Skip to content

KRI Register

Where to find it: Risk Management, then KRI Register (/kris).

A Key Risk Indicator is a measure whose movement tells you a risk is changing before the risk materialises.


KRI versus control indicator

These are often confused. They measure different things for different audiences.

KRIControl Indicator
Attached toA riskA control
MeasuresRisk exposure or its driversControl operation
Question"Is this risk getting worse?""Is this control working?"
ThresholdsGreen, amber, red bandsPass or fail against a rule
AudienceRisk committee, boardControl owner, compliance
ReferenceKRI definitionIND-YYYY-NNNN

Both can measure the same underlying number. "Privileged accounts without MFA" is a control indicator when it asks whether the MFA control operates, and a KRI when it asks whether unauthorised-access exposure is rising.


What a KRI definition carries

FieldPurpose
Name and descriptionWhat is measured, and why it matters
Linked riskThe risk it indicates
Measurement unitCount, percentage, currency, duration
ThresholdsThe amber and red breach points
DirectionWhether higher or lower is worse
FrequencyHow often it is measured
OwnerWho is accountable for measuring it
StatusActive or retired

Measurements and breaches

A measurement records the value at a point in time. A breach occurs when a measurement crosses a threshold.

BandMeaning
GreenWithin tolerance
AmberApproaching the limit; attention warranted
RedBeyond the limit; action required

Breaches surface as risk signals on the linked risk, with the measured value, the threshold crossed and the timestamp.

A KRI breach does not change a risk rating

A breached KRI raises a signal recommending review. It does not rerate the risk, change its status or alter its treatment.

Whether a breach means the residual rating should move is a judgement about context — and the platform does not have the context.


Recording measurements

Measurements can be recorded manually or imported. Requires kri.measure.

Where the underlying number is already produced by a continuous indicator, record the KRI measurement from that result rather than measuring it twice — two sources for one number is two numbers that will eventually disagree.


Choosing good KRIs

Leading beats lagging. "Number of incidents last month" tells you what already happened. "Number of overdue critical patches" tells you what is about to.

Measurable without a project. A KRI requiring a manual data-gathering exercise each month will be measured for two quarters and then quietly stop.

Thresholds you would actually act on. If a red breach would not trigger a decision, the threshold is decoration.

Few. A risk with eleven KRIs has none — nobody reads eleven numbers about one risk.


Permissions

ActionPermission
View definitions, measurements and breacheskri.read
Create, edit and retire definitions and thresholdskri.manage
Record or import measurement valueskri.measure

All require the risk_management entitlement.


Example

Risk RSK-2026-0014 — Unauthorised privileged access.

KRIUnitAmberRedFrequency
Privileged accounts without MFACount15Daily
Privileged accounts inactive over 90 daysCount1025Weekly
Days since last privileged access recertificationDays100120Weekly
Emergency access grants in periodCount38Monthly

March measurements:

KRIValueBand
Accounts without MFA3Amber
Inactive accounts7Green
Days since recertification118Amber
Emergency grants1Green

Two amber breaches, and read together they tell a story the individual numbers do not: the recertification that would have caught the three MFA gaps is itself overdue.

The Risk Manager reviews the signals, leaves the residual rating at Medium given the accounts are on a decommissioning path, and raises a finding on the overdue recertification — which is the more consequential of the two breaches.


Troubleshooting

"A KRI shows no measurements." None have been recorded. KRIs do not measure themselves; the measurement is recorded manually or imported.

"A breach does not appear as a risk signal." Check the KRI is linked to the risk and that the definition is active.

"Thresholds seem to breach constantly." Either the threshold is set at a level the organisation routinely operates beyond, or the risk genuinely sits outside appetite. Both are worth resolving; neither is fixed by widening the threshold without a decision.

"KRI Register is not visible." Requires the risk_management entitlement and kri.read.


OrviQ Enterprise Governance, Risk & Compliance Platform