ADD-ON

Every framework wants a risk assessment. You only need one system.

GDPR, NIS2, ISO 27001, the AI Act — each one asks you to assess risk, and each one asks in its own language. Enterprise Risk Management gives every area its own scale, its own wording and its own appetite, assesses the processes, assets and suppliers you already have in .legal, and adds the exceedances up into one report management can act on.

Trusted by 400+ organisations
Watch a demo of Enterprise Risk Management👇
GDPR-compliant
Hosted in EU
Free onboarding
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell
The Create risk area dialog in .legal offering GDPR, NIS2, AI Act, information security or a custom area, over the list of areas already created

Four frameworks, four spreadsheets, no overview

Most organisations don't have a risk problem. They have four risk problems, in four different files, on four different scales. The GDPR assessment was built when GDPR landed. NIS2 got its own sheet because three steps weren't enough. Information security has a fifth. And when management asks how the organisation is doing on risk, somebody spends a week building an answer by hand.

  • One scale can't serve every domain: IT thinks downtime and attack surface, legal thinks data subjects and fines. Forcing both into the same three steps loses whatever made each of them useful.
  • Risk isn't a list, it's attached to things: It sits on a processing activity, on the system behind it, on the supplier hosting it — all of which are already registered somewhere else in your platform.
  • An assessment nobody acts on is a document: The decision lives in an email thread and the action lives in someone's head, so nothing closes and nothing improves.
.legal in practice

What Enterprise Risk Management gives you

Risk areas and scales

Every area gets its own matrix, its own wording and its own appetite, so GDPR and NIS2 are each assessed on their own terms.

Risk areas and scales

Risk assessment

Assess the processes, assets and suppliers you already have in .legal against the scenarios that actually apply to them.

How assessment works

Mitigation plans

Accept, avoid or mitigate — and follow the plan from proposed through approved to completed, with an owner and a date.

Risk treatment

Risk exposure

Put a figure on what a risk would cost you, and on what it costs to bring it down. A calculation instead of a colour.

Financial exposure

Management report

One report across every area, measured against a single global appetite, with a breakdown by area and a trend over time.

The management report

Observations

A mobile-friendly link with no login, so anyone can report what they noticed before the moment passes.

Risk observations

Linked risks

See how processes, assets and suppliers connect, and trace where a flagged risk was actually inherited from.

Linked risks
A risk assessment of the VPN Gateway asset in .legal, showing a risk exposure of 150,000 EUR and two scenarios: hardware failure rated low, NIS2 non-compliance rated high

Risk attaches to what you already registered

You don't build a risk register. You already have one — the processing activities, the assets and systems, and the suppliers that live in .legal today. Enterprise Risk Management assesses those, against scenarios that fit the entity in front of you, and calculates the level from that area's own matrix.

  • Three entity types: Processes, assets and systems, and suppliers. You choose which of them each area covers.
  • Justification is not optional: Consequence and probability both require one, which is what makes the audit trail worth having.
  • Nothing gets overwritten: Every reassessment adds to the record, so you can still see how a risk was rated at the time it was rated.

Our Customers

+400

companies

+10.000

users

+79.000

contracts

+14.000

processing activities

Bech Bruun

Bech-Bruun

Mikkel Friis Rossa (Partner)

.legal's team has consistently demonstrated a commitment to innovation while being responsive to the needs of our mutual clients.

Rasmus-boutrup-fenerum

Fenerum

Rasmus Boutrup (Financial Controller)

Case Study
With .legal, we've gained a simpler and more manageable solution that better suits our needs
Michael Berner 1

Lægeforeningen

Michael Berner (Lawyer)

.legal has been the right choice for us. .legal are professional and welcoming with skilled employees.
Nanna Rodian Christensen

Molecule Consultancy

Nanna Rodian Christensen (HR & Operational Manager)

Case Study
Firstly, it means that not all the work is in one place (me), and secondly, that the understanding of GDPR is implemented throughout the organisation.
ulrikdueholmbeckmann

Plum Safety

Ulrik Dueholm Beckmann (QC, CM og ESG Lead)

Case Study
From .legal, we experience an incredibly high degree of flexibility and willingness to adapt features to our local needs.
Bech Bruun

Bech-Bruun

Mikkel Friis Rossa (Partner)

.legal's team has consistently demonstrated a commitment to innovation while being responsive to the needs of our mutual clients.

