Import, Export & Backups

How to back up a risk register on Mac

You can do this with RiskOS, a risk register for macOS. Everything — risks, history, controls, settings — in a single file you control.

A register is worth the years behind it. The number on a risk matters far less than the trail that produced it: the assessments and the reasons given for them, the controls the risk has collected, the actions closed against it, the events that proved it real. That record takes months to build and one bad morning to lose. One command writes all of it into a single file, and the whole job takes about as long as reading this paragraph.

Note

Backing up never changes your register. Restoring does — it replaces what is there with the contents of the backup, after telling you exactly what that means and asking you to confirm.

Where backing up lives

The command is File ▸ Back Up RiskOS…, and its shortcut is B. It is not tied to a sidebar section, because it does not act on a selection or on one part of the register: it takes the whole thing. Whichever section of RiskOS you happen to be in, the shortcut does the same job. Its counterpart, File ▸ Restore from Backup…, sits directly beneath it.

There is a second place in the app that writes files, and it is worth separating the two in your head now rather than at the moment you need one of them. Import & Export in the sidebar, under Output, moves rows in and out as CSV. That is for handing a list to somebody or bringing one in. A backup is not a list. It is the register itself, history included, and it is the only thing you can restore from.

Back up the register, step by step

  1. Start the backup

    Press B, or choose File ▸ Back Up RiskOS. Nothing needs to be selected and no section needs to be open first. Changes save as you type, so the rating you adjusted a moment ago is already part of what will be written.

  2. Choose where the file goes

    You are asked where to save, and the choice is entirely yours. Documents ▸ RiskOS is a sensible home if you want one place you will always look; Downloads is fine for a quick copy you are about to move elsewhere. The whole register arrives as one file, so wherever you put it, it travels as a single piece.

  3. Keep the date in the name

    The default filename already carries the date, in the form Risk Register 2026-09-21. Keep it. A folder of dated files sorts itself into age order by name alone, and months later you can tell which file you want without opening any of them. If a particular file is significant, add a few words after the date — Risk Register 2026-09-21 before import — rather than replacing it.

  4. Keep more than the newest file

    Mistakes are usually found late. A bulk edit that set the wrong owner across a dozen selected risks, an import that overwrote a description, a risk closed in error — none of these announce themselves the same afternoon. Keeping three or four generations rather than one means you can step back past the mistake instead of only back to the morning it was noticed.

  5. Keep a copy away from this Mac

    A backup that lives on the same machine as the register shares that machine's fate. Copy the newest file to an external disk, and keep that disk somewhere the original is not. This is the step people skip, and it is the one that decides whether a backup is insurance or a formality.

  6. Set a reminder interval

    A quiet reminder appears when your last backup is getting old, and the interval is yours to set: never, weekly, fortnightly or monthly. Pick the one that matches how much work a period of that length represents for you. The reminder is a prompt, not an obstruction, and choosing never is a legitimate answer if you would rather hold the schedule yourself.

  7. Take an extra backup before anything large

    Some operations touch many rows at once: a CSV import, a bulk edit across a dozen selected risks, a methodology change that re-scores the entire register immediately. Each is reversible in principle and tedious in practice. Pressing B first costs a few seconds and turns an awkward afternoon into a five-minute correction.

  8. Know what restoring does before you need it

    Open File ▸ Restore from Backup… once now, while nothing is wrong, and read what it tells you. Restoring replaces the register with the contents of the backup rather than merging the two, and it says so plainly before anything happens. Cancel the sheet. Knowing that in advance is what stops a bad day from becoming a worse one.

What one backup carries

The file is not a summary and not a selection. It is the register as it stood at the moment you pressed the shortcut, with every part of it that took work to create.

What a RiskOS backup file contains
In the fileWhat that covers
RisksEvery risk, active and closed, with its ratings, treatment, owner, dates and references.
History and audit trailEvery assessment ever recorded, with the reason given and the score it produced.
ControlsType, status, owner, effectiveness and evidence notes, and the risks each one is linked to.
ActionsEvery action across the register, with its status, priority, owner and due date.
Assets and vendorsCriticality, owners, review dates and the risks attached to each.
FrameworksBundled and imported catalogues, and every control mapping you have made against them.
IndicatorsThresholds, direction, cadence and the full reading history behind each chart.
EventsWhat happened, when, how severe, what it cost, the lessons and the risks it is linked to.
SettingsYour methodology, the band thresholds, and the appetite thresholds with their rationales.

Restoring that file puts the register back into RiskOS as a working whole. The references hold, the links between risks and controls hold, and the history is still there to be read. That is the difference between recovering a register and retyping one.

How often to back up

The honest measure is not the calendar but the work. Ask how much effort a week of your register represents, and whether you would be willing to redo it. For a register being built out, that answer changes weekly; for one that is touched mainly at review time, monthly is plenty.

Moments worth a file of their own

Beyond whatever interval you settle on, a handful of moments earn a backup regardless of when the last one was taken.

Moments that deserve a backup taken deliberately
MomentWhy it earns one
Before a CSV importThe preview shows what will happen, but a backup means a wrong file costs nothing but time.
Before a bulk editApplying a field across a dozen selected risks is quick to do and slow to unpick.
Before a methodology changeChanging whether controls reduce likelihood, impact or both re-scores every risk at once.
At the end of a review passCaptures the register exactly as it was when the review was signed off.
Before a board or audit meetingThe register that produced the report stays retrievable, whatever happens next.
Before moving to another MacThe file you carry across is the same file you restore from.

