Risk register settings on Mac, explained
Three areas in RiskOS, the risk register for macOS: how a score is made, how much exposure you will carry, and what stays on your Mac.
Three areas sit behind ⌘,, and between them they settle how every number in your register is made, how much exposure you are willing to carry, and what leaves your Mac. Two of them reach backwards into risks you rated months ago. The third asks nothing of you and is still worth reading. RiskOS keeps the list short on purpose: a setting nobody understands produces numbers nobody trusts.
Two of the choices here change figures you have already recorded. Choosing what a control reduces re-scores every risk immediately; moving the appetite threshold re-checks the whole register against it. Both take effect as you make them, so make them when you have a moment to look at what moved.
Where settings live
Press ⌘, from anywhere in the app, or choose Settings in the sidebar under Output, below Reports and Import & Export. There are three areas and nothing else. Methodology holds the scoring scales, the band thresholds and the one choice about what your controls reduce. Appetite holds the organisation's threshold and any per-category thresholds with their rationales. Privacy sets out the promises the app makes.
Order matters when you are setting up. Methodology comes first, because appetite is expressed in the units methodology defines: a threshold of 9 means nothing until everyone agrees what a 9 is.
Work through settings in one pass
-
Open Settings
Press ⌘,, or choose Settings in the sidebar under Output. The three areas — Methodology, Appetite and Privacy — are the whole of it. Everything you change applies to the register as a whole, not to the risk you happened to be looking at.
-
Read the two scales before anyone rates anything
Methodology sets out the five likelihood ratings — Rare, Unlikely, Possible, Likely, Almost Certain — and the five impact ratings — Insignificant, Minor, Moderate, Major, Severe. The same labels sit beside every stepper in a risk's Assessment section, so the words agreed here are the words a rater sees.
-
Check where the bands cut
Confirm the four bands and the scores behind them: Low is 1–4, Medium 5–9, High 10–16 and Critical 17–25. The band drives the badge beside a risk in the table, where its marker sits on the matrix, and how a row reads in a report, so a rater who believes 10 is still Medium files rows that read wrongly.
-
Choose what a control reduces
This is the one setting in the window that changes numbers. It tells the register whether a control pushes a risk down the likelihood axis, down the impact axis, or across both. Pick the one that matches how your controls actually work, and expect every residual score to be recalculated the moment you do.
-
Set the organisation appetite threshold
Open Appetite and set the highest residual score the organisation will tolerate, on the same 1 to 25 scale. Every risk is measured against it at once, and anything above the line is flagged wherever that risk appears. The register carries an over-appetite filter of its own, so the whole set is one click away whenever you want to look at it.
-
Give a category its own threshold where it earns one
Where one part of the register warrants less tolerance than the rest, add a threshold for that category and write the rationale beside it. The rationale is what survives the meeting; a bare number invites the same argument again in six months.
-
Read the Privacy pane
Open Privacy and read what it says. There is nothing to switch on. The pane exists so the promises are written out in the app rather than taken on trust, which is what a client asking how you handle their data will want to see.
-
Refresh any client profiles
Each profile keeps its own snapshot of the methodology and the appetite, so a change made in Settings does not reach a profile on its own. Choose Profiles, select each profile that should follow the new rule, and use Update from Current Settings.
-
Back up once the settings are right
Choose File ▸ Back Up RiskOS… or press ⇧⌘B. The backup carries your settings along with everything else RiskOS holds — risks, history, controls, actions, assets, vendors, frameworks, indicators and events — so a restored register rates risks exactly as this one does.
Every switch, and what it moves
The useful way to read this window is by reach: one choice recalculates the whole register, one re-checks every row against a line, and the rest are there to be read and agreed on.
| Setting | Area | What happens when you change it |
|---|---|---|
| What controls reduce | Methodology | Every residual score in the register is recalculated immediately, and residual matrix markers move along the axis you chose. |
| Likelihood and impact scales | Methodology | Shown for reference. These are the labels beside every stepper, and the shared language a rating depends on. |
| Band thresholds | Methodology | Shown for reference. Low 1–4, Medium 5–9, High 10–16, Critical 17–25, as used by badges, cells and reports. |
| Organisation appetite | Appetite | Every risk without an override is re-checked against the new line. Breach flags and counts update at once. |
| Category threshold and rationale | Appetite | Risks in that category are measured against the category's number instead of the organisation's, and the rationale travels with it. |
| Privacy promises | Privacy | Nothing to change. The commitments are written out so you can read them rather than assume them. |
The switch that reaches backwards
You rate inherent likelihood and impact — the exposure with nothing standing in its way. RiskOS works out the residual from the controls you have linked, and the methodology decides which axis that reduction acts along. Change it and the whole register is re-scored at once, which is the behaviour you want: old rows rated under one rule and new rows under another is how a register stops being comparable with itself.
