Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk, Treasury & Financial Control
1Risk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
2Enterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
3Risk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
4Credit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
5Market Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
6Liquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
7Operational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
8Risk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
9Treasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
10Financial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
11Operational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

How to build a KRI Dashboard: Eight Steps to a Usable One

Building a dashboard runs in eight steps: name the decisions it serves, list the risks that bear on them, choose one measure for each, force the mix so it is not all counts, number the set, set each trigger between today and the limit, attach an action or write down that there is none, then test it against the last year and review it annually by removing.

A key risk indicator, and the fact that some indicators move before the loss while most count what has already landed, is covered separately. The craft question comes next, and almost nobody is taught it: given a blank sheet and an institution full of numbers, how is the dashboard actually built, in what order, and what stops it turning into the thing every institution ends up with? Each step taken either adds a row or takes one away, and the order of the steps is what decides which.

Why does the usual way of building one produce a dashboard that grows forever?

Watch how a dashboardA single view of a chosen set of indicators with their status, which is really a list of choices about what to watch. gets built when nobody has a method. Somebody is asked for one. The obvious first move is to go and find out what can be counted, and the list already exists: every system in the institution produces numbers whether anybody reads them or not. Somebody picks the ones that look important. A draft goes round. Three people ask for one more line each. Every one of those requests is entirely reasonable: the number they want is available, it is true, and it is about something that genuinely matters. So the lines go on. Next quarter, three more.

Nobody in that story did anything wrong, and the outcome is reliable for exactly that reason. No argument defeats a number that is available, true and relevant, so starting from what can be measured makes every step after it an addition. The only argument that would work is that the dashboard is already long enough, and nobody has ever won that argument by asserting it. So the dashboard gets to thirty rows, then forty. At forty rows a committee reads the two that are red and skims the rest. The other thirty eight cost something to produce and return nothing at all.

Here is the household version. Most households have built one without calling it that. A household running on one salary keeps an informal watch list: the bank balance, the date the loan instalment goes out, how much is left on the credit card, whether the school fee notice has arrived. Every one of those is a real number and every one of them reports something that has already happened. The number that would actually warn that household is different and harder: how many hours of overtime the earner has been offered this month compared with last, or whether the firm has stopped hiring. Nobody puts that on the fridge: the number is awkward to get and nobody asked for it. The household watch list, like the institutional one, is built from what is easy to see. The whole of the method below is machinery for not doing that.

Derivatives Foundation Bootcamp — Fin Maverick

What are the eight steps, and what does each one do to the length of the dashboard?

Eight steps, numbered KD1 to KD8 so that the rest of this guide can point at them. The sequence matters more than any individual step. Only the first three put anything on the dashboard. KD4 and KD5 fix what is already there. KD6 and KD7 refine each row without changing how many rows there are. KD8 is the only step in the whole method that can make the dashboard shorter than it was last year.

EIGHT STEPS, AND NOTHING IS ADDED TO THE DASHBOARD AFTER STEP THREE The tag on the right of each row says what that step does to the number of rows on the finished dashboard. KD1 Name the decisions the dashboard has to serve which body reads it, and what does that body actually decide STARTS THE LIST KD2 List the risks that bear on those decisions checked against the breach log and the register, never against itself STARTS THE LIST KD3 Choose one measure for each risk one, and the discipline of the step is entirely in that word STARTS THE LIST KD4 Force the mix before agreeing anything count the leading signals and the lagging counts, then read the totals EXCLUDES KD5 Number the set so that sixteen indicators are cited the same way in every paper FIXES THE SET KD6 Set each trigger inside the useful window bounded by today's position at one end and the limit at the other REFINES A ROW KD7 Attach an action, or write the absence down one of the two, on every single row, and there is no third option REFINES A ROW KD8 Test against last year, review by removing run it backwards over a year already recorded, then take lines off SHORTENS Three steps build the list, one cuts it, one fixes it, two refine each row, and one shortens it. That distribution is the method. Vindhya Commercial Bank Limited is invented and every figure used here belongs to it.
Only the first three of the eight steps put anything on the dashboard, one step cuts, two refine a row without adding one, and the annual review in the last step is the single point in the whole sequence where a line can come off.

How are the decisions named, and why is that step one rather than step four?

