Performing a Risk Assessment
A risk assessment lets you evaluate the real-world impact and likelihood of a specific risk scenario — and define what should be done to reduce it.
Risk assessments in dotLegal let you evaluate threats against a processing activity or a system/asset by rating likelihood and impact across predefined risk scenarios, then export results or create mitigation tasks directly from the assessment.
You can perform assessments for:
- A processing activity (e.g. payroll handling)
- A system/asset (e.g. Microsoft 365)
How to perform an assessment
Before you begin, make sure your risk template is set up.
- Select the Scope (asset or activity) and the Compliance domain (GDPR, NIS2, etc.).
- Open the Risk Assessment for the relevant processing activity or an asset.

- The risk scenarios will appear.

- For each scenario, complete the following fields:
- Rate likelihood and describe possible consequences.
- Rate impact and describe security measures.
- Describe existing controls.
- Suggest planned actions.
- Provide an overall justification.

Examples
- Scenario: Loss of availability
- Likelihood: Low
- Impact: High
- Controls: Redundant backup and 24/7 monitoring
- Final score: Moderate
After assessment
- Export to PDF or Excel
- Create mitigation tasks directly from scenarios
- Reassess later using version control