How to find overdue risk reviews on Mac
RiskOS puts a review date on every risk. Here is how to see which dates have passed, and which of those rows deserves the first hour.
A review date is a promise about attention: somebody agreed to look at this risk again, and named the month it would happen. Promises like that go stale quietly. A risk rated in March still reads as current in October, the Trend column still reads exactly as it did then, and the first person to notice is whoever asks the question in a meeting. Three parts of the register answer that question directly, and each suits a different moment.
Confirming or re-scoring a risk stamps its review date and schedules the next one from that risk's own cadence. Skipping leaves the risk completely untouched, so it stays in the next pass.
Where review dates live
Every risk carries two review fields in its panel, in the Summary section: a review cadence, which is how often you intend to look at it, and a next review date, which is when that falls due. The register table shows the second of those in its Review column, so the whole register can be read in date order on one screen. RiskOS keeps that date current for you: it moves forward on its own each time the risk is reviewed.
The other answer sits further down the sidebar. Review opens a guided pass over the register, and before it starts it offers four scopes, each with a live count beside it. The first is Overdue for review, and that number is the answer to this question with no sorting or filtering at all. The third place is quieter: controls, vendors and indicators keep review dates of their own, and a stale control is often the reason a risk rating is no longer true.
Find every overdue review, step by step
-
Show the Review column in the register
Choose Risks in the sidebar. If the Review column is not in the table, right-click any column header and switch it on. The same menu hides and reorders columns, and RiskOS remembers the arrangement, so this is a one-off piece of setup rather than something to repeat each quarter.
-
Sort the table by review date
Click the Review column header to sort on it. Every date that has already passed gathers at one end of the table in one unbroken block, instead of being scattered down the register among rows that are perfectly current. Click the header again to reverse the direction.
-
Take closed and accepted rows out of the view
Open the register's filters and leave show closed and accepted switched off, so the backlog you are counting is made only of risks that are still live. The filter icon fills in whenever any filter is active, which is worth a glance before you trust a number you have read off the screen.
-
Save the view you have built
Choose Save Current Filter… and name the combination something plain, such as Review backlog. Next month the same view comes back in one click, which matters more than it sounds: a pass that is rebuilt from memory each time quietly changes its own definition of what counts as late.
-
Read the live counts in Review
Choose Review in the sidebar. Four scopes appear — Overdue for review, Due within 30 days, Above appetite and All active risks — each showing how many risks it currently holds. Read the numbers before you start. They are the difference between a ten-minute pass and an afternoon you need to plan for.
-
Start the overdue pass
Select Overdue for review and begin. Risks arrive one at a time, worst first, with a progress bar showing how far through you are. Each one carries its owner, its actions, its linked controls and its last review on the same screen as the scoring inputs, so the judgement can be made without going to look anything up.
-
Confirm, re-score or skip each risk
If the rating still holds, press ⇧⌘↩ to confirm it. If it has moved, change the likelihood or impact — the projected rating updates live, before anything is written — then press ↩ to save and go to the next risk. ⌘→ skips the risk in front of you and ⌘← steps back to the previous one.
-
Read the summary at the end
The pass closes with a summary of what moved, risk by risk. A risk you skipped has not moved, so there is nothing for it to report: it keeps its old date and returns in the next pass. Read that summary before telling anyone the backlog is clear, and use it as the note of what changed and why.
What overdue actually means
A risk is overdue when its next review date has passed. That date is not typed in and forgotten; it is produced by the cadence you set, and it moves on its own every time the risk is properly looked at.
The cadence sets the next date
Set the review cadence in the risk's Summary section. When you confirm or re-score the risk, RiskOS stamps the review date and schedules the next one from that cadence, so a monthly risk reappears a month later without anyone maintaining a list. A risk whose cadence is wrong is the most common cause of a backlog that will not shrink: it comes due faster than anyone intends to look at it.
A confirmation is a real review
Most reviews end with nothing changing, and that is a result worth recording. A re-score that leaves the numbers where they were is kept as a confirmation, so the history shows that somebody looked on that date and agreed. A register in which only the changes are recorded cannot tell the difference between a stable risk and a neglected one.
Skipping is not a review
Skipping leaves the risk completely untouched — no stamp, no new date, no entry in the history. That is deliberate. Skipping is for the risk you cannot honestly assess this morning because the owner is away or the evidence is not in yet, and the register's job is to bring it back rather than quietly count it as done.
