Building the Register

How to organise risks by category on Mac

You can do this with RiskOS, a risk register for macOS. One small field, set once, that decides what your searches, your filters and your appetite thresholds can reach.

A category is the cheapest field on a risk and the one that repays you most often. It decides what a search brings back, which threshold the appetite check uses, and whether anyone can answer how much cyber risk are we carrying without reading the register row by row. Settling the set early costs an afternoon; settling it late costs a relabelling exercise.

Note

Categories come from a list you can add to. Recategorising a risk never changes its likelihood, its impact or its score. It can change whether the risk reads as over appetite, because a category is allowed to carry a threshold of its own.

Where categories live

Choose Risks in the sidebar and click any row. The panel on the right opens on Summary, and that one section holds the whole of a risk's filing: status, category, subcategory, owner, business unit, review cadence and next review date. Nothing about the score lives there: filing and rating are separate jobs.

The category also shows in the table, under the title in the Risk column, so you can read the shape of a register without opening a row. The third place it appears is Settings ▸ Appetite, where a category can be given its own tolerance and the reason for it.

Categorise a risk, step by step

  1. Open the risk you want to file

    Choose Risks in the sidebar and click the row. The panel opens on Summary. If the risk does not exist yet, press N to create one; new rows pin to the top of the table, so you can file it before it drops into the sort order.

  2. Choose a category from the list

    Open the category field in Summary and pick the one that fits. RiskOS ships with a starting list covering the ground most registers need: cybersecurity, cloud, third-party and vendor risk, business continuity, project delivery, compliance and regulatory risk, and artificial intelligence. Changes save as you type.

  3. Add your own category when nothing fits

    If the risk belongs to something the shipped list does not name — health and safety, treasury, facilities, environmental — add your own, and it joins the list for every risk after it. Add sparingly: a category invented for one row is a label, and labels do not help you compare anything.

  4. Set a subcategory if the category is broad

    Use the subcategory field to say which kind. Cybersecurity covers ransomware, privileged access and data loss, and those three call for different controls and different owners. Leave it empty where the category is already specific enough to act on; an empty subcategory beats one that repeats the title.

  5. Record the business unit that carries it

    Set the business unit to the part of the organisation that lives with the consequence, not the team fixing it this month. Category answers what kind of risk is this; business unit answers whose problem is it when it lands. Keeping them apart lets one register serve a security review and a divisional one.

  6. File a run of risks in one pass

    Select several risks in the table and the panel turns into a bulk editor. Tick category, choose the value, and apply it to everything selected. The same pass can set owner, business unit, status, treatment strategy and review cadence. Anything left unticked stays as it was, so a group edit never overwrites a field you were not thinking about.

  7. Find everything in a category

    Type the category name into the search field above the register. Search covers the title, the reference, the category, the owner, the detail and the tags, so one word brings the group into view. Narrow it with the band filter or over appetite only; the filter icon fills while a filter is on, so you always know the table is showing a subset.

  8. Save the view you will want again

    Once the search and the filters give you the group you want, choose Save Current Filter… and name it: Cyber above appetite, Vendor risks due for review. The named view comes back in one click, which turns a category from a tidy habit into a working shortcut.

  9. Give the category its own appetite

    Open Settings ▸ Appetite. Alongside the organisation-wide threshold, any category can carry its own highest tolerable residual score and a written rationale. Set one where the tolerance genuinely differs, and every risk in that category is measured against it from then on.

Choosing a set of categories that lasts

A category set is a small piece of policy. It says which comparisons your organisation cares about, and once a hundred risks are filed against it, changing it is real work. The set below is the one RiskOS starts you with, and it suits most registers as it stands.

