Compliance: KPIs
Control operation, evidence coverage and gap ageing, with unevidenced controls counted separately from failing ones.
Markdown. No sign-up, no email.
The measure of a compliance function is not whether it passed the audit. It is whether the controls were operating on the days nobody was looking.
The six that matter#
| Measure | Definition | Target | How it gets gamed |
|---|---|---|---|
| Controls operating | Share evidenced as operating this month | Above 95% | Counting unevidenced as operating |
| Unevidenced controls | Controls with no evidence either way | Under 5% | Merging this into the pass number, which is the classic move |
| Evidence collected automatically | Share gathered as work happens | Above 80% | Reconstructing afterwards and calling it collection |
| Gap age | Days a known control gap stays open | Under 30 | Reclassifying a gap as an accepted risk without a date |
| Obligations mapped | Regulatory obligations with a named control | 100% | Mapping to a control that does not actually address it |
| Audit findings repeated | Findings that also appeared last time | Zero | Closing findings on paper rather than in the control |
Unevidenced is its own number and never folded into passing. "No failure detected" and "verified as operating" are different states, and the gap between them is where a control quietly stops working for eight months.
Repeated audit findings are the most damaging number here. A first finding is a gap; the same finding twice is a statement about whether the organisation acts on what it is told, and auditors read it that way.
Two counter-metrics#
| Counter-metric | Catches |
|---|---|
| Controls that have never failed | Either genuinely robust or not actually testing anything. Worth knowing which |
| Time spent producing evidence manually | The work automation was supposed to remove. If this is not falling, the automation is decorative |
Gap register, monthly#
| Question | Bad answer |
|---|---|
| Which obligations have no control? | Any. This is an uncontrolled obligation, not a future risk |
| Which gaps are past their remediation date? | Any, unresolved and unescalated |
| Which accepted risks have expired? | Any. An expired acceptance is an unowned risk |
| Which controls depend on one person? | Any, without a documented alternative |
What is deliberately not measured#
- Policies written. Documents, not controls.
- Training completion. Attendance. Measure whether the behaviour changed.
- Audits passed. A point-in-time result that says little about the other 364 days.
- Certifications held. Useful commercially, weak as a measure of control operation.
Cadence#
| Continuous | Control monitoring, evidence collection |
| Monthly | Gap register, unevidenced controls, expired acceptances |
| Quarterly | Obligation mapping review, control effectiveness attestation by a person |
| Annually | External audit, if in scope |