How to edit many risks at once on Mac
You can do this with RiskOS, a risk register for macOS. Tick the fields you mean, leave the rest alone, and change a hundred rows as carefully as one.
Registers go stale one field at a time. Someone leaves and forty rows still carry their name. A reorganisation renames a business unit. A quarter turns over and a dozen risks all need the same review cadence. None of this is difficult work, and all of it is dull enough to be postponed, which is how a register quietly stops being trusted. Editing many risks in a single pass removes the tedium without removing the care.
A bulk edit only writes the fields you tick. Anything left unticked keeps the value it already had on every risk in the selection, so a change to fifty rows stays exactly as narrow as you made it.
Where the bulk editor lives
Choose Risks in the sidebar. In RiskOS the register fills the middle of the window as a sortable table — Ref, Risk, Owner, Inherent, Residual, Target, Trend, Appetite, Status, Review — and the panel on the right shows whatever is selected. Select a single row and the panel is that risk, with its summary, assessment, treatment and everything else. Select several and the panel changes job: it becomes a bulk editor listing the fields that can be set across the whole selection at once.
There is no mode to enter and nothing to switch on first. The panel follows the selection: narrow the table to the rows you mean, select them, and work on the right. Drop back to a single row and the panel returns to that one risk.
Change a field across several risks
The sequence below holds for every field RiskOS offers in the bulk editor. Do the narrowing first: a selection made from an already-filtered table is far easier to check than one assembled by scrolling.
-
Narrow the table to the rows you mean
Type into the search field above the register. Search covers the title, the reference, the category, the owner, the detail and the tags, so searching an owner's surname brings back everything they hold. Add filters if you need them — band, over-appetite only, or show closed and accepted — and the filter icon fills in to remind you that a filter is on.
Sorting helps as much as filtering. Click a column header to sort by it and the rows you want usually end up adjacent, which makes the next step a single gesture.
-
Select the rows you want to change
Click the first row, then hold ⇧ and click the last to take everything between them. To build a selection that is not a run, hold ⌘ and click rows one at a time; ⌘-clicking a selected row takes it back out again. Mixing the two works: take a block with ⇧, then ⌘-click the two exceptions out of it.
-
Check the panel has become the bulk editor
With more than one row selected, the panel on the right stops showing a single risk and lists the fields you can change across the selection: category, owner, business unit, status, treatment strategy and review cadence. If the panel is still showing one risk's assessment, only one row is selected — go back and extend the selection.
-
Tick only the fields you want to change
Each field in the bulk editor has a tick beside it, and ticking a field is what brings it into the edit; everything you leave unticked is not written at all. You are not filling in a form that overwrites a risk — you are naming the two or three fields that should move.
-
Set a value for each ticked field
Choose the value every selected risk should end up with. Category offers the seeded list plus any category you have added yourself; status, treatment strategy and review cadence offer their fixed choices. The value applies to the whole selection, so if some rows need a different value, make two passes rather than one.
-
Apply the change to every selected risk
Apply the edit and RiskOS writes every ticked field to every risk in the selection at once. Fields you did not tick stay exactly as they were on each individual risk, including on rows where that field was empty.
-
Check the result in the table
Look at the column you changed. If it is not shown, right-click the table header and switch it on — that menu shows, hides and reorders columns, and the arrangement is remembered. Sorting by the column afterwards groups the edited rows together, which is the quickest way to confirm the change landed.
-
Undo if it was not what you meant
Press ⌘Z to undo the edit, and ⇧⌘Z to put it back. A bulk edit undoes as one action rather than one risk at a time, so a selection of forty rows comes back in a single step.
The fields you can set in bulk
RiskOS lets six fields be set across a selection. They are the descriptive and procedural parts of a risk — who owns it, where it sits, how it is being treated, how often it is looked at — rather than anything that would change a score.
| Field | What it sets | When bulk is the right tool |
|---|---|---|
| Category | The heading a risk is filed under, from the seeded list or your own. | After a reorganisation, or when library entries all arrived under one broad heading. |
| Owner | The person who answers for the risk. | A handover. One person leaves and their rows need a new name today. |
| Business unit | The part of the organisation the risk belongs to. | A team moves, merges or is renamed and its risks should follow. |
| Status | Whether a risk is active, accepted or closed. | Retiring a batch of risks together after a project or a migration ends. |
| Treatment strategy | Mitigate, Accept, Transfer or Avoid. | A decision taken once that covers several risks — accepting a group of low residual rows, for instance. |
| Review cadence | How often the risk should come back for review. | Putting a whole category on the same rhythm before a quarterly pass. |
Category and business unit
These two do more than tidy the table. Category is what per-category appetite is resolved against, so moving a risk between categories can change the threshold it is measured by, and therefore whether it shows as over appetite. Resolution runs in a fixed order — a risk's own override first, then its category, then the organisation-wide threshold — so a bulk category change only moves the goalposts for risks without an override.
