How to move a risk register to a new Mac
You can do this with RiskOS, a risk register for macOS. One backup file travels with you, and the new machine picks up exactly where the old one left off.
A new Mac arrives and the register has to come with it: every risk, every score you argued over, every control, every assessment you recorded along the way. The move itself takes about five minutes. The part worth doing carefully is the check afterwards, because a register you cannot vouch for is not much use in a meeting.
Nothing syncs between machines. There is no account, nothing is uploaded, and your register never leaves the Mac it lives on — so it moves when you move a backup file, and not before.
Where backing up and restoring live
RiskOS keeps both in the File menu. File ▸ Back Up RiskOS… — or ⇧⌘B — writes the whole register to a single file and asks you where to put it. File ▸ Restore from Backup… reads one back in. That pair is the whole move.
The Import & Export section in the sidebar is a different job. It handles CSV — risks, controls, assets and vendors, one kind of record at a time — which is what you want when you are bringing a single list in or taking a single list out. For a move between your own Macs, the backup file is the right instrument, because it carries everything at once rather than a slice.
Move a register to a new Mac, step by step
-
Note what the old register holds
On the Mac you are leaving, open Dashboard and write down the headline figures: how many active risks there are, the average residual score, how many sit above appetite, how many reviews are overdue, how many actions are open and where framework coverage stands. Five numbers on a scrap of paper turn the check at the other end into a matter of fact rather than an impression.
-
Take a fresh backup on the old Mac
Choose File ▸ Back Up RiskOS… or press ⇧⌘B. Keep the suggested filename, which carries the date — Risk Register 2026-09-21 — so that the newest file is obvious later. Save it somewhere deliberate, such as Documents ▸ RiskOS, rather than wherever the save sheet happens to land.
Take this backup after you have finished working for the day. A backup is a snapshot of the register at the moment you make it, so anything you change afterwards on the old Mac will not be in the file.
-
Copy the backup to the new Mac
Move the file across however you normally move a file between your own machines, and put it somewhere you will find it in a hurry — Documents ▸ RiskOS on the new Mac mirrors where it came from. A backup is a complete copy of your register, so treat it with the same care while it is in transit.
-
Install RiskOS on the new Mac
Install the app on the new machine and let it finish updating before you do anything else. Requires macOS 14.0 or later. Running the current version on the new Mac matters for the next step: a backup written by a newer version than the one you are restoring into is refused rather than half-read, and updating first avoids that entirely.
-
Restore the backup
Open the app on the new Mac and choose File ▸ Restore from Backup…. Select the file you copied across. You are told exactly what a restore means — the register is replaced with the backup's contents — and asked to confirm before anything happens. Read that sheet rather than clicking through it, then confirm.
-
Check the counts agree
Open Dashboard on the new Mac and compare it with the figures you wrote down. Active risks, average residual, the number above appetite, overdue reviews, open actions and framework coverage should all match. If a number looks wrong, check the filters before you check the restore: the filter icon above the risk table fills in when a filter is on, and the show-closed and show-accepted toggles change what is being counted.
-
Spot-check a risk you know well
Open Risks and pick a risk you could describe from memory. Check the reference is unchanged, the owner and category are right, the inherent and residual scores match, the linked controls are still attached, and History still lists every assessment with the reason behind it. References are never reissued, so RSK-0007 on the old Mac is RSK-0007 on the new one.
-
Check your methodology and appetite
Press ⌘, to open Settings. In Methodology, confirm the band thresholds and the choice of whether controls reduce likelihood, impact or both. In Appetite, confirm the organisation threshold and any per-category thresholds with their rationales. These decide how every score in the register reads, so they are worth thirty seconds of attention.
-
Set the backup reminder, and take a new one
Set how often you want to be reminded to back up — never, weekly, fortnightly or monthly — and then take a backup straight away on the new Mac. You now have two good copies from two machines, which is the point at which the move is genuinely finished. Keep the file you carried across until the new register has survived a normal week of work.