Four promises hold whichever option you choose. A residual score never exceeds the inherent score, never falls below 1, and a stronger control never raises a score. Only a control that is implemented or operating reduces anything: a planned control, however strong it will be one day, moves nothing yet, and the risk's panel says so.
What Methodology shows rather than asks
The scales and the band cuts are set out so a team can read them together and agree what each point means in their own organisation. That agreement is the real setting. Write the anchors you settle on into the risk descriptions — a cost, a duration, a regulatory outcome — so a Major rather than a Moderate is still legible a year later.
Appetite, and the order it resolves in
Appetite is the line between exposure you are content to carry and exposure you are not. One number covers the register, a category can depart from it with a reason, and a single risk can depart from both. To decide whether a risk is over appetite, RiskOS works down that list and takes the first answer it finds.
| Order | Level | Where it is set | When it applies |
|---|---|---|---|
| 1 | Risk override | The Appetite section of the risk's panel | Always wins, for that risk alone, and explains the threshold it replaced. |
| 2 | Category | Settings ▸ Appetite | Applies to every risk in that category that has no override of its own. |
| 3 | Organisation | Settings ▸ Appetite | Applies to everything else in the register. |
| 4 | None | — | With no threshold set at any level, nothing is flagged and the Appetite column stays quiet. |
Choose the number by looking at the register you already have. Twelve active risks averaging 9.6, with four rows over an appetite of 9, is a line doing useful work: tight enough to catch the backup restoration that has never been tested end to end, six points above the threshold, and loose enough that the rest are not clamouring for attention. A threshold that flags nothing is decoration; one that flags everything is noise.
The Privacy pane, in plain terms
Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine. The pane spells that out in the app so that you can read the commitments rather than take them on faith, and so that you have something to point at when a client asks where their risk data lives.
What it sets out: no account and no sign-in, no tracking, no analytics, no servers and no sync, and no advertising. The one piece of network the app uses is Apple's App Store, for purchases, and it never sees a single risk.
How settings reach a client profile
A profile dresses the whole app for one client: its own methodology, risk appetite, report defaults, client name and client logo. The methodology and appetite it carries are snapshots, which is why a change in Settings does not rewrite the rules you agreed with a client last quarter.
Update from Current Settings refreshes a profile's snapshot from whatever Settings now says. Do it profile by profile, and only where the new rule is one that client has accepted. Switching takes a keystroke — ⌃⌘P cycles profiles, and there is a switcher in the sidebar footer — so checking each one takes a minute.
RiskOS includes one profile. Small Business, Enterprise and Consultant unlock more with a one-time purchase, never a subscription, and profiles beyond your current cap are locked rather than deleted.
Choices that live outside Settings
Several things people go hunting for in Settings are set where they are used, and remembered from then on. A preference is easier to get right in front of the thing it changes.
| Choice | Where it is made |
|---|---|
| Which columns the register shows, and in what order | Right-click the table header in Risks. The arrangement is remembered. |
| A filtered view you keep rebuilding | Set the filters, then use Save Current Filter… to name the combination. |
| The appetite threshold for one particular risk | The Appetite section of that risk's panel. |
| How often a risk comes back for review | The review cadence field in the risk's Summary section. |
| What a report contains, and who it says it was prepared by | The cover fields and section toggles in Reports. |
| Your business name, logo and contact details on exports | Set Up Branding, with a live preview of the real header and footer. |
| A client's name and logo on their reports | The profile itself, in Profiles. |
| Sidebar and panel widths | Drag them. RiskOS remembers where you leave them. |
Troubleshooting
Every score changed and I did not touch a risk
Something in Methodology moved, almost certainly the choice of what controls reduce. Every residual score is recalculated the moment that changes, so no row is left rated under the old rule. Open a risk you know well and compare its residual figure in History with what you expected. If the new direction is wrong, change it back and the scores return.
I raised the threshold and one risk is still flagged
That risk has an override, and a threshold set on the risk itself wins over both the category and the organisation. Open the risk, look at the Appetite section, and either adjust the override or switch it off to let the inherited threshold apply again. The section names the threshold it is replacing.
