Metrics question

You are part of the Internal Auditing team in a company. How would you set the KPIs to measure compliance and risk appetite?

Practice this question out loud. An AI interviewer asks it, follows up like a real interviewer would, and scores your answer. Type or speak.

Start a mock interview on this question · Mock interview from a job description

What this question tests

Ability to translate an abstract governance mandate into concrete, trackable KPIs for a fintech's internal audit function.

How to approach it

  1. Clarify risk appetite means the level of risk leadership has explicitly agreed to tolerate, not something audit itself sets.
  2. Segment KPIs into compliance, whether rules are being followed, and risk appetite, whether operations stay within agreed limits.
  3. Compliance KPIs: number of regulatory findings, time to remediate audit findings, and percentage of controls tested on schedule.
  4. Risk appetite KPIs: percentage of exposure limits breached, such as credit concentration or transaction monitoring thresholds, and near-limit breach trends as an early warning.
  5. Add a guardrail: audit coverage, the percentage of business units audited per cycle, so KPI-chasing doesn't skip high-risk areas.
  6. Report these to the board or audit committee on a regular cadence tied to actual remediation actions, not just scores.

What a strong answer includes

Common mistakes

Likely follow-up questions

More metrics questions

More questions from Revolut

Learn the skill behind it

Chapters of the AI PM course that teach what this question tests.

Preparing for a specific role?

Book summaries for this kind of question

Browse all 4,000+ questions in the bank