How to export a risk report as PDF on Mac
You can do this with RiskOS, a risk register for macOS. A paginated, branded document with a running header, ready for the board pack.
A board pack is read on paper as often as on screen, and it is read quickly. The document you hand over has to carry the register's numbers on its own, in a form a reader can follow without stopping to ask what a figure means. That is the job a PDF does: one paginated file, branded as yours, that says the same thing in the meeting as it said the moment you exported it.
All four report outputs are produced from one snapshot of the register, so the PDF you circulate and anything else you export alongside it always agree with each other.
Where the report builder lives
Choose Reports in the sidebar, under Output. The whole document is assembled on one screen: the cover fields sit at the top, the section toggles beneath them, the scope choice after that, and the export controls at the end. Nothing is hidden behind a wizard, so you can read the shape of the finished document before you produce it.
There is no separate template to pick. The report is defined by what you switch on, and RiskOS lays the rest out for you: page size, headers, table breaks and the order sections appear in.
Export a risk report as PDF, step by step
-
Open the report builder
Choose Reports in the sidebar. The builder opens with the cover fields ready to fill in. If you have several client profiles, check the switcher in the sidebar footer first, because the report is built from the profile you are currently in.
-
Fill in the cover fields
Set the report title, the organisation the report is about, and prepared by. These three lines carry the cover page, so write them the way you want them read aloud: Quarterly Risk Report rather than risks q3 final v2.
-
Set up your branding
Open Set Up Branding to design the header and footer. You can enter a business name, a tagline, an address, a phone number, an email address, a website and a registration or VAT line, and add a logo as PNG, JPEG, PDF or SVG. Add the optional variant for dark backgrounds if your mark needs one.
A live preview shows the real header and footer as you type. What the preview shows is exactly what exports and prints, so there is no need to produce a document to find out whether the logo sits right.
-
Choose which sections to include
Switch on the sections the reader needs: executive summary, risk matrix, top risks, full register, per-risk detail pages, controls, open actions, risk indicators, risk events and framework coverage. Each toggle is independent, so a short executive paper and a full audit pack are the same builder with different switches.
-
Set how many top risks to list
The top risks section takes a number between 3 and 50. Ten is a comfortable reading length for a board; a working group reviewing a whole portfolio may want more. The number sets the depth of the cut rather than picking individual rows, so nobody has to defend why a particular risk was left out.
If the register is small, a high number and the full register section produce much the same document. Pick the smaller figure when the pack has to be read in the room, and switch on the full register when the reader needs every row in front of them.
-
Decide what the scope covers
Choose whether closed and accepted risks are included. Leave them out for a report about what is live, and switch them in when the document has to account for every decision taken in a period. A year-end pack usually needs the accepted rows visible rather than quietly absent.
-
Export the PDF
Press ⇧⌘P, or use the export control at the foot of the builder. RiskOS asks where the file should go — a folder such as Documents ▸ RiskOS keeps packs together — and suggests a name you can accept or edit. Default names carry the date, as in Risk Register 2026-09-21, which keeps successive packs in order without anyone inventing a numbering scheme.
When the file is written, RiskOS confirms with the filename. If an export cannot be completed, the message says what to do next rather than leaving you with a half-written document.
-
Read the document before you send it
Open the PDF and check four things: the cover reads the way you meant it, the running header and footer appear on every page, long tables repeat their column headings after each break, and the page count is what you expected.
What each section puts in the document
Every toggle adds a defined block, so two reports produced a quarter apart carry the same sections in the same shape and can be laid side by side. Switch on only what the reader will use.
| Section | What it adds | Best for |
|---|---|---|
| Executive summary | The register's headline position in a page | Every pack |
| Risk matrix | The grid, with risks placed on it | Board and committee |
| Top risks | The highest-rated risks in scope, 3 to 50 of them | Board and committee |
| Full register | Every risk in scope, as a table | Audit and working groups |
| Per-risk detail pages | A page per risk with its full record | Deep reviews, evidence packs |
| Controls | What you rely on, with status and effectiveness | Assurance and audit |
| Open actions | Outstanding treatment work | Operational follow-up |
| Risk indicators | Measured numbers against their thresholds | Monitoring reports |
| Risk events | What actually happened, and the lessons | Period and incident reviews |
| Framework coverage | Requirements covered, mapped but not operating, and not mapped | Certification and audit |
A shape that suits most boards
Executive summary, risk matrix and top risks at ten, with closed and accepted risks excluded, produces a document a committee can read in the meeting rather than before it. Keep the full register and the per-risk detail pages for the audit version of the same pack.
How the pages are laid out
Pagination is the part of a report that people only notice when it fails. RiskOS sets A4 and handles the breaks itself, which is why the same register produces the same clean document every quarter without anyone nudging a table.
The cover page
The cover carries your branding along with the report title, the organisation and the prepared-by line you typed. It is the page that gets forwarded and pinned to a minute, so the title is worth a moment's thought.
The running header and footer
The header and footer you designed appear on every page, not only the first. A page separated from its pack still says where it came from, who produced it and when — which is precisely what an auditor or a committee secretary needs from a loose sheet.
Tables that cross a page break
Long tables repeat their column headings at the top of each new page, and a row is never split across a break. A register row that begins on one page finishes on that page, so nobody reads a residual score against the wrong risk.
