Skip to content
  • There are no suggestions because the search field is empty.

Performing a Risk Assessment

A risk assessment lets you evaluate the real-world impact and likelihood of a specific risk scenario — and define what should be done to reduce it.

Risk assessments in dotLegal let you evaluate threats against a processing activity or a system/asset by rating likelihood and impact across predefined risk scenarios, then export results or create mitigation tasks directly from the assessment.

You can perform assessments for:

  • A processing activity (e.g. payroll handling)
  • A system/asset (e.g. Microsoft 365)

How to perform an assessment

Before you begin, make sure your risk template is set up.

  1. Select the Scope (asset or activity) and the Compliance domain (GDPR, NIS2, etc.).
  2. Open the Risk Assessment for the relevant processing activity or an asset.
    open-risk-assessment
  3. The risk scenarios will appear.
    risk-assessment
  4. For each scenario, complete the following fields:
    • Rate likelihood and describe possible consequences.
    • Rate impact and describe security measures.
    • Describe existing controls.
    • Suggest planned actions.
    • Provide an overall justification.
      risk-scenaruio

Examples

  • Scenario: Loss of availability
  • Likelihood: Low
  • Impact: High
  • Controls: Redundant backup and 24/7 monitoring
  • Final score: Moderate

After assessment

  • Export to PDF or Excel
  • Create mitigation tasks directly from scenarios
  • Reassess later using version control

Related articles