Import, Export & Backups

How to set a backup reminder on Mac

A quiet notice from RiskOS when your last backup is getting old, at an interval you choose. Four options, and what each one assumes about your register.

A register earns its worth slowly. One risk today, a re-score after a near miss, a control moved to operating in March, and a year of history sitting behind the number somebody is now asking you to defend. All of that lives on one Mac. The reminder exists so that remembering to protect it is not the part you have to be good at.

Note

Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine. The backup you take is therefore the copy that exists.

Where the backup reminder lives

Two things sit behind this job, and they are in different places. Writing a backup is a command: File ▸ Back Up RiskOS…, or B from anywhere in RiskOS. Being reminded to run it is a setting, so it lives with the other choices that apply to the whole register. Press ,, or choose Settings in the sidebar.

The interval has four values: never, weekly, fortnightly and monthly. That is the whole of the control. It changes when a notice appears and nothing else — not what a backup contains, not where files are saved, not how the register behaves day to day.

The notice itself is deliberately quiet. It appears when the age of your last backup passes the interval you chose, it says so, and it waits. Nothing is written on your behalf, because taking a backup means choosing where the file is saved, and that choice stays with you.

Set the reminder, step by step

  1. Decide how much a lost week would cost

    Before choosing an interval, picture the work you would have to redo. A register touched ten times a week — new risks, re-scores, actions closed, readings recorded — is a different proposition from one opened at quarter end. The right interval is the one that keeps the redo list short enough to be an afternoon rather than a project.

  2. Open Settings

    Press ,, or choose Settings in the sidebar. Settings holds the choices that apply across the whole register rather than to a single risk, which is why the backup reminder belongs here and not in a menu you would have to go looking for.

  3. Choose a reminder interval

    Pick never, weekly, fortnightly or monthly. Match it to the answer you gave yourself in the first step rather than to what sounds diligent: a reminder you learn to dismiss without reading is worse than no reminder, because it teaches you that the notice means nothing.

  4. Take a backup straight away

    Choose File ▸ Back Up RiskOS… or press B. RiskOS writes everything into a single file — risks, history, the audit trail, controls, actions, assets, vendors, frameworks, indicators, events and settings — and saves it wherever you choose. Doing it now means the reminder is counting from a real backup instead of from nothing.

  5. Give the file one home

    RiskOS asks where each backup should go, so choose a save location once and use it every time. Documents ▸ RiskOS works as well as anywhere, and the point is only that every backup lands in the same place. A file you cannot find under pressure has not protected anything.

  6. Leave the date in the filename

    The suggested name carries the date already, in the form Risk Register 2026-09-21. Leave it as it is. Named that way, a folder of backups sorts itself into age order, and picking the right one later becomes reading rather than guessing.

  7. Answer the notice when it appears

    When the reminder turns up, back up then. It takes a keystroke and a save location. Leave it for later and it becomes a note to yourself, competing with everything else in the day. Writing a new file is what makes the notice go away for another interval; reading it and carrying on leaves your last backup exactly as old as it was.

  8. Keep more than the newest file

    Do not overwrite yesterday's backup with today's. Keep the last three or four, because the failure you have to plan for is not always a sudden one — sometimes it is a bad import or a change of mind noticed a fortnight later, and then the file you want is the one from before. Dated filenames make that choice obvious.

Choosing an interval

All four settings are defensible. What separates them is an assumption about how much your register changes between one backup and the next, so choose by reading the middle column below and finding the row that sounds like your week.

The four backup reminder intervals and what each one suits
IntervalSuitsWhat it assumes
NeverA register you keep to a schedule of your own, or one you have finished withYou will remember without being asked
WeeklyAn active register: edits most days, reviews in flight, actions closingLosing a week would mean redoing real work
FortnightlySteady maintenance — a few changes a week and a monthly reporting rhythmLosing a fortnight is inconvenient rather than serious
MonthlyA stable register touched mainly around board dates and quarter endsMost weeks change little or nothing

Matching the interval to your review cadence

The cleanest rule is to be reminded a little more often than you review. If risks carry a quarterly cadence and you work through them in one pass, monthly reminders will always land between passes and catch the ordinary edits in between. If you review continuously, a week is a better unit, because a week is roughly how much re-scoring you would have to reconstruct from memory.

When never is the right answer

Choose never when a reminder would be noise. If backing up is already part of a Friday routine you keep without prompting, or the register is a finished piece of work you consult rather than edit, the notice adds nothing and slowly trains you to ignore notices in general. The cost is honest and worth stating: with never selected, nothing will ask, and the age of your last backup becomes entirely your business.

What a backup carries

One file holds the whole register, which is why a backup is the thing to keep rather than a copy of any single list. It is worth knowing what travels, because the parts that are hardest to reconstruct are the ones nobody thinks about until they are gone.

What a RiskOS backup file contains
What travelsWhy it matters
Risks and their historyEvery assessment you ever made, with its reason and the score it produced
The audit trailThe record of what changed, which is what makes a register defensible a year later
ControlsStatus, effectiveness, evidence notes, and the risks that take their residual score from them
ActionsOwners, priorities, due dates and everything already closed
Assets and vendorsCriticality, owners, review dates and the risks attached to each
FrameworksYour imported catalogues and every mapping you made between a control and a requirement
Indicators and eventsThresholds, the full reading history and every event you logged against a risk
SettingsMethodology, appetite thresholds and their rationales, and the rest of the register-wide choices

A backup and a CSV export do different jobs

A CSV export is a readable table of the register as it stands: the right thing to hand to a colleague or attach to the quarter's papers. A backup is the register itself, including the history, the links between risks and controls, and the settings that gave every score its meaning. Keep both habits if you like, but only one of them brings the register back.

