Build one risk register for the whole organisation

GDPR, NIS2, the AI Act, information security: one register, where each risk area keeps its own matrix, scale and appetite. Assess processes, assets and suppliers, plan what has to come down, and count what sits above appetite in one place.

Unlimited users  •  Free onboarding and support  •  No commitment

Illustration of one wide register panel fed by three rails carrying a ring, a stack of documents and a colleague, with four differently sized blank risk matrices standing behind it
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell
The governance overview for the NIS2 risk area in .legal: 23 of 23 entities assessed, one risk above an appetite set to 3, and a risk matrix counting entities in each combination of probability and consequence

One risk register Meridian's risk work moved out of six workbooks and into one register

Maria Holm is group GRC lead at Meridian Nordic, an energy group with two subsidiaries, around 1,200 suppliers, and GDPR, NIS2 and ISO 27001 all live at the same time. Risk used to be assessed in a workbook per framework, each with its own scale and its own owner, and nobody could answer how much sat above appetite in total. Now GDPR, NIS2, AI and information security are risk areas in one register, each with the matrix and appetite that fits it. Processes, assets and suppliers are assessed against concrete scenarios, and what is above appetite is counted in one place.

  • Each risk area keeps its own matrix, scale and appetite, so the GDPR model and the NIS2 model don't have to agree.
  • Processes, assets and suppliers sit in the same register, assessed one at a time or many at once.
  • One overall figure says how many risks in total may exceed appetite before it requires action from management.
  • Nothing gets overwritten: every assessment, decision and plan stays on the entity's own timeline.

  • A model per area

    Each risk area gets its own matrix, scale and appetite, so GDPR and NIS2 don't have to be judged on the same numbers.

  • One count above appetite

    One overall figure says how many risks in total may exceed appetite before it requires action from management.

  • Exposure, not adjectives

    Estimated financial loss if a risk materialises, what is left after mitigation, and what the plan itself is expected to cost.

  • Nothing overwritten

    Every assessment adds to the record, with a justification on both consequence and probability and a timeline per entity.

Illustration of five separate blank grids, each on its own slab and none the same size as another, with a single figure in the middle stretching thin lines out to all of them at once

One risk register Six workbooks, six versions of the truth

Most organisations already assess risk. The problem is where the assessments live, and what happens when somebody asks a question that spans two of them.

  • Each framework grows its own scale, so nothing adds up across them.
  • Nobody can say how many risks currently sit above appetite, because appetite was never written down as a number.
  • When the person who did the assessment changes job, the reasoning leaves with them.
The configuration screen for the NIS2 risk area, with its own 1 to 4 scale, an appetite of 3, editable names for every consequence, probability and risk level, and the matrix mapping each cell to a risk level

One risk register One register, a matrix per risk area

A risk area is a domain you assess within: GDPR, NIS2, the AI Act, information security, or one you define yourself. Set up as many as you need, and let each one keep its own model.

  • Per area you decide the scale, for example 1 to 3 or 1 to 6, the name and icon of each level, and the appetite that applies.
  • The matrix maps each combination of consequence and probability to a risk level. It arrives pre-filled with recommended defaults, and any cell can be edited by clicking it.
  • On top of the areas sits one overall appetite: how many risks in total may exceed appetite before management has to act.
The Operational tab of the NIS2 risk area, listing processing activities, assets and legal entities in one register with their risk before and after mitigation, and a bulk assess action above

One risk register Processes, assets and suppliers, at the scale you actually have

You choose which entities each risk area assesses, and nothing is attached by default. Then you assess them against concrete scenarios, one at a time or many at once.

  • Processes, assets and suppliers, so supply-chain risk sits on the same register as everything else.
  • Scenarios, consequences and security measures come from a catalogue built around GDPR, NIS2 and AI, or you write your own.
  • Bulk works on assessment and on mitigation, which is what makes twenty near-identical systems tractable.
Illustration of a timeline spine with a rising stack of record cards tethered along it, one of them flagged, and the newest card floating clear above the top as it is added

One risk register Nothing gets overwritten

Every assessment adds to the record rather than replacing it, so the register carries its own history. This is the part an auditor asks about, and the part that saves you when the colleague who did the work has moved on.