Business unit is the second axis. Category answers "what kind of risk is this", business unit answers "whose risk is this", and keeping both filled in means a report can be cut either way later without going back through the register by hand.
Owner
Reassigning an owner is the most common reason to reach for a multiple selection. Search the outgoing owner's name, check that every row returned really is theirs, select the lot, tick owner, set the new name and apply. Because search covers the owner field along with title, reference, category, detail and tags, a surname is usually enough to gather the whole set in one go.
A handover is the moment this matters most. A register where a third of the rows point at someone who left in March is a register nobody acts on.
Status and treatment strategy
Status covers whether a risk is active, accepted or closed, and setting it across a selection is how a batch of project risks retires together. Treatment strategy is the choice between Mitigate, Accept, Transfer and Avoid — the intent behind what you are doing about a risk.
The strategy is bulk-editable; the plan and the due date behind it are not, and that is deliberate. A shared decision — "these four are accepted" — is common. The plan that follows a Mitigate decision is specific to each risk, and one written once and stamped across a group would be worth nothing to the next person reading it. Set the strategy for the group, then write the plans in each risk's Treatment section.
Review cadence
Cadence is how often a risk should come back round. The next review date is scheduled from it whenever a review is confirmed or a risk is re-scored, so changing cadence across a selection sets the rhythm from the next review onwards rather than rewriting dates already in place.
If you want both — a new cadence and a fresh clock — do the bulk edit first, then use Mark Reviewed on the same selection. That stamps the review date and schedules the next one from the cadence you have set.
What else a multiple selection can do
Alongside the bulk editor, a multiple selection carries three commands. They act on every selected risk together.
| Command | What it does | Worth knowing |
|---|---|---|
| Mark Reviewed | Stamps today's review date on every selected risk and schedules the next one from each risk's cadence. | The fast way to close out a pass where nothing moved. A review that changes nothing is still a review. |
| Duplicate | Makes a copy of each selected risk. | Copies arrive as new rows at the top of the table, each with its own new reference. References are never reissued. |
| Close | Closes every selected risk. | Closing several asks you to confirm first. Risks are closed, never deleted. |
Duplicating across business units
Duplicate earns its place when the same exposure exists in several parts of the organisation and each part needs to own its copy. Duplicate the source risk as many times as you need, select the new rows — they pin to the top of the table, so they are easy to gather — then bulk-set the business unit and owner, and edit the titles individually. Each copy carries its own reference from the moment it is created.
Closing a group of risks
Closing is the end of a risk's active life, not its removal. A closed risk keeps its reference, its assessments and everything linked to it, and returns to the table whenever the show closed and accepted filter is on. The confirmation that appears when you close several at once is there to be read: check the count before agreeing to it.
Choosing the rows before you edit
The quality of a bulk edit is decided before the panel is touched. If the table holds exactly the rows that should change, the edit is checkable at a glance. If it holds forty rows of which six should not move, you are relying on your own scrolling.
Search reaches further than titles
Search runs across title, reference, category, owner, detail and tags at once, which makes it a selection tool rather than a lookup: search a supplier's name and you have every risk that mentions them anywhere in its detail, search an owner and you have their book of work.
Filters that narrow a selection
Three filters sit beside the search field: band, over-appetite only, and show closed and accepted. Over-appetite only is the sharpest for a bulk pass — it gives you precisely the risks exceeding their threshold, usually the group that needs a shorter cadence or a named owner. The filter icon fills in whenever a filter is active, so a surprisingly short table always has a visible explanation.
Save the view you keep rebuilding
When a combination of search and filters is one you return to, use Save Current Filter… and give it a name. The next time that group needs editing, the view comes back in one click rather than being reassembled from memory — and a view restored the same way every quarter can be trusted to hold the same rows.
What a bulk edit leaves alone
Knowing what will not move is as useful as knowing what will.
Unticked fields. Every field without a tick is left exactly as it was on each risk, individually. A risk with no business unit set keeps having none.
Ratings. Likelihood, impact, control effectiveness and targets are not among the fields RiskOS offers in bulk. A score is a judgement about one specific risk, made in that risk's Assessment section with the full context in front of you. If a group needs re-rating, Review is the place for it: it brings them forward one at a time, worst first, and shows the projected rating before anything is written.