KD1 Name the decisions the dashboard has to serve

Two questions come first, and their answers go at the top of the blank sheet before anything else does. Which body reads this dashboard? And what does that body decide? Not what it is interested in, not what it would like to know: what it decides. A body that decides nothing does not need a dashboard, it needs a newsletter, and the two are different objects with different lengths.

At Vindhya Commercial Bank Limited, invented, the answer is committee G2, the board risk management committee. The committee has 5 members, 3 of them independent directors, and it meets 6 times a year. The decision set is narrow and specific: committee G2 sets every one of the twelve limits L1 to L12, and it accepts or refuses every breach of them. Nothing else falls to that committee for this purpose. So the decisions this dashboard serves are decisions about limits and about breaches, and any indicator that cannot possibly change one of those two decisions is a candidate for not being on the dashboard at all.

Naming the decision set has already done a great deal. Before a single measure has been chosen, there is a test to apply to every candidate, and the test does not require anybody to argue that a number is unimportant. The only question is whether this particular committee, in this particular meeting, could act on it. The credit officer's arrears report matters enormously and belongs on somebody else's dashboard. Step KD1 is how a dashboard acquires an editor.

Try it out

Why is the first step naming the decisions rather than listing what can be measured?

KD2 List the risks that bear on those decisions, and check the list from outside

Now list the risks that could move one of those decisions. Everybody thinks they have done this step, and it is almost always done wrong. The natural way to do it is to sit in a room and think of risks. A room full of the institution's own people will produce a list of the risks the institution already talks about, and the risks the institution actually has are a different list.

So the list is built the other way round. Three records already exist that nobody invented for this purpose, and the list is checked against them one at a time: the breach log, the risk register, and the loss log. The check is mechanical. For every open breach, is there an indicator? For every red entry on the register, is there an indicator? For every category of loss the institution booked last year, is there an indicator?

Run that check on this bank and something falls out on the first pass. Three limits are in live breach at month 12: L3 sector concentration at 108.3 per cent of its cap, L10 the wholesale funding share at 112.8 per cent, and L12 depositor concentration at 120.8 per cent. The dashboard carries two reds. Two of the three open breaches have an indicator; the wholesale funding share does not appear on the dashboard at all. The bank's dependence on wholesale funding has been over its own limit since month 11, sitting at 22.6 per cent of total liabilities against a limit of 20.0 per cent, and every board paper that reproduced it reproduced a dashboard on which that fact could not appear. An indicator that was never chosen produces no colour, so no amount of careful reading of the finished dashboard can ever find it.

STEP KD2, RUN AS A CHECK AGAINST A RECORD THE DASHBOARD DID NOT PRODUCE Every open breach on the left is asked one question: is there an indicator on the right that would have shown it coming? THE BREACH LOG, THREE OPEN AT MONTH 12 THE DASHBOARD, SIXTEEN INDICATORS B1 sector concentration 108.3 per cent of limit L3, open since month 5 B3 wholesale funding share 112.8 per cent of limit L10, open since month 11 B4 top twenty depositor share 120.8 per cent of limit L12, open since month 10 K1 sector concentration on the dashboard, and showing red at month 12 NOT ON THE DASHBOARD no indicator at all so it can produce no colour, ever K2 top twenty depositor share on the dashboard, and showing red at month 12 TWO OF THREE OPEN BREACHES HAVE AN INDICATOR. THE THIRD IS INVISIBLE FROM INSIDE THE DASHBOARD. Every limit, breach, indicator and percentage here belongs to the invented Vindhya Commercial Bank Limited and to nobody else.
Checking the indicator list against the breach log finds at once that the wholesale funding share is in live breach at 22.6 per cent against a 20.0 per cent limit and carries no indicator, which the finished dashboard could never have revealed.
Try it out

Checking the indicator list against the breach log shows the wholesale funding share in breach and on no indicator. Why could that not have been found by reading the dashboard itself, however carefully?

KD3 Choose one measure for each risk, and mean the word one

For each risk on the list, a single measure is chosen. Two measures of the same risk always look better than one, so the whole difficulty of this step lives in the word one. Take depositor concentration. One measure is the top twenty depositors as a share of deposits. Another is the largest single depositor as a share of deposits. A third is the number of depositors above a chosen size. All three are informative, all three move together most of the time, and adopting all three turns one risk into three rows.

