Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Compliance Strategy

Compliance KRIs: Metrics That Show Whether Your Program Is Actually Working

Most compliance dashboards report activity, not risk. Here's how to build compliance KRIs that show whether your program is actually functioning — across the four CMS pillars regulators test, with escalation triggers and board reporting guidance.

Table of Contents

TL;DR

  • Most compliance dashboards measure activity — training completions, policy reviews logged, monitoring reports filed. Activity metrics look backward. Compliance KRIs should look forward: toward where the program is likely to fail before it fails.
  • Compliance KRIs map to the four CMS pillars regulators test: Board/senior management oversight, compliance program, consumer complaint response, and independent audit/review.
  • The most underused compliance KRIs are in the monitoring pillar: exception rate trends, repeat finding patterns, and monitoring coverage gaps that don’t show up in completion counts.
  • Board reporting should show compliance program health, not compliance program activity. “We completed 94% of scheduled monitoring reviews” is a KPI. “Monitoring exception rates increased 18 points in Q3, driven by three business lines, with one unresolved repeat finding” is a KRI.

The compliance program at a regional bank had a 97% training completion rate, 100% policy review completion, and monthly monitoring reports filed on schedule for four consecutive quarters. The examiner called it a “mature compliance management program.” Then the examiner asked a different question: “What happened to the issues your monitoring found?”

It turned out that monitoring was generating exceptions. Those exceptions were being logged. Nobody was tracking whether they were being remediated, whether the same issues were recurring, or whether the business lines were actually changing behavior as a result of monitoring. The program was operationally active and substantively ineffective.

This is the gap between compliance activity metrics and compliance KRIs. Activity tells you the program is running. KRIs tell you whether the program is working.

The Four CMS Pillars — and the KRIs That Signal Health

Regulators assess compliance programs through the structure of the Compliance Management System (CMS): four interconnected pillars that, when functioning, produce a program that identifies compliance risk, responds to it, and demonstrates ongoing improvement. When one pillar weakens, the others typically follow.

The CFPB’s Compliance Management Review framework — and the OCC’s Comptroller’s Handbook on Compliance Management — both organize compliance examination findings around this structure. Understanding the pillars is how you understand where your KRI gaps are.

Pillar 1: Board and Senior Management Oversight

Board oversight KRIs are about whether leadership is actually engaged with compliance risk — not just whether they receive the required reports.

KRIs that signal real engagement:

KRIWhat It MeasuresWarning Signal
Time from compliance issue identification to board notificationGovernance responsivenessMaterial issues taking >60 days to reach the board
Board/committee compliance discussion quality (minutes-based)Whether reports trigger dialogueRepeated “received and noted” without documented questions or actions
Pending risk acceptance items (age)Whether leadership is deferring compliance decisionsItems open >90 days without decision
Compliance budget utilization vs. plannedWhether resources are being deployedSignificant underspend in monitoring/testing budget
Regulatory commitment agingWhether board-level commitments are being trackedOpen commitments >120 days without documented progress

The last metric — regulatory commitment aging — is the one most boards underestimate. If your organization made a commitment in response to an MRA or examination finding and that commitment is not being tracked with an owner, target date, and evidence requirement, you’re managing your regulatory relationship on memory and goodwill. That’s not a governance model; it’s a time bomb.

Pillar 2: Compliance Program Health

This pillar covers four operational functions: policies and procedures, training, monitoring and testing, and regulatory change management. Each has its own KRI profile.

Policies and Procedures:

The policy KPI is “percentage of policies reviewed on schedule.” The policy KRI is what that review process is actually producing. A policy reviewed annually with no changes documented for four consecutive years is either a genuinely static risk environment (unlikely) or evidence that the review is a checkbox rather than a substantive evaluation.

KRIAmber SignalRed Signal
Policies overdue for review>10% of library>20% or any critical policy
Policies without named ownerAnyAny in high-risk areas (BSA/AML, consumer protection, UDAAP)
Time from regulatory change to policy update>90 days for material changes>180 days
Policy exception volume (open)Rising trendRepeat exceptions from same business line or process
Attestation gaps>5% unsignedKey personnel unsigned in high-risk functions

Training:

Training completion rates measure whether people attended training. They don’t measure whether high-risk populations are current before they engage in high-risk activity.

Meaningful compliance training KRIs:

  • Overdue rate for high-risk roles — BSA analysts, relationship managers with customer contact, operations staff with consumer-facing decisions. An overall 95% completion rate can mask a 40% overdue rate in your highest-risk population.
  • Assessment failure rate by module — Repeated failures on the same module indicate either a training design problem or a population knowledge gap. Both are risk signals.
  • Training-to-incident correlation — Was the employee involved in the last three incidents current on their required training? If yes, you have a control gap. If no, you have a training delivery problem and a control gap.
  • Remedial training completion after findings — When a monitoring review generates a finding requiring targeted remediation training, how quickly is it completed? And is it actually completed before the next monitoring review cycle covers the same area?

