APRA CPS 220 Risk Management
Assurance

APRA CPS 220 Risk Management CPS220-11: Annual Audit Review of the Framework

The institution must ensure that compliance with and the effectiveness of the risk management framework is reviewed by internal or external audit at least annually, with results reported to the Board Audit Committee, the senior officer outside Australia or the Compliance Committee as relevant.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 46 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established

NIST SP 800-53 Rev 5 · 3 controls

C5 (Germany) · 2 controls

  • C5-COM-03 Internal audits of the information security management system
  • C5-COM-04 Information on information security performance and management assessment of the ISMS

FedRAMP High · 2 controls

FedRAMP Moderate · 2 controls

ISO 14001:2015 · 2 controls

  • 9.2 Internal audit
  • 9.2.2 Internal audit programme

ISO 37301:2021 · 2 controls

  • 9.2 Internal audit
  • 9.2.2 Internal audit programme

ISO 45001:2018 · 2 controls

  • 9.2 Internal audit
  • 9.2.2 Internal audit programme

SOC 2 · 2 controls

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • 45 Para 45 Internal audit periodic review and assurance on the BCP
  • SPS220-48 Internal and External Audit Arrangements

CMMC 2.0 · 1 control

HIPAA Security Rule · 1 control

ISO 13485:2016 · 1 control

ISO 14004:2016 · 1 control

  • 9.2 Internal audit

ISO 22000:2018 · 1 control

  • 9.2 Internal audit

ISO 22301:2019 · 1 control

  • 9.2 Internal audit

ISO 27001:2022 · 1 control

  • 9.2.2 Internal audit programme

ISO 27701:2019 · 1 control

ISO 37001:2016 · 1 control

  • 9.2 9.2 Internal audit

ISO 55001:2014 · 1 control

  • 9.2 Internal audit

ISO 9001:2015 · 1 control

  • 9.2 Internal audit

ISO/IEC 42001:2023 · 1 control

  • 9.2 Internal audit

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 46 it maps to, and the evidence behind each claim, over MCP and REST.