ADD-ON · ENTERPRISE RISK MANAGEMENT

Risk that speaks your language.

Ask three departments what a high risk looks like and you'll get three answers. With Enterprise Risk Management, every risk area gets its own matrix, its own wording and its own appetite, so the assessment fits the domain instead of forcing the domain to fit the assessment.

Trusted by 400+ organisations
Watch a demo of risk areas and scales👇
GDPR-compliant
Hosted in EU
Free onboarding
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell
The Create risk area dialog in .legal, with the scale set to 1-5 and the dropdown open on 1-3, 1-4 and 1-6, the consequence, probability and risk level names beside it, and a matrix preview on the right

One scale never fits every risk area

Most organisations start with low, medium and high in a spreadsheet, built back when GDPR landed. Then NIS2 arrives and three steps are suddenly too blunt to say anything useful. The problem isn't the spreadsheet. It's that everyone has to share one vocabulary.

  • Different domains, different language: IT thinks downtime and attack surface. Legal thinks data subjects and fines. Both are right, and neither should have to translate.
  • Maturity grows: The scale you started with is rarely the scale you need three years later. Your setup has to be able to grow with you.
  • Appetite isn't universal: You may accept more on information security than you ever would on personal data. That belongs in the system, not in a footnote.
Intro

Why one matrix isn't enough

A short look at how risk areas, scales and appetite fit together.

The Create risk area dialog in .legal offering GDPR, NIS2, AI Act, information security or a custom area, over the list of areas already created

Set up as many risk areas as you need

A risk area defines one compliance or security domain you want to assess and manage risk within. GDPR, NIS2, the AI Act, information security, or something you define yourself.

  • Built around your structure: Create the areas that match how your organisation is actually organised, not a fixed list you have to work around.
  • Each area stands on its own: Its own matrix, its own scenarios, its own appetite. Nothing bleeds between areas unless you want it to.
  • Named and recognisable: Give each area a name and an icon, so people know where they are the moment they open it.
Naming the levels of a risk scale in .legal, with consequence, probability and risk levels each in their own field and the icon picker open on a risk level

Decide the scale, the wording and the icons

The scale is a deliberate choice, not something you inherit. Pick the number of levels the area needs and name them in the language people there actually use.

  • From simple to detailed: Run a three step scale where three steps is enough, and a six step scale where you need the nuance.
  • Your words, not ours: "Low, medium, high" in one area can be "negligible, limited, significant, critical" in another.
  • Icons per level: Make the levels readable at a glance, for people who don't work with risk every day.
A risk area in .legal with its scale set to 1-5 and its appetite to 3, and one cell of the risk criteria matrix selected for editing

Edit the matrix to match your risk model

The matrix maps every combination of consequence and probability to a risk level. It arrives pre-filled with recommended defaults, and every cell can be changed.

  • Click any cell: Adjust a single combination without rebuilding the whole model.
  • Handle regulatory requirements: Where GDPR or NIS2 mean certain combinations must always come out high, set that once and it holds.
  • Weight it your way: Some industries treat consequence as far more important than probability. The matrix can say so.
The Global risk settings dialog in .legal: a global appetite of four risks above appetite, currently exceeded at six, and risk exposure measured as a financial amount in euro

Set appetite per area, and one across the organisation

Risk appetite is the highest risk level an area accepts before anything above it gets flagged.

  • Per area: Different domains carry different tolerance. Set the line where it belongs in each one.
  • Globally: Define how many risks in total, across every area, may sit above appetite before management needs to act.
  • Visible, not implied: Everything above the line is flagged automatically, so nobody has to remember what the threshold was.
The .legal customer success team, ready to help with onboarding and support

Getting You Started Customer Support

You can always get help from a team member who’s ready to support you and your colleagues.
  • You get a dedicated Customer Success Manager.
  • Personal onboarding to ensure a smooth start.
  • Support available Monday to Friday, 9 AM to 3 PM.
A risk area in .legal showing the risk picture as it would be once every open mitigation plan is completed

.legal compliance platform Begin with Enterprise Risk Management today

Curious to see it on your own risk work? Book a conversation and we'll walk through your risk areas, your scales and where the add-on would fit.
  • Works alongside your existing frameworks
  • Free onboarding included
  • No commitment

Frequently Asked Questions about Risk Areas

How many risk areas can I create?

As many as you need. Most organisations start with one or two and add areas as their compliance scope grows.

Can two risk areas use different scales?

Yes. Each area has its own matrix, its own number of levels and its own naming. A four in one area has nothing to do with a four in another.

How reporting works across different scales

What does risk appetite mean in .legal?

It's the highest risk level an area accepts. Anything scoring above it is flagged as over appetite, so it shows up in overviews and reports without anyone having to look for it.

What happens to risks above appetite

Can I change the matrix after I've started assessing?

Yes. Existing assessments keep their history, so you can see how a risk was assessed at the time it was assessed.

How risk assessment works

Do I have to build all my risk scenarios myself?

No. There's a catalogue of common scenarios and consequences you can import from and adjust. Building your own from scratch is also an option.

Read more about Frameworks

Is Enterprise Risk Management included in the platform?

It's an add-on to the .legal platform. Talk to sales and we'll look at what makes sense for your setup.

See all our prices

Still unsure?

Ask Johannes directly, he runs most demos personally

Book him here
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell