Feature Compliance Strategy
Compliance KRIs: Metrics That Show Whether Your Program Is Actually Working
Most compliance dashboards report activity, not risk. Here's how to build compliance KRIs that show whether your program is actually functioning — across the four CMS pillars regulators test, with escalation triggers and board reporting guidance.
Table of Contents
TL;DR
- Most compliance dashboards measure activity — training completions, policy reviews logged, monitoring reports filed. Activity metrics look backward. Compliance KRIs should look forward: toward where the program is likely to fail before it fails.
- Compliance KRIs map to the four CMS pillars regulators test: Board/senior management oversight, compliance program, consumer complaint response, and independent audit/review.
- The most underused compliance KRIs are in the monitoring pillar: exception rate trends, repeat finding patterns, and monitoring coverage gaps that don’t show up in completion counts.
- Board reporting should show compliance program health, not compliance program activity. “We completed 94% of scheduled monitoring reviews” is a KPI. “Monitoring exception rates increased 18 points in Q3, driven by three business lines, with one unresolved repeat finding” is a KRI.
The compliance program at a regional bank had a 97% training completion rate, 100% policy review completion, and monthly monitoring reports filed on schedule for four consecutive quarters. The examiner called it a “mature compliance management program.” Then the examiner asked a different question: “What happened to the issues your monitoring found?”
It turned out that monitoring was generating exceptions. Those exceptions were being logged. Nobody was tracking whether they were being remediated, whether the same issues were recurring, or whether the business lines were actually changing behavior as a result of monitoring. The program was operationally active and substantively ineffective.
This is the gap between compliance activity metrics and compliance KRIs. Activity tells you the program is running. KRIs tell you whether the program is working.
The Four CMS Pillars — and the KRIs That Signal Health
Regulators assess compliance programs through the structure of the Compliance Management System (CMS): four interconnected pillars that, when functioning, produce a program that identifies compliance risk, responds to it, and demonstrates ongoing improvement. When one pillar weakens, the others typically follow.
The CFPB’s Compliance Management Review framework — and the OCC’s Comptroller’s Handbook on Compliance Management — both organize compliance examination findings around this structure. Understanding the pillars is how you understand where your KRI gaps are.
Pillar 1: Board and Senior Management Oversight
Board oversight KRIs are about whether leadership is actually engaged with compliance risk — not just whether they receive the required reports.
KRIs that signal real engagement:
| KRI | What It Measures | Warning Signal |
|---|---|---|
| Time from compliance issue identification to board notification | Governance responsiveness | Material issues taking >60 days to reach the board |
| Board/committee compliance discussion quality (minutes-based) | Whether reports trigger dialogue | Repeated “received and noted” without documented questions or actions |
| Pending risk acceptance items (age) | Whether leadership is deferring compliance decisions | Items open >90 days without decision |
| Compliance budget utilization vs. planned | Whether resources are being deployed | Significant underspend in monitoring/testing budget |
| Regulatory commitment aging | Whether board-level commitments are being tracked | Open commitments >120 days without documented progress |
The last metric — regulatory commitment aging — is the one most boards underestimate. If your organization made a commitment in response to an MRA or examination finding and that commitment is not being tracked with an owner, target date, and evidence requirement, you’re managing your regulatory relationship on memory and goodwill. That’s not a governance model; it’s a time bomb.
Pillar 2: Compliance Program Health
This pillar covers four operational functions: policies and procedures, training, monitoring and testing, and regulatory change management. Each has its own KRI profile.
Policies and Procedures:
The policy KPI is “percentage of policies reviewed on schedule.” The policy KRI is what that review process is actually producing. A policy reviewed annually with no changes documented for four consecutive years is either a genuinely static risk environment (unlikely) or evidence that the review is a checkbox rather than a substantive evaluation.
| KRI | Amber Signal | Red Signal |
|---|---|---|
| Policies overdue for review | >10% of library | >20% or any critical policy |
| Policies without named owner | Any | Any in high-risk areas (BSA/AML, consumer protection, UDAAP) |
| Time from regulatory change to policy update | >90 days for material changes | >180 days |
| Policy exception volume (open) | Rising trend | Repeat exceptions from same business line or process |
| Attestation gaps | >5% unsigned | Key personnel unsigned in high-risk functions |
Training:
Training completion rates measure whether people attended training. They don’t measure whether high-risk populations are current before they engage in high-risk activity.
