Skip to main content
Category: Monitoring and Performance

Key Performance Indicator

Also known as: KPI, performance indicator, key performance metric
Simply put

A Key Performance Indicator (KPI) is a quantifiable measure used to track how well an organization, activity, or project is progressing toward its defined goals and objectives. KPIs answer the question of how far along you are in reaching a target, and they need to be measurable rather than subjective. In a monitoring context, they help show whether performance is improving, holding steady, or falling short of expectations.

Formal definition

A KPI is a quantifiable performance measurement tied to strategic objectives and used to evaluate progress or success of an organization, activity, or project against defined goals. KPIs are distinct from individual key metrics, which are the underlying data points; a KPI typically represents a grouped or higher-order measure of performance aligned to an objective rather than a single raw data element. To be usable, a KPI must be quantifiable, which constrains it to what can be measured and excludes purely qualitative judgments unless they are operationalized into measurable form.

Why it matters

In third-party and supply chain risk programs, KPIs translate performance expectations into measurable terms, allowing organizations to track whether a supplier relationship or an internal risk process is progressing toward defined objectives rather than relying on subjective impressions. Because a KPI is quantifiable, it creates a common reference point that risk, procurement, and compliance stakeholders can use to determine whether performance is improving, holding steady, or falling short. This matters most in ongoing monitoring, where the question is not simply whether a supplier passed onboarding but how far along the relationship is in meeting its stated goals over time.

The usefulness of a KPI depends heavily on how it is chosen and defined. A KPI tied to a clear strategic objective can surface deteriorating performance early, while a poorly aligned or purely activity-based measure can create a false sense of assurance. Because KPIs must be quantifiable, they inherently exclude purely qualitative judgments unless those judgments are operationalized into measurable form, which means some important dimensions of supplier performance may be underrepresented if a program relies on KPIs alone.

KPIs should also be distinguished from the underlying data points that feed them. A KPI typically represents a grouped or higher-order measure aligned to an objective, whereas individual key metrics are the raw data elements beneath it. Confusing the two can lead teams to monitor a mass of individual metrics without a clear line of sight to the objective they are meant to inform, or to treat a single raw data point as if it captured overall performance.

Who it's relevant to

Third-Party Risk and Vendor Management Teams
These teams use KPIs to move beyond point-in-time onboarding checks toward ongoing measurement of whether a supplier relationship is meeting defined objectives. Because KPIs must be quantifiable, they help standardize how performance is tracked across a portfolio, though teams should recognize that qualitative concerns not yet operationalized into measurable form may fall outside what KPIs capture.
Procurement and Sourcing Professionals
Procurement functions rely on KPIs to evaluate supplier progress against contractual goals and expectations, distinguishing higher-order performance measures aligned to objectives from the individual key metrics that feed them. This helps avoid monitoring large volumes of raw data points without a clear connection to the outcomes those measures are meant to inform.
Compliance and Assurance Functions
Compliance teams use KPIs to demonstrate whether processes and controls are progressing toward defined targets in measurable terms. They should remain aware that a KPI reflects only what has been operationalized into a quantifiable measure and does not, on its own, capture every dimension of risk or provide independent verification of underlying performance.
Risk and Resilience Leadership
Leaders use KPIs to gauge whether organizational and program-level objectives are being met and whether performance is improving, holding steady, or falling short. Because KPIs answer how far along a process is toward its goals, they support oversight and reporting, but leadership benefits from ensuring each KPI is genuinely tied to a strategic objective rather than to activity that appears measurable but conveys little about outcomes.

Inside KPI

Metric definition
A clearly specified measure tied to a defined objective, stating what is counted, the unit of measurement, and the calculation method so that results are reproducible and comparable over time.
Target or threshold
The expected value, acceptable range, or tolerance against which actual performance is compared. In many third-party programs, thresholds are tiered according to the criticality of the supplier relationship.
Data source and collection method
The origin of the underlying data (for example self-reported attestations, contractual reporting, monitoring feeds, or independent assessments) and how it is gathered. The reliability of a KPI depends heavily on whether its source is independently verified or self-reported.
Measurement frequency
How often the indicator is calculated and reviewed, which may range from continuous monitoring to periodic point-in-time reporting depending on the risk tier and the nature of the metric.
Ownership and accountability
The individual or function responsible for producing, reviewing, and acting on the KPI, along with the escalation path when values breach defined thresholds.
Scope boundary
A statement of what the KPI does and does not measure. A KPI focused on, for example, service availability typically says nothing about a supplier's financial, geopolitical, or ESG risk, and rarely extends visibility beyond the direct third party.

Common questions

Answers to the questions practitioners most commonly ask about KPI.

