Building the Register

How to see a risk's history on Mac

You can do this with RiskOS, a risk register for macOS. Every assessment a risk has ever had, kept with the reason behind it and the score it produced.

A register answers two questions, and only one of them fits in a table. How bad is this risk today is on every row. How did it get to that number, and who decided is the question an auditor asks, the question a new risk owner asks in their first week, and the question a board asks when a score halves between one meeting and the next. A list of current scores cannot answer it. A history can.

Note

A re-score that changes nothing is recorded as a confirmation. That means a rating which has held steady for a year reads as a decision somebody made and stood behind, rather than a row nobody opened.

Where a risk's history lives

Choose Risks in the sidebar and select a row. The panel on the right holds the whole risk in sections — Summary, Assessment, Treatment, Appetite, Controls, Actions, Context, Intelligence and History. History is the last of them, and it is the only one that looks backwards. Every other section describes the risk as it stands today; History describes how it came to stand there.

History has two parts. At the top, a chart of the residual score over time: the number as it stood after your controls were taken into account, plotted at each point it was assessed. Beneath it, the list of assessments themselves, each one carrying the reason it was made and the score it produced. RiskOS writes both as you work. Between them they turn a single figure into a line you can follow.

Read a risk's history, step by step

  1. Find the risk you want to trace

    Choose Risks in the sidebar and use the search field. Search covers the title, the reference, the category, the owner, the detail and the tags, so RSK-0007 and restoration both land on the same row. If the risk you want is not in the list, switch on show closed and accepted in the filters — risks are closed rather than deleted, and a closed risk keeps everything it ever recorded.

  2. Go to the History section

    Move to History at the foot of the panel. The residual score chart sits at the top of the section and the list of assessments runs beneath it. The panel shows whatever is selected in the list, so you can work down the table and read each risk's record in the same place. Drag the divider if the chart wants more room; RiskOS remembers where you leave it.

  3. Read the shape before the entries

    Look at the chart before you read a word. A flat line, a single step down, a slow slope or a sudden rise each point at a different kind of event, and the shape tells you which entries are worth opening. On a risk like RSK-0007, where an inherent of 20 now carries a residual of 15, the interesting moment is the one step where the gap opened, not every entry around it.

  4. Work down the list of assessments

    Each entry records an assessment: the score it produced and the reason given for it. Read them as a sequence rather than in isolation. Two assessments a fortnight apart with contradictory reasons usually mean the risk was re-described rather than re-rated, and that is worth fixing in the title before it happens again.

  5. Match a movement to its cause

    Open the Controls section on the same risk. It lists every linked control with its status and effectiveness, and it is where most residual movement comes from: a control reaching implemented or operating, an effectiveness rating revised, a control unlinked. If a value you set by hand disagrees with the controls you have linked, the panel says so rather than quietly picking one.

  6. Check what the last review did

    Look at Summary for the review cadence and the next review date. Confirming or re-scoring a risk in Review stamps the review date and schedules the next one from that cadence, so the two records read together: History says what the rating did, and the review date says when somebody last looked at it deliberately.

  7. Write the reason when you re-score

    The score is arithmetic and RiskOS handles it. The reason is the part only you can supply, and it is what makes the entry readable in a year: the near miss in the spring, the supplier's own disclosure, the finding from an audit, the control that finally went live. Changes save as you type, so the record is written as you work rather than at the end.

  8. Keep the history safe

    Choose File ▸ Back Up RiskOS or press B. A backup writes everything — risks, their history, the audit trail, controls, actions, assets, vendors, frameworks, indicators, events and settings — to a single file you save wherever you choose. Default filenames carry the date, like Risk Register 2026-09-21.

What the chart is telling you

The chart plots residual, not inherent. That is deliberate: inherent is your judgement of the exposure and it should be stable, while residual is where you actually stand, and it moves as controls come and go. Most shapes fall into a handful of patterns.

