Skip to main content

Key Risk Indicators (KRIs)

Define and monitor quantitative metrics that provide early warning signals when risks are increasing, enabling proactive risk management.

What are KRIs?#

Key Risk Indicators (KRIs) are quantitative metrics that provide early warning signals when risks are increasing. Unlike lagging indicators that tell you what happened, KRIs are leading indicators that help you anticipate problems before they materialize.

Effective KRIs enable proactive risk management by triggering attention and action when metrics breach defined thresholds. This transforms risk management from reactive firefighting to predictive prevention.

Quantitative

KRIs are numbers, not subjective assessments. They can be measured consistently.

Leading

KRIs predict future problems, not just report past events.

Actionable

Threshold breaches trigger specific response actions.

KRIs vs KPIs#

While Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) are related, they serve different purposes:

AspectKPIsKRIs
PurposeMeasure performance and successMeasure risk exposure and early warnings
FocusValue creation and achievementValue protection and risk prevention
DirectionHigher is usually betterDepends on the metric (could be either)
TriggerCelebrate success or investigate underperformanceTrigger risk response and escalation
ExampleRevenue growth rate: 15%Customer concentration: Top customer = 35% of revenue

Creating a KRI#

To add a Key Risk Indicator to a risk in Risk Radar:

1

Open the risk

Navigate to the risk you want to monitor and open its detail view.
2

Go to the KRI tab

Click on the "Key Risk Indicators" tab to view existing KRIs or add new ones.
3

Click "Add KRI"

Click the "Add KRI" button to open the KRI configuration form.
4

Define the metric

Provide a name, description, unit of measure, and measurement frequency.
5

Set thresholds

Define green/yellow/red thresholds that determine when alerts are triggered.
6

Configure data source

Choose whether to enter data manually or connect an automated data feed.
7

Save and start tracking

Save the KRI. It will now appear on the risk dashboard and in trend charts.

KRI Configuration#

Each KRI includes the following configuration options:

FieldDescriptionExample
NameShort, descriptive name for the KRICustomer Concentration
DescriptionWhat the KRI measures and why it mattersRevenue percentage from largest customer
UnitUnit of measurementPercentage, Days, Count, Currency
FrequencyHow often the metric is measuredDaily, Weekly, Monthly, Quarterly
DirectionWhether higher values increase or decrease riskHigher is riskier / Lower is riskier
Green ThresholdValue indicating acceptable risk levelLess than 20%
Yellow ThresholdValue indicating elevated risk (warning)Between 20% and 30%
Red ThresholdValue indicating critical risk levelGreater than 30%
OwnerPerson responsible for monitoring this KRICFO
Data SourceWhere the metric data comes fromManual entry, API, Integration

Thresholds#

Thresholds define the boundaries between acceptable and unacceptable risk levels. Well-defined thresholds are critical for effective KRI monitoring.

Green Zone

Normal operating range. No action required beyond routine monitoring.

Yellow Zone

Warning level. Increased attention and potential preparation for action.

Red Zone

Critical level. Immediate action and escalation required.

Thresholds can be set as:

Threshold TypeDescriptionExample
AbsoluteFixed numeric valuesRed if > 100 failed logins
PercentageRelative to a baselineRed if > 20% above baseline
Trend-basedRate of change over timeRed if increasing > 10% per week
RangeUpper and lower boundsRed if < 30 days or > 400 days

Data Sources#

KRI values can be populated through several methods:

Manual Entry

Enter values directly through the Risk Radar interface. Best for metrics collected through other processes.

Automated Integration

Connect to data sources via API or integration. Values update automatically on schedule.

Calculated Metrics

Compute KRIs from other data points using formulas and aggregations.

Report Import

Import KRI values from spreadsheets or exported reports on a scheduled basis.

Beyond current values, analyzing KRI trends over time provides deeper insight into risk trajectory and the effectiveness of mitigation efforts.

Trending Up

For 'higher is riskier' KRIs, an upward trend may indicate deteriorating conditions even if still in green zone.

Trending Down

A downward trend may indicate improving conditions or effective mitigation, warranting positive recognition.

Historical Charts

View KRI history over time with configurable date ranges and comparisons to thresholds.

Volatility Analysis

Identify KRIs with high variability that may need more frequent monitoring or refined thresholds.

Trend analysis is available in the KRI detail view and on the Risk Radar dashboard. Use the date range selector to examine specific time periods.

KRI Examples#

Here are examples of effective KRIs organized by risk category:

Financial Risk KRIs#

KRIDescriptionThresholds
Days Sales OutstandingAverage days to collect receivablesGreen: <30 | Yellow: 30-45 | Red: >45
Cash RunwayMonths of operating expenses in cashGreen: >12 | Yellow: 6-12 | Red: <6
Customer ConcentrationRevenue % from top customerGreen: <15% | Yellow: 15-25% | Red: >25%
Debt-to-Equity RatioTotal debt relative to equityGreen: <1.0 | Yellow: 1.0-1.5 | Red: >1.5

Operational Risk KRIs#

KRIDescriptionThresholds
System UptimePercentage of scheduled availabilityGreen: >99.9% | Yellow: 99-99.9% | Red: <99%
Supplier DependencyCritical suppliers with single-sourceGreen: 0 | Yellow: 1-2 | Red: >2
Process Error RateErrors per 1,000 transactionsGreen: <1 | Yellow: 1-5 | Red: >5
Backlog AgeOldest item in processing queueGreen: <7 days | Yellow: 7-14 days | Red: >14 days

Cybersecurity Risk KRIs#

KRIDescriptionThresholds
Failed Login AttemptsFailed logins per dayGreen: <50 | Yellow: 50-100 | Red: >100
Patch ComplianceSystems with current patchesGreen: >95% | Yellow: 90-95% | Red: <90%
Mean Time to PatchDays from patch release to deploymentGreen: <7 | Yellow: 7-30 | Red: >30
Phishing Click RateUsers clicking simulated phishingGreen: <5% | Yellow: 5-15% | Red: >15%

Compliance Risk KRIs#

KRIDescriptionThresholds
Training CompletionEmployees with current compliance trainingGreen: >95% | Yellow: 90-95% | Red: <90%
Policy AcknowledgmentEmployees who acknowledged policiesGreen: 100% | Yellow: 95-100% | Red: <95%
Days Since AuditDays since last compliance auditGreen: <365 | Yellow: 365-400 | Red: >400
Open Audit FindingsUnresolved findings from auditsGreen: 0 | Yellow: 1-3 | Red: >3

Best Practices#

Follow these best practices to maximize the effectiveness of your KRIs: