Key Risk Indicators
Live KPI/KRI dashboards derived from real assessment and evidence data — every indicator tied to a named risk, a threshold traceable to appetite, and the requirements it measures.
- UnitOne risk → several numeric indicators
- BandsGreen · Amber · Red · Not measured
- DirectionHigher-is-worse and lower-is-worse
- OwnershipThe function closest to the control
Key Risk Indicators
A key risk indicator is a number with a job: it is tied to one named risk, has a unit and a cadence, and its thresholds trace back to the organisation's appetite for that risk. A KPI tells you how the business is performing; a KRI tells you how close a risk is to materialising. Most programmes have plenty of the first and almost none of the second.
Two failures make KRI programmes quietly useless. The first is direction: an indicator like patch-SLA compliance or MFA coverage is worse when it falls, and an engine that only understands 'higher is worse' will show it green however far it drops. The second is silence: an indicator nobody has read for a quarter is not green, it is unknown — and a dashboard that renders the two the same makes the emptiest register look the healthiest.
GRCLens builds the engine around those two rules, and adds a third that turns indicators into findings: inside a maturity assessment, an indicator names the requirements it measures. When it sits outside appetite while every linked requirement was answered as met, that contradiction is surfaced — the finding a self-assessed score can never produce.
What the indicator engine does
Direction-aware bands
Each indicator declares whether up or down is worse. Restore-test pass rate, reserves cover and patch-SLA compliance alert when they fall, as they should.
Not measured is not green
An unread indicator renders as unmeasured, in its own state, never as 'within appetite'.
Thresholds from appetite
Amber sits roughly 70–80 % of the way to red, so the amber band is an early warning rather than a second red.
Leading and lagging, together
Phishing-report rate beside incident count; time-to-patch beside vulnerabilities exploited. A register asserted by tests to stay mixed.
Traceable to requirements
In maturity assessments every measured indicator names the catalogue items it measures, across all seven engines — SAMA, NCSB, PSR, MCSS, AESCSF, Essential Eight and OTCC.
Contradiction findings
Outside appetite while the linked requirements are marked met: the number and the questionnaire disagree, and the platform says so.
How it shows up in a tenant
Indicators live beside the risk they measure and beside the assessment they contradict.
Risk register
Each of the sample risks carries several worked indicators — 46 across 15 risks in the demo tenant — with trend, band and owner.
Maturity KRI tab
Derived indicators computed on read (not met, claimed-but-unevidenced, unanswered, stale) plus measured indicators linked to requirements.
Alerting
Band changes and stale readings notify the owning function, not a generic 'Risk' inbox.
Reports
Indicators outside appetite listed with their risk in the executive summary, in English and Arabic.
Frameworks where indicators do the most work
ISO/IEC 27001:2022 Information Security Management
Annex A controls, Statement of Applicability, risk treatment and evidence — managed in one place, ready for your certification body.
Open the framework page →NCA Essential Cybersecurity Controls
Assess, evidence and report against the Kingdom's Essential Cybersecurity Controls — in Arabic or English, hosted in your own environment.
Open the framework page →ISO 22301:2019 Business Continuity Management Systems
Assess and evidence your business continuity management system — from business impact analysis to exercising — against every ISO 22301 requirement.
Open the framework page →PCI DSS v4.0.1 Payment Card Industry Data Security Standard
Scope your cardholder data environment, work through SAQ or ROC, and evidence every PCI DSS v4.0.1 requirement.
Open the framework page →Key Risk Indicators
What is the difference between a KPI and a KRI in GRCLens?
A KPI measures performance of a process. A KRI is tied to one named risk, is numeric with a unit and cadence, and has thresholds traceable to risk appetite. GRCLens stores and evaluates KRIs; KPIs appear on dashboards but do not drive alerting.
Can an indicator alert when a value falls rather than rises?
Yes. Every indicator carries a direction. Lower-is-worse indicators such as MFA coverage or backup restore-test pass rate turn amber and red as they fall.
What happens when nobody records a reading?
The indicator is shown as not measured, distinct from green. A stale reading past its cadence is itself flagged, so an unattended register cannot look healthy.
Deep expertise across the disciplines that matter

See a register that cannot lie by omission
A walkthrough of the risk register, the maturity indicator tab and the contradiction findings, with your own risks if you bring them.