ADD-ON · ENTERPRISE RISK MANAGEMENT
Risk that speaks your language.
Ask three departments what a high risk looks like and you'll get three answers. With Enterprise Risk Management, every risk area gets its own matrix, its own wording and its own appetite, so the assessment fits the domain instead of forcing the domain to fit the assessment.
+
One scale never fits every risk area
Most organisations start with low, medium and high in a spreadsheet, built back when GDPR landed. Then NIS2 arrives and three steps are suddenly too blunt to say anything useful. The problem isn't the spreadsheet. It's that everyone has to share one vocabulary.
-
Different domains, different language: IT thinks downtime and attack surface. Legal thinks data subjects and fines. Both are right, and neither should have to translate.
-
Maturity grows: The scale you started with is rarely the scale you need three years later. Your setup has to be able to grow with you.
-
Appetite isn't universal: You may accept more on information security than you ever would on personal data. That belongs in the system, not in a footnote.
Set up as many risk areas as you need
A risk area defines one compliance or security domain you want to assess and manage risk within. GDPR, NIS2, the AI Act, information security, or something you define yourself.
-
Built around your structure: Create the areas that match how your organisation is actually organised, not a fixed list you have to work around.
-
Each area stands on its own: Its own matrix, its own scenarios, its own appetite. Nothing bleeds between areas unless you want it to.
-
Named and recognisable: Give each area a name and an icon, so people know where they are the moment they open it.
Decide the scale, the wording and the icons
The scale is a deliberate choice, not something you inherit. Pick the number of levels the area needs and name them in the language people there actually use.
-
From simple to detailed: Run a three step scale where three steps is enough, and a six step scale where you need the nuance.
-
Your words, not ours: "Low, medium, high" in one area can be "negligible, limited, significant, critical" in another.
-
Icons per level: Make the levels readable at a glance, for people who don't work with risk every day.
Edit the matrix to match your risk model
The matrix maps every combination of consequence and probability to a risk level. It arrives pre-filled with recommended defaults, and every cell can be changed.
-
Click any cell: Adjust a single combination without rebuilding the whole model.
-
Handle regulatory requirements: Where GDPR or NIS2 mean certain combinations must always come out high, set that once and it holds.
-
Weight it your way: Some industries treat consequence as far more important than probability. The matrix can say so.
Set appetite per area, and one across the organisation
Risk appetite is the highest risk level an area accepts before anything above it gets flagged.
-
Per area: Different domains carry different tolerance. Set the line where it belongs in each one.
-
Globally: Define how many risks in total, across every area, may sit above appetite before management needs to act.
-
Visible, not implied: Everything above the line is flagged automatically, so nobody has to remember what the threshold was.
Getting You Started Customer Support
-
You get a dedicated Customer Success Manager.
-
Personal onboarding to ensure a smooth start.
-
Support available Monday to Friday, 9 AM to 3 PM.
Frequently Asked Questions about Risk Areas
How many risk areas can I create?
As many as you need. Most organisations start with one or two and add areas as their compliance scope grows.
Can two risk areas use different scales?
Yes. Each area has its own matrix, its own number of levels and its own naming. A four in one area has nothing to do with a four in another.
How reporting works across different scales
What does risk appetite mean in .legal?
It's the highest risk level an area accepts. Anything scoring above it is flagged as over appetite, so it shows up in overviews and reports without anyone having to look for it.
What happens to risks above appetite
Can I change the matrix after I've started assessing?
Yes. Existing assessments keep their history, so you can see how a risk was assessed at the time it was assessed.
How risk assessment works
Do I have to build all my risk scenarios myself?
No. There's a catalogue of common scenarios and consequences you can import from and adjust. Building your own from scratch is also an option.
Read more about Frameworks
Is Enterprise Risk Management included in the platform?
It's an add-on to the .legal platform. Talk to sales and we'll look at what makes sense for your setup.
See all our prices
Info
.legal A/S
hello@dotlegal.com
+45 7027 0127
VAT-no: DK40888888
Support
support@dotlegal.com
+45 7027 0127
Need help?
Let me help you get started
+45 7027 0127 and I'll get you started
.legal is not a law firm and is therefore not under the supervision of the Bar Council.