Import, Export & Backups

How to export a risk register to CSV on Mac

RiskOS writes your whole register to one plain table, dated and saved where you choose. Here is what travels with it, and what does not.

Sooner or later the register has to leave the window. A snapshot for the quarter's papers, a working copy for a round of edits, a file to carry across to a new machine, or a record of exactly where things stood on the day an auditor asked. A CSV export answers all four: one plain table, every risk in the register, with the numbers as they were the moment you saved it.

Note

A CSV export is the register as a table. It is not a backup, and RiskOS does not treat it as one. Keep both habits: the export for sharing and editing, File ▸ Back Up RiskOS… for safety.

Where the CSV export lives

Choose Import & Export in the sidebar. It sits under Output, alongside Reports and Settings, and it gathers everything that moves information into or out of the register into one screen. Exports are on one side, imports on the other, so there is no hunting through the register itself for a control that only exists in one place.

Export the register, step by step

  1. Open Import & Export

    Choose Import & Export in the sidebar, under Output. Everything that moves data in or out is collected here, so you do not need to be in any particular part of the register before you start.

  2. Fill the gaps before you export

    A file is only as complete as the register behind it, and an empty field in the register is an empty cell in the file. Scan the table for rows with no owner, no category or no review date. Selecting several risks at once turns the panel into a bulk editor: tick the fields you want to set, choose their values, and apply them to every selected risk in one pass.

  3. Start the CSV export

    In Import & Export, choose the CSV export for the risk register. You are asked where to put the file before anything is written, so this is the point to change your mind without consequence.

  4. Choose where the file goes

    RiskOS asks where the file should go before it writes anything, so the folder is yours to choose. Pick one you will still be able to find in six months. Documents ▸ RiskOS is a reasonable home: keeping every export in one folder means the dated files line up in order and the history reads itself. Scattering them across Downloads and half a dozen other folders is how a register loses its trail.

  5. Keep the date in the filename

    The suggested name already carries the date, in the form Risk Register 2026-09-21. Change the rest if it helps — a client name, a quarter — but keep the date. A folder of dated files sorts itself into a chronology; a file called register final tells nobody anything three quarters later.

  6. Save, and read the confirmation

    Confirm the save. The export tells you the filename it wrote, so you know both that it finished and what to look for. If it cannot write the file, the message says what to do next rather than leaving you to guess — usually it is a folder that cannot be written to, and choosing another one is the whole fix.

  7. File it with the papers it belongs to

    An export nearly always exists for something: a board pack, an audit request, a handover. Put it with those papers on the day you make it, while you still remember which version it is.

  8. Take a backup as well

    Press B, or choose File ▸ Back Up RiskOS…. The CSV holds the register as a table; the backup holds everything RiskOS keeps — risks, history, the audit trail, controls, actions, assets, vendors, frameworks, indicators, events and settings — in a single file you can restore from later. The two jobs are different, and doing one does not cover the other.

What travels in the file

The export carries the register: one row for each risk, and a column for each thing the register knows about it. That is a wider table than the one on screen, because the table shows what is useful at a glance while the file carries what you have recorded.

The groups of fields a CSV export of the risk register carries
GroupWhat comes out with each risk
IdentityReference, title, description, category, subcategory and tags.
OwnershipOwner, business unit and status.
AssessmentInherent likelihood and impact, control effectiveness, onset velocity, detectability and any exposure amount.
OutcomeThe inherent, residual and target ratings, the band each falls in, the trend and whether the risk sits above appetite.
TreatmentStrategy — mitigate, accept, transfer or avoid — with the plan and its due date.
ReviewReview cadence and next review date.

Why the reference is the column that matters

Every risk carries a reference in the form RSK-0001, and a reference is never reissued. That makes it the one value in the file that identifies a row beyond argument. Titles get rewritten, owners move on and categories are reorganised, but RSK-0007 is the same risk it was last year. If you plan to bring the file back in, that column is the one to leave alone.

