Key Risk Indicators (KRIs): Types, Examples, and How They Work

Key risk indicators (KRIs) are metrics that flag rising risk before it becomes a loss. Learn KRI types, examples by category, thresholds, and KRI vs KPI.
Published on
Saturday, August 15, 2026
Updated on
August 15, 2026

Key risk indicator (KRI) is a measurable metric that signals when an organization's risk exposure is rising toward or beyond the level it is prepared to accept. KRIs act as early warning signals, flagging a developing problem while there is still time to act rather than after a loss has occurred.

Their importance tracks the risk environment leaders now face. In the NC State University and Protiviti Executive Perspectives on Top Risks survey of 1,215 board members and C-suite executives worldwide, cyber threats and data breaches rank as the second highest near-term risk, and third-party and supply chain risk ranks seventh. KRIs are how organizations turn concerns like these into monitored metrics with defined thresholds and clear owners.

A simple example: for a retail business, a rising number of customer complaints can indicate a developing operational or quality problem. For a security team, a growing count of internet-facing assets can indicate an expanding external attack surface. In each case the metric reflects exposure, and a defined threshold marks the point where that exposure needs a response.

Why Key Risk Indicators Matter

Without early warning, organizations tend to discover risks only after they materialize as financial loss, regulatory action, or reputational damage. Forrester's The State of Enterprise Risk Management, 2025 found that nearly 75% of enterprises experienced at least one critical risk event in the past year, which shows how routinely exposure turns into impact.

KRIs narrow that gap in several ways:

  • Early warning. A KRI flags a developing risk before a threshold breach becomes a loss, leaving time for preventive action.
  • Monitoring between assessments. KRIs give continuous insight in the months between formal risk reviews, when conditions change.
  • Better decisions. Quantified, timely information helps management and the board prioritize attention and resources.
  • Accountability. Each KRI carries an owner who is responsible for monitoring it and acting when it breaches a threshold.

The shared purpose is time. The earlier a risk becomes visible, the cheaper and easier it is to contain.

KRIs vs KPIs vs KCIs

KRIs are frequently confused with key performance indicators (KPIs), and both are distinct from key control indicators (KCIs). The three measure different things and work well together.

Metric What It Measures Orientation Example
KRI (Key Risk Indicator) Exposure to a potential risk event Forward-looking, predictive Percentage of systems missing critical patches
KPI (Key Performance Indicator) Progress toward a business goal Performance, results to date Percentage of the revenue target achieved
KCI (Key Control Indicator) Effectiveness of a control Control assurance Percentage of access reviews completed on time

A KPI and a KRI are often complementary. Full patch coverage is a performance goal (KPI), while the share of systems left unpatched is the matching risk indicator (KRI). Defining one frequently surfaces the other.

Types of Key Risk Indicators

KRIs fall into two broad types based on when they signal risk relative to an event.

1. Leading indicators

Leading indicators are predictive. They change before a risk event occurs, giving time to intervene. Examples include a rising number of failed login attempts, growing dependence on a single supplier, or an increasing count of unpatched vulnerabilities. Leading indicators carry the highest preventive value, since they point to a risk that has not yet materialized.

2. Lagging indicators

Lagging indicators are measured after an event. They confirm that a risk materialized and help quantify its effect. Examples include the number of security incidents last quarter or the count of audit findings. Lagging indicators support trend analysis and validate whether controls and leading indicators are working.

Effective programs combine the two: leading indicators to anticipate risk, and lagging indicators to confirm patterns and calibrate thresholds.

Characteristics of Effective KRIs

A KRI delivers value only when it is well constructed. Effective KRIs share a consistent set of traits:

  • Measurable. The metric is quantifiable using reliable, repeatable data.
  • Relevant. It maps to a specific, material risk that affects a real objective.
  • Predictive. For leading KRIs, it changes early enough to allow a response.
  • Comparable over time. It can be tracked against a baseline to reveal trends.
  • Threshold-based. It has defined levels that separate acceptable exposure from unacceptable exposure.
  • Actionable. A breach triggers a defined response and reaches a named owner.

