Key risk indicator
A key risk indicator is a measure used in management to indicate how risky an activity is. Key risk indicators are metrics used by organizations to provide an early signal of increasing risk exposures in various areas of the enterprise. It differs from a key performance indicator in that the latter is meant as a measure of how well something is being done while the former is an indicator of the possibility of future adverse impact. KRI give an early warning to identify potential events that may harm continuity of the activity/project.
KRIs are a mainstay of operational risk analysis.
Definitions
According to OECDRisk management
Security risk management
According to Risk IT framework by ISACA, key risk indicators are metrics capable of showing that the organization is subject or has a high probability of being subject to a risk that exceeds the defined risk appetite.Organizations have different sizes and environment. So every enterprise should choose its own KRI, taking into account the following steps:
- Consider the different stakeholders of the organization
- Make a balanced selection of risk indicators, covering performance indicators, lead indicators and trends
- Ensure that the selected indicators drill down to the root cause of the events
- Choose high relevant and high probability of predicting important risks:
- * High business impact
- * Easy to measure
- * With high correlation with the risk
- * Sensitivity
- Determine thresholds and triggers for the set of KRI's
- Locate and fold in data sources that contribute or feed data into KRI triggers
- Determine notification methods, recipients, and action or response sequences
- Provide an early warning: a proactive action can take place
- Provide a backward looking view on risk events, so lesson can be learned by the past
- Provide an indication that the risk appetite and tolerance are reached
- Provide real time actionable intelligence to decision makers and risk managers
Qualities of good key risk indicators
Some qualities of a good key risk indicator include:- Ability to measure the right thing
- Quantifiable
- Capability to be measured precisely and accurately
- Ability to be validated against ground truth, and confidence level one has in the assertions made within the framework of the metric
- Comparability Over Time and Business Units
- Assessment of Risk Owners’ Performance