TL;DR: Twelve KPIs across three categories tell you whether your AI governance program is working: coverage metrics (what is governed), activity metrics (what governance actions are happening), and outcome metrics (what risks are actually being reduced). Without this data, governance is paperwork. With it, you can report status to leadership, respond to auditors, and identify gaps before they become incidents.
Most AI governance programs look fine on paper. There is a policy document. There is a vendor checklist. There is a tool register with a dozen entries. But when a regulator asks whether the program is working, or when a board member asks what the company's AI risk exposure actually is, there is no data to answer the question.
The measurement gap is the most common weakness in AI governance programs at organizations without dedicated compliance teams. This guide closes that gap with 12 KPIs, grouped by what they actually measure, and a practical approach to reporting them.
The measurement problem
AI governance without metrics is a policy exercise. You write the rules, you distribute the policy, and you assume compliance is happening because no one has reported a problem. This assumption is almost always wrong.
The problems with unmeasured governance are predictable. Tools get added to the environment without going through the tool review process. Vendor DPAs expire without renewal. Training gets skipped when teams are busy. Incidents happen but are not recognized as incidents and so are never reported.
Each of these failures is invisible until it becomes an audit finding, a regulatory inquiry, or a data breach. Metrics make them visible before that point.
The good news: you do not need enterprise governance tooling to measure your program. A spreadsheet with monthly updates covers all 12 metrics described here. The question is which metrics to collect, not which platform to use.
The three categories of AI governance metrics
AI governance metrics fall into three categories that build on each other.
Coverage metrics answer: what is actually inside your governance program? What percentage of AI tools in your environment are documented? What percentage have completed risk assessments? What percentage of high-risk tools have a human review policy? Coverage metrics are the foundation. Without them, you do not know the scope of what you are governing.
Activity metrics answer: is your governance process actually running? How many tool reviews did you complete this quarter? How long does vendor due diligence take? How many incidents were reported? Activity metrics measure whether the machine is turning. High coverage with low activity usually means the register is a snapshot, not a living program.
Outcome metrics answer: is governance reducing actual risk? How many policy violations occurred? What percentage of audit findings have been closed? What is your vendor compliance rate? Outcome metrics take longer to accumulate and are harder to measure, but they are the ones that answer whether the program is doing its job.
Coverage metrics (4 KPIs)
KPI 1: AI tool registry coverage rate. The percentage of AI tools in your environment that are documented in the official tool register. Numerator: tools in the register. Denominator: estimated total tools in use, based on periodic discovery exercises (network traffic analysis, expense report review, employee survey). Target: above 90%. A rate below 70% means your governance program does not cover most of the AI exposure in your organization.
KPI 2: Risk assessment completion rate. The percentage of registered tools that have a completed risk assessment on file. Numerator: tools with a completed assessment. Denominator: total tools in the register. Target: 100% for high-risk tools; above 80% overall. Any registered tool without a completed assessment is a documented unknown, which is almost as problematic as an undocumented tool.
KPI 3: Human review policy coverage for high-risk tools. The percentage of tools classified as high-risk in your register that have a documented human review policy specifying when a human must review or override an AI output. This metric is especially relevant for teams subject to EU AI Act Article 14 requirements. Target: 100% of high-risk tools.
KPI 4: Data processing agreement (DPA) coverage rate. The percentage of AI vendors with a signed DPA on file. Numerator: vendors with signed DPAs. Denominator: all vendors in the register that process personal data. Target: 100%. A missing DPA is a direct GDPR Article 28 violation. This metric tends to reveal legacy vendor relationships where contracts predate AI-specific data handling requirements.
Activity metrics (4 KPIs)
KPI 5: AI tool reviews completed per quarter. The total number of new tool reviews completed, including initial approvals, re-reviews triggered by updates, and denials. This metric tells you whether the governance process is keeping up with the rate of new tool adoption. If your organization is adding five new AI tools per month and completing two reviews per quarter, the backlog is growing faster than the program can handle.
KPI 6: Time to complete vendor due diligence. The median number of business days from when a vendor review request is opened to when a decision is reached. Track P50 (median) and P90 (90th percentile, for slow outliers). A median over 30 business days suggests the review process is a bottleneck that business teams will work around, producing shadow AI adoption.
KPI 7: AI incidents reported vs. estimated total. The number of AI incidents formally reported through your incident process in the period, compared to an estimated total based on near-miss rates or employee surveys. A large gap between reported and estimated incidents indicates under-reporting, which means the incident process is not reaching the people who experience AI problems. This metric is hard to estimate precisely, but even a rough ratio is useful for identifying reporting culture gaps.