How to Develop Key Risk Indicators

Building a KRI program follows a clear sequence, from understanding the risks to monitoring the metrics that track them.

  1. Define objectives and identify risks. Clarify the objectives that matter, then articulate the financial, operational, compliance, and cyber risks that threaten them.
  2. Link each risk to its objective. Connect every risk to the objective it endangers, and rank risks by likelihood and impact.
  3. Define the metric. For each priority risk, decide what to measure and how it indicates rising exposure.
  4. Set thresholds. Establish the levels that mark acceptable, elevated, and unacceptable exposure for each KRI.
  5. Identify data sources. Determine where the data comes from, such as logs, incident reports, financial systems, or monitoring tools, and how it is collected.
  6. Assign ownership and measurement. Give each KRI an owner and put systems in place to measure it on a regular cadence.
  7. Monitor, report, and review. Track KRIs continuously, report them to stakeholders, and refine them as the business and the risk landscape change.

How to Set KRI Thresholds

A KRI becomes useful when it is paired with thresholds that define when a value is acceptable, when it warrants attention, and when it demands action. A common approach uses three bands:

kri thresholds
  • Green. Within risk appetite; routine monitoring continues.
  • Amber. Elevated exposure; investigate and watch the metric closely.
  • Red. Beyond tolerance; trigger escalation and a defined response.

Thresholds map to the organization's risk appetite and carry a defined escalation path, so a red reading reaches a named decision maker. For example, a KRI tracking unpatched critical vulnerabilities could set green below 5% of systems, amber between 5% and 10%, and red above 10%, with a red reading escalated to the security lead within 24 hours.

Key Risk Indicator Examples by Category

KRIs vary by industry and risk profile. The examples below show common KRIs by category with sample measurement points. Organizations calibrate the exact numbers to their own risk appetite.

Financial KRIs

  • Liquidity ratio falling below a set minimum level.
  • Days sales outstanding rising beyond an agreed number of days.
  • Customer concentration above a set percentage of revenue from a single client.

Operational KRIs

  • Employee turnover rising above a set percentage in a single quarter.
  • Production output falling a set percentage below demand.
  • System downtime exceeding an agreed number of hours per month.

Compliance and Regulatory KRIs

  • Overdue regulatory remediation items rising above a set count.
  • Number of policy exceptions granted per quarter.
  • Audit findings left unresolved past their due date.

Strategic KRIs

  • Market share declining across consecutive quarters.
  • Customer churn rate rising above target.
  • Milestones slipping on a major strategic initiative.

Cybersecurity Key Risk Indicators

Cybersecurity ranks among the top risks leaders track, which makes cyber KRIs a core part of most programs. Because a large share of the relevant exposure sits outside the network perimeter, several effective cyber KRIs measure external conditions.

cybersecurity key risk indicators

Size of the external attack surface

The count of internet-facing assets, unknown or shadow assets, and high-risk exposures. A sudden rise can indicate uncontrolled growth that widens the ground an attacker can target, which is why cyber asset attack surface management treats asset discovery as a continuous activity.

Unpatched and misconfigured systems

The share of systems is missing critical patches, along with weak encryption settings and misconfigurations. Poor patching cadence correlates with higher breach and ransomware likelihood, and ongoing external vulnerability scanning keeps this indicator current.

Leaked credentials and dark web exposure

The number of employee or customer credentials exposed in breach dumps or surfacing through dark web monitoring, plus mentions of the brand on criminal forums. Tracking leaked credentials turns a hidden exposure into a measurable signal of account-takeover risk.

Third-party and vendor risk

The number of vendors with critical vulnerabilities, changes in a vendor's security posture, and concentration on a small set of critical suppliers. These indicators give early warning of a supply chain attack reaching the organization through a trusted partner.

