Indicators & Events

How to set up a key risk indicator on Mac

RiskOS turns a number you already collect into an early warning: a direction, two thresholds, and a status that shows up on every risk it watches.

Most registers move on a calendar. Someone reviews, someone re-scores, and between those two moments the numbers sit still while the world does not. A key risk indicator is the part of the register that refuses to wait for the meeting: one measurement, taken on a cadence, with two lines drawn across it so that movement announces itself.

Note

Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine.

Where indicators live

Choose Indicators under Signals in the sidebar. RiskOS sorts the list worst first, so the indicator in the most trouble is at the top of the screen rather than the one you happened to add most recently. The columns are Ref, Indicator with its direction shown beside the name, Latest, Status, Trend, Thresholds, Risks and Next Due. Read across a row and you have the whole story.

Selecting a row opens it in the panel on the right, where the indicator is set up and where readings are recorded. The list is searchable, and N here creates an indicator rather than a risk, because it always makes the right kind of item for the section you are standing in.

Set up an indicator, step by step

  1. Open the Indicators list

    Choose Indicators under Signals in the sidebar. If this is your first one the table is empty and the panel on the right is waiting. If it is not, read the top few rows first: the worst-first order shows whether you already measure something close to what you are about to create.

  2. Create the indicator

    Press N. A new indicator appears and opens in the panel on the right, ready to be named. There is no separate command to save it; changes are kept as you make them.

  3. Name the number, not the worry

    Give the indicator a title that says exactly what is being counted, with the unit in the name so nobody has to guess later: Critical patches outstanding beyond SLA, Backup restore test success rate, Days to detect a security event. A name like Patching will be read three different ways by three people, and a threshold set against it means nothing.

  4. Say which direction is bad

    Tell RiskOS whether a rising number is the problem or a falling one. For outstanding patches, higher is worse. For a restore success rate, lower is worse. This one choice is what lets the register decide a status for you, and it is shown beside the name in the list so anyone reading the table knows which way to read the figure.

  5. Set the warning and the breach threshold

    Warning is the value at which you want to look. Breach is the value at which you want to act. Set both in the units you named the indicator with, and keep them far enough apart that the warning buys you time. Both are inclusive and both are read in the direction you chose, so a warning of 3 on a higher-is-worse indicator turns at 3, not at 4.

  6. Add a target if you have one

    The target is optional, and it is not a third threshold. It states where you intend the number to settle once the treatment work has landed, so the reading history shows whether you are moving towards the figure you promised or merely staying out of breach. Leave it empty if you have no honest answer yet.

  7. Choose how often you will read it

    Set the cadence on which you intend to take a reading. It fills the Next Due column, and it is the only thing standing between a live indicator and a number somebody stopped updating in March. Choose an interval you will genuinely meet rather than the one that sounds diligent.

  8. An indicator attached to nothing is a number on a page. From the indicator's own panel, link it to every risk it is genuinely evidence about. One indicator can watch several risks and a risk can carry several indicators; the Risks column counts how many rely on this one. Each linked risk then shows the indicator with its live status under Intelligence in its own panel, where the measurement sits beside the rating it tests.

  9. Record the first reading

    A reading is a value, a date and a note. Record one straight away, because until you do the indicator reads as no data, which is not the same as being in tolerance. Once readings exist, the history chart draws your warning and breach lines across them, so the status in the table has a picture behind it.

Choosing a number worth measuring

The hard part is never the setting up. It is choosing something that moves before the risk does, and that someone will still be able to produce in eighteen months' time.

Measure the cause, not the consequence

Counting incidents tells you what has already gone wrong. As a warning it arrives too late to be useful. The measurements that earn their place sit upstream of the event: patches outstanding rather than breaches suffered, restore rehearsals passed rather than data lost, assurance reviews overdue rather than suppliers failed.

Prefer a number somebody already produces

An indicator that requires a new piece of work every month will be abandoned by the third month. Look first at figures that already exist somewhere in the organisation and are not written down beside the risk they concern. A measurement you can take in two minutes beats a better one you will stop taking.