References. A risk keeps the reference it was issued — RSK-0007 stays RSK-0007 through every category change, owner change and closure. References are never reissued, which is what lets a report from last year still point at something real.
Everything linked. Controls, actions, assets, vendors, indicators, events and the assessment history stay attached to their risks throughout.
Troubleshooting
The panel still shows one risk
Only one row is selected. A plain click replaces a selection rather than adding to it, so clicking after building one reduces it back to a single row. Hold ⇧ to extend to a run of rows, or ⌘ to add and remove rows without losing what you had.
I applied the edit and nothing changed
Check the ticks. Setting a value in the bulk editor is not the same as choosing to write it — the field also has to be ticked, and an unticked field is left alone no matter what value is showing beside it. Tick the field, confirm the value, and apply again.
Rows disappeared from the table after I applied
They are almost certainly filtered out rather than gone, and nothing RiskOS does in a bulk edit removes a row from the register. If you set status to closed or accepted while show closed and accepted was switched off, those rows leave the current view the moment they change. Turn that filter on and they come back, with their references and history intact.
I ticked the wrong field and applied it
Press ⌘Z. The whole bulk edit reverses as one action, across every risk it touched, and ⇧⌘Z reapplies it if you undo one step too far.
Some of the risks I recategorised are still flagged over appetite
Those risks carry their own appetite override. Appetite resolves in order: a risk's own override wins, then the category threshold, then the organisation-wide one. A risk with an override set in its own Appetite section is measured against that number regardless of which category it now sits in. Open the risk and turn the override off if the category threshold should apply instead.
I cannot find a way to delete several risks
There is not one, by design. Risks are closed rather than deleted, so the record of what you were once worried about survives, with its reference and its assessments. Close the selection instead, and confirm when asked.
Routines worth keeping
- Filter, then select, then edit. A selection made from a table that already holds the right rows can be checked at a glance; one assembled by scrolling is being trusted.
- Handle a handover the day it happens. Search the departing owner's name, select everything returned, tick owner, set the new name.
- Change cadence, then Mark Reviewed. The bulk edit sets the rhythm; Mark Reviewed sets the clock running from today at the new interval.
- Do one field at a time when the group is large. Two narrow passes are easier to verify than one wide edit across six ticked fields.
- Show the column you are about to change. Right-click the table header, switch it on, sort by it, and the result of the edit is visible in the table rather than taken on trust.
- Save the views you return to. Name the filter combinations you rebuild every quarter so the same group comes back the same way each time.
- Read the count before confirming a close. The confirmation exists to be read, and closing a group is a decision worth making on purpose.
Frequently asked questions
How do I edit multiple risks at once on a Mac?
Open the register, select several rows — click the first, hold Shift and click the last, or hold Command and click rows individually — and the panel on the right becomes a bulk editor. Tick the fields you want to change, set their values, and apply. RiskOS writes only the ticked fields, leaving everything else on each risk untouched.
Which fields can be changed across several risks?
Six: category, owner, business unit, status, treatment strategy and review cadence. These are the descriptive and procedural parts of a risk. Ratings are not included, because likelihood and impact are judgements about one specific risk and belong in that risk's own assessment or in a review pass.
What happens to fields I do not tick?
Nothing. An unticked field is not written at all, so each risk keeps the value it already had, including an empty one. That is why a value showing beside an unticked field is not applied — the tick is the instruction, not the value. It is what makes a change across fifty rows safe to make.
Can I undo a bulk edit?
Yes. Press Command-Z and the whole edit reverses as one action across every risk it touched, rather than one row at a time. Shift-Command-Z redoes it. This holds however many rows were in the selection, so an edit applied to the wrong group is a single keystroke away from being put back.
How do I reassign all of one person's risks to someone else?
Search their name. Search covers the owner field along with title, reference, category, detail and tags, so the results gather everything they hold. Select the rows, tick owner in the bulk editor, set the new name and apply. Check the Owner column afterwards by sorting on it.
Can I delete several risks at once?
Risks are closed rather than deleted, so there is no bulk delete. Select the rows and use Close; closing several asks you to confirm first. A closed risk keeps its reference, its assessment history and everything linked to it, and reappears in the table whenever the show closed and accepted filter is turned on.
Does changing a risk's category change its appetite threshold?
It can. Appetite resolves in order: a risk's own override first, then its category threshold, then the organisation-wide one. A risk without an override is measured against its new category's threshold as soon as the category changes, which may add or remove an over-appetite flag. Risks carrying their own override are unaffected.
Do bulk edits stay on my Mac?
Yes. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine. Edits are written locally as you make them, and the only way anything travels is when you export or back up the register yourself, to a location you choose.