Clearing several at once
Some rows do not need a pass of their own. Select several risks in the table and choose Mark Reviewed, and each one is stamped and rescheduled from its own cadence. Keep this for rows you have genuinely considered together — a group of low risks in one category, looked at in a single conversation — rather than as a way of making a number go down.
Which overdue review to clear first
A backlog is rarely cleared in one sitting, so the order matters more than the total. Worst first is the order Review already uses, but severity is not the only signal in the register, and a few of the others are stronger evidence that a rating has drifted.
| Look for | Why it goes first | Where you see it |
|---|---|---|
| Overdue and above appetite | You have already said this level is more than you tolerate, and nobody has checked it since. | The over-appetite flag on the row, and the Above appetite scope in Review |
| Overdue and Critical or High | The rows a report leads with. Being out of date here is the version that gets noticed. | The band badge in the Inherent and Residual columns |
| A linked indicator in breach | Something you measure has already moved. The rating is the last thing to catch up. | Intelligence in the risk panel, and the Indicators table |
| A linked event since the last review | The risk has actually happened. That outranks any opinion about likelihood. | Intelligence in the risk panel, and the Events table |
| Overdue actions on the risk | The treatment is late as well as the review, so the residual figure may be optimistic. | The Overdue group in Actions, and the risk's own Actions section |
| The oldest date in the column | Age alone is a reasonable tiebreaker once the signals above are spent. | The Review column, sorted |
Start with what is over appetite
An overdue review on a risk that sits above appetite is the combination worth breaking a day for. RSK-0007, Backup restoration has never been tested end to end, is the shape of it: residual 15 against an organisation appetite of 9, an inherent score of 20 against a target of 4, and a quarterly restore rehearsal that is still only planned. Nothing about that row is a surprise, which is exactly why it drifts.
Let the evidence argue
Indicators and events exist so that a rating can be challenged between reviews. When a risk materialises more often than its likelihood implies, RiskOS says so and suggests what the observed frequency would justify, and the risk's panel shows that warning next to the rating it disagrees with. An overdue review on a risk carrying that warning is not a formality — the register is telling you the number is probably wrong.
Reviews that are not risk reviews
Risks are not the only entries with a date on them. A control that has not been checked in a year is still counted as reducing a risk score, and a vendor whose review lapsed is still linked to everything it brings. Each list carries its own dates, and each shows lateness in its own way.
| Section | Where the date sits | How lateness reads |
|---|---|---|
| Risks | Next review date in Summary; the Review column in the table | Counted live by the Overdue for review scope |
| Controls | Next review in the control's detail; the Review column in the table | Sort the column to bring the stale controls together |
| Vendors | Next review date on the vendor | The vendor list counts overdue reviews in its subtitle |
| Indicators | A measurement cadence and a Next Due column | An indicator that misses its cadence is marked overdue |
| Actions | A due date on each row | Late rows move to the Overdue group and carry a badge |
Why a stale control matters to a score
Only controls that are implemented or operating reduce risk. A control that was operating when it was last checked and has quietly lapsed since is still doing arithmetic on your behalf, and the risks deriving from it are reading lower than they should. Review the control, change its status or effectiveness, and RiskOS re-scores every risk that takes its effectiveness from it immediately, which is why the controls table deserves the same sorted pass as the register.
Indicators cover the gap between reviews
An indicator is a number you measure on a cadence, with a warning and a breach threshold. It is the cheapest form of review there is: a reading takes a value, a date and a note, and the threshold lines do the judging. An indicator that has missed its own cadence reads as overdue, and one that has never been measured reads as no data, which is not the same as being in tolerance.
Troubleshooting
I cannot see a Review column
It is switched off in the table's current arrangement. Right-click any column header and switch Review back on. The same menu reorders the columns, so you can put Review next to Status where a lapsed date is hard to miss, and RiskOS remembers the arrangement for the next time you open the register.
The overdue count and the table do not agree
The scope counts in Review cover active risks. The table shows whatever your filters allow, so a band filter, an over-appetite filter or a hidden group of closed rows will give you a different number. Check whether the filter icon is filled in, clear the filters, and count again before deciding which figure is wrong.
