Your Risk Register Tells You What Could Go Wrong. KRIs Tell You When It’s Starting To.

September 23, 2026

Learn what Key Risk Indicators (KRIs) are, how they differ from KPIs, how to set meaningful thresholds and use them to monitor changing risk exposure.

A risk register can tell you that supplier failure is a significant risk. It can record the likelihood, impact, owner, controls and planned response.

But what tells you that the risk is starting to increase today?

Perhaps delivery delays are rising. Service-level agreements are being missed more frequently. More incidents are being reported. A critical supplier assessment is overdue. Or the number of unresolved issues has been climbing quietly for several months.

None of these necessarily means the risk has materialised.

They are signals that the conditions around the risk may be changing and that particular distinction matters.

Risk registers help organisations identify, assess and manage uncertainty. Key Risk Indicators (KRIs) add another important layer: they help organisations monitor the signals that may indicate their exposure is changing.

For organisations trying to move from periodic risk reviews towards more proactive risk management, that can make the difference between recording a risk and seeing it develop.

What Is a Key Risk Indicator (KRI)?

A Key Risk Indicator (KRI) is a measurable indicator used to monitor changes in risk exposure and provide warning that a risk may be increasing, approaching a defined threshold or becoming more likely to materialise.

According to ISACA, a Key Risk Indicator (KRI) is a subset of risk indicators considered highly relevant and likely to predict or indicate important risk. ISACA also distinguishes lead risk indicators as forward-looking measures that can provide early warning before a risk event occurs.

The Institute of Risk Management (IRM) similarly positions KRIs as early-warning tools that can improve risk awareness and help organisations anticipate changing risks. Crucially, IRM emphasises that KRIs should support decision-making rather than simply add more metrics to a dashboard.

In other words:

A risk tells you what could happen.

A KRI helps tell you whether the conditions surrounding that risk are changing.

 

Why a Risk Score Alone May Not Be Enough

Imagine an organisation assesses a critical supplier failure risk in January.

It determines:

Likelihood: 2
Impact: 5
Overall score: 10

Controls are documented, an owner is assigned and the risk is reviewed periodically.

By April, however:

  • supplier SLA breaches have increased;

  • response times are deteriorating;

  • several minor service interruptions have occurred;

  • a scheduled supplier assessment is overdue; and

  • unresolved corrective actions are accumulating.


The original risk still exists, the difference is that the environment around it has changed.

If the organisation relies predominantly on periodic risk scoring, these signals may remain distributed across supplier records, incident logs, assessments, emails and spreadsheets until somebody manually brings them together.

A KRI framework gives the organisation a structured way of monitoring relevant signals between formal risk reviews, however, this does not make the original risk assessment obsolete, it simply makes it more responsive.

 

KRI vs KPI: What Is the Difference?

Key Risk Indicators and Key Performance Indicators are related, but they answer different questions.

A KPI (Key Performance Indicator) measures performance against an objective.

A KRI (Key Risk Indicator) monitors signals associated with uncertainty or exposure that could affect the achievement of that objective.

Consider a customer-facing digital service.

Business objective:
Maintain a reliable service for customers.

KPI:
Service availability.

Risk:
Critical technology outage.

Possible KRIs:
Number of critical incidents, percentage of critical patches overdue, failed backups or infrastructure capacity approaching a defined threshold.

The KPI tells management how the organisation is performing.

The KRI provides information about conditions that could threaten that performance.

The distinction is important because an organisation can still be meeting its KPI while risk is building underneath it.

Today’s performance can look healthy while tomorrow’s problem is already developing.

 

Leading and Lagging Risk Indicators

Not every risk indicator provides the same kind of information.

Some indicators are leading: they can provide warning before an unwanted event occurs.

Others are lagging: they tell you something has already happened.

For a cyber risk, for example:

Possible leading indicators

  • percentage of critical security patches overdue;

  • number of privileged accounts awaiting review;

  • percentage of mandatory security training overdue;

  • critical vulnerabilities outside agreed remediation timescales.

Possible lagging indicators

  • number of security incidents;

  • confirmed data breaches;

  • hours of downtime caused by cyber events;

  • financial losses resulting from incidents.

 

Lagging indicators are not inherently unhelpful. They provide valuable evidence about what has actually happened and can reveal patterns that require attention.

But if every KRI only tells you about events after they occur, the organisation has limited early-warning capability.

A useful KRI framework therefore considers what information could provide management with enough warning to make a decision or intervene before exposure becomes unacceptable.

 

What Makes a Good KRI?

The objective should not be to monitor everything that can be measured. More indicators can actually make risk oversight harder if teams have to distinguish meaningful signals from background noise.