Empty fields export empty

Nothing is filled in for you on the way out. A risk with no owner produces an empty owner cell, and a dozen of those produce a file that looks careless to whoever opens it. Five minutes with the bulk editor before an export is worth an hour of explanation afterwards.

A CSV export is not a backup

This is worth being blunt about, because the two get confused and only one of them brings a register back. The export writes your risks as a table. The backup writes the whole register and everything that sits around it, and it is the only one of the two you can restore from.

How a CSV export and a backup differ
 CSV exportBackup
HoldsThe risk register, one row per risk.Risks, history, the audit trail, controls, actions, assets, vendors, frameworks, indicators, events and settings.
Made fromImport & ExportFile ▸ Back Up RiskOS… or ⇧⌘B
Comes back throughA CSV import, row by row, with a preview.Restore from Backup…, replacing the register wholesale.
Good forSharing, archiving a snapshot, bulk editing.Recovery, and moving everything to another Mac.
Reminds youNothing. It is on demand.A quiet reminder when the last backup is getting old.

Controls, actions, indicators, events, assets, vendors and framework mappings do not travel in a risk export, because they are not risks. Controls, assets and vendors each have their own CSV import, and a backup carries every one of them together.

The round trip: export, edit, import back

The most useful thing about a CSV export is that there is a way back. Export the register, make a set of changes that would be tedious one row at a time — a new owner across a department, a category rename, a batch of review dates — and import the file again. RiskOS matches what it can, shows you line by line what it intends to do, and waits.

Edit ratings, not scores

Change the likelihood and impact values, never the score. Scores are never read from a file: RiskOS recalculates every one of them from the ratings and the controls, on the way in, using your current methodology. A score typed into a file is ignored, which is exactly what you want — it means no number can enter the register without the arithmetic behind it.

Leave the identifying columns as they came out

Edit the fields you mean to change, and leave the rest of the row exactly as it was written. The reference and the title beside it are what the preview has to work with when it decides whether a line is a risk you already hold or a new one, and rewriting both in the same pass is how an update quietly becomes a second copy. If a title needs rewording, do that in the panel afterwards.

Read the preview before you commit

Every import is previewed, and the preview is not a formality. It shows, line by line, what will be created, updated or skipped, the score each row would end up with, any problems it found, and any columns it did not recognise. Out-of-scale values are clamped, unknown values fall back, and nothing is written until you say so.

Choosing the right output for the job

CSV is the right answer when the register needs to be a table: a snapshot to archive, or a working copy to edit in bulk and bring back in. When a person is the audience, a report is the better shape. Every report RiskOS produces is built from a single snapshot of the register, so the four outputs always agree with one another. Templates for the CSV imports ship in the Examples folder.

The available outputs and what each one is best for
OutputBest forShortcut
CSVThe register as a table: archiving a snapshot, or editing in bulk and importing it back.
ExcelA live workbook of seven sheets whose formulas re-score themselves when you change a likelihood.
PDFCirculation. Paginated A4 with a branded cover, a running header and footer, and rows that never split across a page.⇧⌘P
HTMLOne self-contained file that opens in any browser, with no scripts and nothing loaded from the internet.⇧⌘E
PrintExactly the PDF, sent to the printer.⌘P

Troubleshooting

I cannot find the file I exported

The confirmation names the file it wrote, and that name is the thing to search for. If you have lost it, exporting again costs nothing, because an export only reads the register and changes nothing in RiskOS. Choose Documents ▸ RiskOS this time and keep every future export there.

My controls and actions are not in the file

A risk export contains risks. Controls, actions, indicators, events, assets, vendors and framework mappings live in their own sections and are not rows in a risk table. Controls, assets and vendors have their own CSV imports; to carry everything at once, take a backup instead.

Half the columns came out empty

Those fields are empty in the register. Nothing is inferred on the way out. Select the rows that are missing something, use the bulk editor in the panel to set the owner, category, business unit, status, treatment strategy or review cadence in one pass, and export again.