  • Consequence and probability each need a justification, so there is always something concrete to point at.
  • Each entity and scenario has its own timeline of every assessment, decision and mitigation over time.
  • A risk that has been reassessed without a new action being taken is flagged, so it doesn't quietly sit there.
The Mitigation tab of the NIS2 risk area, with plans counted by status from proposal through to cancelled, and one plan taking a supplier risk from High down to Very low

One risk register Decide what to do, and put a number on it

Once a risk is assessed you decide: accept it as it stands, avoid it by stopping the activity that causes it, or mitigate it with an action plan. Mitigation is the one with a process of its own.

  • A plan carries the actions, the risk level you expect once they are done, an estimated cost and the exposure left after mitigation.
  • Plans run proposed, approved, completed. When one completes, the current risk updates and the previous state is saved to history.
  • Across areas, a management report shows exposure now, exposure once open plans are done and what those plans are expected to cost, and it exports with a comment from the person exporting it.
Illustration of a person turning two unmarked dials on a console, with lines running up to a blank grid where a single cell lights up as the result

One risk register Rails, not your risk judgement

We supply the structure, the catalogue and the record. The judgement is yours, and there are two boundaries worth saying out loud before anyone books a demo.

  • The level is calculated from the consequence and probability you state, against a matrix you configured. There is no recommended score and no weighting.
  • The platform documents risk, it does not detect it. It doesn't scan, and it doesn't derive a status from breaches found automatically, so it is not a SIEM.
  • Enterprise Risk Management is a paid add-on and a different product from the risk assessment already in the platform. There is no conversion of existing risk data between the two.
.legal in practice

Features for one risk register

Risk areas with their own matrix (add-on)

Set up as many risk areas as you need and decide the scale, the name and icon of each level, and the appetite that applies. Part of Enterprise Risk Management, a paid add-on released in August 2026.

A catalogue to start from

Risk scenarios, consequences and security measures built from scratch or imported from our catalogue, which is built around GDPR, NIS2 and AI and written broadly enough to carry into other framework work.

Processes, assets and suppliers

Choose which entities each risk area assesses, then score them against concrete scenarios. Supply-chain risk sits on the same register as everything else.

Assess and mitigate in bulk

Assess many entities and scenarios in one go, and do the same on mitigation. That is what makes twenty near-identical systems a morning's work rather than a project.

Mitigation plans with a price on them

A plan carries the actions, the risk level you expect once they are done, an estimated cost and the exposure left after mitigation, and runs proposed, approved, completed.

An append-only audit trail

Nothing is overwritten. Each entity and scenario has its own timeline of every assessment, decision and mitigation, and a risk reassessed without a new action is flagged.

One risk register Frameworks this covers

One register, and the two frameworks it carries most of the weight for.

  • icon-framework-NIS2

    NIS2

    The risk-management measures behind your services, assessed on the processes, assets and suppliers that deliver them, so supply-chain risk is assessed directly rather than inferred.

    Learn about NIS2
  • icon-framework-ISO

    ISO 27001

    The catalogue starts from GDPR, NIS2 and AI, and the scenarios are written broadly enough that the same work carries into ISO 27001. Bulk assessment suits estates of near-identical systems.

    Learn about ISO 27001
.legal compliance platform

Build one risk register with...

Do you need one risk register for the whole organisation? We recommend the following module for that task.

Information Security Management

Where your security documentation, controls and annual wheel live, alongside the risk work on this page. Enterprise Risk Management itself is a separate paid add-on.

Explore Information Security Management

Our Customers

+400

companies

+10.000

users

+79.000

contracts

+14.000

processing activities

Bech Bruun

Bech-Bruun

Mikkel Friis Rossa (Partner)

.legal's team has consistently demonstrated a commitment to innovation while being responsive to the needs of our mutual clients.