Rasmus-boutrup-fenerum

Fenerum

Rasmus Boutrup (Financial Controller)

Case Study
With .legal, we've gained a simpler and more manageable solution that better suits our needs
Michael Berner 1

Lægeforeningen

Michael Berner (Lawyer)

.legal has been the right choice for us. .legal are professional and welcoming with skilled employees.
Nanna Rodian Christensen

Molecule Consultancy

Nanna Rodian Christensen (HR & Operational Manager)

Case Study
Firstly, it means that not all the work is in one place (me), and secondly, that the understanding of GDPR is implemented throughout the organisation.
ulrikdueholmbeckmann

Plum Safety

Ulrik Dueholm Beckmann (QC, CM og ESG Lead)

Case Study
From .legal, we experience an incredibly high degree of flexibility and willingness to adapt features to our local needs.
julie-oxenvad-novicell

Novicell

Julie Oxenvad (Legal Consultant)

Case Study
We are satisfied with the switch to .legal – it has strengthened our compliance work, made processes easier to manage and more transparent, and improved cross-team collaboration
Tinna Schultz

Min By Media

Tinna Schultz (HR Manager)

Case Study
It just works! It is so easy and user-friendly, and the overview of processing activities is brilliant.
ansat_Kaspar_Rochholz_005

DMJX

Kaspar Rochholz (GDPR Coordinator)

Case Study
.legal has really understood what it means to create a user-friendly and efficient solution. Privacy is an attractive product compared to price and functionality.
Profile-picture1

Axel Kaufmann ApS

Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)

Case Study
.legal continuously update the platform to ensure their customers always remain compliant. In our view, any other choice would be a downgrade.

NRGi

Mette Mühlendorph (Compliance Specialist)

Case Study
The implementation of .legal has made a difference in the way we handle compliance. The system has created structure and overview, which has had concrete benefits.
julie-oxenvad-novicell

Novicell

Julie Oxenvad (Legal Consultant)

Case Study
We are satisfied with the switch to .legal – it has strengthened our compliance work, made processes easier to manage and more transparent, and improved cross-team collaboration
Tinna Schultz

Min By Media

Tinna Schultz (HR Manager)

Case Study
It just works! It is so easy and user-friendly, and the overview of processing activities is brilliant.
ansat_Kaspar_Rochholz_005

DMJX

Kaspar Rochholz (GDPR Coordinator)

Case Study
.legal has really understood what it means to create a user-friendly and efficient solution. Privacy is an attractive product compared to price and functionality.
Profile-picture1

Axel Kaufmann ApS

Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)

Case Study
.legal continuously update the platform to ensure their customers always remain compliant. In our view, any other choice would be a downgrade.

NRGi

Mette Mühlendorph (Compliance Specialist)

Case Study
The implementation of .legal has made a difference in the way we handle compliance. The system has created structure and overview, which has had concrete benefits.
The mitigation tab of a risk area in .legal, with plans counted by status from proposal through approved, planned and in progress to completed, above a list showing each plan's risk level before and after

Every coloured cell becomes somebody's task

Identifying a risk is the easy part. Enterprise Risk Management starts where it matters — the risks above the appetite you set yourselves — and makes you take a position: accept it, avoid it, or build a plan. Plans carry an owner, an approval and a date, and a completed plan updates the risk on its own.

  • Accepting is a decision, not an oversight: Recorded with its reasoning, so it holds up when someone asks later.
  • Approval happens in the platform: Not in a mail thread nobody can find, and the expected effect is stated before you approve.
  • One measure, many systems: Bulk mitigation applies the same plan across every entity it covers, worded the same way everywhere.
The full management report in .legal, with mitigation costs of EUR 57,000 across five plans, a breakdown of risks over appetite by NIS2 and the AI Act, and a twelve-month trend against the appetite limit

Different scales still add up to one report

If every area runs its own matrix, you can't average across them — and you don't need to. Being over appetite means the same thing everywhere, whatever the scale underneath, so the exceedances add up. Set one global appetite, and the management report reads the whole organisation against it.

  • Exceedances travel, scales don't: No normalising a three step scale against a six step one to make the numbers meet.
  • Money where you use it: Total exposure now, what it would be once the open plans are done, and what those plans cost.
  • A trend, not a snapshot: A breakdown by area shows where the pressure comes from; the trend shows whether it's improving.
Top swirl

Enterprise Risk Management

Our pricing is simple and transparent. You pay a fixed monthly subscription for the add-on, with unlimited usage and unlimited users.

Card bg

Enterprise Risk Management

EUR 1,000

per month

  • Unlimited risk areas, each with its own scale, matrix and appetite
  • Risk assessment of processes, assets and systems, and suppliers
  • Mitigation plans with owner, approval and deadline
  • Financial risk exposure and mitigation cost
  • Management report across every risk area
  • Risk observations reported without a login
  • Unlimited users
All prices are exclusive of VAT and any taxes. Monthly payments, no commitment.
Top swirl
Intro

How Enterprise Risk Management works

A short look at risk areas, scales and appetite — the piece everything else builds on.

The .legal customer success team, ready to help with onboarding and support

Getting You Started Customer Support

You can always get help from a team member who’s ready to support you and your colleagues.
  • You get a dedicated Customer Success Manager.
  • Personal onboarding to ensure a smooth start.
  • Support available Monday to Friday, 9 AM to 3 PM.
A risk area in .legal showing the risk picture as it would be once every open mitigation plan is completed

.legal compliance platform Begin with Enterprise Risk Management today

Curious to see it on your own risk work? Book a conversation and we'll walk through your risk areas, your scales and where the add-on would fit.
  • Works alongside your existing frameworks
  • Free onboarding included
  • No commitment

Frequently Asked Questions about Enterprise Risk Management

What is Enterprise Risk Management in .legal?

An add-on that turns risk work into part of the platform rather than a parallel exercise. You define a risk area per compliance or security domain, each with its own scale and appetite, assess the processes, assets and suppliers already registered in .legal, decide what to do about what sits above appetite, and report across every area against one global appetite.

Start with risk areas and scales

Is it included in the platform or does it cost extra?

It's an add-on at a fixed monthly price, on top of your .legal platform. There's no per-user or per-entity charge, and no commitment.

See all our prices

Which frameworks can I use it for?

Any of them. A risk area is whatever domain you want to assess within — GDPR, NIS2, ISO 27001, the AI Act, DORA, information security — or one you define yourself. Because each area carries its own scale and wording, you aren't forcing a framework into someone else's model.

Read more about Frameworks

Do we have to start over on the risk work we've already done?

No. The entities you assess are the ones already in the platform, and there is a catalogue of common risk scenarios and consequences to import from and adjust. Existing assessments keep their history when you change a scale or a matrix later.

How the platform fits together

Can we start with one risk area and grow from there?

That's how most organisations do it. One or two areas to begin with, then more as the compliance scope grows. The scale you start on is not the scale you're stuck with.

Risk management software at .legal

Who in the organisation actually uses it?

Whoever owns each risk area does the assessing and the deciding, management reads the report, and everyone else only ever meets the observation link — which needs no account at all.

How observations work

Still unsure?

Ask Johannes directly, he runs most demos personally

Book him here
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell