Vendor register, or synced in
Create a vendor with its basic details, or sync vendors from another system, then work them all in one place.
Classify each vendor on your own criteria, ask for the answers and documents you need, and keep it all on one record. Do the check before you sign, and prove you did.
Unlimited users • Free onboarding and support • No commitment
Peter Lund is legal counsel at Meridian Nordic. With around 1,200 active suppliers and processors, onboarding a new cloud vendor used to mean a scatter of emails, a risk assessment in a spreadsheet, and a data processing agreement that someone had to chase for weeks. Now Peter classifies the vendor on Meridian's own criteria, sends one questionnaire that asks for both answers and documents, and the vendor uploads everything through a link. When it's approved, the contract moves straight into Contract Management with its renewal date and obligations in view.
Classify on your terms
Score a vendor's risk from parameters you define, not a black box.
Ask once, gather everything
One questionnaire pulls answers and documents straight onto the vendor.
No login for vendors
The vendor responds from their own inbox, with nothing to install.
From check to contract
Approved vendors flow into a contract with obligations and renewals tracked.
Everything hangs off the vendor record, so that's where you begin. Create it with the basic details, or sync your vendors in from another system and work them in .legal.
Not every vendor needs the same scrutiny. You set up an internal assessment with the parameters that matter to you, and answering a few questions gives the vendor a risk classification.
Once you know the risk, you ask for what you need. You design the questionnaire, both the questions and the documents, and send it to the vendor as an audit.
The vendor is an outside party, so we don't make them join your platform. You register a contact, and they get a link in their own inbox.
A new vendor and one you've worked with for years need slightly different questions, but it's the same engine underneath. So you set it up once and reuse it.
Saying yes is the start, not the end. Once a vendor is approved, the contract goes into Contract Management and you manage it for as long as it runs.
We give you the technical part, distributing a questionnaire and pulling documentation back from an outside party. We don't hand you a plug-and-play template set, because the right design depends on how you're organised.
Create a vendor with its basic details, or sync vendors from another system, then work them all in one place.
Define the parameters that matter, like whether they handle personal data or how large the deal is, weight them, and get a risk score from your answers.
Design the questions yourself and send them to the vendor as an audit, from IT security measures to a code of conduct.
Ask for the DPA or other documentation, the vendor uploads it through a link, and it lands on the right vendor record.
Set a periodic re-check on a vendor and get a reminder in the system when it's time to send the updated questionnaire.
Move an approved vendor into Contract Management, where AI helps upload the contract, fill the metadata, and scan it against your best practice.
One due diligence process, several regimes that expect it.
NIS2
Show that you assess and monitor the vendors in your value chain, part of the supply-chain security an essential entity must run.
GDPR
Do due diligence on a processor and collect the data processing agreement before any data flows, in line with Article 28.
ISO 27001
Evidence that you evaluate and monitor supplier security, the supplier-relationship controls in Annex A.
DORA
For financial entities, keep due diligence and contracts on ICT third-party providers in order across the value chain.
Assess vendors and run due diligence and internal audits with the audit engine.
Explore Vendor ManagementKeep contracts, obligations and renewals in one overview once a vendor is approved.
Explore Contract Managementcompanies
users
contracts
processing activities
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
The whole process before and during a vendor relationship. You register the vendor, classify its risk, send a questionnaire, collect the documentation you need, and keep it all on one record so you can show you did the check.
No. Nothing is scored automatically. You set up the parameters and how critical each one is, answer a few questions on the vendor, and the risk score comes from your own inputs.
No. You register a contact on the vendor, and they get a link in their own inbox. They can gather the answers with colleagues outside the platform, and everything they submit lands back on the vendor.
Yes. You can build different classifications and questionnaires per vendor type. A data processor might get more than one, say the general vendor check plus a separate data processor audit.
Some, for example a data processor audit. Beyond that we give you the rails to distribute and collect, not a plug-and-play set. We recommend you design your own classification and questionnaire, because the right ones depend on your organisation.
You upload the contract to Contract Management with its metadata, keep obligations and renewals in view, and keep running audits with the vendor across the life of the contract. AI can help upload and tag the contract and scan it against your best practice.
Use the same engine with a version of the questionnaire aimed at existing relationships, and set a periodic review in your annual wheel. The system reminds you when a vendor is due for a fresh check.
Yes, with the Group Companies add-on. The same vendor can be shared across the group and used differently by each company, so you assess once and still reflect how each entity uses it.
The supply-chain expectations in NIS2, processor due diligence under GDPR Article 28, supplier controls in ISO 27001, and ICT third-party risk under DORA for financial entities.
Info
.legal A/S
hello@dotlegal.com
+45 7027 0127
VAT-no: DK40888888
Support
support@dotlegal.com
+45 7027 0127
Need help?
Let me help you get started
.legal is not a law firm and is therefore not under the supervision of the Bar Council.