How to find what needs attention on Mac
You can do this with RiskOS, a risk register for macOS. One card, three counts, and a short path from each of them to the work itself.
Most mornings a register has barely moved. Three or four things have, and the value of keeping one at all is knowing which three or four without reading twelve rows, four tables and a set of indicators to find out. RiskOS gathers the movement into a single card on the Dashboard: what has breached a threshold, what has passed its review date, and what was due and is not done.
Nothing on the card is a list you maintain. Every count is read from the register as it stands, so it is current the moment you open the Dashboard, and it falls as you do the work behind it.
Where the attention card lives
Choose Dashboard in the sidebar. It is the second section, directly under Profiles, and it gathers the shape of the register into a set of cards: how many risks are active, what the average residual score is, where those risks sit on the matrix, how much of your framework is covered. One of those cards is Needs Attention, and it is the one that reads as a to-do list rather than a measurement.
It gathers three counts. Indicators sitting in breach. Risks whose next review date has passed. Actions that are late and still open. Each count is a way into the section holding the rows behind it, so the card is the start of a short pass rather than a screen to stare at.
Everything on the Dashboard belongs to the profile you are working in. Switch profiles and the counts change with the register, because a client's overdue reviews are not yours.
Work the card, step by step
-
Open the Dashboard
Choose Dashboard in the sidebar and find the Needs Attention card. Widen the window until the cards sit comfortably side by side; RiskOS remembers the sidebar and panel widths you leave behind, so this is a one-off adjustment rather than something to redo each morning.
-
Read the three counts before you open anything
Read the card as a whole first, then the Dashboard around it. A register of twelve active risks might sit at an average residual of 9.6 out of 25, with four risks above appetite, three overdue for review and sixteen open actions of which three are late. That is the morning's work in one line, and it tells you whether this is a ten-minute pass or an afternoon.
-
Start with the breached indicators
Choose Indicators in the sidebar. The table arrives worst first and carries Latest, Status, Trend, Thresholds, Risks and Next Due for every measure you keep. A breach means the most recent reading has crossed the threshold you set in the direction you called bad — a restore test success rate at 72 %, say, or fourteen critical patches outstanding beyond their service level.
Open the indicator, read the history chart with its threshold lines drawn across it, and look at the risks it is linked to. A breach is the register telling you that a rating written months ago may no longer be honest.
-
Clear the overdue reviews in one pass
Choose Review and pick the Overdue for review scope, which carries its own live count. Risks arrive one at a time, worst first, with owner, actions, controls and last review on the same screen as the scoring inputs, and a progress bar showing how far through you are.
Use ⇧⌘↩ to confirm a rating that still holds and ↩ to save a change and move on. ⌘→ skips, and skipping leaves the risk completely untouched, so it stays in the next pass rather than quietly disappearing from the count.
-
Deal with the risks above appetite
Choose Risks and switch on the over-appetite only filter. The filter icon fills while a filter is active, so you always know the table is showing you a subset. What is left is every risk whose residual score sits above the threshold you said you would tolerate.
RSK-0007, Backup restoration has never been tested end to end, is the shape of it: a residual of 15 against an appetite of 9, six points over. RiskOS flags that wherever the risk appears. Being over appetite is rarely a rating problem. It is a treatment problem, and the answer is usually an action with a date on it.
-
Work through the overdue actions
Choose Actions. Every action across the register is here, grouped by due state — Just Added, Overdue, Due Soon, Later, No Due Date and Closed — with overdue rows carrying a badge and naming the risk or control they belong to. Work the Overdue group top down.
Each row edits in place, so status, priority, owner and due date all change without leaving the list, and the checkbox completes an action and strikes it through. An action that has slipped three times does not need a fourth date; it needs a different owner or a smaller scope.
-
Check the reviews that are not risk reviews
Choose Vendors and read the subtitle at the top of the list, which counts how many vendor reviews are overdue. Then choose Controls and sort by the Review column to bring the ones falling behind to the top. A control nobody has looked at for a year is still reducing risk in the register, which is the situation worth catching.
-
Save the view you will come back to
Once the risk table is filtered the way a weekly pass wants it — over appetite only, or a single band, or a search across one owner's rows — choose Save Current Filter… and name it. The combination comes back whole next week, which removes the small friction that turns a weekly habit into a monthly one.
