Building the Register

How to close a risk on Mac

A closed risk keeps its reference and every assessment ever made against it, so RiskOS can take the row out of your way without taking the decision out of the record.

Registers age. A supplier is replaced, a legacy service is switched off, a project ships and takes its overrun risk with it. What you do with that row matters more than it looks. Throwing the record away would take with it the judgement you may be asked to account for years later. Closing does the useful half of that — the row leaves your working view — and none of the damaging half.

Note

Closing is not deleting. A closed risk keeps its reference, its description and every assessment in its history, and one filter brings it back into view whenever you need it.

Where closing a risk lives

Choose Risks in the sidebar and select the row you are finishing with. The panel on the right opens on Summary, and the first field in it is Status. That single control is the whole mechanism: RiskOS closes a risk by changing its status, never by removing it from anywhere.

Two other places matter once you close things regularly. The filter control above the table carries show closed and accepted, which decides whether closed rows are visible at all; the filter icon fills in when any filter is on. And selecting more than one row turns the panel into a bulk editor, which is how a tidy-up of several rows takes about as long as one.

Close a risk, step by step

  1. Open the risk you are closing

    Choose Risks in the sidebar and click the row. If the register has grown past the point of scrolling, type into the search field: it covers the title, reference, category, owner, detail and tags, so RSK-0012 and legacy authentication both find the same row.

  2. Settle the record before you change the status

    Write what actually happened into the description while it is fresh: the service was decommissioned in August, the contract ended, the migration completed. A closed risk is read by people who were not in the room, and one sentence of outcome is worth more to them than the rating history.

    Look at the risk's actions in the same pass. Each carries its own status, so tick off what is genuinely done rather than leave open work attached to a row nobody will visit again.

  3. Set the status to Closed

    Open Summary in the panel and set Status to Closed. There is no separate save step; changes are written as you make them. The status badge updates at once, and the risk stops counting as active anywhere the register counts active risks.

  4. Watch the row leave the active list

    With the default filters in place, closed risks are hidden, so the row leaves the table as soon as the status changes. That is the intended behaviour, not a deletion. If the disappearance is disconcerting, turn on show closed and accepted before you start and the row stays in view with its new status.

  5. Close several risks in one pass

    Select several rows in the table and choose Close. Because closing several rows at once is harder to notice than closing one, RiskOS asks you to confirm first. The same selection also offers Mark Reviewed and Duplicate, which suits a quarterly sweep that produces a mixture of outcomes.

  6. Use the bulk editor when more than the status changes

    With several risks selected, the panel becomes a bulk editor. Tick only the fields you want to change — category, owner, business unit, status, treatment strategy, review cadence — set their values, and apply. Anything you leave unticked stays exactly as it was on every selected risk, so you can hand a departing colleague's risks to a new owner and close the finished ones in the same operation.

  7. Bring closed risks back into view

    Open the filters above the table and turn on show closed and accepted. Closed rows rejoin the table, sorted and searchable like everything else, and the filter icon fills in to remind you that you are seeing more than the live register.

  8. Reopen a risk you closed

    Show closed risks, select the one you want back, and set its status in Summary to an active value. It returns with its reference, ratings, linked controls and full history unchanged, because none of that was ever removed. If you closed something by mistake a moment ago, Z undoes it and Z puts it back.

Why risks close rather than disappear

A register earns its keep over years. Its value is in answering a question asked long after the event: what did you know, and what did you decide to do about it. A deleted row answers none of that. Risks in RiskOS are therefore closed and never deleted, and closing keeps the whole record intact.

What a closed risk keeps
WhatAfter closing
ReferenceKept permanently. RSK-0012 stays RSK-0012 and is never reissued.
Title and descriptionKept and still editable, so you can add the outcome after the fact.
RatingsInherent, residual and target stay as they stood on the day you closed it.
HistoryEvery assessment, with its reason and the score it produced, plus the residual chart.
LinksControls, actions, assets, vendors, indicators and events stay attached.
ReportsAvailable to any report whose scope includes closed and accepted risks.
BackupsWritten into every backup with the rest of the register.

The reference stays with it

References read RSK-0001 upwards and are handed out once. Closing a risk does not free its number for reuse: a reference that came back attached to something else would make every old report and board pack ambiguous. If you close RSK-0007 and later face the same exposure again, raise a new risk and say in its description which reference it follows on from.

The history stays readable

Open a closed risk and History still shows the residual score chart and the assessments behind it, each with the reason recorded at the time. This is the part people come back for. A risk whose residual fell from 15 to its target of 4 is evidence that a programme of work did something, and the reason recorded against each assessment says what moved it.

Closed, accepted and active

Three states do different jobs, and the difference between two of them is the one people get wrong most often.

How the three states differ
StateWhat it saysWhere the risk appears
ActiveA live exposure you are still carrying and managing.The register by default, review scopes, dashboard counts and reports.
AcceptedThe exposure is real and you have decided to live with it as it stands.Hidden from the default view; shown by the closed and accepted filter.
ClosedThe exposure no longer applies. There is nothing left to manage.Hidden from the default view; shown by the closed and accepted filter.

When to close

Close when the thing that could go wrong can no longer go wrong here: the system was retired, the supplier relationship ended, the project finished, the data was disposed of. The test is whether anyone could still be harmed by the event the title describes. If not, the row has done its work.