Do that across a list of sixteen risks and the result is a dashboard of forty. Two measures of one risk is not twice the information, it is one piece of information reported twice, plus the standing possibility that the two disagree and nobody knows which to believe. Where the choice genuinely cannot be made, that is a signal about the risk rather than about the measures: what the risk actually is has not yet been decided. The fix is to split it into two risks, name them separately, and give each one a measure. The list gets one row longer and much clearer. Splitting a risk in two is a different transaction from adding a second view of the same thing.

Breaking Into Quants Bootcamp — Fin Maverick

How is the mix forced so the dashboard is not two thirds counts?

KD4 Count the leading and the lagging before agreeing the list

Step KD4 separates a dashboard from a history. The mixThe split between leading signals and lagging counts on a dashboard, which decides whether it warns or only explains. is the split between indicators that move before the loss and indicators that count the loss after it has landed, and the reason it has to be a deliberate step is that nobody ever chooses a lagging count on purpose. Lagging counts accumulate. Loss events booked, complaints received, breaches recorded, issues past their date: every one of those is clean, available, auditable and unarguable, and every one of them is a report on a month that has finished.

The test is a single question, asked of each candidate row. When this number moves, has the thing it stands for already happened? If yes, it is a count. If no, it is a signal. The question has to be answered honestly. The temptation is to argue that a count is really a signal on the grounds that a rise in it predicts more of the same. Sometimes that is even true, and it is still a count.

Then do the arithmetic. Almost nobody does that part. Run the test across this bank's sixteen indicators and eleven of them answer yes: they are counts. Five answer no. Eleven of sixteen is 68.8 per cent lagging and five of sixteen is 31.3 per cent leading. Now look at the colours beside the split. The count stops being a statistic at that point. All five of the leading indicators are green and both of the reds are counts, so the part of the dashboard that could have warned about anything is entirely quiet and the part that is shouting is reporting things that have already happened. Nobody at this bank noticed, and the reason nobody noticed is that nobody had counted. A colour reports one row. Only a count reports the dashboard.

STEP KD4, AND THE COUNT IS THE FINDING RATHER THAN ANY ONE COLOUR Sixteen indicators of one invented bank, sorted into the two kinds and then counted. ELEVEN LAGGING COUNTS, K1 TO K11, AND BOTH REDS ARE HERE K1RED K2RED K3AMBER K4AMBER K5AMBER K6AMBER K7AMBER K8GREEN K9GREEN K10GREEN K11GREEN FIVE LEADING SIGNALS, K12 TO K16, AND EVERY ONE OF THEM IS GREEN K12GREEN K13GREEN K14GREEN K15GREEN K16GREEN THE MIX, COUNTED BEFORE ANYTHING ELSE IS AGREED 11 OF 16 ARE LAGGING COUNTS, 68.8 PER CENT 5 LEADING, 31.3 PER CENT The two reds and the eleven lagging counts are locked by this invented bank's own record. The colours on K3 to K11 are this guide's assignment against that record's locked totals and the bank's own invented triggers, and no figure here is a fact about any real bank.
Eleven of the sixteen indicators are lagging counts and five are leading, and all five leading ones are green while both red indicators are counts, so the dashboard reports the past loudly and says nothing about what is coming.
Try it out

How is the mix forced, and what does the test look like in practice?

Why does a set of sixteen have to be numbered at all?

KD5 Number the set, and do it before the first paper is written

Numbering the set looks like clerical housekeeping and it is not. An unnumbered set has no stable way of being referred to, so every document that mentions it invents its own way. One paper calls a row the depositor concentration indicator. The next calls it top twenty depositor share. A third calls it funding concentration. Funding concentration is actually a different measure on the liability side. Within a year, two committee papers disagree about which indicator went amber in which month. Neither of them is wrong: neither ever agreed what the indicators were called.

Numbering costs one afternoon, it never has to be done again, and it makes every later citation checkable by anybody who was not in the room. The bank counted its indicators and never numbered them. The sixteen are therefore set out below as K1 to K16, a numbering supplied so that the rows below can be pointed at rather than described. The missing numbering is the exact failure step KD5 exists to prevent, demonstrated on the very set it is being applied to.

