Profiles & Working on a Mac

How to keep a risk register private on Mac

You can do this with RiskOS, a risk register for macOS. No account to make, nothing to sync, and one network call you can name.

A risk register is among the most sensitive documents an organisation keeps. It names what could go wrong, how bad it would be, who is accountable, and which of those things has not been fixed yet — so where the document lives matters as much as what is written in it. RiskOS settles that question by never moving it anywhere.

Note

Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine.

Where the privacy promises live

Press , to open Settings, then choose Privacy. The promises are written out there in full, as sentences, so you can read them rather than take them on trust. Read it once before you type a single risk into the register. It tells you exactly which parts of keeping this information private are handled for you, and which parts remain yours.

The rest of the answer is visible by its absence. There is no sign-in screen when the window opens, no account item in the sidebar, no sync status anywhere in the interface, and nothing asking for an email address. Every section — from Profiles at the top to the Output group holding Reports, Import & Export and Settings — works the same whether or not the Mac is connected to anything.

Keep a register private, step by step

  1. Read the privacy promises in Settings

    Press , and open Privacy. Read what is stated there and decide whether it matches the obligations you are working under — a client contract, an internal classification policy, a regulator's expectation. Knowing the answer in advance is what lets you say yes quickly when somebody in procurement asks where the register is held.

  2. Choose where your backup file goes

    Use File ▸ Back Up RiskOS or press B. The backup is a single file, written wherever you tell it to go, and it carries everything: risks, history, the audit trail, controls, actions, assets, vendors, frameworks, indicators, events and settings. Because nothing is held anywhere else, that file is the whole register — so put it somewhere you would be comfortable keeping the register itself, such as Documents ▸ RiskOS. Give that file the same protection you give the register it holds.

  3. Set a backup reminder you will honour

    A quiet reminder appears when your last backup is getting old, and the interval is yours to choose: never, weekly, fortnightly or monthly. Pick the one that matches how often the register actually changes. A register reviewed quarterly does not need a weekly nudge; one being built out during an assessment does.

  4. Treat every export as a deliberate act

    Exports are the only way anything in the register moves. A report, a CSV of the register or a backup file exists because you asked for it, and from that moment it is an ordinary document you are responsible for. RiskOS confirms each export with the filename it wrote, so you always know what was produced and where it landed.

  5. Decide what a report carries before you send it

    Open Reports and work down the section toggles: executive summary, risk matrix, top risks, the full register, per-risk detail pages, controls, open actions, indicators, events and framework coverage. Switch off what the reader does not need. Per-risk detail pages in particular carry owners, treatment plans and history, which is right for an internal pack and often wrong for an external one.

  6. Check the scope as well as the sections

    Beneath the section toggles, scope decides whether closed and accepted risks are included. Closed risks are kept rather than deleted, which makes the record defensible over years — and also means a report set to include them reaches back further than the reader may expect. Set the top-risks count to the number the audience will actually read, anywhere from three to fifty.

  7. Keep each client in its own profile

    If you hold risk for more than one organisation, give each one a profile. A profile dresses the whole app for that client: its own methodology, risk appetite, report defaults, client name and client logo. Switch from the sidebar footer, or cycle with P, and the register in front of you is that client's alone.

  8. Know the one network call the app makes

    The only network RiskOS uses is Apple's App Store, and it uses it for one thing: purchases, such as unlocking the Small Business, Enterprise and Consultant profiles. That is a one-time purchase rather than a subscription, and the App Store never sees your register. There is nothing else to switch off, because there is nothing else being sent.

What RiskOS never does

Most privacy questions are answered faster by a list of absences than by a policy. This is the whole of it.