When to accept

Accepting is a treatment decision, not an ending. The exposure is still there; you have weighed it and chosen not to spend more on it. Record that as the Accept treatment strategy in the risk's Treatment section, with the reasoning in the plan, and keep a review cadence on it. An accepted risk above your appetite stays flagged wherever it appears, which is the argument you want in front of you.

The failure mode to avoid is closing a risk you have merely got used to. A residual of 15 does not become nothing because the register looks crowded.

Finding risks that are ready to close

Closing works best as a scheduled sweep rather than a reflex. Twice a year through a register of a dozen risks is a short job, and it keeps the live list honest.

Sweep with a saved filter

Build the view you want and use Save Current Filter… to name it. Closure sweep comes back with one click next quarter, exactly as you left it. Right-click the table header while you are there and bring the Review and Trend columns forward, so rows that have not moved in a year are obvious at a glance; RiskOS remembers the arrangement.

Close what the review pass surfaces

Choose Review in the sidebar and pick a scope; overdue for review is the usual one. Risks arrive one at a time, worst first, with the owner, actions, controls and last review beside the scoring inputs. That is the moment a retired system announces itself, because the context on screen no longer matches anything you still run. Skip it in the pass and close it from the register afterwards.

Troubleshooting

I cannot find the risk I closed

It is in the register; the default view is hiding it. Open the filters, turn on show closed and accepted, and the row returns. Search covers closed rows once they are shown, so the reference takes you straight there.

I closed the wrong risk

Press Z straight away and the change is undone. If you have moved on since, show closed risks, select the row and set its status back. Nothing was lost in between: the ratings, links and history were never touched.

Closed risks are still showing in my report

The report's scope includes them. Open Reports, find the scope option for including closed and accepted risks, turn it off and rebuild. RiskOS builds every output from one snapshot, so all four agree once you have changed it.

The review pass still shows a risk I thought I closed

Review scopes count active risks, so a row appearing there is still active. The likeliest cause is a bulk edit where Status was not ticked, since unticked fields stay as they were by design. Select the risk and check its status in Summary.

The filter icon is filled in and I am not sure why

Something is narrowing the view. The icon fills whenever any filter is on, including show closed and accepted, a band filter or over-appetite only. Open the filters and read what is switched on; clearing them returns the table to every active risk.

Habits that keep closures honest

  • Write the outcome, not the word "closed". One sentence saying what removed the exposure turns a row into a record somebody can read cold years later.
  • Close in a sweep, not in passing. A twice-yearly pass with a saved filter catches retired systems and finished projects together, which is more consistent than closing things one at a time.
  • Separate accepting from closing. If the exposure is still there, it is an accepted risk with a review cadence, not a closed one.
  • Tidy the actions first. Open actions attached to a closed risk are the commonest loose end, and each carries its own status until you tick it.
  • Raise a new reference for a returning risk. References are never reissued, so a recurrence gets a new row naming the old one rather than a reopened row with a confusing history.
  • Check the report scope before a board pack. Decide deliberately whether closed rows belong in this quarter's story. Both answers are defensible; neither should be an accident.
  • Back up after a large tidy-up. File ▸ Back Up RiskOS writes the whole register, closed rows included, to a single file wherever you choose.

Frequently asked questions

Can I delete a risk in RiskOS?

No. Risks are closed rather than deleted, so the reference, the description, the ratings and every assessment in the history survive. Closing takes the row out of your default view, which is the practical result people want, without destroying the evidence of a decision you may need to explain later.

How do I see closed risks?

Open the filters above the risk table and turn on show closed and accepted. Closed rows rejoin the table with their status badges showing, and sorting and search work on them as usual. The filter icon fills in while any filter is active, so you can tell at a glance that the view is wider than the live register.

How do I reopen a closed risk?

Show closed risks with the filter, select the row, and set Status in the Summary section back to an active value. Everything returns with it: the reference, the ratings, the linked controls and actions, and the full assessment history. If you closed it moments ago, pressing Z undoes the change outright.

Will closed risks appear in my reports?

Only if you ask for them. Reports carry a scope option for including closed and accepted risks; leave it off and the report covers active risks alone. All four outputs — PDF, HTML, Excel and print — come from one snapshot, so whichever way you set it, they agree with each other.

What is the difference between closing a risk and accepting it?

Closing says the exposure no longer exists, so there is nothing left to manage. Accepting says the exposure is real and you have chosen to carry it. An accepted risk keeps its review cadence and is still flagged when it sits above your appetite, which is the argument you want to keep seeing rather than close away.

Can I close several risks at once?

Yes. Select the rows in the table and choose Close; because a bulk closure is easy to miss, you are asked to confirm first. The same selection also offers Mark Reviewed and Duplicate, and the bulk editor lets you tick Status alongside owner, category or cadence and apply the lot in one go.

Does closing a risk free up its reference number?

No. References are issued once and never reissued, so RSK-0012 belongs to that risk permanently. It means an old report or email that cites a reference always points at the same thing. When a closed risk becomes relevant again, raise a new one and note in its description which reference it follows on from.

Are closed risks included in a backup?

Yes. A backup writes the whole register — risks of every status, history, controls, actions, assets, vendors, frameworks, indicators, events and settings — to a single file saved wherever you choose. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine.