Page 14 of the board pack is a table of twenty numbers headed "Key Risk Indicators". Complaints volume, staff turnover, system availability, aged debtors, open audit actions. Every number has a colour, most of them green, and nobody asks a question about the page because nobody knows what question to ask. Then a payments run fails, a batch of customer refunds goes out late, and the first anyone hears of it is a complaint.
A key risk indicator is a measure that moves before the risk does. Page 14 never did: it reported what had already happened last quarter, not what was about to happen. If yours only move afterwards, you have a performance report with a different heading.
In short
A key risk indicator (KRI) is a measurable signal that tells you a specific risk is becoming more or less likely, or more or less severe, before it crystallises into a loss, a breach or a complaint.
- Tied to one risk - an indicator that floats free of the register is just a number.
- Leading, not lagging - it moves ahead of the outcome you care about.
- Thresholds from appetite - appetite, tolerance and trigger, each traceable to the statement.
- An owner who acts - if nobody responds when it turns amber, take it off the page.
What a Key Risk Indicator Actually Is
A KRI is a leading measure of exposure to a named risk. Three words in that sentence do the work.
- Leading. The measure moves ahead of the outcome you care about. Days since the last disaster recovery test is leading; number of outages is lagging.
- Exposure. It measures how exposed you are, not how well the business is performing. Sales volume is not a KRI. The proportion of sales made by staff who have not completed conduct training is.
- Named. It belongs to one risk on your risk register, not to a general sense of unease.
In practice you will also carry some lagging indicators, because a rising count of near misses is still useful information. The point is to know which is which, and to stop presenting a page of lagging measures as if it gave the board any warning.
KRIs, KPIs and KCIs: The Difference That Matters
These three get mixed up constantly, and the confusion is why so many KRI pages read as a management information pack. The distinction is about what each one tells you.
| Measure | What it tells you | Example | Who acts on it |
|---|---|---|---|
| Key performance indicator (KPI) | How well the business is doing against a target | Policies written this month | First-line management |
| Key risk indicator (KRI) | How exposed you are to a specific risk, ahead of the event | Proportion of policies bound without a completed suitability check | Risk owner, second line |
| Key control indicator (KCI) | Whether a specific control is operating as designed | Percentage of quarterly control tests completed on time | Control owner |
The same underlying data can feed all three. Staff turnover is a KPI for HR, a KRI for key person and operational risk, and a KCI if your control is "trained staff perform the reconciliation". What changes is the threshold you set and the question you ask when it is crossed. The control side of that is covered in control testing 101.
How to Pick a KRI That Predicts Rather Than Reports
Start from the risk, not from the data you happen to have. Take one risk from your register and ask what would have to be true for it to be about to crystallise. Then ask what you could measure that would show those conditions building.
For a risk of client money being misallocated, the conditions are things like reconciliation breaks left open, staff performing reconciliations without sign-off, and manual adjustments to client balances. Each of those is measurable, and each moves before a misallocation is discovered.
Three tests help when you are choosing between candidates:
- Does it move early enough to act on? A measure that only changes in the same week as the loss is a smoke alarm going off after the house has burned.
- Can you get it monthly, or more often, without a project? A brilliant indicator that requires a quarterly manual extract will be stale by the time it is read.
- Does someone own the response? If nobody can say what they would do when the number turns amber, it will be looked at and ignored.
Aim for two or three KRIs per principal risk, not ten. A long list dilutes attention and makes thresholds impossible to maintain.
Setting Thresholds That Mean Something
A KRI without a threshold is a chart. The threshold is where the indicator connects to your risk appetite statement, and the connection has to be explicit. Most firms need three levels for each indicator.
- Appetite level - the range you are content to operate in. Inside it, nothing happens beyond routine monitoring.
- Tolerance level - the point at which you are outside where you want to be but not yet at the limit of what you can bear. Crossing it should generate a documented response from the risk owner: what is happening, why, and what they are doing about it.
- Trigger level - where the second line and, depending on your governance, the risk committee are informed as a matter of course. This is the point at which you would expect to see the item in the next committee pack with a named action.
Set the levels by working backwards from the appetite statement. If the statement says you have low appetite for client detriment from late refunds, then the indicator "refunds outstanding beyond ten working days" needs thresholds tight enough that a breach of the statement is preceded by a trigger, not announced by one. If you cannot connect a threshold back to a sentence in the appetite statement, either the threshold or the statement needs work.
Review thresholds at least annually and whenever the business changes shape. A threshold set when you had 4,000 customers is meaningless at 40,000.

