How to tell if a risk is underrated on Mac
You can do this with RiskOS, a risk register for macOS. Your incident history, read back against the rating that was meant to predict it.
A likelihood rating is a prediction, and predictions can be checked against what happened next. The check is rarely made. A risk rated Unlikely in the spring is still Unlikely in the autumn, after occurring twice, because the rating and the incident history were never read together. RiskOS reads them together on the risk itself, and names the rating the record would support.
The warning is evidence-led. RiskOS looks for at least two events linked to the risk across a full year before it says a likelihood is sitting low, so one bad fortnight never moves a rating on its own.
Where the evidence lives
Two sections hold the evidence. Signals ▸ Events is what has actually happened: Ref, Event with its linked risks, Occurred, Severity, Status, Detection delay and Cost. Signals ▸ Indicators is what you measure on a cadence, worst first, each with its latest reading and its status against your thresholds.
The risk brings the two together. Open Risks, select a row, and find Intelligence in the panel on the right, between Context and History. It lists the indicators watching this risk with their live status, the events linked to it, and, where the history disagrees with the rating, a warning carrying a suggested likelihood. The rest of this page is knowing when to act on it.
Check a rating against what actually happened
-
Record every event, not only the serious ones
Choose Events in the sidebar and press ⌘N. Name what happened, then set the dates it occurred and was detected, the severity as you experienced it, its status, the cost, and the lessons while they are fresh. Small events make the pattern visible; a log of disasters alone has nothing to count.
-
Link each event to the risk it came from
In the event's detail, link it to the risk it is an instance of. Everything else depends on that one action: an unlinked event is a story in a list, a linked one is evidence attached to a rating. The Event column shows each entry's linked risks, so a scan down the table finds what is still floating.
-
Open Intelligence on the risk
Return to Risks, select the risk and read Intelligence in the panel on the right. It gathers three things in one view: the indicators watching this risk with their live status, the events linked to it, and any warning that the likelihood is sitting below what the record supports.
-
Read the suggested likelihood
When a risk materialises more often than its rating implies, RiskOS says so, and the warning carries a suggested rating: the likelihood the observed frequency would justify, on the same 1 to 5 scale you rate against. Nothing is changed for you. The decision stays yours, made with the record in view.
-
Check the indicators watching the same risk
Read the status of every indicator linked to the risk. A breach is a measurement crossing a line you set in advance, which carries more weight than an opinion formed in a meeting. A backup risk sitting at a comfortable rating while Backup restore test success rate reads 72 % and breached has stopped describing the organisation.
-
Compare the severity you rated with the severity you recorded
Read down the Severity and Cost columns in the events table, then set them against the impact rating on the risk. The warning in RiskOS speaks to frequency, so the impact half of the score is a judgement you make by eye. Events landing above the impact you rated say the score is low for the other reason.
-
Re-score with the evidence in view
Move the inherent likelihood stepper in Assessment; the score, the band and the matrix marker answer immediately, and changes save as you type. For several risks at once, Review brings them one at a time with owner, actions, controls and last review beside the scoring inputs. Press ⇧⌘↩ to confirm a rating that stands, or ↩ to save a change and move on.
-
Read the history afterwards
Open History on the risk. It draws the residual score over time and lists every assessment with its reason, so the change reads as a decision rather than a number that moved. A raised likelihood also raises the residual, and a risk that has crossed your appetite threshold is now flagged everywhere it appears.
What the suggested rating is telling you
The suggestion answers one narrow question: if you knew nothing about this risk except how often it has occurred, what likelihood would you give it? It is useful because it ignores the plan, the intention and the reassurance of the last review. It is an input to a judgement, not the judgement.
| Rating | Value | What a year of linked events tends to look like |
|---|---|---|
| Rare | 1 | Nothing recorded, here or in the years you can remember. |
| Unlikely | 2 | One event at most, and several things had to go wrong at once. |
| Possible | 3 | One event in the year, or a steady trickle of small ones. |
| Likely | 4 | Two or more in the year, or one event and an indicator in breach. |
| Almost Certain | 5 | It recurs. The open question is severity, not whether. |
Why two events, and why a year
One event is an anecdote: the cause you have already fixed, or the supplier you have replaced. Two across a full year is the smallest history that separates a pattern from a coincidence, and the span matters as much as the count. Three events in a fortnight are usually one event with three symptoms; three across twelve months are a rate.
A suggestion is not an instruction
Nothing re-rates itself. The rating is always the one a person chose, which is what makes it defensible six months later. Take the suggestion, argue with it, record the outcome either way. A rating confirmed against contrary evidence, with its reason written down, is stronger than one nobody tested.
The other signs that a rating is sitting low
Events are the loudest evidence, not the only kind. Several things argue quietly with a rating, and each is visible without opening a report.
| Signal | Where you see it | How to read it |
|---|---|---|
| An indicator in breach | Intelligence on the risk | A number you chose to measure has crossed the line you set, and the rating has not caught up. |
| An indicator reading no data | Latest column, Indicators | Nothing has been recorded, which is not the same as being in tolerance. |
| An overdue indicator | Next Due column, Indicators | The cadence has lapsed, so you are rating on evidence that stopped. |
| A rising trend | Trend column, the register | Successive assessments have moved the residual score the wrong way. |
| A long detection delay | Detection delay column, Events | The gap before you noticed argues the detectability you recorded is optimistic. |
| A control still Planned | Controls section on the risk | A planned control reduces nothing yet, however strong it will be. |
Where a breached indicator meets a low rating
Take RSK-0007, Backup restoration has never been tested end to end: inherent 20, residual 15, target 4, six points over an appetite of 9. Its indicator, Backup restore test success rate, reads 72 % and breached, and the control standing in the way, CTL-0003 Quarterly restore rehearsal, is still Planned. Three parts of the register are saying the same thing, and the rating is rarely the part that is right.
