Skip to content

Glossary · Foundations

KRI (Key Risk Indicator)

A metric used to monitor whether an identified risk is changing or approaching the organization's risk-tolerance threshold.

What a KRI shows

A Key Risk Indicator is a measurable signal that exposure to a defined risk is changing or approaching an agreed tolerance. A useful KRI is tied to a specific risk scenario and one of its drivers, such as increasing likelihood, more severe consequences, a new source of exposure, or weakening controls. Its trend or threshold should give a decision-maker time to act.

Criteria for a useful KRI

  • Define the calculation, scope, data source, measurement frequency, and owner.
  • Set warning and escalation thresholds from the organization's risk tolerance rather than from an arbitrary round number.
  • Specify the action and accountable role for each threshold breach.
  • Review whether the indicator still reflects the risk as systems, threats, and objectives change.

A practical example

For the risk that ransomware causes an extended outage, the percentage of critical services without a recent successful restore test can be a KRI. A rising value signals that the recovery control may be weakening. Crossing an agreed warning threshold could trigger an investigation; crossing the tolerance limit could require escalation and an immediate recovery exercise. The organization chooses the actual thresholds from its recovery needs and capacity.

KRI versus KPI

A Key Performance Indicator asks whether a process or control is meeting its performance objective; a KRI asks what that performance means for risk exposure. Patch completion within target can be a KPI, while the number of internet-facing critical vulnerabilities overdue beyond tolerance can be a KRI. The same underlying data may support both, but the purpose, threshold, and management response are different.

Terms matter when they become defensible work.