KPI 8: AI literacy training completion rate. The percentage of employees in scope for AI governance training who have completed the required training in the current cycle. Numerator: completions. Denominator: employees in scope (often all employees who use approved AI tools). EU AI Act Article 4 requires providers and deployers to ensure sufficient AI literacy. Training completion rate is the primary evidence of compliance with that obligation.
Outcome metrics (4 KPIs)
KPI 9: AI policy violation rate. The number of confirmed policy violations per quarter, by category (unauthorized tool use, data handling violation, output use outside approved scope). This metric requires a functioning reporting and investigation process. In the first year of tracking, the number will likely rise as reporting culture improves and more violations are identified. A sustained increase after the first year indicates a policy or training gap.
KPI 10: Audit finding closure rate. The percentage of open audit findings (from internal audits, external audits, or regulatory reviews) that have been closed within the target resolution period. Target: above 80% closure within 90 days for non-critical findings, 100% closure within 30 days for critical findings. A low closure rate is a leading indicator of regulatory risk: unresolved audit findings are the most common trigger for escalated regulatory attention.
KPI 11: Vendor compliance rate. The percentage of AI vendors in your register that meet all your compliance requirements, including DPA signed, training opt-out policy confirmed (where relevant), data residency requirements met, and security assessment completed. Target: above 95%. Vendors below 100% on individual requirements should be tracked individually with remediation timelines.
KPI 12: AI governance policy review currency rate. The percentage of governance policies (acceptable use policy, AI tool review procedure, incident response plan) that have been reviewed within the required review cycle (typically annually). A policy last reviewed in 2023 does not reflect current regulatory requirements. This metric ensures the governance framework itself stays current.
Maturity model: three tiers
Governance measurement programs typically evolve through three tiers.
Tier 1 (basic, months 1-6): Track coverage metrics only. Get the tool register built, risk assessments started, and DPA tracking underway. The goal at this tier is to know what you are governing.
Tier 2 (operational, months 6-18): Add activity metrics. Measure whether the governance process is running at the pace required. Identify backlogs and bottlenecks. The goal at this tier is to make governance continuous rather than periodic.
Tier 3 (advanced, 18 months onward): Add outcome metrics and leading indicators. At this tier, you are tracking whether governance is actually reducing risk, not just running process. You can start connecting metrics to business outcomes (fewer security incidents, fewer contract disputes with AI vendors) and to regulatory requirements.
Most organizations with fewer than 200 employees should operate at Tier 2. Getting to Tier 3 requires reliable incident reporting, which takes 12-18 months of investment in reporting culture.
How to report metrics to leadership
Leadership reporting should follow a red-amber-green (RAG) format. One row per metric, four columns: metric name, current value vs. target, trend arrow (up, flat, or down), and a one-line action note for any red or amber metric.
The dashboard should be reviewed at least quarterly at board or executive level, and monthly by the person accountable for AI governance. Do not include methodology in the executive dashboard. That belongs in a separate methodology appendix for auditors.
The narrative accompanying the dashboard should answer three questions: What changed since last period? What is the most important gap right now? What action is being taken?
A sample 12-metric dashboard header looks like this:
| Metric | Current | Target | Trend | Action |
|---|---|---|---|---|
| Tool registry coverage | 84% | 90% | Up | Discovery exercise Q3 |
| DPA coverage | 91% | 100% | Flat | 3 vendors in remediation |
| Training completion | 78% | 95% | Up | Reminder campaign active |
Connecting metrics to regulatory requirements
Different metrics map to different regulatory obligations, which matters when you are preparing for a regulatory inspection or responding to a due diligence questionnaire.
Tool registry coverage and risk assessment completion map to EU AI Act Article 9 (risk management system must cover all relevant AI systems). DPA coverage maps to GDPR Article 28. Training completion maps to EU AI Act Articles 4 and 26. Incident reporting rate maps to EU AI Act Article 73. Audit finding closure rate maps to demonstrated regulatory responsiveness under any framework.
Maintaining a mapping table between your 12 KPIs and the regulatory requirements they evidence makes regulatory reporting substantially faster. When an auditor asks for evidence of your risk management system, you can point to the tool registry coverage and risk assessment completion rates as the primary evidence, supplemented by the underlying records.
For teams looking for a starting point, the AI governance metrics dashboard for small teams provides a spreadsheet template that tracks 15 metrics including the 12 covered here. The AI governance checklist covers what policies and processes need to be in place before metrics collection makes sense.
Related reading
- AI governance metrics dashboard for small teams
- AI governance checklist 2026
- AI tool register template
- AI governance for small teams, complete guide
- AI compliance cost for small teams in 2026
- Shadow AI policy for small teams - shadow AI tool density is a leading indicator metric worth tracking
- AI compliance program maturity model 2026