Rasmus-boutrup-fenerum

Fenerum

Rasmus Boutrup (Financial Controller)

Case Study
With .legal, we've gained a simpler and more manageable solution that better suits our needs
Michael Berner 1

Lægeforeningen

Michael Berner (Lawyer)

.legal has been the right choice for us. .legal are professional and welcoming with skilled employees.
Nanna Rodian Christensen

Molecule Consultancy

Nanna Rodian Christensen (HR & Operational Manager)

Case Study
Firstly, it means that not all the work is in one place (me), and secondly, that the understanding of GDPR is implemented throughout the organisation.
ulrikdueholmbeckmann

Plum Safety

Ulrik Dueholm Beckmann (QC, CM og ESG Lead)

Case Study
From .legal, we experience an incredibly high degree of flexibility and willingness to adapt features to our local needs.
Bech Bruun

Bech-Bruun

Mikkel Friis Rossa (Partner)

.legal's team has consistently demonstrated a commitment to innovation while being responsive to the needs of our mutual clients.

Rasmus-boutrup-fenerum

Fenerum

Rasmus Boutrup (Financial Controller)

Case Study
With .legal, we've gained a simpler and more manageable solution that better suits our needs
Michael Berner 1

Lægeforeningen

Michael Berner (Lawyer)

.legal has been the right choice for us. .legal are professional and welcoming with skilled employees.
Nanna Rodian Christensen

Molecule Consultancy

Nanna Rodian Christensen (HR & Operational Manager)

Case Study
Firstly, it means that not all the work is in one place (me), and secondly, that the understanding of GDPR is implemented throughout the organisation.
ulrikdueholmbeckmann

Plum Safety

Ulrik Dueholm Beckmann (QC, CM og ESG Lead)

Case Study
From .legal, we experience an incredibly high degree of flexibility and willingness to adapt features to our local needs.
julie-oxenvad-novicell

Novicell

Julie Oxenvad (Legal Consultant)

Case Study
We are satisfied with the switch to .legal – it has strengthened our compliance work, made processes easier to manage and more transparent, and improved cross-team collaboration
Tinna Schultz

Min By Media

Tinna Schultz (HR Manager)

Case Study
It just works! It is so easy and user-friendly, and the overview of processing activities is brilliant.
ansat_Kaspar_Rochholz_005

DMJX

Kaspar Rochholz (GDPR Coordinator)

Case Study
.legal has really understood what it means to create a user-friendly and efficient solution. Privacy is an attractive product compared to price and functionality.
Profile-picture1

Axel Kaufmann ApS

Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)

Case Study
.legal continuously update the platform to ensure their customers always remain compliant. In our view, any other choice would be a downgrade.

NRGi

Mette Mühlendorph (Compliance Specialist)

Case Study
The implementation of .legal has made a difference in the way we handle compliance. The system has created structure and overview, which has had concrete benefits.
julie-oxenvad-novicell

Novicell

Julie Oxenvad (Legal Consultant)

Case Study
We are satisfied with the switch to .legal – it has strengthened our compliance work, made processes easier to manage and more transparent, and improved cross-team collaboration
Tinna Schultz

Min By Media

Tinna Schultz (HR Manager)

Case Study
It just works! It is so easy and user-friendly, and the overview of processing activities is brilliant.
ansat_Kaspar_Rochholz_005

DMJX

Kaspar Rochholz (GDPR Coordinator)

Case Study
.legal has really understood what it means to create a user-friendly and efficient solution. Privacy is an attractive product compared to price and functionality.
Profile-picture1

Axel Kaufmann ApS

Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)

Case Study
.legal continuously update the platform to ensure their customers always remain compliant. In our view, any other choice would be a downgrade.

NRGi

Mette Mühlendorph (Compliance Specialist)

Case Study
The implementation of .legal has made a difference in the way we handle compliance. The system has created structure and overview, which has had concrete benefits.
Use cases

Find the job you need done

Every use case is a real piece of compliance work, told the way it actually runs in the platform. Filter by who you are, what you work with, and which frameworks you answer to.

Book demo

6 use cases

Frequently Asked Questions about risk management

How is this different from the risk assessment we already have in the platform?

