How to use the risk library on Mac
You can do this with RiskOS, a risk register for macOS. Thirty-nine worked examples across seven categories, and how to make one your own.
A register that starts empty tends to stay narrow. The first dozen risks anyone writes down are the ones already on their mind, and the ones that eventually hurt are usually the ones nobody thought to name. The risk library exists to widen that first pass: thirty-nine worked examples, written out properly, waiting to be argued with.
Library entries arrive in your register as drafts, and their suggested ratings are a starting point for your own assessment rather than an authority. Nothing is final until you have read it and re-rated it.
Where the risk library lives
Choose Risk Library under Reference in the sidebar, below the register and the signals sections. The list in the middle holds the thirty-nine entries; selecting one opens it in the panel on the right, where the whole example is laid out on a single screen.
Above the list are the controls you will use most: a search field, a category filter, and a toggle that hides entries already added to your register. Search covers the entry itself, so a word from the description finds it as readily as a word from the title. The panel and the sidebar both resize, and RiskOS remembers where you leave them.
Add a library risk to your register, step by step
-
Open the risk library
Choose Risk Library in the sidebar under Reference. The full set of thirty-nine entries loads straight away, and selecting any one of them opens the whole example in the panel on the right.
-
Narrow to the category you are worried about
Use the category filter to show one of the seven groups on its own — cybersecurity, cloud, third-party and vendor, business continuity, project delivery, compliance and regulatory, or artificial intelligence. Reading one category end to end is a better use of ten minutes than skimming all thirty-nine, because the entries within a group are written to contrast with each other.
-
Read the entry before you add it
Select an entry and read the panel. Each one carries a suggested starting rating, a typical treatment and a short list of controls to consider. Ask the only question that matters at this stage: could this happen here, in a form somebody would recognise? If the answer is no, move on. A register padded with risks nobody believes in is worse than a short one.
-
Add the entry to your register
Add the entry from its detail view. It is created as a draft risk with its own permanent reference, and the panel confirms what it did in plain words — Added as RSK-0042. The entry is then marked in the library list, so a second pass through the same category shows you at a glance what you have already taken.
-
Rewrite the title in your own words
Open Risks and select the new draft. Edit the title and description in the panel header so they describe your organisation rather than a generic one: name the system, the supplier, the regulator or the deadline. A risk called Backup restoration has never been tested end to end starts an argument in a meeting; a risk called Backups does not.
-
Rate it against your own scales
Open Assessment and set the inherent likelihood and impact yourself on the 1–5 steppers. Treat the suggested rating as a prompt to react to rather than a number to keep. If your answer lands well away from the suggestion, that difference is worth a sentence in the description — it is usually the most interesting thing about the risk.
-
Link the controls it suggests
Open Controls on the risk and work through the entry's list of controls to consider. Use the picker to link one you already have, or to create it where you do not. Remember that only controls that are implemented or operating reduce the residual score; a control you intend to build reduces nothing yet, and RiskOS says so rather than flattering the number.
-
Set the treatment, the owner and the review cadence
In Treatment, choose Mitigate, Accept, Transfer or Avoid and write the plan with a due date. In Summary, set the owner, the business unit and the review cadence, which schedules the next review date. The entry's typical treatment tells you what most organisations do; the owner is the part only you can supply.
-
Take it out of draft
When the title, the rating, the controls and the owner all describe your organisation, change the status in Summary from draft to active. Until you do, the draft is a clear signal in the table that the risk is borrowed and has not yet been thought about properly.
The seven categories, and what each one covers
The categories exist to make browsing tractable, not to be a taxonomy. Most real risks touch two or three of them, and the entry sits under whichever one it is usually owned from.
| Category | What it covers | Where it usually bites |
|---|---|---|
| Cybersecurity | Attack, intrusion, data exposure, access that was never withdrawn. | Ransomware, unreviewed privileged access, unencrypted devices. |
| Cloud | Dependence on hosted infrastructure and the services built on it. | A single region failing, a configuration nobody owns. |
| Third-Party / Vendor | What other organisations do on your behalf, or fail to. | Concentration in one supplier, an outage at a payroll provider. |
| Business Continuity | Whether you could actually carry on, and for how long. | Untested restores, key person dependency, no second site to work from. |
| Project Delivery | Change you have chosen to make and may not finish. | Budget overrun, a migration that stalls halfway. |
| Compliance & Regulatory | Obligations with dates, evidence and consequences attached. | A reporting deadline missed, a control with no evidence behind it. |
| Artificial Intelligence | Systems that generate output somebody then relies on. | Unreviewed model output reaching customers. |
A useful exercise on a quiet afternoon is to open each category in turn and count how many entries you can honestly say do not apply to you. Where a whole category comes back empty, that is usually a gap in the register rather than good fortune.