NumberWhat it measures at Vindhya Commercial Bank LimitedKindStatus
K1Sector concentration against limit L3laggingRed
K2Top twenty depositor share against limit L12laggingRed
K3Net operational loss over a rolling twelve months against limit L11laggingAmber
K4Share of open issues past their agreed remediation date, 31 of 92laggingAmber
K5Open issues aged beyond 365 days, of which there are 9laggingAmber
K6Backtesting exceptions in the last 250 days, of which there were 7laggingAmber
K7Single name exposure utilisation on limit L1, at 94.5 per centlaggingAmber
K8Customer complaints closed in the monthlaggingGreen
K9Operational loss events recorded in the monthlaggingGreen
K10Near misses recorded in the monthlaggingGreen
K11Trading book value at risk utilisation on limit L5, at 86.7 per centlaggingGreen
K12Attrition in the dealing roomleadingGreen
K13The age profile of open privileged access rightsleadingGreen
K14The share of manual journal entries at closeleadingGreen
K15Exceptions approved by the same person who raised themleadingGreen
K16The certificate of deposit roll rateleadingGreen
16Eleven lagging counts and five leading signals11 and 59 green, 5 amber, 2 red

One row on that table shows how easily a set can double count itself. K16, the certificate of deposit roll rate, is the same measurement as W2 on this bank's separate list of seven early warning indicators. One measurement, two lists, two different jobs: on the dashboard it reports a position to a committee, and on the warning list it has a trigger and an action attached to it. The duplication is not an error in the bank's records. The overlap is the cleanest demonstration available that the difference between the two objects has nothing to do with the measurement and everything to do with what is attached to it.

Try it out

Why does the method include a whole step for numbering the set?

Where does each trigger sit, and what bounds the choice at both ends?

KD6 Set each trigger inside the window that actually exists

Every row now needs a level at which its colour changes. The instinct is to argue about what the right level is, in the abstract, for hours. The method replaces that argument with a construction. Find the two hard edges, and only then choose inside them.

The lower edge is where the measure stands today. The upper edge is the limit, or whatever level the institution will not tolerate crossing. The space between them is the trigger windowThe range between today's position and the limit, being the only part of the scale where a trigger can do anything useful., and it is the only part of the whole scale where a trigger does any work at all. Set the trigger below the lower edge and the indicator is amber on the day it is written. A committee learns within two meetings that the colour means nothing. Set it at the upper edge and the trigger fires at the moment the limit is crossed. Firing then is not a warning at all: it is a breach report with a colour put on top of it.

Work it on K3, this bank's net operational loss over a rolling twelve months. The measure stands at Rs 43.8 crore. Limit L11 is Rs 60.0 crore, the bank's own cap and not anybody's requirement. So the window runs from Rs 43.8 crore to Rs 60.0 crore and it is Rs 16.2 crore wide, or 27.0 per cent of the limit. Every useful trigger for this indicator lives inside that Rs 16.2 crore, and the argument about exactly where inside it is a far smaller argument than the one people usually have. The window also shows something the level alone never would: an indicator whose window is almost nothing is an indicator sitting on top of its limit, and it is going to be amber permanently whatever anybody does. A window that narrow is worth knowing about before the dashboard is printed.

STEP KD6 ON INDICATOR K3, NET OPERATIONAL LOSS OVER A ROLLING TWELVE MONTHS Two hard edges first, then the choice inside them. Both edges destroy the indicator, and they do it in different ways. TODAY Rs 43.8 crore LIMIT L11 Rs 60.0 crore ALREADY RUNNING, Rs 43.8 CRORE OF NET OPERATIONAL LOSS USEFUL WINDOW Rs 16.2 CRORE Rs 0 A TRIGGER SET BELOW TODAY is amber on the day it is written, and it stays amber, so it reports the present and it warns nobody at all. A TRIGGER SET AT THE LIMIT fires at the moment the limit is crossed, which is a breach report with a colour put on top of it. The scale runs from Rs 0 crore at the left edge to limit L11 at the right edge, and that cap is the invented bank's own. Rs 16.2 crore is 27.0 per cent of the Rs 60.0 crore limit, so this indicator has a wide window and plenty of room to choose in. Every figure here belongs to the invented Vindhya Commercial Bank Limited and none of it is a requirement of any kind.
On indicator K3 the window runs from today's Rs 43.8 crore to limit L11 at Rs 60.0 crore and is Rs 16.2 crore wide, and a trigger outside it is either amber from birth or a breach report wearing a colour.

What is attached to each row, and what is written when nothing is attached?