Monitoring and Testing:

This is where the gap between compliance activity and compliance effectiveness is most visible — and most consequential. Monitoring completion is a KPI. What monitoring produces and what happens as a result are KRIs.

KRIWhat It MeasuresEscalation Trigger
Exception rate by business line (trend)Whether compliance performance is improvingRising exception rate in 2+ consecutive periods
Repeat exception rateWhether prior findings are being remediatedAny exception that appeared in prior cycle without documented closure
Monitoring coverage gap% of high-risk areas reviewed in periodCritical area not reviewed in >12 months
Issue-to-action conversion rateWhether monitoring findings result in documented action<80% conversion over rolling 6 months
Days from finding to CAP completionRemediation velocityCAPs open >120 days for significant findings

The repeat exception rate is the most telling metric on this list. If the same exception appears in your Q1 monitoring review and your Q3 monitoring review without documented closure in between, your monitoring program is producing information that nobody is acting on. That finding will surface in your next examination — often with the examiner noting that you knew about it and didn’t fix it.

Regulatory Change Management:

Regulators issue guidance continuously. Tracking new rules and proposed rulemaking is the beginning, not the end. The KRI question is: what happens between a regulation being identified and your organization being in compliance?

  • Intake-to-impact assessment timing — How long between a regulatory change being identified and a formal impact assessment being documented?
  • Implementation task overdue rate — Percentage of regulatory implementation tasks past their documented completion date
  • Policy/procedure lag — Number of policies not yet updated for regulatory changes with passed effective dates
  • Training completion before effective date — Percentage of affected staff trained before the regulatory requirement takes effect
  • Evidence readiness — For upcoming deadlines, do you have documented evidence of control implementation before the examiner asks?

Pillar 3: Consumer Complaint Response

Complaint data is one of the most underused compliance leading indicators in financial services. A rising complaint volume is a KPI. A rising complaint escalation rate concentrated in a specific product or issue type is a KRI.

Complaint KRIs that indicate program stress:

KRIWhat It MeasuresWarning Signal
Escalation rate (complaints going to regulators or CFPB)Consumer dissatisfaction reaching supervisory attentionRising rate over 2+ months
Repeat complaint pattern by issue typeSystemic product or process failureSame issue type in >3 complaints without root cause response
Time to resolution trendOperational capacity and prioritizationMedian resolution time increasing quarter-over-quarter
Unfavorable outcome rateWhether complaints are being resolved in consumers’ favorRising rate without documented justification
Complaint-to-monitoring feedback loopWhether complaint data informs compliance monitoringComplaint patterns not appearing in monitoring scope

The CFPB’s examination framework specifically evaluates whether complaint data is being used to identify systemic compliance issues — not just resolved case-by-case. If your complaint management process produces case closures but not compliance insights, the examiner’s notes will reflect that gap.

Pillar 4: Independent Audit and Review

Audit KRIs measure whether your independent testing function is producing meaningful risk insight — and whether findings are being remediated.

  • Repeat audit findings — The single most common examination observation. An audit finding that recurred in the next audit cycle is documented evidence that remediation is either not happening or not effective.
  • CAP aging by severity — Corrective action plan items by severity and days open. A high-severity CAP open for 180 days is both an audit KRI and a board governance KRI.
  • Validation failure rate — Percentage of CAP closures where the validation found the control not yet effective. Rising validation failure rates indicate either weak CAPs being approved too quickly or business lines closing items on paper without substantive change.
  • Management response quality — Audit management responses that commit to remediation without specifying the control, the owner, and the evidence standard are KRI signals. “We will enhance our process” is not a management response that generates a defensible audit trail.

Building a Compliance KRI Dashboard

A compliance KRI dashboard has two audiences: management (who needs operational detail to direct action) and the board (who needs program health signals to exercise oversight).

Management dashboard (monthly): Training overdue by business line and role tier, monitoring exception rates and trends, complaint escalation rate, open CAPs by severity and age, policy and procedure currency, regulatory change implementation status.

Board dashboard (quarterly): Overall compliance program health rating (with supporting rationale), number of amber and red KRI events in the period, open regulatory commitments status, critical issues requiring board decision or awareness, and one or two trend lines showing whether the program is improving or degrading.

The board dashboard should never show 30 green dots. It should show the honest picture of where the program has stress, what’s being done about it, and whether the trajectory is improving. If you’ve never shown an amber or red indicator to your board, either your program is genuinely without significant issues (unlikely if you’re growing) or your thresholds are calibrated to never produce an uncomfortable signal.