Detection and response times

Mean time to detect and mean time to respond. A rising mean time to detect signals, weakening monitoring, while improving detection accuracy, shortens the window an attacker operates in.

KRIs in Enterprise Risk Management

KRIs are a core component of an enterprise risk management (ERM) program. Within an ERM framework, identified risks are recorded in a risk register, assessed for likelihood and impact, and assigned KRIs that track how each risk trends over time.

KRIs feed risk dashboards and board reporting, connecting day-to-day metrics to the organization's risk appetite. Frameworks such as COSO ERM and ISO 31000 treat ongoing monitoring as a continuous requirement, and KRIs are the practical mechanism that makes that monitoring measurable.

Benefits of KRIs

  • Early warning. Developing risks surface before they become losses.
  • Continuous monitoring. KRIs maintain visibility between formal assessments, supported by continuous external monitoring of fast-moving exposures.
  • Better decisions. Quantified data informs how leaders prioritize risk and allocate resources.
  • Accountability. Defined thresholds and owners make response a clear responsibility.
  • Board-ready reporting. KRIs translate operational detail into risk language tied to appetite.

Best Practices for KRIs

  • Keep the set focused. A few decision-relevant KRIs deliver more than dozens of vanity metrics.
  • Pair every KRI with a threshold and an owner. A metric without a trigger and a responsible person rarely drives action.
  • Automate data collection. Automated feeds improve accuracy and keep indicators current.
  • Combine leading and lagging indicators. Anticipate risk and confirm trends in the same program.
  • Review regularly. Retire KRIs that no longer signal real risk, and add new ones as the risk landscape shifts.

Common pitfalls mirror these practices in reverse: tracking too many metrics, defining KRIs without thresholds, relying on stale data, and leaving indicators without a clear owner.

Frequently Asked Questions

What is a key risk indicator in simple terms?

A key risk indicator is a metric that gives an early warning that a specific risk is becoming more likely or more severe. It tracks exposure against a threshold, so a rising value signals the need to act before a loss occurs.

What is the difference between a KRI and a KPI?

A KRI measures exposure to a potential risk, while a KPI measures progress toward a goal. KRIs are forward-looking warnings, and KPIs report on performance. The two are complementary, and one often has a matching counterpart.

What is an example of a key risk indicator?

The percentage of systems missing critical security patches is a common KRI because a rising value signals growing breach exposure. Other examples include employee turnover rate, liquidity ratio, and the number of leaked credentials found on the dark web.

What is the difference between a leading and a lagging KRI?

A leading KRI signals risk before an event occurs, such as a rise in failed logins. A lagging KRI measures risk after the fact, such as the number of incidents last quarter. Leading indicators support prevention, and lagging ones confirm trends.

How many KRIs should an organization track?

There is no fixed number, but most organizations track a focused set tied to their top risks rather than dozens of metrics. A smaller group of well-chosen, threshold-based KRIs with clear owners proves more useful than broad coverage.

What is a KRI threshold?

A KRI threshold is the value that defines when a risk metric moves from acceptable to elevated or unacceptable. Many programs use green, amber, and red bands tied to risk appetite, with a red reading triggering escalation to a named owner.

Related Posts
Key Risk Indicators (KRIs): Types, Examples, and How They Work
Key risk indicators (KRIs) are metrics that flag rising risk before it becomes a loss. Learn KRI types, examples by category, thresholds, and KRI vs KPI.
What is Vendor Compliance? Types, Rules & How to Manage
Vendor compliance ensures third-party vendors meet an organization's regulatory, security, and contractual standards. Learn the types, requirements, and process.
What is Third-Party Data Breach? Causes, and Prevention
A third-party data breach exposes an organization's data through a compromised vendor. Learn how they happen, real examples, impact, and how to prevent them.

Start your demo now!

Schedule a Demo
Free 7-day trial
No Commitments
100% value guaranteed

Related Knowledge Base Articles

No items found.