Where to keep the files

One folder, clearly named, is enough. Documents ▸ RiskOS works because it is somewhere you will think to look under pressure, which is the only real requirement. What matters more is that the newest file also exists somewhere the Mac is not.

How many generations to hold

Three or four is a reasonable working number for most registers: the newest, the one before it, and one from a month or so back. Add to that any file you deliberately took before a large change, and keep those a little longer. The dated names make the pruning obvious — when a folder holds a dozen files, the oldest few can go without much thought.

Treat the file as the register

A backup holds everything the register holds, which includes owners' names, the exposure amounts you have recorded and the lessons written up after events. Store it where you would store the register itself and give it the same handling. It is not a lesser copy; it is the whole thing in one piece.

Backups and versions

Backups are versioned, and the rule is deliberately one-directional. An older backup always restores into a newer version of the app. A file written by a newer version than the one you are running is refused outright rather than half-read, because a partially understood register is worse than no register at all.

This only becomes visible when two Macs are involved, and then it matters. If a restore is refused, the file was made by a newer version of RiskOS than the one on the Mac in front of you. Bring that Mac up to date and open the file again — the backup has not been harmed by the refusal, and it will restore once the versions line up.

A backup, an export and a report

Three things in RiskOS produce a file, and knowing which one you want saves a lot of hunting later.

A backup is the register, entire, and the only one of the three you can restore from. A CSV export writes your rows out as data, for handing a list to a colleague or keeping the rows on their own. A report — PDF, HTML, Excel or straight to the printer — is a considered presentation of the register for people to read, drawn from a single snapshot so every output agrees with the others.

The distinction to hold on to is that reports and exports are for other people. A backup is for you, and specifically for the version of you who needs the register back.

Troubleshooting

I cannot remember when I last backed up

Look at the folder you save into: the filenames carry their dates, so the newest name is the answer. Then set a reminder interval so the question stops depending on memory. The prompt appears quietly when the last backup is getting old, and you can take a fresh file the moment you see it.

My backup file was refused

The file was written by a newer version of the app than the one running on this Mac. Restores go one way only: older files open in newer versions, never the reverse. Update RiskOS on this Mac and try the restore again. Nothing has happened to the file, and nothing has happened to your current register.

I restored and lost this morning's work

Restoring replaces the register with the contents of the backup, which is what the confirmation describes before you agree to it. The habit that prevents this is to take a fresh backup immediately before restoring an older one. That way both states exist as files and you can move between them rather than in one direction.

I have a folder of files and cannot tell them apart

Read the names. Because every default filename begins with the same words and ends with its date, name order is date order, and the newest file is the last one in the folder. If several files share a date, the few words you added at the time are what separate them, which is the argument for adding those words when a file is taken for a particular reason.

The reminder keeps appearing

It appears when the last backup is older than the interval you chose. Take a backup and it settles. If the interval is tighter than your actual rhythm, lengthen it — fortnightly and monthly are both there — or choose never and keep the schedule yourself.

A routine that holds

Backing up fails through neglect, not difficulty. A few habits carry it through a busy month.

  • Learn the shortcut, not the menu. B takes seconds and works from any section, which is what makes it something you will actually do.
  • Back up at the end of a session, not the start. The file then holds the work you have done rather than the state you found.
  • Pair it with the review. Finish a review pass, take a backup. The register as signed off stays retrievable, which is exactly what an auditor will ask for.
  • Always precede a bulk change. Imports, bulk edits and methodology changes move many rows at once. One file beforehand makes all three reversible.
  • Keep one copy off the machine. A backup sitting beside the register protects you from mistakes, but not from losing the Mac itself.
  • Keep the dates and keep a few generations. Dated names sort themselves, and three or four files let you step back past a mistake you found late.
  • Read the restore warning once, calmly. Knowing that a restore replaces rather than merges is worth far more before you need it than during.

Frequently asked questions

How do I back up a risk register on a Mac?

Press B, or choose File ▸ Back Up RiskOS. You are asked where to save, the default filename carries the date, and the entire register is written to that one file. Nothing needs to be selected first, and backing up never alters the register you are working in.

What is included in a RiskOS backup?

Everything: risks, their full history and audit trail, controls, actions, assets, vendors, frameworks and your mappings against them, indicators with their readings, events, and your settings including methodology and appetite thresholds. Restoring puts all of it back as a working register, with the links between risks and controls intact rather than needing to be rebuilt.

How often should I back up a risk register?

Weekly suits a register being actively built out, fortnightly a settled one with regular treatment work against it, and monthly one touched mainly at review time. Set the reminder interval to match and take an extra backup before any large change — an import, a bulk edit, or a methodology change that re-scores every risk.

Where is the backup file saved?

Wherever you choose. You are asked for a location each time, so a folder such as Documents ▸ RiskOS or an external disk both work. The whole register arrives as a single file, which makes it simple to copy elsewhere afterwards. The default name carries the date so the folder stays readable over time.

Can I restore a backup made by an older version of RiskOS?

Yes. Older backups always restore into a newer version of the app. The reverse is refused: a file written by a newer version than the one you are running will not be opened at all, rather than read in part. If that happens, update the app on that Mac and try the restore again.

Is exporting to CSV the same as backing up?

No. A CSV export writes rows out for someone else to use, and a report presents the register for people to read. Neither can be restored from. A backup is the register itself, history and audit trail included, and it is the only file that brings everything back exactly as it stood.

Does my backup file go anywhere I have not put it?

No. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine except in the files you save yourself. A backup sits exactly where you chose to put it, and moving a copy to another disk is a decision you make, never one made for you.