From your file to the report
A fictitious risk register, kept in Excel the way many SMEs keep it, flaws included. Everything below is calculated by the import screen's code from this file, with no manual correction.
10 rows below the header, “;” separator, UTF-8: it opens in Excel like the register export. Company, roles and figures are invented.
Download the fictitious example (CSV)The import screen exists in French only, and it recognises columns from French headers. The example file is therefore in French too; a column with an English header is assigned by hand, from the list.
How the file gets in
There is no file upload. You open the file in Excel, select the rows including the headers, copy them and paste them under “Registre”, “Importer depuis Excel”. Nothing is saved before you click “Importer”, and 300 rows at most go through per paste.
1. The columns taken over
The screen guesses the mapping from the file's headers; each choice can be corrected from a list. Only the risk title is required.
| File column | First value | Becomes |
|---|---|---|
| N° | 1 | Ignored |
| Risque | Cyberattaque par rançongiciel | Risk title |
| Catégorie | Informatique | Category |
| Description | Chiffrement des serveurs, facturation et planification à l'arrêt | Description |
| Propriétaire | Directeur | Owner |
| Probabilité | 4 | Net likelihood |
| Impact | 5 | Net impact |
| Mesures en place | Sauvegarde hebdomadaire sur disque externe | Controls in place |
| Plan d'action | Double authentification sur la messagerie | Action plan |
| Responsable action | Responsable informatique | Action owner |
| Échéance | 30.11.2026 | Action due date |
| Remarque | — | Ignored |
2. What the file lacks
No column fills these fields. The import still goes ahead, with these consequences:
- Gross likelihood and impact, before controls: copied from the file's only pair. Gross and net are therefore equal, and the report cannot show what the controls in place reduce.
- Trend: every risk comes in as “stable”. From the first period close onwards, the trend is calculated from one quarter to the next.
- Left empty: Cause.
The columns “N°” and “Remarque” match no field: their content is not imported. Risks receive the codes R-01, R-02… in file order.
3. What the screen flags before importing
These warnings appear below the preview, before you click “Importer”:
Empty rating, replaced by 3: 1 of 9 (row 5 of the file).
Due date that does not exist in the calendar, left empty: 1 of 9 (“31.09.2026”).
Row without a risk title, ignored: 1.
No warning, because the conversion is unambiguous: ratings written in words become numbers (“Élevé” → 4, “Moyen” → 3). The preview shows the original value under each rating.
What the screen does not flag
The duplicate. Rows 2 and 7 of the file hold the same risk. The import does not compare rows with each other: they become two risks, and one of them has to be deleted by hand in the register.
4. The resulting register
The risks as they arrive in the register, ranked by net level (likelihood × impact), with no retouching.
- Risks imported
- 9
- Above appetite (net ≥ 12)
- 5
- Default ratings
- 1
- Duplicates imported
- 1
Of the 5 risks above appetite, 1 comes from the duplicate and 1 rests on a default likelihood: the board would be reading wrong figures.
| Code | Risk | Owner | Net |
|---|---|---|---|
| R-01 | Cyberattaque par rançongiciel Informatique | Directeur | 20 · Critical |
| R-06 | Cyberattaque par rançongiciel Informatique | Directeur | 20 · Critical |
| R-04 | Défaillance du principal client Commercial | Directeur | 15 · Critical |
| R-02 | Départ du chef d'atelier Ressources humaines | Directeur | 12 · High |
| R-03 | Hausse du prix de l'électricité Financier | Responsable finances | 12 · High |
| R-07 | Panne de la presse principale Opérationnel | Chef d'atelier | 9 · Medium |
| R-08 | Retard de livraison de l'acier Approvisionnement | Responsable achats | 9 · Medium |
| R-05 | Accident sur une presse Santé-sécurité | Chef d'atelier | 8 · Medium |
| R-09 | Données personnelles mal protégées Juridique | Directeur | 6 · Medium |
5. What the file does not hold: the settings
The report needs settings that an Excel register does not carry. They are entered once under “Paramètres”:
- Risk appetite threshold: the net level from which the board must decide. 12 when the workspace is created, adjustable.
- Period of the report, for example Q4 2026.
- Company name, sector, report author and their role, printed at the top of the report.
6. To check before presenting the report
This work remains manual, risk by risk:
- Delete the duplicate (rows 2 and 7 of the file).
- Rate the likelihood left at 3 (row 5 of the file).
- Enter gross ratings where the controls in place reduce the risk.
- Correct the unreadable due date (“31.09.2026”).
- Review the appetite threshold and the period under “Paramètres”.
The demonstration report comes from another fictitious register, Helvetia Métal SA's, which runs through the whole demonstration: this is what the deliverable looks like once the register has been checked.
See a complete board report →