Common shapes in a residual score chart and what usually causes them
ShapeUsually meansWhere to look next
Flat lineThe rating has held. Either it was confirmed at each review, or nothing has been assessed since the first entry.The assessment list, and the next review date in Summary
Single step downA control reached implemented or operating, or its effectiveness was revised upwards.The Controls section on the risk
Slope across several entriesA treatment plan working through in stages rather than one change landing at once.Treatment, and the open actions beneath it
Step upInherent likelihood or impact was re-rated higher, or a control was retired, downgraded or unlinked.The reason on that entry, then Controls
Line that starts lateThe risk existed before it was rated — a library entry that arrived as a draft, or a row captured in a hurry.Assessment, to set inherent ratings properly

A flat line is not always neglect

Registers are often judged on movement, which pushes people towards changing numbers to show activity. A risk that has been confirmed at four consecutive reviews and has not moved is in better shape than one that has drifted a point each quarter with no reason attached to any of it. Read the entries under a flat line before concluding anything: a run of confirmations is evidence of attention, and an empty stretch is the opposite.

A step you cannot account for

If a movement has no obvious cause on the risk itself, the cause is almost always one level out. Editing a control's status or effectiveness re-scores every risk deriving from that control, and changing whether controls reduce likelihood, impact or both re-scores the entire register at once. Both are intended behaviour, and both show up as movement on charts nobody opened that day.

What lands in History, and what does not

Knowing which actions leave a record — and which deliberately leave none — is what stops a history being misread. The distinction matters most during a review pass, where three keys do three different things.

Actions in RiskOS and the record each one leaves on a risk
What you doWhat the record shows
Move an inherent likelihood or impact stepperA new assessment with the score it produced. The matrix markers move at the same time.
Press ⇧⌘↩ to confirm in ReviewA confirmation. The review date is stamped and the next one scheduled from the risk's cadence.
Press ↩ to save and go to the next riskThe new assessment with its reason, plus the same review stamp and schedule.
Press ⌘→ to skip a risk in ReviewNothing at all. The risk is left completely untouched and stays in the next pass.
Change a linked control's status or effectivenessEvery risk deriving from that control re-scores, and the movement appears on each of their charts.
Change whether controls reduce likelihood, impact or bothThe whole register re-scores immediately, so no risk is left rated under the old rule.
Edit a title, owner, category or treatment planNo score movement, so the chart is unchanged. These are not assessments.

Why a confirmation counts

A register that only recorded changes would quietly lose its best evidence. The most common outcome of a competent review is that a rating is still right, and if that outcome left no trace, the record could never distinguish between a risk somebody examined and agreed with and a risk nobody has opened since it was written. Recording a confirmation closes that gap.

Why skipping leaves nothing

Skipping is the honest option when you do not have what you need to judge a risk — the owner is away, the incident report has not landed, the control evidence is still being gathered. Because a skip leaves the risk completely untouched, its review date is not stamped and it stays in the queue for the next pass. A skip is not a soft confirmation, and the history is careful not to let it look like one.

Where else the register keeps a record

The History section is the per-risk view. Several other parts of RiskOS carry the same story at a different scale, and knowing which one answers your question saves opening twelve risks one at a time.

The Trend column

The register table carries a Trend column beside Inherent, Residual and Target. It gives the direction of travel on every row at once, which is the fastest way to find the risks whose history is worth reading. The table sorts by any column, and right-clicking the header lets you show, hide and reorder them; the arrangement is remembered.

The review summary

At the end of a review pass, a summary shows what moved, per risk. It is the record of a single sitting rather than the record of a single risk, and it is the thing to keep beside the minutes when somebody asks what the quarterly review actually did.

Events and indicators

Two more records sit alongside the ratings. Events holds the risks that actually happened, with the date they occurred, the date they were detected, the severity as experienced, the cost and the lessons. Indicators keeps a reading history for every measure you track, drawn as a chart with the warning and breach lines on it. Both appear on the risk's Intelligence section, and when a risk materialises more often than its rating implies, RiskOS says so and suggests what the observed frequency would justify.

Carrying the record outward

Reports can include per-risk detail pages alongside the executive summary, the matrix and the top risks, all drawn from one snapshot so every section agrees. Press P for a paginated PDF or E for a self-contained HTML file, and the state of the register on that date travels with the document.

Troubleshooting

History is empty on a risk I have had for months

A history begins at the first assessment, not at the moment the row was created. A risk added from Risk Library arrives as a draft carrying a suggested starting rating, and a risk captured quickly in a workshop may never have had its steppers set. Open Assessment, set the inherent likelihood and impact, and the record starts from there.