Meaningful compliance training KRIs:
- Overdue rate for high-risk roles — BSA analysts, relationship managers with customer contact, operations staff with consumer-facing decisions. An overall 95% completion rate can mask a 40% overdue rate in your highest-risk population.
- Assessment failure rate by module — Repeated failures on the same module indicate either a training design problem or a population knowledge gap. Both are risk signals.
- Training-to-incident correlation — Was the employee involved in the last three incidents current on their required training? If yes, you have a control gap. If no, you have a training delivery problem and a control gap.
- Remedial training completion after findings — When a monitoring review generates a finding requiring targeted remediation training, how quickly is it completed? And is it actually completed before the next monitoring review cycle covers the same area?
Monitoring and Testing:
This is where the gap between compliance activity and compliance effectiveness is most visible — and most consequential. Monitoring completion is a KPI. What monitoring produces and what happens as a result are KRIs.
| KRI | What It Measures | Escalation Trigger |
|---|---|---|
| Exception rate by business line (trend) | Whether compliance performance is improving | Rising exception rate in 2+ consecutive periods |
| Repeat exception rate | Whether prior findings are being remediated | Any exception that appeared in prior cycle without documented closure |
| Monitoring coverage gap | % of high-risk areas reviewed in period | Critical area not reviewed in >12 months |
| Issue-to-action conversion rate | Whether monitoring findings result in documented action | <80% conversion over rolling 6 months |
| Days from finding to CAP completion | Remediation velocity | CAPs open >120 days for significant findings |
The repeat exception rate is the most telling metric on this list. If the same exception appears in your Q1 monitoring review and your Q3 monitoring review without documented closure in between, your monitoring program is producing information that nobody is acting on. That finding will surface in your next examination — often with the examiner noting that you knew about it and didn’t fix it.
Regulatory Change Management:
Regulators issue guidance continuously. Tracking new rules and proposed rulemaking is the beginning, not the end. The KRI question is: what happens between a regulation being identified and your organization being in compliance?
- Intake-to-impact assessment timing — How long between a regulatory change being identified and a formal impact assessment being documented?
- Implementation task overdue rate — Percentage of regulatory implementation tasks past their documented completion date
- Policy/procedure lag — Number of policies not yet updated for regulatory changes with passed effective dates
- Training completion before effective date — Percentage of affected staff trained before the regulatory requirement takes effect
- Evidence readiness — For upcoming deadlines, do you have documented evidence of control implementation before the examiner asks?
Pillar 3: Consumer Complaint Response
Complaint data is one of the most underused compliance leading indicators in financial services. A rising complaint volume is a KPI. A rising complaint escalation rate concentrated in a specific product or issue type is a KRI.
Complaint KRIs that indicate program stress:
| KRI | What It Measures | Warning Signal |
|---|---|---|
| Escalation rate (complaints going to regulators or CFPB) | Consumer dissatisfaction reaching supervisory attention | Rising rate over 2+ months |
| Repeat complaint pattern by issue type | Systemic product or process failure | Same issue type in >3 complaints without root cause response |
| Time to resolution trend | Operational capacity and prioritization | Median resolution time increasing quarter-over-quarter |
| Unfavorable outcome rate | Whether complaints are being resolved in consumers’ favor | Rising rate without documented justification |
| Complaint-to-monitoring feedback loop | Whether complaint data informs compliance monitoring | Complaint patterns not appearing in monitoring scope |
The CFPB’s examination framework specifically evaluates whether complaint data is being used to identify systemic compliance issues — not just resolved case-by-case. If your complaint management process produces case closures but not compliance insights, the examiner’s notes will reflect that gap.
Pillar 4: Independent Audit and Review
Audit KRIs measure whether your independent testing function is producing meaningful risk insight — and whether findings are being remediated.
- Repeat audit findings — The single most common examination observation. An audit finding that recurred in the next audit cycle is documented evidence that remediation is either not happening or not effective.
- CAP aging by severity — Corrective action plan items by severity and days open. A high-severity CAP open for 180 days is both an audit KRI and a board governance KRI.
