A key control indicator measures whether a specific control is operating as designed. Where a KRI signals that exposure is changing and a KPI signals how a programme is performing, a KCI answers a narrower question: is this particular safeguard working?
A control exists to reduce a risk. The KCI measures the control. The KRI measures the exposure the control was meant to reduce. The KPI measures how well the function delivering both is performing.
Take backup and recovery. Share of critical systems with a successful backup in the last 24 hours is a KCI. Share of critical systems with a verified restore in the last 90 days is also a KCI, and a better one. Estimated recovery time for the tier-one estate is closer to a KRI. Whether the recovery programme is hitting its agreed protection level is the KPI.
The distinction gets muddled constantly, and mostly it does not matter as long as the population and threshold are clear. Where it does matter is ownership. Control owners own KCIs. Risk owners own KRIs. Confusing them means nobody is accountable for the gap between a control that passes its test and a risk that keeps rising.
A good KCI measures operation, not existence. “Backup jobs configured” is existence. “Backup jobs completed successfully” is operation. “Restores tested successfully” is closer to effect.
It covers the full population, not a sample.
It has a failure threshold agreed in advance with the control owner.
It is reported at a frequency that matches how fast the control can fail. A control that can break silently on any given night should not be measured quarterly.
A high pass rate across a control set is comfortable and can be almost meaningless. If the controls in scope were selected because they were easy to test automatically, the set describes what is measurable rather than what is protective. Coverage of the control framework matters more than the pass rate within it.
From the blog