How to add a risk on Mac
You can do this with RiskOS, a risk register for macOS. One line about what could go wrong, two ratings, and a reference number that stays yours for good.
A register earns its keep one row at a time. A risk that has been written down can be owned, rated, challenged and reviewed; a risk that lives in somebody's head is not a risk at all, it is a surprise with a date on it that nobody has seen yet. Adding one properly takes two or three minutes, and most of that goes on the sentence at the top.
A risk is useful as soon as it has a title, a category, an owner and the two inherent ratings. Everything else can wait for its first review.
Where the register lives
The sidebar groups the app by the job in front of you. Under Register sit Risks, Controls, Actions and Review. Choose Risks and the middle of the window fills with the register itself: a sortable table of Ref, Risk, Owner, Inherent, Residual, Target, Trend, Appetite, Status and Review.
The panel on the right shows whatever is selected. It is where a risk is written, rated, treated and reviewed, and it is organised in sections — Summary, Assessment, Treatment, Appetite, Controls, Actions, Context, Intelligence and History. Both the sidebar and the panel resize, and RiskOS remembers where you leave them.
Add a risk, step by step
-
Open the Risks section
Choose Risks in the sidebar. The table in the middle of the window is your register. If this is the first risk you have written, the table is empty — the only time it will be.
-
Create the risk
Press ⌘N. A new row appears pinned to the top of the table with the next reference in the sequence, and the panel opens on it ready to type into. The same key makes the right kind of item wherever you are, so it adds a control in Controls and an action in Actions.
-
Name the event, not the topic
Type the title straight into the panel header. Name what could happen: Backup restoration has never been tested end to end tells a reader what they are being asked to rate, where Backups only names a subject. A vague title is the most common reason two people score the same risk differently.
-
Describe what would actually happen
Use the description under the title for the cause, the event and the consequence, and say who would feel it and for how long. It carries your reasoning to whoever reads the risk in a year, and search looks inside it, so the words here are how the risk will be found again.
-
File it in the Summary section
Open Summary and set the category — the seeded list covers the usual ground and you can add your own — then the subcategory, the owner and the business unit. The owner is a person, not a department: a risk with a name against it gets looked at, and a risk owned by "IT" does not.
-
Set a review cadence
Still in Summary, choose how often the risk should come back to you and set its next review date. RiskOS schedules the following review from that cadence each time the risk is confirmed or re-scored, and anything that falls behind is counted for you when you choose a scope in Review.
-
Rate the inherent exposure
Open Assessment and set inherent likelihood and impact on the two segmented steppers, each a row of five with its scale label beside it. This is the risk with nothing standing in its way. The score appears at once — likelihood multiplied by impact, 1 to 25 — with its band named beside it and a marker moving to the matching cell of the matrix.
-
Link the controls you already rely on
Open Controls and link what is already in place, or create a control from the same picker. With derive effectiveness from linked controls switched on, the residual score follows your strongest operating control, and a second marker appears on the matrix. Only controls that are implemented or operating reduce anything; a planned control changes nothing yet, and the panel says so.
-
Choose a treatment and give it a date
Open Treatment, pick Mitigate, Accept, Transfer or Avoid, write the plan in a sentence or two and set a due date. Add the first action inline in Actions so the work has an owner and a deadline rather than an intention. Everything saves as you type, and ⌘Z undoes anything you did not mean.
What the register does with a new risk
Several things happen the moment a risk exists, and none of them need doing by hand.
The risk is given a reference in the form RSK-0001, counting up from wherever your register has reached, and references are never reissued. The new row pins to the top of the table, so you never have to hunt for the thing you created a moment ago.
As soon as it has ratings it gains a band badge — Low, Medium, High or Critical — shown as a colour, a symbol and the written word together, so it reads the same to someone who cannot separate the colours. If its residual score sits above your appetite it is flagged wherever it appears: in the table, in the panel header and in every report that carries it. Its trend starts recording from the first assessment, and History keeps every score you give it alongside the reason.
The fields on a new risk, and what each one is for
Not every field needs filling on the first pass. The rest can be added when the risk comes round for review, which is what the review pass is for.
| Field | Where it sits | What it earns you |
|---|---|---|
| Reference | Panel header | Set by RiskOS, never reissued. The stable name of the risk in every report. |
| Title | Panel header | The one line everyone rates against. Name the event. |
| Description | Panel header | Cause, event, consequence, and the reasoning behind the rating. Searchable. |
| Status | Summary | Where the risk sits in its life, and whether it appears in the default view. |
| Category & subcategory | Summary | Groups the register for search and filters, and lets a category carry its own appetite. |
| Owner | Summary | A name to answer for it, and one filter that shows everything they hold. |
| Business unit | Summary | Splits a shared register by the part of the organisation carrying the risk. |
| Review cadence | Summary | Schedules the next review date automatically after every review. |
| Inherent likelihood & impact | Assessment | The only two numbers you type. Everything else follows from them. |
| Onset velocity & detectability | Assessment | How fast it arrives and whether you would notice. Neither changes the score. |
| Exposure amount | Assessment | Optional. A figure to put beside the rating when money makes the case. |
| Target likelihood & impact | Assessment | Where you intend to get to, and the gap the plan has to close. |
| Treatment strategy & plan | Treatment | Mitigate, Accept, Transfer or Avoid, with a plan and a due date. |
What to leave empty on the first pass
Target ratings, exposure amounts and detectability are worth real thought, and thought is the enemy of getting twelve risks written down in an afternoon. Capture the register in broad strokes, then use Review to walk back through it properly. Twenty honest half-finished risks are worth more than four immaculate ones and a blank page.
Writing a risk people can rate
The title is the part of a risk that travels. It goes into the board pack, the report and the conversation in the corridor, and it is the only part most people will ever read. A good one names a specific event with a visible consequence, and can be rated by somebody who was not in the room when it was written.
| Too vague to rate | Specific enough to rate |
|---|---|
| Cyber security | Ransomware encrypts primary file shares |
| Suppliers | Supplier concentration in a single logistics partner |
| Compliance | Regulatory reporting deadline missed |
| Cloud | Single cloud region outage halts customer portal |
| Staffing | Key person dependency in platform engineering |
| AI | Unreviewed AI model output reaches customers |
One risk per row
If a title contains "and", check whether you have two risks. Backups are untested and the offsite copy may be writable has two halves with different likelihoods, different impacts and different controls, so it cannot be rated honestly as one row. Split it.
Faster ways to add risks
Typing each risk from nothing is only one route, and rarely the quickest when a register is being built from scratch.
Start from the risk library
Open Risk Library for thirty-nine worked example risks across cybersecurity, cloud, third-party and vendor, business continuity, project delivery, compliance & regulatory, and artificial intelligence. Each carries a suggested starting rating, a typical treatment and controls to consider. Browse or search, filter by category, and hide the ones you have already taken. Entries arrive as drafts, and the detail view confirms the reference they were given — the suggested ratings are a prompt for your own assessment, never an authority.
Duplicate a risk you have already written
When several risks share a shape — the same category, owner, cadence and control set, differing only in which system they apply to — select one in the table, choose Duplicate, and edit the copy. The duplicate is given its own reference.
Bring a list in from CSV
If your risks already exist as a list, Import & Export takes them from CSV, with a preview that shows line by line what will be created, what will update an existing entry, what will be skipped, the score each row would produce and any columns it has ignored. Nothing is written until you confirm. Scores are never read from the file: RiskOS recalculates every one of them from the ratings, so an import cannot smuggle in a number that does not add up.
Fill in the common fields together
After a bulk capture, select several risks at once and the panel becomes a bulk editor. Tick only the fields you want to change — category, owner, business unit, status, treatment strategy, review cadence — set their values and apply them to everything selected. Fields left unticked keep whatever they already had.
Troubleshooting
My new risk is not in the table
A filter is hiding it. Check the search field first, then the filter control — its icon fills when any filter is on. A band filter, an over-appetite-only filter or a saved view that excludes new work will each leave a perfectly real risk out of sight. Clear the filter and the row reappears at the top.