What Examiners Actually Test

When CFPB, OCC, or FDIC examiners assess your compliance management system, they are testing the four CMS pillars with a specific question in mind: does this program detect and correct compliance failures, or does it document compliance activity?

The examiner questions that separate the two:

  1. Show me the last three significant monitoring findings. What management action followed?
  2. What compliance issues was senior management aware of in the last 12 months? How do you know?
  3. How does complaint data inform your compliance monitoring scope?
  4. Show me a repeat finding from your last audit cycle. What changed?
  5. What regulatory change came into effect in the last six months? Show me how your policies and training reflect it.

If your compliance KRI program answers these questions with documented metrics, escalation records, and management actions — before the examiner asks — you’re not defending a compliance program. You’re demonstrating one.

So What?

Compliance program health cannot be measured by checking whether activities occurred. Training happened doesn’t mean high-risk staff were current. Monitoring was conducted doesn’t mean findings were remediated. Policies were reviewed doesn’t mean they reflect current regulatory expectations.

Compliance KRIs are the mechanism that converts activity into accountability — that connects what the program does to whether the program works. An examiner who asks what your compliance KRIs are and receives a list of activity counts isn’t satisfied. An examiner who receives a list of risk indicators mapped to the four CMS pillars, with documented escalation paths and evidence of management action on breaches, has seen a functioning program.

If you’re building or upgrading your compliance KRI program, the Compliance Essentials bundle includes pre-built KRI templates for each CMS pillar, escalation and ownership RACI structures, and a board reporting dashboard designed for quarterly compliance program review. Available at buy.stripe.com/dRm8wI04H9BNeQ56uW6J20g.

Related reading:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What's the difference between a compliance KPI and a compliance KRI?
A KPI measures compliance program activity: training completion rate, policy review rate, exam responses submitted on time. A KRI measures whether the program is generating the right risk outcomes: whether training is actually reaching high-risk populations before incidents occur, whether policies are aging without review, whether exam responses contain repeat commitments from prior cycles. Activity metrics look backward. Risk indicators look forward — toward where the program is likely to fail before it does.
What compliance KRIs do regulators actually look for?
CFPB, OCC, and FDIC examiners assess compliance programs through the lens of the four CMS pillars: Board/senior management oversight, compliance program (policies, training, monitoring), consumer complaint response, and independent audit/review. For each pillar, they look for KRIs that show whether the function is performing — not just operating. For example, in the monitoring pillar, they don't just want to know how many monitoring reviews you completed. They want to know what the exception rate was, what happened when exceptions were found, and whether the same exceptions are appearing in multiple reviews.
How do I know if my compliance training KRIs are meaningful?
A training completion rate is a KPI, not a KRI. The risk indicator question is: 'Are the right people getting the right training before they need it?' Meaningful compliance training KRIs include: overdue completion rates for high-risk populations (AML analysts, customer-facing staff), assessment pass/fail rates by role, training-to-incident correlation (was the employee involved in an incident current on relevant training?), and targeted remediation completion after a finding. If your training KRI is '95% completion rate,' an examiner will ask how many of the 5% missing are in your highest-risk roles.
What does a complaint KRI look like in practice?
A complaint volume metric is a KPI. A complaint KRI tracks what complaints are signaling about program health: escalation rate (complaints going to regulators or requiring elevated response), repeat complaint pattern by issue type, time to resolution trend, unfavorable outcome rate, and whether complaint trends are feeding back into your compliance monitoring. A rising escalation rate combined with concentrated complaint issue types — for example, three consecutive months of rising complaints about a specific disclosure — is a KRI signal that should trigger a monitoring review, not just case management.
How often should compliance KRIs be reviewed?
Board-level compliance KRIs (program health, exam commitments, issue aging) should be reviewed at least quarterly. Management-level compliance KRIs (training, monitoring, complaints, policy aging) should be reviewed monthly. Operational compliance KRIs (issue age, exception rates, specific product or business line metrics) should be reviewed continuously or weekly. The review cadence should be tied to the risk level of the metric: a complaint escalation rate that's been stable for 12 months can be reviewed monthly; a complaint escalation rate that doubled in the last 30 days needs weekly attention.
What happens when a compliance KRI hits red?
A red compliance KRI should trigger an escalation path within 24–48 hours: notification to the compliance officer or CRO, a written escalation memo documenting the metric, likely cause, and proposed interim action, and — if the metric is board-level — Risk Committee notification. What should not happen: a compliance KRI sits at red while someone decides whether it's 'really' a problem. Red means a threshold connected to your compliance risk appetite has been approached or breached. That's a governance event.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Compliance Essentials

Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.