How to score a risk on Mac
You can do this with RiskOS, a risk register for macOS. Two ratings, one number, and a band you can defend in a meeting.
Scoring is the moment a risk stops being a sentence and becomes something you can sort, compare and report. It is also where registers go wrong: two people rate the same exposure differently, a number gets typed over by hand, and six months later nobody can say why a risk sits where it does. The fix is not a better argument about numbers. It is a scale everyone rates against, and a register that does the arithmetic itself.
Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine.
What you are actually rating
You rate inherent likelihood and impact — the risk as it would be with nothing standing in its way. That is the honest starting point, and it is the only pair of numbers you type. Everything else follows from it: RiskOS multiplies the two, names the band, and works out what is left once your controls are taken into account.
The reason to rate inherent rather than "how bad is it now" is that the second question quietly bakes your controls into a number nobody can unpick. Rate the exposure, record the controls separately, and the register can always show its working — including what would happen if a control were withdrawn.
Where scoring lives
Choose Risks in the sidebar and select a risk. The panel on the right opens on Summary; the section beneath it is Assessment, and that is where every rating on the risk is set. It holds the inherent likelihood and impact steppers, the control effectiveness picker, onset velocity, detectability, an optional exposure amount, and the target ratings — with the matrix and the comparison grid underneath, answering as you go.
Sections in the panel start closed and carry a preview on their own title row, so a risk with eight sections can be skimmed without opening one. Click Assessment to open it.
Rate a risk, step by step
-
Open the risk
Choose Risks in the sidebar and click the row you want. If the risk does not exist yet, press ⌘N to create one; it pins to the top of the table so you do not have to hunt for it.
-
Write the risk down properly first
Give it a one-line title that names the event, not the worry — Backup restoration has never been tested end to end rather than Backups — and a short description of what would actually happen. A vague title is the single most common cause of two people rating the same risk differently.
-
Open the Assessment section
Click Assessment in the panel. The inherent likelihood and impact steppers sit at the top, each a row of five buttons with the scale label shown beside it, so you can see you are choosing Likely and not just 4.
-
Set the inherent likelihood
Pick from Rare, Unlikely, Possible, Likely and Almost Certain. Think in a fixed window — "in any given year" is the usual one — and be consistent about it across the register. If you find yourself arguing between two values, take the higher one and write the reason into the description.
-
Set the inherent impact
Pick from Insignificant, Minor, Moderate, Major and Severe. Rate the realistic bad outcome rather than the worst thing imaginable, and rate against the organisation rather than against the team — a week of one department's disruption is rarely Severe.
-
Read the score and the band
The score appears immediately: likelihood multiplied by impact, from 1 to 25, with its band named beside it and a glossy severity bar showing where it falls. Low is 1–4, Medium 5–9, High 10–16 and Critical 17–25. The matrix underneath moves its inherent marker to the cell you just chose.
-
Add the context that changes decisions
Set onset velocity — how fast the risk would arrive once it starts — and detectability, how likely you are to notice. Neither changes the score. Both change what you do about it: a Moderate risk that arrives immediately and goes unnoticed deserves attention ahead of a High one you would see coming for months.
-
Link the controls that reduce it
Open Controls and link what you rely on. With derive effectiveness from linked controls switched on, the residual score follows your strongest operating control automatically. The residual bar drops and the matrix gains a second marker, so the distance between the two is visible rather than asserted.
-
Set a target, and check the gap
Set the target likelihood and impact you intend to reach. The comparison grid then shows inherent, residual, target and the gap between them, along with a line telling you what strength of control would close it. Changes save as you type, and every scoring edit is recorded in History with the score it produced.
The likelihood scale
The five points are deliberately coarse. A five-point scale forces a judgement; a hundred-point scale invites false precision and endless argument. What matters is that everyone rating risks in your register reads the points the same way.
| Rating | Value | A working reading |
|---|---|---|
| Rare | 1 | Would surprise you. No history of it here, and none nearby. |
| Unlikely | 2 | Possible, but you would not plan around it this year. |
| Possible | 3 | It has happened to organisations like yours, and could happen here. |
| Likely | 4 | You would not be surprised to be dealing with it this year. |
| Almost Certain | 5 | Expect it. The question is when and how bad, not whether. |
The impact scale
Impact is the harder of the two, because it invites people to rate the feeling rather than the consequence. Agree a rough anchor for each point — a cost, a duration, a number of customers, a regulatory outcome — and write it into the risk descriptions so the next person can see what you meant.
| Rating | Value | A working reading |
|---|---|---|
| Insignificant | 1 | Absorbed in the ordinary course of work. Nobody outside the team notices. |
| Minor | 2 | Noticeable disruption, handled within the team, no lasting effect. |
| Moderate | 3 | Management attention, real cost, recovery measured in days. |
| Major | 4 | Executive attention. Customers, regulators or the balance sheet feel it. |
| Severe | 5 | Threatens the organisation's obligations, licence to operate or survival. |
What the bands mean
The band is the register's shorthand. It sets the colour of the cell, the bar and the badge, and it is what a report leads with. It is never the only carrier of meaning: every band pairs its colour with a symbol and the written word, so the register reads the same to someone who cannot separate the two colours.
| Band | Score | What it usually calls for |
|---|---|---|
| Low | 1–4 | Accept and keep under review at the cadence you set. |
| Medium | 5–9 | Treat where it is cheap to do so; watch for movement. |
| High | 10–16 | A named owner, a treatment plan and a date. |
| Critical | 17–25 | Escalate. These are the rows an executive summary exists to carry. |
Why the thresholds sit where they do
On a 5×5 scale the products are not evenly spread — there is no way to score 11, 13, 14, 17, 18, 19, 21, 22, 23 or 24 — so the bands are cut where real scores cluster. Setting the boundary between High and Critical at 17 means only the top-right corner of the matrix reaches Critical, which is the point: a band that catches a quarter of the register tells you nothing.
