Key risk indicator, a measure that moves before the loss does
A key risk indicator is a metric chosen because it moves before a loss does, giving warning that exposure is increasing while there is still time to act. In third-party risk, useful KRIs track the programme and the portfolio — overdue reassessments, unremediated critical findings, vendors without exit plans — rather than counting activity. Also called KRI.
KRI, KPI and the difference that matters
A KPI tells you how well something performed. A KRI tells you that something is becoming more likely to go wrong. "Assessments completed this quarter" is a KPI — it measures throughput and can be improved by lowering the bar. "Critical vendors whose reassessment is more than 30 days overdue" is a KRI, because the number rising is itself the warning.
The test is whether the metric could change before the bad outcome. Counting breaches is not a KRI; it is a record of outcomes. Counting critical vendors with unremediated high-severity findings past their SLA is, because it describes the condition that precedes one.
Third-party risk KRIs worth reporting
A short set beats a dashboard. Coverage: critical vendors with a current assessment, as a percentage. Timeliness: overdue reassessments, and remediation actions past SLA. Exposure: vendors with a material adverse change since last review; critical vendors without a tested exit plan. Structure: concentration in a single provider or region, and vendors with no named business owner.
Each needs a threshold agreed in advance and an owner who acts when it is breached. An indicator with no threshold is a number on a slide, and a threshold with no owner is a number that gets explained rather than fixed.
Common questions
What is the difference between a KRI and a KPI?
How many KRIs should a third-party risk programme report?
What makes a good third-party risk KRI?
Related terms and pages
Definitions are the easy part. Evidence is not.
See what your vendors actually expose — scored, monitored and evidenced in one place.