Reporting & Branding

How to export a risk report as PDF on Mac

You can do this with RiskOS, a risk register for macOS. A paginated, branded document with a running header, ready for the board pack.

A board pack is read on paper as often as on screen, and it is read quickly. The document you hand over has to carry the register's numbers on its own, in a form a reader can follow without stopping to ask what a figure means. That is the job a PDF does: one paginated file, branded as yours, that says the same thing in the meeting as it said the moment you exported it.

Note

All four report outputs are produced from one snapshot of the register, so the PDF you circulate and anything else you export alongside it always agree with each other.

Where the report builder lives

Choose Reports in the sidebar, under Output. The whole document is assembled on one screen: the cover fields sit at the top, the section toggles beneath them, the scope choice after that, and the export controls at the end. Nothing is hidden behind a wizard, so you can read the shape of the finished document before you produce it.

There is no separate template to pick. The report is defined by what you switch on, and RiskOS lays the rest out for you: page size, headers, table breaks and the order sections appear in.

Export a risk report as PDF, step by step

  1. Open the report builder

    Choose Reports in the sidebar. The builder opens with the cover fields ready to fill in. If you have several client profiles, check the switcher in the sidebar footer first, because the report is built from the profile you are currently in.

  2. Fill in the cover fields

    Set the report title, the organisation the report is about, and prepared by. These three lines carry the cover page, so write them the way you want them read aloud: Quarterly Risk Report rather than risks q3 final v2.

  3. Set up your branding

    Open Set Up Branding to design the header and footer. You can enter a business name, a tagline, an address, a phone number, an email address, a website and a registration or VAT line, and add a logo as PNG, JPEG, PDF or SVG. Add the optional variant for dark backgrounds if your mark needs one.

    A live preview shows the real header and footer as you type. What the preview shows is exactly what exports and prints, so there is no need to produce a document to find out whether the logo sits right.

  4. Choose which sections to include

    Switch on the sections the reader needs: executive summary, risk matrix, top risks, full register, per-risk detail pages, controls, open actions, risk indicators, risk events and framework coverage. Each toggle is independent, so a short executive paper and a full audit pack are the same builder with different switches.

  5. Set how many top risks to list

    The top risks section takes a number between 3 and 50. Ten is a comfortable reading length for a board; a working group reviewing a whole portfolio may want more. The number sets the depth of the cut rather than picking individual rows, so nobody has to defend why a particular risk was left out.

    If the register is small, a high number and the full register section produce much the same document. Pick the smaller figure when the pack has to be read in the room, and switch on the full register when the reader needs every row in front of them.

  6. Decide what the scope covers

    Choose whether closed and accepted risks are included. Leave them out for a report about what is live, and switch them in when the document has to account for every decision taken in a period. A year-end pack usually needs the accepted rows visible rather than quietly absent.

  7. Export the PDF

    Press P, or use the export control at the foot of the builder. RiskOS asks where the file should go — a folder such as Documents ▸ RiskOS keeps packs together — and suggests a name you can accept or edit. Default names carry the date, as in Risk Register 2026-09-21, which keeps successive packs in order without anyone inventing a numbering scheme.

    When the file is written, RiskOS confirms with the filename. If an export cannot be completed, the message says what to do next rather than leaving you with a half-written document.

  8. Read the document before you send it

    Open the PDF and check four things: the cover reads the way you meant it, the running header and footer appear on every page, long tables repeat their column headings after each break, and the page count is what you expected.

What each section puts in the document

Every toggle adds a defined block, so two reports produced a quarter apart carry the same sections in the same shape and can be laid side by side. Switch on only what the reader will use.

The report sections and what each one contributes
SectionWhat it addsBest for
Executive summaryThe register's headline position in a pageEvery pack
Risk matrixThe grid, with risks placed on itBoard and committee
Top risksThe highest-rated risks in scope, 3 to 50 of themBoard and committee
Full registerEvery risk in scope, as a tableAudit and working groups
Per-risk detail pagesA page per risk with its full recordDeep reviews, evidence packs
ControlsWhat you rely on, with status and effectivenessAssurance and audit
Open actionsOutstanding treatment workOperational follow-up
Risk indicatorsMeasured numbers against their thresholdsMonitoring reports
Risk eventsWhat actually happened, and the lessonsPeriod and incident reviews
Framework coverageRequirements covered, mapped but not operating, and not mappedCertification and audit

A shape that suits most boards

Executive summary, risk matrix and top risks at ten, with closed and accepted risks excluded, produces a document a committee can read in the meeting rather than before it. Keep the full register and the per-risk detail pages for the audit version of the same pack.

How the pages are laid out

Pagination is the part of a report that people only notice when it fails. RiskOS sets A4 and handles the breaks itself, which is why the same register produces the same clean document every quarter without anyone nudging a table.

The cover page

The cover carries your branding along with the report title, the organisation and the prepared-by line you typed. It is the page that gets forwarded and pinned to a minute, so the title is worth a moment's thought.

The header and footer you designed appear on every page, not only the first. A page separated from its pack still says where it came from, who produced it and when — which is precisely what an auditor or a committee secretary needs from a loose sheet.

Tables that cross a page break

Long tables repeat their column headings at the top of each new page, and a row is never split across a break. A register row that begins on one page finishes on that page, so nobody reads a residual score against the wrong risk.

Branding, and whose name goes on it

Branding is set once and reused by every export and every print. The designer covers the identity that appears on the document, and the live preview means you are never guessing.