They are two separate products, and we would rather say that clearly than let it be a surprise. Enterprise Risk Management is a paid add-on released on 14 August 2026, with risk areas, appetite, treatment, mitigation plans, financial exposure and reporting. The risk assessment already in the platform stays live and keeps working if you don't buy the add-on. There is no conversion of your existing risk data between the two, so treat this as a new register rather than an upgrade of the old one.

Can each part of the organisation use its own risk model?

Yes, that is what a risk area is for. Each area comes with its own risk matrix, so you decide the scale, for example 1 to 3 or 1 to 6, the names and icons for each level, and the appetite that applies to that area. The matrix maps each combination of consequence and probability to a risk level, arrives pre-filled with recommended defaults, and any cell can be edited by clicking it.

What can we risk-assess?

Processes, assets and suppliers. You start by choosing which entities each risk area should assess, so nothing is attached by default and an area only holds what you put in it. Once an entity is in the area you add risk scenarios to it, and the same entity can be assessed in several areas at once if it needs to be.

What supply-chain security covers

Does the platform decide our risk for us?

No. The risk level is calculated automatically, but what that means is a lookup: it reads the consequence and probability you state against the matrix you configured. Consequence and probability each need a justification, so there is always a reason on the record. There is no recommended score and no weighting of consequences or measures, and controls or documentation attached to an assessment are references only, so they do not move the level.

Do we have to write all the risk scenarios ourselves?

Only if you want to. Risk scenarios, consequences and security measures can all be built from scratch or imported from our catalogue, and imported definitions can be edited afterwards to fit how you work. The catalogue is built around GDPR, NIS2 and AI, and because the scenarios are written broadly they also become usable in work on other frameworks, ISO 27001 for example. There is no separate ISO 27001 scenario set, and we would rather say so than let you expect one.

How risk assessment works in ISO 27001

What happens after a risk is assessed, and who approves a plan?

You decide how to handle it: accept it as it stands, avoid it by stopping the activity that causes it, or mitigate it with an action plan. A plan describes the actions, the risk level you expect once they are done, an estimated cost and the exposure that remains after mitigation, and it runs from proposed to approved to completed. When a plan completes, the current risk updates and the previous state is saved to history. Three levels of responsibility run through the module, the people doing the assessments, the person responsible for the risk area, and management. How approval should be gated in your organisation is a good thing to raise on a demo rather than read as a promise here.

Can we show an auditor why a risk was assessed the way it was?

That is what the audit trail is for. Every assessment adds to the record rather than replacing it, so nothing is ever overwritten, and each entity and scenario has its own timeline showing every assessment, decision and mitigation over time. Consequence and probability both carry a justification, and the system flags a risk that has been reassessed without a new action being taken. What we don't claim is an export of the trail itself, because that is not something we have documented, so ask about it rather than assume it.

Our risks are connected. Does the register show that?

Yes. A relationship graph shows how entities are connected, for example how a processing activity relates to the assets and suppliers behind it, which makes it easier to see why an entity has inherited a risk from elsewhere in the chain and to trace that connection as far as you need. The governance overview for a risk area carries linked risks over appetite as one of its key figures, so a connection to something over appetite is visible rather than implied.

Can colleagues report something they have noticed, without a login?

Yes. Observations are a mobile-friendly way to report something you have spotted, shared through a public link that doesn't require logging in, so a colleague out on a site can flag a concern in a minute. Observations land in an inbox where they are reviewed and, if relevant, converted into a risk scenario with the responsible person notified automatically. The triage is deliberately a person's job, not an automatic one.

What does management actually get out of this?

Where several risk areas are in play, a management report brings the numbers together across all of them, measured against your overall risk appetite: how many entities have been assessed, how many risks currently sit above appetite, financial exposure now and once open mitigation plans are completed, what those plans are expected to cost, a breakdown by area showing where the pressure comes from, and a trend over time. The report can be exported, and the person exporting it can insert a comment as part of the export, so what reaches the board is the figures plus the risk owner's own framing, in one artefact.

What management is accountable for under NIS2

Still unsure?

Ask Johannes directly, he runs most demos personally

Book him here
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell