How to assign a risk owner on Mac
You can do this with RiskOS, a risk register for macOS. One name against every row, and a register that can tell you who holds what.
A risk with no owner is a note to nobody. It gets read out in a meeting, nodded at, and left exactly where it was, because accountability that belongs to everyone belongs to no one in particular. Putting a single name against each row is the cheapest change you can make to a register, and the one that most reliably turns a list of worries into work that moves.
An owner is a person. The team they sit in belongs in Business unit, a separate field on the same section, so you can read the register by person or by department without one crowding out the other.
Where the owner field lives
Choose Risks in the sidebar and click a row. The panel on the right opens on Summary, and that is where ownership is set: status, category, subcategory, owner, business unit, review cadence and next review date, in that order. Nothing here needs saving. Changes are written as you type.
The same name appears in the register table, in the Owner column, which you can sort, move or hide like any other. It also travels with the risk into review sessions and into reports, so the name you type once is the name a director reads six months later.
Risks are not the only records that carry a name. Controls, actions and assets each have an owner of their own, and vendors carry a relationship owner. Those are covered further down, because they answer slightly different questions.
Assign an owner, step by step
-
Open the risk you want to assign
Choose Risks in the sidebar and click the row. The panel on the right opens on Summary, with the reference and title at the top so you can confirm you have the right row. If the risk does not exist yet, press ⌘N and it pins to the top of the table.
-
Agree what owning a risk means
Settle the definition before you type a single name. The workable one is this: the owner answers for the rating being current and for the treatment moving. They need not do the work themselves, and they need not be the person who spotted the risk. The field only means what everyone agrees it means.
-
Set the owner in Summary
Open Summary in the panel and type the person's name into Owner. There is no dialogue to dismiss and no save button: RiskOS takes the change as you type it, and the Owner column updates behind the panel. If you change your mind, ⌘Z steps the edit back.
-
Use one form of every name
Decide on a format and hold to it — M. Halvorsen rather than Mike on one row and Halvorsen, M. on another. Search matches on the owner text, so three spellings of one person become three owners, and any count of their workload will be wrong.
-
Record the business unit alongside it
Set Business unit on the same section. The owner tells you who to ask; the business unit tells you where the consequence lands, and the two are often not the same department. Record both and you can read the register either way later, without going back through every row.
-
Give the owner a date
Still in Summary, set a review cadence and a next review date. A name with no date is a label; a name with a date is an appointment. The cadence schedules the following review as soon as this one is confirmed, so the owner keeps hearing from the register without anyone chasing them.
-
Show the Owner column in the table
Right-click the table header to show, hide and reorder columns, and put Owner where your eye lands first. Click the column heading to sort by it, which gathers each person's rows together. RiskOS remembers the arrangement, so the table you set up is the table you come back to.
-
Assign a backlog in one pass
If you have inherited a register with an empty Owner column, do not work down it a row at a time. Select several risks and the panel becomes a bulk editor: tick owner, set the name, and apply it to every selected risk. Unticked fields are left alone, so twenty rows gain an owner without their categories, statuses or cadences moving.
-
Check your work by name
Type the owner's name into the search field above the register. Search covers title, reference, category, owner, detail and tags, so the name alone narrows the table to everything that person holds. Count the rows, read the residual scores, and the conversation you are about to have is already prepared.
Choosing the right owner
The field takes a name you type, so the discipline has to come from you. Three habits carry almost all of it.
One name, not a committee
Resist IT, the security team, or two names separated by a slash. A shared owner is an unowned risk with extra steps: each person assumes the other is watching, and the review date passes untroubled. If a risk spans two departments, name the person who would be asked to explain it and record the second department as the business unit.
The accountable person, not the busiest one
The engineer who runs the nightly restore is not automatically the owner of Backup restoration has never been tested end to end. The owner is whoever can commit the time, argue for the budget and say the treatment is finished. Put the engineer on the action instead, where the work sits.
Name a person who knows they own it
An owner who has never been told is record-keeping and nothing else. Assigning ownership is the second half of a conversation, not a substitute for one. RiskOS remembers the agreement and brings it back on a date; the agreement itself is yours to make.
Who owns what elsewhere in the register
Ownership is not one field in one place. Five kinds of record carry a name, and each answers for something different. Keeping them distinct stops a register collapsing into a list where one person appears to own everything.
| Record | Field | What that person answers for |
|---|---|---|
| Risk | Owner | That the rating is current and the treatment is moving. |
| Control | Owner | That the control is still operating, at the effectiveness recorded, with evidence behind it. |
| Action | Owner | Finishing one piece of work by its due date. |
| Asset | Owner | The system, data set, facility or process itself. |
| Vendor | Relationship owner | The relationship with that third party, and its next review. |
The distinction pays for itself the first time a control slips. A risk owner whose residual score has moved can see which control changed and who owns it, without a message asking who looks after what. Controls carries its own Owner column beside the effectiveness meter and the count of risks relying on it.
Seeing everything one owner holds
A register earns its keep when it can answer a question in the shape it was asked. "What is J. Whitfield carrying?" is the most common such question, and there are three ways to answer it.
Search by name
Type the name into the search field above the register. Search covers the owner along with title, reference, category, detail and tags, so a name narrows the table to that person's rows at once. Add a band filter to ask a sharper question: everything they own sitting in High or Critical.
Sort the Owner column
Sorting groups the register by person and shows the whole distribution rather than one slice. It is the fastest way to spot the two problems that matter: one name against nine rows while three colleagues hold one each, and a run of blanks nobody has claimed.
Save the view you keep rebuilding
If you rebuild the same combination every Monday, use Save Current Filter… to name it and bring it back in one click. The filter icon fills while a filter is active, so you always know the table in front of you is a subset.
Filter the actions list by owner
Choose Actions and use the owner filter to see every piece of treatment work assigned to one person, grouped by due state: Just Added, Overdue, Due Soon, Later, No Due Date and Closed. This is the list to bring to a one-to-one. The register says what someone is accountable for; the actions list says what they have agreed to do about it, by when.
A small register makes the pattern obvious. Twelve active risks, an average residual of 9.6 out of 25 and an appetite of 9 divide like this.
| Owner | Risks held | Highest residual | What the row tells you |
|---|---|---|---|
| A. Okonkwo | RSK-0001, RSK-0006, RSK-0010 | 15 | Holds the joint-highest exposure in the register, and a control of their own. |
| M. Halvorsen | RSK-0002, RSK-0007, RSK-0009 | 15 | One risk six points over appetite, with a rehearsal control still only planned. |
| S. Ramirez | RSK-0003, RSK-0005, RSK-0011 | 12 | A cluster around suppliers and regulation — a pattern worth a category threshold. |
| J. Whitfield | RSK-0004, RSK-0008, RSK-0012 | 9 | Lower scores, but three review dates to keep and no one else to keep them. |
Ownership in a review and in a report
The name is not decoration in either place. In Review, risks arrive one at a time, worst first, and each brings its full context onto one screen: owner, actions, controls and last review, beside the scoring inputs. You never have to remember who you are about to hold to a rating.
In Reports, the cover carries the report title, the organisation and who prepared it, and the section toggles decide how much of the register travels with it. Turn on the full register or the per-risk detail pages and the accountability you recorded goes into the document you hand over. All four outputs come from one snapshot, so the PDF, the HTML file, the workbook and the printed copy never disagree about who owns what.
Troubleshooting
The Owner column is not in my table
It has been hidden. Right-click the table header, tick Owner, and drag it to where you want it to sit. The arrangement is remembered, so it stays put the next time you open the register.