KD7 Attach an action, or write the absence down, and there is no third option

Here is the step that changes what a dashboard is. Beside every row, there is a cell that asks what happens when this colour changes. An attached actionWhat happens when a trigger is crossed, written down in advance, so that crossing it starts something rather than merely being noticed. fills that cell with something specific: this paper goes to that committee within that many working days, or this position stops being added to until somebody has approved it. An indicator with an action is a warning. An indicator without one is a measurement, and a measurement is not a bad thing to have, it is simply a different object.

The step is not that every row needs an action. Several of this bank's sixteen genuinely do not, and forcing an action onto them would produce a dashboard of ceremonial escalations that everybody learns to ignore inside two quarters. The step is that every row needs either an action or an explicit sentence saying there is none. The explicit sentence is the written absenceAn explicit statement that no action is attached to an indicator, which is what stops a reader assuming that one exists., and it is one line of text that costs nothing and changes behaviour immediately.

Why does it change behaviour? Because a committee sitting in front of an amber row will assume something happens. Not because anybody told them so, but because a colour in a risk paper carries an implied promise, and nobody ever announces that the promise is not there. So the amber sits for four meetings, everybody assumes it is in hand somewhere, and it is nowhere. An unwritten absence is indistinguishable from an unkept promise, and the whole of step KD7 is the machinery for telling the two apart. At this bank, not one of the sixteen carries an action, and not one of the sixteen says so either.

ONE SENTENCE IS THE WHOLE OF STEP KD7 Same indicator, same colour, same month. The only thing that changes is the last cell on the row. THE ROW AS THE COMMITTEE SEES IT TODAY INDICATOR WHAT IT MEASURES STATUS WHAT HAPPENS NEXT K4 the share of open issues past their agreed date AMBER nothing is written here THE SAME ROW WITH ONE SENTENCE ADDED INDICATOR WHAT IT MEASURES STATUS WHAT HAPPENS NEXT K4 the share of open issues past their agreed date AMBER no action attached, this row reports a position The invented bank's own row, reproduced twice. An unwritten absence and an unkept promise look identical on a dashboard.
An indicator row that reads amber, no action attached, reports a position tells a committee something true, and the same row without that phrase quietly invites everybody to assume that a colour change starts something.
Try it out

Several indicators genuinely do not need an action attached. What does step KD7 require for those?

The failure is step KD7, and the arithmetic of fixing it is smaller than it sounds

Count everything this bank measures and reports as a risk signal. Sixteen key risk indicators K1 to K16, none of which carries an action. Seven early warning indicators W1 to W7, every one of which carries a defined action against a defined trigger. The two lists together hold 23 entries, of which 7 promise anything at all. Seven of twenty three is 30.4 per cent. A little under a third of everything this bank watches actually undertakes to start something when it moves.

Now attach actions one at a time and watch what happens. The step stops looking like a heavy project at once. Give two indicators an action and coverage goes to 9 of 23, being 39.1 per cent. The two to do first pick themselves: K1 and K2 are the two reds. Give four an action and it is 11 of 23, being 47.8 per cent. Give five and it is 12 of 23, being 52.2 per cent. Five is the first whole number that takes this bank past half: half of 23 needs 11.5 and there is no such thing as half an indicator. Give nine and it is 16 of 23, being 69.6 per cent.

Five rows. Five rows is the size of the job that takes an institution from under a third to over a half, and the reason it never gets done is that nobody has ever written the arithmetic down. For the rows that do not warrant an action, the fix is one sentence each, cheaper still. The counting has one honesty note attached to it: 23 is a count of entries across two lists, and one measurement appears on both. K16 and W2 are the same certificate of deposit roll rate wearing two different hats.

Indicators given an actionMeasures carrying an actionCoverageNote
07 of 2330.4 per centwhere the bank stands at month 12
29 of 2339.1 per centthe cheapest first move, being the two reds
411 of 2347.8 per centstill under half
512 of 2352.2 per centthe first whole number past half
916 of 2369.6 per centa little over two thirds
1623 of 23100.0 per centevery measure promises something
Try it out

The bank holds 23 measures and 7 of them carry a defined action. How many of the sixteen key risk indicators would need an action to take the bank past half?

Play with it

Turn measurements into warnings, one indicator at a time

One control: how many of the sixteen key risk indicators are given a defined action, from none to all sixteen. The seven early warning indicators W1 to W7 already carry one and never change. The chips redraw, the coverage bar moves, and the bar turns dark the moment coverage passes half of the 23. The default is where this bank actually stands.

NONE0 INDICATORS GIVEN AN ACTIONALL SIXTEEN
TWENTY THREE MEASURES ON TWO LISTS, AND WHAT EACH ONE PROMISES W1 to W7 are the early warning indicators and each already has a trigger and an action. K1 to K16 are the dashboard. THE SEVEN WARNINGS, FIXED, AND THE SIXTEEN INDICATORS, SET BY THE CONTROL W1ACTION W2ACTION W3ACTION W4ACTION W5ACTION W6ACTION W7ACTION K1NO ACTION K2NO ACTION K3NO ACTION K4NO ACTION K5NO ACTION K6NO ACTION K7NO ACTION K8NO ACTION K9NO ACTION K10NO ACTION K11NO ACTION K12NO ACTION K13NO ACTION K14NO ACTION K15NO ACTION K16NO ACTION ACTION COVERAGE ACROSS THE 23 HALF OF THE 23 30.4 per cent NOT YET HALF This measures coverage and not usefulness. Attaching an action to an indicator does not make it a good indicator, and a bank that attached a meaningless action to all sixteen would read 100 per cent here and be no better off than it was before. Vindhya Commercial Bank Limited is invented and the 16 measurements and 7 warnings are its own position at month 12.
Measures with an action
7 of 23
Action coverage
30.4 per cent
Still measurements
16 of 16

With 0 of the sixteen indicators given a defined action, 7 of the bank's 23 measures carry one, being 30.4 per cent, and 16 are still measurements.

Educational illustration. Invented figures throughout. Vindhya Commercial Bank Limited, its sixteen key risk indicators, its seven early warning indicators and the fact that none of the sixteen carries an action are all that bank's own position at month 12. The limit of the model is stated on the drawing: this control measures coverage and not usefulness. The 30.4 per cent above is action coverage across 23 measures and it is not the 30.8 per cent of incidents preceded by a warning, a figure that counts events out of 13.
Debt Capital Markets Bootcamp — Fin Maverick

What does the whole method look like run end to end on one bank?

Take the eight steps and put them against what Vindhya Commercial Bank Limited actually built. The gap between the two is the useful part. KD1: the dashboard goes to committee G2, the body that sets every limit and accepts or refuses every breach, so the decisions are about limits and breaches, and that much the bank clearly did. KD2: checked against the breach log, one of three open breaches has no indicator. KD3: one measure per risk, and this bank held that line, so the dashboard is sixteen rows rather than forty. KD4: not done, and the count is 11 lagging against 5 leading. KD5: not done, so the sixteen had to be numbered above. KD6: triggers exist and the windows are workable, K3 having Rs 16.2 crore of room. KD7: not done on any of the sixteen. KD8: not done at all.

Four of the eight steps were done and four were not, and the four that were skipped are the four that turn a list of numbers into something a committee can act on. Two figures come out of the skipped steps and they land uncomfortably close together, so the two need naming apart before anything else. Action coverageThe share of an institution's measures that carry a defined action against a defined trigger. is 30.4 per cent, or 7 of the 23 measures the bank holds. The foresight rateThe share of a period's incidents preceded by a warning, which is the only external test of a dashboard. is 30.8 per cent, or 4 of the 13 incidents of the year. The two figures sit 0.4 percentage points apart, they count entirely different sets of entirely different things, and no arithmetic whatever connects them.

TWO FIGURES 0.4 PERCENTAGE POINTS APART, AND NOTHING CONNECTS THEM Name the set every time. One counts measures out of twenty three, the other counts events out of thirteen. ACTION COVERAGE 30.4 per cent 7 of 23 measures carry a defined action the set is the 23 measures this bank holds it says nothing about whether they work INCIDENT FORESIGHT 30.8 per cent 4 of 13 incidents were preceded by a colour the set is the 13 incidents of the year it says nothing about how many measures exist NO ARITHMETIC WHATEVER CONNECTS THE TWO. THE NEAR MATCH IS A COINCIDENCE OF SMALL COUNTS. Both figures belong to the invented Vindhya Commercial Bank Limited and neither describes any real institution.
Action coverage of 30.4 per cent counts measures that promise something out of twenty three, incident foresight of 30.8 per cent counts events preceded by a colour out of thirteen, and nothing joins them.
Try it out

Action coverage is 30.4 per cent and incident foresight is 30.8 per cent. What is the relationship between them?

How is a dashboard tested before anybody has to rely on it?

