Reporting & Branding

How to export a risk register to Excel on Mac

You can do this with RiskOS, a risk register for macOS. Seven sheets, built from the same snapshot as every other report, with the arithmetic still in them.

A board paper is read once. A workbook gets argued with. Somebody will always want to know what the top risk looks like if its likelihood moves from Likely to Possible, and the Excel output exists for that conversation: seven sheets with the arithmetic still in them, built from the same snapshot as the report you handed round.

Note

All four outputs are built from the same snapshot, so a workbook and a PDF produced in the same pass always agree.

Where the Excel export lives

Choose Reports in the sidebar, under Output. The page is a report builder rather than a list: cover fields at the top, a column of section toggles beneath them, a scope setting, and the four outputs at the end. Excel is one of those four, and it reads the same settings as the other three.

Nothing on this page alters your register. Switch sections on and off, export, change your mind and export again. The only thing that leaves RiskOS is the file you save.

Export the register as a workbook

  1. Open the Reports section

    Choose Reports in the sidebar, under Output. The builder opens on the report defaults held by the profile you are working in, so a monthly export is a matter of checking the settings rather than rebuilding them.

  2. Fill in the cover fields

    Set the report title, the organisation and prepared by. All three identify the export whichever output you produce, so the workbook you circulate and the PDF you print describe themselves the same way. Choose a title that will still mean something a year from now, such as Risk Register, Q3 2026.

  3. Choose the sections the workbook carries

    Switch on what the audience needs: executive summary, risk matrix, top risks, the full register, per-risk detail pages, controls, open actions, risk indicators, risk events and framework coverage. Each toggle is a decision about the reader. A workbook built for a treatment meeting rarely wants the same sections as one built for a board.

  4. Set how many top risks to carry

    Top risks takes a number between 3 and 50. Ten suits an executive audience; twenty-five suits a working session with the people who own the rows. Pick the number your readers will work through, not the number that looks thorough.

  5. Decide whether closed and accepted risks count

    The scope setting chooses whether closed and accepted risks are included. Leave it off when the question is where you stand today. Switch it on for an audit pass, a year-end summary or a handover, where the closed rows are the evidence that the register has been worked.

  6. Check which profile you are in

    If you keep more than one profile, glance at the switcher in the sidebar footer before you export, or cycle with P. A profile carries its own methodology, appetite, report defaults, client name and client logo, so it decides whose register you are exporting and whose name it goes out under.

  7. Choose Excel and save the workbook

    Choose Excel from the four outputs and pick where to save. Documents ▸ RiskOS is a sensible home if you want exports to accumulate somewhere predictable. Give the file a name carrying the date, so several months of exports sort themselves. RiskOS confirms the export with the filename it wrote, and a failed export says what to do next.

  8. Change a likelihood and watch the scores follow

    Open the workbook you have saved and change a likelihood on one of the rows. The formulas re-score themselves: the score that rating feeds moves, and the band that follows it moves too. That is what this output is for: a model of your register rather than a picture of it.

What each section adds

The section toggles are the whole of the decision. Anything you leave off is absent rather than hidden, so a workbook sent outside the organisation carries only what you meant it to.

The report sections and what each one contributes to an export
SectionWhat it contributes
Executive summaryWhere the register stands, for the reader who goes no further than the opening.
Risk matrixThe 5×5 grid with your risks placed on it.
Top risksThe number of rows you set, from 3 to 50.
Full registerEvery risk in scope with reference, owner, inherent, residual, target, trend, appetite, status and review date.
Per-risk detail pagesA full write-up for each risk rather than a single row.
ControlsType, status, effectiveness, owner and the number of risks each control carries.
Open actionsWhat is still to be done, with owner, priority, due date and the risk or control it belongs to.
Risk indicatorsEach indicator with its latest reading, its status against its thresholds and when it is next due.
Risk eventsWhat has happened: when it occurred, when it was detected, the severity as experienced and the cost.
Framework coverageRequirement by requirement: covered, mapped but not operating, or not mapped.
ScopeWhether closed and accepted risks appear at all.

What makes the workbook live

The Excel output keeps the working rather than only the answers. Seven sheets come out of a single export, and the formulas in them re-score when you change a likelihood, so a question asked in the room gets a consistent answer back.

What recalculates, and how to read it

A score is likelihood multiplied by impact on a 1 to 5 methodology, so it runs from 1 to 25, and the band is the shorthand that number falls into. Move a likelihood and both follow. Keep the bands in front of you while you model: what matters is a row crossing a boundary, not a row drifting a point.

The four severity bands and the scores they cover
BandScoreWhat a move into it signals
Low1–4Tolerable. Keep it under review and spend the attention elsewhere.
Medium5–9Worth treating where treatment is cheap, and worth watching for movement.
High10–16A named owner, a plan and a date. The band that fills most registers.
Critical17–25Escalate. The rows an executive summary exists to carry.

Ask the questions that come up in the room

The useful what-if is rarely abstract. Take RSK-0007, Backup restoration has never been tested end to end, at a residual of 15 against an appetite of 9. Somebody asks what a quarterly restore rehearsal would buy. Change the likelihood, read the score and the band, and the conversation moves from whether the number is right to whether the treatment is worth funding.

Change the register in RiskOS, not in the file

A workbook is a copy taken at the moment you exported it. Model in it freely. When a decision is made, make the change in RiskOS so it is recorded: the assessment is kept in History with its reason, every linked control, action and indicator stays attached, and the residual score chart shows the movement in context. Confirming or re-scoring the risk in Review then stamps the review date and schedules the next one from the risk's cadence. Re-export and the workbook agrees with the register again.

