Indicators & Events

What a key risk indicator is, and how to choose one

RiskOS keeps indicators beside the risks they watch, on macOS. One number, a cadence, and two lines that say when the picture has changed.

A register records what you believe about a risk. An indicator tells you whether the belief is still true. The distance between those two things is where risk work quietly goes stale, and a key risk indicator — a KRI — is the instrument that closes it: one number, measured on a fixed cadence, with lines drawn across it that say when the picture has moved far enough to act.

Note

An indicator with no readings reads as no data, which is deliberately not the same as being in tolerance. An empty indicator has never told you anything, and the list says so rather than showing a reassuring blank.

What a key risk indicator actually is

An indicator is a number you measure on a cadence — patch latency, failed logins, restore success rate — carrying a warning threshold, a breach threshold and, if you want one, a target. You also declare which direction is bad, because that is not something any register can guess: a rising count of outstanding patches is bad, a rising restore success rate is good, and the same arithmetic has to read both correctly.

The word that earns its place in the name is key. A measure is a key risk indicator when a change in it would change a decision. If the number can move by half and nobody would do anything differently, it is a statistic, and statistics belong in a report rather than in the register.

The other thing worth saying early is that indicators point forwards. A risk event records what already happened; an indicator is the thing that should have moved first. When a restore rehearsal starts failing, the register can show the exposure drifting weeks before anyone loses a file share. That head start is the whole return on the effort.

Where indicators live

Choose Indicators under Signals in the sidebar. The table sorts worst first, so the rows that need you are already at the top: Ref, Indicator with its direction, Latest, Status, Trend, Thresholds, Risks and Next Due. Search covers the list, and N creates a new indicator while you are in the section.

RiskOS also puts indicators where the decisions are made. Open any risk, and the Intelligence section of the panel lists the indicators linked to it with their live status alongside any linked events, so a rating is read next to the evidence for and against it rather than on its own.

Choose an indicator, step by step

  1. Start from a risk, not from the data you happen to have

    Open Risks and pick the risk you want early warning about. Ask what would have to be true for that risk to be getting worse, and look for the number that would show it first. Starting from available data produces indicators nobody can attach to anything, which is how registers end up with measures that are watched but never used.

  2. Name the decision the number should trigger

    Before choosing a measure, write the sentence out: when this number reaches a stated level, we will do a stated thing. If the second half of that sentence is hard to finish, the measure is not a key risk indicator yet. The sentence also tells you roughly where the thresholds belong, which saves an argument later.

  3. Choose a measure you can take the same way every time

    Pick something countable that someone can produce on a schedule without a project: a count, a percentage, a number of days. Consistency matters more than sophistication, because a reading is only meaningful next to the readings either side of it. A crude measure taken identically every month beats an elegant one taken differently each quarter.

  4. Create the indicator

    Choose Indicators in the sidebar and press N. Name it so the measure and its unit are both obvious from the list — Backup restore test success rate rather than Backups, Days to detect a security event rather than Detection. The table shows that name beside a number, and the pair has to be readable without opening anything.

  5. Set the direction that counts as bad

    Declare whether a rising value or a falling value is the bad one. Everything downstream depends on it: which side of a threshold counts as a breach, which way the trend arrow means trouble, and how the row is ordered when the list sorts worst first. Get this wrong and a healthy indicator will read as a crisis.

  6. Set the warning and breach thresholds

    Set two lines, not one. The warning is the level at which you want to look; the breach is the level at which you have agreed to act. Both are inclusive, so a value that lands exactly on a threshold counts as having reached it. Add a target if there is a level you are actively working towards.

  7. Link it to every risk whose exposure it speaks to — one indicator can reasonably watch several. The Risks column then shows the count, and each linked risk carries the indicator's live status in its own panel, so the connection is visible from both ends rather than living in somebody's head.

  8. Record the first reading

    Enter a value, the date it applies to and a short note on where it came from. That note is what makes the number auditable months later. The reading history chart then draws the threshold lines across it, so you can see at a glance whether a value is drifting towards a line or sitting comfortably clear of it.

  9. Give it a cadence, then keep it

    Set how often the indicator should be measured, and treat the date in Next Due as a commitment. An indicator that misses its cadence is marked overdue, because a stale number is worse than no number: it looks like evidence while describing a world that has moved on. If a measure has stopped being worth taking, pause it from the list rather than letting it rot.

What separates an indicator from a number you merely watch

Most organisations already report plenty of numbers. Very few of them survive the tests below, and that is the useful filter when you are deciding which handful to bring into the register.

