How to import risks from CSV on Mac
You can do this with RiskOS, a risk register for macOS. Every line is shown as created, updated or skipped before a single row is written.
Most registers begin life somewhere else. A list a colleague kept, the rows typed up after a workshop, an export handed over at the end of an audit — the content is usually sound, and retyping forty risks by hand is nobody's idea of a morning. Importing takes the list as it stands, shows you exactly what it would do with every line, and waits.
The preview is not optional and it is not a summary. Every line of the file is listed with what will happen to it, and nothing is written to your register until you confirm.
Where importing lives
Choose Import & Export in the sidebar, under Output. That one section holds everything that moves data in or out: the CSV imports for risks, controls, assets and vendors, and the export that writes your register back out as CSV.
The import you want here is the one for risks. It reads your file, works out what each line means against the register you already have, and presents the result for inspection. Nothing changes while you are looking at it, so you can open the preview, read it, close it and come back with a better file as many times as you like.
Import a CSV, step by step
-
Back up before you start
Choose File ▸ Back Up RiskOS… or press ⇧⌘B, and save it somewhere you will find it again, such as Documents ▸ RiskOS. A backup covers everything — risks, history, controls, actions, assets, vendors, frameworks, indicators, events and settings — so an import that turns out to be wrong costs you nothing but the time it took.
-
Start from the template
Open the Examples folder that ships with RiskOS and take the risks template. Its headings are the fields the import knows how to read, so a file built on it needs no interpretation on your part. Paste your rows underneath, keep the heading row where it is, and save the result as CSV.
If reshaping the list you have been given would take longer than it is worth, import it as it stands anyway. The preview will name every column it could not use, which tells you precisely what to rename rather than leaving you to guess.
-
Put one risk on each row
A row is a risk. Give each one a title that names the event rather than the subject — Backup restoration has never been tested end to end rather than Backups — because the title is what everyone reads afterwards, and a vague one is the usual reason two people rate the same risk differently.
Fill in the likelihood and impact ratings if you have them, along with the owner, the category and anything else the template carries. Blanks are fine: a risk that arrives with a title and nothing else is still in the register, where you will see it and can rate it properly later.
-
Open the risks import
Go to Import & Export and start the import for risks. Choose your file, and the preview opens on its own. Nothing has been written at this point — the file has been read and interpreted, and the result is on screen for you to argue with.
-
Read the preview line by line
Every line of the file appears with the outcome it would produce: created for a risk that is new to the register, updated for one that matches something already there, and skipped for a line that cannot be brought in. Read the skips first, then the updates. The creations are rarely where the surprises are.
-
Check the projected scores
Each line carries the score it would produce, worked out from the ratings in the file rather than copied from it. This is the quickest test of the list you were given: if a risk you know to be serious is projected as Low, the ratings are wrong, and fixing them now is easier than re-rating thirty risks afterwards.
-
Read the problems and the ignored columns
Problems are named against the line that caused them, in plain language, so you are never told only that something failed. The preview also lists the columns it ignored, which is the honest way round: a column silently dropped is a field you would discover missing weeks later.
Most first attempts produce a short list of both. Close the preview, correct the file, and start it again. Nothing accumulates between attempts because nothing was written.
-
Confirm, then check the register
When the preview says what you expect, confirm the import. Then choose Risks and look at the new rows: they carry fresh references, issued in sequence and never reissued, and sorting by residual will put the ones that need attention at the top. Spend the next ten minutes on the risks that came in without an owner, because an unowned risk is the one nobody reviews.
What the preview is telling you
The preview exists because an import is the one operation that can change a whole register at once. Reading it properly takes two minutes and saves an afternoon. There are only three outcomes, and each one asks a different question of you.
| Outcome | What it means | What to check |
|---|---|---|
| Created | The line does not match anything in the register. A new risk will be added and given the next reference. | That it is genuinely new, and not a near-duplicate of a risk already recorded under a different title. |
| Updated | The line matches an entry already in the register. That entry will be changed rather than duplicated. | That you meant to overwrite it. An update replaces what was there with what the file says. |
| Skipped | The line cannot be brought in as it stands. It is left alone and nothing is written for it. | The problem named beside it. A skip is almost always a missing title or an empty line. |
Alongside the outcome, each line carries its projected score and any problems found in it, and the preview as a whole lists the columns it ignored. Those four pieces of information describe the entire import; nothing happens behind them that you cannot see before you agree to it.
How values are handled
Files that come from elsewhere are rarely tidy, and the handling is deliberately forgiving. What matters is that forgiving never means silent: wherever a value is adjusted, the line says so.
Out-of-scale ratings are clamped
Ratings run from 1 to 5 in both directions. A file offering a likelihood of 7, or a 0, is brought back inside the scale rather than rejected, and the preview names the adjustment. A whole column of out-of-scale ratings usually means the list was kept on a different scale, and the sensible response is to re-map it in the file rather than accept the clamp.
Unrecognised values fall back
Where a value is not one RiskOS recognises, it falls back to a sensible default and the line records what happened. A status spelled a way the register does not use, or a treatment strategy that does not match any of Mitigate, Accept, Transfer and Avoid, produces a risk that still arrives — with the fallback shown, so you can correct it in the panel or fix the file and import again.
Scores are never read from a file
This is the rule that matters most. A score column in your file is not copied in. RiskOS recalculates every score from the ratings, so the number in the register is always the product of a likelihood and an impact you can see, on the methodology your organisation has set.
The same applies to residual. It follows from the effectiveness of the controls a risk is linked to, or from a value set by hand in the panel, and it is recalculated rather than imported. Arithmetic done in one place is what lets a register explain itself in a meeting.