The chart is flat but I know things changed

The chart draws the residual score and nothing else. Reassigning the owner, moving the risk to another category, rewriting the treatment plan and closing three actions are all real work, and none of them is an assessment. If the score genuinely has not moved through all of that, the treatment has not yet reached the point where a control changed status.

The residual dropped and nobody re-scored anything

Somebody changed a control. Editing a control's status or effectiveness re-scores every risk that derives from it, which is the point — a risk should not keep claiming credit for a control that has been withdrawn, or miss the benefit of one that has gone live. Open the risk's Controls section to see which one moved.

A review pass left nothing on some risks

Those risks were skipped. Skipping leaves a risk completely untouched, so there is no assessment, no confirmation and no review stamp, and the risk stays in the scope for the next pass. If you meant to agree with the rating, open the risk and confirm it rather than skipping past it.

I cannot find a risk we retired last year

Closed risks are hidden from the register until you switch on show closed and accepted in the filters. Nothing was lost: risks are closed rather than deleted precisely so that the assessments, the reasons and the chart survive the decision to stop tracking them. The filter icon fills when a filter is on, which is the quickest way to tell why a row is missing.

Habits that keep a history worth reading

  • Give every assessment a reason. A score with no reason is an opinion with a number attached, and it is the first entry anyone will question. One sentence naming what changed is enough.
  • Confirm rather than skip. If the rating is still right, say so. Confirmations are what let a flat line mean attention instead of silence.
  • Review on a cadence you can keep. A quarterly cadence that happens beats a monthly one that does not, and the review date scheduled from the cadence is what keeps the record evenly spaced.
  • Re-rate the exposure, not the comfort. Inherent ratings should move rarely. If one changes every quarter, the controls are leaking into the rating and the history will show it.
  • Read the chart before the meeting. Five minutes across the risks with the steepest movement is a better agenda than a full register read aloud.
  • Close risks instead of deleting them. A closed risk keeps its history, which is what lets you answer a question about a risk you stopped tracking two years ago.
  • Back up before anything large. Before an import, a framework revision or a methodology change, press B. The backup carries the history, not only the current scores.

Frequently asked questions

How do I see when a risk score changed?

Select the risk in Risks and open the History section at the foot of the panel. A chart plots the residual score over time and the list beneath it holds every assessment ever made, each with the reason it was made and the score it produced. Read the chart for the shape, then open the entries around any step.

What does a risk's History section show?

Two things. A residual score chart, which draws the number as it stood after controls at each point it was assessed, and the full list of assessments with their reasons. Together they show not only where a risk sits today but how it arrived there, which is the part a current score can never tell you.

Why does a review that changed nothing still appear?

Because agreeing with a rating is a decision. A re-score that changes nothing is recorded as a confirmation, so a steady line can be read as a risk somebody examined and stood behind rather than one nobody opened. Without that, a register could never distinguish attention from neglect.

Why did a residual score change when nobody edited the risk?

Something the risk depends on moved. Editing a control's status or effectiveness re-scores every risk deriving from it, and changing whether controls reduce likelihood, impact or both re-scores the whole register at once. Open the risk's Controls section to see which control changed, then read the History entry alongside it.

Can I see the history of a closed risk?

Yes. Risks are closed rather than deleted, so a closed risk keeps its assessments, its reasons and its chart. Switch on show closed and accepted in the register filters, select the risk and read History as usual. This is why closing is the right way to retire a risk you no longer track.

Does a backup include risk history?

Yes. File ▸ Back Up RiskOS writes risks, their history, the audit trail, controls, actions, assets, vendors, frameworks, indicators, events and settings to a single file saved wherever you choose. Restoring that file brings the history back with everything else, so a record is never reduced to current scores alone.

How long is risk assessment history kept?

Every assessment a risk has ever had is kept for as long as the risk exists, and risks are closed rather than deleted, so nothing falls off the end. That is what makes a register defensible over years: the answer to a question about a rating made three years ago is still in the risk that carried it.

Does my risk history leave my Mac?

No. There is no account and no sign-in, nothing is uploaded, and there is no tracking of any kind. Your register and its history stay on your Mac and leave it only when you export or back them up yourself. The only network use is Apple's App Store, for purchases, and it never sees your register.