I looked at the risk but it is still overdue
The date moves when the review is recorded, not when the risk is opened. Confirm or re-score it in Review, or select it in the table and choose Mark Reviewed. If you moved through the risk with ⌘→, it was skipped, and a skipped risk is left exactly as it was.
The next review date is not where I expected
The next date is scheduled from the risk's cadence at the moment the review is recorded, so a risk on a monthly cadence returns a month later, not on the date it was originally due. If a whole group of risks is coming back too often, select them and set review cadence in the bulk editor; only the fields you tick are changed.
I had to leave in the middle of a pass
Go back to Review and carry on. The session survives leaving for another section, so you can open a risk in the register, check a control or look at an indicator's history and return to the same place in the queue with the progress bar where you left it.
Vendor reviews are late but Review says nothing
Review walks risks. Vendor reviews are counted in the subtitle of the vendor list, and control reviews live in the Review column of the controls table. Treat those as two short passes of their own; they are usually a handful of rows each, and they are where a risk score stops being true without anything appearing to change.
Keeping the backlog from forming
A backlog is a symptom. These few routines address the cause, and they cost less than the pass they save you.
- Give every risk a cadence the day you write it. A risk with no rhythm has no date, and a risk with no date never becomes anyone's problem until it becomes everyone's.
- Match the cadence to the band, not to the calendar. Critical rows that are reviewed at the same interval as Low ones produce either a backlog or a waste of everybody's morning.
- Run the overdue scope before the due-soon one. Clear what has already lapsed, then take Due within 30 days in the same sitting while the context is fresh.
- Keep a saved filter for the pass. The same view every month makes the backlog comparable between months, which is the only way to tell whether it is growing.
- Fix cadences in bulk when you notice a pattern. Select the group, tick review cadence in the bulk editor, set the value once, and leave every other field untouched.
- Let indicators carry the weeks in between. A measured number with thresholds will flag movement long before a review date comes round.
- Export after the pass, not before it. ⇧⌘P exports a PDF of the register as it now stands, carrying the review dates the pass has stamped.
- Back up when the pass is done. ⇧⌘B writes everything, including the history the pass has added, to a single file wherever you choose.
Frequently asked questions
How do I find risks that are overdue for review?
Choose Review in the sidebar. The first scope, Overdue for review, shows a live count of every active risk whose next review date has passed. For the same answer as a list, open Risks, show the Review column, and sort on it — the lapsed dates gather in one block at the end of the table.
What does overdue for review mean in RiskOS?
The risk's next review date has gone by. That date is set from the review cadence on the risk, and it moves forward each time the risk is confirmed, re-scored or marked as reviewed. Until one of those happens the risk stays in the overdue count, however recently somebody opened it to read.
Does skipping a risk in Review mark it as reviewed?
No. Skipping leaves the risk completely untouched: no review date is stamped, nothing is written to its history, and it appears again in the next pass. That is what makes skipping safe to use for a risk you cannot assess honestly today, without it disappearing from the backlog.
How do I mark several risks as reviewed at once?
Select the rows in the register and choose Mark Reviewed. Each risk is stamped with today's date and rescheduled from its own cadence, so risks on different rhythms do not end up bunched together. Use it for rows you have genuinely considered as a group rather than to reduce a count.
Can I see which controls and vendors are overdue for review?
Yes. The controls table has its own Review column, so sorting on it brings the stale controls together, and each control's detail holds its next review date. The vendor list counts overdue vendor reviews in its subtitle. Both are worth a short pass, because a lapsed control is still reducing risk scores in the meantime.
How often should a risk be reviewed?
Often enough that the rating could not have drifted unnoticed. In practice that means tying the cadence to the band: Critical and High rows on a short rhythm, Medium in the middle, Low on a long one. Anything above appetite deserves the shorter interval regardless of its band, because you have already said the level is more than you tolerate.
Does a review count if nothing changed?
Yes, and it should. A re-score that leaves the ratings where they were is recorded as a confirmation, with the date and the reason kept in the risk's history. That record is what separates a risk that is stable from one nobody has opened since the spring, and it is the first thing an auditor asks to see.
Is there a reminder when reviews fall due?
The register carries the dates rather than chasing you. Review shows a live count of what is overdue and what falls due within 30 days, and the Review column shows the same thing per risk. Open Review at a fixed point in your month and the counts tell you immediately whether anything needs the next hour.