Controls & Treatment

How to link a control to a risk on Mac

You can do this with RiskOS, a risk register for macOS. Connect the two from either side, and the residual score answers for itself.

A control that has never been attached to a risk is a good intention with a reference number. The link is what puts it into the arithmetic: once a risk knows what stands in the way of it, the residual figure stops being an assertion and becomes something you can show your working for. It takes seconds, and it is the edit that does the most work in a register.

Note

Only a control that is implemented or operating reduces a score. A planned control, however strong it will be once it lands, reduces nothing yet, and the panel says so rather than letting the number flatter you.

The relationship is held in two places and reads the same from both. Choose Risks in the sidebar and select a risk: the panel on the right carries a Controls section, below Treatment and Appetite. Inside it are a toggle for deriving effectiveness from linked controls, the list of everything linked with its status and effectiveness beside it, an unlink control on each row, and a picker that links an existing control or creates a new one.

Choose Controls and you are at the other end of the same connection. The table carries a Risks column counting how many risks each control is attached to, alongside its reference, type, status, an effectiveness meter, owner and next review date. A control sitting at zero is doing nothing for the register yet, whatever its effectiveness says.

  1. Open the risk you want to reduce

    Choose Risks in the sidebar and click the row. Search covers title, reference, category, owner, detail and tags, so either RSK-0007 or a word from the title will find it. The panel on the right fills with that risk.

  2. Open the Controls section

    Scroll the panel to Controls and open it. Anything already linked is listed with its status and effectiveness on the row, so you can see whether the risk relies on things that are in place or on things somebody still intends to build.

  3. Open the picker and choose the control. It joins the linked list at once, carrying its status and effectiveness with it, and the count on the Controls table goes up by one. Link everything the risk genuinely depends on, not only the strongest one: the list is the record of what you would lose if a control were withdrawn.

  4. Create the control if it does not exist yet

    The same picker will create one, so a control you think of mid-assessment does not have to wait. Give it a name that says what it does — Immutable offsite backups reads better in a report than an acronym. Open Controls later to finish the detail: description, type, owner, next review date and evidence notes.

  5. Set the status so the control counts

    A control stays Planned until it is genuinely in place; once it is implemented or operating it begins to reduce risk. This is the step people miss. CTL-0003 Quarterly restore rehearsal can be rated High and still move nothing while it is planned, and the panel says so.

  6. Record how effective the control really is

    Open the control and set its effectiveness. Each level carries a written descriptor, so you choose a described strength rather than a bare number, and the same value appears as the meter in the Controls table. Rate what the control does in practice, not what it was designed to do.

  7. Switch on derive from linked controls

    Back in the risk's Controls section, turn on the derive toggle. The risk now takes its control effectiveness from the strongest linked control that is implemented or operating, and keeps following it as that control changes. Nothing about the residual score is typed in by hand from here on.

  8. Read what the score does next

    The residual figure updates, and the matrix in Assessment glides its residual marker to the new cell, so the distance from inherent is visible rather than described. The comparison grid shows inherent, residual, target and the gap, with a line telling you what strength of control would close it. The change is written into History.

Linking is not a filing decision. It is the input to the residual score, and RiskOS always shows which control produced the number. Where the reduction lands is set once for the whole register in Settings ▸ Methodology: controls can reduce likelihood, impact or both. Change that choice and every risk re-scores at once.

Only live controls count

Status is the gate, and this is the whole of it.

How control status affects a linked risk
StatusReduces the score?What the risk shows
PlannedNoListed on the risk with its intended effectiveness, contributing nothing yet.
ImplementedYesCounts from the moment the status changes, and the risk re-scores.
OperatingYesThe usual state for a control you rely on day to day.
RetiredNoStays on the record and in history; hidden from the list until you show retired controls.

The strongest control sets the pace

When several controls are linked, the risk follows the strongest one that is live. Two moderate controls do not add up to a strong one, and that is deliberate: stacking effectiveness would let a register talk itself down to Low on a pile of half-measures. Link them all for the record, and strengthen the best one when you want the number to move.

The limits the arithmetic keeps

RiskOS keeps three rules whatever you link. A residual score never rises above the inherent score, because a control cannot make a risk worse than it would have been unopposed. It never falls below 1, because nothing is eliminated entirely. And a stronger control never raises a score.

Derived effectiveness, or a value you set

The derive toggle is a choice between a number that maintains itself and one you own. Most registers are better off deriving, but there are honest reasons to set a value by hand: an arrangement you have not written up yet, or a control that works better for this particular risk than its general rating suggests.

Where control effectiveness comes from
SettingWhere the value comes fromWhat you see
Derive switched onThe strongest linked control that is implemented or operating.The value follows that control, and the risk re-scores whenever it changes.
Derive switched offThe effectiveness you choose on the risk itself.Linked controls are still listed, still counted and still reported.
Off, and the two disagreeYour value stands.A divergence warning in the Controls section naming the difference.

When the two disagree

The warning is not an error and does not overrule you. A hand-set figure that has drifted from the evidence is the thing an auditor finds first, so the register surfaces it rather than hiding it. Either switch deriving back on, or write the reason for your figure into the risk description.

