Start Here

How to set up your risk methodology on Mac

Decide it once in RiskOS, the risk register for macOS, and every score made afterwards is made the same way as every score made before.

A methodology is the agreement underneath every number in a register. It decides what a likelihood of 4 means, where High stops and Critical begins, and what a control is allowed to move. Settle it early and the register stays comparable with itself for years. Settle it late and you spend an afternoon working out which rule each of a hundred rows was rated under.

Note

Methodology is a register-wide decision. Change how controls reduce risk and RiskOS re-scores every risk immediately, so nothing is left rated under the previous rule.

Where methodology lives

Press , from anywhere in the app, or choose Settings in the sidebar under Output. Settings holds three areas. Methodology is the scoring scales, the band thresholds and the choice of what your controls reduce. Appetite is the highest residual score your organisation tolerates. Privacy sets out the promises the app makes, written down so you can read them rather than take them on trust.

Methodology comes first, because the other two are measured against it. An appetite of 9 means nothing until everyone agrees what a 9 is.

Set up your methodology, step by step

  1. Open Settings and choose Methodology

    Press ,, or choose Settings in the sidebar, then open Methodology. Everything on this page applies to the whole register at once, so do it with the people who will be rating risks.

  2. Read both scales end to end

    Methodology sets out the five likelihood ratings — Rare, Unlikely, Possible, Likely, Almost Certain — and the five impact ratings — Insignificant, Minor, Moderate, Major, Severe. The same labels sit beside every stepper in a risk's Assessment section, so what you agree here is what a rater sees.

  3. Fix the window every likelihood is rated against

    Decide the period you are rating over and hold everyone to it. A year is the usual choice. Mixing a once-in-a-decade judgement with a this-quarter judgement in one column makes the sort order meaningless, and it is the commonest reason two people rate one exposure differently.

  4. Anchor each impact rating to something you can point at

    Agree a rough anchor for each of the five impact points: a cost, a number of customers, a duration of disruption, a regulatory outcome. Write those anchors into the risk descriptions as you go, so the next person can see what Major meant to you.

  5. Check where the bands cut

    Confirm that everyone knows the four bands and the scores behind them: Low is 1–4, Medium 5–9, High 10–16 and Critical 17–25. The band is what a badge, a matrix cell and a report respond to, so a rater who thinks 10 is still Medium produces rows that read wrongly.

  6. Choose whether controls reduce likelihood, impact or both

    This is the one setting on the page that changes numbers. It tells the register which way a control pushes a risk: down the likelihood axis, down the impact axis, or across both. Choose the one that matches how your controls work, and expect every residual score to be recalculated the moment you do.

  7. Set the appetite your scores will be measured against

    Open Appetite and set the highest residual score the organisation will tolerate, on the same 1 to 25 scale. Anything above it is flagged wherever it appears. Give a category its own threshold, with a written rationale, where it warrants less tolerance than the rest of the register.

  8. Test the methodology on a real risk

    Choose Risks, select a row and open Assessment. Move an inherent rating and watch the score, the band and the matrix markers answer. Link a control and watch the residual marker travel along the axis your methodology chose. If the movement surprises you, the setting is wrong, not the risk.

  9. Refresh your profiles, then back up

    Each profile keeps its own snapshot of the methodology and the appetite, so open Profiles and use Update from Current Settings on any profile that should follow the new rule. Then choose File ▸ Back Up RiskOS or press B; the backup carries your settings with everything else.

The two scales, and what each point has to mean

Five points per axis is a deliberate coarseness: a five-point scale forces a judgement, where a hundred-point scale invites false precision. The score is likelihood multiplied by impact, so the pair runs from 1 to 25.

The five values and the likelihood and impact ratings they carry
ValueLikelihoodImpact
1RareInsignificant
2UnlikelyMinor
3PossibleModerate
4LikelyMajor
5Almost CertainSevere

Fixing the likelihood window

Say out loud that every rating answers one question — how likely is this in any given year — and the five points fall into place. Rare would surprise you. Possible has happened to organisations like yours. Almost Certain is something you expect, and are arguing only about timing. When a rater is stuck between two values, take the higher one and write the reason into the description.

Anchoring the impact scale

Impact needs anchors because it is rated against the organisation, not against the team that feels it first. A week of one department's disruption is rarely Severe. Reserve Severe for outcomes that threaten obligations, a licence to operate or survival, and keep Moderate for what costs real money and takes days to recover from.