Branding, and whose name goes on it
Branding is set once and reused by every export and every print. The designer covers the identity that appears on the document, and the live preview means you are never guessing.
| Field | What it is for |
|---|---|
| Business name | The organisation producing the report |
| Tagline | A short line of positioning or department name |
| Address | A postal address for formal documents |
| Phone & email | How a reader reaches the author of the pack |
| Website | Your public address |
| Registration or VAT line | The statutory line many jurisdictions expect on issued documents |
| Logo | PNG, JPEG, PDF or SVG |
| Dark-background variant | An alternative mark for use on a dark ground |
Reports produced for a client
If you keep a profile per client, the export carries that client's prepared for name and logo while your own identity stays primary. A profile also holds its own methodology, appetite and report defaults, so switching client before you export changes the shape of the pack, not only the logo. Update from Current Settings refreshes a profile's methodology and appetite snapshots.
Choosing the PDF over the other outputs
The builder produces four things from the same snapshot, so they never contradict one another. The PDF is the one to reach for when a document is going to be read, filed or tabled rather than worked on.
| Output | Shortcut | Reach for it when |
|---|---|---|
| ⇧⌘P | The pack is being circulated, tabled or filed as a record | |
| HTML | ⇧⌘E | You want one self-contained file, with no scripts and nothing loaded from the internet |
| Excel | — | Someone needs a live workbook whose formulas re-score when a likelihood changes |
| ⌘P | You need the same document on paper, straight away |
Troubleshooting
The report is far longer than I expected
Per-risk detail pages are the usual cause: they add a page for every risk in scope, so the length of that section follows the size of the register. The full register, and a scope that includes closed and accepted risks, lengthen the document further. Switch the detail pages off for a board pack and keep them for the evidence version.
My logo disappears on the dark header
Add the optional dark-background variant in Set Up Branding. A single-colour mark designed for white paper often vanishes on a dark ground, and the variant exists so you do not have to compromise the version that works everywhere else. The live preview shows which one is in use.
The report shows a client name I did not type
You are in a client profile. Each profile carries its own client name and logo, and exports use them for the prepared for line. Check the switcher in the sidebar footer, or press ⌃⌘P to cycle to the profile you meant to be in, then export again.
A risk is missing from the report
Check the scope first: closed and accepted risks are only included when you ask for them. Then check the top risks number, if that is the only section you switched on — a top-ten list stops at ten however many risks sit below it. Switch on the full register to see everything in scope.
The PDF and an older export disagree
Each export is a snapshot of the register at the moment you produced it. One made last month reflects last month's scores, which is exactly what a filed record should do. When two documents are compared in a meeting, check the dates on their covers before anyone reconciles a number.
The export did not finish
RiskOS confirms every successful export with the filename it wrote, and when one cannot be completed it says what to do next rather than failing quietly. Check the destination you chose, then export again.
Routines that keep the report honest
A reporting habit is worth more than one perfect document. These hold up over years of packs.
- Set branding once, at the start. Every export and printed copy uses it afterwards, so time spent on the header and footer pays back on every document you produce.
- Keep two configurations in mind. A short board pack and a long audit pack are the same builder with different toggles; produce both from the same snapshot when a meeting needs the summary and the evidence.
- Review before the pack, not after. Review walks the risks that are due, worst first, so the report reflects current ratings.
- Lead with the exceptions. Risks above appetite are flagged everywhere they appear, which makes the executive summary and top risks the two sections worth switching on first.
- Name files by date, not by version. The suggested name already carries one. Risk Register 2026-09-21 tells a reader more in a year than final v3 ever will.
- File the PDF as the record. A paginated document with a running header survives being forwarded, printed and attached to a minute.
- Back up before a reporting cycle. File ▸ Back Up RiskOS… writes everything RiskOS holds to a single file, so the register behind the pack is recoverable as well as reportable.
Frequently asked questions
How do I export a risk report as a PDF on a Mac?
Choose Reports in the sidebar, fill in the report title, organisation and prepared-by fields, switch on the sections you need, then press ⇧⌘P. RiskOS asks where to save the file, suggests a name carrying the date, and confirms with the filename once the document is written.
What page size is the exported risk report?
A4. The document is paginated for it, with a branded cover, a running header and footer on every page, column headings repeated after each table break, and rows that never split across a page. Pagination is handled for you, so the same register produces the same clean document each time.
Can I put my company logo on the risk report?
Yes. Set Up Branding opens a header and footer designer covering your business name, tagline, address, phone, email, website and a registration or VAT line, plus a logo as PNG, JPEG, PDF or SVG. Add an optional variant for dark backgrounds. A live preview shows exactly what will export and print.
How many risks should a board report list?
The top risks section accepts any number from 3 to 50, drawn in residual order. Ten suits most boards: long enough to show the shape of the portfolio, short enough to be read in the room. Working groups reviewing a whole portfolio often want the full register instead.
Does the report include closed and accepted risks?
Only if you ask for it. The scope choice in the report builder decides. Leave closed and accepted risks out for a report about what is live, and switch them in for a year-end or audit pack that has to account for every decision taken in the period, including the ones to accept.
Will the PDF and the other exports show the same numbers?
Yes. All four outputs are produced from one snapshot of the register, so a PDF, a printed copy, a self-contained HTML file and a workbook exported together always agree. Documents produced weeks apart naturally differ, because each one records the register as it stood on the day.
Is anything uploaded when I export a report?
No. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine except in the file you export yourself, to the location you choose. The exported document contains only what you switched on in the report builder.
Can I produce a report branded for a client?
Yes. A profile dresses the app for one client, carrying its own methodology, appetite, report defaults, client name and client logo. Exports made in that profile carry the client's prepared-for name and logo while your own identity stays primary on the document. Switching profile takes a keystroke.