite, which is how many risks in total may exceed appetite before management has to act.
A report that leaves the platform as bare figures gets explained in a separate email, and then the email and the figures live apart. Here the person exporting the report inserts a comment as part of the export.
Three financial figures run through the module, and the report puts them next to each other. That is the trade-off a board is actually asked to approve.
Beneath the management report is the governance overview, for whoever is responsible for a risk area. That is where the numbers in the report are made, and where they get worked.
The platform also has a Compliance Dashboard, which has been there since 2024, and it is a different object from the management report. Worth being plain about, because the two get confused.
One report across every risk area, measured against your global risk appetite: entities assessed, risks above appetite, exposure and plan cost. Part of the Enterprise Risk Management add-on.
The report exports, and the person exporting it inserts a comment as part of the export. The board gets the figures and the risk owner's framing in one artefact.
The estimated loss if a risk materialises, the expected exposure once a plan is complete, and the plan's own estimated cost. Three figures, one decision.
See which area the exposure comes from, so a board meeting goes straight to the two areas under pressure instead of touring all of them.
The layer beneath the report: a matrix of how many entities sit in each combination of consequence and probability, entities over appetite, linked risks over appetite and overdue mitigation plans.
Switch to what the picture would look like if every mitigation plan were completed, or back to a past point in time to see exactly how things looked then.
Run your information security management and meet NIS2, ISO 27001 and more in one place.
Explore Information Security Managementcompanies
users
contracts
processing activities
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Every use case is a real piece of compliance work, told the way it actually runs in the platform. Filter by who you are, what you work with, and which frameworks you answer to.
6 use cases
No use cases match that combination yet. Try removing a filter.
A report that brings your risk numbers together across every risk area and measures them against one global risk appetite. It shows how many entities have been assessed, how many risks currently sit above appetite, financial exposure now and once the open mitigation plans are completed, what those plans are expected to cost, a breakdown showing which area the pressure comes from, and a trend over time. It arrived with the Enterprise Risk Management add-on in August 2026.
A risk status, and the difference matters. The report reads risk data: areas, entities, appetite, exposure and mitigation plans. It does not aggregate framework progress, control completion, policy acknowledgements, the record of processing activities or vendor audit scores, so a full compliance picture for a board is still put together outside the platform.
Manage compliance across a group of companiesYes. The report exports, and the person exporting it can insert a comment as part of the export, so the figures arrive with the risk owner's own framing on them instead of in a separate email. We deliberately do not name a file format here, because none is documented. Ask about it on a demo.
No. The Compliance Dashboard has been in the platform since 2024 and is the operational layer: counts of processing activities, assets, vendors and tasks, documentation progress, a monthly task graph, incidents by severity, the latest audit submissions and the risks that scored high or very high. It has no risk appetite, no financial exposure and no trend against a target, so it is not a management report and we do not present it as one.
Your own assessments. Consequence and probability are stated by the person doing the assessment, each with a justification, and the risk level is looked up in a matrix you configure yourself, cell by cell if you want. The exposure figures are your estimates too. The platform does the arithmetic and keeps the record. It does not decide what your risks are.
The report shows the picture as it stands when you open it, and you export it when you need it, typically ahead of a board meeting. So it is pulled on demand rather than arriving by itself. If you need an older picture, the area owner can switch to any past point in time and see exactly how things looked then.
Yes. The management report and the governance overview beneath it came with Enterprise Risk Management, which is a paid add-on. Customers who do not have it carry on with the risk module they already use, and that module has no risk report of its own.
No. The report is exported and handed on, so nobody has to open the platform to read it. Users are unlimited if you do want a board member or an internal auditor to have access, but the report is built to be received rather than logged into.
What an internal audit involvesA plan moves from proposed to approved to completed, and it carries an estimated cost and the expected exposure once it is done, which is what the decision actually needs. The module is built around three levels of responsibility: the people assessing, the person responsible for a risk area, and management. How tightly approval should be locked down is worth raising on a demo, because that is where organisations differ most.
What management is accountable for under NIS2
Info
.legal A/S
hello@dotlegal.com
+45 7027 0127
VAT-no: DK40888888
Support
support@dotlegal.com
+45 7027 0127
Need help?
Let me help you get started
.legal is not a law firm and is therefore not under the supervision of the Bar Council.