What is the difference between a KPI and a KRI?
KPI
A Key Performance Indicator measures performance: are we carrying out the process as intended? Examples include inventory coverage, completed assessments, tested controls, trained staff and assessed vendors.
KRI
A Key Risk Indicator signals exposure: is our risk increasing? Examples include incidents, systems without an owner, overdue assessments, failed controls and residual risk above threshold.
A KPI primarily looks at operation; a KRI at exposure. An operational metric records activity, a target describes the expected result, and a threshold is the point that triggers review or escalation.
Why measure AI governance?
Without measurement, it is difficult to know whether an AI governance framework works in practice. Metrics make AI governance observable and reveal trends rather than isolated snapshots.
What makes an indicator useful?
A clear purpose
It should answer a real question and support a decision.
An accountable owner
Someone must review it and be able to act.
A frequency and data source
The organisation should know when it is reviewed and where the data comes from.
A target and threshold
The target describes the desired result; the threshold defines when to review or escalate.
A defined action
For example: critical systems with overdue assessments; threshold above 5%; immediate review by the AI governance owner.
Inventory and coverage KPIs
The AI inventory is a foundation of governance. Useful measures include the percentage of systems identified, systems with an owner, classifications reviewed and active systems within their review date.
These KPIs measure coverage, but 100% coverage does not guarantee accurate records. A practical AI register must remain current.
Risk and assessment KPIs
AI risk management can be measured through completed and pending assessments, average assessment time, treated or accepted risks, and overdue actions.
Useful examples include the percentage of relevant systems with a current risk assessment and the time from identification to completed assessment.
Control effectiveness KPIs
Controls need to do more than exist. Organisations may measure controls implemented, tested, effective, failed or overdue, together with open exceptions.
Examples include the percentage of critical controls tested on schedule and the percentage supported by sufficient evidence.
Training and AI literacy KPIs
AI literacy may be measured through training coverage, critical roles covered, refresher activity, internal assessments and practical exercises.
Attendance does not automatically equal competence. Completion data may need to be combined with assessment, behaviour and incident data.
Vendor and third-party KPIs
AI vendor management may track assessed and pending suppliers, completed reviews, contract requirements, notified changes and third-party incidents.
Examples include relevant vendors subject to due diligence before purchase and critical vendors reviewed within the agreed cycle.
Incident and deviation KRIs
Possible KRIs include incident volume and severity, resolution time, recurrence, and incidents by system or supplier.
The absolute number may mislead. More reports can mean more problems or a healthier reporting culture. Zero incidents is not sufficient evidence that governance works.
Residual risk KRIs
Organisations may track systems with high residual risk, risks above appetite, risks awaiting acceptance, risks without an owner and overdue treatment.
Examples include systems above the approved residual-risk threshold and critical risks without a treatment plan.
Evidence and traceability KPIs
AI evidence may cover complete evidence packs, documented assessments, recorded decisions, control evidence, traceable reviews and closed audits.
The metric should demonstrate that governance leaves a reliable trail, without treating documentary compliance as equivalent to effectiveness.
How to build an AI governance dashboard
A useful dashboard may start with ten or twelve indicators covering inventory, ownership, risk assessment, residual risk, control effectiveness, training, vendors, incidents, evidence and improvement.
Each indicator should include its current value, target, trend, threshold, owner and review frequency. That turns the dashboard into a decision tool. The dashboard itself is not proof of good governance.

How to interpret the indicators
An isolated figure can mislead. Zero incidents may mean none occurred or none were detected. One hundred per cent training completion does not prove that rules are applied correctly.
Interpretation should consider trend, context, relationships between indicators and data quality.
Common mistakes
Measuring too much
Too many metrics create noise; volume does not demonstrate maturity.
Measuring activity only
Twenty meetings reveal little about effectiveness.
Failing to define thresholds
A number without a reference point does not enable action.
Failing to assign owners
The dashboard exists, but nobody decides.
Mixing KPIs and KRIs
This obscures interpretation.
Using only positive measures
Deviations must also be visible.
Measuring training by attendance alone
Attendance does not prove competence.
Failing to review the indicators
The framework evolves, and so should its measures.
What an organisation should measure first
A practical starting set can cover inventory coverage, system ownership, current risk assessments, critical controls, training coverage, assessed vendors, incident management and decision evidence.
The model can then mature and connect measures to governance roles and AI system change management.
What is not measured eventually depends on perception
AI governance should not be assessed by asking “do we think it works?” It should be observable through metrics, trends, risks and decisions.
KPIs show whether processes perform. KRIs show when exposure increases. Together they connect governance → performance → risk → decision → improvement.
The objective is not the most sophisticated dashboard. It is to know whether the framework is producing the result for which it was designed.
References
- ISO/IEC 42001:2023 — Artificial intelligence management system.
- ISO/IEC 23894:2023 — Guidance on AI-related risk management.
- NIST AI Risk Management Framework — AI RMF.
- NIST AI RMF Playbook.
These references do not prescribe a universal list. Indicators should reflect each organisation’s context, scope, risks and objectives.
Do you know whether your AI governance model is actually working?
Having policies, controls and processes is only part of the picture.
Start the diagnostic →
You also need to know whether they are applied, whether they reduce risk and where governance gaps remain. Céntrika’s diagnostic can help identify that starting point.
