Sign in

Blog · Board and management reporting · Compliance

KPIs for compliance teams: ten measures that matter, each with its formula and the export it comes from

The ten KPIs a compliance function should run on, each with its formula, the export it comes from and what it tells you: obligation to control coverage, regulatory change coverage, control testing on schedule, test failure rate and repeat failures, issue ageing by owner, training completion against role requirement, incident reporting against activity, policy attestation, time to close findings, and evidence completeness. Also the three measures most compliance teams miss, the figures to drop, the identities, and who owns what.

The short answerA compliance function should run on ten measures: coverage of obligations by mapped controls; coverage of new regulatory change by controls within a stated time; control testing completed on schedule; test failure rate, with repeat failures separated; open issue ageing by owner against remediation dates; training completion against what each role requires; incident reporting set against business activity; policy attestation; time to close findings by severity; and evidence completeness for tested controls. They come from the obligations register, the control library, the testing schedule and results, the issues log, the learning system and the incident log. The three most often missed are obligations with no control mapped at all, because reports cover the controls that exist; incident reporting against activity, because the unit reporting nothing is rarely the safest; and repeat failures, which show remediation that did not work.

A compliance function is judged on what it can evidence. The measures that matter show which obligations have a control behind them, which controls were tested and passed, which findings are ageing with whom, and which units are suspiciously quiet.

The ten measures

# Measure Formula Export What it tells you
1 Obligation to control coverage Obligations with a mapped, owned and tested control ÷ obligations, weighted by risk rating Obligations register; control library Obligations with nothing behind them
2 Regulatory change coverage New or changed obligations with a control mapped within the stated days ÷ new or changed obligations Regulatory change log; control library Whether the register keeps up
3 Testing on schedule Control tests completed by due date ÷ tests due, by risk rating Testing schedule Controls that slipped, highest risk first
4 Failure rate and repeat failures Tests failed ÷ tests completed; failures on controls that failed the prior test Test results Remediation that did not work
5 Issue ageing by owner Open issues past remediation date, by owner, days overdue, number of extensions Issues log Where findings wait
6 Training against role requirement Required modules completed and in date ÷ required modules, per person, by unit Learning system; role matrix Who is overdue, and where
7 Incident reporting against activity Incidents reported per unit of activity, by business unit, against the firm median Incident log; activity volumes Units that report nothing
8 Policy attestation Staff attested within the window ÷ staff required, by policy and unit Attestation records Policies nobody has confirmed reading
9 Time to close findings Median days from finding to verified closure, by severity and source Issues log Whether serious findings close faster than minor ones
10 Evidence completeness Tested controls with evidence attached and dated ÷ tested controls Testing records Assertions that could not be shown to a regulator

Every one of these is computed per account, per business unit and owner, and in total, and every one carries an identity that must hold before the table is shown.

The three most compliance teams miss

Obligations with no control mapped. Reporting starts from the control library, so an obligation that never got a control never appears.

Incident reporting against activity. Raw counts make the busiest, most diligent unit look worst.

Repeat failures. A control that fails, is remediated, and fails again counts as one failure each year.

A worked line

A register holds 640 obligations. Controls are mapped to 590; of those, 540 have an owner and 470 were tested in the last cycle. Coverage by the strict definition is 73 percent, not the 92 percent usually reported. Of the 50 with nothing mapped, 12 are rated high and 9 of those arrived through regulatory change in the last year. Those 12 are the agenda.

What to drop

Number of controls. More controls is not more compliance.

Training completion as one firm-wide percentage. It hides the unit at 60 percent and ignores what each role requires.

Incidents reported, as a raw count. Always against activity.

The identities

Table Must hold
Coverage Obligations = mapped, owned and tested + mapped with a gap + unmapped
Testing Tests due = completed on time + completed late + overdue
Issues Opening issues + raised − closed = closing issues
Training Required = completed in date + expired + never completed

A table whose identity fails is a table with a row missing or counted twice. It is not shown until it is fixed.

Who owns what

Measure Owner Reviewed
Issue ageing; testing on schedule Issue and control owners; head of compliance Monthly
Training; attestation Unit heads Monthly
Obligation and regulatory change coverage Head of compliance Quarterly, and on each regulatory change
Incident reporting against activity; repeat failures; evidence Head of compliance; risk committee Quarterly

A measure with no owner is a metric, not a KPI; see KPI versus metric versus measure.

Go deeper

The short version

Ten measures from the register, the control library, the testing records and the logs. Start from the obligations, not the controls, and look hardest at what is missing and what is quiet. Covirage computes all of them from the exports compliance teams already produce, files only, with the definitions stated and the identities checked. See Covirage for compliance teams.

Questions people ask

What is obligation to control coverage?

Every regulatory obligation in the register should map to at least one control that addresses it, with an owner and a test. Coverage is obligations with a mapped, owned, tested control over all obligations, weighted by risk rating. The list of obligations with nothing mapped is the most important output, and it cannot be seen from the control library alone.

Why set incident reports against activity?

A unit with a tenth of the firm's transactions and none of its incident reports is not ten times safer; it is not reporting. Incidents per thousand transactions, or per head, by unit, against the firm's median, shows where the reporting culture is weak. Low outliers deserve as much attention as high ones.

How should issue ageing be read?

By owner, against the remediation date originally agreed, with extensions counted. An issue open for two hundred days with three date changes is a different matter from one opened last month. The table by owner shows where findings go to wait.