User Guide
Features and operation for end users
1. Signing in and initial setup
First-time setup (administrator)
On the very first launch there is no account yet. The app automatically opens the admin setup. Set an admin password (at least 8 characters) and confirm it. The administrator manages users, projects and the database location.
Sign in
Enter your user name and password and tap “Sign in”. User accounts are created by the administrator. Via “Sign in as admin” you switch to admin sign-in.
Choosing another database
At the bottom of the sign-in screen the current database location is shown. Tapping it opens a file picker where you can select another existing database (e.g. a backup or a second database).
Signing in after switching databases: When you switch to a different/imported database – or join a shared iCloud database – the app adopts that database's user accounts and signs you out. The sign-in screen appears again, and you can then sign in only with an account that exists in the imported or shared database (its administrator or a user created there) – your previous local account does not apply. Without an administrator the app starts with admin setup; if the file is encrypted it asks for the passphrase first.
2. User management (administrator only)
As an administrator you open user management via the shield icon at the bottom of the sidebar. On the Mac it is additionally available from the menu bar under “Risky Business” → “User management…”.
- Create a user: enter user name and password (min. 8 characters) and tap “Create user”.
- Further administrators: enable “Create as administrator”, or promote/demote an existing account via the ⋯ menu. The primary “Admin” account and the last remaining admin are protected.
- Reset password: key icon in the respective user row.
- Delete user: trash icon; a confirmation appears.
3. Projects
Risks can be assigned to projects. Using the project picker in the sidebar you filter the view to a single project or show “All projects”.
- Create: “+” in the sidebar or “Create project” in project management.
- Rename / change description: edit directly in project management and save.
- Delete: trash icon with confirmation. Assigned risks are kept but lose their project assignment.
- Permissions: per project you decide with switches which users get access. The administrator always has access.
4. Creating and editing risks
Use “Add risk” (plus icon) in the risk register to open a menu: “Blank risk” opens the empty form, “From template…” opens the template catalog. To edit, open a risk and tap “Edit”.
Creating from a template
The template catalog contains pre-written standard risks, grouped by category and searchable – each with a title, description, category, suggested probability and impact, and an initial mitigation plan. After you pick one, the form opens already pre-filled; you adjust the values and save.
Fields
- Title and description.
- Category: Operational, Financial, Strategic, Compliance, Technology or Reputation.
- Probability (P) and impact (I): values from 1 to 5 each.
- Status: Identified, Assessed, Mitigated, Accepted, Occurred or Closed. “Occurred” is highlighted in red.
- Owner and an optional due date.
- Mitigation plan and measure effectiveness (optional).
- Target value (optional): capture the intended residual risk via “Set target”.
- Review cycle: the interval for the next review – Default, No review, Every 30/90/180 days or Yearly.
- Project assignment.
Text formatting
The free-text fields Description, Mitigation plan and Effectiveness of measures support formatting with a real text editor via a small toolbar above the field: Bold (B), Italic (I), Strikethrough (S), Code and Bullet list (•); the formats can be combined freely. The detail view renders the fields with their formatting; the same formatting is available for the project description.
Score and priority
The score is probability × impact (1–25). The priority is derived from it: Low (1–5), Medium (6–11), High (12–19), Critical (20–25).
Comments
In the detail view any signed-in user can leave comments/notes – with author and timestamp, separate from the change history and synchronized across all devices.
Marking as reviewed
In the detail view you can mark a risk as reviewed via “Mark as reviewed” (checkmark icon in the toolbar). The time appears as “Last reviewed” in the details and is recorded in the history. You can also do this straight from the widget or Lock Screen (see section 13).
Review cycle and re-review
From the chosen review cycle and the last review (or the creation date) the app calculates the next review due. In the detail view you see a “Next review” row (overdue ones highlighted); risks that are due can be filtered in the register and appear as a “Due for review” card on the dashboard. The default review cycle is set by the administrator in the risk-budget configuration; optionally the app reminds you of due reviews (section 13).
5. Risk register
The risk register shows the risks according to the project selection in the sidebar: the risks of the currently selected project – or all risks you can access when “All projects” is selected. Choosing “No project” shows only risks that aren’t assigned to any project. The following then apply within that selection.
