Import, Export & Backups

How to restore a risk register from a backup on Mac

You can do this with RiskOS, a risk register for macOS. One file carries the whole register back, and nothing is replaced until you have read what replacing means.

Nobody restores a backup on a good day. It happens after an import that went the wrong way, on the first morning with a new Mac, or in the twenty minutes after somebody realises a quarter's worth of assessments are not where they thought. The point of a backup is that all of those mornings end the same way: one file, a few seconds, and a register that is exactly what it was.

Note

A restore replaces the register on this Mac with the contents of the backup. It is not a merge and it does not add the two together. RiskOS says exactly what that means before it does anything, and waits for you to confirm.

Where restoring lives

In RiskOS, backing up and restoring both sit in the File menu rather than the sidebar. Choose File ▸ Back Up RiskOS… to write a backup, and File ▸ Restore from Backup… to put one back. The backup shortcut is B, which is worth learning because you will use it far more often than the restore.

That is a different job from Import & Export in the sidebar, under Output. The CSV imports there add one kind of thing to an existing register and leave the rest alone. A backup is the whole register in one file, so restoring replaces rather than adds.

Restore a backup, step by step

  1. Find the backup you want

    RiskOS writes backups wherever you chose to put them, commonly Documents ▸ RiskOS or Downloads. Default filenames carry the date they were written, in the form Risk Register 2026-09-21, so the one you want is usually obvious at a glance.

    Pick by date rather than by feel. The right file is the last one written before whatever went wrong, which is often not the newest.

  2. Back up the register you have now

    Before you replace anything, press B and write a backup of the register as it stands. It takes seconds, and it is what makes the restore reversible: if you pick the wrong file, the state you started from is one more restore away.

    Give it a name you will recognise under pressure. Keeping the date and adding a word such as before restore tells the two files apart in a hurry.

  3. Choose Restore from Backup and select the file

    Choose File ▸ Restore from Backup… and pick the backup you identified in the first step. Nothing in your register has changed at this point, and choosing a file commits you to nothing.

  4. Read what you are told before confirming

    RiskOS then tells you exactly what restoring this file means for the register on this Mac — its contents will be replaced by the contents of the backup — and asks you to confirm. This is the moment to check the date of the file you chose. Nothing is written until you answer.

    If anything about the file looks wrong, cancel. Cancelling leaves the register untouched, and you can start again with a different file.

  5. Confirm the restore

    Confirm, and the register is replaced. Risks, assessment history, the audit trail, controls, actions, assets, vendors, frameworks, indicators, events and settings all come back together, because they were written together into the one file.

  6. Check the register came back

    Open Dashboard and read the totals: active risks, the average residual score, how many sit above appetite, how many reviews are overdue and how many open actions there are. Compare them with the day the backup was written. A count that looks short is often the show closed and accepted filter rather than the file.

    Then open Settings with , and look at Methodology and Appetite. Both travel in the backup, so the restored register scores and flags itself as it did when the file was written.

  7. Take a fresh backup and set the reminder

    Once you are satisfied, press B again and write a clean backup of the restored register. Then set how often you want to be reminded — never, weekly, fortnightly or monthly — so the next time you need a file like this one, it exists.

What a restore replaces

A backup is not a partial copy or a list of risks. It is the register, whole, and restoring puts all of it back at once. That is why the confirmation exists: everything in the table below is replaced together.

What a RiskOS backup carries and what restoring does with each part
What the backup carriesWhat restoring puts back
RisksEvery risk with its reference, ratings, owner, category, treatment and tags, including closed ones.
Assessment historyEvery assessment ever recorded, with the reason behind it and the score it produced.
Audit trailThe record of what changed, so the restored register reads as a history rather than a snapshot.
ControlsReferences, type, status, effectiveness, owners, review dates and evidence notes.
ActionsEvery action with its status, priority, owner and due date, still attached to its risk or control.
Assets and vendorsCriticality, owners, review dates and the links back to the risks they touch.
FrameworksImported catalogues and every mapping between a control and a requirement.
IndicatorsThresholds, direction, cadence and the full reading history behind each chart.
EventsWhat happened, when it was detected, what it cost and the lessons recorded.
SettingsThe scoring methodology, the band thresholds and the appetite thresholds with their rationales.

