Profiles & Working on a Mac

How to manage risk for multiple clients on Mac

You can do this with RiskOS, a risk register for macOS. A profile for each client, switched with a keystroke, and every export in that client's terms.

Advisory work multiplies everything. Four clients means four sets of scales, four appetites, four report covers and four readings of what counts as a Major impact, and once those start bleeding into one another the numbers stop meaning anything. RiskOS keeps them apart with profiles: one for each client, carrying its own methodology, appetite, report defaults, client name and client logo.

Note

Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine.

Where client profiles live

Profiles is the first section in the sidebar, above the dashboard, because for anyone working across several clients it is the first decision of the day. Choosing it lists the profiles you have; selecting one opens it in the panel on the right, where its name, its client details and its snapshot of the methodology and appetite are set.

A second way in matters more in practice. A switcher sits in the sidebar footer and is visible from every section, so you never have to leave the register to change client. P cycles through your profiles from the keyboard.

Set up a profile for each client

Work through this once per client. It is the last time you will have to think about that client's scales, thresholds or report cover.

  1. Open the Profiles section

    Choose Profiles at the top of the sidebar. RiskOS includes one profile, which is the one you have been working in whether you noticed it or not. Look at it before you add anything: it holds the settings your register is running on now.

  2. Set up your own identity first

    Open Set Up Branding and fill in your own details — business name, tagline, address, phone, email, website and a registration or VAT line — then add your logo. A live preview shows the real header and footer as you type, and what you see there is exactly what exports and prints.

    This is your identity, not the client's, and it stays primary in every profile.

  3. Set the methodology this client scores against

    Press , and open Settings ▸ Methodology. Set the scoring scales, the band thresholds and the one choice that changes every number in the register: whether controls reduce likelihood, impact or both. Some clients hold a written methodology you have to match; others will take yours. Changing this re-scores every risk immediately, so settle it before you start rating rather than after.

  4. Set the appetite this client is held to

    Still in Settings, open Appetite and set the organisation-wide threshold — the highest residual score this client will live with. Where a client is tighter in one area than another, give that category its own threshold and write the rationale beside it, so the number has an argument behind it when somebody asks.

  5. Create the profile and name it for the client

    Back in Profiles, add a profile and name it for the client. It takes the methodology and the appetite you have set as its own snapshot, so the work in the two previous steps now sits inside the profile rather than floating in your settings.

    Name it the way you would name an invoice. A profile called Northbank Mutual is unambiguous at a glance in the sidebar footer; one called Client 2 is a mistake waiting for a Friday afternoon.

  6. In the profile, set the client name and drop in the client's logo. Logos arrive as PNG, JPEG, PDF or SVG, and you can add a separate variant for dark backgrounds if the client supplies one. The client name is what appears as the "prepared for" line on exports; your own identity stays primary alongside it.

  7. Set the report defaults for this client

    A profile carries its report defaults, so decide them once. Set the report title, the organisation and the prepared-by line, choose which sections a report includes — executive summary, risk matrix, top risks, the full register, per-risk detail pages, controls, open actions, indicators, events and framework coverage — and say whether closed and accepted risks are in scope. A board pack for one client and a working paper for another rarely want the same sections.

  8. Switch profiles and check one export

    Press P to cycle to the new profile and watch the sidebar footer name the client you are in. Then produce one export — P for PDF is the quickest check — and read the cover, the running header and the footer. If those are right, every export from this profile will be.

What a profile carries

A profile dresses the whole app for one client. It is worth knowing exactly what is inside one, because that is also the list of things you never have to remember again once it is set.

What a client profile in RiskOS holds
What the profile holdsWhat it coversHow it behaves
MethodologyScoring scales, band thresholds, and whether controls reduce likelihood, impact or both.Held as a snapshot. Refreshed with Update from Current Settings.
Risk appetiteThe organisation-wide threshold and any per-category thresholds with their rationales.Held as a snapshot, and refreshed the same way.
Report defaultsCover fields, the section toggles and the scope of a report.Applied to reports produced while the profile is active.
Client nameThe "prepared for" name that appears on exports.Sits alongside your own identity, which stays primary.
Client logoPNG, JPEG, PDF or SVG, with an optional variant for dark backgrounds.Appears on exports from this profile only.