What each entry gives you
An entry is not a template to be pasted in. It is three separate pieces of thinking, and each one is meant to be used differently.
| Part of the entry | What it is | What to do with it |
|---|---|---|
| Suggested starting rating | A likelihood and impact pairing that is typical for this scenario. | React to it. Set your own ratings and note why yours differ. |
| Typical treatment | The strategy most organisations choose for this kind of exposure. | Use it as a sanity check on the strategy you were going to pick. |
| Controls to consider | The controls that usually do the work of reducing it. | Link the ones you already run; create the ones you are missing. |
The suggested starting rating
The rating is there to stop a blank page, and to give you something to disagree with. Disagreement is the point: an organisation with rehearsed restores should rate a continuity risk well below the suggestion, and an organisation that has never tried should rate it above. A register full of untouched suggested ratings is a register nobody has read.
Once you set your own inherent likelihood and impact, the score, the band and the matrix markers follow immediately, and the assessment is written into the risk's History with the reason you give. That history is what makes a borrowed risk defensible a year later.
The typical treatment
Each entry names the treatment strategy that usually fits the scenario, drawn from the same four the register offers: Mitigate, Accept, Transfer or Avoid. It is a check on your instinct rather than a decision. Where your chosen strategy differs from the typical one, that is worth recording in the treatment plan, because it is precisely the choice a board or an auditor will ask about.
The controls to consider
This is the part that saves the most time. Rather than inventing a control set from nothing, you get a short list of what actually reduces this exposure, and you can link each one from the risk's Controls section — linking what exists, creating what does not. The list also works as a quiet audit of your own control set: a suggested control you cannot match to anything you run is a finding, not an omission in the library.
Making an entry your own
The difference between a register that survives its first review and one that does not is how much of it was actually written by the organisation it describes. Four edits do most of that work.
Name the thing, not the worry
Replace any generic noun in the title with the specific one. Supplier concentration becomes Supplier concentration in a single logistics partner. The register's search covers title, reference, category, owner, detail and tags, so specific words are also what make the risk findable in two years' time.
Set the category and the business unit
In Summary, confirm the category and subcategory, and set the business unit. Categories can carry their own appetite threshold, so where a risk sits determines the line it is measured against — a compliance risk may be held to a stricter threshold than an operational one.
Give it an owner who knows
An owner is a person who can be asked about the risk and answer without preparing. Library entries cannot supply one, and a risk with no owner tends to keep its suggested rating for ever. Setting the owner also gives the table something to sort by: the Owner column brings together everything one person answers for.
Check it against appetite
Once the rating is yours, look at the over-appetite flag in the risk header. A drafted risk that lands above your appetite the moment you rate it honestly is the most valuable thing the library can hand you, because it is an exposure you were carrying without having named it.
Using the library once the register already exists
The library is usually read once at the start and then forgotten, which wastes most of it. A few later uses earn their time.
As a gap check before a review. Before a quarterly pass, open a category and turn on the toggle that hides entries you have already added. What remains is a short list of scenarios you have not written down. Two or three of them will deserve a risk each time.
As a workshop prompt. Reading entries aloud to a team produces better risks than asking people what keeps them awake. Concrete scenarios prompt concrete objections, and the objections are where your real wording comes from.
As a second opinion on a rating. When an existing risk covers the same ground as a library entry, comparing the two ratings is a cheap challenge. Where yours is far lower, you should be able to point to the operating control that explains the difference.