The consequence is worth stating plainly. Anything added after the backup was written is not in the file, so it is not there after the restore. That is why step two exists: it turns an irreversible decision into a reversible one.

Which backups restore, and which are refused

Backups are versioned. That sounds like housekeeping, but it is the difference between a file that restores cleanly years later and one that loads halfway and leaves you unsure what you are looking at.

How RiskOS treats backups written by different versions of the app
The backup fileWhat happensWhat to do
Written by an older version of RiskOSRestores. Older backups always restore.Nothing. Restore it as normal.
Written by the version you are runningRestores.Nothing.
Written by a newer version of RiskOSRefused. The file is not read at all rather than read in part.Install the current version of RiskOS on this Mac, then restore again.

Why a newer file is refused rather than opened

A backup written by a newer version may describe things this version has no way to represent. Reading what it recognises and discarding the rest would produce a register that looks complete and quietly is not. Refusing the file leaves the backup intact and the problem visible. Update the app and the same file restores in full.

Restoring a backup from a long time ago

An older file restores without ceremony, and the register comes back as it was on the day it was written — old ratings, old appetite, old methodology and all. If that methodology differs from the one you have used since, the restored register uses the backup's, and every score follows it. Check Settings ▸ Methodology afterwards so you know which rule the numbers obey.

Checking the restore landed

It is worth two minutes to confirm the file you chose was the file you meant. Read a handful of numbers you would notice being wrong.

Places to look after a restore and what each one confirms
Where to lookWhat you are confirming
DashboardThe headline counts: in the worked register, twelve active risks, an average residual of 9.6 out of 25, four above appetite and three overdue for review.
RisksThe newest risk you remember is present — RSK-0012, with RSK-0007 still six points above appetite.
ControlsStatus and effectiveness survived. CTL-0001 operating at High, CTL-0003 still planned rather than operating.
ActionsThe open count agrees with the day the backup was written — sixteen open, three of them overdue.
IndicatorsLatest readings and their status — a backup restore test success rate of 72 % showing as breached.
FrameworksYour mapping work came back with the register — coverage of seven of twenty-eight on the RiskOS Control Baseline.
SettingsThe organisation appetite threshold and any per-category thresholds read as they should.

When restoring is the right move

Restoring is a blunt instrument used precisely. It is the right answer in a few situations and the wrong one in most others.

After a change you cannot unpick

Undo and redo, Z and Z, handle the edit in front of you. A restore is for what sits further back than that — a bulk edit applied to the wrong selection, an import confirmed against the wrong register, a methodology change that turns out to have been premature. Take the pre-restore backup, put the older file in place, and compare.

Moving to another Mac

Back up on the old machine, move that one file to the new one, and restore it there. The register arrives complete, history and settings included, which is why this is the ordinary way to move.

Starting again on a clean machine

After a fresh installation of macOS, or on a Mac that has never run RiskOS before, a restore is the first thing to do: install the app, choose the file, confirm, and the register is in front of you.

When a restore is not what you want

If you need only some rows from another register — a control catalogue, a list of assets, risks captured by a colleague — a restore would replace everything rather than add anything. That job belongs to the CSV imports in Import & Export, which show line by line what will be created, updated or skipped.

Troubleshooting

The restore was refused and mentioned a newer version

The file was written by a newer version of RiskOS than the one on this Mac. It is intact and nothing has been lost. Install the current version, then choose File ▸ Restore from Backup… again and select the same file.

I restored the wrong file

Restore the backup you wrote in step two and you are back where you started. If you skipped it, use the most recent backup you hold; it will be older than the register you had, but it is the nearest point you can return to.

Risks I added this week are missing

The backup predates them. A backup carries the register exactly as it stood when the file was written, so anything added afterwards was never in it. Check the date in the filename against the day you added the work. If a later backup exists, restore that one instead.