What stays the same in every profile

Your own business identity — the branding header and footer you set once — stays primary whichever client you are working for, and so do the shortcuts, the sidebar sections and the way the register behaves. Switching client changes the terms the register is expressed in, not the app you know how to drive.

Keeping each client's work apart

A profile settles the terms. Separating the rows themselves is a matter of how you file them, and the register gives you three ways to do that which cost nothing at the time and pay you back every reporting cycle.

Give every risk a business unit

The Summary section of a risk's panel carries a business unit field. Fill it with the client, or with the client's division where an engagement spans several, on the day the risk is created. If you have inherited a register where nobody did, select the rows belonging to one client and the panel becomes a bulk editor: tick business unit, set the value once and apply it to every selected risk. Anything left unticked stays as it was.

Save one filter per client

Search covers title, reference, category, owner, detail and tags, so a client name typed into the search field narrows the table straight away. Add the filters you want on top — a band, over-appetite only, whether closed and accepted risks show — then use Save Current Filter… to name the combination. The filter icon fills whenever a filter is on, so you always know you are looking at part of the register rather than all of it.

Filter actions by owner

Actions gathers every action across the register in one place, grouped by due state, with an owner filter at the top. When each client's work is owned by a named contact, that filter becomes a per-client to-do list: overdue first, then due soon, each row showing the risk or control it belongs to.

When separation has to be absolute

Some engagements come with a confidentiality clause that will not tolerate one client's rows sitting beside another's. For those, keep a backup per client and restore the one the engagement needs. In RiskOS, File ▸ Back Up RiskOS… writes everything to a single file saved wherever you choose, and Restore from Backup… replaces the register with a backup's contents after telling you exactly what that means and asking you to confirm.

Exports that arrive in the client's terms

With the right profile active, a report carries your identity as the author and the client's as the recipient, scored on the client's methodology and measured against the client's appetite, without you editing a cover page by hand. All four outputs come from the same snapshot, so a PDF, a workbook and a printed page always agree — which matters when three of them reach the same meeting.

The four report outputs and what each suits in client work
OutputShortcutWhat it suits
PDF⇧⌘PThe deliverable. Paginated A4 with a branded cover, a running header and footer, repeated table headers, and rows that never split across a page.
HTML⇧⌘EOne self-contained file that opens in any browser, with no scripts and nothing loaded from the internet. Easy to send, easy to open.
ExcelA live workbook of seven sheets whose formulas re-score themselves when a client changes a likelihood in the room.
Print⌘PExactly the PDF, sent to the printer, for the client who still wants paper on the table.

Each export confirms with the filename it wrote, and a failure says what to do next. Default filenames carry the date, which is enough to keep a folder of client deliverables in order.

Methodology and appetite are snapshots

This is the one piece of behaviour worth understanding properly, because it is what stops one client's decisions leaking into another's. A profile does not point at your current settings. It holds a copy of the methodology and the appetite as they were when it took them.

The useful consequence is that retuning the scales for a client who has asked for tighter impact anchors does not quietly re-score another client's register. The consequence to watch for is the mirror image: a profile can fall behind what you now consider your house methodology, and it will not catch up on its own.

Update from Current Settings answers both. Set the methodology and appetite you want, open the profile and refresh its snapshot deliberately. Since a methodology change re-scores every risk immediately, do it where you want to see the movement — at the start of a review round rather than the night before a board pack.

How many profiles you get

RiskOS includes one profile, which is all a single organisation ever needs. Small Business, Enterprise and Consultant unlock more, each as a one-time purchase. There is never a subscription, and nothing expires.

Profiles beyond your current cap are locked, never deleted. The client's name, logo, methodology snapshot, appetite and report defaults stay exactly where they were, and become available again the moment the cap allows for them. An engagement that ends and restarts a year later costs you nothing to pick up.

Troubleshooting

I switched profile and the risks did not change

That is what a profile does and does not do. It changes the methodology, the appetite, the report defaults, the client name and the client logo — the terms the register is expressed in. It is not a filter on the rows. Use the business unit field and a saved filter to narrow the table to one client, or a backup file per client where the separation has to be complete.

The wrong logo is on the report

Two logos reach an export. Yours comes from Set Up Branding and stays primary in every profile; the client's comes from the active profile and appears as the "prepared for" identity. If the wrong mark is on the cover, check the switcher in the sidebar footer before exporting again. The branding designer's live preview shows the real header and footer, so you can confirm without producing a file.