What each signal means
The three counts are not interchangeable. They come from different parts of the register and they call for different responses, so it is worth being precise about what each one is actually claiming.
| Signal | Where it comes from | What it is telling you |
|---|---|---|
| Breach | An indicator's latest reading | Something you measure has crossed the line you drew. The world has changed, whatever the rating says. |
| Overdue review | A risk's next review date | Nobody has confirmed this rating since the date you said it should be confirmed by. |
| Overdue action | An action's due date and status | Work you committed to has not happened, so the reduction you were counting on has not arrived. |
Breached, warning and no data
An indicator carries a warning threshold and a breach threshold, and you tell RiskOS which direction is bad. Thresholds are inclusive and direction-aware, so a reading that lands exactly on the breach line counts as a breach, and a restore test success rate of 72 % reads as breached because low numbers are the ones you called bad. A warning is the earlier line, worth reading as a prompt rather than an alarm.
An indicator with no readings reads as no data, deliberately distinct from being in tolerance: a measure nobody has taken is not evidence of safety. Indicators that miss their cadence are marked overdue as well, so a number last recorded in March is not presented as current. Where a measure no longer applies, pause it from the list.
Overdue for review
Every risk carries a review cadence and a next review date, and the date is what the count reads. Confirming a rating or re-scoring it in Review stamps the review date and schedules the next one from the cadence, and a re-score that changes nothing is recorded as a confirmation. Mark Reviewed does the same for the rows you select in the table.
Overdue actions
An action counts as overdue once its due date has passed and it has not been completed. The Actions list groups by due state rather than by risk, which is the right grouping for a weekly pass: everything late sits in one place. The owner filter narrows the list to one person before a conversation, and the show-completed toggle brings closed work back into view.
Deciding what to do first
When all three counts are non-zero, order matters more than speed. The sequence below puts the signals that can change a rating ahead of the ones that only reflect it.
| Order | What you look at | Why it comes first |
|---|---|---|
| 1 | Breached indicators | Evidence that reality has moved. It may change a rating, which changes everything downstream. |
| 2 | Risks above appetite | These are the rows you have already agreed are beyond tolerance. They need a plan, not a discussion. |
| 3 | Overdue reviews | Ratings nobody has stood behind recently. One pass in Review clears them worst first. |
| 4 | Overdue actions | Commitments that have slipped. Re-date, reassign or close them honestly. |
| 5 | Vendor and control reviews | Slower-moving, but they decay quietly and nobody notices for a year. |
Do the whole sequence in one sitting rather than a piece a day: the counts only tell a clean story read together. Write the reason for anything you change into the risk while you are there, so the record still makes sense next quarter.
Attention that shows up inside a risk
Some warnings belong to one row and appear in the panel on the right rather than on the Dashboard. Each one names a disagreement inside the register, so they are worth recognising on sight.
The over-appetite flag
The risk panel header carries a flag when the residual score sits above the threshold that applies to this risk. Which threshold that is follows a fixed order: an override on the risk itself, then the category's threshold, then the organisation-wide one, then none at all. The Appetite section spells out which of those is in force and why, so a flagged risk never leaves you guessing where the number came from.
The control divergence warning
A risk can take its control effectiveness from its strongest operating control automatically, or hold a value you set by hand. When a hand-set value disagrees with the controls actually linked, RiskOS says so in the Controls section rather than quietly picking a side. It usually means a control was downgraded after the risk was last assessed, and the fix is a minute's work.
The underrated likelihood warning
When a risk has materialised more often than its likelihood rating implies, the Intelligence section says so and suggests what the observed frequency would justify. It needs at least two logged events across a full year first, which keeps it from reacting to a single bad month. The same section shows the live status of every linked indicator, so a breach is visible from inside the row as well.
Troubleshooting
The overdue count did not drop after my review session
Check how many risks you skipped. ⌘→ leaves a risk completely untouched — no review date, no assessment, no change at all — so a risk you were not ready to judge stays in the queue. The summary at the end of a session shows what moved, per risk.
Nothing is flagged and I do not believe it
Three settings quietly produce an empty card. A register with no appetite threshold set flags nothing as over appetite. Risks with no review cadence never fall due. And indicators with no readings show as no data rather than as a breach. Set the organisation threshold in Settings ▸ Appetite, give each risk a cadence, and record a first reading against every indicator.
