How to track risk treatment actions on Mac
You can do this with RiskOS, a risk register for macOS. One list of everything that was promised, ordered by what is already late.
A treatment plan earns nothing until somebody does the work inside it. Actions are the part of a register that actually moves: the restore rehearsal to be booked, the contract clause to be renegotiated, the access review promised in March that has not happened since.
The difficulty is never writing them down. It is finding them again. Actions scattered across dozens of risk records are actions nobody reads, so RiskOS gathers every one into a single list ordered by lateness rather than by the risk it came from.
Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine.
Where actions live
Choose Actions in the sidebar, in the Register group beneath Risks and Controls. What opens is every action on every risk and every control, as one list split into groups by due state: Just Added, Overdue, Due Soon, Later, No Due Date and Closed.
Each row carries the name of the risk or control it belongs to, so a line reading Book the quarterly restore rehearsal is never orphaned from RSK-0007. Rows edit in place: title, status, priority, owner and due date all change without opening anything, so a stand-up can be worked straight down the list.
The same actions appear where they were written. A risk's panel lists its own in an Actions section, and a control's panel holds its remediation actions the same way. Nothing is duplicated: Actions is the gathered view of one set, so ticking a row in one place ticks it everywhere.
Work the action list, step by step
-
Open the actions list
Choose Actions in the sidebar. The groups stack worst-first, so Overdue sits near the top and Later below it. Read Overdue before anything else: it is the only part of a register that is measurably failing rather than merely unpleasant.
-
Create the action on the thing it belongs to
Open the risk in Risks, expand its Actions section and add the action there, so it arrives attached to that risk and carries the risk's name wherever it later appears. Remediation work on a control is added the same way from the control's own panel. Inside the Actions section itself, ⌘N creates a new action, pinned to Just Added so you can finish filling it in.
-
Name the action after its deliverable
Write what will exist when the action is finished, not the area it concerns. Run a full restore of the finance share and record the timings can be marked done by anybody who reads it. Backups cannot, and will still be in the list next quarter.
-
Give the action an owner
Set the owner in the row. One name, and a real one — an action owned by a department is owned by nobody, and it is the first to stall. The owner field is what the owner filter reads, so a consistent spelling of each name lets RiskOS pull one person's whole workload out of the register in a click.
-
Set a due date
The due date decides which group an action sits in, so it is the field that makes the list useful. A date in the past moves the row to Overdue and gains it a badge; a date on the near horizon moves it to Due Soon; anything further out lands in Later. Leave it empty and the action goes to No Due Date, the group to raid when you want work that was agreed but never scheduled.
-
Set the priority and the status
Priority is High, Normal or Low, separating the two or three things that cannot slip from the many that can. Status is Not Started, In Progress or Done. Move a row to In Progress the day work begins, so the list shows movement between reviews rather than a wall of untouched rows.
-
Narrow the list to the work you own
Search covers the list, and the owner filter cuts it to one person. Set that filter to a colleague's name before a one-to-one and the screen becomes their workload, in due order, with the risk behind each line visible. Clear it afterwards so the next pass sees the whole register again.
-
Tick it off when it is done
Each row has a checkbox. Tick it and the action completes and strikes through, leaving a record of the close rather than a gap. Completed actions are hidden by default; the show-completed toggle brings them back when a reviewer asks what was finished and when.
How the groups work
The grouping is the whole design. A flat list sorted by date tells you what is next; a grouped list tells you what is wrong. RiskOS derives every group below from the row's due date and completion state, so you never file an action into a group by hand.
| Group | What puts a row here | How to read it |
|---|---|---|
| Just Added | An action you have only now created | A holding area while you fill in the owner and the date. |
| Overdue | A due date that has passed, still open | The commitment the register is currently failing. Badged in the row. |
| Due Soon | A due date on the near horizon | This period's work. The group a weekly pass should empty. |
| Later | A due date further out | Scheduled and accounted for. Read it monthly, not daily. |
| No Due Date | No due date set | Intentions, not commitments. Give each one a date or close it. |
| Closed | Completed with the checkbox | The record of what was done. Shown when the toggle is on. |
What moves a row between groups
Changing a due date moves the row immediately, and so does ticking the checkbox. Nothing else does. Priority deliberately has no effect on the grouping: a High action not due for two months is still not this week's problem, and hoisting it above overdue work would hide what needs saying out loud.
The No Due Date group is the honest one
Most registers accumulate agreed work that was never scheduled, and because an undated action cannot be late, it never appears in an overdue count. Keeping it visible in its own group is the point. Work through it at the end of each review: date the row, give it an owner, or close it and accept the risk as it stands.
Status, priority and what each is for
Three statuses are enough to say where a piece of work has got to, and few enough that people keep them current.
| Status | What it means | When to move on |
|---|---|---|
| Not Started | Agreed and owned. No work has begun. | The day someone starts, not the day it is finished. |
| In Progress | Actively being worked, with a date to hit. | When the deliverable in the title exists. |
| Done | Finished. Tick the checkbox to close it out. | Nothing follows. The struck-through row is the record. |
Priority answers a different question. Status says how far along the work is; priority says what happens when two actions collide in the same week. Keep High scarce: a register where most rows are High has a priority field that no longer sorts anything.