What an update replaces
Where a line matches an entry you already have, the values in the file are written over the values in the register. So an update is worth aiming narrowly: if the only thing changing is the owner, offer a file carrying the matching reference and the owner rather than a re-export of everything, and check those lines in the preview before you confirm.
The other CSV imports
Risks are rarely the only thing waiting to be brought in. Controls, assets and vendors each import from CSV too, and each one opens the same preview with the same three outcomes, the same named problems and the same list of ignored columns.
| Import | An existing entry is recognised by | Worth knowing |
|---|---|---|
| Controls | The control reference, such as CTL-0004. | Where an import changes a control's status or effectiveness, every risk relying on that control is re-scored. |
| Assets | The asset name. | Each asset shows the worst residual risk attached to it once the links are in place. |
| Vendors | The vendor name. | Vendors carry a criticality, an owner and a next review date, and the list counts overdue reviews. |
Order helps. Bring the controls in first if you have both, so they exist to be linked to; then the risks; then assets and vendors, which give the register its context. It is not compulsory, and the preview tells you the truth whichever way round you go.
Troubleshooting
The preview says a line will be skipped
Read the problem named beside it. A skip is nearly always a line with no title, a stray blank row at the bottom of the file, or a heading row that has been duplicated part-way down. Correct the file and run the import again; skipped lines write nothing, so there is no half-finished state to clean up.
I have ended up with duplicate risks
Two lists described the same risk in different words, so the register had nothing to match on and created both. Select the copies you do not want to keep — normally the rows the import created, which carry the higher references — and use Close. Risks are closed, never deleted, so the record and its history stay intact, and the closed rows drop out of the table until you switch on show closed.
The score in my file is not the score in the register
Scores are never read from a file. The register recalculates from the likelihood and impact on each row, using the methodology in Settings ▸ Methodology. If the numbers differ consistently, the list you were given was kept on a different scale or with a different band arrangement, and the ratings need re-mapping rather than the score.
A column I care about was ignored
The preview lists every column it ignored by name. Compare that list against the headings in the template from the Examples folder, rename yours to match, and import again. A column with no counterpart in the register — an internal project code, for example — has nowhere to land; put what it says into the risk's description instead, where search will find it.
Scores moved on risks that were not in my file
You imported controls. Where an import changes a control's status or effectiveness, every risk deriving its residual from that control is re-scored immediately. Open one of the risks that moved and look at History: the change is recorded there with the score it produced, so the movement can be explained rather than merely noticed.
I imported the wrong file
Use File ▸ Restore from Backup… and choose the backup you took before starting. Restoring replaces the register with the contents of that file, and you are told exactly what that means and asked to confirm before it happens. Backups are versioned, so an older one always restores; a file written by a newer version of RiskOS is refused rather than half-read.
Habits that keep imports clean
An import is not a one-off. Lists arrive from clients, from audits and from colleagues for as long as you keep a register, and a few habits make each one routine.
- Back up first, every time. ⇧⌘B before the import costs seconds and turns a bad file into an inconvenience rather than an incident.
- Import a handful before you import everything. Take five representative rows, run them through, look at the result in the register, and only then bring in the remaining hundred.
- Build from the template rather than fixing afterwards. Headings that already match mean a preview with no ignored columns, which is the state worth aiming for.
- Read the skips before the creations. The lines that will not come in are the ones carrying the information about your file.
- Treat imported ratings as drafts. Somebody else's likelihood was rated against their own window and their own anchors. Put the new risks through Review and rate them against yours.
- Give every new risk an owner. Select the ones that arrived without one and use the bulk editor to set an owner, a review cadence and a business unit in a single pass.
- Keep the source file. Store it beside your backups in Documents ▸ RiskOS for a few months, so that a question about where a risk came from has an answer.
Frequently asked questions
How do I import a list of risks into RiskOS?
Open Import & Export in the sidebar, start the risks import and choose your CSV file. A preview opens showing every line as created, updated or skipped, with its projected score and any problems found. Nothing is written until you confirm, so you can read it, close it, correct the file and try again.
What file format does a risk import need?
CSV, with a heading row and one risk on each line underneath. The simplest route is the risks template in the Examples folder, because its headings are already the fields RiskOS reads. Any CSV can be offered, though, and the preview names every column it could not use so you know what to rename.
Will importing overwrite the risks I already have?
Only where a line matches an entry already in the register, and the preview marks every one of those as an update before anything happens. Lines that match nothing are created as new risks. An update replaces the values it carries, so check the updated lines in the preview before you confirm.
Can I import risk scores from a file?
No, and that is deliberate. RiskOS recalculates every score from the likelihood and impact ratings, on the methodology your organisation has set. A score column in the file is not copied in. The preview still shows the score each line is projected to produce, so you can check the ratings before importing them.
What happens if my file has a rating outside the 1 to 5 scale?
It is brought back inside the scale rather than rejected, and the preview names the adjustment on that line. A whole column of out-of-scale ratings usually means the list was kept on a different scale, in which case re-map the column in your file before importing rather than accepting the clamp.
How do I undo an import?
Use File ▸ Restore from Backup… and choose the backup you took beforehand. Restoring replaces the register with that file's contents, and RiskOS tells you exactly what that means and asks you to confirm first. This is the reason to press ⇧⌘B before every import: it costs seconds and makes a bad file reversible.
Can I import controls, assets and vendors as well?
Yes. Each has its own CSV import with the same preview. Controls are matched on their reference, assets and vendors on their name, so a second import updates rather than duplicates. Where an import changes a control's status or effectiveness, every risk relying on that control is re-scored at once.
Does importing a file send anything anywhere?
No. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine. The file is read where it sits, the result is shown to you, and what you confirm is written to the register on your own Mac and nowhere else.