The branding fields available in the header and footer designer
FieldWhat it is for
Business nameThe organisation producing the report
TaglineA short line of positioning or department name
AddressA postal address for formal documents
Phone & emailHow a reader reaches the author of the pack
WebsiteYour public address
Registration or VAT lineThe statutory line many jurisdictions expect on issued documents
LogoPNG, JPEG, PDF or SVG
Dark-background variantAn alternative mark for use on a dark ground

Reports produced for a client

If you keep a profile per client, the export carries that client's prepared for name and logo while your own identity stays primary. A profile also holds its own methodology, appetite and report defaults, so switching client before you export changes the shape of the pack, not only the logo. Update from Current Settings refreshes a profile's methodology and appetite snapshots.

Choosing the PDF over the other outputs

The builder produces four things from the same snapshot, so they never contradict one another. The PDF is the one to reach for when a document is going to be read, filed or tabled rather than worked on.

The four report outputs, their shortcuts and what each is for
OutputShortcutReach for it when
PDF⇧⌘PThe pack is being circulated, tabled or filed as a record
HTML⇧⌘EYou want one self-contained file, with no scripts and nothing loaded from the internet
ExcelSomeone needs a live workbook whose formulas re-score when a likelihood changes
Print⌘PYou need the same document on paper, straight away

Troubleshooting

The report is far longer than I expected

Per-risk detail pages are the usual cause: they add a page for every risk in scope, so the length of that section follows the size of the register. The full register, and a scope that includes closed and accepted risks, lengthen the document further. Switch the detail pages off for a board pack and keep them for the evidence version.

My logo disappears on the dark header

Add the optional dark-background variant in Set Up Branding. A single-colour mark designed for white paper often vanishes on a dark ground, and the variant exists so you do not have to compromise the version that works everywhere else. The live preview shows which one is in use.

The report shows a client name I did not type

You are in a client profile. Each profile carries its own client name and logo, and exports use them for the prepared for line. Check the switcher in the sidebar footer, or press P to cycle to the profile you meant to be in, then export again.

A risk is missing from the report

Check the scope first: closed and accepted risks are only included when you ask for them. Then check the top risks number, if that is the only section you switched on — a top-ten list stops at ten however many risks sit below it. Switch on the full register to see everything in scope.

The PDF and an older export disagree

Each export is a snapshot of the register at the moment you produced it. One made last month reflects last month's scores, which is exactly what a filed record should do. When two documents are compared in a meeting, check the dates on their covers before anyone reconciles a number.

The export did not finish

RiskOS confirms every successful export with the filename it wrote, and when one cannot be completed it says what to do next rather than failing quietly. Check the destination you chose, then export again.

Routines that keep the report honest

A reporting habit is worth more than one perfect document. These hold up over years of packs.

  • Set branding once, at the start. Every export and printed copy uses it afterwards, so time spent on the header and footer pays back on every document you produce.
  • Keep two configurations in mind. A short board pack and a long audit pack are the same builder with different toggles; produce both from the same snapshot when a meeting needs the summary and the evidence.
  • Review before the pack, not after. Review walks the risks that are due, worst first, so the report reflects current ratings.
  • Lead with the exceptions. Risks above appetite are flagged everywhere they appear, which makes the executive summary and top risks the two sections worth switching on first.
  • Name files by date, not by version. The suggested name already carries one. Risk Register 2026-09-21 tells a reader more in a year than final v3 ever will.
  • File the PDF as the record. A paginated document with a running header survives being forwarded, printed and attached to a minute.
  • Back up before a reporting cycle. File ▸ Back Up RiskOS… writes everything RiskOS holds to a single file, so the register behind the pack is recoverable as well as reportable.

Frequently asked questions

How do I export a risk report as a PDF on a Mac?

Choose Reports in the sidebar, fill in the report title, organisation and prepared-by fields, switch on the sections you need, then press ⇧⌘P. RiskOS asks where to save the file, suggests a name carrying the date, and confirms with the filename once the document is written.

What page size is the exported risk report?

A4. The document is paginated for it, with a branded cover, a running header and footer on every page, column headings repeated after each table break, and rows that never split across a page. Pagination is handled for you, so the same register produces the same clean document each time.

Can I put my company logo on the risk report?

Yes. Set Up Branding opens a header and footer designer covering your business name, tagline, address, phone, email, website and a registration or VAT line, plus a logo as PNG, JPEG, PDF or SVG. Add an optional variant for dark backgrounds. A live preview shows exactly what will export and print.

How many risks should a board report list?

The top risks section accepts any number from 3 to 50, drawn in residual order. Ten suits most boards: long enough to show the shape of the portfolio, short enough to be read in the room. Working groups reviewing a whole portfolio often want the full register instead.

Does the report include closed and accepted risks?

Only if you ask for it. The scope choice in the report builder decides. Leave closed and accepted risks out for a report about what is live, and switch them in for a year-end or audit pack that has to account for every decision taken in the period, including the ones to accept.

Will the PDF and the other exports show the same numbers?

Yes. All four outputs are produced from one snapshot of the register, so a PDF, a printed copy, a self-contained HTML file and a workbook exported together always agree. Documents produced weeks apart naturally differ, because each one records the register as it stood on the day.

Is anything uploaded when I export a report?

No. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine except in the file you export yourself, to the location you choose. The exported document contains only what you switched on in the report builder.

Can I produce a report branded for a client?

Yes. A profile dresses the app for one client, carrying its own methodology, appetite, report defaults, client name and client logo. Exports made in that profile carry the client's prepared-for name and logo while your own identity stays primary on the document. Switching profile takes a keystroke.