Where the bands cut

Bands are the register's shorthand. They set the colour of a badge, the shade of a matrix cell and the tone of an executive summary, and they are never carried by colour alone: every band pairs a colour with a symbol and the written word.

The four bands, the scores they cover, and how each reads in the register
BandScoreHow it reads in the register
Low1–4Recorded and watched at the cadence you set. It rarely shapes a plan.
Medium5–9Treat it where treating it is cheap. Most registers cluster here.
High10–16A named owner, a plan and a date. The rows a review exists to work through.
Critical17–25Escalated on sight. Only the top corner of the grid reaches it.

Read those cuts against your own register. Twelve active risks with an average residual of 9.6 out of 25 sit where Medium gives way to High, with the worst rows — an untested backup restoration at 15, ransomware against primary file shares at 15 — well inside High. A register where two thirds of the rows are Critical has stopped separating anything, and the cause is usually the impact anchors.

The one choice that changes every score

You rate inherent likelihood and impact — the exposure with nothing standing in its way. RiskOS works out the residual from the effectiveness of the controls you link, and the methodology decides which axis that reduction acts on. On the matrix, it is the direction the residual marker travels away from the inherent one.

The three reduction settings and what each one moves
SettingWhat moves on the matrixWhere it fits
LikelihoodThe residual marker travels along the likelihood axis. Impact stays where you rated it.Registers whose controls exist mainly to stop the event happening at all.
ImpactThe residual marker travels down the impact axis. Likelihood stays where you rated it.Continuity and recovery work, where the event is hard to prevent but the damage can be contained.
BothThe reduction is shared across the two axes, so the marker moves diagonally.Mixed registers, where preventive and recovery controls sit side by side.

Changing the setting re-scores the whole register at once, which is the behaviour you want; old rows under one rule and new rows under another is how a register stops being comparable. Make the change deliberately, then look at the risks that moved furthest and satisfy yourself the movement makes sense.

The guarantees that hold whichever mode you choose

Whatever the methodology says, the arithmetic underneath keeps four promises. They are what make a residual score defensible.

  • A residual score never exceeds its inherent score. Controls reduce exposure; they do not create it.
  • A residual score never falls below 1. No risk is scored away to nothing.
  • A stronger control never raises a score.
  • Only controls that are implemented or operating reduce anything. A planned control, however strong it will be one day, reduces nothing yet, and the register says so rather than flattering the row.

How the methodology reaches the rest of the register

The settings page is quiet, but almost nothing in the app is untouched by it. Half an hour at the start saves a rescue operation later.

Where the methodology shows up across the app
WhereWhat the methodology decides
The risk tableThe Inherent, Residual and Target columns, and the band on every badge.
The matrixWhich cell each of the three markers sits in, and how far apart they are.
Appetite flagsThe residual score compared with your threshold, everywhere it is exceeded.
The Risk LibraryThe suggested starting rating on each worked example, read against the scales you agreed.
Review modeThe projected rating shown live, before anything is written.
ReportsThe matrix section, the ranking behind top risks, and the scores in all four formats.
Excel exportThe formulas that re-score themselves when you change a likelihood in the workbook.
CSV importScores are never read from a file. RiskOS recalculates them under your methodology.

Methodology across client profiles

Carry risk for more than one organisation and the methodology is not one decision but several. A profile dresses the whole app for one client: its own methodology, appetite, report defaults, client name and logo. P cycles between them, and every export goes out in that client's terms.

A profile's methodology and appetite are snapshots rather than live links, so changing Settings does not reach back into a profile saved under an older rule. When a profile should follow the current methodology, open it and use Update from Current Settings. One client's decision should not re-score another client's register overnight.

Troubleshooting

Every score in the register changed and I did not touch a risk

Somebody changed what controls reduce. That setting re-scores the whole register the moment it moves, so no row is left under the old rule. Set it back if it was not intended and the register recalculates again. Each risk's History keeps every assessment with the score it produced, so you can see what moved.

Everything is coming out High or Critical

Impact inflation, nine times out of ten. If most rows sit at Major or Severe, the scale has stopped separating anything. Re-read your impact anchors, re-rate a handful of the smallest risks first, and let the rest settle around them. Check too that people are rating the inherent exposure in those steppers, not what is left after the controls.