KD8 Run it backwards over a year already recorded

Almost every dashboard in existence has been evaluated exactly once, by the people who chose the indicators, at the moment they chose them. A single evaluation by the authors is not a test, it is an opinion. The test is cheaper than the opinion and it takes an afternoon.

Here is the dashboard backtestRunning a finished dashboard against a past period to see how many of that period's events it would have preceded. in full. The backtest runs on a period that has already happened, ideally the last twelve months, and on the list of things that actually went wrong in it: the loss events, the breaches, the incidents. For each one, the month before it happened is examined to see whether any indicator on the finished dashboard was amber or red at that point on something connected to it. The yes answers are counted and divided by the number of events. The resulting share is what the dashboard would have delivered, and it is the only figure about a dashboard that comes from outside the dashboard.

Run it on this bank. Thirteen operational risk incidents were recorded in the twelve months. Four of them were preceded by an amber or a red indicator. Four of thirteen is 30.8 per cent, so nine of thirteen, being 69.2 per cent, arrived with the dashboard showing nothing relevant at all. Nine of the year's thirteen incidents walked in on a dashboard that was, as far as they were concerned, entirely quiet. Nine unheralded incidents are not a scandal, and they do not mean the sixteen indicators are worthless. The dashboard is worth about three in ten, a fact the institution now has and did not have before, and one it can measure again next year to see whether the changes made did anything.

STEP KD8, THE DASHBOARD RUN BACKWARDS OVER A YEAR THAT HAS ALREADY HAPPENED Thirteen operational risk incidents of one invented bank. Four were preceded by an amber or a red indicator on the dashboard. The record counts four and does not say which four, so the cells below are positions in the year, not named incidents. THIRTEEN INCIDENTS, AND WHAT THE DASHBOARD WAS SHOWING THE MONTH BEFORE EACH 1WARNED 2WARNED 3WARNED 4WARNED 5NOTHING 6NOTHING 7NOTHING 8NOTHING 9NOTHING 10NOTHING 11NOTHING 12NOTHING 13NOTHING WHAT THE FINISHED DASHBOARD WAS WORTH OVER ONE YEAR 4 OF 13, 30.8 PER CENT 9 OF 13 ARRIVED WITH NOTHING SHOWING, 69.2 PER CENT The test needs no new data and no new system. It needs the loss log, the finished dashboard and one afternoon. Every count here belongs to the invented Vindhya Commercial Bank Limited and describes no real institution.
Run the sixteen indicators against the thirteen incidents of the year and four were preceded by an amber or a red, being 30.8 per cent, so nine arrived with nothing showing at all.
Try it out

How is a dashboard tested before anybody has to rely on it?

Writing an Investment Thesis — free micro-course from Fin Maverick

What does the annual review actually remove?

The second half of step KD8 is the review, and it is the only point in the entire method where the dashboard can get shorter. Being precise about the review is worth the effort: there are two ways to run one and only one of them does anything.

The way that does nothing is to go through the rows and ask, for each, whether it is still relevant. The answer will be yes. The yes holds for every row, every year, forever. Relevance was the test the row passed to get on the dashboard in the first place, and nothing has happened since to make sector concentration or operational loss irrelevant. A relevance review is a ceremony that ends with the dashboard one row longer, and somebody always brings a suggestion.

Review by removalAn annual pass that takes lines off a dashboard on the evidence that nobody used them, being the only step that shortens it. asks a different question, and the difference is that the new question has an evidence trail behind it. Who used this row in the last twelve months, and what did they do because of it? Then go and look: the minutes, the papers, the escalations. A row that nobody cited, that changed no colour anybody discussed and that started nothing comes off. Not because it is unimportant, but because twelve months of evidence says it is not being used. A row nobody reads is worse than no row at all: it costs production time and it dilutes the rows that are read.

The everyday version again. A person who keeps a list of eleven things to check every month, and who has genuinely looked at three of them, does not have a list of eleven. The real list is three, plus eight lines of decoration, and the honest move is to write down the three. The institutional version is identical, except that the eight lines have owners who will defend them. The evidence question matters so much for that reason: it is very hard to argue with minutes.

Try it out

Which of the eight steps is the only one that makes the dashboard shorter?

Rebalancing: When, Why and What It Costs teaches you to choose a rebalancing rule and say what it buys and what it costs.

Who actually picks up a dashboard built this way, and what do they do with it?

