A useful key risk indicator is five things, not one: the metric itself, its green/amber/red thresholds, the system it comes from, the owner who answers for it, and how often it refreshes. This page is a working reference library built exactly that way — five per-risk-type KRI tables (credit, liquidity, operational, cyber, and fraud) with illustrative thresholds you can calibrate to your institution, followed by a broad indicator list across sixteen risk categories. For behavioral and conduct indicators, see the companion guide to non-financial risk indicators.
The structure follows the discipline in COSO and the NC State ERM Initiative’s guidance, Developing Key Risk Indicators to Strengthen Enterprise Risk Management (2010): good KRIs are leading rather than lagging where possible, trace to a root cause, and connect to the organization’s risk appetite — which is precisely what a threshold column forces you to write down. An indicator with no threshold, no owner, or no refresh cadence is a dashboard decoration, not a control.
Credit Risk KRIs
| Indicator | Green | Amber | Red | Source system | Owner · refresh |
|---|---|---|---|---|---|
| Nonperforming loans / total loans | <1.5% | 1.5–3% | >3% | Loan servicing system | Chief Credit Officer · monthly |
| Watchlist migration — net downgrades in quarter | <2% of rated book | 2–5% | >5% | Credit MIS | Head of Credit Risk · quarterly |
| Top-20 borrower exposure / Tier 1 capital | <80% | 80–120% | >120% | Credit data warehouse | CRO · quarterly |
| Policy exceptions on new originations | <5% of approvals | 5–10% | >10% | Loan origination system | Credit Administration · monthly |
| 30–89 day past-due ratio (early delinquency) | <1% | 1–2% | >2% | Loan servicing system | Portfolio Manager · monthly |
Liquidity Risk KRIs
| Indicator | Green | Amber | Red | Source system | Owner · refresh |
|---|---|---|---|---|---|
| Liquidity coverage ratio (LCR; regulatory floor 100%) | >110% | 100–110% | <100% | Treasury / ALM system | Treasurer · daily |
| Top-10 depositor concentration | <10% of deposits | 10–20% | >20% | Core banking | Treasury · monthly |
| Wholesale funding / total funding | <15% | 15–25% | >25% | ALM system | Treasurer · monthly |
| Unencumbered HQLA vs. 30-day stress outflows | >125% | 100–125% | <100% | Treasury system | ALCO · weekly |
| Contingency funding capacity drawn | 0% | <10% | ≥10% | Treasury system | ALCO · monthly |
Operational Risk KRIs
| Indicator | Green | Amber | Red | Source system | Owner · refresh |
|---|---|---|---|---|---|
| Unreconciled items aged >30 days | None material | Non-material aging | Material items aged | Reconciliation tool | Controller · monthly |
| Critical system availability | ≥99.9% | 99.5–99.9% | <99.5% | ITSM / monitoring | CIO · monthly |
| Operational losses vs. annual loss budget (YTD pace) | <50% | 50–100% | >100% | Op-risk event system | Head of Operational Risk · monthly |
| Overdue high-risk audit issues | 0 | 1–2 | ≥3 | Issue-tracking system | CAE · monthly |
| Turnover in critical-function staff (rolling 12 months) | <10% | 10–20% | >20% | HRIS | COO · quarterly |
Cyber Risk KRIs
| Indicator | Green | Amber | Red | Source system | Owner · refresh |
|---|---|---|---|---|---|
| Critical vulnerabilities open past 15-day SLA | 0 | 1–10 | >10 | Vulnerability scanner | CISO · weekly |
| Phishing simulation failure rate | <5% | 5–10% | >10% | Security awareness platform | CISO · quarterly |
| Privileged accounts without MFA | 0 | Any, with dated remediation plan | Any, without plan | IAM system | CISO · monthly |
| End-of-life systems in production | 0 | Isolated, with compensating controls | Any internet-facing | CMDB | CIO · quarterly |
| Mean time to detect security incidents | <24 hrs | 24–72 hrs | >72 hrs | SIEM | SOC Manager · quarterly |
Fraud Risk KRIs
| Indicator | Green | Amber | Red | Source system | Owner · refresh |
|---|---|---|---|---|---|
| Confirmed fraud losses vs. loss appetite (YTD pace) | <50% | 50–100% | >100% | Fraud case system | Head of Fraud · monthly |
| Fraud alerts unworked >5 days | <2% of alerts | 2–5% | >5% | Transaction monitoring | Fraud Operations · weekly |
| Card / payment chargeback rate | <0.5% | 0.5–0.9% | >0.9% | Payments platform | Payments Risk · monthly |
| Code-of-conduct attestation completion | 100% | 95–99% | <95% | GRC / HR system | Ethics Officer · annual |
| Whistleblower investigations open >60 days | 0 | 1–2 | ≥3 | Case management system | General Counsel / Ethics · quarterly |
Two cautions before you lift these into a risk report. First, every threshold above is an illustrative starting point drawn from banking practice — calibrate to your institution’s size, complexity, and stated risk appetite, and document the rationale; the five-field pattern is the durable part, not the specific numbers. Second, for internal auditors the tables cut both ways: they are a scoping aid for your own risk assessment, and they are test criteria for management’s — when you audit an ERM or risk-reporting process, check whether each KRI in production has all five fields. Missing owners and missing thresholds are findings.