Four worked examples

Here is how a small set looks once direction and thresholds are in place. The latest readings are the ones carried through these guides; the warning and breach values are an example of where a team might draw its own two lines, and yours will differ.

Four example indicators with their direction, thresholds, latest reading and resulting status
IndicatorDirectionWarningBreachLatestStatus
Critical patches outstanding beyond SLAHigher is worse51014Breached
Backup restore test success rateLower is worse95 %80 %72 %Breached
Vendor assurance reviews overdueHigher is worse363Warning
Days to detect a security eventHigher is worse373Warning

The last two rows are the ones to pause on. Both sit exactly on their warning value and both read as a warning, because thresholds are inclusive. Reaching the number counts as reaching the number.

Direction, thresholds and what the status means

Once a direction and two thresholds are in place you never work out a status yourself. Record a value and RiskOS places it immediately, in the list and on every risk the indicator is linked to.

The states an indicator can be in and what each one asks of you
StateWhat it meansWhat it asks for
In toleranceThe latest reading sits on the safe side of the warning threshold.Nothing beyond keeping to the cadence.
WarningThe latest reading has reached the warning value, read in the direction you set.Look at it now, while there is room between here and breach.
BreachedThe latest reading has reached the breach value.An action, an owner and a date on the risk it watches.
No dataThe indicator exists but nothing has ever been recorded against it.A first reading. It is not a pass.
OverdueThe cadence came and went without a reading.A reading, or an honest change of cadence.
PausedYou have stopped the indicator from the list. Its history is intact.Nothing until you resume it.

Why the thresholds are inclusive

A threshold that triggers only once a value has passed it leaves a silent gap exactly where you were paying most attention. Landing on the number is the interesting case, so landing on it is what counts. Set the warning at the first value you would want to be told about rather than the last one you are comfortable with.

No data is not good news

An indicator with no readings is kept visibly distinct from one sitting comfortably inside its thresholds, and that distinction is deliberate. A register full of green that turns out to be a register full of nothing is worse than no indicators at all: it has been quietly telling everybody somebody is watching. The Latest column is empty for these, so a glance down the list finds them.

Cadence, Next Due and pausing

An indicator is a promise to keep taking a measurement. The cadence is where that promise is written down, and Next Due is where it is held to.

What overdue really tells you

When the cadence passes without a reading, the indicator is marked overdue. That marking is about you rather than about the risk: the number has not got worse, you have stopped knowing. Several overdue rows mean the cadences are too ambitious. Stretch them until they are honest, because an indicator that is always current beats a frequent one that is three months stale.

Pausing instead of removing

Sometimes a measurement stops making sense for a while: the system it counts is being replaced, or the team that produces the figure is mid-transition. Pause the indicator from the list. It stops asking for readings, and every reading already taken stays where it is. Resume it from the same place and the history continues, the gap itself part of the record.

Reading the trend column

Trend is the column people underuse. A breached indicator improving over four readings and a breached one worsening over four are the same colour and entirely different problems. Let status decide what gets escalated, and trend decide what gets worked on first.

What an indicator changes on a risk

Open a risk you have linked and look at Intelligence in the panel. The indicators watching it are listed there with their live status, so whoever opens the record sees the measurement beside the rating.

What an indicator does not do is move the score on its own. The rating stays where you set it until a person changes it: a number crossing a line is evidence, not a decision. Where the evidence is persuasive, take the risk through Review and re-score it there, so the change is stamped with a date and a reason.

Indicators carry through to what you send out. The report builder has a risk indicators section you can switch on, so a board pack shows the breached measurements beside the risks they belong to, from the same snapshot as every other figure in the document.

Troubleshooting

My indicator says no data even though I set the thresholds

Thresholds describe where the lines are; they are not a measurement. An indicator reads as no data until a reading exists, and that state is kept apart from being in tolerance on purpose. Record a value with its date and the status resolves.

The status looks backwards

Check the direction. A restore success rate where falling is the problem reads as improving as it drops if the direction is set the other way, and every status that follows is wrong in the same tidy, consistent manner. The direction sits beside the name in the list, so you can confirm it without opening the record.

