AI governance dashboard with KPIs and KRIs for performance and risk monitoring

AI GOVERNANCE · METRICS

AI Governance KPIs and KRIs: How to Measure Whether the Framework Works

An artificial intelligence governance framework can look robust on paper.

It may include policies, roles, an inventory, controls, training, assessments and committees.

But one important question remains:

how do we know whether it actually works?

Measuring AI governance is not about filling a dashboard with charts. It is about selecting indicators that show whether processes are being carried out, risks remain controlled, controls work, deviations emerge and the organisation is improving.

This is where KPIs and KRIs matter. KPIs help measure performance. KRIs help identify risk exposure.

The aim is not to have many indicators. It is to have the right ones.

What is the difference between a KPI and a KRI?

KPI

A Key Performance Indicator measures performance: are we carrying out the process as intended? Examples include inventory coverage, completed assessments, tested controls, trained staff and assessed vendors.

KRI

A Key Risk Indicator signals exposure: is our risk increasing? Examples include incidents, systems without an owner, overdue assessments, failed controls and residual risk above threshold.

A KPI primarily looks at operation; a KRI at exposure. An operational metric records activity, a target describes the expected result, and a threshold is the point that triggers review or escalation.

Why measure AI governance?

Without measurement, it is difficult to know whether an AI governance framework works in practice. Metrics make AI governance observable and reveal trends rather than isolated snapshots.

What makes an indicator useful?

A clear purpose

It should answer a real question and support a decision.

An accountable owner

Someone must review it and be able to act.

A frequency and data source

The organisation should know when it is reviewed and where the data comes from.

A target and threshold

The target describes the desired result; the threshold defines when to review or escalate.

A defined action

For example: critical systems with overdue assessments; threshold above 5%; immediate review by the AI governance owner.

Inventory and coverage KPIs

The AI inventory is a foundation of governance. Useful measures include the percentage of systems identified, systems with an owner, classifications reviewed and active systems within their review date.

These KPIs measure coverage, but 100% coverage does not guarantee accurate records. A practical AI register must remain current.

Risk and assessment KPIs

AI risk management can be measured through completed and pending assessments, average assessment time, treated or accepted risks, and overdue actions.

Useful examples include the percentage of relevant systems with a current risk assessment and the time from identification to completed assessment.

Control effectiveness KPIs

Controls need to do more than exist. Organisations may measure controls implemented, tested, effective, failed or overdue, together with open exceptions.

Examples include the percentage of critical controls tested on schedule and the percentage supported by sufficient evidence.

Training and AI literacy KPIs

AI literacy may be measured through training coverage, critical roles covered, refresher activity, internal assessments and practical exercises.

Attendance does not automatically equal competence. Completion data may need to be combined with assessment, behaviour and incident data.

Vendor and third-party KPIs

AI vendor management may track assessed and pending suppliers, completed reviews, contract requirements, notified changes and third-party incidents.

Examples include relevant vendors subject to due diligence before purchase and critical vendors reviewed within the agreed cycle.

Incident and deviation KRIs

Possible KRIs include incident volume and severity, resolution time, recurrence, and incidents by system or supplier.

The absolute number may mislead. More reports can mean more problems or a healthier reporting culture. Zero incidents is not sufficient evidence that governance works.

Residual risk KRIs

Organisations may track systems with high residual risk, risks above appetite, risks awaiting acceptance, risks without an owner and overdue treatment.

Examples include systems above the approved residual-risk threshold and critical risks without a treatment plan.

Evidence and traceability KPIs

AI evidence may cover complete evidence packs, documented assessments, recorded decisions, control evidence, traceable reviews and closed audits.

The metric should demonstrate that governance leaves a reliable trail, without treating documentary compliance as equivalent to effectiveness.

How to build an AI governance dashboard

A useful dashboard may start with ten or twelve indicators covering inventory, ownership, risk assessment, residual risk, control effectiveness, training, vendors, incidents, evidence and improvement.

Each indicator should include its current value, target, trend, threshold, owner and review frequency. That turns the dashboard into a decision tool. The dashboard itself is not proof of good governance.

Team analysing AI governance metrics, risks and control effectiveness

How to interpret the indicators

An isolated figure can mislead. Zero incidents may mean none occurred or none were detected. One hundred per cent training completion does not prove that rules are applied correctly.

Interpretation should consider trend, context, relationships between indicators and data quality.

Common mistakes

Measuring too much

Too many metrics create noise; volume does not demonstrate maturity.

Measuring activity only

Twenty meetings reveal little about effectiveness.

Failing to define thresholds

A number without a reference point does not enable action.

Failing to assign owners

The dashboard exists, but nobody decides.

Mixing KPIs and KRIs

This obscures interpretation.

Using only positive measures

Deviations must also be visible.

Measuring training by attendance alone

Attendance does not prove competence.

Failing to review the indicators

The framework evolves, and so should its measures.

What an organisation should measure first

A practical starting set can cover inventory coverage, system ownership, current risk assessments, critical controls, training coverage, assessed vendors, incident management and decision evidence.

The model can then mature and connect measures to governance roles and AI system change management.

What is not measured eventually depends on perception

AI governance should not be assessed by asking “do we think it works?” It should be observable through metrics, trends, risks and decisions.

KPIs show whether processes perform. KRIs show when exposure increases. Together they connect governance → performance → risk → decision → improvement.

The objective is not the most sophisticated dashboard. It is to know whether the framework is producing the result for which it was designed.

References

  • ISO/IEC 42001:2023 — Artificial intelligence management system.
  • ISO/IEC 23894:2023 — Guidance on AI-related risk management.
  • NIST AI Risk Management Framework — AI RMF.
  • NIST AI RMF Playbook.

These references do not prescribe a universal list. Indicators should reflect each organisation’s context, scope, risks and objectives.

Do you know whether your AI governance model is actually working?

Having policies, controls and processes is only part of the picture.

Start the diagnostic →
You also need to know whether they are applied, whether they reduce risk and where governance gaps remain. Céntrika’s diagnostic can help identify that starting point.