Reporting & Branding

How to choose what goes in a risk report on Mac

Composed in RiskOS, a risk register for macOS. Ten toggles decide what a reader sees, and what they are spared.

A report fails in two directions. Send a board forty pages and the four risks that mattered are buried somewhere inside them; send an auditor a single summary page and the first reply is a list of everything you left out. The report builder in RiskOS makes that judgement explicit rather than accidental: ten sections, each one on or off, chosen for the person who is going to read the thing.

Note

Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine.

Where the report builder lives

Choose Reports in the sidebar, under Output. The page reads top to bottom in the order a report is assembled. The cover fields come first — report title, organisation, prepared by — and those three lines are what a reader meets before anything else. Beneath them sit the section toggles, one per section of the finished document, then the scope switch, then the export controls.

The choices are not made per format. One set of toggles feeds every output, and all four are built from the same snapshot, so a figure on the cover of a PDF and the same figure in a workbook cannot quietly drift apart.

Compose a report, step by step

  1. Open the report builder

    Choose Reports in the sidebar. The register behind it does not have to be finished. A report is a view of whatever the register holds at the moment you export, so you can build one early and run it again next quarter without setting it up twice.

  2. Fill in the cover fields

    Set the report title, the organisation it covers and the name of whoever prepared it. Write the title for the reader rather than for yourself: Q3 Risk Report — Operations Committee tells someone what they are holding, where Risk Report tells them nothing once three of them sit in the same folder.

  3. Name the reader before you touch a toggle

    Every switch below is a question about the audience, not about the register. A board wants the shape and the exceptions. An auditor wants the working. A risk owner wants their own rows and the dates attached to them. Say who the reader is out loud, and most of the ten sections answer themselves.

  4. Start with the summary and the matrix

    Turn on executive summary and risk matrix first. Between them they carry the shape of the register in two pages: where the numbers stand, and how the risks are distributed across likelihood and impact. A report holding only these two still says something useful.

  5. Set the number of top risks

    Turn on top risks and choose how many to list, anywhere from 3 to 50. The section ranks by residual score, so the number is really a decision about attention: ten is a discussion, fifty is an appendix. On a register of twelve active risks, five is usually the honest cut.

  6. Choose between the register and detail pages

    Full register adds the whole table, one row per risk, as a reference. Per-risk detail pages gives every risk a page of its own with its assessment and context written out. The second multiplies your page count by the size of the register, so pick one deliberately.

  7. Add the sections that answer the next question

    Turn on controls, open actions, risk indicators, risk events and framework coverage only where the reader will actually ask. Controls and coverage answer "what are you doing about it". Open actions answers "who is doing it, and by when". Indicators and events answer the sharper question: "how do you know these ratings are right".

  8. Set the scope

    The scope switch decides whether closed and accepted risks are included. Leave it off and the report covers the active register, which is what most readers expect to be given. Turn it on when the report has to account for everything on the books — an audit, a handover, a year-end paper.

  9. Export in the format the reader needs

    Export a PDF with P, a self-contained HTML file with E, or send the pages to a printer with P. Choose where the file is saved; Documents ▸ RiskOS keeps a quarter's reports together. RiskOS confirms each export with its filename, and if one fails it says what to do next.

What each section puts on the page

Ten toggles, ten decisions. The short version of each is below: what the section contributes, and the condition under which it earns its space.

The ten report sections and when to include each one
SectionWhat it contributesInclude it when
Executive summaryThe register's headline position, read in one pageNearly always. It is the page most readers finish
Risk matrixEvery risk placed on the grid by likelihood and impactThe reader needs distribution rather than a list
Top risksThe highest residual scores in order, 3 to 50 of themAlways. This is the section decisions come out of
Full registerThe whole risk table, one row per riskThe report is meant to be a reference document
Per-risk detail pagesA page each: assessment, treatment, owner, contextA reader will work through risks one at a time
ControlsWhat you rely on, with status and effectivenessThe reader will ask what is being done about it
Open actionsOutstanding work with owners and due datesSomebody in the room will chase the dates
Risk indicatorsMeasured numbers against warning and breach thresholdsYou want evidence beside the judgements
Risk eventsWhat has actually happened, with severity and costThe ratings need testing against reality
Framework coverageCovered, mapped but not operating, and not mappedThe audience is assurance, audit or compliance

Building for the reader

Four audiences cover most of what anyone is asked to produce, and each is a different answer to the same ten questions.

A board or executive pack

Executive summary, risk matrix, top risks at five or ten. Leave the rest off. A board is not reading the register; it is deciding whether the organisation's position has changed and whether anything needs its authority. A pack that says twelve active risks, an average residual of 9.6 out of 25, four above appetite and three overdue for review does that work in a paragraph.

An assurance or audit pack

Turn on the full register, controls, framework coverage, risk indicators and risk events, and switch the scope to include closed and accepted risks. An assurance reader is testing whether the register is maintained, not whether it looks tidy, so the sections that show your working matter more than the ones that summarise it.

A working pack for risk owners

Full register, controls and open actions, with the matrix and framework coverage switched off. Owners want the rows they answer for and the work attached to them. The Excel output suits them, because its formulas re-score themselves when a likelihood changes, so an owner can test a treatment before committing to it.

A pack prepared for a client

Work inside the client's profile before you export. A profile carries its own methodology, risk appetite, report defaults, client name and client logo, so the export comes out addressed to the client while your own identity stays primary on the page. Switching profiles takes a keystroke, and P cycles through them.

The scope switch, and what it changes

The scope switch is one line on the page and the largest single change you can make to a report. Risks are closed rather than deleted, and a risk treated by accepting it stays on the books by design, so the population a report describes depends on whether those two groups are counted.

