Glossary · Foundations
KRI (Key Risk Indicator)
A metric used to monitor whether an identified risk is changing or approaching the organization's risk-tolerance threshold.
What a KRI shows
A Key Risk Indicator is a measurable signal that exposure to a defined risk is changing or approaching an agreed tolerance. A useful KRI is tied to a specific risk scenario and one of its drivers, such as increasing likelihood, more severe consequences, a new source of exposure, or weakening controls. Its trend or threshold should give a decision-maker time to act.
Criteria for a useful KRI
- Define the calculation, scope, data source, measurement frequency, and owner.
- Set warning and escalation thresholds from the organization's risk tolerance rather than from an arbitrary round number.
- Specify the action and accountable role for each threshold breach.
- Review whether the indicator still reflects the risk as systems, threats, and objectives change.
A practical example
For the risk that ransomware causes an extended outage, the percentage of critical services without a recent successful restore test can be a KRI. A rising value signals that the recovery control may be weakening. Crossing an agreed warning threshold could trigger an investigation; crossing the tolerance limit could require escalation and an immediate recovery exercise. The organization chooses the actual thresholds from its recovery needs and capacity.
KRI versus KPI
A Key Performance Indicator asks whether a process or control is meeting its performance objective; a KRI asks what that performance means for risk exposure. Patch completion within target can be a KPI, while the number of internet-facing critical vulnerabilities overdue beyond tolerance can be a KRI. The same underlying data may support both, but the purpose, threshold, and management response are different.