Troubleshooting
I cannot find an entry I know is there
Check whether a filter is still on. A category filter or the hide-already-added toggle narrows the list, and an entry you have added is hidden by that toggle rather than removed. Clear the search field as well — search matches the entry's own wording, so a term borrowed from your register may not appear in the library's.
The risk I added is not in my register
It is there, as a draft, with the reference the library confirmed when it added it. If the register's table is filtered by band or set to hide anything, the new row can be filtered out of view. Clear the filters — the filter icon fills when one is on — and look at the top of the table, where new rows pin themselves.
The suggested rating looks wrong for us
Then it is doing its job. The suggestion describes a typical organisation, not yours, and it is deliberately editable the moment the risk lands in your register. Set the ratings you believe, and write the reason into the description so the next reader understands the gap between the two.
I added an entry I did not mean to
Risks are closed rather than deleted, so the row stays in the record with its reference intact. Select it and close it. Closed risks are hidden from the register by default and can be brought back into view with the show-closed filter whenever you need to show what was considered and set aside.
My register has started to read as generic
That happens when entries are added faster than they are edited. Sort the register by its Status column to bring the drafts together, work through them one at a time, and give each a specific title, an owner and a rating of your own. If a draft survives that and still says nothing about your organisation, close it.
Habits that get more from the library
- Add in small batches. Three entries fully edited beat fifteen left as drafts. The library is not going anywhere, and drafts age badly.
- Read the whole category, add from part of it. The entries you reject still shape how you word the ones you keep.
- Edit the title first, always. It is the field that appears in the table, in every search and in every report, and it is the one that makes a borrowed risk yours.
- Link controls before you re-rate. With the linked controls in place, the residual score comes from the effectiveness of what you actually run, rather than from a number you nudged until it looked right.
- Revisit the library each quarter. Hide what you have added and read what is left. It is the cheapest gap analysis available to you.
- Use it to grow the control set too. A suggested control you cannot link to anything is a control you do not have. Create it as planned, and give it an action with a date.
- Keep the drafts visible. Draft status is a working signal. Clearing it deliberately, risk by risk, is what turns a borrowed list into a register.
Frequently asked questions
How many risks are in the RiskOS risk library?
Thirty-nine worked examples, across seven categories: cybersecurity, cloud, third-party and vendor, business continuity, project delivery, compliance and regulatory, and artificial intelligence. Each one carries a suggested starting rating, a typical treatment and a short list of controls to consider, so an entry gives you a rating to argue with as well as a title.
What happens when I add a risk from the library?
A new risk is created in your register as a draft, with its own permanent reference, and the detail view confirms it in plain words — for example, Added as RSK-0042. The entry is then marked in the library list so you can see what you have already taken. Everything on the new risk is yours to edit.
Are the suggested ratings accurate for my organisation?
They describe a typical organisation, which is not the same as yours. Treat a suggestion as a prompt: set your own inherent likelihood and impact on the 1–5 steppers, and note in the description why your rating differs. The score, the band and the matrix markers all follow from your ratings, not from the suggestion.
Does adding a library entry create its controls as well?
No. The entry names the controls worth considering, and you decide what to do with them. Open the risk's Controls section and link a control you already run, or create one where you do not. Only controls that are implemented or operating reduce the residual score, so a newly created planned control changes nothing yet.
Can I add the same library entry twice?
Added entries are marked in the list, and a toggle hides them entirely, so the library is built around adding each one once. If you want a second version of the same scenario for another business unit or client, duplicate the existing risk in the register instead. The duplicate gets its own reference and can be edited independently.
How do I search the risk library?
Use the search field above the list, which matches the wording of the entries themselves. Combine it with the category filter to read one group at a time, and with the toggle that hides what you have already added when you are looking for gaps rather than browsing. Clearing all three restores the full set of thirty-nine.
Can I remove a risk I added from the library by mistake?
Risks are closed rather than deleted, so the record stays complete. Select the risk and close it; if several want closing at once, select them together and confirm the prompt. Closed risks drop out of the register view and can be shown again with the show-closed filter, which means a scenario you considered and set aside is still there to point at during a review.
Is the risk library stored on my Mac?
Yes. The library comes with the app, so it is there the first time you open the register. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine. Browsing the library, adding an entry and re-rating it all work with no network connection of any kind.