The Full Landscape: Indicators by Risk Category
For breadth beyond the five deep-dive tables, the reference list below spans sixteen risk categories with the indicators most commonly monitored in each — useful as a completeness check when building a risk universe or challenging whether a category has been left unmeasured.
| Risk Category | Key Risk Indicators |
|---|---|
| Financial Risk | Value at Risk (VaR), interest rate risk, credit risk, liquidity risk, counterparty risk, capital adequacy ratios, market volatility risk, currency exchange risk, commodity price risk, capital market fluctuations |
| Cybersecurity Risk | Number of cyber incidents, data breaches, vulnerability assessments, adherence to security policies, patch management, network security effectiveness, access control effectiveness, security awareness training completion |
| Fraud Risk | Fraud losses, fraud attempts, code of conduct breaches, whistleblower complaints, anti-fraud controls effectiveness, vendor due diligence, segregation of duties effectiveness, fraud detection mechanisms |
| Regulatory Compliance | Compliance violations, regulatory fines, adherence to legal standards, regulatory reporting accuracy, regulatory change management, licensing and permits compliance, customer data privacy compliance, product labeling compliance |
| Operational Risk | Business continuity planning, IT system downtime, process inefficiencies, employee turnover, supply chain disruptions, inventory management effectiveness, production capacity utilization, third-party vendor risk, operational error rates |
| Reputational Risk | Customer complaints, negative media coverage, social media sentiment, brand perception, stakeholder satisfaction, online reviews and ratings, public opinion surveys, brand loyalty and recognition |
| Environmental Risk | Carbon emissions, waste management, environmental incidents, compliance with regulations, sustainability initiatives, environmental impact assessments, water and air pollution control measures, eco-friendly product development |
| Strategic Risk | Market share erosion, new market entry risks, technological disruptions, competitor analysis, mergers and acquisitions risks, innovation and R&D effectiveness, strategic partnership evaluations, market research and analysis |
| Market Risk | Volatility of market indices, price risk, interest rate risk, foreign exchange risk, commodity price fluctuations, market liquidity, geopolitical risks, regulatory changes impacting markets, supply-demand imbalances |
| Technology Risk | IT system disruptions, data breaches, IT infrastructure vulnerabilities, system availability, adoption of emerging technologies, IT project management effectiveness, IT governance and controls, technology obsolescence risks |
| Supply Chain Risk | Supplier reliability, inventory management, supply chain disruptions, transportation risks, counterfeit products, supplier diversity and redundancy, demand forecasting accuracy, supply chain visibility, lean and agile practices |
| Operational Efficiency | Process automation, employee productivity, cost control, time to market, performance measurement, quality control effectiveness, resource allocation optimization, business process standardization, lean and Six Sigma implementation |
| Legal and Compliance | Non-compliance with laws, litigation, regulatory examination findings, anti-money laundering compliance, whistleblower reports, intellectual property protection, contract management effectiveness, privacy and data protection compliance |
| Health and Safety | Workplace accidents, occupational health hazards, safety training, work-related illnesses, compliance with safety regulations, ergonomics and workstation assessments, employee health and wellness programs, incident reporting and investigation |
| Reputation and Brand | Product recalls, customer satisfaction, social responsibility, online presence, brand value, corporate social responsibility initiatives, brand ambassador programs, social media influencer engagement |
| Business Continuity | Disaster recovery planning, emergency response preparedness, business interruption risks, crisis management, recovery time objectives, insurance coverage adequacy, alternative business site readiness, incident response testing and simulations |
Leave a Reply