How to set a risk review cadence on Mac
RiskOS keeps the cadence on the risk itself, so the next review date is set the moment the current one is confirmed, and the review queue fills from the dates already on the register.
The difference between a register and a list is that a register comes back to you. A risk written in March and never opened again is a record of what somebody believed in March, and by autumn nobody can say whether it still holds. A cadence is the small field that settles this: it decides how often each risk returns for a look, and it produces the date that brings it back.
A cadence schedules; it never scores. Confirming or re-scoring a risk stamps its review date and sets the next one from the cadence. Skipping a risk leaves it completely untouched, so it stays in the next pass.
Where the cadence lives
Choose Risks in the sidebar and click a row. The panel on the right opens on Summary, and that section holds the whole of a risk's filing: status, category, subcategory, owner, business unit, review cadence and next review date. The two review fields sit together because they answer two halves of the same question — how often, and when next.
The register table carries the result. Its Review column shows each risk's next review date, and sorting on it puts the oldest promise at the top. Review in the sidebar then works from the same dates, offering a scope of Overdue for review or Due within 30 days with live counts beside each one, so the schedule you set here is the schedule that fills the queue later.
Set a cadence on a risk
-
Open the risk you want to schedule
Choose Risks in the sidebar and click the row. The panel on the right opens on Summary. If the risk has not been written down yet, press ⌘N first; the new row pins to the top of the table, so you can rate it and schedule it in the same sitting.
-
Find the two review fields
In Summary, look past status, category and owner to review cadence and next review date. Cadence is the rule; the date is the appointment that rule produces. You set both once, and from then on the date maintains itself.
-
Choose how often the risk should come back
Pick monthly, quarterly or annually. Choose against how quickly the risk can change rather than how frightening it sounds: a Critical exposure that has been static for two years may need less attention than a Medium one sitting under an active migration. Most registers settle on quarterly for the bulk of their rows.
-
Set the first review date by hand
Set next review date yourself for this first cycle. Spread the dates deliberately rather than giving forty risks the same Monday: a handful each week is a habit, a hundred on one morning is a day nobody has. After this, each confirmed review schedules the following one.
-
Put a name against the date
Set owner in the same section. A cadence says when the risk comes back; the owner says who it comes back to. A date with no name attached is the commonest reason a review slips twice and then stops being expected at all.
-
Bring the Review column into view
Right-click the table header and make sure Review is shown; the same menu reorders columns, so you can move it next to Owner. Click the column heading to sort on it, oldest first. RiskOS remembers the arrangement, so the register opens on the schedule every time.
-
Schedule the rest of the register in one pass
Do not work down an inherited register a row at a time. Select several risks and the panel becomes a bulk editor: tick review cadence, choose the value, and apply it to everything selected. Fields you leave unticked stay exactly as they were.
-
Confirm a review to start the cycle
Choose Review in the sidebar, pick a scope, and work the risks it brings you one at a time. Press ⇧⌘↩ to confirm a rating that still holds, or change a rating and press ↩ to save and move on. Either way the review date is stamped and the next one is scheduled from the risk's cadence.
Choosing the right cadence
The temptation is always to over-schedule. A cadence that produces a queue nobody works is worse than a longer one that is honoured, because a permanently red overdue count stops carrying information.
| Cadence | Suits | What it asks of you |
|---|---|---|
| Monthly | Risks above appetite, risks under active treatment, anything whose controls are still being built. | A short pass every month. Keep this group small enough to finish in one sitting. |
| Quarterly | The working majority of a register: owned, rated, treated and moving at a normal pace. | Four substantial passes a year, each one a genuine re-reading rather than a tick. |
| Annually | Stable exposures, accepted risks, and long-standing rows that have not moved in years. | One considered look. Enough to catch a risk that has quietly changed shape. |
Let the band suggest the cadence, not decide it
Severity is a reasonable first cut. Critical and High risks earn monthly attention while they are being treated; Medium risks fit a quarter; a risk that has been Low for two years rarely repays more than an annual look. RiskOS leaves the choice to you, because two risks can share a score and change at completely different speeds.
Schedule against movement, not size
Ask what could make the rating wrong before the next review lands. A vendor risk on a contract that renews in eighteen months moves slowly; a cloud region risk during a migration moves weekly. Two fields already record this: onset velocity, how fast the risk would arrive once it starts, and detectability, how likely you are to notice. A risk that arrives fast and goes unseen deserves a tighter cadence than its score alone suggests.
Use appetite as the tie-breaker
Anything above your appetite threshold is, by definition, exposure you have said you do not want to carry. RSK-0007, Backup restoration has never been tested end to end, sits at a residual of 15 against an appetite of 9 — six points over, and a monthly cadence until the restore rehearsal is operating and the number comes down. Once a risk is back inside appetite, a quarterly cadence is usually right again.
How the next review date is set
Only a completed review moves the date. That is the rule worth internalising, because it is what stops the schedule from drifting quietly while the register looks maintained.
| What you do | Where | What happens to the review date |
|---|---|---|
| Confirm the rating (⇧⌘↩) | Review | The review date is stamped and the next one scheduled from the cadence. |
| Re-score and save (↩) | Review | The same. A re-score that changes nothing is recorded as a confirmation. |
| Skip (⌘→) | Review | Nothing at all. The risk is left completely untouched and stays in the next pass. |
| Mark Reviewed | The register table, with rows selected | The selected risks are reviewed in place, without opening each one. |
| Edit next review date | Summary | The date becomes whatever you set. Use this to move one appointment. |
| Change review cadence | Summary, or the bulk editor | Governs the scheduling from the next completed review onwards. |
Why skipping leaves no trace
Skipping is for the risk you cannot honestly assess this morning, because the owner is away or the evidence is not in yet. It writes nothing: no date, no assessment, no entry in the risk's history. The risk keeps its overdue standing and arrives again in the next pass. A review you did not really do should never look like one you did.
Why an unchanged rating still counts
A rating that has held steady for a year is a judgement somebody made and stood behind, not a row nobody opened. That is why a re-score changing nothing is recorded as a confirmation, with the date stamped and the next review scheduled. History then shows an unbroken run of assessments with the reasons behind them, which is what tells a reader a year later that the register was alive.
Cadences elsewhere in the register
Risks are not the only thing that goes stale. Three other parts of RiskOS carry dates of their own, and a register is only as current as the weakest of them.
| What | Where it is set | What a lapse looks like |
|---|---|---|
| Controls | Next review, in the control's detail | A control nobody has checked in two years is an assumption rather than a defence, and every risk deriving from it inherits that assumption. |
| Vendors | Next review date, on the vendor | The vendor list counts overdue reviews in its subtitle, so the number is visible before you open anything. |
| Indicators | The measurement cadence on the indicator | An indicator that misses its cadence is marked overdue, and a reading that never arrives is not the same as one in tolerance. |
Let indicators carry the weeks between reviews
A quarterly cadence leaves three months in which a rating could quietly become wrong. Indicators close that gap. Each one is a number you measure on its own cadence — Critical patches outstanding beyond SLA, Backup restore test success rate — with a warning and a breach threshold, linked to the risks it watches. When a threshold is breached, the risk's Intelligence section says so long before the review date arrives, and you can bring that review forward rather than waiting for it.
Working the schedule
Once cadences are set, the queue maintains itself and your job becomes working it. Review offers four scopes with live counts — Overdue for review, Due within 30 days, Above appetite and All active risks — and brings the risks worst first, one at a time, with a progress bar and the full context beside the scoring inputs. The session survives leaving for another section, and a summary at the end shows what moved, per risk.
Troubleshooting
The review date did not move after I looked at a risk
Reading a risk is not reviewing it. The date is stamped when you confirm with ⇧⌘↩ or save a re-score with ↩ in Review, or when you choose Mark Reviewed with rows selected in the table. If you pressed ⌘→, you skipped, and a skip is designed to leave the risk exactly as it was.
