How to export a risk dashboard as HTML on Mac
Do it in RiskOS, a risk register for macOS. One file, no scripts, and nothing fetched while it is open.
A dashboard earns its keep the moment somebody who never opens the register can read it. That is the job the HTML export does: the written position, the matrix and the risks that matter, gathered into one file you can hand over, with every number exactly as it stood when you pressed the key.
The file is complete in itself. No scripts run inside it, nothing is fetched while it is open, and the person reading it does not need RiskOS on their Mac. It opens in any browser, on any machine, with the network off.
All four report outputs are built from the same snapshot, taken the moment you export. An HTML file and a PDF made one after the other will always agree, down to the last score.
Where the report builder lives
Choose Reports in the sidebar. It sits in the Output group, beneath Register, Signals, Inventory and Reference, alongside Import & Export and Settings. What opens is a description of the report rather than the report itself: the cover fields at the top, the section toggles under them, and the scope switch at the foot.
Nothing in that screen is specific to one format. You describe the report once — what it is called, who it is about, which sections it carries, whether closed risks count — and then choose how it comes out. That is why the PDF, the HTML file and the printed copy never disagree with one another.
Build and export the dashboard
-
Open the report builder
Choose Reports in the sidebar. Before you touch a toggle, make sure the register behind it is in the state you want reported: a risk you re-scored an hour ago is included, and one you have been meaning to close is included too.
-
Fill in the cover fields
There are three: the report title, the organisation the report covers, and prepared by. Write a title that will still mean something in a year — Risk dashboard, third quarter reads better six months later than Dashboard. These three fields are the first thing anybody who opens the file will see.
-
Switch on the three dashboard sections
Turn on executive summary, risk matrix and top risks. Those three are what makes a file a dashboard rather than a register: a written position, the picture of where everything sits, and the handful of rows the position rests on.
Set how many top risks to carry. Anywhere from 3 to 50 is allowed, and the lower half of that range is usually right: a list somebody reads to the end is worth more than a longer one they skim.
-
Decide what else earns its place
The remaining toggles are full register, per-risk detail pages, controls, open actions, risk indicators, risk events and framework coverage. For a dashboard, open actions and risk indicators usually pay their way, because both answer the question a summary provokes: what is being done, and is it working.
Leave per-risk detail pages off unless the file is meant to be read as a reference. They are the longest section by far, and they turn a dashboard into a document.
-
Set the scope
One switch decides whether closed and accepted risks are included. A dashboard is nearly always about live exposure, so leave it off and let the file show only what is still open. Turn it on when the audience needs the whole year, such as an annual pack that has to account for what was closed and why.
-
Add your branding
Choose Set Up Branding and fill in the header and footer: business name, tagline, address, phone, email, website and a registration or VAT line. Drop in a logo as PNG, JPEG, PDF or SVG, and add the dark-background variant if your mark needs one. The live preview shows the real header and footer, so what you approve there is what the exported file carries.
-
Export as HTML
Press ⇧⌘E. Choose where the file should go — somewhere you will find it again, such as Documents ▸ RiskOS — and give it a name that carries the date, so that this quarter's file never gets confused with last quarter's. RiskOS confirms the export by naming the file it wrote.
-
Open the file and read it through
Open it from wherever you saved it and read it as your audience will, from the top. Check that the cover says what you meant, that the matrix shows the spread you expect, and that the top risks list ends where you told it to. Reading the file once before sending it catches nearly every mistake worth catching.
What makes the file a dashboard
A dashboard answers three questions in order: where do we stand, what does that look like, and which rows are driving it. The executive summary gives the position in numbers — a register of twelve active risks with an average residual of 9.6 out of 25, four of them over appetite, three overdue for review, sixteen open actions of which three are late, and framework coverage of 7 of 28 on the Control Baseline.
The risk matrix turns that into a picture. Every risk lands in a cell, and the shape of the cluster says more in a glance than a column of numbers does in a page. The top risks section then names the rows: RSK-0007 Backup restoration has never been tested end to end at a residual of 15, RSK-0001 Ransomware encrypts primary file shares also at 15, RSK-0011 Supplier concentration in a single logistics partner at 12.