Impact can be underrated as well
Frequency is the easier half to check, because counting is easy. Consequence is where registers drift, and it drifts one way: the first estimate of an impact is made before anybody has lived through one.
Your events carry the correction. Each holds the severity as you experienced it and, where you recorded one, a cost. Read a handful against the impact on the parent risk. A risk rated Moderate that has produced two events you logged as Major describes an expectation reality has overtaken. Raise the impact, or say why those events were unrepresentative.
When the rating is right and the evidence misleads
A warning is a prompt to look, not a verdict. Three situations regularly produce a frequency that overstates today's exposure.
The events were all the same incident
A single outage logged three times, by the service desk, by the platform team and again in the review afterwards, counts as three occurrences and reads as a pattern. Keep one event per occurrence and put the rest in its description.
The cause has since been treated
Two events last year, with a control that has moved to Operating since the second, is a different situation from two events and nothing changed. The history still argues for a higher inherent likelihood, since inherent describes the exposure with nothing in the way, but the residual you manage against should already have answered. Check the control is linked and its status current.
The events happened while controls were working
This is the uncomfortable one. Events that occurred despite an operating control argue two things at once: the inherent likelihood is understated, and the effectiveness recorded for that control is generous. A control that has let the same thing through twice is not High effectiveness, and RiskOS re-scores every risk deriving from it the moment you change the value.
Troubleshooting
I have logged events but nothing is flagged
Check the links first: only events linked to the risk count towards its history, and one filed against the wrong risk is invisible to the right one. Then check the count and the span, since the warning needs two events across a full year. A risk already at Almost Certain has nowhere higher to go.
The suggested rating looks too high
It may well be, and you decide. The suggestion reads frequency alone and knows nothing of what you have fixed since. Look for duplicate events covering one incident, and for a control that moved to Operating after the last of them. If the rating stands, confirm it in Review with the reason.
I raised the likelihood and the warning is still there
The comparison reads the linked events against the rating as it stands, so moving from Unlikely to Possible while the record supports Likely leaves the evidence pointing higher. Take the rating to the suggested level, or look again at whether all those events belong here.
An indicator says breached but the risk still looks calm
An indicator does not move a score. It is an early warning sitting beside the rating, waiting for a person. Read its status in Intelligence and decide whether the breach changes the likelihood, the control effectiveness or neither. Check the direction as well: thresholds are direction-aware, so a rising number is only bad where you said so.
A routine that keeps ratings honest
- Log the event the week it happens. A month later the detection delay is a guess and the lessons have become folklore.
- Link before you leave the event. An unlinked event teaches the register nothing, and linking is rarely done later.
- Read the evidence before you re-rate. Open Intelligence on the risk, then take the decision into Review, which brings risks one at a time with owner, actions, controls and last review beside the scoring inputs.
- Give your loudest risks an indicator. A number measured on a cadence challenges a rating continuously, not once a quarter when someone remembers to ask.
- Re-read the whole register once a year. Scope Review to all active risks. Ratings drift downwards quietly, and an annual pass catches the drift.
- Write the reason every time. History keeps every assessment with its reason, and that is what makes a rating readable to whoever inherits it.
Frequently asked questions
How do I know if a risk is underrated?
Compare the rating with the record. Open the risk in RiskOS and read the Intelligence section: it gathers the events linked to that risk, the indicators watching it with their live status, and a warning where the risk has materialised more often than its likelihood implies, carrying the rating the observed frequency would justify.
How many events does RiskOS need before it suggests a higher likelihood?
At least two events linked to the risk, across a full year. That threshold stops a single incident, or a cluster from one bad fortnight, moving a rating on its own. Below it the events are still listed on the risk to read, but no warning is raised and no likelihood suggested.
Does RiskOS change a risk rating automatically?
No. Inherent likelihood and impact are always set by a person. RiskOS suggests, flags and explains, then waits. That is deliberate: a rating somebody chose can be defended in a meeting, and every change or confirmation is kept in the risk's History with its reason.
Can a key risk indicator show that a risk is underrated?
Yes, and usually sooner than an event does. An indicator is a number you measure on a cadence, with a warning threshold and a breach threshold. When a linked indicator sits in breach while the risk reads comfortably, the measurement and the rating disagree. Its status appears on the risk itself, in Intelligence.
Should I log a near miss as a risk event?
Log it where the risk actually occurred, even if the consequence turned out small. Severity is recorded as you experienced it, so a low-severity entry is an honest record rather than an inflated one. Be consistent, because the count of linked events is what the likelihood comparison reads.
What does detection delay tell me about a risk?
It is the gap between the date an event occurred and the date you detected it, shown as a column in the Events table. A long delay argues the detectability recorded on the risk is optimistic. Detectability does not change the score, but it changes what you do: a risk noticed late deserves earlier attention.
Does the event and indicator data I record leave my Mac?
No. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine. Events, readings, ratings and the history behind them stay where you put them, and go elsewhere only when you export or back up a file yourself.