Back to Articles and Learning
Risk Management9 min read

What Is a Key Risk Indicator? KRIs, Thresholds and Reporting Explained

Elliot Poublan
Sep 21, 2026
What Is a Key Risk Indicator? KRIs, Thresholds and Reporting Explained

Page 14 of the board pack is a table of twenty numbers headed "Key Risk Indicators". Complaints volume, staff turnover, system availability, aged debtors, open audit actions. Every number has a colour, most of them green, and nobody asks a question about the page because nobody knows what question to ask. Then a payments run fails, a batch of customer refunds goes out late, and the first anyone hears of it is a complaint.

A key risk indicator is a measure that moves before the risk does. Page 14 never did: it reported what had already happened last quarter, not what was about to happen. If yours only move afterwards, you have a performance report with a different heading.

In short

A key risk indicator (KRI) is a measurable signal that tells you a specific risk is becoming more or less likely, or more or less severe, before it crystallises into a loss, a breach or a complaint.

  • Tied to one risk - an indicator that floats free of the register is just a number.
  • Leading, not lagging - it moves ahead of the outcome you care about.
  • Thresholds from appetite - appetite, tolerance and trigger, each traceable to the statement.
  • An owner who acts - if nobody responds when it turns amber, take it off the page.

What a Key Risk Indicator Actually Is

A KRI is a leading measure of exposure to a named risk. Three words in that sentence do the work.

  • Leading. The measure moves ahead of the outcome you care about. Days since the last disaster recovery test is leading; number of outages is lagging.
  • Exposure. It measures how exposed you are, not how well the business is performing. Sales volume is not a KRI. The proportion of sales made by staff who have not completed conduct training is.
  • Named. It belongs to one risk on your risk register, not to a general sense of unease.

In practice you will also carry some lagging indicators, because a rising count of near misses is still useful information. The point is to know which is which, and to stop presenting a page of lagging measures as if it gave the board any warning.

KRIs, KPIs and KCIs: The Difference That Matters

These three get mixed up constantly, and the confusion is why so many KRI pages read as a management information pack. The distinction is about what each one tells you.

Measure What it tells you Example Who acts on it
Key performance indicator (KPI) How well the business is doing against a target Policies written this month First-line management
Key risk indicator (KRI) How exposed you are to a specific risk, ahead of the event Proportion of policies bound without a completed suitability check Risk owner, second line
Key control indicator (KCI) Whether a specific control is operating as designed Percentage of quarterly control tests completed on time Control owner

The same underlying data can feed all three. Staff turnover is a KPI for HR, a KRI for key person and operational risk, and a KCI if your control is "trained staff perform the reconciliation". What changes is the threshold you set and the question you ask when it is crossed. The control side of that is covered in control testing 101.

How to Pick a KRI That Predicts Rather Than Reports

Start from the risk, not from the data you happen to have. Take one risk from your register and ask what would have to be true for it to be about to crystallise. Then ask what you could measure that would show those conditions building.

For a risk of client money being misallocated, the conditions are things like reconciliation breaks left open, staff performing reconciliations without sign-off, and manual adjustments to client balances. Each of those is measurable, and each moves before a misallocation is discovered.

Three tests help when you are choosing between candidates:

  • Does it move early enough to act on? A measure that only changes in the same week as the loss is a smoke alarm going off after the house has burned.
  • Can you get it monthly, or more often, without a project? A brilliant indicator that requires a quarterly manual extract will be stale by the time it is read.
  • Does someone own the response? If nobody can say what they would do when the number turns amber, it will be looked at and ignored.

Aim for two or three KRIs per principal risk, not ten. A long list dilutes attention and makes thresholds impossible to maintain.

Setting Thresholds That Mean Something

A KRI without a threshold is a chart. The threshold is where the indicator connects to your risk appetite statement, and the connection has to be explicit. Most firms need three levels for each indicator.

  • Appetite level - the range you are content to operate in. Inside it, nothing happens beyond routine monitoring.
  • Tolerance level - the point at which you are outside where you want to be but not yet at the limit of what you can bear. Crossing it should generate a documented response from the risk owner: what is happening, why, and what they are doing about it.
  • Trigger level - where the second line and, depending on your governance, the risk committee are informed as a matter of course. This is the point at which you would expect to see the item in the next committee pack with a named action.

Set the levels by working backwards from the appetite statement. If the statement says you have low appetite for client detriment from late refunds, then the indicator "refunds outstanding beyond ten working days" needs thresholds tight enough that a breach of the statement is preceded by a trigger, not announced by one. If you cannot connect a threshold back to a sentence in the appetite statement, either the threshold or the statement needs work.

Review thresholds at least annually and whenever the business changes shape. A threshold set when you had 4,000 customers is meaningless at 40,000.

Worked Example: A Payments Firm and Settlement Failures

A payments firm with around 60 staff carries "failure to settle customer transactions on time" as a principal operational risk. Its appetite statement says it has very low appetite for customer-facing settlement delay.

The first-line team proposes two indicators: number of failed settlements last month, and customer complaints about delayed payments. Both are lagging - by the time either moves, customers have already been affected.

Working with the risk team, they replace them with three leading measures:

  • Settlement batches completed after cut-off - appetite under 2%, tolerance 2-5%, trigger above 5%.
  • Open incidents on the settlement platform older than five days - appetite zero, tolerance one, trigger two or more.
  • Days since the last successful test of the settlement failover - appetite under 90, tolerance 90-120, trigger above 120.

