Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

GLOSSARY · Risk

Key Risk Indicator (KRI)

A Key Risk Indicator (KRI) is a measurable quantity that signals a change in the likelihood or impact of a given risk before the risk materializes, read against a threshold derived from the organization’s risk appetite. Where a KPI measures performance already achieved, a KRI is a leading signal: patching delay on critical systems, share of privileged accounts without MFA, number of suppliers with a degraded rating, open critical findings past their due date.

What separates a KRI from a metric

A metric becomes a KRI when three things are true: it is tied to a named risk in the register, it has a threshold that means something (amber, red) rather than a trend nobody interprets, and someone owns the response when the threshold is crossed. A dashboard with forty security metrics and no thresholds is reporting; six KRIs with thresholds and owners are governance. The number of indicators matters less than the fact that each one changes a decision.

Examples that hold up

Median time to patch critical vulnerabilities on internet-facing assets, against a threshold in days. Percentage of critical suppliers without a valid assessment. Number of security exceptions past their expiry. Share of controls whose evidence is older than its cadence. Incidents open beyond the reporting deadline of the applicable regulation. Each is computable from data the organization already holds, which is the difference between a KRI that is measured monthly and one that is estimated in a meeting.

From the KRI to the board

The board does not read forty indicators either. The board pack carries the handful of KRIs tied to the top risks, each with its threshold, its trend and the decision pending when it breached. Presented that way, the indicator is not a technical curiosity but the answer to the question directors are now asked under NIS2 and DORA: did you know the risk was moving, and what did you decide?

ON MINDLAPSE

Where this term lives in the platform.

The pages that put the definition to work.

SEE IT VERIFIED

Definitions are the easy part. Proving them is the product.

Thirty minutes on your scope: risk, compliance, third parties, and how each term above becomes a verified control.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.