Actions in the rest of the register
The gathered list is where actions get worked. Attaching each one to a risk or a control is what makes it turn up wherever decisions are made, without anyone copying it there.
On the risk itself
A risk's Actions section sits beneath its treatment strategy and plan, and the adjacency is the argument. A risk marked Mitigate with no open actions is a statement of intent. RSK-0007, at a residual of 15 against a target of 4, is credible only if the work that closes the gap is listed underneath.
On the control
Remediation work belongs on the control it fixes, in that control's own panel. A control only reduces risk once it is implemented or operating, so CTL-0003, a quarterly restore rehearsal still marked Planned, reduces nothing yet. The action that takes it into operation re-scores every risk deriving from that control.
During a review pass
Review mode puts each risk's actions on screen beside the scoring inputs, so you re-rate with the open work in front of you rather than from memory. A risk whose actions have all sat overdue since the last pass rarely deserves the lower rating it is about to be given.
On the dashboard and in reports
The dashboard counts open actions and how many are overdue: sixteen open with three overdue is a register being worked. Reports carry an open actions section you can switch on, so a board pack shows what was promised alongside the scores it is meant to change.
Troubleshooting
My action never shows up as overdue
It has no due date. An action without one cannot be late, so it stays in No Due Date and never reaches the overdue count. Open that group, set a date in the row, and it moves to where the date belongs as soon as you leave the field.
I cannot find an action I added a moment ago
Look in Just Added, at the top of the list. New actions pin there rather than dropping into a date group, so a row you have not finished filling in cannot disappear into the middle of the register. Give it a due date and it moves to its proper group on its own.
A completed action has disappeared
Ticking the checkbox closes the action and strikes it through, and completed rows stay hidden until you ask for them. Switch on the show-completed toggle and the Closed group returns, which is the view you want when someone asks what was delivered last quarter.
The list looks half empty
A filter is on. The owner filter cuts the list to one person and search narrows it further. Clear the search field, set the owner filter back to everyone, and the full set of actions returns.
An action is attached to the wrong risk
Actions belong to whatever they were created on. If a row shows the wrong parent, add it again from the correct risk or control's own Actions section with the same owner and date, then tick the misplaced one to close it, so the record remains rather than vanishing.
Routines that keep actions moving
- Read Overdue first, every time. Anything in that group either gets done, gets a new date with a reason, or gets closed honestly.
- Empty No Due Date once a month. Every row there is a decision that was never made. Date it, own it, or close it — leaving it undated is the only outcome that helps nobody.
- Filter by owner before a one-to-one. One name, one screen, in due order, with the risk behind each line, and the updates happen in the room.
- Keep High scarce. If more than a handful of rows are High, demote until the list is short enough to read aloud.
- Prioritise actions that change a control's status. Completing those re-scores every risk deriving from that control, so they move more of the register than anything else.
- Switch on the open actions section in reports. A board pack that shows scores without commitments invites the question anyway.
- Close, rather than delete. A ticked action stays as a struck-through record of what was done and when, which is exactly what you will want to point at a year later.
Frequently asked questions
How do I see all my risk treatment actions in one place?
Choose Actions in the sidebar. It shows every action attached to every risk and every control in the register as one list, grouped by due state: Just Added, Overdue, Due Soon, Later, No Due Date and Closed. Each row names the risk or control it belongs to, and every field can be edited in the row.
What is the difference between a treatment plan and an action?
The plan on a risk states the approach and why you chose it. Actions are the individual pieces of work that carry it out, each with an owner, a due date, a priority and a status. A plan with no actions under it is intention without delivery, and the risk's panel shows both together so the gap is obvious.
How does RiskOS decide which actions are overdue?
By the due date on the action. Any open action whose date has passed moves into the Overdue group and carries a badge on its row. Completing the action with its checkbox takes it out of that group immediately. An action with no due date cannot be overdue, and sits in the No Due Date group instead.
Can I assign a risk action to someone else?
Yes. Set the owner directly in the action's row, alongside the status, priority and due date. The owner filter then cuts the whole list to that person, which turns a register-wide list into one individual's workload in due order, with the risk or control behind each line still visible.
What do the action priorities High, Normal and Low actually do?
They separate the work that cannot slip from the work that can when two actions land in the same week. Priority does not change which group a row appears in — that follows the due date alone — so an important action still has to be dated to be chased. Keep High scarce or it stops distinguishing anything.
Where do actions for a control go?
On the control itself. Remediation work is added in the control's own panel and appears in the gathered Actions list with that control named on the row. Prioritise it: a control only reduces risk once it is implemented or operating, so the action that moves a planned control into operation re-scores every risk relying on it.
How do I show completed actions again?
Switch on the show-completed toggle. Completed actions are struck through and hidden from the working list by default, and the toggle brings the Closed group back into view. Actions are closed rather than removed, so the list doubles as the record of what was delivered and when somebody asks for evidence.
Do risk actions appear in an exported report?
Yes, if you switch on the open actions section when setting up the report. It travels in the same snapshot as the rest of the document, so the scores, the controls and the outstanding work all describe the same moment. The section appears in the PDF, the HTML file, the Excel workbook and the printed copy alike.