ADD-ON · ENTERPRISE RISK MANAGEMENT
Catch it when it happens.
Risk rarely turns up during the hour you set aside for risk work. Observations give anyone a mobile-friendly way to report what they've noticed, through a link that doesn't ask them to log in. It lands in an inbox, and you decide what deserves to become a risk scenario.
+
Most risks are noticed by someone who won't report them
Something gets mentioned in a meeting. A colleague walks past a room that shouldn't have been left unlocked. An advisory lands in someone's inbox. Then nothing happens, because there are three clicks and a login sitting between noticing something and recording it.
-
The reporter isn't a risk person: They don't have an account, and they shouldn't need one.
-
The moment passes: If it can't be reported in thirty seconds on a phone, it usually isn't reported at all.
-
Volume needs triage: Capturing more only helps if there's a sensible way to sort through what comes in.
Report from anywhere, no login required
Observations are shared through a public link.
-
No account needed: Anyone in the organisation can flag a concern without being a user in .legal.
-
Built for a phone: Short form, quick to submit, designed for the moment somebody notices something.
-
One link to share: Put it wherever people already are, on the intranet, in an onboarding pack, on a wall.
Everything lands in one inbox
Reported observations arrive in a single place to be reviewed.
-
One queue: Whatever the source, it ends up somewhere with an owner rather than in a mailbox.
-
Reviewed, not auto-filed: A person decides what each observation actually is before anything happens to it.
-
A visible backlog: You can see what's waiting, which is the fastest way to keep it from piling up.
Convert an observation into a risk scenario
When something is worth acting on, it moves into the risk work properly.
-
One step across: Turn the observation into a risk scenario without retyping it somewhere else.
-
The responsible person is notified: Whoever owns the area finds out automatically.
-
Assessed like anything else: From there it follows the same route as every other scenario, with consequence, probability and justification.
Not everything needs to become a risk
Closing something is a perfectly good outcome.
-
Triage is the job: Reviewing an observation and deciding it isn't relevant is a decision, and it's recorded as one.
-
Keeps the register honest: A risk register that absorbs everything reported to it quickly stops being useful.
-
Encourages reporting: People keep reporting when they can see it's being read, not when everything turns into a task.
Getting You Started Customer Support
-
You get a dedicated Customer Success Manager.
-
Personal onboarding to ensure a smooth start.
-
Support available Monday to Friday, 9 AM to 3 PM.
Frequently Asked Questions about Observations
Do people need a .legal account to report an observation?
No. Observations come in through a public link that doesn't require logging in.
Can observations be reported from a phone?
Yes. The form is mobile-friendly and deliberately short.
Where do reported observations go?
Into an inbox, where they can be reviewed and either converted into a risk scenario or closed.
Does the platform subscribe to external sources like ENISA?
Not at the moment. If someone reads an advisory and thinks it's relevant, they can file it as an observation through the same link.
What threat intelligence is
Who finds out when an observation becomes a risk scenario?
The responsible person for the relevant area is notified automatically.
How risk areas and owners are set up
What if an observation isn't relevant?
You close it. Not everything reported needs to end up in the risk register, and deciding that is part of the process.
Info
.legal A/S
hello@dotlegal.com
+45 7027 0127
VAT-no: DK40888888
Support
support@dotlegal.com
+45 7027 0127
Need help?
Let me help you get started
+45 7027 0127 and I'll get you started
.legal is not a law firm and is therefore not under the supervision of the Bar Council.