Risk areas and scales
Every area gets its own matrix, its own wording and its own appetite, so GDPR and NIS2 are each assessed on their own terms.
Risk areas and scalesADD-ON
GDPR, NIS2, ISO 27001, the AI Act — each one asks you to assess risk, and each one asks in its own language. Enterprise Risk Management gives every area its own scale, its own wording and its own appetite, assesses the processes, assets and suppliers you already have in .legal, and adds the exceedances up into one report management can act on.
+
Most organisations don't have a risk problem. They have four risk problems, in four different files, on four different scales. The GDPR assessment was built when GDPR landed. NIS2 got its own sheet because three steps weren't enough. Information security has a fifth. And when management asks how the organisation is doing on risk, somebody spends a week building an answer by hand.
Every area gets its own matrix, its own wording and its own appetite, so GDPR and NIS2 are each assessed on their own terms.
Risk areas and scalesAssess the processes, assets and suppliers you already have in .legal against the scenarios that actually apply to them.
How assessment worksAccept, avoid or mitigate — and follow the plan from proposed through approved to completed, with an owner and a date.
Risk treatmentPut a figure on what a risk would cost you, and on what it costs to bring it down. A calculation instead of a colour.
Financial exposureOne report across every area, measured against a single global appetite, with a breakdown by area and a trend over time.
The management reportA mobile-friendly link with no login, so anyone can report what they noticed before the moment passes.
Risk observationsSee how processes, assets and suppliers connect, and trace where a flagged risk was actually inherited from.
Linked risks
You don't build a risk register. You already have one — the processing activities, the assets and systems, and the suppliers that live in .legal today. Enterprise Risk Management assesses those, against scenarios that fit the entity in front of you, and calculates the level from that area's own matrix.
companies
users
contracts
processing activities
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Identifying a risk is the easy part. Enterprise Risk Management starts where it matters — the risks above the appetite you set yourselves — and makes you take a position: accept it, avoid it, or build a plan. Plans carry an owner, an approval and a date, and a completed plan updates the risk on its own.
If every area runs its own matrix, you can't average across them — and you don't need to. Being over appetite means the same thing everywhere, whatever the scale underneath, so the exceedances add up. Set one global appetite, and the management report reads the whole organisation against it.
Our pricing is simple and transparent. You pay a fixed monthly subscription for the add-on, with unlimited usage and unlimited users.
EUR 1,000
per month
Getting You Started Customer Support
An add-on that turns risk work into part of the platform rather than a parallel exercise. You define a risk area per compliance or security domain, each with its own scale and appetite, assess the processes, assets and suppliers already registered in .legal, decide what to do about what sits above appetite, and report across every area against one global appetite.
Start with risk areas and scalesIt's an add-on at a fixed monthly price, on top of your .legal platform. There's no per-user or per-entity charge, and no commitment.
See all our pricesAny of them. A risk area is whatever domain you want to assess within — GDPR, NIS2, ISO 27001, the AI Act, DORA, information security — or one you define yourself. Because each area carries its own scale and wording, you aren't forcing a framework into someone else's model.
Read more about FrameworksNo. The entities you assess are the ones already in the platform, and there is a catalogue of common risk scenarios and consequences to import from and adjust. Existing assessments keep their history when you change a scale or a matrix later.
How the platform fits togetherThat's how most organisations do it. One or two areas to begin with, then more as the compliance scope grows. The scale you start on is not the scale you're stuck with.
Risk management software at .legalWhoever owns each risk area does the assessing and the deciding, management reads the report, and everyone else only ever meets the observation link — which needs no account at all.
How observations work
Info
.legal A/S
hello@dotlegal.com
+45 7027 0127
VAT-no: DK40888888
Support
support@dotlegal.com
+45 7027 0127
Need help?
Let me help you get started
.legal is not a law firm and is therefore not under the supervision of the Bar Council.