, , ,

Key Risk Indicators: Example KRI Tables by Risk Type

A useful key risk indicator is five things, not one: the metric itself, its green/amber/red thresholds, the system it comes from, the owner who answers for it, and how often it refreshes. This page is a working reference library built exactly that way — five per-risk-type KRI tables (credit, liquidity, operational, cyber, and fraud) with illustrative thresholds you can calibrate to your institution, followed by a broad indicator list across sixteen risk categories. For behavioral and conduct indicators, see the companion guide to non-financial risk indicators.

The structure follows the discipline in COSO and the NC State ERM Initiative’s guidance, Developing Key Risk Indicators to Strengthen Enterprise Risk Management (2010): good KRIs are leading rather than lagging where possible, trace to a root cause, and connect to the organization’s risk appetite — which is precisely what a threshold column forces you to write down. An indicator with no threshold, no owner, or no refresh cadence is a dashboard decoration, not a control.

Credit Risk KRIs

IndicatorGreenAmberRedSource systemOwner · refresh
Nonperforming loans / total loans<1.5%1.5–3%>3%Loan servicing systemChief Credit Officer · monthly
Watchlist migration — net downgrades in quarter<2% of rated book2–5%>5%Credit MISHead of Credit Risk · quarterly
Top-20 borrower exposure / Tier 1 capital<80%80–120%>120%Credit data warehouseCRO · quarterly
Policy exceptions on new originations<5% of approvals5–10%>10%Loan origination systemCredit Administration · monthly
30–89 day past-due ratio (early delinquency)<1%1–2%>2%Loan servicing systemPortfolio Manager · monthly

Liquidity Risk KRIs

IndicatorGreenAmberRedSource systemOwner · refresh
Liquidity coverage ratio (LCR; regulatory floor 100%)>110%100–110%<100%Treasury / ALM systemTreasurer · daily
Top-10 depositor concentration<10% of deposits10–20%>20%Core bankingTreasury · monthly
Wholesale funding / total funding<15%15–25%>25%ALM systemTreasurer · monthly
Unencumbered HQLA vs. 30-day stress outflows>125%100–125%<100%Treasury systemALCO · weekly
Contingency funding capacity drawn0%<10%≥10%Treasury systemALCO · monthly

Operational Risk KRIs

IndicatorGreenAmberRedSource systemOwner · refresh
Unreconciled items aged >30 daysNone materialNon-material agingMaterial items agedReconciliation toolController · monthly
Critical system availability≥99.9%99.5–99.9%<99.5%ITSM / monitoringCIO · monthly
Operational losses vs. annual loss budget (YTD pace)<50%50–100%>100%Op-risk event systemHead of Operational Risk · monthly
Overdue high-risk audit issues01–2≥3Issue-tracking systemCAE · monthly
Turnover in critical-function staff (rolling 12 months)<10%10–20%>20%HRISCOO · quarterly

Cyber Risk KRIs

IndicatorGreenAmberRedSource systemOwner · refresh
Critical vulnerabilities open past 15-day SLA01–10>10Vulnerability scannerCISO · weekly
Phishing simulation failure rate<5%5–10%>10%Security awareness platformCISO · quarterly
Privileged accounts without MFA0Any, with dated remediation planAny, without planIAM systemCISO · monthly
End-of-life systems in production0Isolated, with compensating controlsAny internet-facingCMDBCIO · quarterly
Mean time to detect security incidents<24 hrs24–72 hrs>72 hrsSIEMSOC Manager · quarterly

Fraud Risk KRIs

IndicatorGreenAmberRedSource systemOwner · refresh
Confirmed fraud losses vs. loss appetite (YTD pace)<50%50–100%>100%Fraud case systemHead of Fraud · monthly
Fraud alerts unworked >5 days<2% of alerts2–5%>5%Transaction monitoringFraud Operations · weekly
Card / payment chargeback rate<0.5%0.5–0.9%>0.9%Payments platformPayments Risk · monthly
Code-of-conduct attestation completion100%95–99%<95%GRC / HR systemEthics Officer · annual
Whistleblower investigations open >60 days01–2≥3Case management systemGeneral Counsel / Ethics · quarterly

Two cautions before you lift these into a risk report. First, every threshold above is an illustrative starting point drawn from banking practice — calibrate to your institution’s size, complexity, and stated risk appetite, and document the rationale; the five-field pattern is the durable part, not the specific numbers. Second, for internal auditors the tables cut both ways: they are a scoping aid for your own risk assessment, and they are test criteria for management’s — when you audit an ERM or risk-reporting process, check whether each KRI in production has all five fields. Missing owners and missing thresholds are findings.