- Validation failure rate — Percentage of CAP closures where the validation found the control not yet effective. Rising validation failure rates indicate either weak CAPs being approved too quickly or business lines closing items on paper without substantive change.
- Management response quality — Audit management responses that commit to remediation without specifying the control, the owner, and the evidence standard are KRI signals. “We will enhance our process” is not a management response that generates a defensible audit trail.
Building a Compliance KRI Dashboard
A compliance KRI dashboard has two audiences: management (who needs operational detail to direct action) and the board (who needs program health signals to exercise oversight).
Management dashboard (monthly): Training overdue by business line and role tier, monitoring exception rates and trends, complaint escalation rate, open CAPs by severity and age, policy and procedure currency, regulatory change implementation status.
Board dashboard (quarterly): Overall compliance program health rating (with supporting rationale), number of amber and red KRI events in the period, open regulatory commitments status, critical issues requiring board decision or awareness, and one or two trend lines showing whether the program is improving or degrading.
The board dashboard should never show 30 green dots. It should show the honest picture of where the program has stress, what’s being done about it, and whether the trajectory is improving. If you’ve never shown an amber or red indicator to your board, either your program is genuinely without significant issues (unlikely if you’re growing) or your thresholds are calibrated to never produce an uncomfortable signal.
What Examiners Actually Test
When CFPB, OCC, or FDIC examiners assess your compliance management system, they are testing the four CMS pillars with a specific question in mind: does this program detect and correct compliance failures, or does it document compliance activity?
The examiner questions that separate the two:
- Show me the last three significant monitoring findings. What management action followed?
- What compliance issues was senior management aware of in the last 12 months? How do you know?
- How does complaint data inform your compliance monitoring scope?
- Show me a repeat finding from your last audit cycle. What changed?
- What regulatory change came into effect in the last six months? Show me how your policies and training reflect it.
If your compliance KRI program answers these questions with documented metrics, escalation records, and management actions — before the examiner asks — you’re not defending a compliance program. You’re demonstrating one.
So What?
Compliance program health cannot be measured by checking whether activities occurred. Training happened doesn’t mean high-risk staff were current. Monitoring was conducted doesn’t mean findings were remediated. Policies were reviewed doesn’t mean they reflect current regulatory expectations.
Compliance KRIs are the mechanism that converts activity into accountability — that connects what the program does to whether the program works. An examiner who asks what your compliance KRIs are and receives a list of activity counts isn’t satisfied. An examiner who receives a list of risk indicators mapped to the four CMS pillars, with documented escalation paths and evidence of management action on breaches, has seen a functioning program.
If you’re building or upgrading your compliance KRI program, the Compliance Essentials bundle includes pre-built KRI templates for each CMS pillar, escalation and ownership RACI structures, and a board reporting dashboard designed for quarterly compliance program review. Available at buy.stripe.com/dRm8wI04H9BNeQ56uW6J20g.
Related reading:
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Compliance Essentials
Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What's the difference between a compliance KPI and a compliance KRI?
What compliance KRIs do regulators actually look for?
How do I know if my compliance training KRIs are meaningful?
What does a complaint KRI look like in practice?
How often should compliance KRIs be reviewed?
What happens when a compliance KRI hits red?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Compliance Essentials
Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.
◆ Keep reading
Related posts.
Compliance Strategy
GRC Framework for a Small Risk Team: One Control Library, Five Workflows, No Enterprise Platform
A GRC program that runs on one control library, five traceable workflows, and a set of spreadsheets beats a half-implemented enterprise platform every time. Here's how to build it.
Jul 24, 2026
Compliance Strategy
Compliance Monitoring Plan in Excel: Convert the Risk Assessment Into a Defensible Test Universe
Build a compliance monitoring plan template in Excel that traces risks and obligations to scope, evidence, exceptions, and remediation.
Jul 23, 2026
Compliance Strategy
Your Reg E Program Wasn't Built for FedNow: The Error Resolution Timeline Trap in Instant Payments
Reg E's 10-business-day provisional credit requirement applies to FedNow and RTP consumer transactions—but instant payment irrevocability means the fraud money is gone before you finish the investigation. Here's what your error resolution procedures actually need to say for instant payments, and where most programs have a documented gap.
Jul 22, 2026