The risk register lists all visible risks with search (title/description/owner), filters (priority/status/category and “Due for review only”), sorting (score, ID, title, status, due date, next review or last change) and multiple selection to move risks to the trash or export them together – or, via “Edit selected”, to set status, owner, project or due date for all selected risks at once. Risks with status “Occurred” appear in red. Matches in the title are highlighted.
Quick actions: via the context menu (right-click on the Mac, long-press on iPhone/iPad) or swipe gestures you change the status, mark a risk “as reviewed” or duplicate it – without the form.
Keyboard shortcuts (Mac/iPad): ⌘F focuses the search, ⌘E edits and ⌘D duplicates the selected risk; ⌘N creates a new one. On the iPhone the rarer actions are grouped in a “More” overflow menu.
Via the “Columns” button you decide which fields the PDF and PowerPoint export of the register contains (e.g. additionally the due date, project, review cycle or target score); the Excel export stays complete.
Trash
Deleted risks first land in the trash (button in the toolbar, with a count). There you can restore individual risks or delete them permanently, or empty the trash. The trash is synchronized across all devices.
6. Risk matrix
The risk matrix places risks in a 5×5 grid by probability and impact. The cell color indicates the priority; tapping a risk opens its details.
Current → Target
When open risks have a target value, a “Current → Target” view appears below the matrix. An arrow leads from the current position to the target. The arrow color shows the effect: green = the target lowers the score, red = higher, blue = same score.
7. Dashboard & Portfolio
The dashboard shows key figures (total, critical, high, open), priority and status charts, target achievement, a “Due for review” card and the top risks by score. The “Management report” button generates a summary – as a PDF or an editable PowerPoint. With “Choose sections …” you decide which parts are included: summary (key figures, priority and status distribution), risk matrix, Current → Target and the risk timeline.
Portfolio (across projects)
The Portfolio view in the sidebar summarizes all projects at a glance – regardless of the currently selected project. At the top you see the number of projects and the total risk budget. Below, “Risks per project” lists each project with its key figures, a proportional priority bar (heatmap), the risk budget and the average score. Tapping a project jumps to the filtered register; unassigned risks appear under “No project”.
Via the “Export” button at the top of the Portfolio view you generate a Portfolio report as a PDF or PowerPoint – with the key metrics and charts (budget and priority per project, status and category distribution, trend of the active risks) plus a per-project table.
8. Risk budget
The risk budget estimates the expected value per risk: every probability level is mapped to a percentage and every impact level to a monetary value. The budget is probability (%) × impact value. Shown in the form, the detail view, as a chip in the register and as the total risk budget on the dashboard. The mapping is configured by the administrator (menu or the € icon in the sidebar); there they also set the default review cycle (section 4).
9. Risk timeline
The risk timeline shows the evolution over time. Every change is logged with timestamp, user and a field diff. Switch between Day/Week/Month; with inventory, activity and risk movements on the matrix. Via “Audit log” you export the full history as Excel (.xlsx), CSV or a multi-page PDF – in the Excel file all columns can be filtered and sorted.
10. Export (PDF, PowerPoint, Excel)
All main views (dashboard, portfolio, risk register, risk matrix, risk timeline) are exported via one “Export” menu grouped by output: the view as PDF or editable PowerPoint (PPTX), plus Excel in the register, the management report on the dashboard and the audit-log export on the timeline. When exporting the risk matrix, a second page or slide “Current → Target” is added.
The Excel export (menu “Export → Export as Excel”) always contains the full column structure – unlike PDF/PowerPoint; the “Columns” selection (section 5) only applies to the on-screen table, PDF and PowerPoint. Which risks (rows) are included follows the current view (search, filters, sorting, multiple selection). To read data back, use “Import from Excel”: existing risks are updated by ID/number, new ones are added, nothing is deleted. The exported workbook shows content-heavy text columns with text wrapping and an AutoFilter in the header row.
Report branding
Every PDF page and PowerPoint slide carries a header branding. In Settings under “Report branding” the administrator sets a company name, an optional footer note and a company logo (without a logo the app icon serves as a fallback). The branding is shared by all users.
Every export suggests a file name that begins with the export date (year-month-day), e.g. 2026-08-18_RiskyBusiness_Risikomatrix.pdf – so archived files sort chronologically by name.
