Blog · Board and management reporting · Compliance
The ten KPIs a compliance function should run on, each with its formula, the export it comes from and what it tells you: obligation to control coverage, regulatory change coverage, control testing on schedule, test failure rate and repeat failures, issue ageing by owner, training completion against role requirement, incident reporting against activity, policy attestation, time to close findings, and evidence completeness. Also the three measures most compliance teams miss, the figures to drop, the identities, and who owns what.
A compliance function is judged on what it can evidence. The measures that matter show which obligations have a control behind them, which controls were tested and passed, which findings are ageing with whom, and which units are suspiciously quiet.
| # | Measure | Formula | Export | What it tells you |
|---|---|---|---|---|
| 1 | Obligation to control coverage | Obligations with a mapped, owned and tested control ÷ obligations, weighted by risk rating | Obligations register; control library | Obligations with nothing behind them |
| 2 | Regulatory change coverage | New or changed obligations with a control mapped within the stated days ÷ new or changed obligations | Regulatory change log; control library | Whether the register keeps up |
| 3 | Testing on schedule | Control tests completed by due date ÷ tests due, by risk rating | Testing schedule | Controls that slipped, highest risk first |
| 4 | Failure rate and repeat failures | Tests failed ÷ tests completed; failures on controls that failed the prior test | Test results | Remediation that did not work |
| 5 | Issue ageing by owner | Open issues past remediation date, by owner, days overdue, number of extensions | Issues log | Where findings wait |
| 6 | Training against role requirement | Required modules completed and in date ÷ required modules, per person, by unit | Learning system; role matrix | Who is overdue, and where |
| 7 | Incident reporting against activity | Incidents reported per unit of activity, by business unit, against the firm median | Incident log; activity volumes | Units that report nothing |
| 8 | Policy attestation | Staff attested within the window ÷ staff required, by policy and unit | Attestation records | Policies nobody has confirmed reading |
| 9 | Time to close findings | Median days from finding to verified closure, by severity and source | Issues log | Whether serious findings close faster than minor ones |
| 10 | Evidence completeness | Tested controls with evidence attached and dated ÷ tested controls | Testing records | Assertions that could not be shown to a regulator |
Every one of these is computed per account, per business unit and owner, and in total, and every one carries an identity that must hold before the table is shown.
Obligations with no control mapped. Reporting starts from the control library, so an obligation that never got a control never appears.
Incident reporting against activity. Raw counts make the busiest, most diligent unit look worst.
Repeat failures. A control that fails, is remediated, and fails again counts as one failure each year.
A register holds 640 obligations. Controls are mapped to 590; of those, 540 have an owner and 470 were tested in the last cycle. Coverage by the strict definition is 73 percent, not the 92 percent usually reported. Of the 50 with nothing mapped, 12 are rated high and 9 of those arrived through regulatory change in the last year. Those 12 are the agenda.
Number of controls. More controls is not more compliance.
Training completion as one firm-wide percentage. It hides the unit at 60 percent and ignores what each role requires.
Incidents reported, as a raw count. Always against activity.
| Table | Must hold |
|---|---|
| Coverage | Obligations = mapped, owned and tested + mapped with a gap + unmapped |
| Testing | Tests due = completed on time + completed late + overdue |
| Issues | Opening issues + raised − closed = closing issues |
| Training | Required = completed in date + expired + never completed |
A table whose identity fails is a table with a row missing or counted twice. It is not shown until it is fixed.
| Measure | Owner | Reviewed |
|---|---|---|
| Issue ageing; testing on schedule | Issue and control owners; head of compliance | Monthly |
| Training; attestation | Unit heads | Monthly |
| Obligation and regulatory change coverage | Head of compliance | Quarterly, and on each regulatory change |
| Incident reporting against activity; repeat failures; evidence | Head of compliance; risk committee | Quarterly |
A measure with no owner is a metric, not a KPI; see KPI versus metric versus measure.
Ten measures from the register, the control library, the testing records and the logs. Start from the obligations, not the controls, and look hardest at what is missing and what is quiet. Covirage computes all of them from the exports compliance teams already produce, files only, with the definitions stated and the identities checked. See Covirage for compliance teams.
Every regulatory obligation in the register should map to at least one control that addresses it, with an owner and a test. Coverage is obligations with a mapped, owned, tested control over all obligations, weighted by risk rating. The list of obligations with nothing mapped is the most important output, and it cannot be seen from the control library alone.
A unit with a tenth of the firm's transactions and none of its incident reports is not ten times safer; it is not reporting. Incidents per thousand transactions, or per head, by unit, against the firm's median, shows where the reporting culture is weak. Low outliers deserve as much attention as high ones.
By owner, against the remediation date originally agreed, with extensions counted. An issue open for two hundred days with three date changes is a different matter from one opened last month. The table by owner shows where findings go to wait.