The same person appears under two names
Two spellings, almost certainly. Search for the shorter form to find the stray rows, select them in the table, and use the bulk editor to set the owner to your agreed spelling in a single pass. Then write the format down, because this happens again the moment a second person starts adding risks.
Someone has left and I need to reassign their risks
Search the register for their name, select every row it returns, tick owner in the bulk editor and set the new name. Do the same in Actions using the owner filter, then check Controls and Vendors. A leaver is the one moment ownership is urgent: nothing will chase an empty name.
There is no owner filter on the risk table
The register's filters are band, over-appetite only, and whether to show closed and accepted risks. Owner is handled by search instead, which covers it along with title, reference, category, detail and tags — so typing a name does the same job, and combines with the filters rather than competing with them.
I assigned the wrong person to a dozen risks
Press ⌘Z. Undo and redo work across the register, and ⇧⌘Z brings the change back if you overshoot. If you have moved on since, search for the wrong name and run the bulk editor again — it is the same three clicks in the other direction.
Routines that keep ownership honest
Assigning owners is a morning's work. Keeping the names true is a habit, and these cost least.
- Sort by owner once a month. Thirty seconds tells you who is carrying too much, who is carrying nothing, and which rows are still blank.
- Never leave a new risk unowned overnight. A name set at creation is a decision; a name added three weeks later is an argument.
- Pair every owner with a cadence. Accountability without a date drifts. The cadence schedules the next review the moment the current one is confirmed.
- Read the actions list before a one-to-one. Filter by owner, look at Overdue and Due Soon, and the meeting writes itself.
- Reassign the day someone leaves. Search their name, bulk-edit the risks, then check actions, controls and vendors for the rest.
- Keep owners off the controls they assure. If one person owns the risk, the control and the evidence behind it, the register has stopped being a check on anything.
- Say the name out loud in the review. RiskOS remembers the agreement; only a conversation makes it one.
Frequently asked questions
How do I assign an owner to a risk?
Choose Risks in the sidebar, click the row, and open Summary in the panel on the right. Type the person's name into Owner. RiskOS saves the change as you type, and the Owner column updates immediately. To assign several risks at once, select them in the table and use the bulk editor that replaces the panel.
Can two people own the same risk?
The field holds one name, and that is the right shape for it. A risk with two owners tends to have none in practice, because each person assumes the other is watching the review date. Name the single person who would be asked to explain the risk, record the second department in Business unit, and put the other people on the actions.
How do I find every risk one person owns?
Type their name into the search field above the register. Search covers the owner as well as title, reference, category, detail and tags, so the table narrows to that person's rows at once. Sorting the Owner column groups the whole register by name instead, which is the faster way to compare how much each person is carrying.
What is the difference between a risk owner and a business unit?
The owner is a person who answers for the risk. The business unit is where the consequence lands. They are separate fields in Summary because they are often different: a payroll outage may be owned by a finance manager while the impact sits across the whole organisation. Recording both lets you read the register by person or by department.
How do I reassign risks when someone leaves?
Search the register for their name, select every row it returns, then tick owner in the bulk editor, set the new name and apply. Fields you do not tick are left alone. Repeat in Actions using the owner filter, and check Controls and Vendors, where a departing colleague may also have been the named owner.
Do controls and actions have owners as well?
Yes, and they answer for different things. A control owner answers for the control still operating at the effectiveness recorded. An action owner answers for finishing one piece of work by its due date. Assets carry an owner too, and in RiskOS a vendor carries a relationship owner, responsible for that third party and its next review.
Why is there no owner filter on the risk register?
Because search already covers it. The register's filters narrow by band, by whether a risk is over appetite, and by whether closed and accepted risks are shown. Owner is a name, so typing it into search does the job and still combines with those filters. Save Current Filter… names the combination you keep rebuilding.
Is an owner's name stored anywhere outside my Mac?
No. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine unless you export or back it up yourself. The names you record are read by you and by anyone you hand a report to, and by nobody else.