Colour is never the only thing carrying a band. Every band badge pairs its colour with a symbol and the written word, so a reader who cannot separate red from orange still reads Critical as Critical.
| Section | What it adds | In a dashboard |
|---|---|---|
| Executive summary | The position in numbers: counts, average residual, breaches, overdue work. | Always |
| Risk matrix | Every risk placed on the grid, by band. | Always |
| Top risks | The worst rows by residual score, 3 to 50 of them. | Always |
| Open actions | What is being done, by whom, and what is late. | Usually |
| Risk indicators | The measured numbers and whether they sit in tolerance. | Usually |
| Controls | What you rely on, with status and effectiveness. | Sometimes |
| Risk events | What actually happened, what it cost, how long it took to notice. | Sometimes |
| Framework coverage | Requirements covered, mapped but not operating, or not mapped. | For an audit audience |
| Full register | Every risk as a table row. | Rarely |
| Per-risk detail pages | A page for each risk, with its full assessment. | Rarely |
When HTML is the right output
Four outputs come from the same description, and they are built from one snapshot, so the choice is about how the file will be read rather than about what it says.
| Output | Shortcut | What it is | Reach for it when |
|---|---|---|---|
| HTML | ⇧⌘E | One self-contained file, no scripts, nothing loaded from the internet. | The file will be read on a screen, kept in a shared folder, or opened years from now. |
| ⇧⌘P | Paginated A4 with a branded cover, a running header and footer, and rows that never split across a page. | It goes into a board pack, an audit file or anything with page numbers. | |
| Excel | — | A live workbook of seven sheets whose formulas re-score themselves when you change a likelihood. | Somebody wants to work the numbers rather than read them. |
| ⌘P | Exactly the PDF, sent to the printer. | The meeting is in a room with paper on the table. |
Why self-contained matters
Everything the page needs sits inside the one file. There is nothing beside it to lose and nothing to download before it will display. Move it, copy it, leave it in a shared folder for two years, and it renders the way it did the day you made it.
It is also quiet. No scripts run and nothing is fetched while the page is open, so reading the file tells nobody that it was read. For a document naming your organisation's worst exposures and their owners, that is not a small property.
What HTML does not do
It has no pages. An HTML dashboard scrolls, which is the right behaviour on a screen and the wrong one for a document somebody has to cite by page number in a committee. When the audience needs pagination, a running header on every sheet and tables that keep their headers when they break, export the PDF with ⇧⌘P instead. Both come from the same snapshot, so you can produce them one after the other and be certain they match.
Exporting a dashboard for a client
If you carry a register for more than one organisation, a profile dresses the whole app for one of them: its own methodology, its own appetite, its report defaults, its name and its logo. ⌃⌘P cycles between profiles, and a switcher sits in the sidebar footer.
Exports made while a client profile is active carry that client's prepared for name and logo, while your own identity stays primary on the header and footer. The practical rule is to switch first and export second: confirm the switcher shows the right client before you press ⇧⌘E, and the file cannot come out addressed to the wrong organisation.
A profile's methodology and appetite are snapshots rather than live copies. If you have changed the scales or the appetite threshold since the profile was made, choose Update from Current Settings before exporting, so the file reports against the rules you are actually working to.
Troubleshooting
The matrix is missing from my file
Its section toggle is off. Return to Reports, switch risk matrix back on and export again. Every section in the file is there because its toggle was on at the moment you exported, so read down the list of toggles before each export and confirm the three dashboard sections — executive summary, risk matrix and top risks — are all on before you press the key.
Fewer top risks appeared than I asked for
The number you set is a ceiling, not a quota. A register of twelve active risks cannot fill a list of twenty, and closed and accepted risks are left out unless the scope switch says otherwise. Check the count in Risks against the number you asked for before assuming something went wrong.
