---
sourceDocument: Brazil Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/governance-risk-compliance

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# GRC: Metrics in Integrated Risk Management

# GRC: Metrics in Integrated Risk Management {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of GRC: Metrics in Integrated Risk Management

Risk metrics in Integrated Risk Management (IRM) are quantifiable measures used to track and assess the status and exposure of specific risks over time.
They provide continuous visibility into risk and control performance, enabling organizations to monitor changes, detect trends, and support timely decision-making.
Metrics serve as an early warning system by highlighting deviations before operational losses occur, thus enhancing risk monitoring, reporting, and governance.
Show full answer Show less  

## Key Features

* **Quantifiable Measures:** Metrics capture data in various forms such as numbers, percentages, or monetary amounts, unlike indicators which support only pass/fail results.
* **Enhanced Escalation and Notification:** Metrics facilitate better communication by enabling alerts and notifications to designated data owners.
* **Standardized Risk Oversight:** They support consistent risk governance through uniform measurement and reporting practices.
* **Types of Metrics:**
  * **Key Risk Indicators (KRIs):** Measure exposure to specific risks, e.g., number of IT hack attempts.
  * **Key Control Indicators (KCIs):** Assess the effectiveness of controls mitigating risks.
  * **Key Performance Indicators (KPIs):** Reflect how well risk exposure is managed against objectives.
* **Difference from Indicators:** Indicators are primarily binary (pass/fail) and used for automated control tests, while metrics can be quantitative or qualitative and monitor broader GRC objects.

## Practical Use for ServiceNow Customers

The GRC: Metrics application in ServiceNow IRM allows risk teams to measure, monitor, and analyze risk data effectively. By using predefined risk metrics, teams can track operational risk exposure across business units, visualize data on dashboards, and prioritize remediation efforts based on trends and exceptions. This capability supports informed decision-making and strengthens risk governance by providing actionable insights into risk and control performance.  
Risk metrics are defined as a quantifiable measure that is used to track and assess the status of a specific risk. Metrics help in tracking the exposure of a risk over time.

Metrics are quantifiable measures used in operational risk management to monitor and signal changes in an organization's risk exposure. They provide ongoing visibility into the effectiveness of controls and the organization's
alignment with its defined risk appetite. In this context, metrics function as an early warning mechanism by highlighting trends or deviations that may indicate increasing operational risk before losses occur. These metrics support
risk monitoring, reporting, and governance processes, enabling informed decision-making and timely management actions within the operational risk framework. Indicators only support one type of results called Pass or Fail and don't
support data types such as number, percentage, or monetary amount. Metrics provide a better escalation and notification mechanisms, enable specific definition of data owners, and the classification of the indicators.  
The key benefits of metrics are as follows.

* Provides continuous visibility into risk and control performance.
* Alerts respective owners about changes in risk and control performance.
* Enables timely decision‑making by highlighting trends, exceptions, and threshold breaches.
* Supports consistent risk oversight and governance through standardized measurement and reporting.
{#using-metrics-in-irm__ul_fzj_1hp_ssb}

## Uses of the GRC: Metrics in Integrated Risk Management {#using-metrics-in-irm__section_kzw_2cp_fxb}

In Integrated Risk Management (IRM), the GRC: Metrics application helps organizations measure, monitor, and analyze risk-related data to support informed decision-making. For example, a risk team tracks operational risk exposure across business units
using predefined risk metrics. These metrics capture data such as the number of open risks by severity, overdue risk response tasks, and trends in inherent versus residual risk scores over time. By visualizing this data on
dashboards, risk managers can quickly identify areas with increasing risk exposure and prioritize remediation efforts.

## Types of metrics {#using-metrics-in-irm__section_wm1_bmp_ssb}

The following are the types of metrics.

* Key risk indicators (KRIs): These indicators identify the amount of exposure to a given risk or set of risks. Examples of KRIs are Staff morale determined through employee surveys, number of hacks attempted on IT, number of negative social media posts following a loss event and so on.
* Key control indicators (KCIs): These indicators identify the effectiveness of the controls that have been implemented to reduce or mitigate a given risk exposure.
* Key performance indicators (KPIs): These indicators show how effectively the risk exposure is managed. These indicators show the achievement against objectives.
{#using-metrics-in-irm__ul_pz4_dmp_ssb}

## Difference between indicators and metrics {#using-metrics-in-irm__section_okx_fsp_ssb}

Indicators are used as automated control tests or assessments while metrics are used as KRIs and KCIs monitoring tool. The following table lists the differences between an indicator and a metric.{#using-metrics-in-irm__table_ifh_f5p_ssb__entry__2}

| GRC Indicators | Metrics |
|-|-|
| Used for continuous monitoring of risks and controls and for collecting supporting data​. | Used to measure the degree to which a system, component, or process, possesses a given attribute.​ |
| Can be used to monitor a risk or control. | Can be used to measure any GRC object. |
| Can have only binary values such as pass or fail. | Can have any value such as, Quantitative (numbers) or Qualitative (text)​. |
[Table 1. Indicators versus metrics]

{#using-metrics-in-irm__table_ifh_f5p_ssb}

