KPI/KRI Definitions

Tier 2 MONITOR

What This Requires

Define KPIs (performance, adoption, efficiency) and KRIs (security incidents, compliance violations, drift events) for AI governance. Set targets and thresholds. Track monthly and report to leadership quarterly.

Why It Matters

What gets measured gets managed. KPIs/KRIs provide objective metrics for governance effectiveness and enable data-driven prioritization.

How To Implement

Define KPIs

Performance: model accuracy, latency p99, SLA uptime. Adoption: active users, queries/day. Efficiency: cost per query, retraining frequency.

Define KRIs

Security: prompt injection attempts, data leakage incidents. Compliance: policy violations, audit findings. Reliability: drift events, incident count, MTTR.

Set Targets & Thresholds

KPIs: targets (e.g., accuracy >95%). KRIs: thresholds (e.g., <5 incidents/month). Define green/yellow/red zones.

Track & Report

Collect metrics monthly. Plot trends over time. Report to leadership quarterly with commentary (what's improving, what's concerning, why).

Evidence & Audit

  • KPI/KRI definitions document
  • Targets and thresholds per metric
  • Monthly tracking data (spreadsheet, dashboard)
  • Quarterly leadership reports
  • Trend analysis and commentary

Related Controls