I changed a score in the file and it was ignored

That is deliberate. Scores are never read from a file. Change the inherent likelihood and impact instead, and the score is recalculated from those ratings and from the effectiveness of the controls the risk relies on, under the methodology in Settings.

Re-importing created duplicates instead of updating

The lines did not match what was already in the register, so each one arrived as something new. The preview states, for every line, whether it will be created, updated or skipped, which makes a column of unexpected creations visible before you confirm. Where duplicates have already landed, select them in the table and use Close: risks are closed, never deleted, so the record and its history stay intact and the closed rows drop out of the table until you switch on show closed.

The export would not write

When an export cannot be written, RiskOS says what went wrong and what to do next rather than failing silently. In practice it is almost always the destination: a folder that cannot be written to, or one that is not available at that moment. Choose somewhere local, such as Documents ▸ RiskOS, and try again.

Routines worth keeping

  • Export on the day you review. A file made the day a review pass finishes captures the register at its most defensible, with the review dates freshly stamped and the scores agreed.
  • Keep every export in one folder. Dated filenames in a single place become a history of the register at no effort. Spread across three folders they become nothing.
  • Tidy before you export, not after. Owners, categories and review dates are quick to fill with the bulk editor and slow to explain when they are missing from a file somebody else is holding.
  • Back up on a schedule, export on demand. The backup reminder interval is yours to set — never, weekly, fortnightly or monthly — and the export is there for the moments something has to leave the app.
  • Round-trip in small batches. Import a handful of edited rows first, read the preview properly, then do the rest. A preview you actually read is worth more than a large import you trusted.
  • Keep the reference column sacred. It is the only thing that reliably says which risk a row is, and it is never reissued.

Frequently asked questions

How do I export a risk register to CSV on a Mac?

Choose Import & Export in the sidebar, under Output, and start the CSV export for the risk register. Choose a folder, keep the date in the suggested filename, and confirm. RiskOS writes every risk as a row and tells you the name of the file it created.

What fields are included in a CSV export?

Each risk comes out with its reference, title, description, category, subcategory and tags; its owner, business unit and status; the inherent likelihood and impact, control effectiveness, onset velocity, detectability and any exposure amount; the resulting inherent, residual and target ratings with their bands; the treatment strategy, plan and due date; and the review cadence and next review date.

Is a CSV export the same as a backup?

No. A CSV export is the risk register as a table. A backup, from File ▸ Back Up RiskOS…, holds risks, history, the audit trail, controls, actions, assets, vendors, frameworks, indicators, events and settings in one file, and it is the only one of the two RiskOS can restore from. Do both.

Can I edit the file and import it back in?

Yes, and that round trip is one of the main reasons to export. Edit the rows, then import the file again. Every line is shown as created, updated or skipped, with the score it would end up with, before a single row is written. Change the fields you mean to change and leave the reference and title as they came out, so each line is recognised as the risk it came from.

Why were the scores I edited in the file ignored?

Scores are never read from a file. RiskOS recalculates every score on the way in, from the likelihood and impact ratings and the effectiveness of the linked controls, under your current methodology. Edit the ratings and the score follows. It means no number can reach the register without the reasoning behind it.

Does the export include closed risks?

Risks in RiskOS are closed rather than deleted, so a closed risk is still part of the register and still carries its reference and its history. If your register contains closed rows and you are producing a file for a reader rather than for editing, say in the covering note which statuses are present so nobody counts them as live exposure.

How often should I export my risk register?

Export when there is a reason: at the end of a review pass, at a quarter end, before a bulk edit, or when somebody asks for the numbers. Exports are snapshots, not protection, so keep them on demand and let the backup reminder — never, weekly, fortnightly or monthly — look after safety separately.

Does my register leave my Mac when I export it?

Only in the file you create, and only to the folder you chose. There is no account and no sign-in, nothing is uploaded, and there is no tracking of any kind. Your register lives on your Mac, and the only network RiskOS uses is Apple's App Store, for purchases, which never sees your register.