A risk I fixed is still flagged above appetite
Look at the status of the control you added. Only controls that are implemented or operating reduce risk; a planned control, however strong it will be, reduces nothing yet. Open the control, set its status, and every risk deriving from it re-scores at once. If the residual still sits above the threshold, the comparison grid names the strength of control that would reach your target.
An action I completed still appears in the list
Ticking the checkbox completes an action and strikes it through, and completed work moves to the Closed group rather than vanishing. If closed actions are filling the list, switch the show-completed toggle off. If a completed action is still counted as overdue, check its status is set to Done rather than In Progress.
The Dashboard and the risk table disagree
Almost always a filter is on. The filter icon fills when any filter is active, including a saved one you brought back last week, and show closed and accepted changes how many rows the table holds. Clear the filters and the table agrees with the card again.
A weekly pass that keeps the card short
The card stays short when the work behind it is routine rather than heroic. A few habits carry most of that.
- Open the Dashboard first, every time. Reading the three counts before you open a single risk stops you spending the morning on the row you happened to remember.
- Give every risk a cadence. A risk with no review date is never overdue, which sounds restful and means it is invisible. A quarterly rhythm suits most rows, and something shorter suits anything sitting above appetite.
- Keep indicators few and real. Four measures you keep up with beat twenty that show no data, and each should be a number somebody already produces.
- Put a date on every action. An action with no due date sits in the No Due Date group forever and never reaches the card at all.
- Re-date honestly or close. Moving a due date twice is a plan changing. Moving it five times is a plan that was never real, and closing it is the honest record.
- Save the filter you use each week. Named filters make the pass a click rather than a rebuild, and the column arrangement you settle on is remembered as well.
- Finish with a backup. File ▸ Back Up RiskOS…, or ⇧⌘B, writes everything RiskOS holds to a single file you keep wherever you choose. A quiet reminder appears when the last one is getting old.
Frequently asked questions
How do I see what needs attention in my risk register?
Choose Dashboard in the sidebar and read the Needs Attention card. It gathers three counts: indicators sitting in breach, risks whose review date has passed, and actions that are late. Each one leads to the section holding the rows behind it, so a weekly pass takes a few minutes rather than a morning of hunting through tables.
What counts as an overdue risk review?
A risk is overdue once its next review date has passed without anyone confirming or re-scoring it. The date is set from the risk's review cadence, and confirming a rating stamps the review date and schedules the next one automatically. A re-score that changes nothing still counts as a confirmation, so agreeing with yourself is recorded properly.
Why does an indicator show no data instead of a status?
Because no reading has been recorded against it yet. RiskOS keeps that state separate from being in tolerance, since a measure nobody has taken is not evidence that anything is fine. Record a reading with its value, date and a short note, and the indicator takes a real status against your warning and breach thresholds from then on.
How do I find risks above appetite on a Mac?
Choose Risks in the sidebar and switch on the over-appetite only filter; the filter icon fills while it is active. Review mode offers the same set as a scope with a live count, which is the better route when you intend to re-score them. Risks above appetite are also flagged on the row, on the Dashboard and in every report.
What is the difference between a warning and a breach on an indicator?
Both are thresholds you set, and both are direction-aware, so the app knows whether high numbers or low numbers are the bad ones. The warning threshold is the earlier line: a prompt to look. The breach threshold is the one you said you would not cross. Thresholds are inclusive, so a value that lands exactly on the line counts.
Do closed risks still show as needing attention?
No. Closing a risk takes it out of the active register, and the review scopes count active risks only. Nothing is deleted: the row, its history and its assessments are all kept, and the show closed and accepted filter brings them back into the table whenever you need to look at what you decided and why.
Why has an action stayed overdue after I finished the work?
The row is probably still set to In Progress. Tick the action's checkbox, which completes it and strikes it through, or set the status to Done directly in the row. Completed actions move to the Closed group rather than disappearing, and the show-completed toggle controls whether they stay in view.
Does anything on my dashboard leave my Mac?
No. There is no account and no sign-in, nothing is uploaded, and there is no tracking or telemetry of any kind. Your register stays on your Mac and leaves it only when you export or back it up yourself. The only network use is Apple's App Store, for purchases, and it never sees your register.