Worked example

A KRI doing its job quietly

Two months later the late-batch figure creeps to 3%. It is inside tolerance, so the head of operations writes a two-line note: a new banking partner's cut-off is thirty minutes earlier than the old one, and the batch schedule has not caught up. The schedule is changed the following week. No customer is affected, nothing reaches the board, and the KRI has done its job precisely because nobody outside operations needed to hear about it.

Common Pitfall: The Dashboard Nobody Reads

The most common failure is not a bad indicator. It is a page of twenty indicators, all sourced from whatever the finance and HR systems already produce, presented monthly with a colour and no commentary.

The board glances at the colours, sees mostly green, and moves on. When something goes wrong, the page is quietly blamed for not predicting it, and the response is to add more indicators. The page gets longer and less read.

The fix is subtraction. Cut to the indicators that have a named risk, a threshold linked to appetite, and an owner who has actually responded to a threshold breach in the last year. If an indicator has never turned amber, ask whether its thresholds are set too loosely to ever matter. If it has turned amber and nobody did anything, ask why it is on the page at all.

Then change how the page is presented. Lead with movement, not levels: which indicators changed band this period, and what the owner says about each. A board can engage with three indicators that moved and a sentence on each. It cannot engage with twenty static colours.

How Often to Report, and to Whom

Indicators should be collected at the cadence at which they can change materially, which for most operational risks is monthly and for some conduct and financial risks weekly. Reporting cadence can be slower than collection cadence, as long as trigger breaches escalate immediately rather than waiting for the next pack.

  • First line sees everything, every period, because they own the response.
  • Second line sees everything too, with the job of challenging whether thresholds are still right and whether responses were adequate.
  • Risk committee and board see exceptions and trends: what crossed tolerance, what crossed trigger, what has been drifting for three periods, and what has been done about it.

If the board pack shows every indicator every quarter, it is a data dump rather than a report. What boards should be getting instead is set out in board-ready risk reporting.

How Initia Risk Handles This

Initia Risk attaches key risk indicators directly to risks in the register, so an indicator cannot exist without a named risk and a named owner. Each indicator carries its appetite, tolerance and trigger thresholds, and those thresholds are shown alongside the risk appetite statement the risk sits under, which makes the connection between the number and the statement visible rather than assumed.

Showing the bands rather than a bare number means the reading interprets itself. An upheld complaint rate of 11% means nothing on its own; sitting just over a 10% tolerance line, it is a prompt for the risk owner to explain what changed and what they are doing about it, well before the trigger level brings the risk committee into it.

When a reading crosses tolerance, the risk owner is prompted for a response in the platform, and that response sits with the indicator's history so the second line can see what was said and when. Trigger breaches surface in the committee reporting view automatically, with the owner's commentary attached, so the pack leads with what moved rather than with a wall of colour.

Because control tests, incidents and indicators live in the same place, an indicator can also be read against the controls it relates to. A rising indicator next to a control test that failed last quarter tells a clearer story than either would on its own. Book a conversation if you want to see that in practice.

Key Takeaways

  • A KRI is a leading measure of exposure to one named risk. If it only moves after the event, it is a performance measure with a different heading.
  • Keep KRIs, KPIs and KCIs distinct. The same data can feed all three; the threshold and the question asked are what differ.
  • Choose indicators by starting from the risk - ask what conditions would build before it crystallised, then test for timeliness, availability and ownership.
  • Set three levels: appetite, tolerance and trigger, each connected back to a sentence in the risk appetite statement.
  • Two or three indicators per principal risk is enough. Twenty on a page is a dashboard nobody reads.
  • Report movement, not levels. The board should see what changed band and what the owner did, not every indicator every quarter.
  • Review thresholds annually and whenever the business changes shape.

Related reading: how to build a risk appetite statement, what is a risk rating, board-ready risk reporting, and the KRI entry in the GRC glossary for the one-line definition.

Frequently asked questions

What is a key risk indicator in simple terms?
A key risk indicator is a number you watch because it goes up or down before a particular risk turns into a real problem. It gives you time to act. A count of complaints received is not a KRI because it moves after the customer has already been let down; a count of refunds overdue is, because it moves before the complaint arrives.
What is the difference between a KRI and a KPI?
A KPI measures how well the business is performing against a target. A KRI measures how exposed the business is to a specific risk, ahead of the event. The same data can be either depending on the question you ask of it and the threshold you set.
How many key risk indicators should a firm have?
Two or three per principal risk is a workable number for most small and mid-sized regulated firms. More than that and thresholds stop being maintained and the report stops being read. Fewer, well-owned indicators beat a long list every time.
How do you set a threshold for a key risk indicator?
Work backwards from the risk appetite statement. Decide the range you are content to operate in (appetite), the point at which the owner must document a response (tolerance), and the point at which the second line and committee are informed (trigger). If a threshold cannot be traced back to a sentence in the appetite statement, revisit one or the other.
Who owns a key risk indicator?
The owner of the underlying risk, usually a first-line manager, owns the indicator and the response when a threshold is crossed. The second line owns the challenge: whether the thresholds are still right and whether the response was adequate.
What is the difference between a KRI and a KCI?
A key risk indicator tells you how exposed you are to a named risk. A key control indicator tells you whether a specific control is operating as designed - for example the percentage of quarterly control tests completed on time. The same underlying data can feed both; what changes is the threshold and the question you ask when it is crossed.

See Initia in action

Book a demo.

An exploratory call to discuss what works and what doesn't, what's still done on Excel, and what you're looking for in a tool.

By submitting, you agree to allow Initia Risk to store and process your personal data.

Initia Risk
As a professional risk manager with over 16 years' experience, I have seen many systems over the years. Initia Risk is without doubt one of the most user-friendly and intuitive platforms I have encountered.
Elaine Atkinson · Risk Manager