What a backup carries
A backup is not a partial export. It is the register in one file, which is what makes it the right thing to move. Everything in the table below travels together, in one operation, with nothing to reconcile at the far end.
| What travels | What to check on the new Mac |
|---|---|
| Risks, with their references | The row count, and that RSK numbers are unchanged |
| Assessment history and the audit trail | History on a risk you have re-scored more than once |
| Controls | Status and effectiveness on a control several risks rely on |
| Actions | The overdue group, which is the one people notice first |
| Assets and vendors | Criticality badges, and vendor review dates |
| Frameworks and your control mappings | Coverage on the framework you actually report against |
| Indicators and their readings | The latest reading and its status on a breached indicator |
| Events | Occurred and detected dates on your most recent event |
| Settings | Methodology, band thresholds and appetite |
What a backup does not carry is anything you have already taken out of the register, such as a report you exported last quarter. Those stay wherever you saved them, and a restore leaves them untouched.
The version rule that decides a restore
RiskOS versions every backup it writes, and the rule is deliberately one-directional. It exists so that a restore is either complete or does not happen, rather than leaving you with a register that is partly one thing and partly another.
| The backup was written by | Restoring into | What happens |
|---|---|---|
| An older version | The current version | Restores. Older backups always restore. |
| The same version | The same version | Restores. |
| A newer version | An older version | Refused, rather than half-read. Update first, then restore. |
Update the new Mac before you restore
The awkward case only arises when the new machine is running behind the old one. Let RiskOS update on the new Mac before you open the restore sheet and the question never comes up. If you have already tried and been turned away, nothing has been changed: update, then try again with the same file.
Moving in the other direction
Going backwards is always allowed: an older file is something the current version understands completely. That is worth remembering when you want to see how the register read before a large re-scoring exercise.
Checking the two registers agree
Comparing dashboards catches most problems in a few seconds, since every figure RiskOS shows is counted from the register sitting in front of you. When you want more than that — a register you report to a board from, or a client's register you hold on their behalf — a few stronger checks are worth the extra minute.
Read both ends of the register
Open Risks and sort by Ref. Read the first reference, the last one and the row count. References are never reissued, so the sequence on the new Mac runs exactly as it did on the old one and ends on the same number. Do the same in Controls, where references read CTL-0001 upwards. Turn on the show-closed toggle while you look, so that a risk you closed months ago is not mistaken for one that failed to arrive.
Export the same report twice
Build a report with the same sections ticked on both Macs and export it. Every output is produced from one snapshot of the register, so two reports built from the same register agree with each other and with the tables they came from. If the executive summary, the top risks and the framework coverage read the same on both machines, the register moved intact.
Look at the things that are easy to miss
Counts can agree while a detail escapes notice, so glance at the edges of the register too. Indicators that were paused should still be paused. A risk with an appetite override should still show its own threshold rather than the organisation's. Saved filters should still be there when you go looking for the view you use every Monday.
Troubleshooting
The restore says the backup is from a newer version
The new Mac is running behind the machine that wrote the file. Nothing has been changed by the attempt. Update RiskOS on the new Mac, open File ▸ Restore from Backup… again and choose the same file. A file from a newer version is refused outright rather than partly read, which is why the register you were restoring into is still exactly as it was.
I had already started work on the new Mac
A restore replaces the register with the backup's contents, and you are told so before you confirm. If you had begun adding real risks on the new machine, back that register up first — ⇧⌘B, and give the file a name you will recognise — so you keep a copy of both. Then restore, and re-enter the handful of rows you created.
The numbers do not match
Check the file before you doubt the restore. Default filenames carry the date, so the newest backup is the one with the latest date in its name; restoring last week's by mistake explains most mismatches. If the file is right, look at the filters: an active filter, or a show-closed toggle set differently on the two machines, changes what is counted without changing what is there.
