How to run a quarterly risk review on Mac
You can do this with RiskOS, a risk register for macOS. One scoped pass, worst risk first, and a record at the end that somebody else can read.
Registers rarely fail loudly. They drift. A rating set in March that nobody has looked at since, an action whose due date passed in a quarter nobody remembers, a control still marked planned two years on. The quarterly pass is the habit that stops the drift, and it works best when it is the same pass every time: same scope, same order, same record at the end.
Ninety minutes, four times a year, is enough to keep a register defensible. A quarter is long enough that something real has changed, and short enough that you can still remember what. RiskOS is built around that rhythm — it knows which risks are due, brings them to you one at a time worst first, and writes down what the pass decided.
Skipping a risk during a review leaves it completely untouched: no review date, no assessment, nothing. It stays in the queue for the next pass. Skip freely when the person who knows the answer is not in the room.
What a quarterly pass has to produce
Three things, and naming them first decides how you run the hour. A current rating on every risk that was due, either confirmed as it stands or re-scored with a reason. A decision on the exceptions: the risks above appetite, the actions already late, the indicators sitting in breach. And a record somebody who was not in the room can read six months later. RiskOS produces all three from the same pass.
Everything else is optional. A quarterly review is not the occasion to rewrite the register or re-argue the methodology. It is a pass over what is due, and leaving the rest alone keeps it to ninety minutes rather than a lost afternoon.
Where review mode lives
Choose Review in the sidebar. It sits in the Register group, beneath Risks, Controls and Actions. What opens is not a list: it is a chooser with four scopes, each showing a live count of how many risks it would gather right now. Pick one and the pass begins.
From then on the screen holds one risk at a time, worst first, with a progress bar showing how far through the queue you are. The scoring inputs sit beside the full context of the risk — its owner, its open actions, the controls linked to it and when it was last reviewed — so the judgement and the evidence for it are in one view. The projected rating updates as you move a stepper, before anything is written.
Run the quarterly pass, step by step
-
Put the pass in the diary before the quarter starts
Book a fixed point — the second week of each quarter is a common choice — and keep it. Each risk schedules its own next review from the cadence set on it, so a pass that happens at roughly the same point every quarter keeps the due dates landing together instead of scattering across the calendar. Invite the risk owners whose risks are due, not everybody.
-
Read the register before you open a single risk
Choose Dashboard in the sidebar and write down the headline numbers: active risks, average residual score, how many sit above appetite, how many reviews are overdue, how many actions are open and late. A register might open the quarter at twelve active risks, an average residual of 9.6 out of 25, four above appetite and three overdue. Those figures are the first line of the meeting and what you compare against next quarter.
-
Open Review and choose the scope
Choose Review and read the four counts before committing to one. Overdue for review is the backlog. Due within 30 days is what would otherwise become next quarter's backlog. Above appetite is the exception list. All active risks is the whole open register. Start an ordinary quarter with the overdue scope; it is the count that has to reach zero.
-
Work the queue worst first
Risks arrive in order of severity, so the pass spends its sharpest half hour on the rows that deserve it. Read the context beside the scoring inputs before you touch a stepper: who owns the risk, what was promised last time, which controls are linked and what state they are in. A risk with three overdue actions usually needs a conversation about the actions rather than a new rating.
-
Confirm what has not moved
When the rating still looks right, press ⇧⌘↩ to confirm. That stamps today's date as the review date and schedules the next review from the risk's own cadence. A confirmation is a real outcome, not a skipped row: it records that the risk was looked at on that date and that the rating stood.
-
Re-score what has moved, and say why
Where something has genuinely changed, adjust the inherent likelihood or impact and watch the projected rating update before you commit. Press ↩ to save and move to the next risk. Write the reason down as you go — the supplier's disclosure, the near miss in July, the control that finally went live. A re-score landing on the same number is recorded as a confirmation, so nothing is lost by checking.
-
Answer the flags the register raises
Some risks arrive carrying a warning. An over-appetite flag means the residual score exceeds the threshold that applies to that risk. A linked indicator in breach means what you chose to measure has crossed the line you set. An underrated-likelihood warning means the risk has materialised more often than its rating implies, and it carries the rating the observed frequency would justify. Each is a question to answer, not a decoration.
-
Clear the overdue actions
When the queue is empty, choose Actions and work the Overdue group from the top. Every row edits in place, so a status, an owner or a due date changes without opening anything, and each row names the risk or control it came from. Three late actions out of sixteen open is a normal quarter; the point is that every one of them leaves the meeting with a name and a date against it.