Is a KPI the same thing as a KRI (Key Risk Indicator)?
No. Although the terms are often used interchangeably, they serve distinct purposes. A KPI typically measures how well a third-party relationship or a TPRM process is performing against expected objectives, such as service levels, remediation timeliness, or assessment completion rates. A KRI is oriented toward signaling exposure to a potential adverse condition before it materializes. A single metric can sometimes function in both roles depending on how it is framed and the threshold applied, but treating performance measurement as equivalent to risk signaling can leave a program blind to emerging exposure that a well-performing operational metric does not surface.
Does meeting all contractual KPIs mean a third party's risk is under control?
Not necessarily. KPIs generally measure defined, agreed-upon aspects of performance, and strong performance against those metrics does not confirm that all material risks are being managed. A supplier can meet service-level and delivery KPIs while carrying unaddressed information security, financial, geopolitical, concentration, or ESG risk that the chosen indicators do not capture. KPIs reflect only what is measured, and they should be read alongside risk assessments and monitoring rather than as a standalone assurance that residual risk is acceptable.
How many KPIs should we track per third party?
There is no universal number, and the appropriate set typically varies by risk tier and the nature of the relationship. In many programs, higher-criticality suppliers warrant a broader and more frequently reviewed set of indicators, while lower-tier relationships may be monitored with a small number of core metrics. The practical constraint is that each KPI should be actionable, tied to a defined objective or threshold, and supported by a reliable data source; tracking metrics that no one reviews or acts on tends to add overhead without improving oversight.
Where should KPIs and their targets be defined in the vendor relationship?
KPIs and their associated thresholds are commonly defined during contracting, frequently within service-level agreements or accompanying schedules, so that measurement criteria, targets, and consequences are agreed before performance is assessed. Defining them at this stage helps establish the data the third party is expected to provide or permit access to. Depending on the program, KPIs may also be reviewed and adjusted over the life of the relationship as objectives, risk tier, or scope of services change.
How often should KPIs be reviewed?
Review frequency typically depends on the risk tier of the relationship and the volatility of what is being measured. In many programs, critical suppliers are reviewed more frequently than lower-tier ones. It is worth noting that a KPI reviewed only periodically reflects performance over its measurement window and may not surface a rapidly emerging issue between review cycles, so review cadence should be matched to how quickly the underlying condition can change and how significant a deviation would be.
What should happen when a third party misses a KPI target?
Effective programs generally define in advance what a missed target triggers, rather than treating a breach as an ad hoc event. Responses can range from documentation and root-cause discussion to escalation, remediation plans, or contractual remedies, depending on the severity and persistence of the shortfall and the criticality of the relationship. A missed KPI is usually best treated as a prompt for investigation, since the metric indicates that a threshold was not met but does not by itself explain the cause or the appropriate corrective action.

Common misconceptions

A KPI and a KRI (key risk indicator) are the same thing.
They serve related but distinct purposes. A KPI typically measures how well an activity or relationship is performing against an objective, whereas a KRI is oriented toward signalling changes in exposure or the likelihood of an adverse event. A metric can function as one, the other, or both depending on how it is used, but conflating them can obscure whether a program is tracking performance or emerging risk.
A green or on-target KPI means the associated third-party risk is under control.
A KPI reflects only what it is defined to measure and only as of its measurement point. A favourable value for one indicator does not address risks outside its scope, and where the underlying data is self-reported rather than independently verified, the result may not reflect actual conditions. Point-in-time KPIs can also become stale between measurement cycles.
More KPIs produce better oversight.
A large volume of indicators can dilute attention, create reporting burden, and mask the few metrics that meaningfully signal changes in performance or risk. In many programs, a smaller set of well-scoped, decision-relevant KPIs is more effective than an extensive dashboard.

Best practices

Tie each KPI to a specific objective and state explicitly what it measures and what falls outside its scope, so stakeholders do not read broader assurance into a narrow metric.
Set thresholds and review frequency according to the risk tier of the third party, applying tighter tolerances and more frequent measurement to critical relationships.
Document the data source for each KPI and distinguish self-reported or attested inputs from independently verified ones, weighting interpretation accordingly.
Define clear ownership and an escalation path so that threshold breaches trigger a defined response rather than sitting unactioned on a dashboard.
Complement point-in-time KPIs with mechanisms that reduce staleness, such as more continuous monitoring for higher-risk suppliers, and note where visibility does not extend beyond the direct third party.
Periodically review the KPI set to retire indicators that no longer inform decisions and to confirm that the remaining metrics still map to current objectives and risk exposures.
Promotional banner for the Penetration Report Template Kit