There’s an old joke that makes the rounds in management circles. A factory changes owners. The new owner walks the floor and finds a man pacing back and forth in a corridor, doing nothing in particular.
“What are you doing?” the owner asks.
“Chasing away crocodiles.”
“There are no crocodiles here.”
“Exactly.”
It’s a joke, but it’s also a fairly precise description of what a well-run prevention function, legal, security, IT, quality, actually looks like from the outside: mysteriously calm, apparently underworked, and very hard to justify on a spreadsheet. Keep that image in mind. We’ll come back to it.
Where KPIs Get It Exactly Right
I’ve spent thirty years in enterprise sales, as a rep and later building and running go-to-market functions at Xerox, Cisco, Samsung, Oracle, and SAP, and now advising CxOs through Anovatra. In sales, the KPI logic is close to unbreakable, because more pipeline, more qualified conversations, and more closed revenue are, in the great majority of cases, genuinely good things. A rep who books more meetings tends to close more deals. A team that hits quota tends to have grown the business. Activity and value point in the same direction, so a quota-and-commission structure isn’t a management shortcut: it’s an accurate reflection of how the work actually creates value.
That’s exactly why it’s tempting to reuse the same logic everywhere else in the company. If counting outputs and rewarding volume works this well for sales, why not apply the same discipline to legal, IT, HR, and finance? The answer is that in those functions, the thing you’d be counting usually isn’t the value being created. Often it’s the opposite.
The KPI Question That Should Worry You
A colleague recently sat through a job interview for a General Counsel role. At some point, the panel asked the obvious modern question: what KPIs would you set for the legal team, and how would you measure whether they were being met?
The instinctive answer many boards reach for is some version of “number of problems resolved” or “cases closed.” It sounds rigorous. It sounds measurable. For a role like this, it’s close to the worst possible metric available.
Here’s why. If you pay a person for the number of problems they solve, you have built an incentive structure where more problems is good for them. Not consciously, not maliciously in most cases, but structurally. Contracts get written a little more loosely. Risks get flagged a little later. Disputes get allowed to simmer instead of being defused early, because defusing something early leaves no trace in a KPI report. You end up paying, in effect, for the fires, not for their absence.
This isn’t a legal-department quirk. It’s one of the most common and most expensive mistakes in management, and it shows up anywhere the job is fundamentally about prevention rather than production.
Two Different Jobs, One Scorecard
Most organizations, without quite meaning to, use one measurement philosophy for every function: count the outputs, reward the volume. That philosophy is excellent for roles where more activity genuinely means more value, which is most of revenue generation. It breaks down badly for roles where the entire point is that nothing visible should happen.
Value-creating roles (sales, business development, most of marketing) generate outcomes that are close to monotonic: more qualified conversations tend to produce more revenue, more good campaigns tend to produce more pipeline. This is where performance KPIs, quotas, and commission structures belong, and they belong there because the incentive and the goal are aligned.
Prevention-oriented roles (legal, information security, systems administration, quality assurance, compliance, much of finance control) generate value precisely by keeping things from becoming visible. A contract that never triggers a dispute, a server that never goes down, a filing that never draws an audit: these are successes with no footprint. Reward the footprint instead (tickets closed, incidents resolved, fires put out), and you’re rewarding the failure of the underlying job. You will get more of it.
Ask yourself what happens if a system administrator is paid a base salary plus a bonus for the number of problems resolved. You already know the answer, because you’ve probably lived it: constant reinstalls, mysterious recurring issues, a machine you’re almost afraid to turn on. The tracking sheet shown to management looks fantastic. Nobody cares that you couldn’t get any work done. What gets rewarded is the entry in the log, not your ability to use your computer.
In the sales audits we run at Anovatra, this shows up from the other direction too: companies that, out of habit, hand support functions a rev-gen-style scorecard, and then can’t work out why legal spend or IT ticket volume keeps climbing even as the “problems resolved” number looks better every quarter.
Why This Matters More Than It Looks
If your organization has chronic firefighting, constant litigation, repeated audits, ongoing partner conflicts, recurring “emergency” escalations, it’s worth asking an uncomfortable question. Is this bad luck, a hostile environment, or is it possible that your incentive system is quietly manufacturing the fires it claims to be putting out?
This is a structural, design-level issue, and it sits squarely in the CxO’s remit, not the department head’s. A CFO, an IT director, or a Head of Legal can only optimize within the incentive frame they’ve been handed. If that frame rewards visible problem-solving over invisible problem prevention, no amount of individual competence will fix the underlying pattern. The fix has to come from how the C-suite designs the scorecard in the first place.
There’s a second, less obvious cost: timing. When you have a genuine crisis, the good specialists you’d want are already busy. They’re handling other clients’ litigation, other companies’ security incidents, other teams’ deadlines, because those clients understood something you didn’t: you don’t call a strong specialist when the building is already on fire. You retain their attention in advance.
This is why the smartest way to work with a strong lawyer, security consultant, or senior operator is rarely “we’ll call when something breaks.” It’s closer to a retainer: a fixed block of hours per week or month that buys you two things with nothing to do with problem counts. It buys reserved capacity, and it buys speed of response when you need it. In a crisis, you aren’t buying hours of labor. You’re buying the ability to lose significantly less money than the specialist costs you. That math only works if the relationship already exists.
What to Measure Instead
None of this means prevention-oriented roles should go unmeasured. It means they need a different kind of measurement, built around leading and trailing quality indicators rather than raw activity counts. In practice, this tends to look like:
- Trend metrics, not raw counts. Track the frequency and severity of incidents over time, not the number resolved this month. A downward trend in serious incidents is success. A high resolution count with a flat or rising incident trend is a warning sign, not an achievement.
- Leading indicators over lagging ones. Audit findings caught before an external review, near-miss reports filed voluntarily, risks flagged before a contract is signed rather than after a dispute starts. These are hard to game because they reward visibility of small problems, not the existence of big ones.
- Response and availability, not resolution volume. For roles that exist to be ready, SLA adherence and reserved-capacity utilization tell you more than a ticket count ever will.
- Structural indicators. Percentage of contracts reviewed pre-signature rather than post-dispute, percentage of systems patched proactively rather than after an exploit, percentage of hires who complete onboarding without an HR escalation. These measure whether the process is designed to prevent problems, not just clean them up.
- Periodic external benchmarking, rather than continuous internal self-reporting, for the trust problem described below.
The Real Obstacle: Control, Not Metrics
If you’ve read this far and you’re the owner or CEO, there’s a decent chance the honest sticking point isn’t the metric design. It’s control. Performance KPIs feel safe because they’re visible and countable. Prevention metrics require you to trust that the absence of a problem is real work, not luck or laziness, and that trust is genuinely hard to extend, especially to functions you don’t have deep expertise in yourself.
There isn’t a shortcut around this. The only durable answer is hiring or partnering with someone senior enough in that domain to translate outcomes for you, someone who can look at “nothing happened this quarter” and tell you credibly whether that’s a well-run function or a ticking clock. That’s a hiring and governance decision, not a spreadsheet decision.
The crocodile joke works because it’s uncomfortable. The man in the corridor could genuinely be doing nothing, or he could be the reason the factory floor is still standing. From the outside, on a KPI dashboard, those two situations look identical. Designing a measurement system that can tell them apart, and knowing which functions need that system in the first place, is one of the more valuable, and more neglected, jobs a CxO has.
Anovatra works with CxOs on exactly this kind of structural question: how sales, legal, IT, and compliance functions should actually be measured and motivated, not just how they should report. If your organization’s incentive design hasn’t been reviewed in a while, it’s worth a look before the next fire tells you why.