A useful KRI should generally be:

Relevant

There should be a credible relationship between the indicator and the risk being monitored.

If an indicator changes, risk owners should understand why that matters.

Measurable

The organisation needs a reliable way of collecting the underlying information.

That could come from assessments, questionnaires, operational systems, incident data, compliance monitoring or other internal and external sources.

Timely

Information needs to arrive early enough for somebody to respond.

A perfectly accurate indicator received six months after the decision it could have influenced has limited value as an early-warning mechanism.

Owned

Someone should be responsible for reviewing the indicator and understanding what happens when it moves outside expected parameters.

Threshold-based

There should be a defined point at which a change requires attention, escalation or action.

Without this, a dashboard can display information without telling anyone when it matters.

Actionable

Perhaps most importantly, ask:

What would we do differently if this indicator changed?

If nobody can answer that question, it may be an interesting metric rather than a useful KRI.

 

How KRIs Connect Risk Appetite to Day-to-Day Decisions

This is where KRIs become particularly useful.

Risk appetite expresses the amount and type of risk an organisation is willing to accept in pursuit of its objectives. Risk tolerances and thresholds can then make those boundaries more operational.

RIMS describes risk tolerance as specific predefined thresholds which, when exceeded, can trigger notification, assessment or corrective action. It describes KRIs as metrics used to quantify and monitor individual risks.

That creates an important relationship:

Business Objective → Risk → Risk Appetite → KRI → Threshold → Action

Consider third-party availability risk.

The organisation may accept occasional minor supplier disruption but have very little appetite for disruption affecting a critical customer service.

A relevant KRI could monitor the number of significant SLA breaches over a defined period.

Rather than waiting until a supplier fails completely, thresholds can help identify when performance is moving towards a level the organisation no longer considers acceptable.

The KRI therefore does more than add another number to a dashboard.

It helps translate risk appetite into something that can be monitored operationally.

How to Set KRI Thresholds

A common mistake is to begin with colours.

Green.

Amber.

Red.

Then work backwards to decide what the colours mean.

A stronger approach is to start with the risk.

Ask:

  • What change would indicate that our exposure is becoming uncomfortable?
  • At what point should the risk owner investigate?
  • At what point would management need to intervene?
  • What level would indicate that risk appetite or tolerance may have been exceeded?

From there, thresholds can be designed around meaningful decisions.

For example:

IndicatorGreenAmberRed
Critical supplier SLA breachesWithin expected levelIncreasing / approaching toleranceAbove agreed tolerance
Critical patches overdueWithin agreed timeframeRemediation deadline approachingOutside agreed remediation timeframe
Overdue compliance actionsNormal levelIncreasing backlogDefined escalation threshold exceeded
Failed recovery testsNo material issueWeakness requiring reviewCritical recovery capability failure

The actual thresholds will depend on the organisation, its objectives, risk appetite, operating environment and the quality of available data.

There is no universally correct red number.

The important thing is that the threshold has meaning in the context of the risk.

 

Examples of Key Risk Indicators

Different risks require different signals.

Cybersecurity risk

Possible KRIs could include:

  • critical vulnerabilities outside remediation timescales;

  • overdue access reviews;

  • phishing simulation failure rates;

  • privileged accounts without appropriate review;

  • high-severity security incidents.

Third-party risk

Possible KRIs could include:

  • supplier SLA breaches;

  • overdue supplier assessments;

  • unresolved supplier issues;

  • deterioration in financial indicators;

  • critical suppliers without current continuity evidence.

Operational risk

Possible KRIs could include:

  • critical incidents;

  • repeated process failures;

  • system downtime;

  • unresolved high-priority service issues;

  • increasing operational losses.

Compliance risk

Possible KRIs could include:

  • overdue compliance actions;

  • failed control assessments;

  • policy attestations outstanding;

  • regulatory reporting deadlines approaching;

  • repeated compliance exceptions.

Business continuity risk

Possible KRIs could include:

  • overdue continuity exercises;

  • failed recovery tests;

  • critical plans awaiting review;

  • recovery objectives not achieved during testing;

  • critical dependencies without current continuity arrangements.

People risk

Possible KRIs could include:

  • turnover in critical roles;

  • prolonged vacancies in key functions;

  • mandatory training completion;

  • absence trends;

  • dependency on individual employees for critical processes.

These are examples rather than universal KRIs. An indicator only becomes useful when it is relevant to a particular organisation, risk and decision.

 

Your KRI Turns Red. What Happens Next?

This is one of the most important questions in KRI design.

Because a red indicator is not risk management.

It is information.

Imagine a KRI monitoring critical incidents breaches its agreed threshold.

What should happen?