Scores moved when I switched client

Expected, and worth trusting. Each profile carries its own methodology, and one choice inside a methodology is whether controls reduce likelihood, impact or both. Change that and every residual score is recalculated at once. If a client's numbers look unfamiliar, open Settings ▸ Methodology and read the scales you are scoring against.

The keystroke did not switch client

Check which one you pressed. P — control, not shift — cycles profiles. P exports a PDF and P sends one to the printer. The three are the keys a client visit actually uses, but they are not interchangeable.

A risk is still flagged above appetite after I raised the threshold

Appetite resolves in a fixed order: the risk's own override first, then the category threshold, then the organisation-wide one, then none. A risk carrying its own override keeps it whatever the profile says. Open the risk, look at the Appetite section, and switch the override off if the client's organisation-wide figure should govern it.

A working routine for client work

A handful of habits carry most of the weight once several clients run at the same time.

  • Name profiles the way you name invoices. The client's real name, spelled the way they spell it. The sidebar footer is small and you read it under pressure.
  • Settle the methodology before the first risk. Scales agreed at the start save a full re-score at the end.
  • Fill in the business unit on the day. Two seconds while the risk is in front of you saves a bulk edit across a hundred rows later.
  • Keep one saved filter per client. Name it, use it, and let the filled filter icon remind you that you are looking at a slice rather than the whole register.
  • Check the switcher before you export. One glance at the sidebar footer prevents the most embarrassing mistake in multi-client work.
  • Refresh a snapshot on purpose. When your house methodology moves, open each profile and use Update from Current Settings at a moment when you want to see the scores move.
  • Back up before a round of client reviews. B writes everything to one file, and the default filename carries the date, so a folder of them reads as a timeline.
  • Run one review pass per client. Review takes a scope — above appetite, overdue, due within thirty days — and walks the risks one at a time, worst first, which is the shape of a client meeting.

Frequently asked questions

Can I use RiskOS for more than one client?

Yes. Profiles are built for it. Each profile holds one client's methodology, risk appetite, report defaults, client name and client logo, and switching between them takes a keystroke. RiskOS includes one profile, and the Small Business, Enterprise and Consultant options raise that cap with a one-time purchase.

What does a client profile actually change?

It changes the terms the register is expressed in: the scoring methodology, the risk appetite, the defaults a report is built from, and the client name and logo that appear on exports. It does not change which risks are in the register. Separating rows by client is done with the business unit field and a saved filter.

How do I switch between client profiles on a Mac?

Two ways. A switcher sits in the sidebar footer and is visible from every section of the app, so you can change client without leaving the register. Or press ⌃⌘P to cycle through your profiles from the keyboard. The footer always names the profile you are currently in, which is worth a glance before any export.

Do I need a subscription for extra client profiles?

No. Small Business, Enterprise and Consultant are one-time purchases that raise how many profiles you can hold. Nothing renews and nothing expires. If you later hold more profiles than your cap allows, the extra ones are locked rather than deleted, and everything in them is still there when the cap allows for them again.

Can each client have a different risk appetite?

Yes, and a different methodology too. Each profile keeps its own snapshot of both, taken from your settings at the time. A client that tolerates a residual score of 12 and one that stops at 6 can sit side by side without either one affecting the other, and any category inside a client can carry its own threshold and rationale.

How do I put a client's logo on a risk report?

Add it to the client's profile as a PNG, JPEG, PDF or SVG, with an optional variant for dark backgrounds. Your own logo and business details live separately in Set Up Branding and stay primary on every export. With the profile active, the client's name and logo appear as the "prepared for" identity on the cover.

How do I keep one client's risks out of another client's report?

Give every risk a business unit naming the client, then save a filter for that client so the register shows only their rows. Where confidentiality means two clients must never share a register at all, keep a backup per client and restore the one you need. RiskOS explains exactly what a restore replaces before anything happens.

If I change my methodology, does it affect every client?

Only the ones you refresh. A profile holds its methodology and appetite as a snapshot rather than pointing at your current settings, so retuning the scales for one client leaves the others as they are. Use Update from Current Settings on a profile when you do want it to catch up, and expect its scores to recalculate immediately.