The same risks keep coming back too often
Their cadence is tighter than the work warrants. Open each one's Summary and move it from monthly to quarterly, or select the group in the table and change the cadence in the bulk editor in a single pass. A cadence you set in a nervous first week is worth revisiting once the register has settled.
I cannot tell what is due from the table
The Review column is probably hidden. Right-click the table header, show it, and use the same menu to move it somewhere you will read it. Click the heading to sort oldest first and the overdue rows collect at the top. For a fuller picture, Review shows the count for each scope before you start.
Half the register has no review date
That is normal in an inherited register, and it is a bulk job rather than a row-by-row one. Sort on Review so the empty entries gather together, select them, tick review cadence in the bulk editor and apply. Then set first dates on the handful that need spreading across the coming weeks.
The review queue looks empty when I know work is due
Check the scope. Overdue for review shows only what has already passed its date; Due within 30 days is the one to use when you are working ahead. Closed risks are not in the active scopes at all, which is intended — a closed risk keeps its record without asking for your time.
Habits that keep a schedule alive
- Set the cadence on the day you write the risk. It costs one click at creation and saves a sweep through the register six months later.
- Default to quarterly. Reserve monthly for what sits above appetite or is under active treatment, and annual for what has genuinely stopped moving.
- Pair every cadence with an owner. A date brings the risk back; a name decides who is standing in front of it when it arrives.
- Work the queue in one pass. Review brings risks worst first with the full context beside the scoring inputs, which is faster and more consistent than opening rows one by one.
- Skip rather than rubber-stamp. A skip keeps the risk in the queue and writes nothing, which is exactly what an unfinished review should do.
- Re-cadence after a big change. A new control, a materialised event or a breached indicator is a reason to look again sooner, not at the usual time.
Frequently asked questions
How often should a risk be reviewed?
Quarterly suits most risks in most registers. Move to monthly for anything above your appetite threshold or under active treatment, where the picture changes between passes. Annually is enough for stable, accepted exposures that have not moved in years. The better question is what could make the rating wrong before the next review lands, and how fast that could happen.
What review cadences can I set in RiskOS?
Monthly, quarterly or annually, chosen in the Summary section of the risk's panel alongside the next review date. The cadence decides how the following review is scheduled once the current one is confirmed, so it is set once per risk rather than renewed by hand each time.
How does the next review date get set automatically?
By completing a review. Confirming a rating or saving a re-score stamps the risk's review date and schedules the next one from its cadence. Nothing else moves the date on its own, which is what keeps the schedule truthful: a risk only leaves the overdue count when somebody has actually looked at it and said so.
What happens if I skip a risk during a review?
Nothing is written. A skipped risk is left completely untouched — no review date, no assessment, no change to its schedule — so it keeps its place in the queue and comes back in the next pass. Skip freely when the owner is away or the evidence has not arrived; an unfinished review should never look like a finished one.
Can I set the same review cadence for many risks at once?
Yes. Select the rows in the register and the panel becomes a bulk editor. Tick review cadence, choose the value, and apply it to every selected risk. The same pass can set category, owner, business unit, status and treatment strategy. Anything you leave unticked stays exactly as it was.
Where do I see which risks are overdue for review?
Two places. The Review column in the register table shows each risk's next review date, and sorting on it gathers the oldest at the top. Review in the sidebar shows a live count beside its Overdue for review scope and walks those risks one at a time, worst first.
Do controls, vendors and indicators have review dates too?
They do. Each control carries its own next review date in its detail view, each vendor has a review date and the vendor list counts overdue reviews in its subtitle, and every indicator is measured on a cadence and marked overdue when a reading is missed. A register is only as current as the least-reviewed thing in it.
Does reviewing a risk change its score?
Only if you change a rating. You can confirm that the current assessment still holds, in which case the score stays where it is and the confirmation is recorded in the risk's history with the date. If you do re-score, the projected rating updates live before anything is saved, so you can see where the risk will land first.