Risk areas with their own matrix (add-on)
Set up as many risk areas as you need and decide the scale, the name and icon of each level, and the appetite that applies. Part of Enterprise Risk Management, a paid add-on released in August 2026.
GDPR, NIS2, the AI Act, information security: one register, where each risk area keeps its own matrix, scale and appetite. Assess processes, assets and suppliers, plan what has to come down, and count what sits above appetite in one place.
Unlimited users • Free onboarding and support • No commitment
Maria Holm is group GRC lead at Meridian Nordic, an energy group with two subsidiaries, around 1,200 suppliers, and GDPR, NIS2 and ISO 27001 all live at the same time. Risk used to be assessed in a workbook per framework, each with its own scale and its own owner, and nobody could answer how much sat above appetite in total. Now GDPR, NIS2, AI and information security are risk areas in one register, each with the matrix and appetite that fits it. Processes, assets and suppliers are assessed against concrete scenarios, and what is above appetite is counted in one place.
A model per area
Each risk area gets its own matrix, scale and appetite, so GDPR and NIS2 don't have to be judged on the same numbers.
One count above appetite
One overall figure says how many risks in total may exceed appetite before it requires action from management.
Exposure, not adjectives
Estimated financial loss if a risk materialises, what is left after mitigation, and what the plan itself is expected to cost.
Nothing overwritten
Every assessment adds to the record, with a justification on both consequence and probability and a timeline per entity.
Most organisations already assess risk. The problem is where the assessments live, and what happens when somebody asks a question that spans two of them.
A risk area is a domain you assess within: GDPR, NIS2, the AI Act, information security, or one you define yourself. Set up as many as you need, and let each one keep its own model.
You choose which entities each risk area assesses, and nothing is attached by default. Then you assess them against concrete scenarios, one at a time or many at once.
Every assessment adds to the record rather than replacing it, so the register carries its own history. This is the part an auditor asks about, and the part that saves you when the colleague who did the work has moved on.
Once a risk is assessed you decide: accept it as it stands, avoid it by stopping the activity that causes it, or mitigate it with an action plan. Mitigation is the one with a process of its own.
We supply the structure, the catalogue and the record. The judgement is yours, and there are two boundaries worth saying out loud before anyone books a demo.
Set up as many risk areas as you need and decide the scale, the name and icon of each level, and the appetite that applies. Part of Enterprise Risk Management, a paid add-on released in August 2026.
Risk scenarios, consequences and security measures built from scratch or imported from our catalogue, which is built around GDPR, NIS2 and AI and written broadly enough to carry into other framework work.
Choose which entities each risk area assesses, then score them against concrete scenarios. Supply-chain risk sits on the same register as everything else.
Assess many entities and scenarios in one go, and do the same on mitigation. That is what makes twenty near-identical systems a morning's work rather than a project.
A plan carries the actions, the risk level you expect once they are done, an estimated cost and the exposure left after mitigation, and runs proposed, approved, completed.
Nothing is overwritten. Each entity and scenario has its own timeline of every assessment, decision and mitigation, and a risk reassessed without a new action is flagged.
One register, and the two frameworks it carries most of the weight for.
NIS2
The risk-management measures behind your services, assessed on the processes, assets and suppliers that deliver them, so supply-chain risk is assessed directly rather than inferred.
ISO 27001
The catalogue starts from GDPR, NIS2 and AI, and the scenarios are written broadly enough that the same work carries into ISO 27001. Bulk assessment suits estates of near-identical systems.
Where your security documentation, controls and annual wheel live, alongside the risk work on this page. Enterprise Risk Management itself is a separate paid add-on.
Explore Information Security Managementcompanies
users
contracts
processing activities
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Every use case is a real piece of compliance work, told the way it actually runs in the platform. Filter by who you are, what you work with, and which frameworks you answer to.
6 use cases
No use cases match that combination yet. Try removing a filter.