Six tests that separate a key risk indicator from a general metric
TestA number you only watchA key risk indicator
PurposeReported because it is availableLinked to a named risk in the register
DirectionNobody has agreed which way is badThe bad direction is declared up front
ThresholdsJudged by eye when it looks wrongWarning and breach set before the reading
CadenceMeasured when someone remembersMeasured on a cadence; overdue when missed
ConsequenceNoted, then forgottenTriggers an action or a re-score
TimingConfirms what already happenedMoves before the risk does

The settings that decide what an indicator says

Four choices do nearly all the work. None of them is difficult, and all of them are easier to make before the first reading than after the tenth.

Direction: which way is bad

Some measures count problems, so higher is worse. Others count health, so lower is worse. RiskOS asks which it is and then reads every threshold and every trend arrow accordingly. A restore test success rate reading 72 % is breached because falling is the bad direction and the value has dropped past the line; a count of 14 critical patches outstanding beyond their service level is breached because rising is.

Warning and breach: two lines, not one

A single threshold gives you a binary, and binaries arrive too late. The warning line is where the conversation starts and the breach line is where the agreed response happens, which means the gap between them is the time you have bought yourself. Set it deliberately: too narrow and the warning is decorative, too wide and every reading sits in warning permanently.

Target: where you intend to sit

The target is optional and is not a threshold. It is the level you are working towards, and it belongs on indicators attached to risks with an active treatment plan, where the point of the measure is to show whether the plan is working. On an indicator you are only monitoring, leave it empty rather than inventing an aspiration.

Cadence: the promise you are making

The cadence sets the Next Due date and decides when the indicator is considered overdue. Choose the longest interval that would still catch the movement in time to act. Monthly is right for most operational measures; a quarterly assurance measure does not become more informative by being asked for weekly, and asking is how cadences get abandoned.

How to read an indicator's status

Status is the column you scan. It combines the latest reading, the thresholds and the direction into one word, and it is worth knowing precisely what each of them is claiming.

Indicator statuses and what each one means
StatusWhat it meansWhat to do
No dataNo reading has ever been recordedTake the first reading, or pause the indicator
In toleranceThe latest reading is clear of both linesNothing. Read the trend for drift
WarningThe reading has reached the warning levelLook at the linked risks before it goes further
BreachedThe reading has reached the breach levelDo the thing you agreed to do at this level
OverdueThe cadence has passed without a readingRecord a reading; the last value is no longer evidence

Why no data is its own state

An indicator that has never been measured is not reassuring, and showing it as healthy would be a lie the register tells itself. RiskOS keeps no data separate from in tolerance, so an empty indicator is visible as an empty indicator — usually a sign that the measure was harder to collect than it looked.

Four indicators worth copying

These four sit on common risks, are cheap to collect, and each has an obvious response at the breach line. They are a reasonable starting set for a register that has none.

Four worked key risk indicators and the risks they watch
IndicatorLatestStatusWatches
Critical patches outstanding beyond SLA14 countBreachedRSK-0012 Legacy authentication service reaches end of support
Backup restore test success rate72 %BreachedRSK-0007 Backup restoration has never been tested end to end
Vendor assurance reviews overdue3 countWarningRSK-0011 Supplier concentration in a single logistics partner
Days to detect a security event3 daysWarningRSK-0001 Ransomware encrypts primary file shares

Notice what they have in common. Each is a single number somebody already produces or could produce in an hour. Each has a bad direction that nobody would argue about. And each, at its breach level, points at a specific piece of work rather than at a discussion.

How many indicators are enough

Fewer than you think. A register of a dozen active risks is well served by four to six indicators, concentrated on the risks that sit above appetite or carry the largest gap between residual and target. Every indicator is a promise to measure something on a schedule, and a set of twenty promises nobody keeps reads as overdue rows rather than as insight.

Troubleshooting

My indicator shows no data even though I know the number

Knowing the number and recording it are different things. Open the indicator and add a reading with a value, a date and a note. The status changes as soon as the first reading exists, and the chart starts drawing the threshold lines across the history.

A healthy reading is being treated as a breach

The direction is set the wrong way round. An indicator where higher is better — a success rate, a coverage percentage — has to be told that falling is the bad direction, otherwise every good reading crosses the line from the wrong side. Change the direction and the status re-reads immediately.

It went overdue even though I recorded a reading

Check the date on the reading rather than the day you typed it. A reading carries the date it applies to, so a figure copied across from an earlier period does not answer the measurement that is currently due. Record the reading for the period Next Due is asking about, and take a moment to confirm the cadence is still one somebody can meet.

Everything sits in warning and nobody reacts any more

The warning lines are too close to normal operating levels. Look at a few months of readings, put the warning where the value genuinely does not usually go, and leave the breach where the agreed response begins. A warning that is permanently on is the same as no warning at all.

The indicator is green but the risk still feels wrong

Then the measure is watching something adjacent to the risk rather than the risk itself. Re-read the sentence about what decision it should trigger. If the number could double without changing your view of that risk, replace it. It is also worth checking the risk's Intelligence section for linked events, because a risk that keeps materialising is telling you something the indicator is not.

Nobody is collecting the reading any more

Pause the indicator from the list rather than leaving it overdue. A paused row stops adding noise to a section that is meant to be scanned in seconds, and the rows left showing are the ones that still mean something. Resume it from the same place when the measure is being taken again.

Habits that keep indicators honest

  • Start with your worst risk. Give an indicator to the risk furthest above appetite first. That is where early warning is worth the most, and where a breach will actually be acted upon.
  • Write the response into the threshold. Set the breach line at the level where you have already agreed what happens. A threshold with no agreed response is a number waiting to be argued about in the meeting where it matters.
  • Record the note with every reading. Where the figure came from, and anything unusual about the period. A year later the note is what lets someone tell a real movement from a change in how it was counted.
  • Scan the section, not the individual rows. The list sorts worst first, so reading the top three lines takes seconds and tells you whether anything has moved since yesterday.
  • Let a breach reach the risk. When an indicator breaches, open the risks it is linked to and decide whether the rating still stands. An indicator that never causes a re-score is not being used.
  • Read indicators and events together. Indicators show pressure building; events record what got through. A risk with a breached indicator and two events logged over the past year is unlikely to be rated correctly, and RiskOS will say so.
  • Prune once a year. Retire the measures that have never changed a decision. A small set that is trusted is worth more than a long one that is skimmed.
  • Put them in the report. The risk indicators section carries them into the PDF, HTML and Excel outputs from the same snapshot, so the numbers in the board pack agree with the ones on screen.

Frequently asked questions

What is a key risk indicator?

A key risk indicator is a number you measure on a fixed cadence to tell whether a risk is getting worse. It carries a warning threshold, a breach threshold and a declared bad direction. In RiskOS an indicator is linked to the risks it watches, so its status appears beside the rating it is meant to challenge.

How do I know whether a metric is a good key risk indicator?

Finish this sentence: when this number reaches a stated level, we will do a stated thing. If the second half is easy to write, and the measure can be taken the same way on a schedule, it is a good indicator. If nothing would change whatever the number did, it is a statistic and belongs in a report instead.

How many key risk indicators should a risk register have?

Fewer than most registers attempt. Four to six is a healthy set for around a dozen active risks, concentrated on those above appetite or with the largest gap to target. Every indicator commits someone to a reading on a cadence, and unkept commitments show up as overdue rows rather than as useful early warning.

What is the difference between a warning and a breach threshold?

The warning is the level at which you want to look; the breach is the level at which you have agreed to act. Both are inclusive, so a reading landing exactly on a threshold counts as having reached it. Both are read in the direction you declared bad, which is why a falling success rate can breach a threshold below it.

Why does my indicator say no data instead of in tolerance?

Because nothing has been measured yet. RiskOS keeps those two states apart on purpose: an indicator with no readings has never told you anything, and showing it as healthy would misrepresent the register. Record a reading with a value, a date and a note, and the status resolves against your thresholds straight away.

Do key risk indicators change a risk score automatically?

No. Indicators inform a rating rather than overwrite it. A linked indicator shows its live status in the risk's Intelligence section so you can see the evidence beside the score, and you decide whether to re-rate. Scores move when you change a rating or when the effectiveness of a linked control changes.

What is the difference between a key risk indicator and a risk event?

An indicator measures pressure before anything goes wrong; an event records a risk that actually happened, with its severity, cost and how long it took to detect. Indicators look forward, events look back, and reading them together is the quickest way to tell whether a likelihood rating still matches reality.

Do my indicator readings leave my Mac?

No. There is no account and no sign-in, nothing is uploaded, and there is no tracking or telemetry. Readings, thresholds and history stay on your Mac and leave it only when you export or back the register up yourself. The only network RiskOS uses is Apple's App Store, for purchases, and it never sees your register.