One client's numbers did not move when I changed the methodology

Profiles hold their own snapshot of the methodology and the appetite. Open the profile and choose Update from Current Settings to bring it in line. If that client should stay on the older rule, leave it alone. The separation is the point of profiles.

A strong control is not moving the residual score

Check the control's status first. Only implemented or operating controls reduce risk, so a planned control changes nothing however high its effectiveness. Then check the risk's Controls section: if the derive-from-controls toggle is off, the risk is using a value set by hand, and the panel warns you when that value disagrees with the controls linked.

The scores in the file I imported are not the scores I see

Scores are never read from a file. The import takes the ratings and recalculates the numbers under your current methodology, which is what keeps an imported row comparable with a row typed in by hand. The preview shows the projected score line by line before anything is written, along with anything out of scale that had to be clamped.

I cannot tell two bands apart by colour

You do not have to. Every band badge pairs its colour with a symbol and the written word, in the table, on the matrix and in exports. Reduce Motion removes the marker animations while keeping the highlights, and VoiceOver reads a whole row as a single sentence.

Habits that keep a methodology honest

A methodology is not a document you write once and file. A few habits keep it true as the register grows.

  • Decide it before the tenth risk. Ten rows can be re-rated in an afternoon; two hundred cannot, and the temptation then is to leave the old ones alone.
  • Write the anchors into the risks. A rating with a reason in the description survives a change of staff. A rating on its own is an opinion with a number attached.
  • Calibrate against worked examples. The Risk Library carries thirty-nine examples across seven categories, each with a suggested starting rating. Entries arrive as drafts: a suggestion is a prompt, not an authority.
  • Re-score in one pass. Review walks the risks that are due, worst first, with full context beside the scoring inputs.
  • Let reality argue with the scale. When a risk materialises more often than its rating implies, the register says so and suggests what the observed frequency would justify.
  • Keep appetite in step. A threshold is a point on the scale you agreed. Change what the scale means and the threshold changes meaning with it.
  • Back up after a methodology change. B writes everything to one file, settings included, and the default filename carries the date, like Risk Register 2026-09-21.

Frequently asked questions

What is a risk methodology?

It is the agreed rule for how risks are rated and compared: the five likelihood ratings, the five impact ratings, the score that comes from multiplying them, the thresholds where bands change, and what a control is allowed to reduce. In RiskOS it lives in Settings ▸ Methodology and applies to the whole register at once.

How do I change the risk scoring scale on a Mac?

Press , and open Settings ▸ Methodology. The scales and the band thresholds are set out there so that everyone rates against the same definitions, together with the one setting that does change numbers: whether your controls reduce likelihood, impact or both. Change that and the register re-scores at once.

Should controls reduce likelihood or impact?

Match it to how your controls work. Choose likelihood if most of them exist to stop the event happening. Choose impact if they mainly contain the damage once it starts, as continuity and recovery controls do. Choose both for a mixed register, where the reduction is shared across the two axes and neither kind of control is ignored.

Will changing the methodology re-score risks I have already rated?

Yes, immediately and across the whole register. Leaving older rows under the previous rule would make the register incomparable with itself. Your inherent ratings are untouched — only the residual arithmetic changes — and each risk's History keeps every assessment with the score it produced, so the movement stays visible afterwards.

Where are the risk bands defined?

In Settings ▸ Methodology, alongside the scales. The four bands are Low for 1–4, Medium for 5–9, High for 10–16 and Critical for 17–25. Every badge shows its band as a colour, a symbol and a word together, so the band never depends on colour alone to be read.

Can two clients use different methodologies in the same app?

Yes. Each profile keeps its own methodology, appetite, report defaults, client name and logo, and P cycles between them. Those are snapshots rather than live links, so a profile follows the current settings only when you choose Update from Current Settings on it.

Why can a residual score never be higher than the inherent score?

Because controls reduce exposure rather than create it. Residual is calculated from the effectiveness of the controls you link, and the arithmetic holds three lines: it never rises above inherent, it never falls below 1, and a stronger control never makes a score worse. A control that is only planned reduces nothing yet.

Does my methodology or my register leave my Mac?

No. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine except in the exports and backups you make yourself. The only network use is Apple's App Store, for purchases, and it never sees your register.