The category I need is not in the list
The category list is seeded with the common ones and takes your own alongside them. Add yours in the risk's Summary section and it is available to every risk from then on. Keep the list short: a category is what a per-category appetite attaches to and what you will filter by later, so twenty of them help nobody.
The reference numbers have a gap in them
That is intended. References are issued once and never reissued, so a number belongs permanently to the risk that was given it. A gap means a reference was allocated and the risk is no longer in your current view, not that anything has been lost.
The residual score is the same as the inherent one
Nothing is reducing it yet. Either no control is linked, or the linked controls are still planned rather than implemented or operating. Open Controls in the risk's panel, link what you actually rely on, and the residual drops as soon as a control is operating.
I added a risk I did not mean to
Press ⌘Z straight away and it is undone; ⇧⌘Z brings it back. If it has been there a while and has history against it, close it rather than trying to remove it. Risks are closed, never deleted, so the record of what you were worried about and when stays intact.
Habits that keep a register worth reading
The difference between a register people use and one they tolerate is a handful of habits at the point of capture.
- Write it the day you hear it. The minutes after a near miss, an audit finding or a supplier's apology are when the detail is sharpest.
- Give every risk a person. An owner is the single field that decides whether anything happens next, and one filter then shows everything that person is carrying.
- Rate inherent, always. The steppers are the exposure before controls. Record the controls separately and let the residual be calculated, so the register can always show its working.
- Put the reason in the description. The near miss last spring, the regulator's letter, the supplier's own disclosure. A score without a reason is an opinion with a number attached.
- Set the cadence at creation. A review date chosen now is the only thing that brings the risk back to you later without somebody having to remember it.
- Add one action while you are there. Even a small first step turns a written risk into work with a date, and it appears alongside everything else in Actions.
- Back up once the register matters. File ▸ Back Up RiskOS… writes everything RiskOS holds to a single file you keep wherever you choose.
Frequently asked questions
How do I add a new risk to a risk register on a Mac?
Choose Risks in the sidebar and press ⌘N. A new row is created at the top of the table with the next reference, and the panel opens ready to edit. Give it a title that names the event, add a description, set the category and owner in Summary, then rate inherent likelihood and impact in Assessment. Everything saves as you type.
What information do I need before I can add a risk?
Less than you might think. A one-line title naming the event, a category, an owner and the two inherent ratings are enough for a risk to be sortable, reportable and reviewable. Target ratings, exposure amounts, controls and a treatment plan can all be added later, and the review pass is designed for exactly that kind of filling in.
How does RiskOS number risks?
Each risk is given a reference in the form RSK-0001, counting up as you add them. References are issued once and never reissued, so a number always points at the same risk, including after it has been closed. That is what makes a reference safe to quote in a report, an audit response or a board paper years later.
Can I add several risks at once?
Yes. Take worked examples from the risk library, duplicate a risk that shares a shape with the one you need, or import a list from CSV with a preview showing what will be created, updated or skipped before anything is written. Afterwards, select several rows and use the bulk editor to set category, owner, business unit or cadence across all of them together.
What makes a good risk statement?
A specific event with a visible consequence, rateable by somebody who was not in the room when it was written. "Ransomware encrypts primary file shares" can be rated; "Cyber security" cannot. Keep one risk per row — a title containing "and" is usually two risks — and put the cause and the consequence in the description rather than trying to compress them into the title.
Do I have to fill in the score myself?
You set inherent likelihood and impact on two five-point steppers. RiskOS multiplies them, names the band and places the marker on the matrix. The residual score is calculated from the effectiveness of the controls you link, and the target is whatever you state as your intention. Only the two inherent ratings are typed in by you.
How do I delete a risk I added by mistake?
If it was the last thing you did, press ⌘Z to undo. Otherwise, close the risk rather than removing it. Risks in RiskOS are closed rather than deleted, which keeps the reference, the assessments and the reasons behind them intact. The register's filter can show closed risks again whenever you need to look back at one.
Where is the risk stored after I add it?
On your Mac. There is no account, no sign-in and no sync, nothing is uploaded and there is no tracking or telemetry. The register leaves your machine only when you export or back it up yourself. The single network use is Apple's App Store, for purchases, and it never sees anything in your register.