-
Read the summary, then write the record
At the end of the pass a summary shows what moved, risk by risk — what was confirmed, what was re-scored and in which direction. Read it aloud if the meeting is still running; it is the minutes, already written. Then choose Reports in RiskOS, set the cover fields and sections, and export. Finish with File ▸ Back Up RiskOS… so the quarter is kept as it was signed off.
Choosing the scope for the pass
The scope decides the length of the meeting, so choose it deliberately rather than defaulting to everything. Each of the four carries a live count, so you can size the pass before you start it.
| Scope | What it gathers | When it suits the quarter |
|---|---|---|
| Overdue for review | Every risk whose next review date has already passed. | Always first. This is the count that has to reach zero before the quarter is done. |
| Due within 30 days | Risks falling due in the coming month. | The second pass. Pulling them forward stops next quarter opening with a backlog. |
| Above appetite | Every risk whose residual exceeds the threshold that applies to it. | A board quarter, where the exceptions are the agenda and the rest is background. |
| All active risks | The whole open register, worst first. | An annual pass, a change of risk owner, or a small register you can read end to end. |
A two-pass quarter
The pattern that holds up best over a year is two passes in one sitting. Run Overdue for review until the queue is empty, take a break, then run Due within 30 days. The second pass is usually quick, because most of those risks have not changed and confirm in a keystroke — and each one you confirm now is one that will not be overdue in three months.
Working the queue
Four keys carry the whole pass, and RiskOS asks nothing else of you between one risk and the next. Learning them turns a review from a sequence of clicks into something closer to reading.
| Key | What it does | What it leaves behind |
|---|---|---|
| ⇧⌘↩ | Confirm the rating as it stands | Today's review date, and the next one scheduled from the risk's cadence. |
| ↩ | Save the ratings you changed and go to the next risk | A new assessment in the risk's history, with the reason and the score it produced. |
| ⌘→ | Skip to the next risk | Nothing at all. The risk is untouched and stays in the next pass. |
| ⌘← | Step back to the previous risk | Nothing. Use it when you realise the last decision needs a second look. |
Confirming is a decision, not an absence of one
Most rows in a healthy register confirm. Say so in the meeting, because teams often feel a review has failed when nothing moved. It has not. A confirmed rating carries a date in the risk's history, which is what an auditor wants when they ask how you know the number is still right.
What skipping does
Skipping is the honest option when you cannot answer the question. It writes nothing — no review date, no assessment, no change of any kind — so the risk keeps its due date and reappears in the next pass. Use it when the owner is on leave or a reading is a week away. What you should not do is confirm a rating you do not believe in order to clear the queue.
Leaving the session and coming back
A pass can be interrupted. Go to Controls to correct a status, to Actions to reassign something late, or to Indicators to enter a reading, and the session is waiting when you return. Everything decided before you left is already recorded.
The quarterly agenda in one table
Run the same six stages every quarter and the pass becomes something you can hand to a colleague. The last column matters most: every stage should leave something behind that outlives the meeting.
| Stage | Where | What it leaves behind |
|---|---|---|
| Open with the numbers | Dashboard | The headline counts, written down, ready to compare next quarter. |
| Clear the backlog | Review | A review date on every risk that was overdue. |
| Pull the next month forward | Review | An empty due-soon queue and a quieter next quarter. |
| Work the exceptions | Risks, Indicators, Events | A decision on every risk above appetite and every indicator in breach. |
| Land the actions | Actions | An owner and a date on everything overdue. |
| Write the record | Reports, then File ▸ Back Up RiskOS… | A report for the people who were not there, and a dated backup. |
Writing the record
The pass is only half the job. A quarterly review that leaves nothing behind is a conversation, and conversations are not evidence. Choose Reports while the session is fresh and let RiskOS build the document from the register as it now stands.
What to include in the report
Set the cover fields first — report title, organisation and who prepared it — because those are what a reader checks before anything else. Then choose sections. For a quarterly pack the executive summary, the risk matrix, the top risks and the open actions carry most of the meaning; add risk indicators and risk events when the quarter had movement in them, and framework coverage when somebody is asking about it. The full register and the per-risk detail pages are worth including once a year rather than every quarter.
Which output goes to whom
All four outputs come from the same snapshot, so they never contradict each other. The PDF is the paginated document for the meeting, with a branded cover and a running header and footer. The HTML file is one self-contained page that opens in any browser, which suits a reader who only wants to look. The Excel workbook suits anyone who will test a scenario, because its formulas re-score themselves when a likelihood changes.
Back up when the quarter is signed off
Finish with File ▸ Back Up RiskOS… or ⇧⌘B. One file holds everything RiskOS keeps — risks, history, the audit trail, controls, actions, assets, vendors, frameworks, indicators, events and settings — and the default filename carries the date, so a folder such as Documents ▸ RiskOS becomes a quarter-by-quarter archive. Back up after the review rather than before, so the file matches what was signed off.