With the switch off, every count and average is drawn from the active register. Turn it on and the closed and accepted rows return: the register grows, the averages move, and sections such as top risks and the matrix change composition even though no individual risk has changed. Neither reading is wrong. What matters is that the report says which one it is — a title reading Annual Risk Report, including closed and accepted risks removes the ambiguity in eight words.

Four formats, one snapshot

The same section choices produce four outputs, and because they come from one snapshot they agree with each other. Each presents it in the way its own medium is good at.

The four report formats and what each is best suited to
FormatWhat you getBest for
PDFPaginated A4 with a branded cover, a running header and footer on every page, repeated table headers, and rows that never split across a pageA fixed document to circulate or attach
HTMLOne self-contained file that opens in any browser, with no scripts and nothing loaded from the internetReading on screen, and long tables that suffer from pagination
ExcelA live workbook of seven sheets whose formulas re-score themselves when you change a likelihoodA reader who wants to test the numbers rather than accept them
PrintExactly the PDF, sent to the printerA meeting where paper still wins

Branding applies to all of them

Set Up Branding opens the header and footer designer: business name, tagline, address, phone, email, website and a registration or VAT line, plus a logo, with an optional variant for dark backgrounds. The live preview shows the real header and footer, and what you see there is exactly what exports and prints.

Troubleshooting

The report is far longer than I expected

Almost always per-risk detail pages. That section gives every risk in scope a page of its own, so twelve risks add twelve pages before a single supporting section is counted. Turn it off, keep the full register table, and the same information arrives in a form a reader can scan.

A section came out empty

The section is on, but there is nothing in scope for it to show. Coverage with no control mappings, events where nothing has been logged, or indicators before any readings exist will all report honestly rather than invent filler. Either populate that part of the register or switch the section off for this report.

The cover shows the wrong organisation

The organisation on the cover comes from the cover field on the report page, not from your branding. Correct it there. If the report is for a client, switch to that client's profile first so the client's name and logo are carried through instead of typed in each quarter.

My logo is missing from the header

Open Set Up Branding and add it. Logos drop in as PNG, JPEG, PDF or SVG. If it looks right on the page and wrong against a dark background, add the optional dark-background variant; the preview shows the real header, so you can confirm both before exporting.

Two exports show different numbers

They were taken at different moments. Each export captures the register as it stands when you run it, so a rating changed between the PDF and the workbook shows up as a difference between two files that were never meant to disagree. Export the formats you need in one sitting, and re-export all of them after any change.

Routines that keep a report worth reading

Composition is a habit more than a decision, and a few of them do most of the work.

  • Title it for the folder it will sit in. A period, an audience and a scope save a reader from opening three files to find the right one.
  • Review before you report. A pass through Review stamps the review dates and settles the ratings, so the report describes a register somebody has actually looked at.
  • Cut top risks before you cut the summary. If a pack is too long, shorten the ranked list rather than removing the page that explains the position.
  • Pick one of register or detail pages. Both together is the most common cause of a report nobody finishes.
  • Leave the scope switch off by default. Turn it on deliberately, for audits and year-end papers, and say so in the title when you do.
  • Export every format in one sitting. One pass, one snapshot, four files that agree with each other.
  • Set branding once. The header and footer designer is a short job that applies to every report you produce afterwards.
  • Let a profile carry the client. Client name, logo and report defaults travel with the profile, so the same pack for another client is a keystroke rather than an editing session.

Frequently asked questions

What should a risk report include?

At minimum an executive summary, a risk matrix and a ranked list of top risks. Those three carry the position, the distribution and the exceptions. Add controls, open actions, indicators, events, framework coverage, the full register or per-risk detail pages when the reader will ask for them. RiskOS offers all ten as separate toggles, so a report is composed rather than fixed.

How many top risks should a report show?

Anywhere from 3 to 50, and the number is a decision about attention rather than completeness. Five to ten suits a board, because that is roughly how many risks a meeting can genuinely discuss. Larger numbers suit an appendix. The section ranks by residual score, so a shorter list still puts the most exposed risks in front of the reader.

Should a risk report include closed and accepted risks?

Usually not. Most readers expect the active register, and including closed and accepted rows changes every count and average in the report. Turn the scope switch on for audits, handovers and year-end papers, where the point is to account for everything on the books. When you do, say so in the report title so nobody compares two different populations.

What is the difference between the full register and per-risk detail pages?

The full register is the table: one row per risk, scannable, good as a reference. Per-risk detail pages give every risk in scope a page of its own with its assessment, treatment and context written out. The first keeps a report short; the second makes it long in direct proportion to the size of your register. Choose one.

Can I put my company logo and address on a risk report?

Yes. Set Up Branding opens the header and footer designer, where you set business name, tagline, address, phone, email, website and a registration or VAT line, and add a logo as PNG, JPEG, PDF or SVG. An optional variant handles dark backgrounds. The live preview shows the real header and footer, so what you see is what exports and prints.

Which report format should I send to a board?

PDF. It is paginated A4 with a branded cover, a running header and footer on every page, repeated table headers, and rows that never split across a page, so it reads the same for everyone and prints predictably. Export it with Shift-Command-P. Send the Excel workbook instead when the reader wants to test the numbers themselves.

Do the PDF, HTML and Excel reports show the same numbers?

Yes, when they come from the same export pass. All four outputs are built from one snapshot of the register, so they cannot disagree with each other. A difference between two files means they were exported at different moments with a change in between. Run the formats you need in one sitting, and re-export them all after any edit.

How do I produce a risk report for a client rather than my own organisation?

Switch to that client's profile before exporting. A profile carries its own methodology, risk appetite, report defaults, client name and client logo, and the export is addressed to the client while your own identity stays primary on the page. Control-Command-P cycles between profiles, so producing the same pack for a second client takes a keystroke.