A category threshold does not seem to be applying
Check the risk's category first: a risk filed under a neighbouring category is measured against a different line. Thresholds are set per category, so a subcategory does not carry one of its own. If the category is right, the risk has an override, which takes precedence over everything else.
A client's report still shows the old appetite
Profiles keep snapshots of the methodology and the appetite on purpose, so a change to your own settings does not rewrite a client's agreed position. Choose Profiles, select that client, use Update from Current Settings, then export the report again.
I cannot find a setting for the columns or the filters
They are not in this window. Right-click the table header in Risks to show, hide and reorder columns; the arrangement is remembered. Filters are set in the register itself, where Save Current Filter… names a combination so you can bring it back.
The bands are hard to tell apart
Colour is never the only carrier of state. Every band badge pairs its colour with a symbol and the written word, so a row reads the same whether or not those colours separate for you. With Reduce Motion on, movement is removed and the highlights stay, and VoiceOver reads a whole row as one sentence.
Habits that keep settings out of the way
Settings should be a place you visit twice a year, not a dial you keep adjusting.
- Settle the methodology before the register grows. Ten risks rated under a rule you then change is a pleasant afternoon. Two hundred is not.
- Change one thing at a time. Move what controls reduce and the appetite threshold in the same sitting and you will not know which produced the register in front of you.
- Look at what moved. After any change that re-scores, sort by residual and turn on the over-appetite filter. Two minutes there beats any amount of reasoning about the setting.
- Write the rationale wherever it is offered. A category threshold with a reason attached is a decision. The same number alone is a preference somebody will overturn.
- Refresh profiles in the same sitting. The snapshot protects a client's agreed position, which also means an unrefreshed profile keeps using the old one.
- Back up straight afterwards. ⇧⌘B takes a moment, and the backup carries your settings with everything else.
- Re-read the appetite once a year. The right threshold flags the handful of rows you want in front of a board, and that number drifts as the organisation changes.
Frequently asked questions
Where are the settings in RiskOS on Mac?
Press ⌘, from anywhere in the app, or choose Settings in the sidebar under Output, below Reports and Import & Export. There are three areas: Methodology for the scoring scales, the band thresholds and what your controls reduce; Appetite for the organisation and per-category thresholds; and Privacy, which sets out the promises the app makes.
Which setting changes risk scores I have already recorded?
The choice of whether controls reduce likelihood, impact or both. Change it and RiskOS recalculates every residual score in the register immediately, so no row is left rated under the previous rule. Changing the appetite threshold does not alter any score; it changes which risks are flagged as sitting above the line you tolerate.
Can I change the 1 to 5 scales or the band thresholds?
The scales and the band cuts are set out in Methodology so a team can read them together and rate against the same meanings. Likelihood runs Rare to Almost Certain, impact Insignificant to Severe, with Low at 1–4, Medium 5–9, High 10–16 and Critical 17–25. The work is agreeing what each point means for you.
What is the difference between risk appetite and a target score?
Appetite is a line you measure against: the highest residual score you will tolerate, set for the organisation, a category or one risk. A target is an intention for a single risk — where you mean to get it to, and what the treatment plan has to achieve. A risk can sit under appetite and still have a target below it.
Do settings apply to every client profile?
No. Each profile carries its own snapshot of the methodology and the appetite, along with its report defaults, client name and logo, so changing your settings does not rewrite a client's agreed position. Open Profiles and use Update from Current Settings on each profile that should follow the new rule.
Why is a risk still over appetite after I raised the threshold?
Because something more specific is deciding it. The threshold for a risk is resolved in order: an override on the risk itself, then its category, then the organisation, then none at all. The first one found wins. Open the risk and look at its Appetite section, which names the threshold in force and the one it replaced.
Are my settings included in a backup?
Yes. File ▸ Back Up RiskOS… writes everything RiskOS keeps to a single file: risks, history, audit trail, controls, actions, assets, vendors, frameworks, indicators, events and your settings. A restored register therefore rates risks the same way the original did, which matters most when you move to another Mac.
Does RiskOS need an account or collect usage data?
No. There is no account and no sign-in, no tracking and no analytics, no servers and no sync. Your register sits on your Mac and leaves it only when you export or back it up yourself. The only network use is Apple's App Store, for purchases, and it never sees your register.