The Full Landscape: Indicators by Risk Category

For breadth beyond the five deep-dive tables, the reference list below spans sixteen risk categories with the indicators most commonly monitored in each — useful as a completeness check when building a risk universe or challenging whether a category has been left unmeasured.

Risk CategoryKey Risk Indicators
Financial RiskValue at Risk (VaR), interest rate risk, credit risk, liquidity risk, counterparty risk, capital adequacy ratios, market volatility risk, currency exchange risk, commodity price risk, capital market fluctuations
Cybersecurity RiskNumber of cyber incidents, data breaches, vulnerability assessments, adherence to security policies, patch management, network security effectiveness, access control effectiveness, security awareness training completion
Fraud RiskFraud losses, fraud attempts, code of conduct breaches, whistleblower complaints, anti-fraud controls effectiveness, vendor due diligence, segregation of duties effectiveness, fraud detection mechanisms
Regulatory ComplianceCompliance violations, regulatory fines, adherence to legal standards, regulatory reporting accuracy, regulatory change management, licensing and permits compliance, customer data privacy compliance, product labeling compliance
Operational RiskBusiness continuity planning, IT system downtime, process inefficiencies, employee turnover, supply chain disruptions, inventory management effectiveness, production capacity utilization, third-party vendor risk, operational error rates
Reputational RiskCustomer complaints, negative media coverage, social media sentiment, brand perception, stakeholder satisfaction, online reviews and ratings, public opinion surveys, brand loyalty and recognition
Environmental RiskCarbon emissions, waste management, environmental incidents, compliance with regulations, sustainability initiatives, environmental impact assessments, water and air pollution control measures, eco-friendly product development
Strategic RiskMarket share erosion, new market entry risks, technological disruptions, competitor analysis, mergers and acquisitions risks, innovation and R&D effectiveness, strategic partnership evaluations, market research and analysis
Market RiskVolatility of market indices, price risk, interest rate risk, foreign exchange risk, commodity price fluctuations, market liquidity, geopolitical risks, regulatory changes impacting markets, supply-demand imbalances
Technology RiskIT system disruptions, data breaches, IT infrastructure vulnerabilities, system availability, adoption of emerging technologies, IT project management effectiveness, IT governance and controls, technology obsolescence risks
Supply Chain RiskSupplier reliability, inventory management, supply chain disruptions, transportation risks, counterfeit products, supplier diversity and redundancy, demand forecasting accuracy, supply chain visibility, lean and agile practices
Operational EfficiencyProcess automation, employee productivity, cost control, time to market, performance measurement, quality control effectiveness, resource allocation optimization, business process standardization, lean and Six Sigma implementation
Legal and ComplianceNon-compliance with laws, litigation, regulatory examination findings, anti-money laundering compliance, whistleblower reports, intellectual property protection, contract management effectiveness, privacy and data protection compliance
Health and SafetyWorkplace accidents, occupational health hazards, safety training, work-related illnesses, compliance with safety regulations, ergonomics and workstation assessments, employee health and wellness programs, incident reporting and investigation
Reputation and BrandProduct recalls, customer satisfaction, social responsibility, online presence, brand value, corporate social responsibility initiatives, brand ambassador programs, social media influencer engagement
Business ContinuityDisaster recovery planning, emergency response preparedness, business interruption risks, crisis management, recovery time objectives, insurance coverage adequacy, alternative business site readiness, incident response testing and simulations

Comments

3 responses to “Key Risk Indicators: Example KRI Tables by Risk Type”

  1. […] These examples illustrate how KRIs can serve as effective communication tools, enabling internal auditors to convey critical information about cyber risks to stakeholders and foster a culture of security awareness throughout the organization [11][14][15].  […]

  2. […] Integration with Existing Systems: Ensure that AI tools can seamlessly integrate with existing audit management systems. This will facilitate smoother data flow and enhance the overall efficiency of the audit process [8].  […]

  3. […] Definition of Key Risk Indicators (KRIs) in the Context of Cyber Security Key Risk Indicators are metrics that provide early warning signs of potential risks that could adversely affect an organization. In the realm of cyber security, KRIs serve as quantifiable measures that help internal auditors monitor and evaluate the effectiveness of security controls and the overall health of the organization’s cyber defenses. They can include various metrics, such as the frequency of intrusion attempts, the number of vulnerabilities identified, and the effectiveness of incident response protocols [3][12].  […]

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading