Index / Research / AI insider risk KPIs for the board

AI insider risk KPIs for the board

Research6 min readCited sources

AI insider risk KPIs for the board are a short set of measures that show how much exposure your AI usage creates and whether it is getting better or worse. The defensible set is five: exposure score and band over time, AI tool and account inventory coverage, the share of AI use on personal versus corporate accounts, time to see and act on risky AI data movement, and offboarding completeness for AI sessions and tokens. Each should trend over quarters, sit against a benchmark, and point to two or three moves.

Why boards started asking about AI risk

A year ago the AI question at the board table was about opportunity. Now it arrives with a risk clause attached, because the people governing the company have read the same headlines their employees have and they know AI use inside the business is no longer contained to a sanctioned pilot. It runs on personal accounts, on browser extensions, on tools nobody in security approved.

The average annual cost of insider risk reached 19.5 million dollars.
Ponemon Institute, 2026 Cost of Insider Risks Global Report

The financial framing is what moved it onto the agenda. The average annual cost of insider risk reached 19.5 million dollars (Ponemon Institute, 2026 Cost of Insider Risks Global Report), and most of that is not malice. 53% of insider incidents stem from employee negligence (Ponemon Institute, 2026 Cost of Insider Risks Global Report), which is precisely the shape of an employee pasting a customer list into a personal AI account to save an hour. Boards are not asking whether AI is dangerous. They are asking whether you can measure the exposure and show it moving in the right direction.

The trap is answering with activity. Number of policies published, number of tools blocked, number of training modules completed. None of those tell a director whether the company is more or less likely to lose data through AI this quarter than last. A board needs a small number of measures that survive a hard follow-up question, and each one has to connect to a decision.

The five KPIs worth reporting

Start with the exposure score and band over time. On this index, exposure is scored 0 to 100 across five signals (AI visibility, Data movement, Identity and ownership, Evidence and audit, Remediation reach) weighted 25/25/20/15/15, and the score maps to one of five bands: Contained, Guarded, Elevated, Exposed, Critical. This is the headline. One number, one band, plotted across quarters. A board can read a line that moves from Exposed toward Guarded without any security vocabulary.

Second, AI tool and account inventory coverage. This is the percentage of AI usage you can actually see, expressed against your best estimate of total usage. Coverage of 40% means the score is built on a minority of what is happening, and the board should know that. A rising coverage number is often the first real progress a program makes.

Third, the share of AI use on personal versus corporate accounts. This is the cleanest proxy for ungoverned risk, because a personal account sits outside your logging, your retention, and your ability to revoke access. Report it as a percentage of active AI users. Fourth, time to see and act on risky AI data movement, measured from the moment a sensitive movement happens to the moment someone acts on it. Fifth, offboarding completeness for AI sessions and tokens: of people who left in the period, what share had every AI session, API key, and connected token actually revoked. A departed employee with a live token is an insider risk that no longer shows up on any headcount report.

How to compute each from tools you already run

None of these require a new platform. Exposure score comes from the assessment on this site, which takes about ten minutes and runs on 12 to 15 questions. Run it quarterly with the same person answering and you have a defensible trend line rather than a one-time snapshot.

67% of employees who use AI on corporate devices sign in with a personal account.
Verizon, 2026 DBIR

Inventory coverage comes from joining what you can already see. Your secure web gateway or DNS logs show traffic to AI domains. Your identity provider shows OAuth grants to AI applications. Your CASB or endpoint tooling shows installed extensions and desktop clients. Deduplicate those into a list of tools and accounts in use, then divide by a sensible estimate of total demand. The personal versus corporate split falls out of the same identity data: an AI app authorized through your SSO tenant is corporate, a sign-in with a consumer email domain is personal. 67% of employees who use AI on corporate devices sign in with a personal account (Verizon, 2026 Data Breach Investigations Report), so expect this number to start high.

Time to see and act comes from your DLP or data movement logs joined to your ticketing or case system: timestamp of the flagged movement, timestamp of the first human action, take the median. Offboarding completeness comes from reconciling your leaver list against your identity provider and the admin consoles of your sanctioned AI tools. If a tool has no admin console, that absence is itself a finding worth putting in front of the board.

Presenting exposure to a board

A board slide has three jobs: show the trend, place it against a benchmark, and name the two or three moves. The trend is the exposure score and band across the last four quarters. The benchmark is where your band sits relative to a plausible peer, so a director can tell whether Elevated is normal or alarming for a company like yours. The moves are the small number of actions that would shift the score, each tied to the signal it improves.

Resist the dashboard reflex. A director does not need all five KPIs at equal weight on one screen. Lead with the score and band, support it with the two supporting KPIs that are actually moving, and hold the rest in an appendix for the follow-up question. The point of the report is a decision, usually about where the next dollar of attention goes, and a wall of gauges makes that harder, not easier.

Frame each move as a bet with a payoff. Consolidating AI use onto corporate accounts lowers the personal-account share and lifts inventory coverage at the same time. Wiring AI data movement alerts into the existing case queue cuts time to act. When a move touches two signals, say so, because that is the argument for doing it first.

Grounding the stakes in cost and time

The numbers give the KPIs their weight. The global average cost of a data breach was 4.44 million dollars in 2025 (IBM, Cost of a Data Breach Report 2025), and breaches took a mean of 241 days to identify and contain that year (IBM, Cost of a Data Breach Report 2025). Insider incidents specifically ran to 67 days to contain on average (Ponemon Institute, 2026 Cost of Insider Risks Global Report). Every KPI that shortens detection or containment is bending one of those curves.

Organizations using AI and automation extensively identified and contained breaches about 80 days faster and at 1.9 million dollars lower cost.
IBM, Cost of a Data Breach Report 2025

This is why time to see and act is worth reporting on its own. Organizations that used AI and automation extensively identified and contained breaches about 80 days faster and at 1.9 million dollars lower cost (IBM, Cost of a Data Breach Report 2025). That is the shape of the return: the same measurement that tells the board how exposed you are also names the lever that reduces the cost when something goes wrong.

When a director asks what the program is worth, you have the answer in their language. A rising exposure score paired with a falling time to act is a smaller expected loss, and the figures behind it are external and citable. That is a more honest case than any count of blocked tools, and it holds up under the second question.

Where to start

If you report nothing else this quarter, report the exposure score, its band, and the personal-account share, with one move against each. Those three are computable from data you already hold, they trend cleanly, and they map to decisions a board can make. The other two KPIs follow once the plumbing is in place.

Take the assessment on this site to get your first score and band, then run it again next quarter to establish the line. Teams that want to close the gap between seeing risky AI activity and acting on it often look at how a platform like Anzenna's approach to insider risk pulls identity, data movement, and remediation into one view. Whatever the tooling, the board deliverable stays the same: a small set of numbers that move, benchmarked, with the next moves named.

In short
  • Report a small set: exposure score and band, AI inventory coverage, personal vs corporate account share, time to act, and offboarding completeness.
  • Every KPI is computable from tools you already run: identity provider, web gateway, DLP, ticketing, and admin consoles.
  • Lead the board slide with the score and band over time, benchmark it, and name two or three moves, not a wall of gauges.
  • Ground the stakes in citable numbers: insider risk runs 19.5 million dollars a year and insider incidents take 67 days to contain (Ponemon 2026).
  • AI and automation cut breach detection and containment by about 80 days and 1.9 million dollars (IBM 2025), so time-to-act is a lever, not just a metric.

Common questions

What insider risk KPIs should a board see?

Five: the exposure score and band over time, AI tool and account inventory coverage, the share of AI use on personal versus corporate accounts, time to see and act on risky AI data movement, and offboarding completeness for AI sessions and tokens. Lead with the score and band, and tie each metric to a decision rather than to activity counts.

How do you measure AI insider risk?

Score exposure 0 to 100 across five signals (AI visibility, Data movement, Identity and ownership, Evidence and audit, Remediation reach) and map it to a band from Contained to Critical. Compute the supporting KPIs from tools you already run: identity provider data for the personal versus corporate split, DLP and ticketing timestamps for time to act, and leaver reconciliation for offboarding completeness.

What is a good exposure score?

Direction matters more than the absolute number. On a 0 to 100 scale a lower score is better, and the bands (Contained, Guarded, Elevated, Exposed, Critical) tell the board where you sit. A score falling across quarters while inventory coverage rises is the real signal of progress, because it means the number is built on more of what is actually happening.

How often should you report AI insider risk to the board?

Quarterly for the full set, using the same assessment run the same way so the trend line is defensible. Report material changes out of cycle, such as a spike in personal-account use or a breach with an AI element, rather than waiting for the next scheduled slide.

How do you benchmark exposure?

Place your band against a plausible peer so a director can judge whether it is normal or alarming for a company your size and sector, then ground the stakes in external figures. The average annual cost of insider risk reached 19.5 million dollars (Ponemon Institute, 2026 Cost of Insider Risks Global Report), which frames what movement in the score is worth.

Go deeper on the platform side. Anzenna's work on Anzenna's approach to insider risk covers how teams act on this in production.

Score your exposure

Fifteen questions, about ten minutes, no registration to see your result.

Take the assessment