Four different readers put the same dashboard to four different uses, and the method above serves each of them differently. Seeing that explains why the steps are ordered as they are.

The independent director sits on a committee G2 of five members that meets six times a year, with a papers pack running to dozens of printed sides before the dashboard is reached. The independent director needs triage rather than information: which rows changed, and which of those start something. Steps KD5 and KD7 are entirely for that reader. Numbering lets them say a sentence about K4 that everybody in the room understands identically. The written absence lets them stop wondering whether the amber on K4 has been picked up by somebody: the row says it has not.

The head of internal audit reads the same dashboard for a completely different reason: to test whether the institution's monitoring works. The step that reader cares about is KD8. The foresight rate is the only figure on the whole subject that is not self assessed. Nine incidents out of thirteen arriving unheralded is an audit finding waiting to be written, and it can be written from records the institution already keeps.

A credit analyst at another institution, sizing up this bank as a counterparty rather than as an employer, cannot see the dashboard at all. But the analyst can ask a version of the KD2 question at a meeting, and it is simply this: the annual report shows three open limit breaches, so how many of them appear on the dashboard the board risk committee reads? The answer, and the speed of the answer, is informative in itself.

The mechanism does not change with scale, so here is the household version again. A person running a small shop watches the till total every evening, a count of a day that is over. The leading signal is different and less comfortable: how many regulars they have not seen this fortnight, or how many days the supplier has been slow. Attaching an action is the same move at that scale too. Two slow supplier deliveries in a month means ring the second supplier, not merely notice it, and writing that sentence down is what turns the noticing into something that happens.

What does this method not decide?

A method with eight numbered steps invites being read as a standard, and it is not one, so the size of the claim is worth stating. The eight steps are one workable shape for the work, and other shapes exist. No count of indicators is right in itself: twelve, sixteen and twenty five are all defensible, and the level of any trigger is the institution's own choice.

Three things in particular the method does not do. The method does not establish whether an indicator is any good: coverage is not usefulness, and an institution that attached a hollow action to every row would score perfectly on step KD7 and be no better informed. The method does not settle what the right mix is: it forces the mix to be counted and the number to be looked at, a different and more modest claim. And it cannot make a committee act: a dashboard that starts something only starts it if somebody in the room does the thing. The method undertakes something narrower and still worth having: every row on the finished dashboard can be traced to a decision somebody actually takes, and nobody has to guess what a colour means.

India

What is named here, and where the binding version lives

Every indicator, trigger, limit, colour, count and percentage belongs to Vindhya Commercial Bank Limited, and each of them is that bank's own internal choice rather than anybody's requirement. No supervisor sets the number of indicators an institution keeps, the level of a trigger, the mix or the reporting frequency; the institution sets all four for itself.

Where an international expectation sits behind any of this, it comes from the Basel Committee on Banking Supervision at the Bank for International Settlements, at bis.org, publisher of the principles for risk data aggregation and risk reporting. Those principles are about usefulness, accuracy and timeliness rather than the contents of any particular report, and nobody prescribes a dashboard.

An Indian bank's actual obligation to compute, report and place figures before its board comes from the Reserve Bank of India, at rbi.org.in, and the text there is the only version that binds. Any requirement should be confirmed at that source before it is relied on.

The definition of a key risk indicator, and what makes one leading rather than lagging, comes earlier and is assumed here. Early warning indicators, their triggers and the band between a trigger and a limit are covered separately. The risk report itself, its line items and what a committee is entitled to receive are covered separately too, and a report and a dashboard are different instruments. Risk monitoring as an activity belongs to the enterprise risk treatment. Every underlying exposure the indicators measure, credit, market, liquidity and operational, is taught where it belongs and is only named here as something being indicated. Committee mandates, reporting lines and who is entitled to see what are governance subjects and are covered there.
Risk Management Program Bootcamp — Fin Maverick

Sources

SourceDocumentSite
Reserve Bank of IndiaWhat an Indian bank must actually compute, report and place before its board, and what binds it on risk management arrangementsrbi.org.in
Bank for International SettlementsThe Basel Committee principles for risk data aggregation and risk reporting, and the expectation that reporting is useful and timelybis.org

Vindhya Commercial Bank Limited is invented.
Educational material. Not advice on any investment, tax, budget or market position.

Framework

Other frameworks in Risk Reporting, Data and Model Risk

Framework

How to run Model Validation: Seven Steps and a Written Report

← Previous
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.