The starting categories and the kind of risk each one carries
CategoryWhat it carriesA risk that belongs here
CybersecurityDeliberate attack, misuse of access, loss or exposure of data.RSK-0001 Ransomware encrypts primary file shares
CloudDependence on hosted platforms and the regions they run in.RSK-0002 Single cloud region outage halts customer portal
Third-Party / VendorExposure that arrives through somebody else's organisation.RSK-0011 Supplier concentration in a single logistics partner
Business ContinuityThe ability to keep operating, and to recover when you cannot.RSK-0007 Backup restoration has never been tested end to end
Project DeliveryChange you have chosen to make, and what it costs when it slips.RSK-0009 Migration project overruns its budget
Compliance & RegulatoryObligations imposed from outside, and the penalty for missing them.RSK-0005 Regulatory reporting deadline missed
Artificial IntelligenceAutomated decisions and generated output reaching people who act on them.RSK-0006 Unreviewed AI model output reaches customers

How many categories is too many

Somewhere between six and twelve. Below six, everything important lands in one bucket and the category stops separating anything. Above twelve, people stop choosing and start guessing, and two colleagues file the same exposure in different places. A category still holding one risk after a year was a subcategory wearing the wrong hat.

Name the source, not the symptom

Categories that describe the consequence — downtime, financial loss, reputational damage — collapse quickly, because almost every serious risk produces all three. Categories that name where a risk comes from stay stable for years, and they map onto the people who can do something about it.

Category, subcategory and business unit

Three fields sit next to each other in Summary and are constantly confused. They answer different questions, and a register stays readable only while each keeps to its own.

How the three filing fields differ
FieldThe question it answersWhat a good value looks like
CategoryWhat kind of risk is this?Cybersecurity, Business Continuity, Compliance & Regulatory
SubcategoryWhich kind within that?Ransomware, Restore capability, Statutory reporting
Business unitWhich part of the organisation lives with it?Operations, Customer Platform, Finance
OwnerWho answers for it by name?A. Okonkwo, M. Halvorsen, S. Ramirez

When a subcategory earns its place

Reach for one when a category has grown past about a dozen risks and you have started reading it in groups anyway. Three or four per category is plenty. The test is whether the split would change who you invite to the review: privileged access and ransomware pull in different people, so they earn it; cyber (internal) and cyber (external) pull in the same room, so they do not.

What a business unit is for

Business unit is the second axis, and the one that makes a register readable outside the risk function. A divisional director does not want the cyber view; they want everything their division carries, whatever kind it is. Set it as you go, or in one bulk edit once the categories are settled, and both readings come off the same rows.

What a category pays back

Filing feels like administration until the first time it saves an argument. Three things in RiskOS read the category directly, and each turns a label into something that acts.

A threshold with a reason attached

Appetite is the strongest payback. The organisation sets one number — the highest residual score it will tolerate — and any category can be given a tighter or looser one, with the rationale for the difference. Holding Compliance & Regulatory risk to a tighter threshold than the organisation-wide 9 is a statement of policy, applied every time rather than remembered by whoever chairs the meeting.

The order in which an appetite threshold is resolved for a risk
OrderThreshold usedWhen it applies
1The risk's own overrideThe risk has appetite overridden in its own panel.
2The category thresholdIts category carries one in Settings.
3The organisation thresholdNeither of the above is set.
4NoneNo threshold has been set anywhere.

A risk above its appetite is flagged everywhere it appears, so moving a row into a stricter category can raise a flag that was not there a moment ago. The score has not moved; the standard it is measured against has.

Views you can bring back

A category search plus a filter is a question you will ask again, every quarter or before every board pack. Name it with Save Current Filter… and it becomes a click instead of a rebuild. Arrange the table to suit the pass while you are there: right-click the header to show, hide and reorder columns, and the arrangement is remembered. Whatever you rebuild by hand each month is a named view waiting to happen.

One change across a whole group

Once a group is on screen, the bulk editor works on all of it. Select the rows, tick only the fields you mean to change, and apply. That is how a category gets a new review cadence, a new owner after a reorganisation, or an agreed treatment strategy in one sitting. Multi-select also offers Mark Reviewed, Duplicate and Close, and closing several risks asks you to confirm.

Troubleshooting

I have thirty categories and none of them help

Pick the eight that describe most of the register, then work through the strays with the bulk editor, moving each into one of the eight and using the subcategory field to keep the detail you are giving up. A category holding one risk tells you nothing the title did not.