It is marked overdue, but I did take a reading

Look at the date on the reading rather than the day you entered it. A reading typed in today but dated to the start of last month counts as a reading from the start of last month, which may still leave the cadence unmet. Correct the date and Next Due moves with it.

A breached indicator is not showing on the risk

It is almost certainly not linked. The Risks column counts the links, and a zero there means the indicator is being measured in isolation. Open the indicator, link it to the risk from its panel, and the live status appears under Intelligence on that risk.

The same number is being measured twice

Two indicators with different names measuring the same thing drift apart, and then a meeting is spent deciding which is right. Search the list before creating anything, keep the one with the clearer name and longer history, and pause the other so its readings remain.

A routine that keeps indicators honest

A handful of indicators read reliably is worth far more than a page of them read once. These habits carry most of the weight.

  • Start with three. Pick the three risks you would be asked about first and give each one indicator. Add more once those three have a run of readings behind them.
  • Put the unit in the name. A figure of 14 means nothing alone. Critical patches outstanding beyond SLA reads correctly to somebody who has never opened the register.
  • Set the warning where you would want a nudge. Thresholds are inclusive, so choose the first value that deserves a look rather than the last one you can live with.
  • Read the list worst first. It is already sorted that way. Take the top few rows, decide what each asks for, and stop.
  • Check Next Due before the status. An overdue indicator is a gap in what you know, and a gap is harder to explain to a board than a breach you are managing.
  • Let a breach become an action, not a reflex re-score. Add it on the risk with an owner and a date, then re-score deliberately in Review once the evidence has settled.
  • Back the register up on a cadence too. Readings accumulate quietly and are the hardest part to reconstruct. File ▸ Back Up RiskOS writes indicators, readings and everything else to one file.

Frequently asked questions

What is a key risk indicator?

A key risk indicator is a number you measure on a cadence because its movement tells you a risk is changing before the risk itself does. In RiskOS an indicator carries a direction, a warning threshold, a breach threshold, an optional target and a history of readings, and links to the risks it is evidence about.

How do I add a KRI on a Mac?

Choose Indicators under Signals in the sidebar and press ⌘N. Name the number with its unit, say which direction is bad, set the warning and breach thresholds, choose the cadence you will read it on, link the risks it watches, then record a first reading with a value, a date and a note.

What is the difference between a warning and a breach threshold?

The warning value is where you want to look at something; the breach value is where you want to act. Both are inclusive, so a reading landing exactly on a threshold counts as having reached it, and both are read in whichever direction you told RiskOS was bad. Keep them far enough apart that the warning buys time.

Why does my indicator show no data instead of in tolerance?

Because nothing has been recorded against it yet, and those two states are deliberately kept apart. Setting thresholds describes where the lines sit; it does not measure anything. An unmeasured indicator displaying as healthy would quietly tell everyone that somebody was watching. Record one reading and the status resolves.

Does a breached indicator change the risk score automatically?

No. A breach is evidence, not a decision, so the rating stays where a person put it. The indicator appears with its live status in the Intelligence section of every risk it is linked to. When the evidence is persuasive, re-score the risk in Review, where the change is stamped with a date and a reason and kept in the risk's history.

How often should I record a KRI reading?

On whatever cadence you can genuinely keep. The cadence fills the Next Due column, and missing it marks the indicator overdue. A measurement that is always current is worth more than a frequent one that stopped in the spring, so stretch the interval until it is honest rather than letting the list fill with overdue rows.

Can one indicator watch more than one risk?

Yes. Link an indicator to as many risks as it is genuinely evidence about, and give a risk as many indicators as it needs. The Risks column counts the links, so an indicator sitting at zero is being measured in isolation and will never appear where anyone is looking.

How do I stop an indicator without losing its readings?

Pause it from the Indicators list. It stops asking for readings, while every reading you have taken stays in place. Resume it from the same list when the measurement makes sense again, and the history continues with a visible gap that is itself part of the record.