A key risk indicator is a metric that signals a change in exposure to a risk before that risk materializes. KPIs tell you how a program is performing. KRIs tell you where it is about to hurt.
In most risk registers, each risk carries a description, an owner, likelihood and impact ratings, and the measures meant to reduce it. A KRI is the measurable signal bolted onto that entry.
If the risk is “ransomware disrupts operations”, candidate indicators include the share of critical servers without a tested restore, the age of the oldest unpatched internet-facing system, and the proportion of privileged accounts without step-up authentication.
One risk usually needs several indicators. One indicator can serve several risks.
A KRI without a threshold is decoration. Each indicator needs a normal band, a band that triggers review, and a band that triggers escalation to a named person.
Those bands get agreed with the risk owner in advance. Negotiating them after the number goes red is how a risk program loses its teeth.
GRC platforms model risks and indicators well. What most of them do not do is compute the indicator. The platform holds an empty field, and someone fills it in by hand each quarter from an export.
That manual step is where the damage happens. The number arrives late. The method for producing it lives in one analyst’s head. When that analyst leaves, or the source tool gets replaced, the history stops meaning the same thing it did last year.
Metric Maestro computes indicators from the underlying data instead of waiting for someone to type a number into a field. Sources can be security tools, spreadsheets, HR systems, ERP platforms, or manual entry with supporting evidence attached.
Every value carries its lineage, so a risk owner who opens a red indicator can trace it back to the records that produced it. The formula stays fixed when the source tool is swapped out, which means the history behind the indicator survives the change.
From the blog