What the notice is telling you

The reminder reports age, not health. It is saying that the newest backup on record is older than the interval you set, which means recent work has no copy behind it. Nothing has gone wrong, nothing is damaged, and no risk needs re-scoring. It is a gap in your cover, and it closes the moment you write a new file.

The reminder does not back up for you

Backing up is a decision, because you choose the destination each time — a folder in your documents, a drive you keep for the purpose, a location an auditor has agreed. RiskOS asks rather than assumes, and the reminder is the asking. The upside is that you always know where your register's copies are.

Backups are versioned

Backups are versioned, which matters far more later than it seems now. An older backup always restores, so a file from last year stays usable. A file written by a newer version of RiskOS than the one you are running is refused outright rather than half-read, because a register that came back partly filled would be worse than one that did not come back at all.

Restoring replaces, rather than merges

Restore from Backup… replaces the register in front of you with the contents of the file you chose. Nothing is combined and nothing is kept aside, and RiskOS spells out exactly what that means before asking you to confirm. Take a fresh backup first whenever the current register holds anything you would miss.

Troubleshooting

The reminder has never appeared

Two ordinary causes. The interval may be set to never, in which case no notice is ever due; open Settings and choose weekly, fortnightly or monthly instead. Or your last backup is not old enough yet — a monthly interval stays quiet for a month, which is the behaviour you asked for.

The reminder keeps coming back too often

Either the interval is shorter than your working rhythm, or the notice is being read and dismissed rather than acted on. Only a new backup resets the age it is measuring, so closing the notice changes nothing about the file on record. If the timing is genuinely wrong for you, move from weekly to fortnightly or monthly and see whether the quieter setting still catches enough.

I cannot find the backup I took

RiskOS saves each backup wherever you sent it, so a file written in a hurry to whatever location was offered at the time is the usual explanation. Settle on one destination such as Documents ▸ RiskOS, use it for every backup from now on, and keep the dated filename so the newest is always the last one in the list.

A backup file was refused when I tried to restore it

That file was written by a newer version of RiskOS than the one running on this Mac. Refusing it is deliberate: reading part of a newer file would leave you with a register that looked complete and was not. Restore it on the Mac running the newer version, or bring this Mac up to the same version first, and the file will open normally.

I restored a backup and lost this week's work

A restore replaces the whole register, which is why it explains itself and asks you to confirm before anything happens. The habit that prevents the loss is a backup of the current state immediately before every restore, taken as a matter of routine even when you are confident. That way the register you are about to replace is itself recoverable.

I am not sure which of my backups to use

Work backwards from the last moment you know the register was right. If a bad import is the problem, the backup from before it is the one you want, not the newest. This is the argument for keeping several dated files rather than one: the newest backup answers the question of a failed disk, and an older one answers the question of a mistake.

A backup routine that holds

  • Set the interval to the register, not to your conscience. The best interval is the one whose notices you will actually act on. Weekly reminders that get dismissed protect less than monthly ones that get answered.
  • Back up before anything large. Before importing a file of risks or controls, before changing whether controls reduce likelihood or impact, and before any restore. Each of those touches many rows at once.
  • Keep one destination and never move it. A single folder turns backups into a list you can read at a glance, in date order, with the newest at the end.
  • Keep the dated filename. The date in the name is doing quiet work every time you need to choose between files under pressure.
  • Keep a copy away from this Mac. A drive in a drawer or a disk you keep for the purpose covers the one failure a folder on the same machine cannot.
  • Back up at the end of a review pass. A completed pass through Review stamps review dates, schedules the next ones and often moves several scores, so it is the most valuable moment to capture.
  • Prune on a schedule. Keep the last few files plus one from each quarter, and let the rest go, so the folder stays readable rather than becoming an archive nobody can navigate.

Frequently asked questions

How often should I back up a risk register?

As often as you would mind redoing the work. A register edited most days suits a weekly reminder; one touched around board dates suits monthly. RiskOS offers never, weekly, fortnightly and monthly, and the interval measures the age of your last backup rather than counting your edits.

Where is the backup reminder setting?

It sits with the choices that apply to the whole register. Open Settings from the sidebar, or press ,, then pick never, weekly, fortnightly or monthly. Backing up itself is a separate command in the File menu, with its own keystroke, so a backup can be taken at any time regardless of the interval.

Does RiskOS back up automatically?

No. It reminds you, and you run the backup. That is because you choose where each file is saved, which keeps you in charge of where copies of your register exist. The reminder appears when the last backup passes the age you set, and it stops appearing once a new file is written.

What does a RiskOS backup file contain?

Everything: risks and their full assessment history, the audit trail, controls with their effectiveness and evidence notes, actions, assets, vendors, frameworks and your mappings, indicators with every reading, logged events, and your settings. One file, restored in one step, giving back the register exactly as it stood when the backup was taken.

Can I turn the backup reminder off?

Yes. Set the interval to never and no notice will appear again. That is the right choice if backing up is already part of a routine you keep, or if the register is finished work you only consult. Bear in mind the trade: nothing will tell you how old the last backup has become.

Will an old backup still restore?

Yes. Backups are versioned, and an older file always restores into a newer version of the app. The refusal runs the other way: a backup written by a newer version than the one you are running is declined rather than partly read, so you are never left with a register that looks complete but is missing pieces.

What is the difference between a backup and a CSV export?

An export is a readable table of the register as it stands, meant for sharing. A backup is the register itself, with history, links between risks and controls, and the settings behind every score. Only a backup brings the whole thing back, so keep exports for people and backups for recovery.

Does the reminder mean something is wrong with my register?

No. It reports age and nothing else: your newest backup is older than the interval you chose, so recent work has no copy behind it. No risk needs re-scoring and no data is damaged. Write a new backup and the notice goes quiet until the interval passes again.