The same risk could sit in two categories

Most interesting risks could. File by the source of the exposure rather than its consequence: a vendor outage that stops production is third-party risk with a continuity consequence, not the other way round. Write the second reading into the description so search still finds it, and stay consistent — the consistency matters more than the choice.

Searching a category returns risks that do not belong to it

Search deliberately reaches across the title, the reference, the category, the owner, the detail and the tags. A risk whose description mentions the cloud answers a search for cloud even when it is filed elsewhere. Read the category shown under each title in the Risk column to tell the group apart from the mentions.

A risk went over appetite as soon as I recategorised it

Its new category carries its own threshold, tighter than the organisation-wide one. Open Settings ▸ Appetite to see the number and the rationale recorded beside it. If this risk is a genuine exception, override appetite in its own panel, where the override sits above the category in the resolution order.

Closed risks are missing from my category

Closed and accepted risks are hidden from the table until you ask for them. Turn on show closed and accepted in the filters and they return to the count. Nothing was lost: risks in RiskOS are closed rather than deleted, and a closed risk keeps its category, its history and its reference.

Habits that keep categories honest

  • File at creation, not at review. Setting the category while the risk is fresh takes seconds; reconstructing it from a terse title six months later takes a conversation.
  • Keep a written definition of each category. One line saying what belongs and what does not. The rationale field on a category's appetite threshold is a natural home for it.
  • Review the set once a year, not continuously. Categories that change every quarter destroy the comparisons they exist to support. Make changes in one pass with the bulk editor.
  • Use the subcategory before inventing a category. Nine times out of ten the distinction you want is a level down, not a level across.
  • Set the business unit on everything. One field per risk is the difference between a security register and one the whole organisation can read.
  • Give a category its own appetite only where the tolerance really differs. A threshold on every category is the same as no threshold at all, and it makes the exceptions invisible.

Frequently asked questions

How many risk categories should a register have?

Between six and twelve for most organisations. Fewer than six and everything important lands in one bucket; more than twelve and people guess rather than choose, so the same exposure gets filed two ways. RiskOS starts you with a list covering cybersecurity, cloud, third-party, continuity, project, compliance and AI risk, which suits most registers as it stands.

Can I create my own risk categories?

Yes. The category field in a risk's Summary section offers the list RiskOS ships with, and you can add your own name when nothing fits — health and safety, treasury, facilities, environmental. A category you add joins the list for every risk after it, so add them deliberately rather than one per row.

What is the difference between a risk category and a subcategory?

The category says what kind of risk it is, and it is the field that searches, appetite thresholds and the register table all read. The subcategory says which kind within that, and exists to keep detail without multiplying categories. Ransomware and privileged access are subcategories of cybersecurity, not categories in their own right.

How do I change the category on several risks at once?

Select the rows in the register and the panel becomes a bulk editor. Tick the category field, choose the new value, and apply it to every selected risk. The same pass can set owner, business unit, status, treatment strategy and review cadence, and any field you leave unticked keeps the value it already had.

Does changing a risk's category change its score?

No. Likelihood, impact and the residual score are untouched by filing. What can change is the appetite flag, because a category may carry its own threshold. Move a risk into a category with a stricter tolerance and the same score can read as over appetite — the standard moved, not the rating.

What is a business unit used for in a risk register?

It records which part of the organisation lives with the consequence, separately from what kind of risk it is. That second axis is what lets one register answer both a security question and a divisional one. It is set in a risk's Summary section and can be applied to many risks at once in the bulk editor.

Can each risk category have its own risk appetite?

Yes. Settings holds an organisation-wide threshold, and any category can carry its own highest tolerable residual score with a written rationale. An individual risk can override both. The resolution order is the risk's override first, then the category, then the organisation, then none — and anything above its threshold is flagged wherever it appears.

Is a categorised risk register private?

Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine except when you export or back it up yourself. Category names, business units and owners are yours alone. The only network RiskOS uses is Apple's App Store, for purchases, and it never sees your register.