APRA CPS 220 Risk Management
Board Oversight

APRA CPS 220 Risk Management CPS220-02: Board Responsibility for the Risk Management Framework

The Board is ultimately responsible for the risk management framework and for overseeing its operation by management, and must ensure it sets risk appetite and approves the risk appetite statement and risk management strategy, forms a view of risk culture and drives any changes needed, has senior management monitor and manage all material risks consistently with approved strategy, appetite and policies, has an operational structure that supports effective risk management, has risk taking policies and processes consistent with the strategy and appetite, dedicates sufficient resources to risk management, and recognises the uncertainties, limitations and assumptions in measuring each material risk.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 16 controls across 7 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
  • NIST-CSF-GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
  • NIST-CSF-GV.RR-03 Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies

NIST SP 800-53 Rev 5 · 4 controls

SOC 2 · 3 controls

  • SOC2-CC1.1 CC1.1 Commitment to integrity and ethical values (COSO principle 1)
  • SOC2-CC1.2 CC1.2 Board independence and oversight of internal control (COSO principle 2)
  • SOC2-CC1.5 CC1.5 Accountability for internal control responsibilities (COSO principle 5)
  • 19 Para 19 Board ultimate accountability for operational risk oversight
  • SPS220-13 Board Responsibility for the Risk Management Framework

C5 (Germany) · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 16 it maps to, and the evidence behind each claim, over MCP and REST.