They are two separate products, and we would rather say that clearly than let it be a surprise. Enterprise Risk Management is a paid add-on released on 14 August 2026, with risk areas, appetite, treatment, mitigation plans, financial exposure and reporting. The risk assessment already in the platform stays live and keeps working if you don't buy the add-on. There is no conversion of your existing risk data between the two, so treat this as a new register rather than an upgrade of the old one.
Yes, that is what a risk area is for. Each area comes with its own risk matrix, so you decide the scale, for example 1 to 3 or 1 to 6, the names and icons for each level, and the appetite that applies to that area. The matrix maps each combination of consequence and probability to a risk level, arrives pre-filled with recommended defaults, and any cell can be edited by clicking it.
Processes, assets and suppliers. You start by choosing which entities each risk area should assess, so nothing is attached by default and an area only holds what you put in it. Once an entity is in the area you add risk scenarios to it, and the same entity can be assessed in several areas at once if it needs to be.
What supply-chain security coversNo. The risk level is calculated automatically, but what that means is a lookup: it reads the consequence and probability you state against the matrix you configured. Consequence and probability each need a justification, so there is always a reason on the record. There is no recommended score and no weighting of consequences or measures, and controls or documentation attached to an assessment are references only, so they do not move the level.
Only if you want to. Risk scenarios, consequences and security measures can all be built from scratch or imported from our catalogue, and imported definitions can be edited afterwards to fit how you work. The catalogue is built around GDPR, NIS2 and AI, and because the scenarios are written broadly they also become usable in work on other frameworks, ISO 27001 for example. There is no separate ISO 27001 scenario set, and we would rather say so than let you expect one.
How risk assessment works in ISO 27001You decide how to handle it: accept it as it stands, avoid it by stopping the activity that causes it, or mitigate it with an action plan. A plan describes the actions, the risk level you expect once they are done, an estimated cost and the exposure that remains after mitigation, and it runs from proposed to approved to completed. When a plan completes, the current risk updates and the previous state is saved to history. Three levels of responsibility run through the module, the people doing the assessments, the person responsible for the risk area, and management. How approval should be gated in your organisation is a good thing to raise on a demo rather than read as a promise here.
That is what the audit trail is for. Every assessment adds to the record rather than replacing it, so nothing is ever overwritten, and each entity and scenario has its own timeline showing every assessment, decision and mitigation over time. Consequence and probability both carry a justification, and the system flags a risk that has been reassessed without a new action being taken. What we don't claim is an export of the trail itself, because that is not something we have documented, so ask about it rather than assume it.
Yes. A relationship graph shows how entities are connected, for example how a processing activity relates to the assets and suppliers behind it, which makes it easier to see why an entity has inherited a risk from elsewhere in the chain and to trace that connection as far as you need. The governance overview for a risk area carries linked risks over appetite as one of its key figures, so a connection to something over appetite is visible rather than implied.
Yes. Observations are a mobile-friendly way to report something you have spotted, shared through a public link that doesn't require logging in, so a colleague out on a site can flag a concern in a minute. Observations land in an inbox where they are reviewed and, if relevant, converted into a risk scenario with the responsible person notified automatically. The triage is deliberately a person's job, not an automatic one.
Where several risk areas are in play, a management report brings the numbers together across all of them, measured against your overall risk appetite: how many entities have been assessed, how many risks currently sit above appetite, financial exposure now and once open mitigation plans are completed, what those plans are expected to cost, a breakdown by area showing where the pressure comes from, and a trend over time. The report can be exported, and the person exporting it can insert a comment as part of the export, so what reaches the board is the figures plus the risk owner's own framing, in one artefact.
What management is accountable for under NIS2
Info
.legal A/S
hello@dotlegal.com
+45 7027 0127
VAT-no: DK40888888
Support
support@dotlegal.com
+45 7027 0127
Need help?
Let me help you get started
.legal is not a law firm and is therefore not under the supervision of the Bar Council.