How to search and filter a risk register on Mac
You can do this with RiskOS, a risk register for macOS. One search field, three filters, and a table that answers the question you actually came with.
Twelve risks fit on one screen. Two hundred do not, and by then the question you bring to a register is never "show me everything". It is narrower and more awkward: which cybersecurity risks sit above appetite, which of S. Ramirez's rows are overdue, where that supplier risk from the spring went. Search and the filters are how you ask, and how you stop rebuilding the same question every Monday.
Narrowing the table changes what you are looking at, not what the register holds. A filtered-out row is still there, and a filter on the table is not a filter on a report — report scope is chosen separately when you build one.
Where search and the filters live
Choose Risks in the sidebar. Above the table sits the search field, and beside it the filter control. Three filters change which rows are eligible at all: band, over-appetite only, and show closed and accepted. Save Current Filter… sits with them, so a combination can be named rather than remembered.
The table is the third control, and the easiest to forget. Every column sorts, and right-clicking the header lets you show, hide and reorder columns: Ref, Risk with its category, Owner, Inherent, Residual, Target, Trend, Appetite, Status and Review. RiskOS remembers the arrangement, so the register opens the way you left it.
Narrow the register, step by step
-
Open the Risks section
Choose Risks in the sidebar. The full register appears as a sortable table, with the search field and the filter control above it. Start from the whole list: it is the one state you can be certain about, and the only one where a row count means what you think it means.
-
Search for what you can name
Type into the search field. Search covers the title, reference, category, owner, detail and tags of every risk at once, so you need not know which field holds the word you remember. "Ransomware", "RSK-0007", "Halvorsen" and "logistics" are all reasonable things to type.
-
Filter by band
Open the filter control and choose a band to see only Low, Medium, High or Critical rows. The bands are cut at the same points everywhere in the register — 1–4 Low, 5–9 Medium, 10–16 High and 17–25 Critical — so this is the quickest way to triage a long register by seriousness before you read a single row in full.
-
Show only risks above appetite
Switch on over-appetite only. What remains is every risk whose residual score sits above the threshold that applies to it, whether that came from the risk's own override, its category, or the organisation-wide figure. In a register of twelve risks with an appetite of 9, that is often the four rows a meeting is about.
-
Decide whether closed and accepted risks count
Closed and accepted risks are hidden by default, because most days they are noise. Switch on show closed and accepted when you are looking backwards: auditing a decision, or finding a risk somebody retired last year. Risks are closed, never deleted, so the row is still there to find.
-
Sort what is left
Click a column header to sort the rows that survived. Residual is the usual first read: it is where you stand today rather than where you started. Review orders the table by what is due, Owner groups a person's work, and Trend surfaces what is moving the wrong way.
-
Check the filter icon before you conclude anything
The filter icon fills when a filter is on. Look at it before you read a count, quote a number in a meeting, or decide a risk has vanished. It is the difference between "we have three risks above appetite" and "three of the High risks I am looking at are above appetite".
-
Act on the rows you found
Select several rows to work on them together. Multi-select offers Mark Reviewed, Duplicate and Close, and closing several asks you to confirm. The panel also becomes a bulk editor: tick the fields to change — category, owner, business unit, status, treatment strategy, review cadence — set their values and apply them to every selected risk. Anything unticked stays as it was.
-
Save the combination you will want again
Choose Save Current Filter… and name the combination. Name it for the question rather than the settings: "Above appetite, open" reads better in six months than a list of toggles. Bringing the whole arrangement back turns a five-click routine into one.
What the search field looks at
One field, six places. That matters more than it sounds, because you rarely remember which field held the word you are reaching for. In RiskOS you search with whatever you happen to know: a fragment of the name, the owner, the category, or a reference quoted in a report.
| Matched on | What it holds | Useful when |
|---|---|---|
| Title | The one-line statement of what could go wrong | You remember roughly what it was called |
| Reference | The permanent identifier, such as RSK-0007 | Somebody has quoted a row from a report |
| Category | Cybersecurity, Cloud, Compliance & Regulatory and the rest | You want a whole theme at once |
| Owner | The person accountable for the risk | Preparing for a one-to-one or a handover |
| Detail | The description of what would actually happen | The word you remember was in the explanation |
| Tags | Whatever labels you have put on a risk | You keep your own cross-cutting groupings |
Because references are never reissued, searching for one is the most reliable lookup there is. RSK-0007 means the same risk for the life of the register, including after it closes, which is why it belongs in minutes rather than a title that may be reworded.
The three filters
The filters answer questions search cannot, because they are about a risk's position rather than its wording. No amount of typing finds everything above the threshold that applies to a category. That is arithmetic, and RiskOS does it for you.
| Filter | What it leaves on screen | Reach for it when |
|---|---|---|
| Band | Only rows in the band you pick: Low, Medium, High or Critical | Triaging by seriousness, or checking a band is not swallowing half the register |
| Over appetite only | Only rows whose residual score exceeds the threshold that applies to them | Building an agenda, or asking what you are tolerating that you said you would not |
| Show closed and accepted | Adds closed and accepted rows back alongside the active ones | Looking backwards: audits, handovers, an old decision |
Why the appetite filter is the sharpest one
A band filter tells you how big something is. The appetite filter tells you whether it is acceptable, a judgement your organisation has already made and written down. Appetite resolves in a fixed order — the risk's own override, then its category, then the organisation-wide threshold — so a Medium risk in a strict category can be over appetite while a High risk elsewhere is not. The two filters rarely give the same list.
What the filter icon is telling you
A filled filter icon is the register saying "you are not looking at everything". Almost every confusing moment in a filtered table — a missing risk, a count that seems too low, a category that looks empty — comes from a filter left on from the last question. Glance at it, then trust the table.
Stacking search, filters and sort
The three controls do different jobs, and work best in that order: filter to the population you care about, search within it, then sort to decide what to read first.
Everything narrows together
Search text and the filters apply at once, so the rows that survive satisfy every condition you have set. Typing "vendor" with the band on High and over-appetite only switched on gives the overlap, usually a handful of rows and sometimes none. An empty table is an answer, not a fault.
Sort is a separate question
Sorting changes the order of what is showing; it never changes which rows show. Keep that in mind and you can re-sort freely while you read, without wondering whether you are losing rows. New risks pin to the top of the table, so a row you have added a moment ago is where you expect it.
Columns decide what you can read
You can only sort on a column you can see, so your columns quietly shape how you work. Right-click the table header to show, hide and reorder them. Treatment work wants Residual, Target, Trend and Review in view; governance wants Owner, Appetite and Status. The arrangement is remembered, so set it once.
Searching the rest of the register
Every list section in RiskOS is searchable, and several carry filters shaped for what they hold. The pattern is the same everywhere: a search field, then a few filters aimed at the question that section answers.
| Section | Filters available | The question it answers |
|---|---|---|
| Risks | Band, over appetite only, show closed and accepted | What is serious, and what we are tolerating |
| Controls | Type, show retired | What we rely on, and whether it still runs |
| Actions | Owner, show completed | Who owes what, and what is overdue |
| Risk Library | Category, hide entries already added | What a register like ours usually holds |
| Frameworks | Coverage | Which requirements have nothing mapped |
Actions deserves a particular mention. It gathers every action across the register into one place, grouped by due state — Just Added, Overdue, Due Soon, Later, No Due Date and Closed. Filtering by owner is the quickest way to prepare for a conversation about everything one person is carrying.
Troubleshooting
I know this risk exists, but I cannot find it
Check the filter icon. If it is filled, a band filter or the appetite toggle is excluding the row before your search sees it. If the icon is clear, the risk is probably closed or accepted, which is hidden by default: switch on show closed and accepted and search again.
Searching for a person's name returns nothing
Search matches the owner as it is recorded, so "Maria" will not find a risk owned by "M. Halvorsen". Look at the Owner column for the form your register uses, then search that. If two spellings of one person have crept in, select the affected rows and use the bulk editor to set the owner consistently in one go.
The table came back empty
The conditions are stacking further than you meant. Filters and search text apply together, so a Critical band plus over-appetite only plus a search term can leave nothing. Clear the search field first: if rows return, the text was the narrow part; if not, loosen the filters one at a time.
Closed risks keep appearing in my list
The show closed and accepted toggle is still on from an earlier question. Switch it off and the table returns to active risks only. Do that deliberately after any backward-looking session, because closed rows inflate every count you read off the screen.
A tag I searched for found nothing
An empty result means no risk carries that exact tag. Try the wording of the description instead, since detail is searched too, and try the category: a theme you think of as a tag often already exists as one.
Habits that keep a register findable
- Write titles that name the event. Backup restoration has never been tested end to end is findable by half a dozen words somebody might type. Backups is findable by one.
- Quote references, not titles. RSK-0007 survives every rewording and is never reissued, so it is the safe thing to put in minutes and in email.
- Keep owner names in one form. One spelling per person makes the owner filter, the owner search and every report agree with each other.
- Save the filters you use weekly. Above appetite, and your own risks, are the usual two. Named once, they are a click thereafter.
- Clear a filter when you have finished with it. The filled icon tells you one is on, and clearing it stops a stale question shaping the next answer.
- Use a filtered view to act, not only to look. Once the right rows are in front of you, select them and mark them reviewed, or bulk-edit an owner or a cadence.
- Read the whole register occasionally. Clear everything once a quarter. Filters answer questions; the unfiltered table shows what you have stopped asking about.
Frequently asked questions
How do I search a risk register on a Mac?
Choose Risks in the sidebar and type into the search field above the table. One search covers the title, reference, category, owner, detail and tags of every risk, so a fragment of a name, an owner, a category or a reference such as RSK-0007 all find the right row without choosing a field first.
How do I see only risks above appetite?
Open the filter control and switch on over-appetite only. The table then shows every risk whose residual score exceeds the threshold that applies to it. Appetite resolves from the risk's own override, then its category, then the organisation-wide setting, so a Medium risk in a strict category can appear beside a Critical one.
Why can I not see a risk I closed?
Closed and accepted risks are hidden by default so daily work shows only what is live. Switch on show closed and accepted to bring them back. Nothing is lost: risks in RiskOS are closed rather than deleted, and their references, history and assessments stay intact for audits and handovers.
Can I save a filter I use often?
Yes. Build the combination you want — the band, the appetite toggle, the closed-and-accepted toggle — then choose Save Current Filter… and name it. Name it for the question it answers rather than its settings, so "Above appetite, open" still makes sense to a colleague months later.
How do I know whether a filter is on?
The filter icon fills whenever a filter is active. Check it before reading a count or deciding a risk has disappeared, because most confusing moments in a register come from a filter left on from an earlier question. The icon fills rather than merely changing tone, so the signal never rests on colour alone.
Can I change which columns the register shows?
Right-click the table header to show, hide and reorder columns. The choices are Ref, Risk with its category, Owner, Inherent, Residual, Target, Trend, Appetite, Status and Review. Your arrangement is remembered, and since you can only sort on a visible column, it shapes how fast you can answer a question.
Does searching my register send anything anywhere?
No. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine. Searches and saved filters are local, there is no tracking or analytics of any kind, and the only network use is Apple's App Store, for purchases, which never sees your register.