Troubleshooting
Review says there is nothing due
The overdue count is genuinely zero, which is good news, but check the cadences first. A register where every risk is on an annual cadence looks quiet for three quarters and then arrives all at once. Open Risks, look at the Review column, and shorten the cadence on anything High or Critical.
The same risks are overdue again every quarter
Two causes, easy to tell apart. Either they are being skipped, which writes nothing and leaves the due date where it was, or their cadence is shorter than the gap between your passes — a monthly cadence reviewed quarterly is overdue by definition. Decide which risks genuinely need watching monthly and set the rest to the rhythm you work to.
I skipped a risk by mistake
Nothing has been lost, because a skip writes nothing. Press ⌘← to step back and make the decision properly. If the pass has already finished, the risk is still overdue, so starting the overdue scope again brings it back to the front of the queue.
The pass is taking too long
Narrow the scope. An hour on the overdue queue beats three hours on the whole register, and the counts show the size of the job before you commit. Where a group of Low risks genuinely has not changed, select them together in Risks and choose Mark Reviewed rather than walking each one through the queue.
The report does not match what I saw in the review
A report is a snapshot of the register at the moment you export it. Produced before the pass finished, it shows the older picture. Export again once the queue is empty and the actions are landed — every output is built from one snapshot, so the PDF, the HTML file and the workbook all agree.
Habits that make the next pass shorter
Most of the effort in a quarterly review goes on things that could have been settled weeks earlier. These are the habits that pay back.
- Set the cadence when you create the risk. A cadence chosen as you write the risk down is a decision; one chosen during a backlog clear-out is a guess.
- Save the quarter's view. Build the filter combination you open every quarter — over appetite, a particular category, closed hidden — and use Save Current Filter… to name it, so the next pass starts with one click.
- Let indicators watch between passes. A key risk indicator measures something real on its own cadence and flags a breach the week it happens, not the quarter you next open the register.
- Record events when they happen. An event logged in the week it occurred is accurate; one reconstructed during the review is folklore, and it is the accurate ones that let RiskOS tell you a likelihood is underrated.
- Keep the reasons short and concrete. One sentence naming what changed beats a paragraph of justification, and it is what makes the history readable a year later.
- Export the same sections every quarter. A pack whose shape does not change lets a reader compare quarters instead of relearning the document.
- Back up on the same day as the review. The reminder interval is yours to choose, and a dated file saved at the end of every pass means the quarter can be reconstructed exactly as it was signed off.
Frequently asked questions
How often should a risk register be reviewed?
Quarterly is the usual rhythm for the register as a whole, with each risk's own cadence doing the finer work — annually for stable Low risks, quarterly or monthly for High and Critical ones. RiskOS schedules the next review from that cadence when you confirm or re-score, so the queue fills itself between passes.
What should a quarterly risk review cover?
Everything overdue for review, everything falling due in the next month, every risk above appetite, and every action already late. Start from the dashboard numbers, work the review queue worst first, deal with the indicators sitting in breach, then land the overdue actions. Leave category tidying and methodology debates for a separate sitting.
How long does a quarterly risk review take?
For a register of around a dozen active risks, roughly ninety minutes. The scope counts tell you before you start: risks that have not moved confirm in one keystroke, so the time goes on the handful that have. If a pass regularly runs past two hours, the scope is too wide or the cadences are too short.
What is the difference between confirming a risk and re-scoring it?
Confirming accepts the rating as it stands. Re-scoring changes the likelihood or impact first. Both stamp today's review date, schedule the next from the risk's cadence and appear in its history. A re-score that lands on the same number is recorded as a confirmation, so there is no penalty for checking.
Does skipping a risk in a review mark it as reviewed?
No. Skipping leaves the risk completely untouched — no review date, no assessment, no change. It keeps its existing due date and reappears in the next pass. That makes skipping safe when the owner is unavailable or you are waiting on a number, and it is always better than confirming a rating you do not believe.
Can I stop a review halfway and finish it later?
Yes. The session survives leaving for another section, so you can check a control's status or reassign a late action and come back to the risk you left. Everything you have already confirmed or re-scored is saved as you go, so an interrupted pass never loses the decisions made before the interruption.
How do I produce a record of a quarterly risk review?
The end-of-session summary shows what moved, risk by risk. For the formal record, open Reports, fill in the title, organisation and preparer, choose your sections and export. The PDF suits a meeting pack, the HTML file suits a single reader, and the Excel workbook suits anybody who will test a scenario against the numbers.
Does a quarterly review send anything off my Mac?
No. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine except in the exports and backups you create yourself. The only network use is Apple's App Store, for purchases, and it never sees your register.