Compliance departments today use detailed dashboards to track various metrics, such as the rate of training sessions, the number of alerts raised, the evaluation of third parties, the number of controls performed, processing delays, and the number of action plans closed. This development is generally seen as positive because it helps compliance teams show that they are managing their programs effectively. However, treating compliance indicators like traditional performance metrics can be misleading. Simply measuring more does not always mean understanding more. A high training rate, for example, does not necessarily show that employee behaviors have changed, and a drop in the number of alerts does not automatically mean that risks have decreased. Similarly, faster processing of files does not always indicate better investigations. A low number of incidents could suggest either a strong compliance program or a lack of detection capability. Compliance key performance indicators (KPIs) are often ambiguous in their interpretation. While the numbers are essential, they are rarely sufficient on their own. Measuring activity, such as how many people have completed training, is useful for understanding the reach of a program, but it doesn’t necessarily show how effective the training is. For instance, a company might report that 98 percent of its employees have completed anti-corruption training, which helps identify who hasn’t been trained. However, it doesn’t reveal whether employees will recognize a conflict of interest months later or if they can spot warning signs in their work. It is important to distinguish between execution indicators and effectiveness indicators. Conducting an audit is not the same as reducing a risk, and performing a due diligence check is not the same as making a better decision. While these activities show that a program is in place, proving its effectiveness requires showing that it actually makes a difference. The paradox of compliance indicators is that the same statistical change can reflect completely different realities. An increase in internal alerts might show more problematic behavior, but it could also mean that employees are more confident in the program's confidentiality or that the company has a more open culture for reporting issues. Conversely, a decrease in alerts could indicate real improvement or a loss of trust, fear of retaliation, or the belief that reporting has no impact. The number of incidents does not necessarily mean that there is no risk. While activity indicators are important, they should not be the only way to measure progress. A second level of measurement focuses on quality: whether training is understood, whether controls are targeting the most significant risks, whether third-party due diligence is appropriate to the risk level, whether investigations are well-documented, and whether remediation plans are actually carried out. A third, often more revealing, dimension is behavior: whether employees consult compliance before making important decisions, whether managers recognize situations that need escalation, and whether conflicts of interest are declared early. A strong compliance program can sometimes produce "bad" numbers. For example, an improvement in the program might temporarily worsen certain indicators, such as better detection leading to more anomalies or an effective awareness campaign resulting in more alerts. A less mature organization might show very reassuring indicators simply because it detects very few issues. The ability to identify risk often comes before the ability to reduce it. When a compliance program matures, its early statistics might look less favorable but could indicate that it is finally generating useful information. The timing of escalation is also an important indicator. Two companies might report the same number of compliance-related consultations, but the value of those consultations could be very different. In one case, compliance might act after a contract is signed, while in another, it might intervene before a decision becomes irreversible. Recurrence can sometimes be more telling than volume. The number of incidents is an imperfect measure when analyzed alone. One useful indicator is the recurrence of issues after remediation, as repeated problems may suggest deeper structural issues rather than just individual behavior. Averages can also hide risk. Compliance teams should be cautious with statistical tools like averages, which can mask simple alerts closed quickly and critical issues that remain unresolved for long periods. A high average compliance level might hide a concentration of anomalies in a particular subsidiary, region, or type of transaction. A high-performing dashboard should not only compile data but also highlight unusual patterns or concentrations. The value of compliance is often invisible. A strong compliance program prevents certain events, but the events it prevents usually leave little trace. Measuring compliance’s value can be difficult because it lies in reducing uncertainty, improving decision quality, ensuring traceability, and enabling operations to proceed securely rather than being outright prohibited. The real challenge is not to abandon traditional KPIs but to understand what they can and cannot show. A mature compliance function should be able to explain what has objectively changed in the organization due to the compliance program.