A Key Risk Indicator (KRI) is a metric used to monitor the level of a particular risk and to give early warning when exposure is increasing. Good KRIs are measurable, tied to a specific risk, and equipped with thresholds that trigger attention or escalation when crossed — for example the number of overdue access reviews, the rate of failed control checks, or the count of unpatched critical vulnerabilities.
KRIs differ from Key Performance Indicators (KPIs): a KPI measures how well something is performing, while a KRI measures how much risk is building. Used together, they let a risk team see trouble forming rather than only reacting after an incident.
The value of a KRI lies in being leading rather than lagging. Tracking the right indicators turns risk management from periodic, point-in-time review into continuous monitoring, where thresholds and trends prompt action before a risk becomes a loss.
Comply automates this — see the risk platform page.