A profile is locked on the new Mac
Profiles beyond your cap are locked, never deleted, so everything inside them is intact and waiting. The Small Business, Enterprise and Consultant packs unlock more profiles with a one-time purchase through the App Store, the only network the app uses, and it never sees your register. Once the purchase is recognised on the new Mac, the profiles open again with their methodology, appetite and client branding as you left them.
I cannot find the backup file
Backups are saved wherever you chose, not to a fixed location, so retrace the save. The filename begins with Risk Register and carries the date it was written, which makes it easy to recognise in a folder of other things. If you are starting the move again, save the new one to Documents ▸ RiskOS on both machines and the question disappears for good.
A moving routine that holds up
Most registers get moved once and then not thought about for two years, and RiskOS asks nothing of you in between. A few habits make that move dependable.
- Back up last, restore first. Take the backup at the end of a working session on the old Mac, and restore before you do any work at all on the new one. Nothing is then created on either side that the file does not contain.
- Write down five numbers. Active risks, average residual, risks above appetite, overdue reviews, open actions. Compared afterwards, they turn a hopeful restore into a verified one.
- Keep the same folder on both machines. Documents ▸ RiskOS at each end means you are never hunting for a backup under pressure.
- Keep the travelling copy for a month. A backup costs nothing to keep. Hold on to the one you carried across until the new register has been through a full review cycle.
- Set the reminder on the new Mac straight away. Weekly, fortnightly or monthly — whichever you will actually live with. A quiet nudge when a backup is getting old is what keeps the next move painless.
- Back up before anything large. A bulk edit, a framework re-import, a methodology change that re-scores the whole register: take a backup first and you can always look at what came before.
- Retire the old Mac last. Do not wipe the machine you left until the new register has survived a normal week and produced a backup of its own.
Frequently asked questions
How do I transfer my risk register to a new Mac?
Back up on the old Mac with File ▸ Back Up RiskOS…, copy the file to the new machine, install RiskOS there, then use File ▸ Restore from Backup… and confirm. The whole register arrives in one operation — risks, controls, actions, history, assets, vendors, frameworks, indicators, events and settings.
Does RiskOS sync my register between Macs?
No. There is no account, no sign-in and no server, so a register lives on the Mac it was built on and moves only when you move it. That is why the transfer is a backup file you carry across rather than something that appears on the new machine by itself, and why nobody else can see it in the meantime.
What does a RiskOS backup include?
Everything: risks and their history, the audit trail, controls, actions, assets, vendors, frameworks and your mappings, indicators and their readings, events, and your settings. It is written to a single file saved wherever you choose. That completeness is what makes a backup the right way to move a register rather than exporting each list separately.
Will my risk references change after a restore?
No. References such as RSK-0001 and CTL-0001 are never reissued, and a restore brings them across exactly as they were. Anything you have quoted in a board pack, an audit response or an email still points at the same risk on the new Mac, which is the main reason references are fixed for life in the first place.
Can I restore an old backup into the current version?
Yes. Older backups always restore. The rule only runs one way: a file written by a newer version of RiskOS than the one you are restoring into is refused rather than half-read, so you are never left with a partly updated register. Update the app on the receiving Mac and the restore then works normally.
Does restoring a backup delete what is already in the register?
A restore replaces the register with the backup's contents, and RiskOS explains exactly what that means and asks you to confirm before anything happens. If the receiving Mac already holds work you want to keep, back that register up first so you hold a copy of both, then restore.
How often should I back up my risk register?
Choose a reminder interval of weekly, fortnightly or monthly and let the quiet nudge do the remembering. Beyond that, take a backup before anything large — a bulk edit, a framework re-import, a methodology change that re-scores every risk — and after any session where you added or re-scored a number of risks.
Do my client profiles move to the new Mac?
Profile settings travel with the backup, and profiles beyond your cap are locked rather than deleted, so nothing inside them is lost. Extra profiles are unlocked by a one-time purchase through the App Store, never a subscription. Once that is recognised on the new Mac, each profile opens with its own methodology, appetite, report defaults and client logo.