The counts are lower than I expected

Look at the filters before you blame the file. The register hides closed and accepted risks by default, and the filter icon fills when a filter is on. Turn on show closed and accepted, clear any band or over-appetite filter, and the count usually resolves itself.

Scores look different after the restore

Settings travel in the backup. If the file was written under a different methodology — a different choice about whether controls reduce likelihood, impact or both, or different band thresholds — the restored register obeys that methodology, and the residual scores follow it. Open Settings ▸ Methodology to see which rule is in force.

I cannot find the backup file

RiskOS saves backups wherever you chose to put them, so look first in Documents ▸ RiskOS and Downloads. Look for the default naming pattern — the words Risk Register followed by a date, as in Risk Register 2026-09-21. If the backup reminder has been appearing and you have been dismissing it, there may be no recent file; write one now.

Habits that make a restore boring

A restore should be dull. These habits keep it that way.

  • Back up before anything irreversible. An import, a large bulk edit, a methodology change. B takes seconds and makes each of those a decision you can walk back.
  • Keep the reminder on. Weekly suits most registers, fortnightly a quiet one. The one setting that costs you later is never.
  • Keep the dated filenames. The default name carries the date for a reason, and a folder of files you renamed by hand tells you nothing at the moment you need to choose between them.
  • Keep more than one generation. Three or four recent files cover the case where the problem you are fixing started before the newest backup.
  • Put a copy somewhere else. A backup that lives only on the Mac it came from covers a mistake but not a lost machine. Keep the newest file wherever your other important documents live.
  • Test a restore once. Do it deliberately, straight after writing a fresh backup, so the first time you follow these steps is not the day it matters.
  • Check the counts afterwards. Two minutes on the dashboard confirms you put back the file you meant.

Frequently asked questions

How do I restore a risk register from a backup on a Mac?

Choose File ▸ Restore from Backup… and select the backup file. RiskOS tells you what restoring means for the register currently on this Mac and asks you to confirm. Confirm, and risks, history, controls, actions, assets, vendors, frameworks, indicators, events and settings all come back together. Back up the current register first, so the step is reversible.

Does restoring a backup delete my current risk register?

It replaces it. A restore is not a merge, so anything added since the backup was written will not be there afterwards. RiskOS explains this before it does anything and waits for you to confirm, and cancelling leaves the register untouched. Writing a backup of the current state first means you can always return to it.

What does a RiskOS backup file include?

The whole register in one file: risks, every assessment in their history, the audit trail, controls, actions, assets, vendors, frameworks and their mappings, indicators with their readings, events, and your settings — the methodology, the band thresholds and the appetite thresholds. Nothing is left behind for you to move separately.

Why will RiskOS not open my backup file?

Almost certainly because the file was written by a newer version of the app than the one on this Mac. Backups are versioned, and a newer file is refused outright rather than read in part, so you are never left with a register that looks complete but quietly is not. Install the current version and restore the same file again.

Can I restore an old backup from a previous version?

Yes. An older backup always restores. The register comes back as it stood on the day the file was written, including the methodology and appetite in force at the time, so check Settings ▸ Methodology afterwards if the file is old — the restored scores obey the backup's rules rather than your more recent ones.

How do I move my risk register to a new Mac?

Back up on the old Mac with B, move that single file across, then choose File ▸ Restore from Backup… on the new machine and confirm. History, controls, mappings and settings travel with it, so the register on the new Mac is the register you left, not a summary of it.

How often should I back up a risk register?

Weekly suits most registers, and always before something irreversible such as an import, a large bulk edit or a methodology change. A quiet reminder appears when your last backup is getting old, and you choose the interval it works to: never, weekly, fortnightly or monthly. Keeping three or four dated generations is enough for almost any recovery.

Does restoring a backup send anything over the internet?

No. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine. The backup is a file you chose where to save, and restoring reads it from wherever you put it. The only network RiskOS uses at all is Apple's App Store, for purchases, and it never sees your register.