Closed risks are showing up
The scope switch that includes closed and accepted risks is on. Turn it off and export again. It is worth remembering that risks in RiskOS are closed rather than deleted, so a register that has been running a few years holds far more closed rows than live ones, and including them can double the length of a file with no live exposure added.
My logo is not on the exported file
Open Set Up Branding and look at the live preview. The preview is the real header and footer, so if the logo is absent there it is absent in the file. Add the mark as PNG, JPEG, PDF or SVG, and if it disappears against a dark background, supply the dark-background variant as well.
I cannot find the file I exported
The confirmation names the file that was written, so start from that name and look in the folder you chose in the save sheet. Picking one home for exports — Documents ▸ RiskOS is as good as any — and always saving there removes the problem for good. If an export fails rather than completing, RiskOS says what went wrong and what to do about it.
Routines worth keeping
- Export at the end of the review, not before it. A dashboard produced the moment a review pass finishes reflects the decisions that were made in it, rather than the register as it stood the previous week.
- Date the filename. A sequence of quarterly dashboards that sorts itself into order is worth the two seconds it costs, and two files with the same name confuse a reader instantly.
- Make the pair when it matters. Press ⇧⌘E then ⇧⌘P for a file to read on a screen and a document to file, both from the same snapshot.
- Keep the section set stable. The same sections every quarter let a reader compare one file to the next. Changing what is in the file hides movement as effectively as changing the numbers.
- Read it once as the audience. Open the exported file and read the summary and the top risks as somebody who has never seen the register. Vague titles and empty owner fields show up immediately.
- Back up in the same sitting. An export is a picture of one day; File ▸ Back Up RiskOS… with ⇧⌘B preserves the whole register, its history and its audit trail behind that picture.
- Keep old exports. A folder of dated dashboards is the cheapest record you will hold of how the risk position moved, and each file opens on its own.
Frequently asked questions
How do I export a risk dashboard as an HTML file on Mac?
Choose Reports in the sidebar, fill in the report title, organisation and prepared-by fields, switch on executive summary, risk matrix and top risks, then press ⇧⌘E and choose where to save. RiskOS writes one self-contained file and confirms by naming it. Open it from that folder to check it before you send it on.
What does a self-contained HTML report mean?
It means everything the page needs is inside the single file you exported. There is no folder of images beside it, no stylesheet to lose and nothing to download before it displays. No scripts run inside it either, so the file behaves the same way on any Mac, in any browser, for as long as you keep it.
Can I open an exported risk report without an internet connection?
Yes. The file loads nothing from the internet, so it opens with the network off and renders exactly as it did when it was made. That also means it will still open years from now, when whatever was online at the time of the export has long since moved or disappeared.
What is the keyboard shortcut for exporting an HTML report?
⇧⌘E exports HTML. Two others sit beside it: ⇧⌘P exports the PDF and ⌘P sends that same PDF to the printer. All three build from the same snapshot of the register, so producing more than one in a row gives you files that agree with each other exactly.
Why does my HTML dashboard look different from the PDF?
The content is identical; the shape is not. HTML is one continuous page that scrolls, which suits reading on a screen. The PDF is paginated A4 with a branded cover, a running header and footer on every page, repeated table headers and rows that never split across a page break. Choose by how it will be read.
Can I put a client's name and logo on an exported dashboard?
Yes, through profiles. A profile holds a client's name, logo, methodology, appetite and report defaults, and ⌃⌘P cycles between them. Export while that profile is active and the file carries the client's prepared-for name and logo, with your own identity still primary in the header and footer.
How many top risks can a report include?
Between 3 and 50. The number is a ceiling rather than a quota, so a register with fewer live risks than that lists only what it has. For a dashboard, a shorter list usually works better: the section exists to name the rows behind the summary, not to reproduce the register.
Does anything leave my Mac when I export a dashboard?
Only the file you asked for, to the folder you chose. There is no account, nothing is uploaded, and your register never leaves the machine until you export or back it up yourself. The exported file is equally quiet: it fetches nothing while open, so reading it tells nobody that it was read.