Key Risk Indicator (KRI)
A metric that provides an early warning signal about increasing risk exposure. KRIs are forward-looking measures that help organizations detect emerging threats before they materialize into incidents.
Why it matters
Risk assessments are periodic snapshots. KRIs provide continuous monitoring between assessments. A rising number of overdue patches, increasing failed login attempts, or growing vendor dependency are all signals that risk is trending upward. Without KRIs, organizations only learn about elevated risk after something goes wrong. With them, leadership can act on trends before they become incidents.
In practice
KRIs are selected based on your risk landscape: each significant risk category should have at least one measurable indicator with defined thresholds (green, amber, red). They are reviewed regularly and reported to leadership. In vucavoid, the VUCA scoring system functions as a comprehensive KRI framework. Each of the 24 score generators tracks a specific risk dimension, from overdue tasks to control effectiveness gaps, providing a real-time composite signal that traditional KRI dashboards require manual assembly to produce.