Keeping scores consistent
A register's value comes from the comparisons it allows, and comparisons only hold if the scores were made the same way. A few habits carry most of that weight.
Rate against a fixed window
Pick a period — a year is the usual choice — and rate every likelihood against it. Mixing a "once a decade" judgement with a "this quarter" judgement in the same column makes the sort order meaningless.
Never type a residual score
Rate the inherent exposure, record the controls, and let RiskOS produce the residual. A residual typed in by hand is a number with no argument behind it, and it is the first thing an auditor will pull on. Where you do set effectiveness by hand, the risk's panel says so, and it points out when your value disagrees with the controls you have linked.
Start from a worked example
Open Risk Library and look at how a comparable risk is framed. The library carries thirty-nine worked examples across cybersecurity, cloud, third-party, continuity, project, compliance and AI risk, each with a suggested starting rating and a typical treatment. Entries arrive in your register as drafts, because a suggestion is a prompt, not an authority.
Write the reason down
A score without a reason is an opinion with a number attached. Use the description to say what drove the rating — the near miss last spring, the supplier's own disclosure, the regulator's letter. History keeps every assessment you ever made, so the reason is what makes the record readable a year later.
Troubleshooting
The score did not change when I changed a rating
Check which stepper you moved. The Assessment section carries two pairs: inherent likelihood and impact near the top, and target likelihood and impact further down. Moving a target rating changes the target marker and the gap, not the score at the head of the panel.
The residual score will not go down
Almost always the control is not yet operating. Only controls that are implemented or operating reduce risk; a planned control, however strong it will be, reduces nothing yet, and the control's own panel says so. Open the control, set its status, and every risk deriving from it re-scores.
Two people scored the same risk differently
Usually they rated different things: one rated the exposure and the other rated what is left after the controls. Agree that the steppers are always inherent, then compare the residual figures, which come from the same arithmetic for everyone.
Every risk is coming out High
Impact inflation. If most rows sit at Major or Severe, the scale has stopped separating anything. Re-read the impact anchors, re-rate a handful of the smallest risks first, and let the rest of the register fall back into shape around them.
I changed the methodology and everything moved
That is the intended behaviour. Settings ▸ Methodology chooses whether controls reduce likelihood, impact or both, and changing it re-scores every risk in the register immediately so that nothing is left rated under the old rule.
Getting more out of a score
Once the ratings are in, most of the value comes from what sits next to them.
- Sort by residual, not inherent. Inherent tells you how bad the world is; residual tells you where you actually stand this morning. The register sorts by any column, so keep residual as the one you read first.
- Set an appetite and let it argue with you. An organisation-wide threshold in Settings flags every risk above it, everywhere it appears — in the table, on the dashboard, in the report.
- Watch the gap, not the number. A Critical risk with a credible plan and a closing gap is in better shape than a Medium one nobody has looked at since March.
- Let indicators challenge the rating. A key risk indicator measures something real on a cadence, and flags movement before anyone re-scores a thing.
- Let events challenge it harder. When a risk materialises more often than its likelihood implies, the register says so and suggests what the observed frequency would justify.
- Re-score in one pass. Review walks the risks that are due, one at a time, worst first, with the full context beside the scoring inputs.
- Keep the history. Every assessment is kept with the reason behind it, which is what turns a register into a record rather than a snapshot.
Frequently asked questions
How is a risk score calculated?
Likelihood multiplied by impact, each rated 1 to 5, giving a score from 1 to 25. RiskOS bands that score as Low (1–4), Medium (5–9), High (10–16) or Critical (17–25), and shows the band as a colour, a symbol and a word together, never colour alone.
Should I score the risk before or after controls?
Before. The steppers you set are always inherent — the exposure with nothing standing in its way. Link the controls separately and the residual score is calculated from their effectiveness, so the register can always show how it got from one number to the other.
What is the difference between a score and a band?
The score is the number, 1 to 25. The band is the category that number falls into, and it is what a report, a dashboard tile and a matrix cell colour respond to. Two risks can share a band and still be several points apart, which is why the register sorts on the score.
Can I change the scoring scale?
The scales and band thresholds are shown in Settings ▸ Methodology, along with the one choice that does change every score: whether controls reduce likelihood, impact or both. Change it and RiskOS re-scores the whole register at once rather than leaving old ratings behind.
Why can I not type a residual score directly?
Because a typed residual is a number with no argument behind it. RiskOS calculates it from the controls you link, or from an effectiveness value you set by hand — and when a hand-set value disagrees with the linked controls, the risk's panel points that out rather than quietly picking one.
Do onset velocity and detectability change the score?
No, and that is deliberate. They change what you do about a risk rather than how big it is. A Moderate risk that arrives immediately and goes unnoticed often deserves attention ahead of a High one you would see coming for months, and recording both lets you make that call from the register.
How do I keep scores consistent across a team?
Rate every likelihood against the same fixed window, anchor each impact rating to something concrete, always rate inherent rather than residual, and write the reason for a rating into the risk's description. History keeps every assessment with its reason, so the record stays readable long after the meeting.
Does anything I score leave my Mac?
No. There is no account and no sign-in, nothing is uploaded, and there is no tracking or telemetry of any kind. Your register stays on your Mac and leaves it only when you export or back it up yourself. The only network use is Apple's App Store, for purchases, and it never sees your register.