Unlinking a control

Unlink from the row in the risk's Controls section when the risk no longer depends on it. Nothing is deleted: the control keeps its own record, its evidence and its actions, and only the connection goes. If deriving is on and the control you removed was the strongest live one, the residual score rises to reflect what you are left with.

One control, many risks

Controls are rarely single-purpose. Endpoint detection reduces ransomware, data loss from a stolen laptop and a good deal in between, so link it to every risk it genuinely touches. The Risks column then tells you how much weight each control carries, which is worth knowing before anyone proposes removing one.

Linking widely means a single edit travels. Change a control's status or effectiveness and every risk deriving from it re-scores there and then. A restore rehearsal moving from planned to operating can lift several continuity risks out of trouble in one action; marking a control retired can put them back.

What else a linked control feeds

The link is read by more than the score. A control mapped to a framework requirement counts towards coverage only when it is implemented or operating, so the status that drives your residual figures also drives what Frameworks shows as covered. Remediation actions for a control live in its own panel and appear in Actions.

Troubleshooting

I linked a control and the residual score did not move

Check the status first. A planned control reduces nothing, so linking one changes the list without changing the number. If the status is fine, look for a stronger live control already linked, because the risk follows the strongest one and a weaker one alongside it moves nothing. Then check the derive toggle: with it off, the risk holds the value you set.

I cannot find the control I want to link

Retired controls are hidden until you show them, so one you retired and then needed again will not appear until the show-retired toggle is on. If it was never created, use the picker to create it from inside the risk and fill in the detail afterwards.

The panel says my value disagrees with the linked controls

That is the divergence warning. Deriving is off, and a hand-set effectiveness sits some distance from what the linked controls would produce. Nothing has been changed for you: switch deriving on to accept the controls' answer, or leave your figure and record why it differs.

Several risks changed when I edited one control

That is the intended behaviour, and the reason to link properly in the first place. Every risk deriving from a control re-scores when the control's status or effectiveness changes. If a change surprised you, each affected risk's History holds the assessment and the score it produced.

A risk is still flagged over appetite after I linked controls

Appetite is compared against the residual score, so the flag clears only once the controls bring it to or below the threshold that applies. Resolution runs in order: the risk's own override, then its category, then the organisation-wide figure. RSK-0007 sits at a residual of 15 against an appetite of 9, and one moderate control will not close a gap of six.

A control map decays quietly. These routines keep it worth reading.

  • Link as you assess, not afterwards. Rating a risk is the moment you remember what actually protects it, and the picker creates a control from inside the risk so the thought is not lost.
  • Sort the controls table by the Risks column. Controls with a count of zero are either unnecessary or unlinked, and both are worth ten minutes.
  • Promote a control the day it goes live. Moving the status from planned to operating pays out across every risk relying on it, and it is the step most often missed once the project that delivered it has closed.
  • Leave deriving switched on by default. A derived residual keeps itself current; a hand-set one is right on the day you type it and not for long after.
  • Unlink deliberately. When a control is withdrawn, unlink it and let the residual score rise. A register that cannot show a risk getting worse is not much use when one does.
  • Review controls on a cadence of their own. Each carries a next review date, and a control nobody has looked at in two years is an assumption rather than a defence.

Frequently asked questions

How do I link a control to a risk on Mac?

Open the risk from the Risks section, open the Controls section in the panel on the right, and use the picker to link an existing control or create a new one. The control joins the linked list with its status and effectiveness shown, and the risk's residual score updates as soon as deriving is switched on.

Why did my residual score not change after linking a control?

Usually the control is still planned. Only controls that are implemented or operating reduce a score. The other two causes are a stronger live control already linked to the same risk, since the strongest one sets the value, and the derive toggle being off, which means the risk is holding an effectiveness you set by hand.

Can one control be linked to more than one risk?

Yes, and most should be. A single control often reduces several risks, and the Risks column on the controls table counts how many it is attached to. When you change that control's status or effectiveness, every risk deriving from it re-scores at once rather than waiting for you to visit each one.

What happens when I unlink a control from a risk?

Only the connection is removed. The control keeps its own record, its evidence notes and its actions, and the risk keeps its history. If the risk derives its effectiveness from linked controls and you removed the strongest live one, the residual score rises to reflect what is genuinely left in place.

Do planned controls reduce risk?

No. A control reduces a score only once it is implemented or operating, however high its intended effectiveness. RiskOS keeps planned controls linked and visible so you can see what is coming, but it will not count them, and the risk's panel explains why the number has not moved.

Can I set control effectiveness by hand instead of deriving it?

Yes. Switch off the derive toggle in the risk's Controls section and choose the effectiveness yourself. Linked controls stay listed and reported. If your figure disagrees with what the linked controls would produce, the panel shows a divergence warning naming the difference rather than silently picking one of them.

Do linked controls count towards framework coverage?

A control mapped to a framework requirement counts as covered only when it is implemented or operating. A mapped control that is still planned shows as mapped but not operating, which is a separate state from not mapped at all. The same status that drives your residual scores therefore drives what coverage reports.

Does anything about my controls leave my Mac?

No. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine except when you export or back it up yourself. The only network use is Apple's App Store, for purchases, and it never sees your controls or your risks.