TPRM glossary

Key risk indicator, a measure that moves before the loss does

A key risk indicator is a metric chosen because it moves before a loss does, giving warning that exposure is increasing while there is still time to act. In third-party risk, useful KRIs track the programme and the portfolio — overdue reassessments, unremediated critical findings, vendors without exit plans — rather than counting activity. Also called KRI.

KRI, KPI and the difference that matters

A KPI tells you how well something performed. A KRI tells you that something is becoming more likely to go wrong. "Assessments completed this quarter" is a KPI — it measures throughput and can be improved by lowering the bar. "Critical vendors whose reassessment is more than 30 days overdue" is a KRI, because the number rising is itself the warning.

The test is whether the metric could change before the bad outcome. Counting breaches is not a KRI; it is a record of outcomes. Counting critical vendors with unremediated high-severity findings past their SLA is, because it describes the condition that precedes one.

Third-party risk KRIs worth reporting

A short set beats a dashboard. Coverage: critical vendors with a current assessment, as a percentage. Timeliness: overdue reassessments, and remediation actions past SLA. Exposure: vendors with a material adverse change since last review; critical vendors without a tested exit plan. Structure: concentration in a single provider or region, and vendors with no named business owner.

Each needs a threshold agreed in advance and an owner who acts when it is breached. An indicator with no threshold is a number on a slide, and a threshold with no owner is a number that gets explained rather than fixed.

Common questions

What is the difference between a KRI and a KPI?
A KPI measures performance after the fact; a KRI is chosen because it moves before a loss and gives warning. The same underlying data can produce both: assessments completed is a performance measure, critical assessments overdue is a risk indicator.
How many KRIs should a third-party risk programme report?
Enough to cover coverage, timeliness, exposure and structure — typically six to ten. Beyond that, thresholds stop being agreed individually and the set becomes a dashboard nobody acts on. Each indicator needs a threshold and a named owner or it is decoration.
What makes a good third-party risk KRI?
It is leading rather than lagging, derived from data the programme already holds, has a threshold agreed in advance, and someone is accountable for acting when it is crossed. If a metric can only be improved by doing less work to a lower standard, it is measuring activity rather than risk.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.