Potentially:

KRI threshold breached
↓
Risk owner notified
↓
Related risk reviewed
↓
Recent incidents examined
↓
Associated controls assessed
↓
Residual risk reconsidered
↓
Corrective action assigned
↓
Escalation where required
↓
Progress monitored

The precise workflow will depend on the organisation.

But the principle is important:

Monitoring creates value when information leads to appropriate decisions and action.

IRM makes a similar point in its guidance: KRIs need to be woven into normal operations and used for decision-making, rather than becoming a collection of visually impressive metrics.

 

The Problem With Monitoring KRIs in Isolation

An organisation may already collect plenty of risk information.

The challenge is often where that information lives.

The risk is in the risk register.

The KRI is in a spreadsheet.

Incidents are in another system.

Control assessments are stored elsewhere.

Actions are tracked through email.

Supplier assessments sit in another platform.

By the time the information reaches a risk committee, somebody has manually collected, reconciled and interpreted it.

This creates a bigger problem than administrative inconvenience.

It separates the signal from its context.

An increasing incident count means more when you can immediately see:

  • which risks those incidents relate to;

  • which controls are supposed to prevent them;

  • whether those controls have recently failed assessment;

  • whether residual exposure is increasing;

  • which business objectives could be affected; and

  • whether remediation actions are already underway.

The individual data points matter.

Their relationships can matter even more.

From Static Risk Registers to Continuous Risk Monitoring

Traditional risk registers are often reviewed periodically. That remains important. Risk owners need opportunities to reassess risks thoughtfully rather than reacting to every fluctuation in operational data.

But periodic assessment and continuous monitoring solve different problems.

Periodic reviews ask:

“What do we currently think about this risk?”

Continuous indicators ask:

“Has anything changed that should make us look again?”

Used together, they can create a more responsive risk-management process.

Instead of waiting for the next quarterly review to discover that conditions have deteriorated, relevant indicators can help direct attention towards the risks that warrant earlier investigation.

This also makes risk teams more efficient.

Not every risk requires constant manual reassessment.

The goal is to make it easier to identify which risks need attention now.

 

Connecting KRIs to Risks, Controls and Incidents

This is where connected GRC becomes particularly valuable.

Consider this sequence:

A KRI begins moving towards its threshold.

At the same time, several related incidents have been recorded.

A control assessment then identifies a weakness in one of the controls intended to mitigate the risk.

Viewed independently, these are three separate records.

Viewed together, they may tell a much more important story.

That is why Symbiant’s KRI functionality connects indicators directly with its wider risk-management environment.

Indicators can be linked to multiple risks, reducing duplicate data collection, while questionnaire responses can update connected risks. Organisations can define category-level KRI appetite, monitor historical responses and filter risks requiring attention.

Symbiant also connects risks with controls, incidents, assessments and actions, allowing risk teams to investigate the wider context rather than treating the indicator as an isolated warning.

The objective isn’t simply to produce more risk data. It is to make existing risk information more useful for decisions.

How Symbiant Supports Key Risk Indicator Monitoring

Symbiant’s KRI functionality is integrated with its Questionnaires, Surveys & Assessments and Risk Register capabilities.

Organisations can:

  • create indicator questions to collect KRI data;

  • link a single indicator to multiple relevant risks;

  • aggregate individual indicators into an overall KRI;

  • define risk-category KRI appetites;

  • monitor current and historical indicator responses;

  • filter risks based on KRI status;

  • connect indicators with the wider risk-management process; and

  • use dashboards to identify areas requiring attention.

Because KRIs sit within the wider Symbiant GRC environment, teams can move from an indicator to the risks, controls, incidents and other information needed to understand what that signal means.

This supports a more proactive approach to risk monitoring without turning risk management into a constant manual reporting exercise.

 

A Risk Register Tells You What Could Go Wrong. The Signals Tell You When to Look Again.

A strong risk register remains fundamental, but risks do not remain static simply because their next scheduled review is three months away.

Suppliers deteriorate.

Controls weaken.

Incidents accumulate.

External conditions change.

Operational pressures increase.

The question is whether those changes become visible early enough for somebody to respond.

Well-designed KRIs provide that early-warning layer.

And when those indicators are connected to the risks, controls, incidents, objectives and actions surrounding them, organisations gain something more useful than another dashboard.

They gain context for deciding where attention is needed next.

 

Turn Risk Signals Into Action

Symbiant’s connected risk-management platform brings Risk Registers, Key Risk Indicators, Controls, Incidents, Assessments and Actions together, helping organisations identify changes in exposure and understand them in context.

Discover Symbiant's risk register software for UK organisations with optional AI Assistant. Configure registers, automate reviews, link controls and actions, and improve risk reporting.