KPIs · Compliance

Compliance: KPIs

Control operation, evidence coverage and gap ageing, with unevidenced controls counted separately from failing ones.

Markdown. No sign-up, no email.

The measure of a compliance function is not whether it passed the audit. It is whether the controls were operating on the days nobody was looking.

The six that matter#

MeasureDefinitionTargetHow it gets gamed
Controls operatingShare evidenced as operating this monthAbove 95%Counting unevidenced as operating
Unevidenced controlsControls with no evidence either wayUnder 5%Merging this into the pass number, which is the classic move
Evidence collected automaticallyShare gathered as work happensAbove 80%Reconstructing afterwards and calling it collection
Gap ageDays a known control gap stays openUnder 30Reclassifying a gap as an accepted risk without a date
Obligations mappedRegulatory obligations with a named control100%Mapping to a control that does not actually address it
Audit findings repeatedFindings that also appeared last timeZeroClosing findings on paper rather than in the control

Unevidenced is its own number and never folded into passing. "No failure detected" and "verified as operating" are different states, and the gap between them is where a control quietly stops working for eight months.

Repeated audit findings are the most damaging number here. A first finding is a gap; the same finding twice is a statement about whether the organisation acts on what it is told, and auditors read it that way.

Two counter-metrics#

Counter-metricCatches
Controls that have never failedEither genuinely robust or not actually testing anything. Worth knowing which
Time spent producing evidence manuallyThe work automation was supposed to remove. If this is not falling, the automation is decorative

Gap register, monthly#

QuestionBad answer
Which obligations have no control?Any. This is an uncontrolled obligation, not a future risk
Which gaps are past their remediation date?Any, unresolved and unescalated
Which accepted risks have expired?Any. An expired acceptance is an unowned risk
Which controls depend on one person?Any, without a documented alternative

What is deliberately not measured#

  • Policies written. Documents, not controls.
  • Training completion. Attendance. Measure whether the behaviour changed.
  • Audits passed. A point-in-time result that says little about the other 364 days.
  • Certifications held. Useful commercially, weak as a measure of control operation.

Cadence#

ContinuousControl monitoring, evidence collection
MonthlyGap register, unevidenced controls, expired acceptances
QuarterlyObligation mapping review, control effectiveness attestation by a person
AnnuallyExternal audit, if in scope

Back to Compliance

Get new material when it is published

Everything here is free and stays free. There is no form in front of any document. If you want to know when new guides and templates go up, leave an email.

Roughly monthly. Unsubscribe in one click. We do not share your address, and we will not call you.