Four outputs, one snapshot

One set of cover fields, toggles and scope produces all four outputs, so they never disagree. Most people export two: one to read and one to interrogate.

The four report outputs and how to produce each one
OutputWhat you getHow to produce it
PDFPaginated A4 with a branded cover, a running header and footer, repeated table headers, and rows that never split across a page.P
HTMLOne self-contained file, with no scripts and nothing loaded from the internet.E
ExcelA live workbook of seven sheets whose formulas re-score themselves when you change a likelihood.Choose Excel in Reports
PrintExactly the PDF, sent to the printer.P

Branding and client work

Set Up Branding opens the header and footer designer: business name, tagline, address, phone, email, website and a registration or VAT line, along with a logo. Logos drop in as PNG, JPEG, PDF or SVG, with an optional variant for dark backgrounds. A live preview shows the real header and footer, so what you see there is exactly what exports and prints.

Export under a client's name

A profile dresses the whole of RiskOS for one client: its own methodology, risk appetite, report defaults, client name and client logo. Exports carry the client's prepared-for name and logo while your own identity stays primary, which is what a consultant wants on a deliverable. Methodology and appetite in a profile are snapshots, so after changing your organisation-wide settings use Update from Current Settings.

Troubleshooting

A section I expected is missing from the workbook

Its toggle was off when you exported. Go back to Reports, switch the section on and export again. Section toggles belong to the profile's report defaults, so a section turned off for a client's deliverable last month is still off for that profile today.

Risks I closed are not in the file

That is the scope setting doing its job. Closed and accepted risks are left out unless you include them, because most reports are about where you stand rather than what you have finished. Switch the scope on and re-export. Risks are closed and never deleted, so nothing has been lost.

I edited the workbook and the register did not change

The workbook is a copy, and modelling in it is meant to be consequence-free. Make the decision in RiskOS, whether that is re-scoring the risk, changing a control's status or closing an action, then export again. For a large set of changes, risks, controls, assets and vendors import from CSV with a preview showing line by line what will be created, updated or skipped.

The export did not complete

Read the message rather than retrying blind: a failed export says what to do next. The usual cause is a save location that cannot be written to, so try a plain destination such as Documents ▸ RiskOS or Downloads. A successful export always names the file RiskOS wrote, so a confirmation with a filename in it is your evidence that the workbook exists.

The report went out under the wrong name

Check the profile switcher in the sidebar footer. The profile you are in supplies the client name and logo that exports carry, and it is easy to build a report in one profile while thinking about another. Switch, confirm the cover fields, and export again.

A routine worth keeping

Exports are most useful when they are boringly regular.

  • Export the workbook and the report together. Produced in one pass, the file people interrogate and the file people read come from the same snapshot, and nobody reconciles two sets of numbers in a meeting.
  • Keep the sections stable month to month. A report whose shape changes every cycle cannot be compared with the last one. Settle the toggles and change them only when the audience does.
  • Name files by date. Something in the shape of Risk Register 2026-09-21 sorts itself and still reads unambiguously a year later.
  • Send the workbook to the people who will argue with it. Risk owners and finance want to move a number and see what happens. Keep the PDF for the readers who want the position stated.
  • Re-score in the app, not in the file. A rating changed in RiskOS is kept in History with its reason, so the next person can see what moved and why. A rating changed in a workbook is an opinion living in one attachment.
  • Back up before a heavy re-scoring session. File ▸ Back Up RiskOS… writes everything RiskOS holds to a single file wherever you choose, so an afternoon of changes is recoverable.

Frequently asked questions

How do I export a risk register to Excel on a Mac?

Choose Reports in the sidebar, fill in the report title, organisation and prepared by, switch on the sections you want, then choose Excel among the four outputs and pick where to save. RiskOS confirms the export with the filename it wrote. The same settings produce the PDF, HTML and printed versions.

What is in the Excel export?

Seven sheets, built from the same snapshot as every other output. What they carry follows the sections you switch on: executive summary, risk matrix, top risks, the full register, per-risk detail, controls, open actions, indicators, events and framework coverage, with a scope setting deciding whether closed and accepted risks appear.

Do the formulas in the exported workbook still work?

Yes. The workbook is live rather than flat: change a likelihood and the formulas re-score themselves, so the score and the band that follows it both move. That makes it useful for the what-if questions that come up in a meeting, without anyone overwriting a number and losing track of how it was reached.

Can I bring changes from the workbook back into my register?

Make decisions in the app, where the assessment is kept in History with its reason. For a large batch of changes, risks, controls, assets and vendors import from CSV, each with a preview that shows line by line what will be created, updated or skipped. Scores are never read from a file: RiskOS recalculates them.

Why do my report and my workbook show different numbers?

They were almost certainly exported at different moments, with a re-score or a control change in between. Outputs produced in the same pass share one snapshot and always agree. Export both again from the same settings and compare. Check too that the scope setting for closed and accepted risks matched on both.

Can I put my own logo on an exported risk report?

Yes. Set Up Branding opens a designer for the header and footer covering business name, tagline, address, phone, email, website and a registration or VAT line, plus a logo as PNG, JPEG, PDF or SVG with an optional variant for dark backgrounds. A live preview shows exactly what will export and print.

Is there a keyboard shortcut for exporting a risk report?

Shift-Command-E exports HTML, Shift-Command-P exports PDF and Command-P prints. The Excel workbook is produced from the outputs in the Reports section, alongside the other three. All four read the same cover fields, section toggles and scope, so whichever you reach for, the contents match.

Does anything leave my Mac when I export a report?

Only the file you save, to the place you choose. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine. The only network use is Apple's App Store, for purchases, and it never sees your register.