11. Database location and multi-user operation
How to tell where you are working: The login screen shows the active database at the bottom — “iCloud sync (Beta)” or “iCloud – shared database” when sync is on, otherwise the local storage location.
The administrator decides where the shared database lives: local (app container), on a network drive or in a cloud folder (iCloud Drive, OneDrive, Dropbox). Several devices share the same file; changes are reconciled every 10 seconds (last saved record wins, deletions are propagated reliably).
Shared database via iCloud (Beta)
One cloud database per database: each local database syncs into its own iCloud store — the contents of different databases never mix. When enabling, you choose between “Upload current data” and “Use existing iCloud data”. When uploading you first give the database a name (required) — so you can always tell which local database belongs to which cloud sync; the name appears in the pickers and can be changed anytime in Settings. With “Choose an existing iCloud database …” you can reconnect — e.g. on another device — to an already-existing iCloud database. iCloud databases you no longer need can be removed entirely from iCloud via “Delete an iCloud database …” (local databases are unaffected).
Administrators only: Enabling iCloud sync, creating a share link and joining a shared database all require administrator rights.
Alternatively, a database can be synchronized and shared directly via Apple iCloud (CloudKit) – marked Beta and switchable per database. In Settings the administrator enables “iCloud sync (Beta)” (uploads the current data and then syncs automatically across devices) and uses “Create share link …” to generate an invitation link with which invited iCloud users collaborate on the same database. Everyone needs an active iCloud account; the data resides in the owner's iCloud (processing by Apple, developer without access – see the privacy policy). iCloud mode can be disabled again at any time. Participants without administrator rights leave a shared database via “Leave cloud database” on the login screen (sign out first).
Encrypting the database (optional)
If the database is a separate file, the administrator can encrypt it with a passphrase using AES-GCM. All authorized users need the same passphrase; it is stored securely in the keychain. Without the passphrase the data cannot be recovered.
12. Backing up and importing the database
Caution — import replaces: Importing a database completely replaces the current risks and projects (it does not add to them). Back up the current database first if needed.
Administrators only: Backing up and importing the entire database is only possible when signed in as an administrator. The Excel export/import of individual risks is available to every signed-in user.
From the database menu you save a complete file (risks and projects) or, after confirmation, replace the current data with the contents of a chosen file.
13. Reminders, widget and shortcuts
Due-date reminders
In Settings enable “Due-date reminders”. Risky Business then notifies you about open risks with a due date – by default on the due date at 9:00 AM, with a configurable lead time (0/1/3/7 days). With “Review reminders” you are additionally notified as soon as a risk is due for re-review according to its review cycle.
Home-screen widget (iPhone, iPad, Mac)
Add the widget to your home screen. Small shows the key figures, medium also the next upcoming due risks. In the medium widget you mark a risk as reviewed right from the checkmark – it turns green and the title is struck through. On the Mac the widget lives in Notification Center or on the desktop.
Lock Screen and Control Center (iPhone, iPad)
On the Lock Screen compact widgets are available (rectangular, circular, inline). In Control Center you can add the “New risk” control.
Siri and Shortcuts
Available shortcuts (also via Siri): “Create a new risk”, “Show due risks”, “Open portfolio” and “Open risk matrix”.
New: Siri answers three shortcuts out loud, without opening the app: “How many open risks”, “What is due” and “Risk budget”.
14. Language and appearance
Window sizes (Mac): The Settings and Risk budget windows are freely resizable on the Mac.
You choose the app language (English, German, Spanish) in Settings under “Language” – System language or fixed; the switch takes effect immediately. In Settings you choose the appearance System, Light or Dark. Under “Security” you can optionally enable a biometric app lock (Face ID / Touch ID / device passcode).
15. Platforms
Risky Business runs on Mac, iPad and iPhone. On the Mac additional windows are available; on iPhone and iPad the app supports portrait and landscape. On iPhone the view is compact (wide graphics can be scrolled sideways).
System requirement (from version 2.3): iOS 26, iPadOS 26 or macOS 26 or newer. If several devices use the same shared database, they must all be on version 2.3 (system 26+), as the file format has been updated.
Glossary
- P – probability (1–5).
- I – impact (1–5).
- Score – P × I (1–25).
- Priority – derived from the score (Low/Medium/High/Critical).