What RiskOS does not do, and what each absence means in practice
ThingIn RiskOSWhat that means for you
Account or sign-inNoneNothing to create, nothing to remember, and no credential that could be lost somewhere else.
Cloud syncNoneThe register is on this Mac. Moving it to another one is something you do, with a backup file.
Analytics or trackingNoneNo usage is measured, recorded or sent. What you look at in the window stays between you and the window.
AdvertisingNoneNo ads, and no profile of you being assembled to serve them.
ServersNoneThere is no copy of your register anywhere other than your Mac and the exports you make.
Network useApple's App Store, for purchasesThe one call the app makes, and it never carries any part of your register.

Why this matters when somebody reviews you

Due diligence questionnaires ask where data is processed, who the sub-processors are, how long information is retained and what happens on deletion. When the register never leaves the Mac it was typed on, most of those questions collapse into one sentence and a description of your own device controls — an answer you can give from memory, without waiting on anybody else.

Every way the register can leave your Mac

There are six, and you start all of them. Five write a file that behaves like any other document from the moment it exists; the sixth puts the same pages on paper.

The six export routes and what each one contains
RouteShortcutWhat it carries
PDF report⇧⌘PA paginated A4 document with your branded cover, header and footer, holding the sections you switched on.
HTML report⇧⌘EOne self-contained file that opens in any browser, with no scripts and nothing loaded from the internet.
Excel reportA workbook of seven sheets whose formulas re-score themselves when a likelihood is changed.
Print⌘PExactly the PDF, sent to the printer instead of to a file.
CSV exportThe register as plain rows, for whatever you need to do with it next.
Backup file⇧⌘BEverything the app holds, in one file, written where you choose.

All four report outputs come from the same snapshot, so a PDF and the workbook produced beside it always agree. The HTML file is worth singling out: it is genuinely self-contained, so the person who opens it fetches nothing from anywhere, and a file that loads nothing cannot report that it was opened.

Default filenames carry the date — Risk Register 2026-09-21 — which is helpful in your own folder and worth a second thought before the file is attached to an email.

Privacy when you hold other people's risk

Consultants and fractional risk managers carry a harder version of this problem: not one confidential register, but several, which must never appear in each other's reports. Profiles are the answer, and they are the first section in the sidebar.

What a profile separates

Each profile keeps its own methodology, risk appetite, report defaults, client name and client logo. Switching takes a keystroke, so there is no moment where one client's material is open beside another's while you reconfigure something. Methodology and appetite are held as snapshots, which is what stops a change made for one engagement drifting into another; when you do want a profile brought up to date, Update from Current Settings refreshes it deliberately.

Whose name goes on the export

Exports carry the client's "prepared for" name and logo while your own identity stays primary, which is the arrangement most engagements expect: your header, their cover. Set your own details once in Set Up Branding — business name, tagline, address, phone, email, website and a registration or VAT line, plus a logo, with an optional variant for dark backgrounds. The live preview shows the real header and footer, so what you see is what leaves the Mac.

What living on your Mac asks of you

The trade is honest and worth stating plainly. Nothing being uploaded also means nothing being kept for you elsewhere. If the Mac is lost and there is no backup, the register is gone, and there is no support queue that can produce a copy — because no copy was ever made.

So the one habit that matters is the backup. File ▸ Back Up RiskOS writes the lot to a single file; Restore from Backup… replaces the register with that file's contents, after telling you exactly what that means and asking you to confirm. Backups are versioned, so an older backup always restores into a newer app, while a file written by a newer version is refused outright rather than read halfway. Keep the backup somewhere you protect as carefully as the Mac itself, and moving to a new machine becomes a two-step job rather than a recovery project.

Troubleshooting

I cannot find where to sign in

There is nothing to sign in to. No account is created, none is required, and no part of the app is held back behind one. If you have bought additional profiles, those unlock through your existing App Store purchase rather than through a login in the window.

My register did not appear on my other Mac

Nothing syncs, by design, so a register typed on one machine stays there. Back up with B, carry the file across however you would carry any confidential document, then use Restore from Backup… on the second Mac. Restore replaces what is there, so read the confirmation before you agree to it.

A report included risks I did not mean to share

Two settings decide this and both sit in Reports. The section toggles decide which parts are built at all — per-risk detail pages are the ones that carry the most context — and the scope setting decides whether closed and accepted risks come along. Set both, then export again; the previous file is a finished document and will not change on its own.

Is the HTML report loading anything from the internet?

No. It is a single self-contained file with no scripts in it and nothing fetched from anywhere when it opens. That is why it can be read on a machine with no connection at all, and why sending one does not quietly tell you when the recipient opened it.

A backup file will not restore

Check which version of the app wrote it. A backup from an older version always restores. A backup written by a newer version is refused rather than partially read, because a half-restored register is worse than none. Update the app on this Mac, then restore.

The wrong client's logo is on my export

You are in the wrong profile. Check the switcher in the sidebar footer, or cycle with P until the register in front of you is the right one, then export again. The client name and logo travel with the profile, not with the report settings.

A routine that keeps it private

None of this needs a policy document. It needs six habits, most of which take seconds.

  • Back up on a schedule you chose. Set the reminder interval to match how fast the register changes, and put the file somewhere you would be content to keep the register itself.
  • Re-read the report toggles before every external send. The pack that suits your board is rarely the pack that suits a customer's procurement team.
  • Check the scope line as well as the sections. Including closed and accepted risks quietly widens what a reader can see.
  • Switch profiles before you open a client's work, not during it. One keystroke at the start of a session prevents the mistake that no export setting can undo.
  • Rename exports for their reader. The default filename carries the date, which is useful to you and occasionally more than a recipient needs.
  • Protect the Mac itself. With no copy held anywhere else, your device controls are the register's controls — worth writing down as a risk of its own.

Frequently asked questions

Does RiskOS store my risk register in the cloud?

No. There are no servers and no sync of any kind. The register lives on the Mac you typed it on, and the only copies that exist anywhere are the reports, CSV exports and backup files you create yourself. If you have not made one, there is no second copy — which is why the backup reminder exists.

Do I need an account to use RiskOS?

No. There is no sign-in, no registration and no email address to hand over. The app opens straight into the register. Additional profiles unlock through a one-time App Store purchase rather than a subscription or a login, and everything else is available from the moment you open the window.

Does RiskOS collect analytics or track what I do?

No. There is no tracking, no telemetry, no analytics and no advertising. Nothing measures which risks you open, how long you spend in a review or what your register contains. The promises are written out in full in Settings under Privacy, so you can read them for yourself rather than take them on trust.

What does RiskOS send over the internet?

One thing: purchases, handled by Apple's App Store, which is how the Small Business, Enterprise and Consultant profiles unlock. That call carries no part of your register, and it happens only when you buy something. There is no other network use to find, disable or audit.

How do I move my risk register to another Mac without the cloud?

Press ⇧⌘B to write a backup, move that single file across however you would move any confidential document, then choose Restore from Backup… on the second Mac. The backup carries risks, history, the audit trail, controls, actions, assets, vendors, frameworks, indicators, events and settings. Restore explains what it will replace and waits for you to confirm.

Is an exported HTML risk report safe to email?

It is a single self-contained file with no scripts and nothing loaded from the internet, so opening it fetches nothing and reports nothing back. Treat it like any other confidential attachment: check the section toggles and the closed-and-accepted scope before you export, so the file says only what you intend it to say.

Can I keep several clients' registers apart on one Mac?

Yes. Profiles separate them. Each carries its own methodology, appetite, report defaults, client name and client logo, and switching between them takes a keystroke from the sidebar footer. Exports carry that client's prepared-for name and logo while your own identity stays primary, so a report can never quietly arrive wearing the wrong badge.

What happens to my register if I stop paying?

There is nothing to stop paying — additional profiles are a one-time purchase, never a subscription. If you are working across more profiles than your current purchase allows, the extra ones are locked rather than deleted, and everything inside them is still there when you unlock them again. Your register is never held hostage.